VendorsMicrosoftwindows_101709
Vulnerabilities

Microsoft Windows 10 1709

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1679CVEs
CVE-2019-1080
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.033
CVE-2019-1133
Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.033
CVE-2020-0908
Windows Text Service Module Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
7.6EPSS 0.033
CVE-2018-0961
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Modified
7.6EPSS 0.032
CVE-2020-1064
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1035
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1058, CVE-2020-1060, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1093
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1060.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1568
Microsoft Edge PDF Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
7.6EPSS 0.031
CVE-2020-1060
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1058
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1060, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1092
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1062.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2019-1193
Microsoft Browser Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.031
CVE-2019-0992
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.026
CVE-2019-0991
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.025
CVE-2019-0993
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.025
CVE-2019-0989
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.024
CVE-2019-1003
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.024
CVE-2019-1024
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.024
CVE-2019-1052
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.024
CVE-2019-1002
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.024
CVE-2020-1172
Scripting Engine Memory Corruption Vulnerability
Published 2020-09-11 · Modified
7.6EPSS 0.022
CVE-2020-1037
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.
Published 2020-05-21 · Modified
7.6EPSS 0.022
CVE-2020-1180
Scripting Engine Memory Corruption Vulnerability
Published 2020-09-11 · Modified
7.6EPSS 0.021
CVE-2019-1139
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.019
CVE-2019-1196
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.019
CVE-2019-1197
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.019
CVE-2019-1131
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.019
CVE-2019-1195
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.019
CVE-2020-16896
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.126
CVE-2019-1453
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.5EPSS 0.099
CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Published 2019-01-08 · Modified
7.5EPSS 0.096
CVE-2020-1374
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
7.5EPSS 0.091
CVE-2018-8360
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Published 2018-08-15 · Modified
7.5EPSS 0.090
CVE-2018-0764
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.
Published 2018-01-10 · Modified
7.5EPSS 0.089
CVE-2018-0879
Microsoft Edge in Windows 10 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".
Published 2018-03-14 · Modified
7.5EPSS 0.083
CVE-2018-0765
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.
Published 2018-05-09 · Modified
7.5EPSS 0.083
CVE-2017-11788
Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to improperly handing objects in memory, aka "Windows Search Denial of Service Vulnerability".
Published 2017-11-15 · Modified
7.5EPSS 0.079
CVE-2019-0688
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
Published 2019-04-09 · Modified
7.5EPSS 0.079
CVE-2019-1083
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.078
CVE-2017-11846
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.5EPSS 0.077
← Prev29 / 42Next →