Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Office MEDIUM 5.0
CVE-2014-2730EPSS 12%

The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity ex…

Mitigation only
Fix from $1,600 2014-04-05
Windows Media Player MEDIUM 6.8
CVE-2014-2671EPSS 46%

Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci…

No fix yet
Fix from $1,600 2014-03-31
Microsoft Forefront Protection 2010 HIGH 10.0
CVE-2014-0294EPSS 21%

Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2014-02-12
Internet Explorer HIGH 9.3
CVE-2014-0271EPSS 38%

The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or c…

Mitigation only
Fix from $1,950 2014-02-12
.net Framework HIGH 9.3
CVE-2014-0257EPSS 70%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method,…

No fix yet
Fix from $1,950 2014-02-12
.net Framework MEDIUM 5.0
CVE-2014-0253EPSS 39%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attac…

Mitigation only
Fix from $1,600 2014-02-12
Office Compatibility Pack HIGH 9.3
CVE-2014-0258EPSS 16%

Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a deni…

Mitigation only
Fix from $1,950 2014-01-15
Office Compatibility Pack HIGH 9.3
CVE-2014-0259EPSS 16%

Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corru…

Mitigation only
Fix from $1,950 2014-01-15
Office Compatibility Pack HIGH 9.3
CVE-2014-0260EPSS 15%

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP…

Mitigation only
Fix from $1,950 2014-01-15
Office Web Apps MEDIUM 6.8
CVE-2013-5059EPSS 11%

Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page c…

Mitigation only
Fix from $1,600 2013-12-11
Word HIGH 7.1
CVE-2013-6801EPSS 14%

Microsoft Word 2003 SP2 and SP3 on Windows XP SP3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed .doc file co…

No fix yet
Fix from $1,950 2013-11-18
Windows 7 HIGH 7.1
CVE-2013-3876EPSS 5%

DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S…

Mitigation only
Fix from $1,950 2013-11-18
Office HIGH 9.3
CVE-2013-0082EPSS 19%

Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD Fil…

Mitigation only
Fix from $1,950 2013-11-13
Office HIGH 9.3
CVE-2013-1324EPSS 31%

Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2013-11-13
Office HIGH 9.3
CVE-2013-1325EPSS 31%

Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect docu…

Mitigation only
Fix from $1,950 2013-11-13
Outlook MEDIUM 5.0
CVE-2013-3905EPSS 12%

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remo…

Mitigation only
Fix from $1,600 2013-11-13
Excel HIGH 9.3
CVE-2013-3889EPSS 27%

Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewe…

Mitigation only
Fix from $1,950 2013-10-09
Excel HIGH 9.3
CVE-2013-3890EPSS 20%

Microsoft Excel 2007 SP3, Excel Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office docum…

Mitigation only
Fix from $1,950 2013-10-09
Word HIGH 9.3
CVE-2013-3891EPSS 19%

Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."

Mitigation only
Fix from $1,950 2013-10-09
Word HIGH 9.3
CVE-2013-3892EPSS 20%

Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Memory…

Mitigation only
Fix from $1,950 2013-10-09
Office Web Apps MEDIUM 6.8
CVE-2013-3895EPSS 30%

Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parame…

Mitigation only
Fix from $1,600 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3860EPSS 32%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows…

Mitigation only
Fix from $1,950 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3861EPSS 83%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) vi…

Mitigation only
Fix from $1,950 2013-10-09
Internet Explorer HIGH 8.8
CVE-2013-3893 KEVEPSS 86%

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers …

Mitigation only
Fix from $1,950 2013-09-18
Sharepoint Foundation HIGH 10.0
CVE-2013-1330EPSS 27%

The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 d…

Mitigation only
Fix from $1,950 2013-09-11
Access HIGH 9.3
CVE-2013-3155EPSS 20%

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…

Mitigation only
Fix from $1,950 2013-09-11
Access HIGH 9.3
CVE-2013-3156EPSS 20%

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…

Mitigation only
Fix from $1,950 2013-09-11
Access HIGH 9.3
CVE-2013-3157EPSS 19%

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…

Mitigation only
Fix from $1,950 2013-09-11
Excel HIGH 9.3
CVE-2013-3158EPSS 19%

Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte…

Mitigation only
Fix from $1,950 2013-09-11
Sharepoint Foundation HIGH 9.3
CVE-2013-3847EPSS 21%

Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2…

Mitigation only
Fix from $1,950 2013-09-11