Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0942 | 0.05 | — | 0.22 | Dec 19, 2000 | The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. | |||
| CVE-2000-0983 | 0.05 | — | 0.21 | Dec 19, 2000 | Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. | |||
| CVE-2000-0830 | 0.05 | — | 0.26 | Nov 14, 2000 | annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705. | |||
| CVE-2000-0653 | 0.05 | — | 0.27 | Jul 20, 2000 | Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability. | |||
| CVE-2000-0581 | 0.05 | — | 0.22 | Jun 30, 2000 | Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. | |||
| CVE-2000-0377 | 0.05 | — | 0.19 | Jun 8, 2000 | The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability. | |||
| CVE-2000-0465 | 0.05 | — | 0.20 | May 17, 2000 | Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability. | |||
| CVE-1999-0980 | 0.05 | — | 0.23 | May 16, 2000 | Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request. | |||
| CVE-2000-0457 | 0.05 | — | 0.53 | May 11, 2000 | ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability. | |||
| CVE-2000-0168 | 0.05 | — | 0.20 | Mar 4, 2000 | Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. | |||
| CVE-2000-0211 | 0.05 | — | 0.21 | Feb 23, 2000 | The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability. | |||
| CVE-2000-0105 | 0.05 | — | 0.21 | Feb 1, 2000 | Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. | |||
| CVE-2000-0132 | 0.05 | — | 0.19 | Jan 31, 2000 | Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. | |||
| CVE-2000-0061 | 0.05 | — | 0.20 | Jan 7, 2000 | Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading. | |||
| CVE-2000-0028 | 0.05 | — | 0.23 | Dec 23, 1999 | Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | |||
| CVE-1999-0999 | 0.05 | — | 0.22 | Nov 19, 1999 | Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. | |||
| CVE-2000-0073 | 0.05 | — | 0.21 | Nov 17, 1999 | Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | |||
| CVE-1999-1577 | 0.05 | — | 0.19 | Oct 31, 1999 | Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. | |||
| CVE-1999-1484 | 0.05 | — | 0.27 | Sep 24, 1999 | Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. | |||
| CVE-1999-1578 | 0.05 | — | 0.19 | Sep 24, 1999 | Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. | |||
| CVE-1999-0886 | 0.05 | — | 0.22 | Sep 17, 1999 | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. | |||
| CVE-1999-0702 | 0.05 | — | 0.24 | Sep 10, 1999 | Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. | |||
| CVE-1999-0668 | 0.05 | — | 0.23 | Aug 21, 1999 | The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | |||
| CVE-1999-0725 | 0.05 | — | 0.25 | Aug 19, 1999 | When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | |||
| CVE-1999-0867 | 0.05 | — | 0.22 | Aug 11, 1999 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | |||
| CVE-1999-0918 | 0.05 | — | 0.26 | Jul 3, 1999 | Denial of service in various Windows systems via malformed, fragmented IGMP packets. | |||
| CVE-1999-0386 | 0.05 | — | 0.19 | Mar 1, 1999 | Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL. | |||
| CVE-1999-1375 | 0.05 | — | 0.31 | Feb 11, 1999 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |||
| CVE-1999-1538 | 0.05 | — | 0.25 | Jan 14, 1999 | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | |||
| CVE-1999-0448 | 0.05 | — | 0.25 | Jan 1, 1999 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | |||
| CVE-1999-0288 | 0.05 | — | 0.21 | Aug 1, 1998 | The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. | |||
| CVE-1999-0153 | 0.05 | — | 0.21 | Jul 1, 1997 | Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. | |||
| CVE-1999-0612 | 0.05 | — | 0.67 | Mar 1, 1997 | A version of finger is running that exposes valid user information to any entity on the network. | |||
| CVE-1999-0077 | 0.05 | — | 0.31 | Jan 1, 1995 | Predictable TCP sequence numbers allow spoofing. | |||
| CVE-2015-6176 | 0.04 | — | 0.13 | Dec 9, 2015 | Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability." | |||
| CVE-2015-6172 | 0.04 | — | 0.54 | Dec 9, 2015 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability." | |||
| CVE-2015-6099 | 0.04 | — | 0.48 | Nov 11, 2015 | Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability." | |||
| CVE-2015-2527 | 0.04 | — | 0.07 | Sep 9, 2015 | The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain… | |||
| CVE-2015-2433 | 0.04 | — | 0.17 | Aug 15, 2015 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application,… | |||
| CVE-2015-0059 | 0.04 | — | 0.11 | Feb 11, 2015 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote… | |||
| CVE-2015-0057 | 0.04 | — | 0.13 | Feb 11, 2015 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a… | |||
| CVE-2015-0009 | 0.04 | — | 0.08 | Feb 11, 2015 | The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle… | |||
| CVE-2015-0002 | 0.04 | — | 0.14 | Jan 13, 2015 | The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token… | |||
| CVE-2014-1767 | 0.04 | — | 0.13 | Jul 8, 2014 | Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… | |||
| CVE-2014-1823 | 0.04 | — | 0.51 | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability." | |||
| CVE-2014-1778 | 0.04 | — | 0.15 | Jun 11, 2014 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777. | |||
| CVE-2014-1771 | 0.04 | — | 0.08 | Jun 11, 2014 | SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a… | |||
| CVE-2013-4858 | 0.04 | — | 0.13 | Dec 30, 2013 | Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav. | |||
| CVE-2013-5045 | 0.04 | — | 0.17 | Dec 11, 2013 | Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability." | |||
| CVE-2013-3881 | 0.04 | — | 0.15 | Oct 9, 2013 | win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a crafted application, aka "Win32k NULL Page Vulnerability." |
- CVE-2000-0942Dec 19, 2000risk 0.05cvss —epss 0.22
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
- CVE-2000-0983Dec 19, 2000risk 0.05cvss —epss 0.21
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
- CVE-2000-0830Nov 14, 2000risk 0.05cvss —epss 0.26
annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.
