imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2007-0069
Alta 9.3

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger mem…

microsoft windows_2003_server · microsoft windows_vista · microsoft windows_xp
0.49EPSS
CVE-2010-0241
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code v…

microsoft windows_server_2008 · microsoft windows_vista
0.49EPSS
CVE-2006-1315
Media 5.0

The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not prope…

microsoft server_service
0.49EPSS
CVE-2004-0200
Alta 9.3

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large i…

microsoft .net_framework · microsoft digital_image_pro · microsoft digital_image_suite · microsoft excel · e altri 20
0.49EPSS
CVE-2007-4776
Alta 9.3

Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are li…

microsoft visual_basic
0.49EPSS
CVE-2017-11793
Alta 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context…

microsoft internet_explorer
0.49EPSS
CVE-2018-8420
Alta 8.8

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server
0.49EPSS
CVE-2020-17117
Media 6.6

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.49EPSS
CVE-2010-0240
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remo…

microsoft windows_server_2008 · microsoft windows_vista
0.49EPSS
CVE-2004-0841
Media 5.0

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s3400 · e altri 3
0.49EPSS
CVE-2006-0025
Alta 9.3

Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

microsoft windows_media_player
0.49EPSS
CVE-2007-2223
Alta 9.3

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

microsoft xml_core_services
0.49EPSS
CVE-2004-0216
Alta 10.0

Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating …

microsoft ie · microsoft internet_explorer
0.49EPSS
CVE-2016-0170
Alta 8.8

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Win…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.49EPSS
CVE-2006-2382
Alta 10.0

Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory…

microsoft internet_explorer
0.49EPSS
CVE-2000-0098
Media 5.0

Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.

microsoft index_server
0.49EPSS
CVE-2005-1990
Media 5.1

Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1)…

microsoft ie · microsoft internet_explorer
0.49EPSS
CVE-2019-1009
Media 4.7

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are …

microsoft windows_7 · microsoft windows_server_2008
0.48EPSS
CVE-2010-0028
Alta 9.3

Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.48EPSS
CVE-2002-0648
Media 5.0

The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.

microsoft internet_explorer
0.48EPSS
CVE-2003-0816
Alta 7.5

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL conta…

microsoft ie · microsoft internet_explorer
0.48EPSS
CVE-2008-0116
Alta 9.3

Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007
0.48EPSS
CVE-2006-3281
Media 5.1

Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose exten…

microsoft internet_explorer
0.48EPSS
CVE-2021-40487
Alta 8.1

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.48EPSS
CVE-2010-0270
Alta 10.0

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corr…

microsoft windows_7 · microsoft windows_server_2008
0.48EPSS