EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

16.469 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2005-1983 HIGH 10.0 microsoft windows_2000 Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as e 93,0% —
CVE-2023-35628 HIGH 8.1 microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability 92,8% —
CVE-2022-21907 CRIT 9.8 microsoft windows_10 HTTP Protocol Stack Remote Code Execution Vulnerability 92,8% —
CVE-2023-28302 HIGH 7.5 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 92,6% —
CVE-2023-21758 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 92,5% —
CVE-2009-3103 HIGH 10.0 microsoft windows_server_2008 Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v 92,3% —
CVE-2017-0004 HIGH 7.5 microsoft windows_7 The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security 91,4% —
CVE-2022-26809 CRIT 9.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 91,0% —
CVE-2009-3023 HIGH 9.0 microsoft internet_information_server Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS F 90,9% —
CVE-2001-0333 HIGH 7.5 microsoft internet_information_server Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. 90,8% —
CVE-2000-0402 LOW 2.1 microsoft sql_server The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. 90,6% —
CVE-2006-2372 HIGH 10.0 microsoft dhcp_client_service Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response. 90,2% —
CVE-2020-17132 CRIT 9.1 microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability 89,9% —
CVE-2023-21547 HIGH 7.5 microsoft windows_10_1607 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 89,3% —
CVE-2006-0026 MED 6.5 microsoft internet_information_server Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). 89,3% —
CVE-2023-21769 HIGH 7.5 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 88,7% —
CVE-2022-30216 HIGH 8.8 microsoft windows_10 Windows Server Service Tampering Vulnerability 88,6% —
CVE-2003-0718 MED 5.0 microsoft internet_information_server The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l 87,9% —
CVE-2000-1209 HIGH 10.0 compaq insight_manager The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight 87,3% —
CVE-2000-0778 MED 5.0 microsoft internet_information_services IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. 87,3% —
CVE-2008-5416 HIGH 9.0 microsoft sql_server Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and 87,0% —
CVE-2005-4360 HIGH 7.8 microsoft internet_information_services The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to prod 86,7% —
CVE-2010-0483 HIGH 7.6 microsoft windows_2000 vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC sha 86,6% —
CVE-2023-36035 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 86,6% —
CVE-2012-0152 MED 4.3 microsoft windows_7 The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service 86,3% —