58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-0100 | HIGH 8.4 | microsoft windows_server_2008 Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability." | 57,2% | — |
| CVE-2008-0075 | HIGH 10.0 | microsoft internet_information_server Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages. | 57,2% | — |
| CVE-2023-36744 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 57,1% | — |
| CVE-2008-1083 | HIGH 8.1 | microsoft windows_2000 Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed hea | 57,1% | — |
| CVE-2016-3222 | HIGH 8.8 | microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." | 56,8% | — |
| CVE-2023-36041 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 56,7% | — |
| CVE-2002-0072 | MED 5.0 | microsoft internet_information_server The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service | 56,6% | — |
| CVE-2004-0842 | HIGH 7.5 | avaya definity_one_media_server Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer over | 56,6% | — |
| CVE-2008-1087 | HIGH 9.3 | microsoft windows-nt Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerab | 56,6% | — |
| CVE-2006-3086 | HIGH 9.3 | microsoft hyperlink_object_library Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrat | 56,5% | — |
| CVE-2002-0073 | MED 5.0 | microsoft internet_information_server The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters. | 56,4% | — |
| CVE-2022-23253 | MED 6.5 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 56,4% | — |
| CVE-2022-38044 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM File System Driver Remote Code Execution Vulnerability | 56,3% | — |
| CVE-2024-30043 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 56,1% | — |
| CVE-2008-3704 | HIGH 9.3 | microsoft visual_basic Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 | 55,9% | — |
| CVE-2006-3280 | HIGH 7.5 | microsoft internet_explorer Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Locatio | 55,9% | — |
| CVE-2017-8635 | HIGH 7.5 | microsoft edge Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the | 55,9% | — |
| CVE-2023-21742 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 55,8% | — |
| CVE-2013-0025 | HIGH 9.3 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability." | 55,8% | — |
| CVE-2005-2124 | HIGH 7.6 | microsoft windows_2000 Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Win | 55,7% | — |
| CVE-2025-21285 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 55,7% | — |
| CVE-2018-0935 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting en | 55,6% | — |
| CVE-2006-1388 | HIGH 7.5 | microsoft ie Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. | 55,5% | — |
| CVE-2002-0186 | HIGH 7.5 | microsoft sql_server Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension." | 55,5% | — |
| CVE-2007-2931 | HIGH 9.3 | microsoft msn_messenger Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions. | 55,5% | — |