imPC@ndo EN

Vulnerabilità Microsoft

15.393 CVE

CVE-2012-1853
Alta 10.0

Stack-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administration P…

microsoft windows_xp
0.29EPSS
CVE-2012-1852
Alta 10.0

Heap-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administr…

microsoft windows_xp
0.29EPSS
CVE-2002-0191
Media 5.0

Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerabili…

microsoft internet_explorer
0.29EPSS
CVE-2007-3041
Alta 9.3

Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "ActiveX Object M…

microsoft internet_explorer
0.29EPSS
CVE-2006-4686
Alta 7.5

Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.

microsoft xml_core_services · microsoft xml_parser
0.29EPSS
CVE-2008-0076
Alta 9.3

Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."

microsoft ie · microsoft internet_explorer
0.29EPSS
CVE-2008-0104
Alta 9.3

Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."

microsoft office · microsoft publisher
0.29EPSS
CVE-2008-0088
Media 6.8

Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP requ…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.29EPSS
CVE-2009-0566
Alta 9.3

Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vul…

microsoft office_publisher
0.29EPSS
CVE-2007-3890
Alta 9.3

Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.

microsoft excel · microsoft office
0.29EPSS
CVE-2009-3130
Alta 9.3

Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) rec…

microsoft compatibility_pack_word_excel_powerpoint · microsoft excel · microsoft excel_viewer · microsoft office · e altri 1
0.29EPSS
CVE-2018-8421
Critica 9.8

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.…

microsoft .net_framework
0.29EPSS
CVE-2011-1995
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2010-3346
Alta 9.3

Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML …

microsoft internet_explorer
0.29EPSS
CVE-2010-3345
Alta 9.3

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Me…

microsoft internet_explorer
0.29EPSS
CVE-2010-3343
Alta 9.3

Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Mem…

microsoft internet_explorer
0.29EPSS
CVE-2008-4024
Alta 9.3

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers …

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · e altri 3
0.29EPSS
CVE-2010-0034
Alta 9.3

Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."

microsoft powerpoint
0.29EPSS
CVE-2014-6340
Media 4.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2018-8587
Alta 7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

microsoft office · microsoft office_365_proplus
0.29EPSS
CVE-2010-0252
Alta 9.3

The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · e altri 2
0.29EPSS
CVE-2009-1529
Alta 8.1

Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCap…

microsoft internet_explorer
0.29EPSS
CVE-1999-0738
Media 5.0

The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

microsoft internet_information_server
0.29EPSS
CVE-1999-0739
Media 5.0

The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

microsoft internet_information_server
0.29EPSS
CVE-2007-3826
Alta 9.3

Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before t…

microsoft internet_explorer
0.29EPSS