Microsoft
microsoft
14,964 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with an...Show more |
1Microsoft 14Live Meeting LyncOffice+11 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
1Microsoft 1Internet Explorer Apr 22, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensiti...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows...Show more |
1Microsoft 4Office Office Compatibility PackWord+1 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, Word 2010 SP2, Word 2013 SP1, Word 2013 R2 SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of se...Show more |
1Microsoft 4Excel Excel ViewerOffice Compatibility Pack+1 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vi...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 Mar 17, 2017 N/A· v4 5.4 MEDIUM· v3 2.9 LOW· v2 Microsoft Windows 10 1607 and Windows Server 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Hyper-V Network Switch Denial of Service Vulnerabilit...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not...Show more |
1Microsoft 1Internet Explorer May 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka...Show more |
1Microsoft 4Windows 10 Windows Server 2008Windows Server 2012+1 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a cra...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote...Show more |
The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Cor...Show more |
1Microsoft 2Windows Server 2008 Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle dynamic link library (DLL) loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execu...Show more |