VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2021-27063HigMar 11, 2021
    risk 0.49cvss 7.5epss 0.06

    Windows DNS Server Denial of Service Vulnerability

  • CVE-2021-26896HigMar 11, 2021
    risk 0.49cvss 7.5epss 0.07

    Windows DNS Server Denial of Service Vulnerability

  • CVE-2021-26881HigMar 11, 2021
    risk 0.49cvss 7.5epss 0.03

    Microsoft Windows Media Foundation Remote Code Execution Vulnerability

  • CVE-2021-26879HigMar 11, 2021
    risk 0.49cvss 7.5epss 0.04

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2021-24111HigFeb 25, 2021
    risk 0.49cvss 7.5epss 0.04

    .NET Framework Denial of Service Vulnerability

  • CVE-2021-1734HigFeb 25, 2021
    risk 0.49cvss 7.5epss 0.04

    Windows Remote Procedure Call Information Disclosure Vulnerability

  • CVE-2021-1723HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.05

    ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • CVE-2021-1694HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.03

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2020-17058HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Microsoft Browser Memory Corruption Vulnerability

  • CVE-2020-17053HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Internet Explorer Memory Corruption Vulnerability

  • CVE-2020-17052HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Scripting Engine Memory Corruption Vulnerability

  • CVE-2020-16992HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.01

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2020-16927HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.06

    A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system…

  • CVE-2020-16863HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.06

    A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Desktop Service on the…

  • CVE-2020-1228HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.04

    A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker…

  • CVE-2020-1031HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.05

    An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory. To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. …

  • CVE-2020-1013HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.06

    An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine. To…

  • CVE-2020-0908HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory. An attacker who successfully exploited the vulnerability could gain execution on a victim system. An attacker could host a specially crafted website that is…

  • CVE-2020-0836HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.05

    A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker…

  • CVE-2020-1597HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.07

    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without…

  • CVE-2020-1570HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker…

  • CVE-2020-1568HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-1565HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.03

    An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted…

  • CVE-2020-1459HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.04

    An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a…

  • CVE-2020-1378HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.04

    An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit…

  • CVE-2020-1374HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.

  • CVE-2020-1260HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.07

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.

  • CVE-2020-1230HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.07

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260.

  • CVE-2020-1216HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.07

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1230, CVE-2020-1260.

  • CVE-2020-1215HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

  • CVE-2020-1214HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

  • CVE-2020-1213HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.07

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

  • CVE-2020-1161HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.05

    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without…

  • CVE-2020-1093HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1092HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1064HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully…

  • CVE-2020-1060HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1058HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1035HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-0909HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.05

    A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security update addresses the…

  • CVE-2020-1018HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.06

    An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information…

  • CVE-2020-0895HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.

  • CVE-2020-0876HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.06

    An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

  • CVE-2020-0848HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827,…

  • CVE-2020-0847HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.

  • CVE-2020-0833HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826,…

  • CVE-2020-0832HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826,…

  • CVE-2020-0831HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827,…

  • CVE-2020-0830HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826,…

  • CVE-2020-0829HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827,…

Page 129 of 314