Microsoft
microsoft
14,964 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Office Office Compatibility PackWordMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "...Show more |
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." |
1Microsoft 8Excel Excel For MacExcel Viewer+5 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3,...Show more |
1Microsoft 6Office Office Compatibility PackOffice Web Apps Server+3 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Ser...Show more |
1Microsoft 7Office Office Compatibility PackOffice Web Apps Server+4 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoin...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain p...Show more |
1Microsoft 2Windows Server 2008 Windows Server 2012May 6, 2026 Feb 10, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 6, 2026 Feb 10, 2016 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which al...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to g...Show more |
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure...Show more |
1Microsoft 3Windows 10 Windows 8.1Windows Server 2012May 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Windows Reader in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a crafted Reader file, aka "Microsoft Windows Reader Vulnerability." |
1Microsoft 3Windows 8.1 Windows Rt 8.1Windows Server 2012May 6, 2026 Feb 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loa...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users t...Show more |
1Microsoft 8Internet Explorer Windows 10Windows 7+5 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loadin...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 22, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." |
1Microsoft 1Sharepoint Foundation May 6, 2026 Feb 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XS...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary c...Show more |
The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data,...Show more |
1Microsoft 4Windows 10 Windows 7Windows 8.1+1 moreMay 6, 2026 Feb 10, 2016 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenticated users to execute arbitrary code via crafted data, aka...Show more |
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via craf...Show more |