imPC@ndo EN

Vulnerabilità Microsoft

15.441 CVE

CVE-2004-0203
Media 4.3

Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.

microsoft exchange_server
0.21EPSS
CVE-2014-0304
Alta 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2008-4256
Alta 8.5

The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to…

microsoft office_frontpage · microsoft project · microsoft visual_basic · microsoft visual_foxpro · e altri 1
0.21EPSS
CVE-2008-4253
Alta 8.5

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote …

microsoft office_frontpage · microsoft project · microsoft visual_basic · microsoft visual_foxpro · e altri 1
0.21EPSS
CVE-2008-4252
Alta 8.5

The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTM…

microsoft office_frontpage · microsoft project · microsoft visual_basic · microsoft visual_foxpro · e altri 1
0.21EPSS
CVE-2013-3847
Alta 9.3

Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cau…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_foundation · microsoft sharepoint_portal_server · e altri 4
0.21EPSS
CVE-2015-6093
Alta 9.3

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute a…

microsoft office · microsoft office_web_apps · microsoft office_web_apps_server · microsoft sharepoint_server
0.21EPSS
CVE-2001-0335
Media 5.0

FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.

microsoft internet_information_server
0.21EPSS
CVE-2001-0322
Media 5.0

MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.

microsoft internet_explorer · microsoft outlook · microsoft outlook_express
0.21EPSS
CVE-2000-0662
Media 5.0

Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

microsoft internet_explorer
0.21EPSS
CVE-2014-1777
Media 4.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2010-0555
Alta 9.3

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.21EPSS
CVE-2013-1335
Alta 9.3

Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."

microsoft word · microsoft word_viewer
0.21EPSS
CVE-2012-1524
Alta 9.3

Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Attribute Remove Remote Code Execution Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2012-1522
Alta 9.3

Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Cached Object Remote Code Execution Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2012-0173
Alta 9.3

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remo…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.21EPSS
CVE-2015-1716
Media 5.0

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict Diffie-Hellman Ephemeral (DHE) …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.21EPSS
CVE-2013-1308
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulner…

microsoft internet_explorer
0.21EPSS
CVE-2014-0294
Alta 10.0

Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitrary code via a crafted message, aka "RCE Vulnerability."

microsoft microsoft_forefront_protection_2010
0.21EPSS
CVE-2006-3655
Media 5.1

Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-…

microsoft powerpoint
0.21EPSS
CVE-2014-4143
Alta 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.21EPSS
CVE-2018-1029
Alta 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft E…

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.21EPSS
CVE-2016-0128
Media 6.8

The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, wh…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.21EPSS
CVE-2013-1317
Alta 9.3

Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."

microsoft publisher
0.21EPSS
CVE-2012-2521
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Asynchronous NULL Object Access Remote Code Execution Vulnerability."

microsoft internet_explorer
0.21EPSS