Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows Nt HIGH 9.0
CVE-2008-1456EPSS 28%

Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server …

Patch available
Fix from $1,950 2008-08-13
Windows Nt HIGH 9.0
CVE-2008-1457EPSS 36%

The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly valida…

Patch available
Fix from $1,950 2008-08-13
Office HIGH 9.3
CVE-2008-3004EPSS 32%

Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3; Office Excel Viewer 2003; and Office 2004 and 2008 for Mac do not properly validate …

Mitigation only
Fix from $1,950 2008-08-12
Office HIGH 9.3
CVE-2008-3005EPSS 32%

Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-08-12
Office MEDIUM 6.6
CVE-2008-3003

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not …

Mitigation only
Fix from $1,600 2008-08-12
Windows Nt HIGH 8.3
CVE-2008-1453

The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via …

Patch available
Fix from $1,950 2008-06-12
Windows 2000 HIGH 7.2
CVE-2008-1451

The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, whic…

Patch available
Fix from $1,950 2008-06-12
Windows Nt HIGH 7.1
CVE-2008-1445EPSS 27%

Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authentica…

Patch available
Fix from $1,950 2008-06-12
Office HIGH 9.3
CVE-2008-1898EPSS 52%

A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attacker…

No fix yet
Fix from $1,950 2008-04-21
Excel HIGH 9.3
CVE-2008-0116EPSS 48%

Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to…

Patch available
Fix from $1,950 2008-03-11
Office HIGH 9.3
CVE-2007-0216EPSS 38%

wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2008-02-12
Office HIGH 9.3
CVE-2008-0105EPSS 44%

Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2008-02-12
Windows 2000 MEDIUM 6.8
CVE-2008-0088EPSS 29%

Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP a…

Mitigation only
Fix from $1,600 2008-02-12
Rich Textbox Control MEDIUM 6.8
CVE-2008-0237EPSS 20%

The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure Sa…

No fix yet
Fix from $1,600 2008-01-11
Publisher MEDIUM 6.8
CVE-2007-6534EPSS 11%

Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application cra…

Mitigation only
Fix from $1,600 2007-12-27
Windows Media Player HIGH 7.5
CVE-2007-5095EPSS 15%

Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regard…

Mitigation only
Fix from $1,950 2007-09-26
Msn Messenger HIGH 9.3
CVE-2007-2931EPSS 55%

Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbi…

No fix yet
Fix from $1,950 2007-08-31
Visual Basic HIGH 9.3
CVE-2007-2884EPSS 36%

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption)…

No fix yet
Fix from $1,950 2007-05-30
Exchange Server HIGH 10.0
CVE-2007-0213EPSS 66%

Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers t…

Patch available
Fix from $1,950 2007-05-08
Word MEDIUM 6.8
CVE-2007-1202EPSS 29%

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse cert…

Patch available
Fix from $1,600 2007-05-08
Office HIGH 9.3
CVE-2007-0035EPSS 32%

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle dat…

Mitigation only
Fix from $1,950 2007-05-08
Office HIGH 9.3
CVE-2007-0208EPSS 30%

Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties…

Mitigation only
Fix from $1,950 2007-02-13
Excel HIGH 9.3
CVE-2007-0028EPSS 33%

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows use…

Patch available
Fix from $1,950 2007-01-09
Dynamics Gp MEDIUM 5.0
CVE-2006-5265EPSS 10%

Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (cras…

Fix: after 9.0
Fix from $1,600 2006-12-31
Data Access Components HIGH 9.3
CVE-2006-5559EPSS 42%

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data …

Patch available
Fix from $1,950 2006-10-27
Ie MEDIUM 5.0
CVE-2006-4301EPSS 39%

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media…

No fix yet
Fix from $1,600 2006-08-23
Ie HIGH 7.5
CVE-2006-3450EPSS 41%

Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access cr…

Patch available
Fix from $1,950 2006-08-08
Ie HIGH 7.5
CVE-2006-3451EPSS 41%

Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a c…

Patch available
Fix from $1,950 2006-08-08
Windows 2000 HIGH 7.8
CVE-2006-3942EPSS 75%

The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash…

Mitigation only
Fix from $1,950 2006-07-31
Excel MEDIUM 5.1
CVE-2006-3014EPSS 30%

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an…

Patch available
Fix from $1,600 2006-06-22