imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2017-0133
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.26EPSS
CVE-2017-0030
High 7.8

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (m…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · and 1 more
0.26EPSS
CVE-2016-0046
High 7.8

Windows Reader in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a crafted Reader file, aka "Microsoft Windows Reader Vulnerability."

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_server_2012
0.26EPSS
CVE-2003-0908
High 7.2

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as d…

microsoft windows_2000
0.26EPSS
CVE-2010-0811
High 9.3

Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, …

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.26EPSS
CVE-2009-0087
High 9.3

Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbit…

microsoft office_word · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.26EPSS
CVE-2000-0830
Medium 5.0

annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.

microsoft webtv
0.26EPSS
CVE-2009-3132
High 9.3

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint …

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.26EPSS
CVE-2008-1092
High 9.3

Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the sa…

microsoft word
0.26EPSS
CVE-2016-3374
Medium 6.5

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnera…

microsoft edge · microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 1 more
0.26EPSS
CVE-2003-0905
Medium 5.0

Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.

microsoft windows_media_services
0.26EPSS
CVE-2009-1539
High 9.3

The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allo…

microsoft directx · microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.26EPSS
CVE-2009-0232
High 9.3

Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.26EPSS
CVE-2009-0091
High 9.3

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NE…

microsoft .net_framework · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.26EPSS
CVE-2005-1216
High 7.5

Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.

microsoft isa_server
0.26EPSS
CVE-2007-2927
Medium 5.0

Unspecified vulnerability in Atheros 802.11 a/b/g wireless adapter drivers before 5.3.0.35, and 6.x before 6.0.3.67, on Windows allows remote attackers to cause a denial of service via a crafted 802.11 management frame.

microsoft all_windows
0.26EPSS
CVE-2008-4800
Medium 5.0

The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the Get…

microsoft debug_diagnostic_tool
0.26EPSS
CVE-2009-3134
High 9.3

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint …

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.26EPSS
CVE-2002-1712
Medium 5.0

Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.

microsoft windows_2000 · microsoft windows_nt
0.26EPSS
CVE-2004-0479
Medium 5.0

Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.

microsoft ie
0.26EPSS
CVE-2018-8269
High 7.5

A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.

microsoft microsoft.data.odata
0.26EPSS
CVE-2003-0820
High 7.5

Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.

microsoft word · microsoft works
0.26EPSS
CVE-2021-24074
Critical 9.8

Windows TCP/IP Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.26EPSS
CVE-2014-0287
High 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.26EPSS
CVE-2011-1968
High 7.1

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets tri…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.26EPSS