Vulnerability index

Browse CVEs

312 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
.net Framework HIGH 9.3
CVE-2013-3171EPSS 21%

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of deleg…

Mitigation only
Fix from $1,950 2013-07-10
Windows Media Format Runtime HIGH 9.3
CVE-2013-3127EPSS 22%

The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3131EPSS 22%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidim…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 7.8
CVE-2013-3129EPSS 32%

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWr…

Mitigation only
Fix from $1,950 2013-07-10
Publisher HIGH 9.3
CVE-2013-1323EPSS 21%

Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-05-15
Word HIGH 9.3
CVE-2013-1335EPSS 21%

Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape C…

Mitigation only
Fix from $1,950 2013-05-15
Remote Desktop Connection HIGH 9.3
CVE-2013-1296EPSS 21%

The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memor…

Mitigation only
Fix from $1,950 2013-04-09
Xml Core Services HIGH 9.3
CVE-2013-0007EPSS 32%

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-01-09
Windows 2003 Server HIGH 9.3
CVE-2012-2556EPSS 21%

The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se…

Mitigation only
Fix from $1,950 2012-12-12
Word HIGH 9.3
CVE-2012-0182EPSS 68%

Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-10-09
Windows 2003 Server HIGH 8.8
CVE-2012-0175EPSS 26%

The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gol…

Mitigation only
Fix from $1,950 2012-07-10
.net Framework HIGH 9.3
CVE-2012-1855EPSS 20%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2012-06-12
Office HIGH 8.8
CVE-2012-0158 KEVEPSS 100%

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3…

Patch available
Fix from $1,950 2012-04-10
.net Framework HIGH 9.3
CVE-2012-0015EPSS 24%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute …

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0019EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0020EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0136EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0137EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0138EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
.net Framework HIGH 7.8
CVE-2012-0014EPSS 28%

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unman…

Mitigation only
Fix from $1,950 2012-02-14
Publisher HIGH 9.3
CVE-2011-1508EPSS 14%

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted rem…

Mitigation only
Fix from $1,950 2011-12-14
Excel HIGH 9.3
CVE-2011-3403EPSS 21%

Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2011-12-14
Publisher HIGH 9.3
CVE-2011-3411EPSS 27%

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of valu…

Mitigation only
Fix from $1,950 2011-12-14
Publisher HIGH 9.3
CVE-2011-3412EPSS 26%

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages inc…

Mitigation only
Fix from $1,950 2011-12-14
Office HIGH 9.3
CVE-2011-3413EPSS 20%

Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint V…

Mitigation only
Fix from $1,950 2011-12-14
Forefront Unified Access Gateway HIGH 9.3
CVE-2011-1969EPSS 17%

Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Jav…

Mitigation only
Fix from $1,950 2011-10-12
Visio HIGH 9.3
CVE-2011-0092EPSS 24%

The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2011-02-10
Visio HIGH 9.3
CVE-2011-0093EPSS 20%

ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows …

Mitigation only
Fix from $1,950 2011-02-10
Wmi Administrative Tools HIGH 9.3
CVE-2010-3973EPSS 72%

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and …

Fix: after 1.1
Fix from $1,950 2010-12-23
Wmi Administrative Tools HIGH 9.3
CVE-2010-4588EPSS 33%

The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary…

Fix: after 1.1
Fix from $1,950 2010-12-23