EN
56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.463 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-43502 HIGH 7.1 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 6,1%
CVE-2000-0415 MED 5.0 microsoft outlook Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. 6,1%
CVE-2019-1030 MED 4.3 microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit th 6,1%
CVE-2001-1219 MED 5.0 microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. 6,0%
CVE-2017-0192 MED 4.3 microsoft windows_10 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gai 6,0%
CVE-2022-24547 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 6,0%
CVE-1999-0179 MED 5.0 microsoft windows_95 Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. 6,0%
CVE-2019-1006 HIGH 7.5 microsoft .net_framework An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. 6,0%
CVE-2014-2781 HIGH 7.6 microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different 6,0%
CVE-1999-0590 HIGH 10.0 apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. 6,0%
CVE-2024-38241 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 6,0%
CVE-2017-8542 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6,0%
CVE-2017-8539 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6,0%
CVE-2016-3232 MED 5.0 microsoft windows_server_2012 The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulne 6,0%
CVE-2021-26700 HIGH 7.8 microsoft npm Visual Studio Code npm-script Extension Remote Code Execution Vulnerability 6,0%
CVE-2017-8659 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability" 6,0%
CVE-1999-0537 HIGH 7.5 microsoft internet_explorer A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. 6,0%
CVE-2021-40486 HIGH 7.8 microsoft office Microsoft Word Remote Code Execution Vulnerability 6,0%
CVE-2025-53145 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,0%
CVE-2025-53144 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,0%
CVE-2003-0301 MED 5.0 microsoft outlook_express The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. 6,0%
CVE-1999-0119 HIGH 10.0 microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. 6,0%
CVE-1999-0570 HIGH 10.0 microsoft windows_nt Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. 6,0%
CVE-1999-0535 HIGH 10.0 microsoft windows_2000 A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. 6,0%
CVE-2020-1045 HIGH 7.5 fedoraproject fedora <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name bei 6,0%