Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Publisher HIGH 10.0
CVE-2013-1318EPSS 26%

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointe…

Mitigation only
Fix from $1,950 2013-05-15
Publisher HIGH 9.3
CVE-2013-1316EPSS 22%

Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via…

Mitigation only
Fix from $1,950 2013-05-15
Publisher HIGH 9.3
CVE-2013-1321EPSS 22%

Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2013-05-15
.net Framework MEDIUM 5.0
CVE-2013-1336EPSS 19%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote…

Mitigation only
Fix from $1,600 2013-05-15
Windows Defender HIGH 7.2
CVE-2013-0078

The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users…

Mitigation only
Fix from $1,950 2013-04-09
Active Directory MEDIUM 5.0
CVE-2013-1282EPSS 27%

The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), an…

Mitigation only
Fix from $1,600 2013-04-09
.net Framework HIGH 9.3
CVE-2013-0004EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, …

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 7.8
CVE-2013-0005EPSS 32%

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Managem…

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 9.3
CVE-2012-4776EPSS 25%

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data th…

Mitigation only
Fix from $1,950 2012-11-14
Sharepoint Server MEDIUM 6.8
CVE-2012-1862EPSS 11%

Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites a…

Mitigation only
Fix from $1,600 2012-07-10
Windows 2003 Server HIGH 7.2
CVE-2012-1864

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Windows 2003 Server HIGH 7.2
CVE-2012-1865

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Windows 2003 Server HIGH 7.2
CVE-2012-1866

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Visio Viewer HIGH 9.3
CVE-2012-0018EPSS 25%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2012-05-09
.net Framework HIGH 9.3
CVE-2012-0160EPSS 23%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attack…

Mitigation only
Fix from $1,950 2012-05-09
.net Framework HIGH 9.3
CVE-2012-0161EPSS 22%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of pa…

Mitigation only
Fix from $1,950 2012-05-09
Office HIGH 9.3
CVE-2012-0165EPSS 25%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate recor…

Mitigation only
Fix from $1,950 2012-05-09
Office HIGH 9.3
CVE-2012-0167EPSS 29%

Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2012-05-09
.net Framework HIGH 9.3
CVE-2012-0163EPSS 38%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attack…

Mitigation only
Fix from $1,950 2012-04-10
Windows 7 HIGH 7.8
CVE-2012-0151 KEVEPSS 84%

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008…

Patch available
Fix from $1,950 2012-04-10
Forefront Unified Access Gateway MEDIUM 5.8
CVE-2012-0146EPSS 11%

Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users t…

Mitigation only
Fix from $1,600 2012-04-10
Publisher HIGH 9.3
CVE-2011-3410EPSS 29%

Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher fi…

Mitigation only
Fix from $1,950 2011-12-14
Forefront Unified Access Gateway MEDIUM 5.0
CVE-2011-2012EPSS 17%

Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo…

Mitigation only
Fix from $1,600 2011-10-12
Host Integration Server MEDIUM 5.0
CVE-2011-2007EPSS 24%

Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…

Mitigation only
Fix from $1,600 2011-10-12
Host Integration Server MEDIUM 5.0
CVE-2011-2008EPSS 21%

Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…

Mitigation only
Fix from $1,600 2011-10-12
Office HIGH 9.3
CVE-2011-1982EPSS 28%

Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allow…

Mitigation only
Fix from $1,950 2011-09-15
Excel HIGH 9.3
CVE-2011-1989EPSS 21%

Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2…

Mitigation only
Fix from $1,950 2011-09-15
Visio HIGH 9.3
CVE-2011-1979EPSS 22%

Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execut…

Mitigation only
Fix from $1,950 2011-08-10
Visio HIGH 9.3
CVE-2011-1972EPSS 22%

Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote…

Mitigation only
Fix from $1,950 2011-08-10
Windows 2003 Server HIGH 10.0
CVE-2011-1268EPSS 11%

The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1…

Mitigation only
Fix from $1,950 2011-06-16