58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-11937 | HIGH 7.8 | microsoft malware_protection_engine The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange S | 28.3% | — |
| CVE-2006-3431 | HIGH 7.5 | microsoft excel Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects | 28.3% | — |
| CVE-2016-7228 | HIGH 7.8 | microsoft excel Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Of | 28.3% | — |
| CVE-2007-6026 | HIGH 9.3 | microsoft jet Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column s | 28.3% | — |
| CVE-2016-0191 | HIGH 7.5 | microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE | 28.3% | — |
| CVE-2009-3270 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. | 28.2% | — |
| CVE-2019-0725 | CRIT 9.8 | microsoft windows_server_2008 A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | 28.2% | — |
| CVE-2011-1276 | HIGH 9.3 | microsoft excel Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attac | 28.2% | — |
| CVE-2001-0004 | MED 5.0 | microsoft internet_information_server IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .H | 28.2% | — |
| CVE-2010-1256 | HIGH 8.5 | microsoft internet_information_server Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, ak | 28.2% | — |
| CVE-2013-0092 | HIGH 9.3 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability." | 28.2% | — |
| CVE-2011-0041 | HIGH 9.3 | microsoft office Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka | 28.2% | — |
| CVE-2003-1566 | MED 5.0 | microsoft internet_information_services Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection. | 28.1% | — |
| CVE-2002-0409 | MED 5.0 | microsoft .net_framework orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | 28.1% | — |
| CVE-1999-0737 | MED 5.0 | microsoft internet_information_server The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | 28.1% | — |
| CVE-2013-0006 | HIGH 8.8 | microsoft expression_web Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability." | 28.1% | — |
| CVE-2001-0875 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download. | 28.1% | — |
| CVE-2000-0071 | MED 5.0 | microsoft internet_information_server IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | 28.1% | — |
| CVE-2007-5347 | MED 6.8 | microsoft ie Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability." | 28.0% | — |
| CVE-2008-1456 | HIGH 9.0 | microsoft windows-nt Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that | 28.0% | — |
| CVE-2013-3175 | HIGH 10.0 | microsoft windows_7 Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a malformed asynchronous RPC re | 28.0% | — |
| CVE-2009-0560 | HIGH 9.3 | microsoft office Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel View | 28.0% | — |
| CVE-2009-0223 | HIGH 9.3 | microsoft office_powerpoint Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," | 28.0% | — |
| CVE-2008-3474 | MED 6.5 | microsoft internet_explorer Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, | 28.0% | — |
| CVE-2011-1347 | HIGH 8.8 | microsoft internet_explorer Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained | 28.0% | — |