imPC@ndo EN

Vulnerabilità Microsoft

15.347 CVE

CVE-2002-1142
Alta 7.5

Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.

microsoft data_access_components · microsoft ie · microsoft internet_explorer
0.76EPSS
CVE-2019-1439
Media 6.5

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.76EPSS
CVE-2019-1181
Critica 9.8

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authenticat…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.76EPSS
CVE-2010-2550
Alta 10.0

The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.76EPSS
CVE-2004-0847
Critica 9.8

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vuln…

microsoft asp.net
0.76EPSS
CVE-2007-0940
Alta 9.3

Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CA…

microsoft biztalk_server · microsoft capicom
0.76EPSS
CVE-2010-2729
Alta 9.3

The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, whi…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.76EPSS
CVE-2010-1885
Alta 9.3

The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP o…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.75EPSS
CVE-2024-38077
Critica 9.8

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · e altri 2
0.75EPSS
CVE-2006-3942
Alta 7.8

The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.75EPSS
CVE-2006-4688
Alta 7.5

Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.75EPSS
CVE-2020-0609
Critica 9.8

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote C…

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.75EPSS
CVE-2022-30136
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.75EPSS
CVE-2023-36756
Alta 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.75EPSS
CVE-2004-0206
Alta 7.5

Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application th…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_nt · e altri 1
0.75EPSS
CVE-1999-0874
Alta 10.0

Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.

microsoft internet_information_server · microsoft windows_2000 · microsoft windows_nt
0.75EPSS
CVE-2000-1089
Alta 10.0

Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.

microsoft windows_2000 · microsoft windows_nt
0.75EPSS
CVE-2012-0002
Alta 9.3

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remo…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.74EPSS
CVE-2013-0081
Media 5.0

Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoi…

microsoft sharepoint_foundation · microsoft sharepoint_portal_server · microsoft sharepoint_server · microsoft sharepoint_services
0.74EPSS
CVE-2007-2897
Alta 7.5

Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access…

microsoft internet_information_server
0.74EPSS
CVE-2005-1213
Alta 7.5

Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.

microsoft outlook_express
0.74EPSS
CVE-2005-0059
Alta 10.0

Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.

microsoft windows_2000 · microsoft windows_98 · microsoft windows_98se · microsoft windows_xp
0.74EPSS
CVE-2012-0013
Alta 9.3

Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arb…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.74EPSS
CVE-2019-1234
Alta 7.5

A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.

microsoft azure_stack
0.74EPSS
CVE-2021-31195
Media 6.5

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.74EPSS