cbcvebase.

Microsoft Windows vulnerabilities

459 known vulnerabilities affecting microsoft/windows.

Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2

Vulnerabilities

Page 17 of 23
CVE-2020-0963P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-0963 [MEDIUM] CVE-2020-0963: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
nvd
CVE-2020-1348P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1348 [MEDIUM] CVE-2020-1348: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-1468P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1468 [MEDIUM] CVE-2020-1468: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1411P4MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+3 more2019-11-12
CVE-2019-1411 [MEDIUM] CWE-125 CVE-2019-1411: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
nvd
CVE-2020-1283P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-06-09
CVE-2020-1283 [MEDIUM] CVE-2020-1283: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2019-0614P4MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+15 more2019-04-08
CVE-2019-0614 [MEDIUM] CVE-2019-0614: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
nvd
CVE-2020-0774P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0774 [MEDIUM] CVE-2020-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0874, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.
nvd
CVE-2019-1465P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1465 [MEDIUM] CWE-125 CVE-2019-1465: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.
nvd
CVE-2020-0993P4MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-0993 [MEDIUM] CVE-2020-0993: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, ak A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
nvd
CVE-2019-0707P4HIGHCVSS 7.0v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-05-16
CVE-2019-0707 [HIGH] CWE-787 CVE-2019-0707: An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS E
nvd
CVE-2019-1338P4MEDIUMCVSS 5.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-10-10
CVE-2019-1338 [MEDIUM] CVE-2019-1338: A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacke A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'.
nvd
CVE-2019-0656P4HIGHCVSS 7.0v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-03-05
CVE-2019-0656 [HIGH] CVE-2019-0656: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1204P4HIGHCVSS 7.1v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-06-09
CVE-2020-1204 [HIGH] CVE-2020-1204: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0931P4HIGHCVSS 7.0v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-05-16
CVE-2019-0931 [HIGH] CVE-2019-0931: An elevation of privilege vulnerability exists when the Storage Service improperly handles file oper An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1037P4HIGHCVSS 7.0v10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-07-15
CVE-2019-1037 [HIGH] CVE-2019-1037: An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles file An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1318P4MEDIUMCVSS 5.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1318 [MEDIUM] CWE-290 CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Se A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
nvd
CVE-2019-1317P4HIGHCVSS 7.3v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-10-10
CVE-2019-1317 [HIGH] CWE-59 CVE-2019-1317: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2020-0917P4MEDIUMCVSS 6.8v10 Version 1809 for x64-based Systems2020-04-15
CVE-2020-0917 [MEDIUM] CVE-2020-0917: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to proper An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.
nvd
CVE-2020-0942P4HIGHCVSS 7.1v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-04-15
CVE-2020-0942 [HIGH] CVE-2020-0942: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0944, CVE-2020-1029.
nvd
CVE-2020-0854P4HIGHCVSS 7.1v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-03-12
CVE-2020-0854 [HIGH] CVE-2020-0854: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows vulnerabilities | cvebase