VendorsMicrosoftwindows_8.1all versions
Vulnerabilities

Microsoft Windows 8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2873CVEs
CVE-2016-7247
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically proximate attackers to bypass the Secure Boot protection mechanism via a crafted boot policy, aka "Secure Boot Component Vulnerability."
Published 2016-11-10 · Modified
7.5EPSS 0.067
CVE-2018-5008
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-07-20 · Modified
7.5EPSS 0.067
CVE-2021-43893
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.5EPSS 0.066
CVE-2020-1108
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.063
CVE-2021-28439
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-04-13 · Modified
7.5EPSS 0.061
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2019-0820
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Published 2019-05-16 · Modified
7.5EPSS 0.057
CVE-2018-8517
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-12-12 · Modified
7.5EPSS 0.057
CVE-2018-4871
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Published 2018-01-09 · Modified
7.5EPSS 0.055
CVE-2020-0660
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2020-02-11 · Modified
7.5EPSS 0.054
CVE-2020-1031
Windows DHCP Server Information Disclosure Vulnerability
Published 2020-09-11 · Modified
7.5EPSS 0.051
CVE-2021-36953
Windows TCP/IP Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.050
CVE-2019-0980
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
Published 2019-05-16 · Modified
7.5EPSS 0.049
CVE-2019-0981
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
Published 2019-05-16 · Modified
7.5EPSS 0.049
CVE-2017-8495
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNAME Security Feature Bypass Vulnerability" or Orpheus' Lyre.
Published 2017-07-11 · Modified
7.5EPSS 0.046
CVE-2020-0909
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets.To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets., aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.046
CVE-2022-21883
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.044
CVE-2022-21848
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.042
CVE-2019-1255
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
Published 2019-09-23 · Modified
7.5EPSS 0.041
CVE-2020-0645
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
Published 2020-03-12 · Modified
7.5EPSS 0.039
CVE-2021-24111
.NET Framework Denial of Service Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.038
CVE-2021-31183
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.038
CVE-2021-1734
Windows Remote Procedure Call Information Disclosure Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.038
CVE-2021-42284
Windows Hyper-V Denial of Service Vulnerability
Published 2021-11-10 · Modified
7.5EPSS 0.037
CVE-2018-0786
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Published 2018-01-10 · Modified
7.5EPSS 0.037
CVE-2022-34720
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-09-13 · Modified
7.5EPSS 0.036
CVE-2022-26832
.NET Framework Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.036
CVE-2021-26879
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published 2021-03-11 · Modified
7.5EPSS 0.036
CVE-2022-26915
Windows Secure Channel Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.036
CVE-2021-26433
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2022-21904
Windows GDI Information Disclosure Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.035
CVE-2021-36933
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2021-36932
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2021-36926
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.035
CVE-2022-21843
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.034
CVE-2022-26831
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.5EPSS 0.033
CVE-2021-36960
Windows SMB Information Disclosure Vulnerability
Published 2021-09-15 · Modified
7.5EPSS 0.033
CVE-2021-34476
Bowser.sys Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2021-33788
Windows LSA Denial of Service Vulnerability
Published 2021-07-14 · Modified
7.5EPSS 0.033
CVE-2019-7108
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
Published 2019-05-23 · Modified
7.5EPSS 0.032
← Prev48 / 72Next →