Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-11-11 CVE-2014-6342 Resource Management Errors vulnerability in Microsoft Internet Explorer 9
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6348.
network
microsoft CWE-399
critical
9.3
2014-11-11 CVE-2014-6341 Resource Management Errors vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4143.
network
microsoft CWE-399
critical
9.3
2014-11-11 CVE-2014-6337 Resource Management Errors vulnerability in Microsoft Internet Explorer 10/11
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2014-11-11 CVE-2014-6335 Code Injection vulnerability in Microsoft Office Compatibility Pack, Office Word Viewer and Word
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Invalid Pointer Remote Code Execution Vulnerability."
network
microsoft CWE-94
critical
9.3
2014-11-11 CVE-2014-6334 Code Injection vulnerability in Microsoft Office Compatibility Pack, Office Word Viewer and Word
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Bad Index Remote Code Execution Vulnerability."
network
microsoft CWE-94
critical
9.3
2014-11-11 CVE-2014-6333 Code Injection vulnerability in Microsoft Office Compatibility Pack, Office Word Viewer and Word
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Double Delete Remote Code Execution Vulnerability."
network
microsoft CWE-94
critical
9.3
2014-11-11 CVE-2014-6332 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
network
microsoft CWE-119
critical
9.3
2014-11-11 CVE-2014-6321 Code Injection vulnerability in Microsoft products
Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via crafted packets, aka "Microsoft Schannel Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-94
critical
10.0
2014-11-11 CVE-2014-4149 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."
network
microsoft CWE-20
critical
9.3
2014-11-11 CVE-2014-4143 Resource Management Errors vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6341.
network
microsoft CWE-399
critical
9.3