Latest CVE Feed
-
8.8
HIGHCVE-2015-2360
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local ... Read more
- Actively Exploited
- EPSS Score: %5.86
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2359
Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Exchange HTML Injection Vulnerability."... Read more
Affected Products : exchange_server- EPSS Score: %14.05
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1771
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnera... Read more
Affected Products : exchange_server- EPSS Score: %2.38
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1770
Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."... Read more
- Actively Exploited
- EPSS Score: %73.20
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1768
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vu... Read more
- EPSS Score: %1.64
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1766
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE... Read more
Affected Products : internet_explorer- EPSS Score: %24.07
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1765
Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a crafted web site.... Read more
Affected Products : internet_explorer- EPSS Score: %19.46
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1764
The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) iss... Read more
Affected Products : exchange_server- EPSS Score: %9.47
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1760
Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."... Read more
- EPSS Score: %35.90
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1759
Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."... Read more
Affected Products : office_compatibility_pack- EPSS Score: %39.19
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-1758
Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a Tro... Read more
Affected Products : windows_7 windows_server_2008 windows_server_2012 windows_vista windows windows_8 windows_rt- EPSS Score: %5.40
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1757
Cross-site scripting (XSS) vulnerability in adfs/ls in Active Directory Federation Services (AD FS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 allows remote attackers to inject arbitrary web script or HTML via the wct parameter, aka "... Read more
Affected Products : active_directory_federation_services- EPSS Score: %12.41
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1756
Use-after-free vulnerability in Microsoft Common Controls in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows user-assisted remote a... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- EPSS Score: %44.31
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1755
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-20... Read more
Affected Products : internet_explorer- EPSS Score: %14.06
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1754
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %24.07
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1753
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732... Read more
Affected Products : internet_explorer- EPSS Score: %24.07
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1752
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE... Read more
Affected Products : internet_explorer- EPSS Score: %24.07
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1751
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %12.94
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1750
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732... Read more
Affected Products : internet_explorer- EPSS Score: %20.84
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1748
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1743.... Read more
Affected Products : internet_explorer- EPSS Score: %9.83
- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025