imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2015-1650
High 9.3

Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Serve…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · and 2 more
0.27EPSS
CVE-2016-3199
High 8.8

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.27EPSS
CVE-2020-17103
High 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.27EPSS
CVE-2011-0979
High 9.3

Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.27EPSS
CVE-2010-0018
High 9.3

Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attac…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · and 2 more
0.27EPSS
CVE-2000-0071
Medium 5.0

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

microsoft internet_information_server · microsoft internet_information_services
0.27EPSS
CVE-2023-21689
Critical 9.8

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.27EPSS
CVE-2004-0117
High 7.5

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

microsoft netmeeting · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · and 2 more
0.27EPSS
CVE-2014-4061
Medium 6.8

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka…

microsoft sql_server
0.26EPSS
CVE-2003-0531
High 7.5

Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Z…

microsoft ie · microsoft internet_explorer
0.26EPSS
CVE-2009-2523
High 10.0

The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW met…

microsoft windows_2000
0.26EPSS
CVE-2009-1135
High 9.0

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, vi…

microsoft isa_server
0.26EPSS
CVE-1999-0918
High 7.8

Denial of service in various Windows systems via malformed, fragmented IGMP packets.

microsoft windows_2000 · microsoft windows_95 · microsoft windows_98 · microsoft windows_nt
0.26EPSS
CVE-2000-0710
Medium 5.0

The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

microsoft frontpage
0.26EPSS
CVE-2011-3412
High 9.3

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."

microsoft publisher
0.26EPSS
CVE-2017-0134
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.26EPSS
CVE-2017-0015
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.26EPSS
CVE-2011-0980
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Ex…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.26EPSS
CVE-2007-0214
High 9.3

The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.26EPSS
CVE-2019-1150
High 8.8

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install p…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.26EPSS
CVE-2008-1544
High 7.1

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) cond…

microsoft internet_explorer
0.26EPSS
CVE-2017-0031
High 7.8

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnera…

microsoft office · microsoft office_compatibility_pack · microsoft word
0.26EPSS
CVE-2006-6311
Medium 5.0

Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.

microsoft internet_explorer
0.26EPSS
CVE-2004-0202
Medium 5.0

IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.

microsoft directx · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · and 3 more
0.26EPSS
CVE-2016-3282
High 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Servi…

microsoft office · microsoft office_compatibility_pack · microsoft office_online_server · microsoft office_web_apps · and 6 more
0.26EPSS