imPC@ndo IT

Microsoft vulnerabilities

15.407 CVE

CVE-2017-0092
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0091
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2017-0085
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2004-0122
Medium 5.0

Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.

microsoft msn_messenger
0.22EPSS
CVE-2018-8629
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.22EPSS
CVE-2009-1546
High 8.5

Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP…

microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.22EPSS
CVE-2011-1983
High 9.3

Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."

microsoft office
0.22EPSS
CVE-2010-0029
High 9.3

Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."

microsoft powerpoint
0.22EPSS
CVE-2014-0268
Medium 4.3

Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevati…

microsoft internet_explorer
0.22EPSS
CVE-2002-1292
High 7.5

The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager …

microsoft java_virtual_machine
0.22EPSS
CVE-2012-4775
High 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreeNode Use After Free Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2022-35742
High 7.5

Microsoft Outlook Denial of Service Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft outlook
0.22EPSS
CVE-2002-0054
High 7.5

SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null sessio…

microsoft exchange_server · microsoft windows_2000
0.22EPSS
CVE-2017-8550
Medium 5.4

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".

microsoft office
0.22EPSS
CVE-2019-1354
High 8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.

microsoft visual_studio_2017 · microsoft visual_studio_2019
0.22EPSS
CVE-2015-6042
High 9.3

Use-after-free vulnerability in the CWindow object implementation in Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corrupt…

microsoft internet_explorer
0.22EPSS
CVE-2025-53772
High 8.8

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

microsoft web_deploy_4.0
0.22EPSS
CVE-2014-2782
High 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.22EPSS
CVE-2006-1043
Medium 5.1

Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution…

microsoft visual_interdev · microsoft visual_studio
0.22EPSS
CVE-2010-1247
High 9.3

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnera…

microsoft excel
0.22EPSS
CVE-2010-0824
High 9.3

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulne…

microsoft excel · microsoft office
0.22EPSS
CVE-2012-0143
High 9.3

Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerabili…

microsoft excel · microsoft office
0.22EPSS
CVE-2016-7233
Medium 6.5

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensit…

microsoft excel_for_mac · microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · and 5 more
0.22EPSS
CVE-2012-0170
High 9.3

Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote Code Execution Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2010-0815
High 9.3

VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote a…

microsoft office · microsoft visual_basic_for_applications · microsoft visual_basic_sdk
0.22EPSS