VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2024-41869
Acrobat Reader | Use After Free (CWE-416)
Published 2024-09-13 · Analyzed
7.8EPSS 0.023
CVE-2018-19449
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.exportAsFDF is used. An attacker can leverage this to gain remote code execution.
Published 2019-06-17 · Modified
7.8EPSS 0.023
CVE-2020-35931
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.
Published 2020-12-31 · Modified
7.8EPSS 0.023
CVE-2022-23186
Adobe Illustrator Out-of-bounds Write could lead to Arbitrary code execution
Published 2022-02-16 · Modified
7.8EPSS 0.023
CVE-2023-44336
TALOS-2023-1794 - Adobe Acrobat Reader Thermometer use-after-free vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.023
CVE-2021-45056
Adobe InCopy JPEG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-13 · Modified
7.8EPSS 0.023
CVE-2020-9614
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.
Published 2020-06-25 · Modified
7.8EPSS 0.022
CVE-2020-9613
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.
Published 2020-06-25 · Modified
7.8EPSS 0.022
CVE-2018-19448
In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain remote code execution.
Published 2019-06-17 · Modified
7.8EPSS 0.022
CVE-2022-30649
Adobe Illustrator Out-of-bounds Write could lead to Arbitrary code execution
Published 2022-06-15 · Modified
7.8EPSS 0.022
CVE-2021-39829
Adobe FrameMaker PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.022
CVE-2018-19446
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution.
Published 2019-06-17 · Modified
7.8EPSS 0.022
CVE-2021-45057
Adobe InDesign JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-13 · Modified
7.8EPSS 0.022
CVE-2021-45058
Adobe InDesign JPEG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-13 · Modified
7.8EPSS 0.022
CVE-2021-45053
Adobe InCopy JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-13 · Modified
7.8EPSS 0.022
CVE-2019-5618
A-PDF WAV to MP3 Stack-based Buffer Overflow
Published 2020-04-29 · Modified
7.8EPSS 0.022
CVE-2021-39831
Adobe FrameMaker PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.022
CVE-2021-42735
Adobe Photoshop Memory Corruption could lead to Arbitrary code execution
Published 2022-06-15 · Modified
7.8EPSS 0.021
CVE-2023-44359
ZDI-CAN-21936: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.021
CVE-2023-44367
ZDI-CAN-21929: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.021
CVE-2022-28848
Adobe Bridge PCX Out-of-bounds Write Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.021
CVE-2022-28846
Adobe Bridge SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.021
CVE-2022-28847
Adobe Bridge Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.021
CVE-2018-19450
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.
Published 2019-06-17 · Modified
7.8EPSS 0.021
CVE-2023-21609
Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-18 · Modified
7.8EPSS 0.021
CVE-2023-26395
Adobe Acrobat parsing PDF Out-of-bounds Write Arbitrary code execution
Published 2023-04-12 · Modified
7.8EPSS 0.021
CVE-2022-21821
NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.
Published 2022-03-29 · Modified
7.8EPSS 0.021
CVE-2024-39426
ZDI-CAN-24312: Adobe Acrobat Reader DC Annotation Memory Corruption Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.021
CVE-2020-17415
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit PhantomPDF Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-11308.
Published 2020-10-13 · Modified
7.8EPSS 0.021
CVE-2023-44338
ZDI-CAN-21493: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.020
CVE-2023-44365
ZDI-CAN-21931: Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.020
CVE-2023-44337
ZDI-CAN-21509: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.020
CVE-2021-40784
Adobe Premiere Rush WAV File Memory Corruption Remote Code Execution
Published 2021-12-20 · Modified
7.8EPSS 0.020
CVE-2021-40783
Adobe Premiere Rush WAV File Memory Corruption Remote Code Execution
Published 2021-12-20 · Modified
7.8EPSS 0.020
CVE-2024-20727
[TianfuCup] out-of-bounds access vulnerability when parsing jpeg2000
Published 2024-02-15 · Modified
7.8EPSS 0.020
CVE-2021-46818
Adobe Media Encoder M4A file memory corruption vulnerability could lead to remote code execution
Published 2022-06-13 · Modified
7.8EPSS 0.020
CVE-2021-42732
Adobe InDesign crashes when parsing the GIF file
Published 2022-06-15 · Modified
7.8EPSS 0.020
CVE-2019-9969
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.
Published 2019-03-24 · Modified
7.8EPSS 0.020
CVE-2021-41783
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Published 2022-08-29 · Modified
7.8EPSS 0.020
CVE-2021-41785
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Published 2022-08-29 · Modified
7.8EPSS 0.020
← Prev119 / 259Next →