Microsoft
microsoft
14,959 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,959)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Sharepoint Foundation Sharepoint ServicesApr 29, 2026 Sep 15, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified param...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerApr 29, 2026 Sep 15, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerApr 29, 2026 Sep 15, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in Sh...Show more |
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
9Canonical DebianGoogle+6 more15Chrome CurlDebian Linux+12 moreApr 29, 2026 Sep 6, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initializa...Show more |
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vul...Show more |
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic vi...Show more |
1Microsoft 2.net Framework Chart Control For Microsoft .net FrameworkApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via specia...Show more |
1Microsoft 2Report Viewer Visual StudioApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a dat...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 7.2 HIGH· v2 NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges v...Show more |
Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream R...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a c...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows Server 2008Apr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 7.1 HIGH· v2 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (re...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 7.2 HIGH· v2 Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows...Show more |
The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, a...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Aug 10, 2011 N/A· v4 N/A· v3 7.1 HIGH· v2 Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a...Show more |
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |