Vulnerability index

Browse CVEs

203 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Windows 2003 Server HIGH 7.2
CVE-2011-1984EPSS 7%

WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over t…

Mitigation only
Fix from $1,950 2011-09-15
Windows 2003 Server HIGH 7.2
CVE-2011-1967

Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W…

Mitigation only
Fix from $1,950 2011-08-10
Windows 2003 Server HIGH 7.2
CVE-2011-1974EPSS 7%

NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly …

No fix yet
Fix from $1,950 2011-08-10
Windows 2003 Server HIGH 7.2
CVE-2011-1249EPSS 8%

The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Serve…

No fix yet
Fix from $1,950 2011-06-16
.net Framework HIGH 7.7
CVE-2011-1271EPSS 20%

The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle express…

No fix yet
Fix from $1,950 2011-05-10
Powerpoint HIGH 9.3
CVE-2011-0976EPSS 25%

Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pac…

Mitigation only
Fix from $1,950 2011-02-10
Excel HIGH 9.3
CVE-2011-0980EPSS 26%

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art obje…

Mitigation only
Fix from $1,950 2011-02-10
Windows 2003 Server HIGH 7.2
CVE-2010-3943

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Mitigation only
Fix from $1,950 2010-12-16
Windows 2003 Server HIGH 7.2
CVE-2010-2741

The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font p…

Mitigation only
Fix from $1,950 2010-10-13
Windows 2003 Server HIGH 7.2
CVE-2010-2744

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R…

No fix yet
Fix from $1,950 2010-10-13
Windows 2003 Server HIGH 7.2
CVE-2010-2740

The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font…

Mitigation only
Fix from $1,950 2010-10-13
Windows 2003 Server MEDIUM 6.8
CVE-2010-1886

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users…

Patch available
Fix from $1,600 2010-08-16
Windows 2003 Server HIGH 7.2
CVE-2010-1894

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified ex…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2003 Server HIGH 7.2
CVE-2010-1895

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory alloca…

Mitigation only
Fix from $1,950 2010-08-11
Open Xml File Format Converter MEDIUM 6.9
CVE-2010-1254

The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to ex…

Mitigation only
Fix from $1,600 2010-06-08
Windows Xp MEDIUM 6.4
CVE-2010-0812EPSS 17%

Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended I…

Mitigation only
Fix from $1,600 2010-04-14
Virtual Pc HIGH 9.3
CVE-2010-1225EPSS 28%

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server…

No fix yet
Fix from $1,950 2010-04-01
Windows 2000 HIGH 10.0
CVE-2010-0231EPSS 41%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Windows 2000 MEDIUM 6.9
CVE-2010-0023

The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes afte…

Mitigation only
Fix from $1,600 2010-02-10
Windows 2000 HIGH 9.3
CVE-2009-0090EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unint…

Mitigation only
Fix from $1,950 2009-10-14
Visual C\+\+ HIGH 8.8
CVE-2009-2493EPSS 38%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Patch available
Fix from $1,950 2009-07-29
Isa Server HIGH 9.0
CVE-2009-1135EPSS 26%

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…

Mitigation only
Fix from $1,950 2009-07-15
Virtual Pc HIGH 9.0
CVE-2009-1542EPSS 8%

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CP…

Mitigation only
Fix from $1,950 2009-07-15
Windows 2000 HIGH 10.0
CVE-2009-0568EPSS 32%

The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 do…

Mitigation only
Fix from $1,950 2009-06-10
Windows 2000 HIGH 9.0
CVE-2009-0230EPSS 35%

The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote…

Mitigation only
Fix from $1,950 2009-06-10
Xml Core Services MEDIUM 5.0
CVE-2009-0419EPSS 15%

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict a…

Mitigation only
Fix from $1,600 2009-02-04
Office Frontpage HIGH 8.5
CVE-2008-4252EPSS 21%

The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during acces…

Mitigation only
Fix from $1,950 2008-12-10
Windows 2003 Server HIGH 7.2
CVE-2008-3464

afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly va…

Patch available
Fix from $1,950 2008-10-15
Outlook Express HIGH 7.1
CVE-2008-1448EPSS 27%

The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Inter…

Patch available
Fix from $1,950 2008-08-13
Windows Nt HIGH 9.0
CVE-2008-1436EPSS 37%

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalSer…

No fix yet
Fix from $1,950 2008-04-21