Known Vulnerabilities for Xml Core Services by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Xml Core Services" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34163 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2016-0147 | Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remo... | 8.8 - HIGH | 2016-04-12 | 2018-10-12 |
| CVE-2015-2471 | Microsoft XML Core Services 3.0, 5.0, and 6.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptogr... | 4.3 - MEDIUM | 2015-08-15 | 2018-10-12 |
| CVE-2015-2440 | Microsoft XML Core Services 3.0, 5.0, and 6.0 allows remote attackers to bypass the ASLR protection mechanism via a crafted w... | 4.3 - MEDIUM | 2015-08-15 | 2018-10-12 |
| CVE-2015-2434 | Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic ... | 4.3 - MEDIUM | 2015-08-15 | 2018-10-12 |
| CVE-2015-1646 | Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive inf... | 4.3 - MEDIUM | 2015-04-14 | 2018-10-12 |
| CVE-2014-1816 | Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explor... | 4.3 - MEDIUM | 2014-06-11 | 2018-10-12 |
| CVE-2013-0007 | Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers ... | 9.3 - HIGH | 2013-01-09 | 2023-12-07 |
| CVE-2013-0006 | Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers ... | 9.3 - HIGH | 2013-01-09 | 2023-12-07 |
| CVE-2012-1889 | Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to ... | 9.3 - HIGH | 2012-06-13 | 2023-12-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Xml Core Services | 6.0 | All | All | All |
| Application | Microsoft | Xml Core Services | 5.0 | All | All | All |
| Application | Microsoft | Xml Core Services | 4.0 | All | All | All |
| Application | Microsoft | Xml Core Services | 3.0 | All | All | All |
| Application | Microsoft | Xml Core Services | 2.6 | All | All | All |
| Application | Microsoft | Xml Core Services | - | All | All | All |