Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

.net Framework HIGH 9.3
CVE-2013-0003EPSS 24%

Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.…

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 9.3
CVE-2013-0004EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, …

Mitigation only
Fix from $1,950 2013-01-09
Xml Core Services HIGH 9.3
CVE-2013-0007EPSS 32%

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-01-09
Xml Core Services HIGH 8.8
CVE-2013-0006EPSS 28%

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 7.8
CVE-2013-0005EPSS 32%

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Managem…

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 9.3
CVE-2013-0002EPSS 25%

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 …

Mitigation only
Fix from $1,950 2013-01-09
Windows 2003 Server HIGH 9.3
CVE-2012-2556EPSS 21%

The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se…

Mitigation only
Fix from $1,950 2012-12-12
Directx HIGH 9.3
CVE-2012-1537EPSS 23%

Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,…

Mitigation only
Fix from $1,950 2012-12-12
Excel HIGH 9.3
CVE-2012-1885EPSS 29%

Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack S…

Mitigation only
Fix from $1,950 2012-11-14
Excel HIGH 9.3
CVE-2012-1886EPSS 22%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Excel Viewer; and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute a…

Mitigation only
Fix from $1,950 2012-11-14
Excel HIGH 9.3
CVE-2012-1887EPSS 25%

Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers t…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-1895EPSS 23%

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which…

Mitigation only
Fix from $1,950 2012-11-14
Excel HIGH 9.3
CVE-2012-2543EPSS 26%

Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 an…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-4776EPSS 25%

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data th…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-4777EPSS 25%

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, wh…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 7.9
CVE-2012-2519

Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows lo…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework MEDIUM 5.0
CVE-2012-1896EPSS 24%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-11-14
Ftp Service MEDIUM 5.0
CVE-2012-2532EPSS 42%

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which a…

Mitigation only
Fix from $1,600 2012-11-14
Word Automation Services HIGH 9.3
CVE-2012-2528EPSS 22%

Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Aut…

Mitigation only
Fix from $1,950 2012-10-09
Works HIGH 9.3
CVE-2012-2550EPSS 22%

Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc fil…

Mitigation only
Fix from $1,950 2012-10-09
Word HIGH 9.3
CVE-2012-0182EPSS 68%

Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-10-09
Windows Phone 7 Firmware MEDIUM 5.9
CVE-2012-2993

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2012-09-18
Visio HIGH 9.3
CVE-2012-1888EPSS 24%

Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka…

Mitigation only
Fix from $1,950 2012-08-15
Internet Explorer HIGH 9.3
CVE-2012-2523EPSS 22%

Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2012-08-15
Office HIGH 9.3
CVE-2012-2524EPSS 20%

Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2012-08-15
Data Access Components CRITICAL 9.8
CVE-2012-1891EPSS 29%

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…

Mitigation only
Fix from $2,300 2012-07-10
Office MEDIUM 6.9
CVE-2012-1894

Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, …

Mitigation only
Fix from $1,600 2012-07-10
Windows 2003 Server HIGH 8.8
CVE-2012-0175EPSS 26%

The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gol…

Mitigation only
Fix from $1,950 2012-07-10
Office HIGH 7.8
CVE-2012-1854 KEVEPSS 21%

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for App…

Mitigation only
Fix from $1,950 2012-07-10
Sharepoint Server MEDIUM 6.8
CVE-2012-1862EPSS 11%

Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites a…

Mitigation only
Fix from $1,600 2012-07-10