VendorsMicrosoftwindows_7any version
Vulnerabilities

Microsoft Windows 7 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3056CVEs
CVE-2022-21915
Windows GDI+ Information Disclosure Vulnerability
Published 2022-01-11 · Modified
6.5EPSS 0.028
CVE-2021-41332
Windows Print Spooler Information Disclosure Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.027
CVE-2022-22015
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.027
CVE-2021-38629
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Published 2021-09-15 · Modified
6.5EPSS 0.027
CVE-2022-22042
Windows Hyper-V Information Disclosure Vulnerability
Published 2022-07-12 · Modified
6.5EPSS 0.027
CVE-2017-0174
Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".
Published 2017-08-08 · Modified
6.5EPSS 0.026
CVE-2022-24498
Windows iSCSI Target Service Information Disclosure Vulnerability
Published 2022-04-15 · Modified
6.5EPSS 0.026
CVE-2022-30208
Windows Security Account Manager (SAM) Denial of Service Vulnerability
Published 2022-07-12 · Modified
6.5EPSS 0.025
CVE-2021-28328
Windows DNS Information Disclosure Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.025
CVE-2022-35837
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-09-13 · Modified
6.5EPSS 0.025
CVE-2019-1081
Microsoft Browser Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.023
CVE-2022-38006
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-09-13 · Modified
6.5EPSS 0.023
CVE-2022-37977
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.019
CVE-2022-38033
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.017
CVE-2022-35759
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Published 2023-05-31 · Modified
6.5EPSS 0.017
CVE-2022-35770
Windows NTLM Spoofing Vulnerability
Published 2022-10-11 · Modified
6.5EPSS 0.017
CVE-2021-40460
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.016
CVE-2022-41097
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2023-34367
Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor considers this a low severity issue.
Published 2023-06-14 · Modified
6.5EPSS 0.012
CVE-2022-26935
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.011
CVE-2022-29121
Windows WLAN AutoConfig Service Denial of Service Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.010
CVE-2011-0091
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
Published 2011-02-10 · Modified
6.4EPSS 0.055
CVE-2018-0967
A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows SNMP Service Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-04-12 · Modified
6.3EPSS 0.185
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
Published 2016-02-10 · Modified
6.21 PoCEPSS 0.131
CVE-2019-0635
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.2EPSS 0.024
CVE-2007-6753
Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
Published 2012-03-28 · Modified
6.2EPSS 0.018
CVE-2019-1399
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1310.
Published 2019-11-12 · Modified
6.2EPSS 0.017
CVE-2021-33765
Windows Installer Spoofing Vulnerability
Published 2021-07-14 · Modified
6.2EPSS 0.007
CVE-2021-26413
Windows Installer Spoofing Vulnerability
Published 2021-04-13 · Modified
6.2EPSS 0.007
CVE-2011-0096
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
Published 2011-01-31 · Modified
6.11 PoCEPSS 0.468
CVE-2017-0055
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.164
CVE-2011-1252
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
Published 2011-06-16 · Modified
6.1EPSS 0.140
CVE-2015-0006
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."
Published 2015-01-13 · Modified
6.1EPSS 0.116
CVE-2012-1872
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."
Published 2012-06-12 · Modified
6.1EPSS 0.064
CVE-2018-8470
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Published 2018-09-13 · Modified
6.1EPSS 0.033
CVE-2020-1220
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
Published 2020-06-09 · Modified
6.1EPSS 0.018
CVE-2021-36961
Windows Installer Denial of Service Vulnerability
Published 2021-09-15 · Modified
6.1EPSS 0.011
CVE-2019-1470
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-12-10 · Modified
6.0EPSS 0.068
CVE-2019-1166
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
Published 2019-10-10 · Modified
5.9EPSS 0.681
CVE-2019-1040
Windows NTLM Tampering Vulnerability
Published 2019-06-12 · Modified
5.9EPSS 0.480
← Prev61 / 77Next →