Vulnerability index

Browse CVEs

409 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2016-3271EPSS 21% The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Script… Edge Mitigation only Fix from $1,6002016-07-13 MEDIUM 5.0 CVE-2016-3256 Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a cr… Windows 10 Mitigation only Fix from $1,6002016-07-13 HIGH 7.5 CVE-2016-3255EPSS 25% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an extern… .net Framework Mitigation only Fix from $1,9502016-07-13 MEDIUM 5.5 CVE-2016-3234EPSS 24% Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 20… Office Mitigation only Fix from $1,6002016-06-16 MEDIUM 5.5 CVE-2016-3215EPSS 34% Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information fr… Windows 10 Patch available Fix from $1,6002016-06-16 MEDIUM 6.5 CVE-2016-3201EPSS 24% Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive infor… Edge Mitigation only Fix from $1,6002016-06-16 MEDIUM 5.5 CVE-2016-0028EPSS 23% Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 … Outlook Web Access Mitigation only Fix from $1,6002016-06-16 MEDIUM 5.5 CVE-2016-0190 Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB … Windows 8.1 Mitigation only Fix from $1,6002016-05-11 MEDIUM 6.5 CVE-2016-0169EPSS 43% GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, … Windows 10 No fix yet Fix from $1,6002016-05-11 MEDIUM 6.5 CVE-2016-0168EPSS 43% GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, … Windows 10 No fix yet Fix from $1,6002016-05-11 MEDIUM 5.9 CVE-2016-0149EPSS 8% Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext informa… .net Framework Mitigation only Fix from $1,6002016-05-11 HIGH 7.1 CVE-2016-0090 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory vi… Windows 10 Mitigation only Fix from $1,9502016-04-12 HIGH 7.1 CVE-2016-0089 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS … Windows 10 Mitigation only Fix from $1,9502016-04-12 HIGH 7.5 CVE-2016-0047EPSS 21% WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process … .net Framework Mitigation only Fix from $1,9502016-02-10 MEDIUM 5.0 CVE-2015-6135EPSS 23% The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remot… Jscript Mitigation only Fix from $1,6002015-12-09 MEDIUM 5.0 CVE-2015-6057EPSS 16% Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Di… Edge Mitigation only Fix from $1,6002015-10-14 MEDIUM 5.0 CVE-2015-2505EPSS 18% Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace i… Exchange Server Mitigation only Fix from $1,6002015-09-09 MEDIUM 5.0 CVE-2015-1716EPSS 21% Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows … Windows 7 Patch available Fix from $1,6002015-05-13 MEDIUM 5.0 CVE-2015-0089EPSS 21% Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,… Windows 7 Patch available Fix from $1,6002015-03-11 MEDIUM 5.0 CVE-2015-0087EPSS 23% Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,… Windows 7 Patch available Fix from $1,6002015-03-11 MEDIUM 5.0 CVE-2014-6355EPSS 34% The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows… Windows 7 Mitigation only Fix from $1,6002014-12-11 MEDIUM 6.6 CVE-2014-0323 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2… Windows 7 Patch available Fix from $1,6002014-03-12 HIGH 7.1 CVE-2014-0266EPSS 19% The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server… Windows 7 Patch available Fix from $1,9502014-02-12 MEDIUM 5.0 CVE-2013-3905EPSS 12% Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remo… Outlook Mitigation only Fix from $1,6002013-11-13 MEDIUM 5.0 CVE-2013-3160EPSS 23% Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML documen… Office Mitigation only Fix from $1,6002013-09-11 MEDIUM 5.0 CVE-2013-3185EPSS 41% Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows… Active Directory Federation Services Mitigation only Fix from $1,6002013-08-14 MEDIUM 5.0 CVE-2013-0095EPSS 21% Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote UR… Office Mitigation only Fix from $1,6002013-03-13 MEDIUM 5.0 CVE-2012-1896EPSS 24% Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers … .net Framework Mitigation only Fix from $1,6002012-11-14 MEDIUM 5.0 CVE-2012-2532EPSS 42% Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which a… Ftp Service Mitigation only Fix from $1,6002012-11-14 MEDIUM 5.0 CVE-2010-0025EPSS 21% The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, d… Windows 2000 Patch available Fix from $1,6002010-04-14