Vulnerability index

Browse CVEs

203 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Windows 7 HIGH 7.2
CVE-2015-0002EPSS 14%

The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, …

No fix yet
Fix from $1,950 2015-01-13
Active Directory Federation Services MEDIUM 5.0
CVE-2014-6331EPSS 20%

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not pr…

Mitigation only
Fix from $1,600 2014-11-11
Internet Information Services MEDIUM 5.1
CVE-2014-4078EPSS 20%

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for doma…

Mitigation only
Fix from $1,600 2014-11-11
.net Framework HIGH 10.0
CVE-2014-4073EPSS 23%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, whi…

Mitigation only
Fix from $1,950 2014-10-15
Nokia Asha 501 Software MEDIUM 6.6
CVE-2014-6602

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mech…

No fix yet
Fix from $1,600 2014-09-22
Windows 8 HIGH 7.2
CVE-2014-4074

The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privi…

Patch available
Fix from $1,950 2014-09-10
Sharepoint Foundation HIGH 9.3
CVE-2014-2816EPSS 16%

Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a T…

Mitigation only
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-0318

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-1814

The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows …

Patch available
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-1819

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.6
CVE-2014-2781EPSS 6%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2014-07-08
Windows 7 HIGH 7.2
CVE-2014-1807

The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-05-14
Office MEDIUM 6.8
CVE-2014-1809EPSS 10%

The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypas…

Mitigation only
Fix from $1,600 2014-05-14
Windows 7 HIGH 7.2
CVE-2014-0300

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…

Patch available
Fix from $1,950 2014-03-12
Office Web Apps MEDIUM 6.8
CVE-2013-3895EPSS 23%

Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parame…

Mitigation only
Fix from $1,600 2013-10-09
Office MEDIUM 6.9
CVE-2013-3859

Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows lo…

Mitigation only
Fix from $1,600 2013-09-11
Windows Defender MEDIUM 6.9
CVE-2013-3154

The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allow…

Mitigation only
Fix from $1,600 2013-07-10
Windows Essentials MEDIUM 6.8
CVE-2013-0096EPSS 16%

Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL p…

Mitigation only
Fix from $1,600 2013-05-15
Sharepoint Foundation HIGH 7.5
CVE-2013-0080EPSS 19%

Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and …

Mitigation only
Fix from $1,950 2013-03-13
.net Framework HIGH 10.0
CVE-2013-0073EPSS 30%

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a…

Mitigation only
Fix from $1,950 2013-02-13
.net Framework HIGH 9.3
CVE-2012-1895EPSS 23%

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-4777EPSS 25%

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, wh…

Mitigation only
Fix from $1,950 2012-11-14
Office MEDIUM 6.9
CVE-2012-1894

Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, …

Mitigation only
Fix from $1,600 2012-07-10
Office Web Apps MEDIUM 5.5
CVE-2012-1860EPSS 13%

Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check…

Mitigation only
Fix from $1,600 2012-07-10
Excel HIGH 9.3
CVE-2012-0184EPSS 24%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and …

Mitigation only
Fix from $1,950 2012-05-09
Excel HIGH 9.3
CVE-2012-0185EPSS 25%

Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows …

Mitigation only
Fix from $1,950 2012-05-09
Excel HIGH 9.3
CVE-2012-1847EPSS 25%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and …

Mitigation only
Fix from $1,950 2012-05-09
Pinyin Ime HIGH 7.2
CVE-2011-2010

The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office P…

Mitigation only
Fix from $1,950 2011-12-14
Ie MEDIUM 5.0
CVE-2010-5071EPSS 13%

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object ret…

Fix: after 8
Fix from $1,600 2011-12-07
.net Framework HIGH 9.3
CVE-2011-1253EPSS 13%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which a…

Mitigation only
Fix from $1,950 2011-10-12