Vulnerability index

Browse CVEs

312 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Office HIGH 9.3
CVE-2009-0559EPSS 29%

Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted E…

Mitigation only
Fix from $1,950 2009-06-10
Office HIGH 9.3
CVE-2009-1134EPSS 36%

Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerP…

Mitigation only
Fix from $1,950 2009-06-10
Office HIGH 7.8
CVE-2009-0557 KEVEPSS 59%

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and S…

Patch available
Fix from $1,950 2009-06-10
Office Powerpoint HIGH 9.3
CVE-2009-0222EPSS 32%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that …

Mitigation only
Fix from $1,950 2009-05-12
Office Powerpoint HIGH 9.3
CVE-2009-0223EPSS 28%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that …

Mitigation only
Fix from $1,950 2009-05-12
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-0224EPSS 30%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft …

Mitigation only
Fix from $1,950 2009-05-12
Office Powerpoint HIGH 9.3
CVE-2009-0225EPSS 31%

Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 nat…

Mitigation only
Fix from $1,950 2009-05-12
Office Powerpoint HIGH 9.3
CVE-2009-1128EPSS 27%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that …

Mitigation only
Fix from $1,950 2009-05-12
Directx HIGH 9.3
CVE-2009-0084EPSS 32%

Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or vi…

Mitigation only
Fix from $1,950 2009-04-15
Ie HIGH 9.3
CVE-2009-0552EPSS 29%

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allow…

Mitigation only
Fix from $1,950 2009-04-15
Office Powerpoint HIGH 8.8
CVE-2009-0556 KEVEPSS 68%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arb…

Patch available
Fix from $1,950 2009-04-03
Excel HIGH 8.8
CVE-2009-0238 KEVEPSS 43%

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, …

Mitigation only
Fix from $1,950 2009-02-25
Office HIGH 9.3
CVE-2008-4024EPSS 29%

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a craft…

Mitigation only
Fix from $1,950 2008-12-10
Windows 2000 CRITICAL 9.8
CVE-2008-4250 KEVEPSS 99%

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows rem…

Patch available
Fix from $2,300 2008-10-23
Organization Chart HIGH 9.3
CVE-2008-3956EPSS 13%

orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute…

No fix yet
Fix from $1,950 2008-09-11
Windows Media Player HIGH 9.3
CVE-2008-2253EPSS 30%

Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that i…

Mitigation only
Fix from $1,950 2008-09-11
Office HIGH 9.3
CVE-2008-3018EPSS 30%

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows rem…

Mitigation only
Fix from $1,950 2008-08-12
Windows Nt HIGH 9.3
CVE-2008-1435EPSS 29%

Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted s…

Mitigation only
Fix from $1,950 2008-07-08
Office Snapshot Viewer Activex MEDIUM 6.8
CVE-2008-2463EPSS 59%

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offi…

No fix yet
Fix from $1,600 2008-07-07
Internet Explorer MEDIUM 6.8
CVE-2008-2841EPSS 15%

Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary…

Fix: after 2.8.7b
Fix from $1,600 2008-06-24
Office HIGH 9.3
CVE-2008-0119EPSS 31%

Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to exe…

Mitigation only
Fix from $1,950 2008-05-13
Office HIGH 9.3
CVE-2008-1091EPSS 41%

Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attacke…

Mitigation only
Fix from $1,950 2008-05-13
Windows Embedded Compact HIGH 9.3
CVE-2008-2160EPSS 18%

Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-05-12
Windows 2000 HIGH 9.3
CVE-2008-0083EPSS 30%

The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Serve…

Patch available
Fix from $1,950 2008-04-08
Ie HIGH 9.3
CVE-2008-1085EPSS 32%

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a cr…

Patch available
Fix from $1,950 2008-04-08
Internet Explorer HIGH 9.3
CVE-2008-1086EPSS 31%

The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vist…

Patch available
Fix from $1,950 2008-04-08
Office HIGH 9.3
CVE-2008-1089EPSS 32%

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrar…

Patch available
Fix from $1,950 2008-04-08
Windows 2000 HIGH 7.2
CVE-2008-1084EPSS 7%

Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows loc…

Patch available
Fix from $1,950 2008-04-08
Biztalk Server HIGH 9.3
CVE-2007-1201EPSS 29%

Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2008-03-11
Office HIGH 9.3
CVE-2008-0110EPSS 32%

Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers …

Patch available
Fix from $1,950 2008-03-11