56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.463 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2006-5758 | HIGH 7.2 | microsoft windows_2000 The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, wh | 6,4% | — |
| CVE-2018-1021 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8123. | 6,4% | — |
| CVE-2025-53143 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6,4% | — |
| CVE-2006-4066 | LOW 2.6 | microsoft windows_xp The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file | 6,4% | — |
| CVE-2019-1449 | CRIT 9.8 | microsoft office A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM. | 6,4% | — |
| CVE-2021-38655 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 6,4% | — |
| CVE-2012-1872 | MED 6.1 | microsoft internet_explorer Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability." | 6,4% | — |
| CVE-2013-0013 | MED 5.8 | microsoft windows_7 The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to c | 6,4% | — |
| CVE-2018-8579 | MED 6.5 | microsoft office An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. | 6,3% | — |
| CVE-2018-1025 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge. | 6,3% | — |
| CVE-2020-36327 | HIGH 8.8 | bundler bundler Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a d | 6,3% | — |
| CVE-2021-38659 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 6,3% | — |
| CVE-2021-38658 | HIGH 7.8 | microsoft office Microsoft Office Graphics Remote Code Execution Vulnerability | 6,3% | — |
| CVE-2021-38654 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6,3% | — |
| CVE-2021-38653 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6,3% | — |
| CVE-2021-27063 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 6,3% | — |
| CVE-2022-30160 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 6,3% | — |
| CVE-2020-0882 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 | 6,3% | — |
| CVE-2020-0880 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 | 6,3% | — |
| CVE-2009-0243 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) c | 6,3% | — |
| CVE-1999-1087 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthori | 6,3% | — |
| CVE-1999-0582 | MED 5.0 | microsoft windows_2000 A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | 6,3% | — |
| CVE-2017-11939 | MED 6.5 | microsoft office Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability". | 6,3% | — |
| CVE-2018-8422 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CV | 6,3% | — |
| CVE-2000-0439 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. | 6,3% | — |