imPC@ndo IT

Microsoft vulnerabilities

15.418 CVE

CVE-2015-0068
High 9.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-00…

microsoft internet_explorer
0.22EPSS
CVE-2000-0942
Medium 5.1

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

microsoft indexing_service
0.22EPSS
CVE-2010-1245
High 9.3

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "E…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.22EPSS
CVE-2004-0118
High 7.2

The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.

microsoft windows_2000 · microsoft windows_nt
0.22EPSS
CVE-2012-1878
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnBeforeDeactivate Event Remote Code Execution Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2015-0032
High 9.3

vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory …

microsoft internet_explorer · microsoft vbscript
0.22EPSS
CVE-2000-0621
High 7.5

Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.

microsoft outlook · microsoft outlook_express
0.22EPSS
CVE-2011-0347
High 9.3

Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz.

microsoft internet_explorer
0.22EPSS
CVE-2015-0019
High 9.3

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2002-1831
Medium 5.0

Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

microsoft msn_messenger
0.22EPSS
CVE-2001-1055
Medium 5.0

The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.

microsoft windows_98 · microsoft windows_98se
0.22EPSS
CVE-2010-3330
Medium 6.5

Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure …

microsoft internet_explorer
0.22EPSS
CVE-2012-0161
High 9.3

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via…

microsoft .net_framework
0.22EPSS
CVE-2009-2503
High 9.3

GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Of…

microsoft .net_framework · microsoft excel_viewer · microsoft expression_web · microsoft forefront_client_security · and 22 more
0.22EPSS
CVE-2011-1979
High 9.3

Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."

microsoft visio
0.22EPSS
CVE-2011-1972
High 9.3

Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."

microsoft visio
0.22EPSS
CVE-2018-8494
High 8.8

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.22EPSS
CVE-2012-2523
High 9.3

Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka "JavaScript Integer Overflow Rem…

microsoft internet_explorer · microsoft jscript · microsoft vbscript
0.22EPSS
CVE-2016-3370
Medium 6.5

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnera…

microsoft edge · microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 1 more
0.22EPSS
CVE-2001-0137
Medium 5.1

Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Pl…

microsoft windows_media_player
0.22EPSS
CVE-2012-2550
High 9.3

Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability."

microsoft works
0.22EPSS
CVE-2016-0035
High 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka…

microsoft excel · microsoft excel_for_mac · microsoft excel_viewer · microsoft office_compatibility_pack
0.22EPSS
CVE-2010-1257
Medium 4.3

Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attac…

microsoft internet_explorer · microsoft office_infopath · microsoft sharepoint_server · microsoft sharepoint_services
0.22EPSS
CVE-2016-7266
High 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 for Mac mishandle a registry check, which allows user-assisted remote attackers to execute arbitrary commands v…

microsoft excel · microsoft excel_for_mac · microsoft excel_viewer · microsoft office_compatibility_pack
0.22EPSS
CVE-2021-24094
Critical 9.8

Windows TCP/IP Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.22EPSS