imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2010-1253
High 9.3

Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execut…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft open_xml_file_format_converter
0.26EPSS
CVE-2010-0263
High 9.3

Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 2 more
0.26EPSS
CVE-2002-0724
High 7.5

Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or …

microsoft windows_2000 · microsoft windows_nt · microsoft windows_xp
0.26EPSS
CVE-2019-1350
High 8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

microsoft visual_studio_2017 · microsoft visual_studio_2019
0.26EPSS
CVE-2007-3751
High 9.3

Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.

apple mac_os_x · microsoft windows_vista · microsoft windows_xp
0.26EPSS
CVE-2006-5577
Medium 4.3

Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerabili…

microsoft ie
0.26EPSS
CVE-2005-0564
High 7.5

Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.

microsoft word
0.26EPSS
CVE-2009-0562
High 9.3

The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) S…

microsoft isa_server · microsoft office · microsoft office_web_components
0.26EPSS
CVE-2004-1560
Medium 5.0

Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.

microsoft sql_server
0.26EPSS
CVE-2022-23285
High 8.8

Remote Desktop Client Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 5 more
0.26EPSS
CVE-2009-2519
High 9.3

The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" cor…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.26EPSS
CVE-2005-2307
Medium 5.0

netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."

microsoft windows_2000 · microsoft windows_xp
0.26EPSS
CVE-2015-6086
Medium 4.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.26EPSS
CVE-2007-3892
High 7.5

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.

microsoft internet_explorer
0.26EPSS
CVE-2025-50154
Medium 6.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.26EPSS
CVE-2005-0420
Medium 5.8

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

microsoft exchange_server
0.26EPSS
CVE-2012-4782
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "CMarkup Use After Free Vulnerability."

microsoft internet_explorer
0.26EPSS
CVE-2014-4081
High 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.26EPSS
CVE-2014-4080
High 9.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-40…

microsoft internet_explorer
0.26EPSS
CVE-2006-5296
Medium 4.3

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint …

microsoft powerpoint
0.26EPSS
CVE-2008-4264
High 9.3

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File …

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · and 1 more
0.26EPSS
CVE-2017-0194
Medium 5.5

Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

microsoft excel · microsoft office_compatibility_pack
0.26EPSS
CVE-2018-8302
Critical 9.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

microsoft exchange_server
0.26EPSS
CVE-2008-1455
Medium 6.8

A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary cod…

microsoft compatibility_pack_word_excel_powerpoint · microsoft office · microsoft office_powerpoint_viewer
0.26EPSS
CVE-2015-3073
High 10.0

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-…

adobe acrobat · adobe acrobat_reader · apple mac_os_x · microsoft windows
0.25EPSS