microsoft

15,064 tracked vulnerabilities.

CVE-2016-0047 HIGH
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1 - Information Disclosure via Crafted Icon Data
Feb 10, 2016
CVSS 7.5
EPSS 0.21
CVE-2016-0046 HIGH
Windows Reader - Remote Code Execution via Crafted Reader File
Feb 10, 2016
CVSS 7.8
EPSS 0.26
CVE-2016-0044 HIGH
Sync Framework in Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 - DoS via Crafted Change Batch Data
Feb 10, 2016
CVSS 7.5
EPSS 0.14
CVE-2016-0042 HIGH
Microsoft Windows - Unauthenticated DLL Loading Privilege Escalation
Feb 10, 2016
CVSS 7.8
EPSS 0.06
CVE-2016-0041 HIGH
Internet Explorer - DLL Loading Remote Code Execution
Feb 10, 2016
CVSS 7.8
EPSS 0.83
CVE-2016-0040 HIGH KEV
Microsoft Windows - Privilege Escalation
Feb 10, 2016
CVSS 7.8
EPSS 0.25
CVE-2016-0039 MEDIUM
Microsoft SharePoint Foundation 2013 SP1 - Cross-Site Scripting via Crafted Request
Feb 10, 2016
CVSS 6.1
EPSS 0.07
CVE-2016-0038 HIGH
Windows Journal - Remote Code Execution via Crafted Journal File
Feb 10, 2016
CVSS 7.8
EPSS 0.18
CVE-2016-0037 HIGH
Windows Server 2012 R2 - Denial of Service via Crafted Data in ADFS Forms-Based Authentication
Feb 10, 2016
CVSS 7.5
EPSS 0.26
CVE-2016-0036 HIGH
Microsoft Windows - Remote Code Execution via Remote Desktop Protocol
Feb 10, 2016
CVSS 8.1
EPSS 0.11
CVE-2016-0033 HIGH
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1 - Denial of Service via Recursive XSLT Compilation
Feb 10, 2016
CVSS 7.5
EPSS 0.18
CVE-2016-0022 HIGH
Microsoft Office - Remote Code Execution via Crafted Office Document
Feb 10, 2016
CVSS 7.8
EPSS 0.20
CVE-2016-0035 HIGH
Microsoft Excel - Remote Code Execution via Crafted Office Document
Jan 13, 2016
CVSS 7.8
EPSS 0.22
CVE-2016-0034 HIGH KEV
Microsoft Silverlight 5.0-5.1.41212.0 - Remote Code Execution via Negative Offset Decoding
Jan 13, 2016
CVSS 8.8
EPSS 0.59
CVE-2016-0032 MEDIUM
Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10-11, 2016 - Cross-Site Scripting via Crafted URL
Jan 13, 2016
CVSS 6.1
EPSS 0.08
CVE-2016-0031 MEDIUM
Microsoft Exchange Server 2016 - Cross-Site Scripting via Crafted URL
Jan 13, 2016
CVSS 6.1
EPSS 0.08
CVE-2016-0030 MEDIUM
Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 - Cross-Site Scripting via Crafted URL
Jan 13, 2016
CVSS 6.1
EPSS 0.08
CVE-2016-0029 MEDIUM
Microsoft Exchange Server 2016 - Cross-Site Scripting via Crafted URL
Jan 13, 2016
CVSS 6.1
EPSS 0.08
CVE-2016-0024 HIGH
Microsoft Edge - Remote Code Execution via Chakra JavaScript Engine Memory Corruption
Jan 13, 2016
CVSS 8.8
EPSS 0.17
CVE-2016-0020 HIGH
Microsoft Windows - Privilege Escalation
Jan 13, 2016
CVSS 7.8
EPSS 0.02
CVE-2016-0019 HIGH
Windows 10 - Remote Desktop Protocol Security Bypass via Blank-Password Account
Jan 13, 2016
CVSS 8.1
EPSS 0.12
CVE-2016-0018 HIGH
Microsoft Windows 7 SP1 to 10 (1511) Privilege Escalation via DLL Loading
Jan 13, 2016
CVSS 7.3
EPSS 0.13
CVE-2016-0016 HIGH
Microsoft Windows - Untrusted Search Path DLL Loading Privilege Escalation
Jan 13, 2016
CVSS 7.8
EPSS 0.30
CVE-2016-0015 HIGH
Microsoft Windows - Remote Code Execution via Crafted File in DirectShow
Jan 13, 2016
CVSS 7.8
EPSS 0.49
CVE-2016-0014 HIGH
Microsoft Windows - Untrusted Search Path Elevation of Privilege via DLL Loading
Jan 13, 2016
CVSS 7.8
EPSS 0.02