Search Results (3090 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2009-2510 1 Microsoft 6 Windows 2000, Windows 2003 Server, Windows 7 and 3 more 2025-04-09 N/A
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
CVE-2009-2497 1 Microsoft 7 .net Framework, Windows 2000, Windows 7 and 4 more 2025-04-09 N/A
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
CVE-2009-0090 1 Microsoft 7 .net Framework, Windows 2000, Windows 7 and 4 more 2025-04-09 N/A
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
CVE-2008-4033 1 Microsoft 13 Expression Web, Groove, Office and 10 more 2025-04-09 N/A
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
CVE-2010-0018 1 Microsoft 6 Windows 2000, Windows 2003 Server, Windows 7 and 3 more 2025-04-09 N/A
Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."
CVE-2018-0878 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2025-04-04 3.1 Low
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how XML External Entities (XXE) are processed, aka "Windows Remote Assistance Information Disclosure Vulnerability".
CVE-2022-30170 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 7.3 High
Windows Credential Roaming Service Elevation of Privilege Vulnerability
CVE-2022-37958 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 8.1 High
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVE-2022-38006 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 6.5 Medium
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-38005 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 7.8 High
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-38004 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 7.8 High
Windows Fax Service Remote Code Execution Vulnerability
CVE-2022-37956 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 7.8 High
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37955 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2025-03-11 7.8 High
Windows Group Policy Elevation of Privilege Vulnerability
CVE-2022-34734 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 8.8 High
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2022-34733 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 8.8 High
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-34732 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 8.8 High
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2022-34731 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 8.8 High
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-34730 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 8.8 High
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2022-34729 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-03-11 7.8 High
Windows GDI Elevation of Privilege Vulnerability
CVE-2022-34728 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2025-03-11 5.5 Medium
Windows Graphics Component Information Disclosure Vulnerability