Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-0249 | Hig | 0.80 | 8.8 | 0.92 | KEV | Jan 15, 2010 | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute… | |
| CVE-2025-33053 | Hig | 0.79 | 8.8 | 0.85 | KEV | Jun 10, 2025 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | |
| CVE-2022-26923 | Hig | 0.79 | 8.8 | 0.83 | KEV | May 10, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2017-8464 | Hig | 0.79 | 8.8 | 0.90 | KEV | Jun 15, 2017 | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via… | |
| CVE-2015-2426 | Hig | 0.79 | 8.8 | 0.87 | KEV | Jul 20, 2015 | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute… | |
| CVE-2014-6324 | Hig | 0.79 | 8.8 | 0.87 | KEV | Nov 18, 2014 | The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain… | |
| CVE-2014-0322 | Hig | 0.79 | 8.8 | 0.85 | KEV | Feb 14, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February… | |
| CVE-2013-3893 | Hig | 0.79 | 8.8 | 0.86 | KEV | Sep 18, 2013 | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of… | |
| CVE-2012-4792 | Hig | 0.79 | 8.8 | 0.79 | KEV | Dec 30, 2012 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and… | |
| CVE-2012-1889 | Hig | 0.79 | 8.8 | 0.84 | KEV | Jun 13, 2012 | Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | |
| CVE-2010-0806 | Hig | 0.79 | 8.8 | 0.82 | KEV | Mar 10, 2010 | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the… | |
| CVE-2026-20963 | Cri | 0.78 | 9.8 | 0.32 | KEV | Jan 13, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| CVE-2024-21412 | Hig | 0.78 | 8.1 | 0.95 | KEV | Feb 13, 2024 | Internet Shortcut Files Security Feature Bypass Vulnerability | |
| CVE-2021-40449 | Hig | 0.78 | 7.8 | 0.74 | KEV | Oct 13, 2021 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-1675 | Hig | 0.78 | 7.8 | 0.86 | KEV | Jun 8, 2021 | Windows Print Spooler Remote Code Execution Vulnerability | |
| CVE-2021-1732 | Hig | 0.78 | 7.8 | 0.78 | KEV | Feb 25, 2021 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2019-1458 | Hig | 0.78 | 7.8 | 0.74 | KEV | Dec 10, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | |
| CVE-2018-0824 | Hig | 0.78 | 8.8 | 0.73 | KEV | May 9, 2018 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server… | |
| CVE-2017-0147 | Hig | 0.78 | 7.5 | 1.00 | KEV | Mar 17, 2017 | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information… | |
| CVE-2013-3918 | Hig | 0.78 | 8.8 | 0.74 | KEV | Nov 12, 2013 | The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold… | |
| CVE-2013-3897 | Hig | 0.78 | 8.8 | 0.77 | KEV | Oct 9, 2013 | Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event… | |
| CVE-2013-3163 | Hig | 0.78 | 8.8 | 0.71 | KEV | Jul 10, 2013 | Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and… | |
| CVE-2013-1347 | Hig | 0.78 | 8.8 | 0.78 | KEV | May 5, 2013 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013. | |
| CVE-2013-0074 | Hig | 0.78 | 7.8 | 0.82 | KEV | Mar 13, 2013 | Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference… | |
| CVE-2011-3402 | Hig | 0.78 | 8.8 | 0.78 | KEV | Nov 4, 2011 | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to… | |
| CVE-2008-0015 | Hig | 0.78 | 8.8 | 0.77 | KEV | Jul 7, 2009 | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2,… | |
| CVE-2025-33073 | Hig | 0.77 | 8.8 | 0.80 | KEV | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| CVE-2024-21410 | Cri | 0.77 | 9.8 | 0.13 | KEV | Feb 13, 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2018-8453 | Hig | 0.77 | 7.8 | 0.70 | KEV | Oct 10, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | |
| CVE-2018-8174 | Hig | 0.77 | 7.5 | 0.89 | KEV | May 9, 2018 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | |
| CVE-2018-0798 | Hig | 0.77 | 8.8 | 0.95 | KEV | Jan 10, 2018 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". | |
| CVE-2016-0151 | Hig | 0.77 | 7.8 | 0.63 | KEV | Apr 12, 2016 | The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security… | |
| CVE-2024-49039 | Hig | 0.76 | 8.8 | 0.14 | KEV | Nov 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability | |
| CVE-2024-7971 | Cri | 0.76 | 9.6 | 0.21 | KEV | Aug 21, 2024 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-21338 | Hig | 0.76 | 7.8 | 0.60 | KEV | Feb 13, 2024 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-6345 | Cri | 0.76 | 9.6 | 0.16 | KEV | Nov 29, 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | |
| CVE-2023-36025 | Hig | 0.76 | 8.8 | 0.88 | KEV | Nov 14, 2023 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-28252 | Hig | 0.76 | 7.8 | 0.49 | KEV | Apr 11, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2021-26858 | Hig | 0.76 | 7.8 | 0.94 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26857 | Hig | 0.76 | 7.8 | 0.96 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2019-0752 | Hig | 0.76 | 7.5 | 0.82 | KEV | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862. | |
| CVE-2019-0541 | Hig | 0.76 | 8.8 | 0.53 | KEV | Jan 8, 2019 | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft… | |
