imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2016-7240
Alta 7.5

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.66EPSS
CVE-2013-3205
Alta 9.3

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.66EPSS
CVE-2007-0213
Alta 10.0

Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.

microsoft exchange_server
0.66EPSS
CVE-2001-0151
Media 5.0

IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.

microsoft internet_information_services
0.66EPSS
CVE-2025-55315
Critica 9.9

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

microsoft asp.net_core · microsoft visual_studio_2022
0.66EPSS
CVE-2010-0242
Alta 7.8

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP …

microsoft windows_server_2008 · microsoft windows_vista
0.66EPSS
CVE-2020-0655
Alta 8.0

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.66EPSS
CVE-2012-1851
Alta 10.0

Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via …

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.66EPSS
CVE-2013-3180
Media 4.3

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."

microsoft sharepoint_foundation · microsoft sharepoint_server
0.66EPSS
CVE-2012-0155
Alta 9.3

Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."

microsoft internet_explorer
0.66EPSS
CVE-2018-0767
Media 5.3

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Informatio…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2017-11911
Alta 7.5

ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulner…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2017-11909
Alta 7.5

ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulner…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2017-11811
Alta 7.5

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Eng…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2023-21768
Alta 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_11 · microsoft windows_server_2022
0.65EPSS
CVE-2018-0860
Alta 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft edge
0.65EPSS
CVE-2018-0838
Alta 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2018-0837
Alta 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2018-0835
Alta 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.65EPSS
CVE-2002-1744
Media 5.0

Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

microsoft internet_information_services
0.65EPSS
CVE-2016-7237
Media 6.5

Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.65EPSS
CVE-2012-1876
Alta 9.3

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Co…

microsoft internet_explorer
0.65EPSS
CVE-2016-7203
Alta 7.5

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.65EPSS
CVE-1999-0278
Media 5.0

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

microsoft internet_information_server · microsoft windows_nt
0.65EPSS
CVE-2017-11764
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine…

microsoft edge
0.64EPSS