imPC@ndo IT

Microsoft vulnerabilities

15.407 CVE

CVE-2020-1349
High 7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.

microsoft 365_apps · microsoft office · microsoft outlook
0.23EPSS
CVE-2016-7257
Medium 6.5

The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Infor…

microsoft office_for_mac · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.23EPSS
CVE-2015-2557
High 9.3

Buffer overflow in Microsoft Visio 2007 SP3 and 2010 SP2 allows remote attackers to execute arbitrary code via crafted UML data in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft visio
0.22EPSS
CVE-2015-1623
High 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and …

microsoft internet_explorer
0.22EPSS
CVE-2014-6351
High 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2012-0176
High 9.3

Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."

microsoft silverlight
0.22EPSS
CVE-2018-8393
High 7.8

A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, W…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server_2008 · and 2 more
0.22EPSS
CVE-2009-3864
High 7.5

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows rem…

microsoft windows · sun jdk · sun jre
0.22EPSS
CVE-2012-1523
High 9.3

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2003-0526
Medium 6.8

Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the …

microsoft isa_server
0.22EPSS
CVE-2017-0128
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0127
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0126
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0125
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0124
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0123
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0122
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0119
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0117
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0116
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0115
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0114
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0113
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0112
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0111
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS