Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2017-04-12 CVE-2017-0155 Unspecified vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation of Privilege Vulnerability."
local
high complexity
microsoft
7.0
2017-04-12 CVE-2017-0106 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Outlook
Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
local
low complexity
microsoft CWE-119
7.8
2017-04-12 CVE-2017-0093 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge
A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers.
network
high complexity
microsoft CWE-119
7.5
2017-04-12 CVE-2017-0058 Information Exposure vulnerability in Microsoft products
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information.
local
high complexity
microsoft CWE-200
4.7
2017-03-27 CVE-2017-7269 Classic Buffer Overflow vulnerability in Microsoft Internet Information Server 6.0
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
network
low complexity
microsoft CWE-120
critical
9.8
2017-03-23 CVE-2017-6517 Uncontrolled Search Path Element vulnerability in Microsoft Skype 7.16.0.102
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
network
low complexity
microsoft CWE-427
critical
9.8
2017-03-17 CVE-2017-0154 Injection vulnerability in Microsoft Internet Explorer 11
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-74
4.4
2017-03-17 CVE-2017-0151 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.
network
high complexity
microsoft CWE-119
7.5
2017-03-17 CVE-2017-0150 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.
network
high complexity
microsoft CWE-119
7.5
2017-03-17 CVE-2017-0149 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 10/11/9
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
network
low complexity
microsoft CWE-787
8.8