imPC@ndo EN

Vulnerabilità Microsoft

15.313 CVE

CVE-2015-0015
Alta 7.8

Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Netw…

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_server_2012
0.79EPSS
CVE-2006-0027
Alta 7.5

Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.

microsoft exchange_server
0.79EPSS
CVE-2000-0302
Media 5.0

Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.

microsoft index_server
0.79EPSS
CVE-2022-34721
Critica 9.8

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.79EPSS
CVE-2017-0070
Alta 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.79EPSS
CVE-2009-0077
Media 5.0

The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of…

microsoft forefront_threat_management_gateway · microsoft internet_security_and_acceleration_server
0.78EPSS
CVE-2023-38545
Critica 9.8

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host na…

fedoraproject fedora · haxx libcurl · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 9
0.78EPSS
CVE-2018-0777
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.78EPSS
CVE-2018-0776
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.78EPSS
CVE-2018-0770
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.78EPSS
CVE-2010-0022
Alta 7.8

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servern…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · e altri 2
0.78EPSS
CVE-2008-3466
Alta 10.0

Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call …

microsoft host_integration_server_2000 · microsoft host_integration_server_2004 · microsoft host_integration_server_2006
0.78EPSS
CVE-2019-1358
Alta 7.8

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.78EPSS
CVE-2002-1123
Alta 7.5

Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.

microsoft data_engine · microsoft sql_server
0.78EPSS
CVE-2007-1748
Alta 10.0

Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing char…

microsoft windows_2000 · microsoft windows_2003_server
0.78EPSS
CVE-2017-0290
Alta 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft forefront_security · microsoft malware_protection_engine · microsoft windows_defender
0.77EPSS
CVE-1999-1011
Alta 10.0

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

microsoft data_access_components · microsoft index_server · microsoft internet_information_server · microsoft site_server
0.77EPSS
CVE-2023-36899
Alta 8.8

ASP.NET Elevation of Privilege Vulnerability

microsoft .net_framework
0.77EPSS
CVE-2016-3236
Critica 9.8

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.77EPSS
CVE-2000-0649
Bassa 2.6

IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

microsoft internet_information_server · microsoft internet_information_services
0.77EPSS
CVE-2022-26937
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · e altri 2
0.77EPSS
CVE-2022-38053
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.76EPSS
CVE-2003-0714
Alta 7.5

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer ove…

microsoft exchange_server
0.76EPSS
CVE-2007-0042
Alta 7.8

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that t…

microsoft .net_framework
0.76EPSS
CVE-2006-5745
Alta 7.6

Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments th…

microsoft xml_core_services
0.76EPSS