IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-31195 MED 6.5 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 73.7% —
CVE-2008-0084 HIGH 7.8 microsoft windows_vista Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet. 73.6% —
CVE-2007-2815 HIGH 10.0 microsoft internet_information_services The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web 73.4% —
CVE-2011-3389 MED 4.3 canonical ubuntu_linux The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-mi 73.3% —
CVE-2016-7202 HIGH 7.5 microsoft edge The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability 73.3% —
CVE-2005-0059 HIGH 10.0 microsoft windows_2000 Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message. 73.3% —
CVE-2022-30136 CRIT 9.8 microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability 73.2% —
CVE-2023-36039 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 73.0% —
CVE-2007-0038 HIGH 9.3 microsoft windows_2000 Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block 72.9% —
CVE-1999-0256 HIGH 7.5 jgaa warftpd Buffer overflow in War FTP allows remote execution of commands. 72.9% —
CVE-2004-0899 MED 5.0 microsoft windows_nt The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a 72.6% —
CVE-2003-0001 MED 5.0 freebsd freebsd Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak. 72.5% —
CVE-2004-0204 HIGH 7.5 bea weblogic_server Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and oth 72.4% —
CVE-2004-1134 HIGH 10.0 microsoft w3who.dll Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string. 72.3% —
CVE-2017-8740 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit 72.2% —
CVE-2017-8729 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit 72.2% —
CVE-2024-20697 HIGH 7.3 microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability 72.2% —
CVE-2017-8636 HIGH 7.5 microsoft edge Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the 72.1% —
CVE-2016-0117 HIGH 7.8 microsoft windows_10 The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability." 71.9% —
CVE-2024-49112 CRIT 9.8 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 71.9% —
CVE-2009-3672 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method fo 71.8% —
CVE-2010-3973 HIGH 9.3 microsoft wmi_administrative_tools The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possi 71.7% —
CVE-2015-0072 MED 4.3 microsoft internet_explorer Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFR 71.7% —
CVE-2006-0564 HIGH 7.5 microsoft html_help Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file f 71.7% —
CVE-2017-8641 HIGH 7.5 microsoft edge Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the 71.6% —