imPC@ndo EN

Vulnerabilità Microsoft

15.420 CVE

CVE-2014-4073
Alta 10.0

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elev…

microsoft .net_framework
0.23EPSS
CVE-2002-1327
Alta 7.5

Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise."

microsoft windows_xp
0.23EPSS
CVE-2010-3218
Alta 9.3

Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."

microsoft word
0.23EPSS
CVE-2010-1902
Alta 9.3

Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 a…

microsoft office · microsoft office_compatibility_pack · microsoft office_word_viewer · microsoft open_xml_file_format_converter · e altri 1
0.23EPSS
CVE-2010-1882
Alta 9.3

Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media f…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.23EPSS
CVE-2010-0479
Alta 9.3

Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerabil…

microsoft publisher
0.23EPSS
CVE-2021-21132
Critica 9.6

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

google chrome · microsoft edge_chromium
0.23EPSS
CVE-2016-0002
Alta 7.5

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerabi…

microsoft jscript · microsoft vbscript
0.23EPSS
CVE-2008-4031
Alta 9.3

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Ope…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · e altri 3
0.23EPSS
CVE-2008-4030
Alta 9.3

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1 allow remote attackers to execute …

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · e altri 3
0.23EPSS
CVE-2008-4026
Alta 9.3

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · e altri 3
0.23EPSS
CVE-2016-0051
Alta 7.8

The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.23EPSS
CVE-2018-8533
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affec…

microsoft sql_server_management_studio
0.23EPSS
CVE-2018-8532
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affec…

microsoft sql_server_management_studio
0.23EPSS
CVE-2018-8527
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affect…

microsoft sql_server_management_studio
0.23EPSS
CVE-2005-0452
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII chara…

microsoft asp.net
0.23EPSS
CVE-2011-1964
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object Memory Corruption Vuln…

microsoft internet_explorer
0.23EPSS
CVE-2011-1963
Alta 9.3

Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "XSLT Memory Corruption Vulnerabilit…

microsoft internet_explorer
0.23EPSS
CVE-2010-1883
Alta 7.8

Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a cr…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.23EPSS
CVE-2002-0647
Alta 7.5

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

microsoft internet_explorer
0.23EPSS
CVE-2006-3897
Media 5.0

Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.

microsoft internet_explorer
0.23EPSS
CVE-2003-0002
Media 6.8

Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

microsoft content_management_server
0.23EPSS
CVE-2004-2289
Alta 10.0

Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

microsoft windows_xp
0.23EPSS
CVE-2013-3160
Media 5.0

Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External…

microsoft office · microsoft word · microsoft word_viewer
0.23EPSS
CVE-2017-8501
Alta 7.8

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 2
0.23EPSS