EN

Vulnerabilità Microsoft

15.453 CVE

CVE-2017-8535
Media 5.5

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft endpoint_protection · microsoft exchange_server · microsoft forefront_endpoint_protection · microsoft security_essentials · e altri 3
0.17EPSS
CVE-2022-22005
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.17EPSS
CVE-2015-6158
Alta 9.3

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2015-6155
Alta 9.3

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2015-6154
Alta 9.3

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2015-6153
Alta 9.3

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2015-6140
Alta 9.3

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2013-0022
Critica 9.0

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."

microsoft internet_explorer
0.17EPSS
CVE-2000-0544
Media 5.0

Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.

microsoft windows_2000 · microsoft windows_nt
0.17EPSS
CVE-2002-1795
Media 4.3

Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

microsoft tsac_activex_control
0.17EPSS
CVE-1999-0224
Media 5.0

Denial of service in Windows NT messenger service through a long username.

microsoft windows_nt
0.17EPSS
CVE-2013-1297
Media 4.3

Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."

microsoft internet_explorer
0.17EPSS
CVE-2007-0356
Media 5.0

The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.

common_controls_replacement_project foldertreeview_activex_control · microsoft ie
0.17EPSS
CVE-2011-1893
Media 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vul…

microsoft sharepoint_foundation · microsoft sharepoint_server · microsoft sharepoint_services
0.17EPSS
CVE-2011-1891
Media 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Con…

microsoft sharepoint_foundation · microsoft sharepoint_services
0.17EPSS
CVE-2016-0102
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2021-21118
Alta 8.8

Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

google chrome · microsoft edge_chromium
0.17EPSS
CVE-2004-0284
Media 5.0

Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) a…

microsoft ie · microsoft internet_explorer · microsoft outlook
0.17EPSS
CVE-2016-0109
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2017-0053
Alta 7.8

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, Word 2010 SP2, Word 2013 SP1, Word 2013 R2 SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted …

microsoft office · microsoft office_compatibility_pack · microsoft word · microsoft word_viewer
0.17EPSS
CVE-2014-4133
Alta 9.3

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4137…

microsoft internet_explorer
0.17EPSS
CVE-2011-1245
Media 4.3

Microsoft Internet Explorer 6 and 7 does not properly restrict script access to content from a (1) different domain or (2) different zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Javascript Information Disclos…

microsoft internet_explorer
0.17EPSS
CVE-2009-3020
Alta 7.1

win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly relate…

microsoft windows_server_2003
0.17EPSS
CVE-2016-7296
Alta 7.5

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-72…

microsoft edge
0.17EPSS
CVE-2010-3225
Alta 7.6

Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After Free V…

microsoft windows_7 · microsoft windows_vista
0.17EPSS