imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2023-38039
Alta 7.5

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server…

fedoraproject fedora · haxx curl · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 6
0.62EPSS
CVE-2006-4446
Media 5.0

Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument s…

microsoft ie
0.62EPSS
CVE-2009-2532
Alta 10.0

Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SM…

microsoft windows_server_2008 · microsoft windows_vista
0.62EPSS
CVE-2018-8384
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-82…

microsoft chakracore
0.62EPSS
CVE-2021-28325
Media 6.5

Windows SMB Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · e altri 2
0.62EPSS
CVE-2009-1136
Alta 9.3

The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Offic…

microsoft isa_server · microsoft office · microsoft office_web_components · microsoft office_xp
0.62EPSS
CVE-2010-1892
Alta 7.8

The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.62EPSS
CVE-2005-2120
Media 6.5

Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a regi…

microsoft windows_2000 · microsoft windows_xp
0.62EPSS
CVE-2006-3441
Alta 10.0

Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.62EPSS
CVE-2008-0086
Alta 9.0

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

microsoft data_engine · microsoft sql_server · microsoft sql_server_desktop_engine · microsoft sql_server_express_edition
0.62EPSS
CVE-2006-1245
Alta 7.5

Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstr…

microsoft ie
0.62EPSS
CVE-2012-1875
Alta 9.3

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."

microsoft internet_explorer
0.62EPSS
CVE-2022-41076
Alta 8.5

PowerShell Remote Code Execution Vulnerability

microsoft powershell · microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · e altri 7
0.62EPSS
CVE-2005-2123
Alta 7.5

Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.61EPSS
CVE-2002-0148
Alta 7.5

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

microsoft internet_information_server · microsoft internet_information_services
0.61EPSS
CVE-2006-1189
Alta 10.0

Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Pars…

microsoft internet_explorer
0.61EPSS
CVE-2005-2087
Media 5.0

Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs …

microsoft ie · microsoft internet_explorer
0.61EPSS
CVE-2021-27084
Alta 7.8

Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

microsoft maven_for_java
0.61EPSS
CVE-2019-1252
Media 6.5

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.61EPSS
CVE-2006-1190
Alta 10.0

Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote…

microsoft internet_explorer
0.61EPSS
CVE-2010-0239
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary cod…

microsoft windows_server_2008 · microsoft windows_vista
0.61EPSS
CVE-2025-29971
Alta 7.5

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_11_24h2
0.61EPSS
CVE-2021-26424
Critica 9.9

Windows TCP/IP Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.61EPSS
CVE-2004-0549
Alta 10.0

The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the locat…

microsoft internet_explorer
0.61EPSS
CVE-2015-6096
Media 4.3

The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE…

microsoft .net_framework
0.61EPSS