Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Windows 2000 HIGH 9.3
CVE-2009-2525EPSS 23%

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does …

Mitigation only
Fix from $1,950 2009-10-14
Windows Media Player HIGH 9.3
CVE-2009-2527EPSS 27%

Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) …

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-2528EPSS 20%

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-3126EPSS 23%

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 8.1
CVE-2009-2502EPSS 22%

Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 7.8
CVE-2009-2524EPSS 28%

Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, W…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2000 MEDIUM 6.8
CVE-2009-2510EPSS 5%

The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Ser…

Mitigation only
Fix from $1,600 2009-10-14
Windows 2000 HIGH 9.3
CVE-2009-0090EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unint…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2000 HIGH 9.3
CVE-2009-0091EPSS 26%

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows rem…

Mitigation only
Fix from $1,950 2009-10-14
Enterprise Library MEDIUM 5.0
CVE-2009-3275

Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows conte…

No fix yet
Fix from $1,600 2009-09-21
Windows Media Format Runtime HIGH 9.3
CVE-2009-2498EPSS 21%

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced S…

Mitigation only
Fix from $1,950 2009-09-08
Windows Media Format Runtime HIGH 8.5
CVE-2009-2499EPSS 16%

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows r…

Mitigation only
Fix from $1,950 2009-09-08
Isa Server HIGH 9.3
CVE-2009-0562EPSS 26%

The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, …

Mitigation only
Fix from $1,950 2009-08-12
Windows 2000 HIGH 9.3
CVE-2009-1923EPSS 25%

Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote att…

Mitigation only
Fix from $1,950 2009-08-12
Windows 2000 HIGH 9.3
CVE-2009-1924EPSS 9%

Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to exec…

Mitigation only
Fix from $1,950 2009-08-12
Biztalk Server HIGH 9.3
CVE-2009-2496EPSS 29%

Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Of…

Mitigation only
Fix from $1,950 2009-08-12
Windows 2003 Server HIGH 8.8
CVE-2009-1544EPSS 21%

Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC mess…

Mitigation only
Fix from $1,950 2009-08-12
Visual C\+\+ MEDIUM 6.5
CVE-2009-2495EPSS 34%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Mitigation only
Fix from $1,600 2009-07-29
Office Publisher HIGH 9.3
CVE-2009-0566EPSS 29%

Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2009-07-15
Isa Server HIGH 9.3
CVE-2009-1136EPSS 62%

The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP …

No fix yet
Fix from $1,950 2009-07-15
Directx HIGH 9.3
CVE-2009-1538EPSS 27%

The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and …

Mitigation only
Fix from $1,950 2009-07-15
Directx HIGH 9.3
CVE-2009-1539EPSS 26%

The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and …

Mitigation only
Fix from $1,950 2009-07-15
Isa Server HIGH 9.0
CVE-2009-1135EPSS 26%

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…

Mitigation only
Fix from $1,950 2009-07-15
Virtual Pc HIGH 9.0
CVE-2009-1542EPSS 8%

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CP…

Mitigation only
Fix from $1,950 2009-07-15
Windows 2003 Server HIGH 8.8
CVE-2008-0015 KEVEPSS 77%

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX…

Mitigation only
Fix from $1,950 2009-07-07
Ie MEDIUM 5.8
CVE-2009-2069

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which a…

Mitigation only
Fix from $1,600 2009-06-15
Ie MEDIUM 5.8
CVE-2009-2057

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT respon…

No fix yet
Fix from $1,600 2009-06-15
Office Powerpoint HIGH 9.3
CVE-2009-0202EPSS 24%

Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to …

Mitigation only
Fix from $1,950 2009-06-11
Office HIGH 9.3
CVE-2009-0549EPSS 28%

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Mic…

Mitigation only
Fix from $1,950 2009-06-10
Office HIGH 9.3
CVE-2009-0558EPSS 31%

Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote a…

Mitigation only
Fix from $1,950 2009-06-10