imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2007-3670
Medium 4.3

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharact…

microsoft internet_explorer · mozilla firefox
0.29EPSS
CVE-2016-0198
High 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office docu…

microsoft office · microsoft office_compatibility_pack · microsoft word · microsoft word_for_mac · and 1 more
0.29EPSS
CVE-2016-0150
High 7.5

HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."

microsoft windows_10
0.29EPSS
CVE-2010-3947
High 9.3

Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Conv…

microsoft office · microsoft office_converter_pack · microsoft works
0.29EPSS
CVE-2011-1243
High 9.3

The Windows Messenger ActiveX control in msgsc.dll in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via unspecified vectors that "corrupt the system state," aka "Microsoft Windows Messenger ActiveX Control Vulnerability."

microsoft windows_xp
0.29EPSS
CVE-2010-0490
High 9.3

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka…

microsoft internet_explorer · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.29EPSS
CVE-2012-1885
High 9.3

Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SerAuxErrBar…

microsoft excel · microsoft office · microsoft office_compatibility_pack
0.29EPSS
CVE-2010-0807
High 9.3

Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

microsoft internet_explorer · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.29EPSS
CVE-2010-0491
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corr…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · and 1 more
0.29EPSS
CVE-2008-2254
High 9.3

Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2008-2256
High 9.3

Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized…

microsoft internet_explorer
0.29EPSS
CVE-2015-1730
High 9.3

Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2010-0488
Medium 6.5

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Informatio…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · and 3 more
0.29EPSS
CVE-2018-8273
Critical 9.8

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

microsoft sql_server
0.29EPSS
CVE-2012-0167
High 9.3

Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."

microsoft office
0.29EPSS
CVE-2006-2373
High 10.0

The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.29EPSS
CVE-2007-3899
High 9.3

Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."

microsoft office · microsoft word
0.29EPSS
CVE-2008-0235
High 10.0

The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.

microsoft vfp_ole_server_activex_control
0.29EPSS
CVE-2010-4669
High 7.8

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by send…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.29EPSS
CVE-2007-0209
High 9.3

Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.

microsoft office · microsoft works
0.29EPSS
CVE-2007-1211
High 7.1

Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes a…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.29EPSS
CVE-2008-2255
High 9.3

Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory C…

microsoft internet_explorer
0.29EPSS
CVE-2008-0078
High 9.3

Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."

microsoft activex · microsoft ie · microsoft internet_explorer
0.29EPSS
CVE-2009-0100
High 9.3

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Forma…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer
0.29EPSS
CVE-2013-1320
High 10.0

Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."

microsoft publisher
0.29EPSS