imPC@ndo EN

Vulnerabilità Microsoft

15.313 CVE

CVE-2010-3971
Alta 9.3

Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a…

microsoft internet_explorer
0.82EPSS
CVE-2023-32031
Alta 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.81EPSS
CVE-2003-0344
Alta 7.5

Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.

microsoft ie · microsoft internet_explorer
0.81EPSS
CVE-2003-0822
Alta 7.5

Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.

microsoft frontpage_server_extensions · microsoft sharepoint_team_services · microsoft windows_2000 · microsoft windows_xp
0.81EPSS
CVE-2023-36777
Media 5.7

Microsoft Exchange Server Information Disclosure Vulnerability

microsoft exchange_server
0.81EPSS
CVE-2003-0719
Alta 7.5

Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attac…

microsoft netmeeting · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · e altri 3
0.81EPSS
CVE-2023-36745
Alta 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.81EPSS
CVE-2003-0812
Alta 7.5

Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the…

microsoft windows_2000 · microsoft windows_xp
0.81EPSS
CVE-2025-21298
Critica 9.8

Windows OLE Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.81EPSS
CVE-2018-0758
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.81EPSS
CVE-2010-0805
Alta 9.3

The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_xp
0.81EPSS
CVE-2013-3183
Alta 7.8

The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly perform memory allocation for inbound ICMPv6 packets, which allows remote attackers to…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2008 · e altri 2
0.80EPSS
CVE-2022-34715
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server_2022
0.80EPSS
CVE-2004-0230
Media 5.0

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-li…

juniper junos · mcafee network_data_loss_prevention · microsoft windows_2000 · microsoft windows_98 · e altri 8
0.80EPSS
CVE-2003-0349
Alta 7.5

Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large P…

microsoft windows_2000
0.80EPSS
CVE-2004-0790
Media 5.0

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLI…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 4
0.80EPSS
CVE-2019-0567
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.80EPSS
CVE-2022-21972
Alta 8.1

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 7
0.80EPSS
CVE-2004-1080
Alta 10.0

The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt
0.80EPSS
CVE-2006-4777
Alta 7.6

Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unkn…

microsoft ie
0.80EPSS
CVE-2026-41089
Critica 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · e altri 2
0.80EPSS
CVE-2006-5614
Bassa 2.6

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereferen…

microsoft windows_nt_helper_components · microsoft windows_xp
0.79EPSS
CVE-2018-0769
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.79EPSS
CVE-2006-4691
Alta 10.0

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

microsoft windows_2000 · microsoft windows_xp
0.79EPSS
CVE-2000-0246
Media 5.0

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

microsoft commercial_internet_system · microsoft internet_information_server · microsoft internet_information_services · microsoft proxy_server · e altri 2
0.79EPSS