imPC@ndo EN

Vulnerabilità Microsoft

15.453 CVE

CVE-2026-20872
Media 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 10
0.20EPSS
CVE-2015-6159
Alta 9.3

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.20EPSS
CVE-2015-6151
Alta 9.3

Microsoft Internet Explorer 8 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.20EPSS
CVE-2015-6148
Alta 9.3

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft internet_explorer
0.20EPSS
CVE-2018-8502
Alta 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microso…

microsoft excel · microsoft office · microsoft office_365_proplus
0.20EPSS
CVE-2018-8173
Alta 7.8

A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in memory, aka "Microsoft InfoPath Remote Code Execution Vulnerability." This affects Microsoft Infopath.

microsoft infopath
0.20EPSS
CVE-2001-0945
Media 5.0

Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.

microsoft outlook_express
0.20EPSS
CVE-2019-0593
Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0605, CVE-2…

microsoft chakracore · microsoft edge
0.20EPSS
CVE-2011-1890
Media 4.3

Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."

microsoft sharepoint_foundation · microsoft sharepoint_server
0.20EPSS
CVE-2017-8691
Alta 8.8

Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow an attacker to execute code remotely on a target system when the Windows font library fails to properly handle specially crafted embedded fonts, aka "Express Compressed Fonts Remote Code Execution Vul…

microsoft windows_7 · microsoft windows_server_2008
0.20EPSS
CVE-2017-11940
Alta 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange S…

microsoft malware_protection_engine
0.20EPSS
CVE-2015-6161
Media 4.3

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."

microsoft internet_explorer
0.20EPSS
CVE-2001-0909
Alta 7.5

Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL.

microsoft windows_xp
0.20EPSS
CVE-2018-0845
Alta 7.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.20EPSS
CVE-2001-1088
Alta 7.5

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow a…

microsoft outlook · microsoft outlook_express
0.20EPSS
CVE-2016-0182
Alta 7.8

Windows Journal in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal (aka .jnt) file, aka "Windows Journal Memory Corruption Vulnerabili…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 1
0.20EPSS
CVE-2006-4685
Bassa 2.6

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.

microsoft xml_core_services · microsoft xml_parser
0.20EPSS
CVE-2014-4068
Media 5.0

The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, which allows remote attackers to cause a denial of service (daemon hang) via a crafted call, aka "Lync Denial of Se…

microsoft lync_server
0.20EPSS
CVE-2008-1441
Media 5.4

Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "…

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.20EPSS
CVE-2015-1755
Alta 9.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-17…

microsoft internet_explorer
0.20EPSS
CVE-2007-4041
Media 6.8

Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar…

microsoft internet_explorer · mozilla firefox
0.20EPSS
CVE-2016-7245
Alta 7.8

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, and Office 2016 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.20EPSS
CVE-2016-7235
Alta 7.8

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability.…

microsoft excel_for_mac · microsoft office · microsoft office_compatibility_pack · microsoft word · e altri 1
0.20EPSS
CVE-2016-3284
Alta 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka…

microsoft excel · microsoft excel_for_mac · microsoft excel_rt · microsoft excel_viewer · e altri 1
0.20EPSS
CVE-2016-3283
Alta 7.8

Microsoft Word Viewer allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft word_viewer
0.20EPSS