Skip to main content

Vendor/product archive

microsoft / windows CVEs

Beta · best-effort

10,104 CVEs tagged to microsoft / windows1,705 Critical, 5,252 High, 2,835 Medium, 311 Low, 1 Unrated.

CVE-2011-0537

Published Feb 4, 2011

Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Win…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0754

Published Feb 2, 2011

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier fo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0450

Published Jan 31, 2011

The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0638

Published Jan 25, 2011

Microsoft Windows does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute a…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4423

Published Jan 19, 2011

Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, when running on Windows, allows local users…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4587

Published Dec 22, 2010

Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assisted remote attackers to have an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1508

Published Dec 9, 2010

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafte…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0530

Published Dec 9, 2010

Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive infor…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4368

Published Dec 2, 2010

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 9,776-9,800 of 10,104 CVEsPage 392 of 405