imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2007-3033
Medium 4.3

Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly…

microsoft windows_vista
0.28EPSS
CVE-2017-0106
High 7.8

Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory …

microsoft outlook
0.28EPSS
CVE-2010-3329
High 9.3

mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vu…

microsoft internet_explorer
0.28EPSS
CVE-2004-0846
High 7.5

Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.

microsoft excel · microsoft office
0.28EPSS
CVE-2018-0792
High 8.8

Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.

microsoft office · microsoft office_online_server · microsoft sharepoint_server · microsoft word
0.28EPSS
CVE-2016-3324
High 8.8

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.28EPSS
CVE-2013-0020
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability."

microsoft internet_explorer
0.28EPSS
CVE-2005-0056
Medium 5.1

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain …

microsoft ie · microsoft internet_explorer
0.28EPSS
CVE-2017-11937
High 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange S…

microsoft malware_protection_engine
0.28EPSS
CVE-2006-3431
High 7.5

Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects …

microsoft excel
0.28EPSS
CVE-2016-7228
High 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Of…

microsoft excel · microsoft excel_for_mac · microsoft office_compatibility_pack
0.28EPSS
CVE-2007-6026
High 9.3

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column s…

microsoft jet · microsoft office · microsoft windows_2000 · microsoft windows_2003_server · and 2 more
0.28EPSS
CVE-2016-0191
High 7.5

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.28EPSS
CVE-2009-3270
Medium 5.0

Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

microsoft internet_explorer
0.28EPSS
CVE-2011-1276
High 9.3

Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attac…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.28EPSS
CVE-2010-1256
High 8.5

Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, ak…

microsoft internet_information_server
0.28EPSS
CVE-2013-0092
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability."

microsoft internet_explorer
0.28EPSS
CVE-2019-1448
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

microsoft excel · microsoft office · microsoft office_365_proplus
0.28EPSS
CVE-2012-0014
High 7.8

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser applicatio…

microsoft .net_framework · microsoft silverlight
0.28EPSS
CVE-2010-1225
High 9.3

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory loc…

microsoft virtual_pc · microsoft virtual_server · microsoft windows_virtual_pc
0.28EPSS
CVE-2011-0041
High 9.3

Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka …

microsoft office · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.28EPSS
CVE-2003-1566
Medium 5.0

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

microsoft internet_information_services
0.28EPSS
CVE-1999-0737
Medium 5.0

The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

microsoft internet_information_server
0.28EPSS
CVE-2013-0006
High 8.8

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

microsoft expression_web · microsoft groove_server · microsoft office · microsoft office_compatibility_pack · and 11 more
0.28EPSS
CVE-2001-0875
High 7.5

Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.

microsoft internet_explorer
0.28EPSS