58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-0038 | MED 5.5 | microsoft windows_10 gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain | 82,1% | — |
| CVE-2022-44690 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 82,1% | — |
| CVE-2003-0812 | HIGH 7.5 | microsoft windows_2000 Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the | 82,1% | — |
| CVE-2023-21707 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 82,0% | — |
| CVE-2018-0886 | HIGH 7.0 | microsoft windows_10 The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, | 82,0% | — |
| CVE-2009-2526 | HIGH 7.8 | microsoft windows_server_2008 Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka | 81,9% | — |
| CVE-2015-6128 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability." | 81,9% | — |
| CVE-2004-0597 | HIGH 10.0 | greg_roelofs libpng Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk | 81,9% | — |
| CVE-2010-3971 | HIGH 9.3 | microsoft internet_explorer Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a | 81,7% | — |
| CVE-2023-32031 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 81,5% | — |
| CVE-2017-0290 | HIGH 7.8 | microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a | 81,4% | — |
| CVE-2003-0344 | HIGH 7.5 | microsoft ie Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page. | 81,3% | — |
| CVE-2003-0719 | HIGH 7.5 | microsoft netmeeting Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attac | 81,2% | — |
| CVE-2025-21298 | CRIT 9.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 80,9% | — |
| CVE-2018-0758 | HIGH 7.5 | microsoft chakracore Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti | 80,8% | — |
| CVE-2010-0805 | HIGH 9.3 | microsoft internet_explorer The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl:: | 80,5% | — |
| CVE-2022-34715 | CRIT 9.8 | microsoft windows_server_2022 Windows Network File System Remote Code Execution Vulnerability | 80,4% | — |
| CVE-2004-0230 | MED 5.0 | juniper junos TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-li | 80,3% | — |
| CVE-2003-0349 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large P | 80,3% | — |
| CVE-2019-0567 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique | 80,1% | — |
| CVE-2004-0790 | MED 5.0 | microsoft windows_2000 Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLI | 80,1% | — |
| CVE-2000-0246 | MED 5.0 | microsoft commercial_internet_system IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | 80,0% | — |
| CVE-2004-1080 | HIGH 10.0 | microsoft windows_2000 The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication | 79,8% | — |
| CVE-2006-4777 | HIGH 7.6 | microsoft ie Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unkn | 79,8% | — |
| CVE-2006-5614 | LOW 2.6 | microsoft windows_nt_helper_components Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereferen | 79,6% | — |