imPC@ndo IT

Microsoft vulnerabilities

15.393 CVE

CVE-2009-2525
High 9.3

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to e…

microsoft windows_2000 · microsoft windows_media_format_runtime · microsoft windows_media_player · microsoft windows_server_2003 · and 3 more
0.23EPSS
CVE-2017-0130
High 7.5

The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerabili…

microsoft internet_explorer
0.23EPSS
CVE-2018-0796
High 8.8

Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerabilit…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.23EPSS
CVE-2009-2497
High 9.3

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (X…

microsoft .net_framework · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.23EPSS
CVE-2018-8136
High 7.8

A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.23EPSS
CVE-2018-8154
Critical 9.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique fr…

microsoft exchange_server
0.23EPSS
CVE-2008-2281
High 9.3

Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing Ja…

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2016-7264
High 7.1

Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted documen…

microsoft excel · microsoft excel_for_mac · microsoft excel_viewer · microsoft office_compatibility_pack
0.23EPSS
CVE-1999-0980
Medium 5.0

Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.

microsoft windows_nt
0.23EPSS
CVE-2005-0562
High 7.5

GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.

microsoft msn_messenger
0.23EPSS
CVE-2011-3406
High 8.8

Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1,…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.23EPSS
CVE-2015-1649
High 9.3

Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute …

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · and 2 more
0.23EPSS
CVE-2017-8502
High 7.8

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8501.

microsoft excel
0.23EPSS
CVE-2006-2094
Medium 5.1

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which…

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2000-0028
Low 2.6

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2017-8718
High 7.8

The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.23EPSS
CVE-2019-0940
High 7.5

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

microsoft edge · microsoft internet_explorer
0.23EPSS
CVE-2010-0261
High 9.3

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET rec…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 2 more
0.23EPSS
CVE-2010-0260
High 9.3

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted …

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 2 more
0.23EPSS
CVE-2018-8225
High 8.1

A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server_2008 · and 2 more
0.23EPSS
CVE-2012-1863
Medium 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScri…

microsoft office_sharepoint_server · microsoft sharepoint_foundation · microsoft sharepoint_server · microsoft sharepoint_services
0.23EPSS
CVE-2012-1859
Medium 4.3

Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via craf…

microsoft office_web_apps · microsoft sharepoint_foundation · microsoft sharepoint_server
0.23EPSS
CVE-1999-1223
Medium 5.0

IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.

microsoft internet_information_server
0.23EPSS
CVE-2016-3260
High 8.8

The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a…

microsoft edge · microsoft internet_explorer
0.23EPSS
CVE-2014-4971
High 7.2

Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys dr…

microsoft windows_xp
0.23EPSS