imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2006-1192
Bassa 2.6

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, …

canon network_camera_server_vb101 · microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2006-6456
Alta 9.3

Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5…

microsoft office · microsoft word · microsoft word_viewer · microsoft works
0.31EPSS
CVE-2013-1325
Alta 9.3

Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Heap Overwrite Vulnerability."

microsoft office
0.31EPSS
CVE-2013-1324
Alta 9.3

Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Stack Buffer Overwrite Vulnerability."

microsoft office · microsoft office_2013_rt
0.31EPSS
CVE-2006-0034
Alta 7.5

Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long …

microsoft distributed_transaction_coordinator · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · e altri 1
0.31EPSS
CVE-2007-0027
Alta 9.3

Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.

microsoft excel · microsoft excel_viewer · microsoft office · microsoft works
0.31EPSS
CVE-2002-0693
Alta 7.5

Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter …

microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_98 · microsoft windows_98se · e altri 3
0.31EPSS
CVE-2015-2460
Alta 9.3

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, …

microsoft .net_framework
0.31EPSS
CVE-2007-3493
Alta 7.5

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the…

microsoft internet_explorer · nctsoft_products nctaudiostudio · nctsoft_products nctwavchunkseditor2.dll
0.31EPSS
CVE-2006-5994
Alta 9.3

Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that trig…

microsoft office · microsoft word · microsoft word_viewer · microsoft works
0.31EPSS
CVE-2006-5584
Alta 7.5

The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.

microsoft windows_2000
0.31EPSS
CVE-2007-3903
Media 6.8

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344,…

microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2006-0143
Alta 7.5

Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 2
0.31EPSS
CVE-2019-0667
Alta 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.

microsoft internet_explorer
0.31EPSS
CVE-2015-6168
Alta 9.3

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6153.

microsoft edge
0.31EPSS
CVE-2014-4109
Alta 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.31EPSS
CVE-2009-2506
Alta 9.3

Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with…

microsoft office_converter_pack · microsoft office_word · microsoft windows_2000 · microsoft windows_server_2003 · e altri 3
0.31EPSS
CVE-2009-2512
Critica 9.8

The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, …

microsoft windows_server_2008 · microsoft windows_vista
0.31EPSS
CVE-2020-0932
Alta 8.8

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-202…

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.31EPSS
CVE-2015-2474
Alta 9.0

Microsoft Windows Vista SP2 and Server 2008 SP2 allow remote authenticated users to execute arbitrary code via a crafted string in a Server Message Block (SMB) server error-logging action, aka "Server Message Block Memory Corruption Vulnerability."

microsoft windows_server_2008 · microsoft windows_vista
0.31EPSS
CVE-2007-0218
Alta 9.3

Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.

microsoft internet_explorer
0.31EPSS
CVE-2008-2249
Alta 9.3

Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.31EPSS
CVE-2006-4697
Alta 9.3

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.

microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2005-4131
Media 6.8

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involvi…

microsoft excel
0.31EPSS
CVE-2008-3476
Alta 9.3

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability."

microsoft internet_explorer
0.31EPSS