imPC@ndo EN

Vulnerabilità Microsoft

15.274 CVE

CVE-2022-26809
Critica 9.8

Remote Procedure Call Runtime Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.91EPSS
CVE-2001-0333
Alta 7.5

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

microsoft internet_information_server
0.91EPSS
CVE-2000-0402
Bassa 2.1

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

microsoft sql_server
0.91EPSS
CVE-2006-2372
Alta 10.0

Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

microsoft dhcp_client_service
0.90EPSS
CVE-2009-3103
Alta 10.0

Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v…

microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2020-17132
Critica 9.1

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.90EPSS
CVE-2017-0004
Alta 7.5

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2023-21547
Alta 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 5
0.89EPSS
CVE-2022-30216
Alta 8.8

Windows Server Service Tampering Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_server_2016 · microsoft windows_server_2022
0.89EPSS
CVE-2023-21769
Alta 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · e altri 8
0.89EPSS
CVE-2024-26256
Alta 7.8

Libarchive Remote Code Execution Vulnerability

fedoraproject fedora · libarchive libarchive · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 1
0.88EPSS
CVE-2000-1209
Alta 10.0

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight …

compaq insight_manager · compaq insight_manager_xe · microsoft data_engine · microsoft msde
0.87EPSS
CVE-2008-5416
Alta 9.0

Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and…

microsoft sql_server
0.87EPSS
CVE-2005-4360
Alta 7.8

The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to prod…

microsoft internet_information_services
0.87EPSS
CVE-2023-36035
Alta 8.0

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.87EPSS
CVE-2003-0718
Media 5.0

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l…

microsoft internet_information_server · microsoft internet_information_services
0.87EPSS
CVE-2005-4560
Alta 7.5

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and…

microsoft windows_2003_server · microsoft windows_xp
0.86EPSS
CVE-2000-0778
Media 5.0

IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.

microsoft internet_information_services
0.86EPSS
CVE-2010-0483
Alta 7.6

vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC sha…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.86EPSS
CVE-2012-0152
Media 4.3

The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service …

microsoft windows_7 · microsoft windows_server_2008
0.86EPSS
CVE-2022-37958
Alta 8.1

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 5
0.86EPSS
CVE-2001-0241
Alta 10.0

Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

microsoft windows_2000
0.86EPSS
CVE-2003-0109
Alta 7.5

Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.

microsoft windows_2000 · microsoft windows_2000_terminal_services
0.86EPSS
CVE-2003-0533
Alta 7.5

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows M…

microsoft netmeeting · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · e altri 3
0.86EPSS
CVE-2009-0075
Alta 9.3

Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, ak…

microsoft internet_explorer
0.85EPSS