microsoft

15,080 tracked vulnerabilities.

CVE-2012-1890
Windows win32k.sys - Local Privilege Escalation via Keyboard Layout File Handling
Jul 10, 2012
EPSS 0.02
CVE-2012-1870
Microsoft Windows - Exposure of Sensitive Information via TLS CBC Mode
Jul 10, 2012
EPSS 0.10
CVE-2012-1863
Microsoft Office SharePoint Server - Cross-Site Scripting via URL Parameter
Jul 10, 2012
EPSS 0.23
CVE-2012-1862
Microsoft SharePoint Server 2007 SP2 and SP3 - Open Redirect via Crafted URL
Jul 10, 2012
EPSS 0.11
CVE-2012-1861
Microsoft SharePoint Server 2010, SharePoint Foundation 2010, and Office Web Apps 2010 - Cross-Site Scripting via URL
Jul 10, 2012
EPSS 0.15
CVE-2012-1860
Microsoft SharePoint Server and Office Web Apps - Information Disclosure and DoS via Search Scope
Jul 10, 2012
EPSS 0.13
CVE-2012-1859
Microsoft SharePoint Server 2010 and Foundation 2010 - Cross-Site Scripting via scriptresx.ashx
Jul 10, 2012
EPSS 0.23
CVE-2012-1854 HIGH KEV
Microsoft Office <2010 - Privilege Escalation
Jul 10, 2012
CVSS 7.8
EPSS 0.21
CVE-2012-1524
Microsoft Internet Explorer 9 - Remote Code Execution via Deleted Object Access
Jul 10, 2012
EPSS 0.21
CVE-2012-1522
Internet Explorer 9 - Remote Code Execution via Cached Object Use-After-Free
Jul 10, 2012
EPSS 0.21
CVE-2012-0175 HIGH
Microsoft Windows Shell - Remote Code Execution via Crafted File or Directory Name
Jul 10, 2012
CVSS 8.8
EPSS 0.26
CVE-2012-1889 HIGH KEV
Microsoft XML Core Services 3.0, 4.0, 5.0, 6.0 - Remote Code Execution via Uninitialized Memory Access
Jun 13, 2012
CVSS 8.8
EPSS 0.84
CVE-2012-1882
Microsoft Internet Explorer 6-9 - Information Disclosure via Cross-Domain Scrolling Events
Jun 12, 2012
EPSS 0.14
CVE-2012-1881
Internet Explorer 8 and 9 - Remote Code Execution via OnRowsInserted Event
Jun 12, 2012
EPSS 0.24
CVE-2012-1880
Microsoft Internet Explorer 6-9 - Remote Code Execution via Deleted Object Access
Jun 12, 2012
EPSS 0.24
CVE-2012-1879 HIGH
Internet Explorer 6-9 - Remote Code Execution via insertAdjacentText Memory Corruption
Jun 12, 2012
CVSS 8.1
EPSS 0.20
CVE-2012-1878
Microsoft Internet Explorer 6-9 - Remote Code Execution via OnBeforeDeactivate Event Handler
Jun 12, 2012
EPSS 0.22
CVE-2012-1877
Microsoft Internet Explorer 6-9 - Remote Code Execution via Title Element Change
Jun 12, 2012
EPSS 0.24
CVE-2012-1876
Microsoft Internet Explorer 6-9 and 10 Consumer Preview - Remote Code Execution via Col Element Handling
Jun 12, 2012
EPSS 0.65
CVE-2012-1875
Microsoft Internet Explorer 8 - Remote Code Execution via Deleted Object Access
Jun 12, 2012
EPSS 0.62
CVE-2012-1874
Microsoft Internet Explorer 8 and 9 - Use-After-Free in Developer Toolbar
Jun 12, 2012
EPSS 0.24
CVE-2012-1873
Microsoft Internet Explorer 7-9 - Information Disclosure via Null Byte String Handling
Jun 12, 2012
EPSS 0.18
CVE-2012-1872 MEDIUM
Internet Explorer 6-9 - Cross-Site Scripting via EUC-JP Character Encoding
Jun 12, 2012
CVSS 6.1
EPSS 0.06
CVE-2012-1868
Windows XP SP3 - Local Privilege Escalation via Win32k.sys Thread Creation Race Condition
Jun 12, 2012
EPSS 0.01
CVE-2012-1867 HIGH
Windows XP/2003/Vista/7/2008 Local Privilege Escalation via TrueType Font Integer Overflow
Jun 12, 2012
CVSS 8.4
EPSS 0.01