VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2017-0314
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.
Published 2017-02-15 · Modified
7.8EPSS 0.003
CVE-2017-0315
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an attempt to access an invalid object pointer may lead to denial of service or potential escalation of privileges.
Published 2017-02-15 · Modified
7.8EPSS 0.003
CVE-2017-0322
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a value passed from a user to the driver is not correctly validated and used as the index to an array, leading to denial of service or potential escalation of privileges.
Published 2017-02-15 · Modified
7.8EPSS 0.003
CVE-2017-0323
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.
Published 2017-02-15 · Modified
7.8EPSS 0.003
CVE-2017-0324
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Published 2017-02-15 · Modified
7.8EPSS 0.003
CVE-2017-0341
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2017-0342
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2017-0344
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2017-0345
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2017-0347
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2017-0348
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.
Published 2017-05-09 · Modified
7.8EPSS 0.003
CVE-2024-39393
Adobe Indesign 2024 PCT File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.003
CVE-2023-25865
Adobe Substance 3D Stager OBJ File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25863
Adobe Substance 3D Stager USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25873
Adobe Substance 3D Stager SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25869
Adobe Substance 3D Stager SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2017-6252
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to a denial of service or potential escalation of privileges.
Published 2017-07-28 · Modified
7.8EPSS 0.003
CVE-2017-6253
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated which may lead to denial of service or potential escalation of privileges
Published 2017-07-28 · Modified
7.8EPSS 0.003
CVE-2017-6254
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from an user to the driver is used without validation which may lead to denial of service or potential escalation of privileges.
Published 2017-07-28 · Modified
7.8EPSS 0.003
CVE-2017-6255
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.
Published 2017-07-28 · Modified
7.8EPSS 0.003
CVE-2024-49538
Illustrator | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.003
CVE-2026-35558
Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
7.8EPSS 0.003
CVE-2024-49544
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.003
CVE-2020-24367
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.
Published 2020-11-10 · Modified
7.8EPSS 0.003
CVE-2021-43940
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Published 2022-02-15 · Modified
7.8EPSS 0.003
CVE-2019-16471
Use-After-Free in app.measureDialog - Tianfu Cup
Published 2023-09-11 · Modified
7.8EPSS 0.003
CVE-2023-47041
ZDI-CAN-21697: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.003
CVE-2025-43545
Bridge | Access of Uninitialized Pointer (CWE-824)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2025-43546
Bridge | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2024-12752
Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability
Published 2024-12-30 · Analyzed
7.8EPSS 0.003
CVE-2022-31664
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Published 2022-08-05 · Modified
7.8EPSS 0.003
CVE-2024-47423
Adobe Framemaker | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2024-10-09 · Analyzed
7.8EPSS 0.003
CVE-2023-26388
ZDI-CAN-20286: Adobe Substance 3D Stager USDZ File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.003
CVE-2023-21621
Adobe FrameMaker Improper Input Validation Remote Code Execution Vulnerability
Published 2023-02-17 · Modified
7.8EPSS 0.003
CVE-2023-22228
Adobe Bridge Improper Input Validation Remote Code Execution Vulnerability
Published 2023-02-17 · Modified
7.8EPSS 0.003
CVE-2022-34235
Adobe Premiere Elements Uncontrolled Search Path Element Privilege Escalation
Published 2022-08-11 · Modified
7.8EPSS 0.003
CVE-2023-21574
Adobe Photoshop Improper Input Validation Remote Code Execution Vulnerability
Published 2023-02-17 · Modified
7.8EPSS 0.003
CVE-2023-21588
Adobe InDesign Improper Input Validation Remote Code Execution Vulnerability
Published 2023-01-13 · Modified
7.8EPSS 0.003
CVE-2022-29583
service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.
Published 2022-04-22 · Modified
7.8EPSS 0.003
CVE-2016-5295
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
7.8EPSS 0.003
← Prev143 / 259Next →