- CVE-2000-0653Jul 20, 2000risk 0.05cvss —epss 0.27
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.
- CVE-2000-0581Jun 30, 2000risk 0.05cvss —epss 0.22
Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.
- CVE-2000-0377Jun 8, 2000risk 0.05cvss —epss 0.19
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.
- CVE-2000-0465May 17, 2000risk 0.05cvss —epss 0.20
Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
- CVE-1999-0980May 16, 2000risk 0.05cvss —epss 0.23
Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.
- CVE-2000-0457May 11, 2000risk 0.05cvss —epss 0.53
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
- CVE-2000-0168Mar 4, 2000risk 0.05cvss —epss 0.20
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
- CVE-2000-0211Feb 23, 2000risk 0.05cvss —epss 0.21
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.
- CVE-2000-0105Feb 1, 2000risk 0.05cvss —epss 0.21
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.
- CVE-2000-0132Jan 31, 2000risk 0.05cvss —epss 0.19
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.
- CVE-2000-0061Jan 7, 2000risk 0.05cvss —epss 0.20
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
- CVE-2000-0028Dec 23, 1999risk 0.05cvss —epss 0.23
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
- CVE-1999-0999Nov 19, 1999risk 0.05cvss —epss 0.22
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
- CVE-2000-0073Nov 17, 1999risk 0.05cvss —epss 0.21
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
- CVE-1999-1577Oct 31, 1999risk 0.05cvss —epss 0.19
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
- CVE-1999-1484Sep 24, 1999risk 0.05cvss —epss 0.27
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
- CVE-1999-1578Sep 24, 1999risk 0.05cvss —epss 0.19
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
- CVE-1999-0886Sep 17, 1999risk 0.05cvss —epss 0.22
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
- CVE-1999-0702Sep 10, 1999risk 0.05cvss —epss 0.24
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.
- CVE-1999-0668Aug 21, 1999risk 0.05cvss —epss 0.23
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
- CVE-1999-0725Aug 19, 1999risk 0.05cvss —epss 0.25
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
- CVE-1999-0867Aug 11, 1999risk 0.05cvss —epss 0.22
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
- CVE-1999-0918Jul 3, 1999risk 0.05cvss —epss 0.26
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
- CVE-1999-0386Mar 1, 1999risk 0.05cvss —epss 0.19
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
- CVE-1999-1375Feb 11, 1999risk 0.05cvss —epss 0.31
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
- CVE-1999-1538Jan 14, 1999risk 0.05cvss —epss 0.25
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
- CVE-1999-0448Jan 1, 1999risk 0.05cvss —epss 0.25
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
- CVE-1999-0288Aug 1, 1998risk 0.05cvss —epss 0.21
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
- CVE-1999-0153Jul 1, 1997risk 0.05cvss —epss 0.21
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
- CVE-1999-0612Mar 1, 1997risk 0.05cvss —epss 0.67
A version of finger is running that exposes valid user information to any entity on the network.
- CVE-1999-0077Jan 1, 1995risk 0.05cvss —epss 0.31
Predictable TCP sequence numbers allow spoofing.
- CVE-2015-6176Dec 9, 2015risk 0.04cvss —epss 0.13
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."
- CVE-2015-6172Dec 9, 2015risk 0.04cvss —epss 0.54
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."
- CVE-2015-6099Nov 11, 2015risk 0.04cvss —epss 0.48
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."
- CVE-2015-2527Sep 9, 2015risk 0.04cvss —epss 0.07
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain…
- CVE-2015-2433Aug 15, 2015risk 0.04cvss —epss 0.17
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application,…
- CVE-2015-0059Feb 11, 2015risk 0.04cvss —epss 0.11
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote…
- CVE-2015-0057Feb 11, 2015risk 0.04cvss —epss 0.13
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a…
- CVE-2015-0009Feb 11, 2015risk 0.04cvss —epss 0.08
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle…
- CVE-2015-0002Jan 13, 2015risk 0.04cvss —epss 0.14
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token…
- CVE-2014-1767Jul 8, 2014risk 0.04cvss —epss 0.13
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows…
- CVE-2014-1823Jun 11, 2014risk 0.04cvss —epss 0.51
Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability."
- CVE-2014-1778Jun 11, 2014risk 0.04cvss —epss 0.15
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.
- CVE-2014-1771Jun 11, 2014risk 0.04cvss —epss 0.08
SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a…
- CVE-2013-4858Dec 30, 2013risk 0.04cvss —epss 0.13
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.
- CVE-2013-5045Dec 11, 2013risk 0.04cvss —epss 0.17
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
- CVE-2013-3881Oct 9, 2013risk 0.04cvss —epss 0.15
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a crafted application, aka "Win32k NULL Page Vulnerability."
Page 234 of 314