Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Windows 7 MEDIUM 5.0
CVE-2014-6355EPSS 34%

The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…

Mitigation only
Fix from $1,600 2014-12-11
Exchange Server MEDIUM 5.0
CVE-2014-6319EPSS 10%

Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requ…

Mitigation only
Fix from $1,600 2014-12-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6333EPSS 18%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office documen…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6334EPSS 17%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6335EPSS 16%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Active Directory Federation Services MEDIUM 5.0
CVE-2014-6331EPSS 20%

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not pr…

Mitigation only
Fix from $1,600 2014-11-11
.net Framework HIGH 9.3
CVE-2014-4149EPSS 21%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote…

Mitigation only
Fix from $1,950 2014-11-11
Internet Information Services MEDIUM 5.1
CVE-2014-4078EPSS 20%

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for doma…

Mitigation only
Fix from $1,600 2014-11-11
.net Framework HIGH 10.0
CVE-2014-4073EPSS 23%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, whi…

Mitigation only
Fix from $1,950 2014-10-15
.net Framework HIGH 10.0
CVE-2014-4121EPSS 19%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows r…

Mitigation only
Fix from $1,950 2014-10-15
Office HIGH 9.3
CVE-2014-4117EPSS 17%

Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Au…

Mitigation only
Fix from $1,950 2014-10-15
Nokia Asha 501 Software MEDIUM 6.6
CVE-2014-6602

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mech…

No fix yet
Fix from $1,600 2014-09-22
Office HIGH 9.3
CVE-2006-1318EPSS 15%

Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, wh…

Mitigation only
Fix from $1,950 2014-09-19
Lync Server MEDIUM 5.0
CVE-2014-4068EPSS 20%

The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, whic…

Mitigation only
Fix from $1,600 2014-09-10
Lync Server MEDIUM 5.0
CVE-2014-4071EPSS 19%

The Server in Microsoft Lync Server 2013 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon hang) via a crafte…

Mitigation only
Fix from $1,600 2014-09-10
.net Framework MEDIUM 5.0
CVE-2014-4072EPSS 31%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which a…

Mitigation only
Fix from $1,600 2014-09-10
Microsoft Tech Companion MEDIUM 5.4
CVE-2014-5711

The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in…

Mitigation only
Fix from $1,600 2014-09-09
Sql Server MEDIUM 6.8
CVE-2014-4061EPSS 26%

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which …

Mitigation only
Fix from $1,600 2014-08-12
Sharepoint Foundation HIGH 9.3
CVE-2014-2816EPSS 16%

Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a T…

Mitigation only
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-1767EPSS 13%

Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows …

No fix yet
Fix from $1,950 2014-07-08
Office Compatibility Pack HIGH 9.3
CVE-2014-2778EPSS 20%

Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corru…

Mitigation only
Fix from $1,950 2014-06-11
.net Framework HIGH 10.0
CVE-2014-1806EPSS 40%

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access…

Mitigation only
Fix from $1,950 2014-05-14
Office HIGH 9.3
CVE-2014-1756EPSS 9%

Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese P…

Mitigation only
Fix from $1,950 2014-05-14
Web Applications HIGH 8.5
CVE-2014-1813EPSS 10%

Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applicatio…

Mitigation only
Fix from $1,950 2014-05-14
Office MEDIUM 6.8
CVE-2014-1809EPSS 10%

The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypas…

Mitigation only
Fix from $1,600 2014-05-14
Office Web Apps Server HIGH 9.0
CVE-2014-0251EPSS 14%

Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 an…

Mitigation only
Fix from $1,950 2014-05-14
Internet Information Services MEDIUM 5.0
CVE-2011-5279EPSS 19%

CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 al…

No fix yet
Fix from $1,600 2014-04-23
Office Compatibility Pack HIGH 9.3
CVE-2014-1757EPSS 17%

Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory incorrectly for file conversions from a binary (aka…

Mitigation only
Fix from $1,950 2014-04-08
Word HIGH 9.3
CVE-2014-1758EPSS 17%

Stack-based buffer overflow in Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Word …

Mitigation only
Fix from $1,950 2014-04-08
Publisher HIGH 9.3
CVE-2014-1759EPSS 14%

pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect po…

Mitigation only
Fix from $1,950 2014-04-08