imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2006-5583
Alta 10.0

Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."

microsoft windows_2003_server
0.53EPSS
CVE-2011-0104
Alta 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.53EPSS
CVE-2020-1074
Alta 7.8

<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.53EPSS
CVE-2005-1978
Alta 7.5

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.53EPSS
CVE-1999-0191
Media 6.4

IIS newdsn.exe CGI script allows remote users to overwrite files.

microsoft internet_information_server
0.53EPSS
CVE-2002-0072
Media 5.0

The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service …

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2002-0149
Alta 7.5

Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2010-0248
Alta 8.1

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka…

microsoft internet_explorer
0.53EPSS
CVE-2018-0840
Alta 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote cod…

microsoft edge · microsoft internet_explorer
0.53EPSS
CVE-2002-0073
Media 5.0

The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2021-34501
Alta 7.8

Microsoft Excel Remote Code Execution Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_online_server
0.53EPSS
CVE-2024-38023
Alta 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.53EPSS
CVE-2007-5348
Alta 9.3

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe…

microsoft digital_image_suite · microsoft forefront_client_security · microsoft internet_explorer · microsoft office · e altri 12
0.53EPSS
CVE-2022-35823
Alta 8.8

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.53EPSS
CVE-2001-0538
Alta 10.0

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

microsoft outlook
0.53EPSS
CVE-2021-31213
Alta 7.8

Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability

microsoft remote
0.53EPSS
CVE-2021-34478
Alta 7.8

Microsoft Office Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office
0.53EPSS
CVE-2008-0108
Alta 9.3

Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft W…

microsoft office · microsoft works
0.53EPSS
CVE-2003-1041
Alta 7.5

Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not h…

microsoft ie · microsoft internet_explorer
0.53EPSS
CVE-2017-8734
Alta 7.5

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Co…

microsoft edge
0.53EPSS
CVE-2008-3471
Alta 9.3

Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 1
0.52EPSS
CVE-2007-3898
Media 6.4

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003
0.52EPSS
CVE-2002-0147
Alta 7.5

Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."

microsoft internet_information_server · microsoft internet_information_services
0.52EPSS
CVE-2008-3013
Alta 9.3

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 200…

microsoft digital_image_suite · microsoft forefront_client_security · microsoft internet_explorer · microsoft office · e altri 9
0.52EPSS
CVE-2008-1898
Alta 9.3

A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface pro…

microsoft office · microsoft works
0.52EPSS