VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2019-6748
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Studio Photo 3.6.6. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EZI files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7637.
Published 2019-06-03 · Modified
7.8EPSS 0.034
CVE-2021-28551
Adobe Acrobat Pro DC JPEG2000 Editing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.034
CVE-2024-20729
TALOS-2023-1890 - Adobe Acrobat Reader Annot3D object zoom event use-after-free vulnerability
Published 2024-02-15 · Modified
7.8EPSS 0.034
CVE-2019-6763
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the ToggleFormsDesign method of the Foxit.FoxitReader.Ctl ActiveX object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7874.
Published 2019-06-03 · Modified
7.8EPSS 0.034
CVE-2022-34215
Adobe Acrobat Reader DC Annotation Polygon Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.033
CVE-2022-34222
Adobe Acrobat Reader DC query Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.033
CVE-2021-21037
Acrobat Reader DC Path Traversal Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
7.8EPSS 0.033
CVE-2021-27271
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in an out-of-bounds read condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12438.
Published 2021-03-30 · Modified
7.8EPSS 0.033
CVE-2018-15983
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-01-18 · Modified
7.8EPSS 0.033
CVE-2019-7093
Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-05-24 · Modified
7.8EPSS 0.033
CVE-2019-7956
Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.
Published 2019-07-18 · Modified
7.8EPSS 0.033
CVE-2021-21038
Acrobat Reader DC Out-Of-Bounds Write Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
7.8EPSS 0.033
CVE-2021-28602
Adobe After Effects Memory corruption could lead to code execution vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.033
CVE-2023-38224
ZDI-CAN-21122: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.032
CVE-2024-41831
ZDI-CAN-24569: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.032
CVE-2008-5315
Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.
Published 2008-12-03 · Modified
7.8EPSS 0.032
CVE-2023-38225
ZDI-CAN-21118: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.032
CVE-2023-26423
ZDI-CAN-20160: Adobe Acrobat Reader DC AcroForm insertItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.031
CVE-2023-26422
ZDI-CAN-20176: Adobe Acrobat Reader DC AcroForm deleteItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.031
CVE-2019-6768
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8164.
Published 2019-06-03 · Modified
7.8EPSS 0.031
CVE-2019-9634
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
Published 2019-03-08 · Modified
7.8EPSS 0.031
CVE-2021-34834
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14014.
Published 2021-08-04 · Modified
7.8EPSS 0.031
CVE-2021-34835
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14015.
Published 2021-08-04 · Modified
7.8EPSS 0.031
CVE-2014-1730
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.
Published 2014-04-26 · Modified
7.8EPSS 0.031
CVE-2021-21039
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
7.8EPSS 0.031
CVE-2021-21041
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
7.8EPSS 0.031
CVE-2021-21040
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
7.8EPSS 0.031
CVE-2022-34217
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.031
CVE-2020-24429
Acrobat Reader DC for macOS Signature Verification Bypass Could Lead to Privilege Escalation
Published 2020-11-05 · Modified
7.8EPSS 0.030
CVE-2014-0563
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.
Published 2014-09-17 · Modified
7.8EPSS 0.030
CVE-2022-23200
Adobe After Effects 3GP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-02-16 · Modified
7.8EPSS 0.030
CVE-2023-38228
ZDI-CAN-21317: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.030
CVE-2023-38227
ZDI-CAN-21241: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.030
CVE-2024-39422
ZDI-CAN-24090: New Vulnerability Report - Use-after-free remote code execution vulnerability in Adobe Acrobat Reader DC
Published 2024-08-14 · Analyzed
7.8EPSS 0.030
CVE-2024-39424
ZDI-CAN-24309: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.030
CVE-2022-34224
Adobe Acrobat Reader DC AcroForm setItems Use-After-Free Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.029
CVE-2021-34843
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14025.
Published 2021-08-04 · Modified
7.8EPSS 0.029
CVE-2020-9551
Adobe Bridge versions 10.0 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2020-03-25 · Modified
7.8EPSS 0.029
CVE-2023-38222
ZDI-CAN-21103: Adobe Acrobat Reader DC AcroForm spawnPageFromTemplate Use-After-Free Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.029
CVE-2018-19452
A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19444, this has a different free location and requires different JavaScript code for exploitation.
Published 2019-06-07 · Modified
7.8EPSS 0.029
← Prev116 / 259Next →