VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2023-25890
ZDI-CAN-19493: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25885
ZDI-CAN-19480: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25897
ZDI-CAN-19520: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25898
ZDI-CAN-19521: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-47074
ZDI-CAN-21812: Adobe Illustrator JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-12-13 · Modified
7.8EPSS 0.004
CVE-2019-18278
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.
Published 2019-10-23 · Modified
7.8EPSS 0.004
CVE-2024-34100
Use-After-Free vulnerability in the latest Adobe Acrobat Reader DC when open malicious PDF file
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2020-4257
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175635.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4258
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175637.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4261
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175644.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4262
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175645.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4263
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175646.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4264
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175647.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2020-4266
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175649.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2016-7085
Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2016-12-29 · Modified
7.8EPSS 0.004
CVE-2020-28963
Passcovery Co. Ltd ZIP Password Recovery v3.70.69.0 was discovered to contain a buffer overflow via the decompress function.
Published 2021-10-22 · Modified
7.8EPSS 0.004
CVE-2023-47039
Perl: perl for windows binary hijacking vulnerability
Published 2024-01-02 · Modified
7.8EPSS 0.004
CVE-2022-38417
Adobe InDesign SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.004
CVE-2022-35673
Adobe FrameMaker SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.004
CVE-2022-38416
Adobe InDesign SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.004
CVE-2018-5485
NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.
Published 2018-05-24 · Modified
7.8EPSS 0.004
CVE-2022-35674
Adobe FrameMaker SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.004
CVE-2023-51549
Foxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2020-12423
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other operating systems are unaffected.* This vulnerability affects Firefox < 78.
Published 2020-07-09 · Modified
7.8EPSS 0.004
CVE-2023-26412
ZDI-CAN-20314: Adobe Substance 3D Designer USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-26416
ZDI-CAN-20318: Adobe Substance 3D Designer DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-21587
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-01-13 · Modified
7.8EPSS 0.004
CVE-2023-38212
ZDI-CAN-21093: Adobe Dimension GLB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-08-09 · Modified
7.8EPSS 0.004
CVE-2023-26383
ZDI-CAN-20287: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-26390
ZDI-CAN-20255: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-25872
Adobe Substance 3D Stager SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-26413
ZDI-CAN-20315: Adobe Substance 3D Designer USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-26394
ZDI-CAN-20236: Adobe Substance 3D Stager USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2021-42108
Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2021-10-21 · Modified
7.8EPSS 0.004
CVE-2018-10514
A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
Published 2018-08-30 · Modified
7.8EPSS 0.004
CVE-2023-31132
Cacti Privilege Escalation
Published 2023-09-05 · Analyzed
7.8EPSS 0.004
CVE-2022-38448
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-38447
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-38445
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-37173
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
Published 2022-08-30 · Modified
7.8EPSS 0.004
← Prev132 / 259Next →