Microsoft Windows 7 Service Pack 1 vulnerabilities
817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.
Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1
Vulnerabilities
Page 35 of 41
CVE-2019-1016P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1016 [MEDIUM] CWE-200 CVE-2019-1016: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1012P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1012 [MEDIUM] CWE-200 CVE-2019-1012: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1046P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1046 [MEDIUM] CWE-200 CVE-2019-1046: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1049P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1049 [MEDIUM] CWE-200 CVE-2019-1049: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1047P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1047 [MEDIUM] CWE-200 CVE-2019-1047: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2021-1699P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2021-01-12
CVE-2021-1699 [MEDIUM] CVE-2021-1699: Windows (modem.sys) Information Disclosure Vulnerability
Windows (modem.sys) Information Disclosure Vulnerability
nvd
CVE-2022-41116P4MEDIUMCVSS 5.9≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41116 [MEDIUM] CWE-362 CVE-2022-41116: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
CVE-2022-41090P4MEDIUMCVSS 5.9≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41090 [MEDIUM] CWE-362 CVE-2022-41090: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2020-17000P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-11-11
CVE-2020-17000 [MEDIUM] CVE-2020-17000: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2020-1083P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1083 [MEDIUM] CVE-2020-1083: <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component impr
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
nvd
CVE-2020-1250P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1250 [MEDIUM] CVE-2020-1250: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application
nvd
CVE-2019-0941P4MEDIUMCVSS 4.4≥ 6.1.0, < publication2019-06-12
CVE-2019-0941 [MEDIUM] CWE-19 CVE-2019-0941: A denial of service exists in Microsoft IIS Server when the optional request filtering feature impro
A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering.
To exploit this vulnerability, an attacker could send a specially crafted req
nvd
CVE-2021-31184P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.24597≥ 6.1.0, < 6.1.7601.245982021-05-11
CVE-2021-31184 [MEDIUM] CVE-2021-31184: Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
nvd
CVE-2020-17029P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-11-11
CVE-2020-17029 [MEDIUM] CVE-2020-17029: Windows Canonical Display Driver Information Disclosure Vulnerability
Windows Canonical Display Driver Information Disclosure Vulnerability
nvd
CVE-2021-1676P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2021-01-12
CVE-2021-1676 [MEDIUM] CVE-2021-1676: Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
nvd
CVE-2020-1485P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-08-17
CVE-2020-1485 [MEDIUM] CVE-2020-1485: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service impr
An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera,
nvd
CVE-2022-23281P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-23281 [MEDIUM] CVE-2022-23281: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2023-21525P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21525 [MEDIUM] CVE-2023-21525: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-21998P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.258602022-02-09
CVE-2022-21998 [MEDIUM] CVE-2022-21998: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd