58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2008-3014 | HIGH 9.3 | microsoft digital_image_suite Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, Po | 36,7% | — |
| CVE-2003-0111 | HIGH 7.5 | microsoft virtual_machine The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Micro | 36,7% | — |
| CVE-2023-28231 | HIGH 8.8 | microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability | 36,6% | — |
| CVE-2009-0901 | HIGH 8.8 | microsoft visual_c\+\+ The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Go | 36,6% | — |
| CVE-2007-0352 | HIGH 9.3 | microsoft html_help_workshop Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string. | 36,6% | — |
| CVE-2007-3490 | HIGH 7.5 | microsoft excel Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls. | 36,6% | — |
| CVE-2017-0084 | HIGH 8.8 | microsoft windows_10 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary cod | 36,5% | — |
| CVE-2003-0824 | MED 5.0 | microsoft frontpage_server_extensions Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request. | 36,5% | — |
| CVE-2015-2461 | HIGH 9.3 | microsoft windows_10 ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to e | 36,4% | — |
| CVE-2016-3259 | HIGH 8.8 | microsoft edge The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corrupt | 36,4% | — |
| CVE-2006-5581 | HIGH 9.3 | microsoft internet_explorer Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script Function Me | 36,3% | — |
| CVE-2024-43464 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 36,3% | — |
| CVE-2022-37974 | MED 6.5 | microsoft windows_10 Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | 36,3% | — |
| CVE-2008-1457 | HIGH 9.0 | microsoft windows-nt The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted even | 36,3% | — |
| CVE-2021-28481 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 36,2% | — |
| CVE-2007-3895 | HIGH 9.3 | microsoft directx Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file. | 36,2% | — |
| CVE-2019-1311 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | 36,2% | — |
| CVE-2007-2581 | MED 4.3 | microsoft sharepoint_server Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every | 36,2% | — |
| CVE-2007-2884 | HIGH 9.3 | microsoft visual_basic Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Nam | 36,2% | — |
| CVE-2003-0231 | MED 5.0 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe. | 36,2% | — |
| CVE-2016-3321 | LOW 2.5 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explo | 36,1% | — |
| CVE-2002-1182 | MED 5.0 | microsoft internet_information_services IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned. | 36,1% | — |
| CVE-2007-0064 | HIGH 9.3 | microsoft windows_media_format_runtime Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Adv | 36,0% | — |
| CVE-2009-1131 | HIGH 9.3 | microsoft office_powerpoint Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of B | 35,9% | — |
| CVE-2006-5162 | MED 5.0 | microsoft internet_explorer wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow. | 35,9% | — |