imPC@ndo EN

Vulnerabilità Microsoft

15.441 CVE

CVE-2016-3271
Media 6.5

The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."

microsoft edge
0.21EPSS
CVE-2015-2408
Alta 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015…

microsoft internet_explorer
0.21EPSS
CVE-2002-0224
Media 5.0

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

microsoft internet_information_services · microsoft sql_server · microsoft windows_2000
0.21EPSS
CVE-2003-0909
Alta 7.2

Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

microsoft windows_xp
0.21EPSS
CVE-2011-2383
Media 4.3

Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that re…

microsoft ie · microsoft internet_explorer
0.21EPSS
CVE-2010-3954
Alta 9.3

Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."

microsoft publisher
0.21EPSS
CVE-2010-3952
Alta 9.3

The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document…

microsoft office · microsoft office_converter_pack
0.21EPSS
CVE-2010-3950
Alta 9.3

The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

microsoft office · microsoft office_converter_pack · microsoft works
0.21EPSS
CVE-1999-1387
Media 5.0

Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

microsoft windows_nt
0.21EPSS
CVE-2015-0093
Alta 9.3

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.21EPSS
CVE-2011-1976
Media 4.3

Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XS…

microsoft report_viewer · microsoft visual_studio
0.21EPSS
CVE-2013-0095
Media 5.0

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and …

microsoft office
0.21EPSS
CVE-2012-1528
Alta 9.3

Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a c…

microsoft windows_7 · microsoft windows_8 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 3
0.21EPSS
CVE-2012-1527
Alta 9.3

Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a …

microsoft windows_7 · microsoft windows_8 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 3
0.21EPSS
CVE-2016-3352
Alta 8.8

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password hashes, aka "Microsof…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1
0.21EPSS
CVE-2006-3471
Media 5.0

Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.

microsoft ie
0.21EPSS
CVE-2013-1329
Alta 9.3

Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."

microsoft publisher
0.21EPSS
CVE-2013-1328
Alta 9.3

Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."

microsoft publisher
0.21EPSS
CVE-2013-1327
Alta 9.3

Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."

microsoft publisher
0.21EPSS
CVE-2013-1323
Alta 9.3

Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."

microsoft publisher
0.21EPSS
CVE-2012-4774
Alta 9.3

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers u…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.21EPSS
CVE-2012-2556
Alta 9.3

The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows re…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · e altri 5
0.21EPSS
CVE-2010-3143
Alta 9.3

Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .contact, .…

microsoft windows
0.21EPSS
CVE-2010-0244
Alta 9.3

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka…

microsoft internet_explorer
0.21EPSS
CVE-2011-3401
Alta 9.3

ENCDEC.DLL in Windows Media Player and Media Center in Microsoft Windows XP SP2 and SP3, Windows Vista SP2, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .dvr-ms file, aka "Windows Media Player DVR-MS Memory Corrupt…

microsoft windows_7 · microsoft windows_vista · microsoft windows_xp
0.21EPSS