imPC@ndo IT

Microsoft vulnerabilities

15.393 CVE

CVE-2012-4777
High 9.3

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or …

microsoft .net_framework
0.25EPSS
CVE-2012-4776
High 9.3

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScr…

microsoft .net_framework
0.25EPSS
CVE-2008-2947
Medium 6.8

Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property…

microsoft internet_explorer
0.25EPSS
CVE-2006-3880
Medium 5.0

Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and rando…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2014-1795
High 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.25EPSS
CVE-2014-1791
High 9.3

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2014-0285
High 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.25EPSS
CVE-2014-0284
High 9.3

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2009-3675
Medium 6.8

LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, a…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2014-6365
Medium 4.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6328.

microsoft internet_explorer
0.25EPSS
CVE-2017-0003
High 7.8

Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft sharepoint_enterprise_server · microsoft word
0.25EPSS
CVE-2010-0030
High 9.3

Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."

microsoft powerpoint
0.25EPSS
CVE-2010-1246
High 9.3

Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."

microsoft excel
0.25EPSS
CVE-2016-3255
High 7.5

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, a…

microsoft .net_framework
0.25EPSS
CVE-2000-0328
Medium 5.0

Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.

microsoft windows_nt
0.25EPSS
CVE-2009-1923
High 9.3

Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length…

microsoft windows_2000 · microsoft windows_2003_server
0.25EPSS
CVE-2008-4265
High 9.3

Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing V…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · and 1 more
0.25EPSS
CVE-2014-6369
High 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2007-0468
Medium 6.8

Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.

microsoft visual_studio
0.25EPSS
CVE-2007-0026
High 7.6

The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2025-24071
Medium 6.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_11_23h2 · and 7 more
0.25EPSS
CVE-2012-0185
High 9.3

Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory…

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.25EPSS
CVE-2011-2004
High 7.1

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vuln…

microsoft windows_7 · microsoft windows_server_2008
0.25EPSS
CVE-2023-24949
High 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 4 more
0.25EPSS
CVE-1999-0448
Medium 5.0

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

microsoft internet_information_server
0.25EPSS