VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2021-41783
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Published 2022-08-29 · Modified
7.8EPSS 0.020
CVE-2021-41785
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Published 2022-08-29 · Modified
7.8EPSS 0.020
CVE-2016-8742
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.
Published 2018-02-12 · Modified
7.81 PoCEPSS 0.020
CVE-2021-39832
Adobe FrameMaker PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.020
CVE-2021-39830
Adobe FrameMaker PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.020
CVE-2021-46817
Adobe Media Encoder M4A file memory corruption vulnerability could lead to remote code execution
Published 2022-06-13 · Modified
7.8EPSS 0.019
CVE-2021-28592
Adobe Illustrator JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2021-08-20 · Modified
7.8EPSS 0.019
CVE-2021-28591
Adobe Illustrator PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2021-08-20 · Modified
7.8EPSS 0.019
CVE-2022-28672
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16640.
Published 2022-07-18 · Modified
7.8EPSS 0.019
CVE-2020-17414
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-11229.
Published 2020-10-13 · Modified
7.8EPSS 0.019
CVE-2019-9133
KMPlayer Subtitles parser Heap Overflow Vulnerability
Published 2019-04-09 · Modified
7.8EPSS 0.019
CVE-2010-0903
Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.
Published 2010-07-13 · Modified
7.8EPSS 0.019
CVE-2017-14686
Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.
Published 2017-09-22 · Modified
7.8EPSS 0.019
CVE-2021-43755
Adobe After Effects Memory Corruption could lead to Arbitrary Code Execution
Published 2022-06-15 · Modified
7.8EPSS 0.019
CVE-2023-44366
ZDI-CAN-21928: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.018
CVE-2018-18333
A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations.
Published 2019-02-05 · Modified
7.8EPSS 0.018
CVE-2019-12172
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137.
Published 2019-05-17 · Modified
7.8EPSS 0.018
CVE-2024-21111
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published 2024-04-16 · Modified
7.81 PoCEPSS 0.018
CVE-2021-40775
Adobe Prelude SVG File Parsing Memory Corruption Arbitrary Code Execution
Published 2021-11-22 · Modified
7.8EPSS 0.018
CVE-2021-40771
Adobe Prelude WAV File Parsing Memory Corruption Arbitrary Code Execution
Published 2021-11-22 · Modified
7.8EPSS 0.018
CVE-2021-40772
Adobe Prelude M4A File Parsing Memory Corruption Arbitrary Code Execution
Published 2021-11-22 · Modified
7.8EPSS 0.018
CVE-2021-42724
Adobe Bridge Memory Corruption could lead to Arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.018
CVE-2021-42729
Adobe Bridge Memory Corruption could lead to Arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.018
CVE-2021-42730
Adobe Bridge Memory Corruption could lead to Arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.018
CVE-2021-42737
Adobe Prelude WAV File Parsing Memory Corruption Arbitrary Code Execution
Published 2021-11-22 · Modified
7.8EPSS 0.017
CVE-2021-40770
Adobe Prelude M4A File Parsing Memory Corruption Arbitrary Code Execution
Published 2021-11-22 · Modified
7.8EPSS 0.017
CVE-2021-40792
Adobe Premiere Pro WAV file memory corruption vulnerability could lead to arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.017
CVE-2009-3097
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
Published 2009-09-08 · Modified
7.8EPSS 0.017
CVE-2018-1458
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
Published 2018-07-10 · Modified
7.8EPSS 0.017
CVE-2021-40793
Adobe Premiere Pro WAV file memory corruption vulnerability could lead to arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.017
CVE-2021-40794
Adobe Premiere Pro MOV file memory corruption vulnerability could lead to arbitrary code execution
Published 2022-03-16 · Modified
7.8EPSS 0.017
CVE-2016-8807
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed from an user to the driver is used without validation as the size input to memcpy() causing a stack buffer overflow, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.017
CVE-2020-9668
AGSService program mishandling symbolic links
Published 2021-04-16 · Modified
7.8EPSS 0.016
CVE-2016-8806
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x5000027 where a pointer passed from an user to the driver is used without validation, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.016
CVE-2019-12807
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution arbitrary code.
Published 2019-08-13 · Modified
7.8EPSS 0.016
CVE-2016-8808
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.016
CVE-2016-8809
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.016
CVE-2016-8811
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.016
CVE-2017-0313
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.
Published 2017-02-15 · Modified
7.81 PoCEPSS 0.016
CVE-2016-7391
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds check can allow a user to write to kernel memory, leading to denial of service or potential escalation of privileges.
Published 2016-11-08 · Modified
7.81 PoCEPSS 0.016
← Prev120 / 259Next →