Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11934 | Med | 0.37 | 5.5 | 0.13 | Dec 12, 2017 | Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability". | ||
| CVE-2017-11853 | Med | 0.37 | 5.5 | 0.11 | Nov 15, 2017 | Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted… | ||
| CVE-2017-11816 | Med | 0.37 | 5.5 | 0.20 | Oct 13, 2017 | The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure… | ||
| CVE-2017-8710 | Med | 0.37 | 5.5 | 0.10 | Sep 13, 2017 | The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console Document (.msc) parses XML input… | ||
| CVE-2017-8572 | Med | 0.37 | 5.5 | 0.13 | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook… | ||
| CVE-2017-0215 | Med | 0.37 | 5.3 | 0.36 | Jun 15, 2017 | Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security… | ||
| CVE-2017-0204 | Med | 0.37 | 5.5 | 0.19 | Apr 12, 2017 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." | ||
| CVE-2017-0029 | Med | 0.37 | 5.5 | 0.16 | Mar 17, 2017 | Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability." | ||
| CVE-2017-0007 | Med | 0.37 | 5.5 | 0.11 | Mar 17, 2017 | Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability." | ||
| CVE-2016-7267 | Med | 0.37 | 5.5 | 0.19 | Dec 20, 2016 | Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." | ||
| CVE-2016-7244 | Med | 0.37 | 5.5 | 0.16 | Nov 10, 2016 | Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability." | ||
| CVE-2016-3279 | Med | 0.37 | 5.5 | 0.16 | Jul 13, 2016 | Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and… | ||
| CVE-2016-3277 | Med | 0.37 | 5.3 | 0.32 | Jul 13, 2016 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | ||
| CVE-2026-55015 | Med | 0.36 | 5.5 | 0.00 | Aug 20, 2026 | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | ||
| CVE-2026-72971 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-70348 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. | ||
| CVE-2026-70325 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70323 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70322 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70320 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70319 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70318 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70317 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70316 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70315 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70314 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70312 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70310 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68813 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68808 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68802 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68799 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68797 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66810 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66806 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-65784 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-65662 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. | ||
| CVE-2026-64917 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-64899 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63531 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63530 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63529 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63528 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63524 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63521 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63517 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-62887 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62842 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
- risk 0.37cvss 5.5epss 0.13
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".
- risk 0.37cvss 5.5epss 0.11
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted…
- risk 0.37cvss 5.5epss 0.20
The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure…
- risk 0.37cvss 5.5epss 0.10
The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console Document (.msc) parses XML input…
- risk 0.37cvss 5.5epss 0.13
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook…
- risk 0.37cvss 5.3epss 0.36
Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security…
- risk 0.37cvss 5.5epss 0.19
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
- risk 0.37cvss 5.5epss 0.16
Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
- risk 0.37cvss 5.5epss 0.11
Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."
- risk 0.37cvss 5.5epss 0.19
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
- risk 0.37cvss 5.5epss 0.16
Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
- risk 0.37cvss 5.5epss 0.16
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and…
- risk 0.37cvss 5.3epss 0.32
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- risk 0.36cvss 5.5epss 0.00
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Page 183 of 314