imPC@ndo EN

Vulnerabilità Microsoft

15.453 CVE

CVE-2012-1849
Alta 9.3

Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync…

microsoft lync
0.18EPSS
CVE-2016-0195
Alta 8.8

The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.18EPSS
CVE-2015-1767
Alta 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015…

microsoft internet_explorer
0.18EPSS
CVE-2016-7230
Alta 7.8

Microsoft PowerPoint 2010 SP2, PowerPoint Viewer, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office_web_apps · microsoft powerpoint · microsoft powerpoint_viewer
0.18EPSS
CVE-2019-1124
Alta 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.18EPSS
CVE-2008-4110
Alta 7.6

Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL …

microsoft sql_server
0.18EPSS
CVE-2019-0674
Alta 7.8

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0…

microsoft office · microsoft office_365_proplus
0.18EPSS
CVE-2008-4381
Media 5.0

Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.

microsoft internet_explorer
0.18EPSS
CVE-2002-1291
Media 5.0

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.

microsoft java_virtual_machine
0.18EPSS
CVE-2021-27078
Critica 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.18EPSS
CVE-2016-3368
Alta 8.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote authenticated users to execute arbitrary code by leveraging a domain …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.18EPSS
CVE-2016-0188
Alta 8.8

The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing protection mechanism via unspecified vectors, aka "Internet Explorer Security Feature Bypass."

microsoft internet_explorer
0.18EPSS
CVE-2019-1462
Alta 7.8

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

microsoft office · microsoft office_365_proplus · microsoft powerpoint
0.18EPSS
CVE-2006-0031
Media 5.1

Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads t…

microsoft office
0.18EPSS
CVE-2025-49712
Alta 8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
0.18EPSS
CVE-2012-0168
Alta 7.6

Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print operation, aka "Print Feature Remote Code Execution Vulnerabi…

microsoft internet_explorer
0.18EPSS
CVE-2001-0545
Media 5.0

IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.

microsoft internet_information_server
0.18EPSS
CVE-2001-0018
Media 5.0

Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.

microsoft windows_2000
0.18EPSS
CVE-2001-0237
Media 5.0

Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.

microsoft windows_2000
0.18EPSS
CVE-1999-1132
Media 5.0

Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.

microsoft windows_nt
0.18EPSS
CVE-1999-1478
Media 5.0

The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.

microsoft internet_information_server
0.18EPSS
CVE-2011-3396
Alta 9.3

Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."

microsoft powerpoint
0.18EPSS
CVE-1999-0031
Bassa 2.6

JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.

microsoft internet_explorer · netscape communicator
0.18EPSS
CVE-2002-0650
Media 5.0

The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, whic…

microsoft sql_server
0.18EPSS
CVE-2018-0922
Alta 7.8

Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Micr…

microsoft office · microsoft office_compatibility_pack · microsoft office_online_server · microsoft office_web_apps · e altri 4
0.18EPSS