EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.454 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-21120 HIGH 8.8 google chrome Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 6,9%
CVE-2005-1792 MED 5.0 microsoft windows_xp Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache. 6,9%
CVE-2020-1284 MED 6.5 microsoft windows_10 A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Denial of Service Vulnerability'. 6,9%
CVE-2016-0075 MED 5.5 microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, ak 6,9%
CVE-2015-1636 LOW 3.5 microsoft sharepoint_foundation Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS 6,9%
CVE-2015-1633 LOW 3.5 microsoft sharepoint_foundation Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script 6,9%
CVE-2015-6117 MED 6.1 microsoft sharepoint_foundation Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Secu 6,9%
CVE-2000-0201 MED 5.1 microsoft internet_explorer The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking. 6,8%
CVE-2006-3250 MED 5.1 microsoft windows_live_messenger Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is imported by the user. 6,8%
CVE-2018-8383 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8388. 6,8%
CVE-2005-0110 LOW 2.6 microsoft ie Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated usin 6,8%
CVE-2020-1022 HIGH 8.0 microsoft dynamics_365_business_central A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. 6,8%
CVE-2007-3671 HIGH 7.8 microsoft windows_vista Unspecified vulnerability in the kernel in Microsoft Windows Vista has unspecified remote attack vectors and impact, as shown in the "0day IPO" presentation at SyScan'07. 6,8%
CVE-2023-28274 HIGH 7.8 microsoft windows_10_1809 Windows Win32k Elevation of Privilege Vulnerability 6,8%
CVE-2021-21119 HIGH 8.8 google chrome Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. 6,8%
CVE-2024-26198 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 6,8%
CVE-2002-2189 MED 5.1 activxperts_software activwebserver Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link. 6,8%
CVE-2000-0226 MED 5.0 microsoft internet_information_server IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." 6,8%
CVE-2006-4732 HIGH 10.0 microsoft visual_basic Unspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event procedure, as demonstrated using the msgbox function and the VB.Label object. 6,8%
CVE-2022-21893 HIGH 8.0 microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability 6,8%
CVE-2023-35388 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 6,8%
CVE-2004-1922 LOW 2.6 microsoft internet_explorer Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large 6,8%
CVE-2019-1099 MED 6.5 microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2 6,8%
CVE-2019-0559 MED 6.5 microsoft office An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. 6,8%
CVE-2016-0137 LOW 3.3 microsoft office The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass." 6,8%