VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2023-26419
ZDI-CAN-20274: Adobe Acrobat Reader DC AcroForm removeField Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.027
CVE-2023-26420
ZDI-CAN-20227: Adobe Acrobat Reader DC AcroForm addField Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.027
CVE-2023-26424
ZDI-CAN-19833: Adobe Acrobat Reader DC PDF Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.027
CVE-2018-19451
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution.
Published 2019-06-07 · Modified
7.8EPSS 0.027
CVE-2021-27261
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12269.
Published 2021-03-30 · Modified
7.8EPSS 0.027
CVE-2020-24415
Adobe Illustrator Memory Corruption Vulnerability
Published 2020-10-20 · Modified
7.8EPSS 0.027
CVE-2020-24557
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
Published 2020-09-01 · Analyzed
7.8KEVEPSS 0.027
CVE-2018-16291
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16292
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16293
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16294
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16295
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16296
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2018-16297
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16296. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Published 2018-10-08 · Modified
7.8EPSS 0.027
CVE-2022-38450
Adobe Acrobat Reader DC XFA Parsing Stack Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.027
CVE-2018-19445
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution.
Published 2019-06-17 · Modified
7.8EPSS 0.026
CVE-2023-26417
ZDI-CAN-20583: Adobe Acrobat Reader DC Popup Use-After-Free Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.026
CVE-2023-44372
TALOS-2023-1842 - Adobe Acrobat Reader U3D page event use-after-free vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.026
CVE-2024-20731
TALOS-2023-1901 - Adobe Acrobat Reader FileAttachment PDAnnot destroy use-after-free vulnerability
Published 2024-02-15 · Modified
7.8EPSS 0.026
CVE-2021-35053
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
Published 2021-11-03 · Modified
7.8EPSS 0.026
CVE-2023-26425
ZDI-CAN-19854: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.026
CVE-2023-21605
Adobe Acrobat Reader DC Font Parsing Heap-based Buffer Overflow Arbitrary code execution
Published 2023-01-18 · Modified
7.8EPSS 0.026
CVE-2023-21604
Adobe Acrobat Reader Stack-based Buffer Overflow Arbitrary code execution
Published 2023-01-18 · Modified
7.8EPSS 0.026
CVE-2022-30647
Adobe Illustrator Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.025
CVE-2022-30648
Adobe Illustrator Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.025
CVE-2022-35667
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.025
CVE-2023-21610
Adobe Acrobat Reader Stack-based Buffer Overflow Arbitrary code execution
Published 2023-01-18 · Modified
7.8EPSS 0.025
CVE-2023-38233
ZDI-CAN-21337: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.025
CVE-2023-38231
ZDI-CAN-21334: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.025
CVE-2021-27269
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process Was ZDI-CAN-12390.
Published 2021-03-30 · Modified
7.8EPSS 0.025
CVE-2021-27267
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12294.
Published 2021-03-30 · Modified
7.8EPSS 0.025
CVE-2021-27268
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12295.
Published 2021-03-30 · Modified
7.8EPSS 0.025
CVE-2023-21606
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-18 · Modified
7.8EPSS 0.025
CVE-2018-19444
A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19452, this has a different free location and requires different JavaScript code for exploitation.
Published 2019-06-17 · Modified
7.8EPSS 0.024
CVE-2021-45055
Adobe InCopy TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-01-13 · Modified
7.8EPSS 0.024
CVE-2023-38234
ZDI-CAN-21359: Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2023-08-10 · Modified
7.8EPSS 0.024
CVE-2020-25773
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.
Published 2020-09-28 · Modified
7.8EPSS 0.024
CVE-2024-20726
[TianfuCup] JP2K Image Parsing Out-Of-Bounds Write
Published 2024-02-15 · Modified
7.8EPSS 0.024
CVE-2020-9592
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.
Published 2020-06-25 · Modified
7.8EPSS 0.023
CVE-2020-9596
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.
Published 2020-06-25 · Modified
7.8EPSS 0.023
← Prev118 / 259Next →