VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2017-0261HigKEVMay 12, 2017
    risk 0.69cvss 7.8epss 0.78

    Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.

  • CVE-2016-7182CriOct 14, 2016
    risk 0.69cvss 9.8epss 0.30

    The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync…

  • CVE-2016-3235HigKEVJun 16, 2016
    risk 0.69cvss 7.8epss 0.43

    Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

  • CVE-2016-0167HigKEVApr 12, 2016
    risk 0.69cvss 7.8epss 0.06

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2013-1331HigKEVJun 12, 2013
    risk 0.69cvss 7.8epss 0.82

    Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."

  • CVE-2013-3660HigKEVMay 24, 2013
    risk 0.69cvss 7.8epss 0.40

    The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a…

  • CVE-2012-0151HigKEVApr 10, 2012
    risk 0.69cvss 7.8epss 0.89

    The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed…

  • CVE-2011-2013CriNov 8, 2011
    risk 0.69cvss 9.8epss 0.34

    Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference…

  • CVE-2026-21509HigKEVJan 26, 2026
    risk 0.68cvss 7.8epss 0.73

    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2024-49138HigKEVDec 12, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2024-43572HigKEVOct 8, 2024
    risk 0.68cvss 7.8epss 0.67

    Microsoft Management Console Remote Code Execution Vulnerability

  • CVE-2024-38193HigKEVAug 13, 2024
    risk 0.68cvss 7.8epss 0.29

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2024-35250HigKEVJun 11, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

  • CVE-2023-36874HigKEVJul 11, 2023
    risk 0.68cvss 7.8epss 0.43

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2023-29360HigKEVJun 14, 2023
    risk 0.68cvss 8.4epss 0.22

    Microsoft Streaming Service Elevation of Privilege Vulnerability

  • CVE-2022-34718CriSep 13, 2022
    risk 0.68cvss 9.8epss 0.47

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2022-34713HigKEVAug 9, 2022
    risk 0.68cvss 7.8epss 0.68

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

  • CVE-2020-0938HigKEVApr 15, 2020
    risk 0.68cvss 7.8epss 0.69

    A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the…

  • CVE-2020-0601HigKEVJan 14, 2020
    risk 0.68cvss 8.1epss 0.89

    A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file…

  • CVE-2019-0785CriJul 15, 2019
    risk 0.68cvss 9.8epss 0.50

    A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

  • CVE-2019-0726CriApr 9, 2019
    risk 0.68cvss 9.8epss 0.54

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0698.

  • CVE-2018-8581HigKEVNov 14, 2018
    risk 0.68cvss 7.4epss 0.27

    An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2016-3393HigKEVOct 14, 2016
    risk 0.68cvss 7.8epss 0.69

    Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via…

  • CVE-2016-0040HigKEVFeb 10, 2016
    risk 0.68cvss 7.8epss 0.25

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

  • CVE-2013-5065HigKEVNov 28, 2013
    risk 0.68cvss 7.8epss 0.35

    NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

  • CVE-2011-2005HigKEVOct 12, 2011
    risk 0.68cvss 7.8epss 0.32

    afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of…

  • CVE-2010-2572HigKEVNov 10, 2010
    risk 0.68cvss 7.8epss 0.63

    Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

  • CVE-2010-0232HigKEVJan 21, 2010
    risk 0.68cvss 7.8epss 0.29

    The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform,…

  • CVE-2009-0563HigKEVJun 10, 2009
    risk 0.68cvss 7.8epss 0.63

    Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility…

  • CVE-2002-0391CriAug 12, 2002
    risk 0.68cvss 9.8epss 0.58

    Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as…

  • CVE-2024-38112HigKEVJul 9, 2024
    risk 0.67cvss 7.5epss 0.84

    Windows MSHTML Platform Spoofing Vulnerability

  • CVE-2024-30080CriJun 11, 2024
    risk 0.67cvss 9.8epss 0.43

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2022-21971HigKEVFeb 9, 2022
    risk 0.67cvss 7.8epss 0.54

    Windows Runtime Remote Code Execution Vulnerability

  • CVE-2021-38648HigKEVSep 15, 2021
    risk 0.67cvss 7.8epss 0.11

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-33766HigKEVJul 14, 2021
    risk 0.67cvss 7.3epss 0.98

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2021-33739HigKEVJun 8, 2021
    risk 0.67cvss 8.4epss 0.07

    Microsoft DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2021-28476CriMay 11, 2021
    risk 0.67cvss 9.9epss 0.39

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2021-28481CriApr 13, 2021
    risk 0.67cvss 9.8epss 0.36

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2017-11774HigKEVOct 13, 2017
    risk 0.67cvss 7.8epss 0.60

    Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

  • CVE-2017-0263HigKEVMay 12, 2017
    risk 0.67cvss 7.8epss 0.10

    The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka…

  • CVE-2017-6517CriMar 23, 2017
    risk 0.67cvss 9.8epss 0.46

    Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the…

  • CVE-2016-7262HigKEVDec 20, 2016
    risk 0.67cvss 7.8epss 0.58

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office…

  • CVE-2016-7193HigKEVOct 14, 2016
    risk 0.67cvss 7.8epss 0.58

    Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1,…

  • CVE-2016-0165HigKEVApr 12, 2016
    risk 0.67cvss 7.8epss 0.14

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2015-1642HigKEVAug 15, 2015
    risk 0.67cvss 7.8epss 0.53

    Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

  • CVE-2015-1671HigKEVMay 13, 2015
    risk 0.67cvss 7.8epss 0.55

    The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and…

  • CVE-2014-4077HigKEVNov 11, 2014
    risk 0.67cvss 7.8epss 0.48

    Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka…

  • CVE-2012-2539HigKEVDec 12, 2012
    risk 0.67cvss 7.8epss 0.53

    Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF…

  • CVE-2009-2494CriAug 12, 2009
    risk 0.67cvss 9.8epss 0.42

    The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant…

  • CVE-2009-0557HigKEVJun 10, 2009
    risk 0.67cvss 7.8epss 0.59

    Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft…

Page 6 of 314