VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10355CVEs
CVE-2021-28631
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.047
CVE-2015-5091
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service via invalid data.
Published 2015-07-15 · Modified
7.8EPSS 0.047
CVE-2023-21607
Adobe Acrobat Reader Improper Input Validation Remote Code Execution Vulnerability
Published 2023-01-18 · Modified
7.8EPSS 0.047
CVE-2021-31452
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13091.
Published 2021-05-07 · Modified
7.8EPSS 0.046
CVE-2019-20358
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.
Published 2020-01-30 · Modified
7.8EPSS 0.046
CVE-2023-26421
ZDI-CAN-19832: Adobe Acrobat Reader DC Doc Object Integer Underflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.046
CVE-2024-41830
Talos Security Advisory for Adobe (TALOS-2024-2009)
Published 2024-08-14 · Modified
7.8EPSS 0.046
CVE-2020-9694
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
7.8EPSS 0.045
CVE-2019-6754
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the localFileStorage method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7407.
Published 2019-06-03 · Modified
7.8EPSS 0.045
CVE-2024-20730
TALOS-2023-1906 - Adobe Acrobat Reader Font CPAL integer overflow vulnerability
Published 2024-02-15 · Modified
7.8EPSS 0.044
CVE-2008-0212
ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.
Published 2008-02-06 · Modified
7.8EPSS 0.044
CVE-2022-23188
Adobe Illustrator Buffer Overflow could lead to Arbitrary code execution
Published 2022-02-16 · Modified
7.8EPSS 0.044
CVE-2020-9675
Adobe Bridge versions 10.0.3 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2020-07-22 · Modified
7.8EPSS 0.044
CVE-2021-31453
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA Forms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13092.
Published 2021-05-07 · Modified
7.8EPSS 0.044
CVE-2021-31441
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13101.
Published 2021-05-07 · Modified
7.8EPSS 0.044
CVE-2021-31451
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13089.
Published 2021-05-07 · Modified
7.8EPSS 0.044
CVE-2021-31450
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13084.
Published 2021-05-07 · Modified
7.8EPSS 0.044
CVE-2024-20755
Adobe Bridge PDF Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Published 2024-03-18 · Analyzed
7.8EPSS 0.044
CVE-2021-28621
Adobe Animate FLA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.043
CVE-2023-26408
ZDI-CAN-20712: AnnotsString Object prototype pollution Restrictions Bypass Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2022-34220
Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.043
CVE-2019-6769
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8165.
Published 2019-06-03 · Modified
7.8EPSS 0.043
CVE-2023-26405
ZDI-CAN-20712: Object Prototype pollution which leads to API Restrictions Bypass
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2023-26407
ZDI-CAN-20712: Net.HTTP.request Arbitrary Command Execution
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2021-31461
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the the handling of app.media objects. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process Was ZDI-CAN-13333.
Published 2021-05-07 · Modified
7.8EPSS 0.043
CVE-2020-17403
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11003.
Published 2020-08-25 · Modified
7.8EPSS 0.043
CVE-2020-17404
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11191.
Published 2020-08-25 · Modified
7.8EPSS 0.043
CVE-2024-30284
ZDI-CAN-23466: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.043
CVE-2020-24411
Adobe Illustrator PDF File Parsing Out-Of-Bounds Write Vulnerability
Published 2020-10-20 · Modified
7.8EPSS 0.042
CVE-2019-6774
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the deleteItemAt method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8295.
Published 2019-10-04 · Modified
7.8EPSS 0.042
CVE-2019-6775
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportValues method within a AcroForm. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8491.
Published 2019-10-04 · Modified
7.8EPSS 0.042
CVE-2022-23742
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
Published 2022-05-12 · Modified
7.8EPSS 0.042
CVE-2023-26406
ZDI-CAN-20712: Net.HTTP.request URL restriction bypass
Published 2023-04-12 · Modified
7.8EPSS 0.042
CVE-2020-17412
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11224.
Published 2020-10-13 · Modified
7.8EPSS 0.042
CVE-2020-17413
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11226.
Published 2020-10-13 · Modified
7.8EPSS 0.042
CVE-2021-21071
Adobe Animate memory corruption vulnerability
Published 2021-03-12 · Modified
7.8EPSS 0.042
CVE-2020-9604
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-06-25 · Modified
7.8EPSS 0.041
CVE-2020-9605
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-06-25 · Modified
7.8EPSS 0.041
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2019-13319
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA forms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8669.
Published 2019-10-04 · Modified
7.8EPSS 0.041
← Prev113 / 259Next →