Windows GDI+
by Microsoft
CVEs (107)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0977 | Med | 0.31 | 4.7 | 0.04 | Jun 12, 2019 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an… | ||
| CVE-2018-8396 | Med | 0.31 | 4.7 | 0.02 | Aug 15, 2018 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from… | ||
| CVE-2017-0073 | Med | 0.31 | 4.3 | 0.33 | Mar 17, 2017 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from… | ||
| CVE-2026-50387 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50380 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-54122 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-49796 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
- risk 0.31cvss 4.7epss 0.04
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an…
- risk 0.31cvss 4.7epss 0.02
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from…
- risk 0.31cvss 4.3epss 0.33
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from…
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 9.6epss 0.01
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.4epss 0.00
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Page 6 of 6