58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-11839 | HIGH 7.5 | microsoft edge Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Co | 62,4% | — |
| CVE-2006-4446 | MED 5.0 | microsoft ie Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument s | 62,2% | — |
| CVE-2009-2532 | HIGH 10.0 | microsoft windows_server_2008 Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SM | 62,2% | — |
| CVE-2021-27084 | HIGH 7.8 | microsoft maven_for_java Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability | 62,1% | — |
| CVE-2018-8384 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-82 | 62,1% | — |
| CVE-2021-28325 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 62,1% | — |
| CVE-2009-1136 | HIGH 9.3 | microsoft isa_server The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Offic | 62,0% | — |
| CVE-2010-1892 | HIGH 7.8 | microsoft windows_7 The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets | 62,0% | — |
| CVE-2005-2120 | MED 6.5 | microsoft windows_2000 Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a regi | 62,0% | — |
| CVE-2006-3441 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are | 62,0% | — |
| CVE-2008-0086 | HIGH 9.0 | microsoft data_engine Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression. | 61,9% | — |
| CVE-2021-27083 | HIGH 7.8 | microsoft remote_development Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | 61,9% | — |
| CVE-2006-1245 | HIGH 7.5 | microsoft ie Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstr | 61,8% | — |
| CVE-2002-0147 | HIGH 7.5 | microsoft internet_information_server Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun." | 61,8% | — |
| CVE-2021-28472 | HIGH 7.8 | microsoft vscode-maven Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability | 61,8% | — |
| CVE-2006-1189 | HIGH 10.0 | microsoft internet_explorer Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Pars | 61,7% | — |
| CVE-2012-1875 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability." | 61,7% | — |
| CVE-2006-1190 | HIGH 10.0 | microsoft internet_explorer Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote | 61,6% | — |
| CVE-2005-2123 | HIGH 7.5 | microsoft windows_2000 Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that | 61,5% | — |
| CVE-2006-4868 | HIGH 9.3 | microsoft internet_explorer Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language | 61,4% | — |
| CVE-2005-2087 | MED 5.0 | microsoft ie Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs | 61,4% | — |
| CVE-2010-0239 | HIGH 10.0 | microsoft windows_server_2008 The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary cod | 61,3% | — |
| CVE-2006-1314 | HIGH 7.5 | microsoft windows_2000 Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that trigger | 61,2% | — |
| CVE-2021-26424 | CRIT 9.9 | microsoft windows_10 Windows TCP/IP Remote Code Execution Vulnerability | 61,1% | — |
| CVE-2004-0549 | HIGH 10.0 | microsoft internet_explorer The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the locat | 61,1% | — |