imPC@ndo EN

Vulnerabilità Microsoft

15.442 CVE

CVE-2010-2573
Alta 9.3

Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulner…

microsoft office · microsoft powerpoint · microsoft powerpoint_viewer
0.21EPSS
CVE-2013-1296
Alta 9.3

The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a web page that triggers access to a deleted obj…

microsoft remote_desktop_connection
0.21EPSS
CVE-2016-0050
Media 5.3

Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Pol…

microsoft windows_server_2008 · microsoft windows_server_2012
0.21EPSS
CVE-2000-0105
Media 5.0

Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

microsoft outlook_express
0.21EPSS
CVE-2006-3729
Bassa 2.6

DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, which le…

microsoft internet_explorer
0.21EPSS
CVE-2009-1544
Alta 8.8

Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC messag…

microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.21EPSS
CVE-2013-1312
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2013-1310
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2013-1307
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerabili…

microsoft internet_explorer
0.21EPSS
CVE-2013-0811
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerabili…

microsoft internet_explorer
0.21EPSS
CVE-1999-1581
Media 5.0

Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that …

microsoft windows_nt
0.21EPSS
CVE-2019-1127
Alta 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.21EPSS
CVE-2013-1337
Alta 7.5

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by …

microsoft .net_framework
0.21EPSS
CVE-2000-0983
Media 5.0

Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.

microsoft netmeeting
0.21EPSS
CVE-2010-2747
Alta 9.3

Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uniniti…

microsoft office · microsoft word
0.21EPSS
CVE-2017-8511
Alta 7.8

A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8512, CVE-2017-02…

microsoft office · microsoft office_online_server · microsoft office_web_apps · microsoft office_web_apps_server · e altri 2
0.21EPSS
CVE-2016-7234
Alta 7.8

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Excel for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on S…

microsoft excel_for_mac · microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · e altri 3
0.21EPSS
CVE-2016-0134
Alta 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office W…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps_server · microsoft sharepoint_server · e altri 3
0.21EPSS
CVE-2015-6097
Alta 9.3

Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted Journal (.jnt) file, aka "Windows Journal Heap Overflow Vulnerab…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.21EPSS
CVE-2013-3171
Alta 9.3

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application…

microsoft .net_framework
0.21EPSS
CVE-2013-3133
Alta 9.3

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Fra…

microsoft .net_framework
0.21EPSS
CVE-2018-0793
Alta 7.8

Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0791.

microsoft office · microsoft office_compatibility_pack · microsoft word
0.21EPSS
CVE-2018-0791
Alta 7.8

Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is un…

microsoft office · microsoft outlook
0.21EPSS
CVE-2015-6094
Alta 9.3

Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Off…

microsoft excel · microsoft excel_for_mac · microsoft sharepoint_server
0.21EPSS
CVE-2016-0047
Alta 7.5

WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."

microsoft .net_framework
0.21EPSS