Vulnerability index

Browse CVEs

409 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Edge MEDIUM 6.5
CVE-2016-3271EPSS 21%

The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Script…

Mitigation only
Fix from $1,600 2016-07-13
Windows 10 MEDIUM 5.0
CVE-2016-3256

Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a cr…

Mitigation only
Fix from $1,600 2016-07-13
.net Framework HIGH 7.5
CVE-2016-3255EPSS 25%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an extern…

Mitigation only
Fix from $1,950 2016-07-13
Office MEDIUM 5.5
CVE-2016-3234EPSS 24%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 20…

Mitigation only
Fix from $1,600 2016-06-16
Windows 10 MEDIUM 5.5
CVE-2016-3215EPSS 34%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information fr…

Patch available
Fix from $1,600 2016-06-16
Edge MEDIUM 6.5
CVE-2016-3201EPSS 24%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive infor…

Mitigation only
Fix from $1,600 2016-06-16
Outlook Web Access MEDIUM 5.5
CVE-2016-0028EPSS 23%

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 …

Mitigation only
Fix from $1,600 2016-06-16
Windows 8.1 MEDIUM 5.5
CVE-2016-0190

Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB …

Mitigation only
Fix from $1,600 2016-05-11
Windows 10 MEDIUM 6.5
CVE-2016-0169EPSS 43%

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

No fix yet
Fix from $1,600 2016-05-11
Windows 10 MEDIUM 6.5
CVE-2016-0168EPSS 43%

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

No fix yet
Fix from $1,600 2016-05-11
.net Framework MEDIUM 5.9
CVE-2016-0149EPSS 8%

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext informa…

Mitigation only
Fix from $1,600 2016-05-11
Windows 10 HIGH 7.1
CVE-2016-0090

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory vi…

Mitigation only
Fix from $1,950 2016-04-12
Windows 10 HIGH 7.1
CVE-2016-0089

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS …

Mitigation only
Fix from $1,950 2016-04-12
.net Framework HIGH 7.5
CVE-2016-0047EPSS 21%

WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process …

Mitigation only
Fix from $1,950 2016-02-10
Jscript MEDIUM 5.0
CVE-2015-6135EPSS 23%

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remot…

Mitigation only
Fix from $1,600 2015-12-09
Edge MEDIUM 5.0
CVE-2015-6057EPSS 16%

Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Di…

Mitigation only
Fix from $1,600 2015-10-14
Exchange Server MEDIUM 5.0
CVE-2015-2505EPSS 18%

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace i…

Mitigation only
Fix from $1,600 2015-09-09
Windows 7 MEDIUM 5.0
CVE-2015-1716EPSS 21%

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …

Patch available
Fix from $1,600 2015-05-13
Windows 7 MEDIUM 5.0
CVE-2015-0089EPSS 21%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,600 2015-03-11
Windows 7 MEDIUM 5.0
CVE-2015-0087EPSS 23%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,600 2015-03-11
Windows 7 MEDIUM 5.0
CVE-2014-6355EPSS 34%

The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…

Mitigation only
Fix from $1,600 2014-12-11
Windows 7 MEDIUM 6.6
CVE-2014-0323

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…

Patch available
Fix from $1,600 2014-03-12
Windows 7 HIGH 7.1
CVE-2014-0266EPSS 19%

The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server…

Patch available
Fix from $1,950 2014-02-12
Outlook MEDIUM 5.0
CVE-2013-3905EPSS 12%

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remo…

Mitigation only
Fix from $1,600 2013-11-13
Office MEDIUM 5.0
CVE-2013-3160EPSS 23%

Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML documen…

Mitigation only
Fix from $1,600 2013-09-11
Active Directory Federation Services MEDIUM 5.0
CVE-2013-3185EPSS 41%

Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows…

Mitigation only
Fix from $1,600 2013-08-14
Office MEDIUM 5.0
CVE-2013-0095EPSS 21%

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote UR…

Mitigation only
Fix from $1,600 2013-03-13
.net Framework MEDIUM 5.0
CVE-2012-1896EPSS 24%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-11-14
Ftp Service MEDIUM 5.0
CVE-2012-2532EPSS 42%

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which a…

Mitigation only
Fix from $1,600 2012-11-14
Windows 2000 MEDIUM 5.0
CVE-2010-0025EPSS 21%

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, d…

Patch available
Fix from $1,600 2010-04-14