Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Excel HIGH 9.3
CVE-2010-3235EPSS 21%

Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel …

Mitigation only
Fix from $1,950 2010-10-13
Excel HIGH 9.3
CVE-2010-3236EPSS 21%

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record infor…

Mitigation only
Fix from $1,950 2010-10-13
Excel HIGH 9.3
CVE-2010-3237EPSS 21%

Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2010-10-13
Excel HIGH 9.3
CVE-2010-3238EPSS 21%

Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attack…

Mitigation only
Fix from $1,950 2010-10-13
Windows Server 2003 HIGH 9.3
CVE-2010-2738EPSS 19%

The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2,…

Mitigation only
Fix from $1,950 2010-09-15
Windows 2003 Server HIGH 9.3
CVE-2010-2566EPSS 15%

The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certi…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2003 Server HIGH 10.0
CVE-2010-2550EPSS 76%

The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Wi…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2003 Server HIGH 8.4
CVE-2010-1896

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Se…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2003 Server HIGH 7.2
CVE-2010-1897

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2000 HIGH 7.8
CVE-2010-0485

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and…

Mitigation only
Fix from $1,950 2010-06-08
Windows 2000 MEDIUM 6.8
CVE-2010-0484

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold…

Mitigation only
Fix from $1,600 2010-06-08
Windows 2000 HIGH 7.2
CVE-2010-0819

Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vi…

Mitigation only
Fix from $1,950 2010-06-08
Windows 2000 MEDIUM 6.4
CVE-2010-1690EPSS 7%

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003…

Patch available
Fix from $1,600 2010-05-07
Windows 7 HIGH 9.3
CVE-2010-0486EPSS 22%

The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows S…

Mitigation only
Fix from $1,950 2010-04-14
Windows 7 HIGH 9.3
CVE-2010-0487EPSS 24%

The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 20…

Mitigation only
Fix from $1,950 2010-04-14
Windows 2000 MEDIUM 5.0
CVE-2010-0024EPSS 11%

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, d…

Patch available
Fix from $1,600 2010-04-14
Windows 2000 HIGH 7.8
CVE-2010-0022EPSS 78%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Windows 2000 HIGH 9.0
CVE-2010-0020EPSS 32%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Internet Information Services MEDIUM 6.0
CVE-2009-4445EPSS 13%

Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to …

Fix: after 6.0
Fix from $1,600 2009-12-29
Windows 2000 HIGH 7.2
CVE-2009-1127

win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does …

Mitigation only
Fix from $1,950 2009-11-11
Windows 2000 HIGH 7.2
CVE-2009-2513

The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and …

Mitigation only
Fix from $1,950 2009-11-11
Sharepoint Server MEDIUM 5.0
CVE-2009-3830EPSS 33%

The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read AS…

No fix yet
Fix from $1,600 2009-10-30
Directx HIGH 9.3
CVE-2009-1538EPSS 27%

The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and …

Mitigation only
Fix from $1,950 2009-07-15
Office Converter Pack HIGH 9.3
CVE-2009-0088EPSS 28%

The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly vali…

Mitigation only
Fix from $1,950 2009-04-15
Windows Live Messenger MEDIUM 5.0
CVE-2009-0647EPSS 17%

msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,600 2009-02-19
Exchange Server MEDIUM 5.0
CVE-2009-0099EPSS 26%

The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used i…

Mitigation only
Fix from $1,600 2009-02-10
Digital Image MEDIUM 6.8
CVE-2008-4493EPSS 18%

Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to…

No fix yet
Fix from $1,600 2008-10-08
Windows Mobile MEDIUM 5.4
CVE-2008-4295EPSS 30%

Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection …

No fix yet
Fix from $1,600 2008-09-27
Windows Image Acquisition Logger HIGH 9.3
CVE-2008-3957EPSS 18%

The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system …

No fix yet
Fix from $1,950 2008-09-11
Office HIGH 9.3
CVE-2008-3007EPSS 32%

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2…

Mitigation only
Fix from $1,950 2008-09-11