EN
56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.463 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2006-5758 HIGH 7.2 microsoft windows_2000 The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, wh 6,4%
CVE-2018-1021 MED 4.3 microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8123. 6,4%
CVE-2025-53143 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,4%
CVE-2006-4066 LOW 2.6 microsoft windows_xp The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file 6,4%
CVE-2019-1449 CRIT 9.8 microsoft office A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM. 6,4%
CVE-2021-38655 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 6,4%
CVE-2012-1872 MED 6.1 microsoft internet_explorer Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability." 6,4%
CVE-2013-0013 MED 5.8 microsoft windows_7 The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to c 6,4%
CVE-2018-8579 MED 6.5 microsoft office An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. 6,3%
CVE-2018-1025 MED 4.3 microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge. 6,3%
CVE-2020-36327 HIGH 8.8 bundler bundler Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a d 6,3%
CVE-2021-38659 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 6,3%
CVE-2021-38658 HIGH 7.8 microsoft office Microsoft Office Graphics Remote Code Execution Vulnerability 6,3%
CVE-2021-38654 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 6,3%
CVE-2021-38653 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 6,3%
CVE-2021-27063 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 6,3%
CVE-2022-30160 HIGH 7.8 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 6,3%
CVE-2020-0882 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 6,3%
CVE-2020-0880 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 6,3%
CVE-2009-0243 HIGH 7.2 microsoft windows_2000 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) c 6,3%
CVE-1999-1087 HIGH 7.5 microsoft internet_explorer Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthori 6,3%
CVE-1999-0582 MED 5.0 microsoft windows_2000 A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. 6,3%
CVE-2017-11939 MED 6.5 microsoft office Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability". 6,3%
CVE-2018-8422 MED 6.5 microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CV 6,3%
CVE-2000-0439 LOW 2.6 microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. 6,3%