VYPR

Windows

by Microsoft

CVEs (2,653)

  • CVE-2017-11927MedDec 12, 2017
    risk 0.43cvss 6.5epss 0.10

    Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an information vulnerability due to the way the Windows its:// protocol…

  • CVE-2017-11872MedNov 15, 2017
    risk 0.43cvss 6.5epss 0.07

    Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice, due to how Microsoft Edge handles redirect requests, aka…

  • CVE-2017-0170MedJul 11, 2017
    risk 0.43cvss 6.5epss 0.07

    Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML…

  • CVE-2017-8533MedJun 15, 2017
    risk 0.43cvss 6.5epss 0.08

    Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure…

  • CVE-2016-7226MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

  • CVE-2016-7225MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

  • CVE-2016-7224MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka…

  • CVE-2016-3209MedOct 14, 2016
    risk 0.43cvss 5.5epss 0.54

    Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…

  • CVE-2016-3372MedSep 14, 2016
    risk 0.43cvss 6.6epss 0.02

    The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation…

  • CVE-2016-1715MedJan 12, 2016
    risk 0.43cvss 6.6epss 0.02

    The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory…

  • CVE-2026-50508MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.09

    Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-21265MedJan 13, 2026
    risk 0.42cvss 6.4epss 0.01

    Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing…

  • CVE-2025-53716MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

  • CVE-2025-24996MedMar 11, 2025
    risk 0.42cvss 6.5epss 0.01

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-21313MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.02

    Windows Security Account Manager (SAM) Denial of Service Vulnerability

  • CVE-2025-21288MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.01

    Windows COM Server Information Disclosure Vulnerability

  • CVE-2025-21272MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.01

    Windows COM Server Information Disclosure Vulnerability

  • CVE-2025-21217MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.02

    Windows NTLM Spoofing Vulnerability

  • CVE-2024-43487MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2024-38234MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Networking Denial of Service Vulnerability

Page 71 of 133