imPC@ndo IT

Microsoft vulnerabilities

15.393 CVE

CVE-2011-1965
High 7.1

Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/I…

microsoft windows_7 · microsoft windows_server_2008
0.25EPSS
CVE-2005-1212
High 7.5

Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.

microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_2003_server · microsoft windows_98 · and 3 more
0.25EPSS
CVE-2010-1261
High 9.3

The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Unin…

microsoft internet_explorer
0.25EPSS
CVE-2009-0098
High 9.3

Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Mem…

microsoft exchange_server
0.25EPSS
CVE-2009-0551
High 8.1

Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document follow…

microsoft internet_explorer
0.25EPSS
CVE-2010-3326
High 9.3

Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized M…

microsoft internet_explorer
0.25EPSS
CVE-2009-3133
High 9.3

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Exce…

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.25EPSS
CVE-2009-3131
High 9.3

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint …

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.25EPSS
CVE-2009-3128
High 9.3

Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Co…

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · and 1 more
0.25EPSS
CVE-2014-0290
High 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0267 and …

microsoft internet_explorer
0.25EPSS
CVE-2010-2561
High 9.3

Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memo…

microsoft xml_core_services
0.25EPSS
CVE-2002-0154
High 7.5

Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.

microsoft sql_server
0.25EPSS
CVE-2002-0056
High 7.5

Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.

microsoft sql_server
0.25EPSS
CVE-2016-7232
High 7.8

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office · microsoft office_compatibility_pack · microsoft word · microsoft word_for_mac
0.25EPSS
CVE-1999-0725
High 7.1

When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

microsoft internet_information_server
0.25EPSS
CVE-2015-4716
High 10.0

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

microsoft windows · owncloud owncloud · owncloud owncloud_server
0.25EPSS
CVE-2008-2959
High 9.3

Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.

microsoft visual_basic_enterprise_edition
0.25EPSS
CVE-2007-1091
Medium 6.8

Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.

microsoft ie · microsoft internet_explorer
0.25EPSS
CVE-2004-0728
Medium 5.0

The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.

microsoft systems_management_server
0.25EPSS
CVE-2010-1249
High 9.3

Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel M…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.25EPSS
CVE-2006-0012
Medium 5.1

Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Sh…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 2 more
0.25EPSS
CVE-2000-0596
High 7.5

Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.

microsoft internet_explorer
0.25EPSS
CVE-2018-8372
High 7.5

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is …

microsoft chakracore · microsoft edge · microsoft internet_explorer
0.25EPSS
CVE-2018-0797
High 7.8

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".

microsoft office · microsoft office_compatibility_pack · microsoft office_online_server · microsoft office_web_apps · and 5 more
0.25EPSS
CVE-2009-1140
High 7.1

Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass t…

microsoft internet_explorer
0.25EPSS