imPC@ndo IT

Microsoft vulnerabilities

15.393 CVE

CVE-2014-0277
High 9.3

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and C…

microsoft internet_explorer
0.25EPSS
CVE-2003-0661
Medium 5.0

The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.25EPSS
CVE-2001-0508
Medium 5.0

Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.

microsoft internet_information_services
0.25EPSS
CVE-2012-0165
High 9.3

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ R…

microsoft office · microsoft windows_server_2008 · microsoft windows_vista
0.25EPSS
CVE-2008-0454
High 9.3

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title fi…

microsoft internet_explorer · skype_technologies skype
0.25EPSS
CVE-2007-3891
Medium 6.8

Unspecified vulnerability in Windows Vista Weather Gadgets in Windows Vista allows remote attackers to execute arbitrary code via crafted HTML attributes.

microsoft windows_vista
0.25EPSS
CVE-2015-6136
High 9.3

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerabi…

microsoft jscript · microsoft vbscript
0.25EPSS
CVE-2007-3032
Medium 6.8

Unspecified vulnerability in Windows Vista Contacts Gadget in Windows Vista allows user-assisted remote attackers to execute arbitrary code via crafted contact information that is not properly handled when it is imported.

microsoft windows_vista
0.25EPSS
CVE-2016-7289
High 7.8

Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft publisher
0.25EPSS
CVE-2019-0572
High 7.8

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019,…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.25EPSS
CVE-2006-7210
Medium 5.0

Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2013-0002
High 9.3

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a cr…

microsoft .net_framework
0.25EPSS
CVE-2017-11906
Medium 5.3

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further c…

microsoft internet_explorer
0.25EPSS
CVE-2010-3951
High 9.3

Buffer overflow in the FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Buf…

microsoft office · microsoft office_converter_pack
0.25EPSS
CVE-2010-3949
High 9.3

Buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Buffer Overflow…

microsoft office · microsoft office_converter_pack
0.25EPSS
CVE-2010-3945
High 9.3

Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter …

microsoft office · microsoft office_converter_pack
0.25EPSS
CVE-2010-2570
High 9.3

Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Ove…

microsoft publisher
0.25EPSS
CVE-2012-1887
High 9.3

Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability.…

microsoft excel · microsoft office
0.25EPSS
CVE-2012-1847
High 9.3

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitra…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.25EPSS
CVE-2026-20945
Medium 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

microsoft sharepoint_server
0.25EPSS
CVE-2016-7276
High 7.1

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "…

microsoft office · microsoft office_for_mac
0.25EPSS
CVE-2015-6055
High 9.3

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Filter argum…

microsoft jscript · microsoft vbscript
0.25EPSS
CVE-2009-3127
High 9.3

Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a craf…

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.25EPSS
CVE-2012-0018
High 9.3

Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."

microsoft visio_viewer
0.25EPSS
CVE-2013-1319
High 10.0

Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."

microsoft publisher
0.25EPSS