VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2024-30362
Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2018-6661
TS102801 True Key DLL Side-Loading vulnerability
Published 2018-04-02 · Modified
7.8EPSS 0.008
CVE-2020-24420
Uncontrolled Search Path Element in Adobe Photoshop for Windows
Published 2020-10-21 · Modified
7.8EPSS 0.008
CVE-2019-5911
Untrusted search path vulnerability in the installer of UNLHA32.DLL (UNLHA32.DLL for Win32 Ver 2.67.1.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2019-02-13 · Modified
7.8EPSS 0.008
CVE-2019-5912
Untrusted search path vulnerability in the installer of UNARJ32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2019-02-13 · Modified
7.8EPSS 0.008
CVE-2019-5913
Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2019-02-13 · Modified
7.8EPSS 0.008
CVE-2020-24559
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2020-09-01 · Modified
7.8EPSS 0.008
CVE-2024-30354
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30342
Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30343
Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30337
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30338
Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2021-41780
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Published 2022-08-29 · Modified
7.8EPSS 0.008
CVE-2018-19666
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server.
Published 2018-11-29 · Modified
7.8EPSS 0.008
CVE-2020-24556
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
Published 2020-09-01 · Modified
7.8EPSS 0.008
CVE-2019-7962
Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-11-14 · Modified
7.8EPSS 0.008
CVE-2019-7960
Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-11-14 · Modified
7.8EPSS 0.008
CVE-2020-7850
Douzone ActiveX File Download and Execution Vulnerability
Published 2021-03-29 · Modified
7.8EPSS 0.008
CVE-2017-14945
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068."
Published 2017-09-29 · Modified
7.8EPSS 0.008
CVE-2017-14946
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x000000000000344e."
Published 2017-09-29 · Modified
7.8EPSS 0.008
CVE-2016-1087
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1090 and CVE-2016-4106.
Published 2016-05-11 · Modified
7.8EPSS 0.008
CVE-2016-1090
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-4106.
Published 2016-05-11 · Modified
7.8EPSS 0.008
CVE-2017-15772
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285e9d."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15773
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285d79."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15775
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000259aa4."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15776
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285ec1."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15778
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285de7."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15780
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15783
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15786
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15801
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15802
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000087."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2017-15803
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000150."
Published 2017-10-22 · Modified
7.8EPSS 0.008
CVE-2016-4106
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-1090.
Published 2016-05-11 · Modified
7.8EPSS 0.008
CVE-2024-30353
Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30355
Foxit PDF Reader AcroForm Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30357
Foxit PDF Reader AcroForm Annotation Type Confusion Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30348
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2018-10513
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
Published 2018-08-30 · Modified
7.8EPSS 0.008
CVE-2019-9896
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
Published 2019-03-21 · Modified
7.8EPSS 0.008
← Prev125 / 259Next →