Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 18433 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-21787 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21786 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21785 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21792 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21791 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21790 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2023-21789 1 Microsoft 1 3d Builder 2024-02-02 N/A 7.8 HIGH
3D Builder Remote Code Execution Vulnerability
CVE-2008-5180 1 Microsoft 1 Office Communicator 2024-02-02 5.0 MEDIUM N/A
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
CVE-2001-0334 1 Microsoft 1 Internet Information Server 2024-02-02 5.0 MEDIUM 7.5 HIGH
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
CVE-2007-2237 1 Microsoft 1 Windows Xp 2024-02-02 7.1 HIGH 5.5 MEDIUM
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
CVE-2011-0611 6 Adobe, Apple, Google and 3 more 9 Acrobat, Acrobat Reader, Adobe Air and 6 more 2024-02-02 9.3 HIGH 8.8 HIGH
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.
CVE-2010-0258 1 Microsoft 6 Excel, Office, Office Compatibility Pack and 3 more 2024-02-02 9.3 HIGH 7.8 HIGH
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."
CVE-2001-1238 1 Microsoft 2 Windows 2000, Windows 2000 Terminal Services 2024-02-02 4.6 MEDIUM 7.8 HIGH
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.