Show filters
5,933 Total Results
Displaying 61-70 of 5,933
Sort by:
Attacker Value
Unknown
CVE-2013-5065 Microsoft NDProxy.sys Privilege Escalation
Disclosure Date: November 28, 2013 (last updated July 25, 2024)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
0
Attacker Value
Unknown
Microsoft Internet Explorer CCaret Use-After-Free
Disclosure Date: September 11, 2013 (last updated October 05, 2023)
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
0
Attacker Value
Unknown
Microsoft Internet Explorer EnsureRecalcNotify Use-After-Free
Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
0
Attacker Value
Unknown
Microsoft Internet Explorer CGenericElement Use-After-Free
Disclosure Date: May 05, 2013 (last updated July 17, 2024)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
0
Attacker Value
Unknown
Microsoft Windows TabStrip MSCOMCTL.OCX RCE Vulnerability
Disclosure Date: August 15, 2012 (last updated July 17, 2024)
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
0
Attacker Value
Unknown
MS12-037 Microsoft Internet Explorer Same ID Property Deleted Object Handling M…
Disclosure Date: June 12, 2012 (last updated October 04, 2023)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."
0
Attacker Value
Very High
CVE-2012-0002
Disclosure Date: March 13, 2012 (last updated December 08, 2023)
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
0
Attacker Value
Unknown
CVE-2011-3400 Microsoft OLE for Windows
Disclosure Date: December 14, 2011 (last updated October 04, 2023)
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
0
Attacker Value
Unknown
CVE-2011-1252
Disclosure Date: June 16, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
1
Attacker Value
Unknown
CVE-2025-27321
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer allows Stored XSS. This issue affects Blightly Explorer: from n/a through 2.3.0.
0