imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2020-0610
Critica 9.8

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote C…

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.68EPSS
CVE-2010-3332
Media 6.4

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify…

microsoft .net_framework
0.67EPSS
CVE-2022-41034
Alta 7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft visual_studio_code
0.67EPSS
CVE-2023-24950
Media 6.5

Microsoft SharePoint Server Spoofing Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
0.67EPSS
CVE-1999-0612
Bassa 0.0

A version of finger is running that exposes valid user information to any entity on the network.

gnu finger_service · gnu fingerd · microsoft windows_2000 · microsoft windows_nt
0.67EPSS
CVE-2010-1681
Alta 7.6

Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.

microsoft visio
0.67EPSS
CVE-2023-36606
Alta 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.67EPSS
CVE-2004-1050
Alta 10.0

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability…

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s3400 · e altri 3
0.67EPSS
CVE-2009-0133
Alta 10.0

Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.

microsoft html_help_workshop
0.67EPSS
CVE-2000-0886
Alta 7.5

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.67EPSS
CVE-2019-0618
Alta 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.67EPSS
CVE-2016-7190
Alta 7.5

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.67EPSS
CVE-2017-8601
Alta 7.5

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Ed…

microsoft edge
0.67EPSS
CVE-2016-3213
Alta 8.8

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 throu…

microsoft internet_explorer · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · e altri 4
0.67EPSS
CVE-2018-8145
Alta 7.5

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulne…

microsoft chakracore · microsoft edge · microsoft internet_explorer
0.67EPSS
CVE-2018-0933
Alta 7.5

ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0934
Alta 7.5

ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2000-0630
Media 5.0

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.67EPSS
CVE-2006-1016
Alta 7.5

Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argum…

microsoft internet_explorer
0.67EPSS
CVE-2010-2551
Alta 7.8

The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.67EPSS
CVE-2015-6133
Alta 7.2

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code …

microsoft windows_10 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 2
0.67EPSS
CVE-2018-8139
Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0953
Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0980
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2008-4844
Alta 9.3

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs,…

microsoft internet_explorer
0.67EPSS