Show filters
2,347 Total Results
Displaying 121-130 of 2,347
Sort by:
Attacker Value
Low

CVE-2015-1635

Disclosure Date: April 14, 2015 (last updated October 05, 2023)
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
0
Attacker Value
Unknown

CVE-2015-0008

Disclosure Date: February 11, 2015 (last updated October 05, 2023)
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."
1
Attacker Value
Unknown

CVE-2013-3900

Disclosure Date: December 11, 2013 (last updated February 11, 2025)
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for W…
Attacker Value
Unknown

CVE-2025-21194

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Microsoft Surface Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-39600

Disclosure Date: July 09, 2024 (last updated January 23, 2025)
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the confidentiality but there is no impact on the integrity and availability.
Attacker Value
Unknown

CVE-2024-23594

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-23593

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
0
Attacker Value
Unknown

CVE-2023-44216

Disclosure Date: September 27, 2023 (last updated October 09, 2023)
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Attacker Value
Unknown

CVE-2022-35759

Disclosure Date: May 31, 2023 (last updated January 11, 2025)
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2022-35758

Disclosure Date: May 31, 2023 (last updated January 11, 2025)
Windows Kernel Memory Information Disclosure Vulnerability