imPC@ndo EN

Vulnerabilità Microsoft

15.391 CVE

CVE-2015-2431
Alta 9.3

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Gr…

microsoft live_meeting · microsoft lync · microsoft lync_basic · microsoft office
0.30EPSS
CVE-2006-1184
Media 5.0

Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain …

microsoft distributed_transaction_coordinator · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · e altri 1
0.30EPSS
CVE-2007-1499
Media 4.3

Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of t…

microsoft ie
0.30EPSS
CVE-2008-2253
Alta 9.3

Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling Rate …

microsoft windows_media_player
0.30EPSS
CVE-2008-0551
Alta 9.3

The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these d…

microsoft activex · sejoong_namo activesquare
0.30EPSS
CVE-2004-0123
Alta 7.5

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 3
0.30EPSS
CVE-2007-6401
Alta 9.3

Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402.

3ivx mpeg-4_codec · microsoft windows_media_player
0.30EPSS
CVE-2008-4261
Alta 9.3

Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute …

microsoft internet_explorer
0.30EPSS
CVE-2016-0016
Alta 7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges vi…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.30EPSS
CVE-2019-0697
Critica 9.8

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.30EPSS
CVE-2010-2742
Media 5.4

The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, ak…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008
0.30EPSS
CVE-2013-0073
Alta 10.0

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a cr…

microsoft .net_framework
0.30EPSS
CVE-2015-6125
Alta 9.3

Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability."

microsoft windows_server_2008 · microsoft windows_server_2012
0.30EPSS
CVE-2011-0656
Alta 9.3

Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007…

microsoft office · microsoft office_compatibility_pack · microsoft office_powerpoint_viewer · microsoft open_xml_file_format_converter · e altri 3
0.30EPSS
CVE-2006-3434
Alta 9.3

Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.

microsoft office
0.30EPSS
CVE-2017-0042
Bassa 3.1

Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive informati…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.30EPSS
CVE-2015-2468
Alta 9.3

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office for Mac 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Word Web Apps 2…

microsoft office · microsoft office_compatibility_pack · microsoft sharepoint_server · microsoft word · e altri 3
0.30EPSS
CVE-2007-1202
Media 6.8

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigg…

microsoft word · microsoft word_viewer · microsoft works
0.29EPSS
CVE-2009-2496
Alta 9.3

Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Sec…

microsoft biztalk_server · microsoft internet_security_and_acceleration_server · microsoft office · microsoft office_web_components · e altri 1
0.29EPSS
CVE-2016-7191
Alta 8.1

The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.

microsoft azure_active_directory_passport
0.29EPSS
CVE-2009-0559
Alta 9.3

Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · e altri 2
0.29EPSS
CVE-2006-3873
Alta 7.5

Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in…

microsoft ie · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.29EPSS
CVE-2001-1319
Media 5.0

Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.

microsoft exchange_server
0.29EPSS
CVE-2006-1313
Media 6.8

Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 2
0.29EPSS
CVE-2012-1891
Critica 9.8

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory…

microsoft data_access_components · microsoft windows_data_access_components
0.29EPSS