| CVE-2017-0101 | Hig | 0.76 | 7.8 | 0.57 | KEV | Mar 17, 2017 | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain… | |
| CVE-2015-2419 | Hig | 0.76 | 8.8 | 0.53 | KEV | Jul 14, 2015 | JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability." | |
| CVE-2015-1701 | Hig | 0.76 | 7.8 | 0.56 | KEV | Apr 21, 2015 | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability." | |
| CVE-2023-36884 | Hig | 0.75 | 7.5 | 0.99 | KEV | Jul 11, 2023 | Windows Search Remote Code Execution Vulnerability | |
| CVE-2023-24955 | Hig | 0.75 | 7.2 | 0.85 | KEV | May 9, 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| CVE-2022-21999 | Hig | 0.75 | 7.8 | 0.42 | KEV | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2021-36942 | Hig | 0.75 | 7.5 | 0.66 | KEV | Aug 12, 2021 | Windows LSA Spoofing Vulnerability | |
| CVE-2020-0787 | Hig | 0.75 | 7.8 | 0.43 | KEV | Mar 12, 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. |
- risk 0.80cvss 8.8epss 0.92
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute…
- risk 0.79cvss 8.8epss 0.85
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
- risk 0.79cvss 8.8epss 0.83
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.79cvss 8.8epss 0.90
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via…
- risk 0.79cvss 8.8epss 0.87
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute…
- risk 0.79cvss 8.8epss 0.87
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain…
- risk 0.79cvss 8.8epss 0.85
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February…
- risk 0.79cvss 8.8epss 0.86
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of…
- risk 0.79cvss 8.8epss 0.79
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and…
- risk 0.79cvss 8.8epss 0.84
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
- risk 0.79cvss 8.8epss 0.82
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the…
- risk 0.78cvss 9.8epss 0.32
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.78cvss 8.1epss 0.95
Internet Shortcut Files Security Feature Bypass Vulnerability
- risk 0.78cvss 7.8epss 0.74
Win32k Elevation of Privilege Vulnerability
- risk 0.78cvss 7.8epss 0.86
Windows Print Spooler Remote Code Execution Vulnerability
- risk 0.78cvss 7.8epss 0.78
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.78cvss 7.8epss 0.74
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- risk 0.78cvss 8.8epss 0.73
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…
- risk 0.78cvss 7.5epss 1.00
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information…
- risk 0.78cvss 8.8epss 0.74
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold…
- risk 0.78cvss 8.8epss 0.77
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event…
- risk 0.78cvss 8.8epss 0.71
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and…
- risk 0.78cvss 8.8epss 0.78
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
- risk 0.78cvss 7.8epss 0.82
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference…
- risk 0.78cvss 8.8epss 0.78
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to…
- risk 0.78cvss 8.8epss 0.77
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2,…
- risk 0.77cvss 8.8epss 0.80
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- risk 0.77cvss 9.8epss 0.13
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.77cvss 7.8epss 0.70
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.77cvss 7.5epss 0.89
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.77cvss 8.8epss 0.95
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
- risk 0.77cvss 7.8epss 0.63
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security…
- risk 0.76cvss 8.8epss 0.14
Windows Task Scheduler Elevation of Privilege Vulnerability
- risk 0.76cvss 9.6epss 0.21
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.76cvss 7.8epss 0.60
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.76cvss 9.6epss 0.16
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- risk 0.76cvss 8.8epss 0.88
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.76cvss 7.8epss 0.49
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.76cvss 7.8epss 0.94
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.76cvss 7.8epss 0.96
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.76cvss 7.5epss 0.82
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.
- risk 0.76cvss 8.8epss 0.53
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft…
- risk 0.76cvss 7.8epss 0.57
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain…
- risk 0.76cvss 8.8epss 0.53
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
- risk 0.76cvss 7.8epss 0.56
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
- risk 0.75cvss 7.5epss 0.99
Windows Search Remote Code Execution Vulnerability
- risk 0.75cvss 7.2epss 0.85
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.75cvss 7.8epss 0.42
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.75cvss 7.5epss 0.66
Windows LSA Spoofing Vulnerability
- risk 0.75cvss 7.8epss 0.43
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Page 2 of 314