Vulnerability index

Browse CVEs

312 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Windows 7 HIGH 9.3
CVE-2015-1696EPSS 18%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1695EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1675EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 CRITICAL 9.8
CVE-2015-1635 KEVEPSS 100%

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers …

Patch available
Fix from $2,300 2015-04-14
Windows 7 HIGH 9.3
CVE-2015-0093EPSS 21%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0092EPSS 17%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0091EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0090EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0088EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Excel HIGH 9.3
CVE-2014-6361EPSS 13%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers t…

Mitigation only
Fix from $1,950 2014-12-11
Excel HIGH 9.3
CVE-2014-6360EPSS 13%

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office documen…

Mitigation only
Fix from $1,950 2014-12-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6356EPSS 12%

Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2014-12-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6333EPSS 18%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office documen…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6334EPSS 17%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6335EPSS 16%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Windows 7 HIGH 10.0
CVE-2014-6321EPSS 96%

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …

Patch available
Fix from $1,950 2014-11-11
Windows 7 HIGH 9.3
CVE-2014-4118EPSS 14%

XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows…

Patch available
Fix from $1,950 2014-11-11
Windows 7 HIGH 8.8
CVE-2014-4148 KEVEPSS 60%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-10-15
Office HIGH 9.3
CVE-2006-1318EPSS 15%

Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, wh…

Mitigation only
Fix from $1,950 2014-09-19
Windows 7 HIGH 9.3
CVE-2014-1824EPSS 19%

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…

Patch available
Fix from $1,950 2014-07-08
.net Framework HIGH 10.0
CVE-2014-1806EPSS 40%

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access…

Mitigation only
Fix from $1,950 2014-05-14
Web Applications HIGH 8.5
CVE-2014-1813EPSS 10%

Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applicatio…

Mitigation only
Fix from $1,950 2014-05-14
Office Web Apps Server HIGH 9.0
CVE-2014-0251EPSS 13%

Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 an…

Mitigation only
Fix from $1,950 2014-05-14
Microsoft Forefront Protection 2010 HIGH 10.0
CVE-2014-0294EPSS 21%

Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2014-02-12
Bing MEDIUM 6.8
CVE-2014-1670EPSS 14%

The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vectors involving a crafted DNS re…

Fix: after 4.2.0
Fix from $1,600 2014-01-25
Office Web Apps MEDIUM 6.8
CVE-2013-5059EPSS 11%

Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page c…

Mitigation only
Fix from $1,600 2013-12-11
Excel Viewer HIGH 7.8
CVE-2013-3906 KEVEPSS 85%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 201…

Patch available
Fix from $1,950 2013-11-06
.net Framework HIGH 9.3
CVE-2013-3132EPSS 22%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, wh…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3133EPSS 21%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote …

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3134EPSS 21%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays o…

Mitigation only
Fix from $1,950 2013-07-10