VendorsMicrosoftwindows_7all versions
Vulnerabilities

Microsoft Windows 7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3086CVEs
CVE-2020-0824
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
Published 2020-03-12 · Modified
7.6EPSS 0.072
CVE-2020-1213
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
Published 2020-06-09 · Modified
7.6EPSS 0.072
CVE-2020-1216
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1230, CVE-2020-1260.
Published 2020-06-09 · Modified
7.6EPSS 0.072
CVE-2020-1260
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
Published 2020-06-09 · Modified
7.6EPSS 0.072
CVE-2019-1063
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
Published 2019-07-15 · Modified
7.6EPSS 0.072
CVE-2020-1230
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260.
Published 2020-06-09 · Modified
7.6EPSS 0.071
CVE-2019-1104
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
Published 2019-07-29 · Modified
7.6EPSS 0.071
CVE-2020-1062
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1092.
Published 2020-05-21 · Modified
7.6EPSS 0.062
CVE-2017-8519
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8547.
Published 2017-06-15 · Modified
7.6EPSS 0.061
CVE-2017-8547
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8519.
Published 2017-06-15 · Modified
7.6EPSS 0.061
CVE-2014-2781
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different integrity levels, which allows attackers to bypass intended access restrictions by leveraging control over a low-integrity process to launch the On-Screen Keyboard (OSK) and then upload a crafted application, aka "On-Screen Keyboard Elevation of Privilege Vulnerability."
Published 2014-07-08 · Modified
7.6EPSS 0.060
CVE-2019-0988
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.057
CVE-2017-11856
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11855.
Published 2017-11-15 · Modified
7.6EPSS 0.056
CVE-2019-0920
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.055
CVE-2017-0109
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0075.
Published 2017-03-17 · Modified
7.6EPSS 0.045
CVE-2020-1567
MSHTML Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
7.6EPSS 0.037
CVE-2019-1194
Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.034
CVE-2019-1005
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.033
CVE-2019-1055
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.033
CVE-2019-1038
Microsoft Browser Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.033
CVE-2019-1080
Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
7.6EPSS 0.033
CVE-2019-1133
Scripting Engine Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.033
CVE-2011-0132
Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.032
CVE-2011-0133
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.032
CVE-2011-0149
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to a "dangling pointer" and iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.032
CVE-2011-0115
The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.032
CVE-2011-0116
Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to DOM manipulations during iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.032
CVE-2020-1035
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1058, CVE-2020-1060, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1093
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1060.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1064
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1092
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1062.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1058
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1060, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2020-1060
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1093.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2019-1193
Microsoft Browser Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.031
CVE-2011-0152
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.027
CVE-2011-0155
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.027
CVE-2011-0164
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.027
CVE-2011-0119
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.026
CVE-2011-0120
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.026
CVE-2011-0121
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Published 2011-03-03 · Modified
7.6EPSS 0.026
← Prev46 / 78Next →