IT

Microsoft vulnerabilities

15.453 CVE

CVE-2014-2814
Medium 4.0

Microsoft Service Bus 1.1 on Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (AMQP messaging outage) via crafted AMQP messages, aka "Service Bus Denial of Service Vulnerability."

microsoft service_bus
0.18EPSS
CVE-2010-1127
Medium 5.0

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript cod…

microsoft internet_explorer
0.18EPSS
CVE-2012-1873
Medium 4.3

Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."

microsoft internet_explorer
0.18EPSS
CVE-2015-6107
High 9.3

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10 Gold and 1511, Office 2007 SP3, Office 2010 SP2, Word Viewe…

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 10 more
0.18EPSS
CVE-2006-0376
High 7.5

The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode e…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.18EPSS
CVE-2006-3660
High 7.6

Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, an…

microsoft powerpoint
0.18EPSS
CVE-2010-2563
High 9.3

The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document …

microsoft windows_server_2003 · microsoft windows_xp
0.18EPSS
CVE-2017-8509
High 8.8

A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-02…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_web_apps_server · and 4 more
0.18EPSS
CVE-2015-2505
Medium 5.0

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability."

microsoft exchange_server
0.18EPSS
CVE-2002-0052
Medium 5.0

Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.

microsoft internet_explorer
0.18EPSS
CVE-2014-1811
Medium 5.0

The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 4 more
0.18EPSS
CVE-2007-1763
High 7.1

The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.

microsoft windows_vista
0.18EPSS
CVE-1999-0385
High 10.0

The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

microsoft exchange_server
0.18EPSS
CVE-1999-0012
High 7.0

Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.

microsoft frontpage · microsoft internet_information_server · microsoft personal_web_server · netscape enterprise_server · and 1 more
0.18EPSS
CVE-2001-0664
High 7.5

Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, ak…

microsoft internet_explorer
0.18EPSS
CVE-2020-17096
High 7.5

Windows NTFS Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 2 more
0.18EPSS
CVE-2015-0005
Medium 4.3

The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2, when a Domain Controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and o…

microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_server_2012
0.18EPSS
CVE-2019-1373
Critical 9.8

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

microsoft exchange_server
0.18EPSS
CVE-2018-8376
High 8.8

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint.

microsoft powerpoint
0.18EPSS
CVE-2017-0196
Medium 6.5

An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

microsoft edge
0.18EPSS
CVE-1999-1593
High 7.6

Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may…

microsoft windows_2000 · microsoft windows_95 · microsoft windows_98
0.18EPSS
CVE-1999-1094
High 7.5

Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."

microsoft internet_explorer
0.18EPSS
CVE-2017-0238
High 7.5

A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

microsoft edge · microsoft internet_explorer
0.18EPSS
CVE-2016-0033
High 7.5

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack…

microsoft .net_framework
0.18EPSS
CVE-2015-2493
High 9.3

The (1) VBScript and (2) JScript engines in Microsoft Internet Explorer 8 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

microsoft internet_explorer
0.18EPSS