VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2017-10747
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10748
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10749
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10750
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-14272
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000595d."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2017-14274
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008706."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2017-14275
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2017-14538
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008823."
Published 2017-09-18 · Modified
7.8EPSS 0.004
CVE-2017-14580
XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000870f."
Published 2017-09-18 · Modified
7.8EPSS 0.004
CVE-2017-1451
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
Published 2017-09-12 · Modified
7.8EPSS 0.004
CVE-2017-1452
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
Published 2017-09-12 · Modified
7.8EPSS 0.004
CVE-2017-6269
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is used without validation which may lead to denial of service or possible escalation of privileges.
Published 2017-09-22 · Modified
7.8EPSS 0.004
CVE-2019-14935
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.
Published 2019-08-11 · Modified
7.8EPSS 0.004
CVE-2024-20792
Adobe Illustrator TIF File Parsing Use-After-Free Remote memory corruption
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2023-24068
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert malicious code into pre-existing attachments or replace them completely. A threat actor can forward the existing attachment in the corresponding conversation to external groups, and the name and size of the file will not change, allowing the malware to masquerade as another file. NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
Published 2023-01-23 · Modified
7.8EPSS 0.004
CVE-2020-5794
A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbitrary code by copying user-supplied files to a specially constructed path in a specifically named user directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
Published 2020-11-06 · Modified
7.8EPSS 0.004
CVE-2024-39377
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2021-28130
Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.
Published 2021-09-24 · Modified
7.8EPSS 0.004
CVE-2022-35701
Adobe Bridge SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.004
CVE-2016-8816
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2024-47411
Animate | Access of Uninitialized Pointer (CWE-824)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2020-5958
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.
Published 2020-03-11 · Modified
7.8EPSS 0.004
CVE-2024-47416
Animate | Integer Overflow or Wraparound (CWE-190)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2021-32461
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2021-07-08 · Modified
7.8EPSS 0.004
CVE-2025-21160
Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2023-1003
Typora WSH JScript code injection
Published 2023-02-24 · Modified
7.8EPSS 0.004
CVE-2024-34121
Illustrator | Integer Overflow or Wraparound (CWE-190)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2024-41857
Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2016-8813
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2016-8814
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2016-8815
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2016-8818
All versions of NVIDIA Windows GPU Display contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a pointer passed from a user to the driver is used without validation, leading to denial of service or potential escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2016-8819
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a handle to a kernel object may be returned to the user, leading to possible denial of service or escalation of privileges.
Published 2016-12-16 · Modified
7.8EPSS 0.004
CVE-2024-47421
Adobe Framemaker | Out-of-bounds Read (CWE-125)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2023-28929
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file is started.
Published 2023-06-26 · Modified
7.8EPSS 0.004
CVE-2025-43575
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2025-06-10 · Analyzed
7.8EPSS 0.004
CVE-2024-30275
Adobe Aero Beta has an arbitrary code execution vulnerability when parsing svg files
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2024-39389
Adobe Indesign PDF File Parsing Stack Based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2023-22235
Adobe InCopy SVG file Use After Free Arbitrary code execution
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-22244
Adobe Premiere Rush PSD files Use After Free Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
← Prev137 / 259Next →