imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2009-1925
High 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby trig…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista
0.27EPSS
CVE-2006-4702
Medium 6.8

Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.

microsoft windows_2003_server · microsoft windows_media_player · microsoft windows_xp
0.27EPSS
CVE-2011-3411
High 9.3

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."

microsoft publisher
0.27EPSS
CVE-2001-1325
High 7.5

Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerabili…

microsoft internet_explorer · microsoft outlook_express
0.27EPSS
CVE-2002-0867
Medium 5.0

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."

microsoft virtual_machine
0.27EPSS
CVE-2010-3138
High 9.3

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Pl…

bsplayer bs.player · microsoft windows_media_player · microsoft windows_xp
0.27EPSS
CVE-2008-4699
High 9.3

Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

microsoft peachtree_accounting
0.27EPSS
CVE-2010-1248
High 9.3

Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."

microsoft excel · microsoft office
0.27EPSS
CVE-2000-1034
High 10.0

Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.

microsoft windows_2000
0.27EPSS
CVE-2008-1445
High 7.1

Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.

microsoft windows-nt · microsoft windows_2003_server · microsoft windows_xp
0.27EPSS
CVE-2007-0943
Medium 6.8

Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.

microsoft ie · microsoft internet_explorer
0.27EPSS
CVE-2020-17047
High 7.5

Windows Network File System Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.27EPSS
CVE-2000-0653
Medium 5.0

Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

microsoft outlook_express
0.27EPSS
CVE-2009-0555
High 9.3

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary co…

microsoft windows_2000 · microsoft windows_media_format_runtime · microsoft windows_media_player · microsoft windows_server_2003 · and 3 more
0.27EPSS
CVE-2009-0233
Medium 5.8

The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easi…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008
0.27EPSS
CVE-2006-3442
High 7.6

Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast message.

microsoft windows_xp
0.27EPSS
CVE-2018-0893
High 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2…

microsoft edge
0.27EPSS
CVE-2012-0171
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability."

microsoft internet_explorer
0.27EPSS
CVE-2009-1132
High 9.3

Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Par…

microsoft windows_server_2008 · microsoft windows_vista
0.27EPSS
CVE-2018-8266
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.27EPSS
CVE-2017-0010
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.27EPSS
CVE-2012-0159
High 9.3

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10…

microsoft office · microsoft silverlight · microsoft windows_7 · microsoft windows_8 · and 3 more
0.27EPSS
CVE-2013-1282
Medium 5.0

The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and servic…

microsoft active_directory · microsoft active_directory_application_mode · microsoft active_directory_lightweight_directory_service · microsoft active_directory_services
0.27EPSS
CVE-1999-1484
High 7.5

Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.

microsoft msn_setup_bulletin_board_services
0.27EPSS
CVE-2004-1319
Medium 5.0

The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into t…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 5 more
0.27EPSS