imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2015-4000
Bassa 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi…

apple iphone_os · apple mac_os_x · apple safari · canonical ubuntu_linux · e altri 21
1.00EPSS
CVE-2012-1459
Media 4.3

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4,…

ahnlab v3_internet_security · alwil avast_antivirus · anti-virus vba32 · antiy avl_sdk · e altri 30
1.00EPSS
CVE-2012-1443
Media 4.3

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner…

ahnlab v3_internet_security · aladdin esafe · alwil avast_antivirus · anti-virus vba32 · e altri 31
1.00EPSS
CVE-2003-0352
Alta 7.5

Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.98EPSS
CVE-2012-1457
Media 4.3

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-…

aladdin esafe · alwil avast_antivirus · anti-virus vba32 · antiy avl_sdk · e altri 24
0.98EPSS
CVE-2009-1122
Alta 7.5

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 Web…

microsoft internet_information_services
0.98EPSS
CVE-2009-1535
Alta 7.5

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position …

microsoft internet_information_services
0.98EPSS
CVE-2012-1453
Media 4.3

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust V…

antiy avl_sdk · ca etrust_vet_antivirus · drweb dr.web_antivirus · emsisoft anti-malware · e altri 10
0.98EPSS
CVE-2012-1420
Media 4.3

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essen…

authentium command_antivirus · cat quick_heal · eset nod32_antivirus · f-prot f-prot_antivirus · e altri 7
0.97EPSS
CVE-2015-0014
Alta 10.0

Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2003 · e altri 3
0.97EPSS
CVE-2001-0500
Alta 10.0

Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.id…

microsoft index_server · microsoft indexing_service · microsoft internet_information_server
0.97EPSS
CVE-2014-6321
Alta 10.0

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via craf…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.96EPSS
CVE-2013-3182
Alta 7.8

The Windows NAT Driver (aka winnat) service in Microsoft Windows Server 2012 does not properly validate memory addresses during the processing of ICMP packets, which allows remote attackers to cause a denial of service (memory corruption and system hang) via c…

microsoft windows_server_2012
0.96EPSS
CVE-1999-0016
Media 5.0

Land IP denial of service.

cisco ios · gnu inet · hp hp-ux · microsoft windows_95 · e altri 4
0.96EPSS
CVE-2023-21554
Critica 9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · e altri 8
0.95EPSS
CVE-2023-24941
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022
0.95EPSS
CVE-2010-3972
Alta 10.0

Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of ser…

microsoft internet_information_services
0.95EPSS
CVE-2010-3964
Alta 7.5

Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted …

microsoft sharepoint_server
0.94EPSS
CVE-2021-41349
Media 6.5

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.94EPSS
CVE-2023-28302
Alta 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · e altri 8
0.94EPSS
CVE-2005-1983
Alta 10.0

Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as e…

microsoft windows_2000 · microsoft windows_xp
0.93EPSS
CVE-2023-35628
Alta 8.1

Windows MSHTML Platform Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.93EPSS
CVE-2022-21907
Critica 9.8

HTTP Protocol Stack Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_server · microsoft windows_server_2019
0.93EPSS
CVE-2023-21758
Alta 7.5

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_server_2016 · microsoft windows_server_2019 · e altri 1
0.93EPSS
CVE-2009-3023
Alta 9.0

Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS F…

microsoft internet_information_server
0.91EPSS