VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2000-0121Feb 1, 2000
    risk 0.03cvss epss 0.05

    The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.

  • CVE-1999-1084Dec 31, 1999
    risk 0.03cvss epss 0.04

    The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

  • CVE-2000-0100Dec 29, 1999
    risk 0.03cvss epss 0.03

    The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.

  • CVE-2000-0025Dec 21, 1999
    risk 0.03cvss epss 0.35

    IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

  • CVE-1999-0975Dec 10, 1999
    risk 0.03cvss epss 0.03

    The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.

  • CVE-1999-0899Nov 4, 1999
    risk 0.03cvss epss 0.03

    The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.

  • CVE-1999-1235Aug 25, 1999
    risk 0.03cvss epss 0.03

    Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the…

  • CVE-2000-0325Aug 20, 1999
    risk 0.03cvss epss 0.04

    The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

  • CVE-1999-0700Jul 29, 1999
    risk 0.03cvss epss 0.03

    Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

  • CVE-1999-0715May 20, 1999
    risk 0.03cvss epss 0.03

    Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.

  • CVE-1999-0716May 17, 1999
    risk 0.03cvss epss 0.03

    Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.

  • CVE-1999-0382Mar 12, 1999
    risk 0.03cvss epss 0.03

    The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.

  • CVE-1999-0376Feb 20, 1999
    risk 0.03cvss epss 0.02

    Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

  • CVE-1999-0372Feb 12, 1999
    risk 0.03cvss epss 0.04

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

  • CVE-1999-0360Jan 30, 1999
    risk 0.03cvss epss 0.06

    MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

  • CVE-2018-5391HigSep 6, 2018
    risk 0.02cvss 7.5epss 0.32

    The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in…

  • CVE-2015-6161Dec 9, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."

  • CVE-2015-6160Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142,…

  • CVE-2015-6159Dec 9, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140,…

  • CVE-2015-6151Dec 9, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 8 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2015-6150Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6154.

  • CVE-2015-6149Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6147.

  • CVE-2015-6148Dec 9, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2015-6147Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6149.

  • CVE-2015-6143Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142,…

  • CVE-2015-6142Dec 9, 2015
    risk 0.02cvss epss 0.20

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140,…

  • CVE-2015-6141Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6134.

  • CVE-2015-6136Dec 9, 2015
    risk 0.02cvss epss 0.25

    The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

  • CVE-2015-6135Dec 9, 2015
    risk 0.02cvss epss 0.23

    The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information…

  • CVE-2015-6134Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6141.

  • CVE-2015-6130Dec 9, 2015
    risk 0.02cvss epss 0.21

    Integer underflow in Uniscribe in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows remote attackers to execute arbitrary code via a crafted font, aka "Windows Integer Underflow Vulnerability."

  • CVE-2015-6125Dec 9, 2015
    risk 0.02cvss epss 0.30

    Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability."

  • CVE-2015-6114Dec 9, 2015
    risk 0.02cvss epss 0.19

    Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6165.

  • CVE-2015-6108Dec 9, 2015
    risk 0.02cvss epss 0.26

    The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4,…

  • CVE-2015-6083Dec 9, 2015
    risk 0.02cvss epss 0.18

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6151.

  • CVE-2015-6045Nov 13, 2015
    risk 0.02cvss epss 0.19

    Use-after-free vulnerability in the CElement object implementation in Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript that improperly interacts with use of the Cascading…

  • CVE-2015-6097Nov 11, 2015
    risk 0.02cvss epss 0.21

    Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted Journal (.jnt) file, aka "Windows Journal Heap Overflow Vulnerability."

  • CVE-2015-6094Nov 11, 2015
    risk 0.02cvss epss 0.21

    Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory…

  • CVE-2015-6093Nov 11, 2015
    risk 0.02cvss epss 0.21

    Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a…

  • CVE-2015-6088Nov 11, 2015
    risk 0.02cvss epss 0.30

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."

  • CVE-2015-6081Nov 11, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6069.

  • CVE-2015-6077Nov 11, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072,…

  • CVE-2015-6076Nov 11, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6066,…

  • CVE-2015-6075Nov 11, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072,…

  • CVE-2015-6071Nov 11, 2015
    risk 0.02cvss epss 0.21

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6066,…

  • CVE-2015-6065Nov 11, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6078.

  • CVE-2015-6064Nov 11, 2015
    risk 0.02cvss epss 0.20

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2015-4716Oct 21, 2015
    risk 0.02cvss epss 0.25

    Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

  • CVE-2015-6055Oct 14, 2015
    risk 0.02cvss epss 0.25

    The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Filter arguments, aka…

  • CVE-2015-6053Oct 14, 2015
    risk 0.02cvss epss 0.19

    Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via crafted parameters in an ArrayBuffer.slice call, aka "Internet Explorer Information Disclosure Vulnerability."

Page 246 of 314