VendorsMicrosoftwindows_7any version
Vulnerabilities

Microsoft Windows 7 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3056CVEs
CVE-2011-1462
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Published 2011-07-21 · Modified
9.3EPSS 0.039
CVE-2020-1153
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.038
CVE-2010-0527
Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
Published 2010-03-31 · Modified
9.3EPSS 0.038
CVE-2020-1046
.NET Framework Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.038
CVE-2010-0536
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.
Published 2010-03-31 · Modified
9.3EPSS 0.037
CVE-2011-3247
Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.
Published 2011-10-28 · Modified
9.3EPSS 0.037
CVE-2020-1175
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1174, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1176
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1174, CVE-2020-1175.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1174
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1175, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1051
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1174, CVE-2020-1175, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2021-1668
Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2011-3251
Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.
Published 2011-10-28 · Modified
9.3EPSS 0.036
CVE-2019-0909
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.036
CVE-2011-0223
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Published 2011-07-21 · Modified
9.3EPSS 0.036
CVE-2011-0237
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Published 2011-07-21 · Modified
9.3EPSS 0.036
CVE-2011-0240
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Published 2011-07-21 · Modified
9.3EPSS 0.036
CVE-2011-0253
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Published 2011-07-21 · Modified
9.3EPSS 0.036
CVE-2010-1286
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2010-1287
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2010-1291
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2020-1339
Windows Media Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.034
CVE-2013-0987
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QTIF file.
Published 2013-05-24 · Modified
9.3EPSS 0.034
CVE-2013-1015
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TeXML file.
Published 2013-05-24 · Modified
9.3EPSS 0.033
CVE-2013-1020
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.
Published 2013-05-24 · Modified
9.3EPSS 0.033
CVE-2020-1061
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.033
CVE-2020-1508
Windows Media Audio Decoder Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.033
CVE-2010-4314
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
Published 2017-03-11 · Modified
9.3EPSS 0.031
CVE-2022-24492
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.031
CVE-2019-1057
MS XML Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.031
CVE-2022-24541
Windows Server Service Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.030
CVE-2011-0248
Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL file.
Published 2011-08-04 · Modified
9.3EPSS 0.030
CVE-2022-21851
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2022-21850
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2013-0999
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1000
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1001
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1002
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1003
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1004
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
CVE-2013-1005
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
9.3EPSS 0.027
← Prev18 / 77Next →