58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2007-0214 | HIGH 9.3 | microsoft windows_2000 The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters. | 26,6% | — |
| CVE-2020-17103 | HIGH 7.0 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 26,5% | — |
| CVE-2011-0979 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows | 26,5% | — |
| CVE-2010-0018 | HIGH 9.3 | microsoft windows_2000 Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attac | 26,5% | — |
| CVE-2023-21689 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 26,5% | — |
| CVE-2004-0117 | HIGH 7.5 | microsoft netmeeting Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code. | 26,5% | — |
| CVE-2014-4061 | MED 6.8 | microsoft sql_server Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka | 26,5% | — |
| CVE-2003-0531 | HIGH 7.5 | microsoft ie Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Z | 26,5% | — |
| CVE-2006-6311 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript. | 26,5% | — |
| CVE-2009-2523 | HIGH 10.0 | microsoft windows_2000 The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW met | 26,5% | — |
| CVE-2009-1135 | HIGH 9.0 | microsoft isa_server Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, vi | 26,5% | — |
| CVE-1999-0918 | HIGH 7.8 | microsoft windows_2000 Denial of service in various Windows systems via malformed, fragmented IGMP packets. | 26,4% | — |
| CVE-2000-0710 | MED 5.0 | microsoft frontpage The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. | 26,4% | — |
| CVE-2011-3412 | HIGH 9.3 | microsoft publisher Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability." | 26,4% | — |
| CVE-2017-0134 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in | 26,4% | — |
| CVE-2017-0015 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in | 26,4% | — |
| CVE-2011-0980 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Ex | 26,4% | — |
| CVE-2003-0820 | HIGH 7.5 | microsoft word Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. | 26,3% | — |
| CVE-2008-1544 | HIGH 7.1 | microsoft internet_explorer The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) cond | 26,3% | — |
| CVE-2017-0031 | HIGH 7.8 | microsoft office Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnera | 26,3% | — |
| CVE-2004-0202 | MED 5.0 | microsoft directx IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet. | 26,3% | — |
| CVE-2016-3282 | HIGH 7.8 | microsoft office Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Servi | 26,3% | — |
| CVE-2004-0197 | HIGH 7.5 | microsoft jet Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query. | 26,3% | — |
| CVE-2009-3674 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized M | 26,3% | — |
| CVE-2006-3591 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference. | 26,2% | — |