VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2024-39389
Adobe Indesign PDF File Parsing Stack Based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2024-30295
When Animate parses FLA files, there is a UAF vulnerability caused by referencing uninitialized memory at Animate.exe+0x1149dcf
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2023-22244
Adobe Premiere Rush PSD files Use After Free Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2022-44518
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2017-10736
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!_VEC_memzero+0x000000000000006a."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10737
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000002e6."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10738
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000002f32332f called from KERNELBASE!CompareStringW+0x0000000000000082."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10739
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000000c1b541c called from xnview+0x00000000003826ec."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10742
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x00000000380a0500 called from ntdll_77df0000!LdrxCallInitRoutine+0x0000000000000016."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10743
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!LdrpInitializeNode+0x000000000000015b."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10744
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Read Access Violation on Control Flow starting at COMCTL32!CToolTipsMgr::s_ToolTipsWndProc+0x0000000000000032."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-10745
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!RtlProcessFlsData+0x00000000000000b0."
Published 2017-07-05 · Modified
7.8EPSS 0.004
CVE-2017-14270
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlFillMemoryUlong+0x0000000000000010."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2017-14271
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlImpersonateSelfEx+0x000000000000024e."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2017-14273
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x00000000000003b0."
Published 2017-09-11 · Modified
7.8EPSS 0.004
CVE-2023-47043
ZDI-CAN-21699: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2022-44520
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2023-47040
ZDI-CAN-21698: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2022-44514
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2019-5691
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a NULL pointer is dereferenced, which may lead to denial of service or escalation of privileges.
Published 2019-11-09 · Modified
7.8EPSS 0.004
CVE-2023-2873
Twister Antivirus IoControlCode filppd.sys 0x80800043 memory corruption
Published 2023-05-24 · Modified
7.8EPSS 0.004
CVE-2020-26155
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.
Published 2021-03-18 · Modified
7.8EPSS 0.004
CVE-2025-23339
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.
Published 2025-09-24 · Modified
7.8EPSS 0.004
CVE-2024-41840
ZDI-CAN-24607: Adobe Bridge JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2026-70354
.NET Core Remote Code Execution Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.004
CVE-2022-22454
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Published 2022-05-10 · Modified
7.8EPSS 0.004
CVE-2024-49553
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-49551
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-34099
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 2 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2024-20783
Adobe Indesign 2024 RLE File Parsing Heap Memory Corruption
Published 2024-07-09 · Modified
7.8EPSS 0.004
CVE-2024-20785
Adobe Indesign 2024 TIFF File Parsing Memory Corruption Remote Code Execution vulnerability
Published 2024-07-09 · Modified
7.8EPSS 0.004
CVE-2024-41850
Adobe Indesign 2024 TIF File Parsing Heap Memory Corruption
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2022-38435
Adobe Illustrator PCX File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2022-10-25 · Modified
7.8EPSS 0.004
CVE-2024-41853
Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2024-41852
Adobe Indesign 2024 AVI File Parsing Stack Based Buffer Overflow
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2023-32163
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2024-39386
ZDI-CAN-24057: Adobe Bridge AVI FIle Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2023-6006
Privilege Escalation Vulnerability
Published 2023-11-14 · Modified
7.8EPSS 0.004
CVE-2024-30273
Adobe Illustrator 2024 PS file Parsing Stack based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-04-11 · Analyzed
7.8EPSS 0.004
CVE-2024-45146
Dimension | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
← Prev138 / 259Next →