VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2017-6277
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.
Published 2017-09-22 · Modified
7.8EPSS 0.004
CVE-2024-53954
Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2022-35672
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-07-27 · Modified
7.8EPSS 0.004
CVE-2019-5669
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer, which may lead to denial of service or escalation of privileges.
Published 2019-02-27 · Modified
7.8EPSS 0.004
CVE-2016-8817
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer overflow, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2024-3037
Arbitrary File Deletion in PaperCut NG/MF Web Print
Published 2024-05-14 · Analyzed
7.8EPSS 0.004
CVE-2019-19166
Tobesoft XPlatform Arbitrary File Execution Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.004
CVE-2023-47066
ZDI-CAN-21705: Adobe After Effects MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-17 · Modified
7.8EPSS 0.004
CVE-2024-47410
Animate | Stack-based Buffer Overflow (CWE-121)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47417
Animate | Heap-based Buffer Overflow (CWE-122)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2020-4265
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175648.
Published 2020-05-14 · Modified
7.8EPSS 0.004
CVE-2024-43756
Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2024-20795
Animate has an arbitrary code execution vulnerability when parsing svg files
Published 2024-04-11 · Analyzed
7.8EPSS 0.004
CVE-2023-21612
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
Published 2023-01-18 · Modified
7.8EPSS 0.004
CVE-2023-47067
ZDI-CAN-21706: Adobe After Effects MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-17 · Modified
7.8EPSS 0.004
CVE-2020-5793
A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
Published 2020-11-05 · Modified
7.8EPSS 0.004
CVE-2023-47068
ZDI-CAN-21702: Adobe After Effects MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-17 · Modified
7.8EPSS 0.004
CVE-2023-21611
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
Published 2023-01-18 · Modified
7.8EPSS 0.004
CVE-2023-47069
ZDI-CAN-21703: Adobe After Effects M4A File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-17 · Modified
7.8EPSS 0.004
CVE-2023-22236
Adobe Animate Heap-based Buffer Overflow Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2023-25874
Adobe Substance 3D Stager SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-22234
Adobe Premiere Rush PSD file Stack-based Buffer Overflow Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2023-22243
Adobe Animate SVG file Stack-based Buffer Overflow Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2023-25868
Adobe Substance 3D Stager SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-25864
Adobe Substance 3D Stager FBX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-22226
Adobe Bridge SVG file Stack-based Buffer Overflow Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2022-34242
Adobe Character Animator SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.004
CVE-2022-47631
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if it detects malicious DLLs in this directory, attackers can exploit a race condition and replace a valid DLL (i.e., a copy of a legitimate Razer DLL) with a malicious DLL after the service has already checked the file. As a result, local Windows users can abuse the Razer driver installer to obtain administrative privileges on Windows.
Published 2023-09-14 · Modified
7.8EPSS 0.004
CVE-2025-27200
Animate | Use After Free (CWE-416)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2023-47042
ZDI-CAN-21696: Adobe Media Encoder MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2021-42954
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.
Published 2021-11-17 · Modified
7.8EPSS 0.004
CVE-2024-12751
Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-12-30 · Analyzed
7.8EPSS 0.004
CVE-2023-32162
Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2019-5543
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed may exploit this issue to run commands as any user.
Published 2020-03-16 · Modified
7.8EPSS 0.004
CVE-2023-25148
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2023-03-07 · Modified
7.8EPSS 0.004
CVE-2023-25146
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2023-03-07 · Modified
7.8EPSS 0.004
CVE-2023-25145
A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2023-03-07 · Modified
7.8EPSS 0.004
CVE-2022-31606
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a failure to properly validate data might allow an attacker with basic user capabilities to cause an out-of-bounds access in kernel mode, which could lead to denial of service, information disclosure, escalation of privileges, or data tampering.
Published 2022-11-18 · Modified
7.8EPSS 0.004
CVE-2023-47055
ZDI-CAN-21765: Adobe Premiere Pro M4A File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2024-52988
Animate | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
← Prev134 / 259Next →