Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Atlas Framework MEDIUM 5.0
CVE-2007-2380EPSS 12%

The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote att…

Mitigation only
Fix from $1,600 2007-04-30
Windows MEDIUM 6.8
CVE-2007-2108EPSS 22%

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers …

Mitigation only
Fix from $1,600 2007-04-18
Windows 2000 HIGH 10.0
CVE-2007-1748EPSS 78%

Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP…

Mitigation only
Fix from $1,950 2007-04-13
Windows Nt MEDIUM 6.9
CVE-2007-1973

Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privil…

Mitigation only
Fix from $1,600 2007-04-11
Word HIGH 7.1
CVE-2007-1911EPSS 12%

Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documen…

No fix yet
Fix from $1,950 2007-04-10
Word MEDIUM 6.8
CVE-2007-1910EPSS 25%

Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arb…

No fix yet
Fix from $1,600 2007-04-10
Windows 2000 MEDIUM 6.8
CVE-2007-1912EPSS 11%

Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.

No fix yet
Fix from $1,600 2007-04-10
Content Management Server HIGH 10.0
CVE-2007-0938EPSS 46%

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which all…

Mitigation only
Fix from $1,950 2007-04-10
Windows 2000 HIGH 9.3
CVE-2007-1205EPSS 31%

Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remot…

Mitigation only
Fix from $1,950 2007-04-10
Windows 2000 HIGH 7.2
CVE-2007-1206

The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows V…

Mitigation only
Fix from $1,950 2007-04-10
Windows 2000 HIGH 7.2
CVE-2007-1215

Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local …

Mitigation only
Fix from $1,950 2007-04-04
Windows 2000 HIGH 7.1
CVE-2007-1211EPSS 29%

Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to c…

Mitigation only
Fix from $1,950 2007-04-04
Windows 2000 MEDIUM 6.6
CVE-2007-1212

Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local …

Mitigation only
Fix from $1,600 2007-04-04
Windows 2000 HIGH 9.3
CVE-2007-0038EPSS 73%

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2007-03-30
Windows 2000 HIGH 7.5
CVE-2007-1692EPSS 15%

The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote…

Mitigation only
Fix from $1,950 2007-03-26
All Windows HIGH 10.0
CVE-2007-1644EPSS 33%

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or conf…

No fix yet
Fix from $1,950 2007-03-24
Visual Studio .net HIGH 10.0
CVE-2007-1512EPSS 11%

Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP…

Mitigation only
Fix from $1,950 2007-03-20
Windows Explorer HIGH 7.1
CVE-2007-1347EPSS 30%

Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial…

No fix yet
Fix from $1,950 2007-03-08
Xbox 360 HIGH 7.2
CVE-2007-1221

The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a c…

Mitigation only
Fix from $1,950 2007-03-02
Xbox 360 MEDIUM 6.2
CVE-2007-1220

The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows atta…

Mitigation only
Fix from $1,600 2007-03-02
Ie MEDIUM 5.0
CVE-2006-7065EPSS 20%

Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet tha…

No fix yet
Fix from $1,600 2007-03-02
Publisher HIGH 10.0
CVE-2007-1117EPSS 18%

Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, relat…

No fix yet
Fix from $1,950 2007-02-27
Windows Explorer HIGH 7.1
CVE-2007-1090EPSS 16%

Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file…

Mitigation only
Fix from $1,950 2007-02-26
Isa Server HIGH 10.0
CVE-2006-7027EPSS 15%

Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remo…

Mitigation only
Fix from $1,950 2007-02-23
Ie MEDIUM 5.0
CVE-2006-7030EPSS 16%

Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly invol…

Mitigation only
Fix from $1,600 2007-02-23
Powerpoint HIGH 9.3
CVE-2007-0913EPSS 12%

Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as expl…

No fix yet
Fix from $1,950 2007-02-14
Internet Explorer HIGH 10.0
CVE-2007-0219EPSS 39%

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, …

Mitigation only
Fix from $1,950 2007-02-13
Internet Explorer HIGH 10.0
CVE-2007-0217EPSS 58%

The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server re…

Mitigation only
Fix from $1,950 2007-02-13
Internet Explorer HIGH 9.3
CVE-2006-4697EPSS 31%

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute …

Mitigation only
Fix from $1,950 2007-02-13
Office HIGH 9.3
CVE-2007-0208EPSS 30%

Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties…

Mitigation only
Fix from $1,950 2007-02-13