Vulnerabilities > Microsoft > XML Core Services > High

DATE CVE VULNERABILITY TITLE RISK
2016-04-12 CVE-2016-0147 Improper Input Validation vulnerability in Microsoft XML Core Services 3.0
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-20
8.8
2012-06-13 CVE-2012-1889 Out-of-bounds Write vulnerability in Microsoft XML Core Services
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
network
low complexity
microsoft CWE-787
8.8