imPC@ndo IT

Microsoft vulnerabilities

15.393 CVE

CVE-2008-2248
Medium 4.3

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.

microsoft exchange_server · microsoft outlook_web_access
0.25EPSS
CVE-2010-4182
High 9.3

Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and po…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_vista · microsoft windows_xp
0.25EPSS
CVE-2015-2548
High 9.3

Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability."

microsoft windows_7 · microsoft windows_vista
0.25EPSS
CVE-2018-0806
High 8.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.25EPSS
CVE-2006-0032
Medium 4.3

Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is in…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2008-2247
Medium 4.3

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability than CVE-2008-2248.

microsoft exchange_server
0.25EPSS
CVE-2014-4129
High 9.3

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2012-2522
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a malformed virtual function table after this table's deletion, aka "Virtual Function Table Corruption Remo…

microsoft internet_explorer
0.25EPSS
CVE-2018-8162
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is uni…

microsoft excel · microsoft office · microsoft office_for_mac
0.24EPSS
CVE-2018-8158
High 7.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-20…

microsoft office
0.24EPSS
CVE-2018-8157
High 7.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-20…

microsoft office
0.24EPSS
CVE-2018-8148
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is uni…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_for_mac
0.24EPSS
CVE-2018-8147
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is uni…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_for_mac
0.24EPSS
CVE-2009-1216
High 10.0

Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as used in gunzip, gzip, pack, pcat, and un…

microsoft subsystem_for_unix-based_applications · microsoft windows_server_2008 · microsoft windows_services_for_unix · microsoft windows_vista
0.24EPSS
CVE-2004-0205
High 7.2

Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s8100 · and 1 more
0.24EPSS
CVE-2014-1800
High 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.24EPSS
CVE-2014-1797
High 9.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-17…

microsoft internet_explorer
0.24EPSS
CVE-2025-21377
Medium 6.5

NTLM Hash Disclosure Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.24EPSS
CVE-2025-21385
High 8.8

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

microsoft purview
0.24EPSS
CVE-1999-0702
High 10.0

Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

microsoft internet_explorer
0.24EPSS
CVE-2012-0183
High 9.3

Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vuln…

microsoft office · microsoft office_compatibility_pack · microsoft word
0.24EPSS
CVE-2006-0015
Medium 6.8

Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary …

microsoft frontpage_server_extensions · microsoft sharepoint_team_services
0.24EPSS
CVE-2018-0807
High 8.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.24EPSS
CVE-2018-0805
High 8.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.24EPSS
CVE-2018-0804
High 8.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.24EPSS