Vulnerability index

Browse CVEs

377 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Internet Explorer MEDIUM 6.5
CVE-2013-7331 KEVEPSS 58%

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC …

Patch available
Fix from $1,600 2014-02-26
Internet Explorer HIGH 8.8
CVE-2014-0322 KEVEPSS 85%

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted …

Patch available
Fix from $1,950 2014-02-14
Windows 10 1507 MEDIUM 5.5
CVE-2013-3900 KEVEPSS 45%

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table an…

Patch available
Fix from $1,600 2013-12-11
Windows 2003 Server HIGH 7.8
CVE-2013-5065 KEVEPSS 35%

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as…

Patch available
Fix from $1,950 2013-11-28
Windows 7 HIGH 8.8
CVE-2013-3918 KEVEPSS 74%

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,…

Patch available
Fix from $1,950 2013-11-12
Excel Viewer HIGH 7.8
CVE-2013-3906 KEVEPSS 85%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 201…

Patch available
Fix from $1,950 2013-11-06
Internet Explorer HIGH 8.8
CVE-2013-3897 KEVEPSS 77%

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execut…

Patch available
Fix from $1,950 2013-10-09
Silverlight MEDIUM 5.5
CVE-2013-3896 KEVEPSS 70%

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers t…

Fix: 5.1.20913.0+
Fix from $1,600 2013-10-09
Internet Explorer HIGH 8.8
CVE-2013-3893 KEVEPSS 86%

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers …

Mitigation only
Fix from $1,950 2013-09-18
Internet Explorer HIGH 8.8
CVE-2013-3163 KEVEPSS 71%

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra…

Patch available
Fix from $1,950 2013-07-10
Office HIGH 7.8
CVE-2013-1331 KEVEPSS 82%

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Off…

Patch available
Fix from $1,950 2013-06-12
Windows 7 HIGH 7.8
CVE-2013-3660 KEVEPSS 40%

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V…

Patch available
Fix from $1,950 2013-05-24
Internet Explorer HIGH 8.8
CVE-2013-1347 KEVEPSS 78%

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an obj…

Patch available
Fix from $1,950 2013-05-05
Silverlight HIGH 7.8
CVE-2013-0074 KEVEPSS 82%

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows r…

Fix: 5.1.20125.0+
Fix from $1,950 2013-03-13
Internet Explorer HIGH 8.8
CVE-2013-2551 KEVEPSS 74%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site tha…

Patch available
Fix from $1,950 2013-03-11
Internet Explorer HIGH 8.8
CVE-2012-4792 KEVEPSS 79%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that…

Patch available
Fix from $1,950 2012-12-30
Office Compatibility Pack HIGH 7.8
CVE-2012-2539 KEVEPSS 53%

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remot…

Patch available
Fix from $1,950 2012-12-12
Internet Explorer HIGH 8.1
CVE-2012-4969 KEVEPSS 82%

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to exec…

Patch available
Fix from $1,950 2012-09-18
Commerce Server HIGH 8.8
CVE-2012-1856 KEVEPSS 62%

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and…

Patch available
Fix from $1,950 2012-08-15
Office HIGH 7.8
CVE-2012-1854 KEVEPSS 21%

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for App…

Mitigation only
Fix from $1,950 2012-07-10
Xml Core Services HIGH 8.8
CVE-2012-1889 KEVEPSS 84%

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code o…

Patch available
Fix from $1,950 2012-06-13
Office HIGH 8.8
CVE-2012-0158 KEVEPSS 100%

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3…

Patch available
Fix from $1,950 2012-04-10
Windows 7 HIGH 7.8
CVE-2012-0151 KEVEPSS 84%

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008…

Patch available
Fix from $1,950 2012-04-10
Windows 7 HIGH 8.8
CVE-2011-3402 KEVEPSS 78%

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows S…

Mitigation only
Fix from $1,950 2011-11-04
Windows Server 2003 HIGH 7.8
CVE-2011-2005 KEVEPSS 32%

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to…

Patch available
Fix from $1,950 2011-10-12
Forefront Threat Management Gateway CRITICAL 9.8
CVE-2011-1889 KEVEPSS 48%

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitr…

Patch available
Fix from $2,300 2011-06-16
Windows 7 HIGH 7.8
CVE-2010-4398 KEVEPSS 9%

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Window…

Patch available
Fix from $1,950 2010-12-06
Office HIGH 7.8
CVE-2010-3333 KEVEPSS 89%

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2…

Patch available
Fix from $1,950 2010-11-10
Powerpoint HIGH 7.8
CVE-2010-2572 KEVEPSS 63%

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,…

Patch available
Fix from $1,950 2010-11-10
Internet Explorer HIGH 8.1
CVE-2010-3962 KEVEPSS 96%

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Casc…

Patch available
Fix from $1,950 2010-11-05