XML Core Services
by Microsoft
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-2434 | 0.01 | — | 0.16 | Aug 15, 2015 | Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different… | |||
| CVE-2015-1646 | 0.01 | — | 0.17 | Apr 14, 2015 | Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability." | |||
| CVE-2014-1816 | 0.01 | — | 0.14 | Jun 11, 2014 | Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these… | |||
| CVE-2009-0419 | 0.01 | — | 0.15 | Feb 4, 2009 | Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from… | |||
| CVE-2026-50359 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. |
- CVE-2015-2434Aug 15, 2015risk 0.01cvss —epss 0.16
Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different…
- CVE-2015-1646Apr 14, 2015risk 0.01cvss —epss 0.17
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."
- CVE-2014-1816Jun 11, 2014risk 0.01cvss —epss 0.14
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these…
- CVE-2009-0419Feb 4, 2009risk 0.01cvss —epss 0.15
Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from…
- risk 0.00cvss 7.0epss 0.00
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
Page 2 of 2