VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2017-11852MedNov 15, 2017
    risk 0.31cvss 4.7epss 0.02

    Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka "Windows GDI…

  • CVE-2017-11851MedNov 15, 2017
    risk 0.31cvss 4.7epss 0.02

    The Windows kernel component on Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709, allows an information disclosure…

  • CVE-2017-11849MedNov 15, 2017
    risk 0.31cvss 4.7epss 0.02

    Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted…

  • CVE-2017-11842MedNov 15, 2017
    risk 0.31cvss 4.7epss 0.02

    Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing…

  • CVE-2017-11832MedNov 15, 2017
    risk 0.31cvss 4.7epss 0.02

    The Microsoft Windows embedded OpenType (EOT) font engine in Windows 7 SP1, Windows Server 2008 SP2 and 2008 R2 SP1, and Windows Server 2012 allows an attacker to potentially read data that was not intended to be disclosed, due to the way that the Microsoft Windows EOT font…

  • CVE-2017-11817MedOct 13, 2017
    risk 0.31cvss 4.7epss 0.02

    The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability…

  • CVE-2017-8719MedSep 13, 2017
    risk 0.31cvss 4.7epss 0.04

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it…

  • CVE-2017-8709MedSep 13, 2017
    risk 0.31cvss 4.7epss 0.04

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it…

  • CVE-2017-8627MedAug 8, 2017
    risk 0.31cvss 4.7epss 0.02

    Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".

  • CVE-2017-8486MedJul 11, 2017
    risk 0.31cvss 4.7epss 0.02

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, aka "Win32k…

  • CVE-2017-8554MedJun 29, 2017
    risk 0.31cvss 4.7epss 0.02

    The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via a specially…

  • CVE-2017-8553MedJun 15, 2017
    risk 0.31cvss 4.7epss 0.03

    An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows Server 2016 when the Windows kernel improperly handles objects in memory, aka "GDI Information Disclosure…

  • CVE-2017-0073MedMar 17, 2017
    risk 0.31cvss 4.3epss 0.33

    The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from…

  • CVE-2017-0049MedMar 17, 2017
    risk 0.31cvss 4.3epss 0.35

    The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those described in…

  • CVE-2017-0011MedMar 17, 2017
    risk 0.31cvss 4.3epss 0.38

    Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.

  • CVE-2017-0009MedMar 17, 2017
    risk 0.31cvss 4.3epss 0.34

    Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0011,…

  • CVE-2017-0008MedMar 17, 2017
    risk 0.31cvss 4.3epss 0.32

    Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009 and…

  • CVE-2016-7218MedNov 10, 2016
    risk 0.31cvss 4.7epss 0.04

    Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive…

  • CVE-2016-3258MedJul 13, 2016
    risk 0.31cvss 4.7epss 0.01

    Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka…

  • CVE-2026-64922MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-64916MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-64902MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-64897MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62917MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62829MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-61350MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

  • CVE-2026-48562MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-47641MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-47640MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-47638MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-47637MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45483MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45479MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45468MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45467MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45462MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-26175MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-20928MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-20959MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.07

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-20834MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.01

    Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

  • CVE-2026-20828MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.01

    Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

  • CVE-2025-21215MedJan 14, 2025
    risk 0.30cvss 4.6epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2025-21213MedJan 14, 2025
    risk 0.30cvss 4.6epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-49087MedDec 12, 2024
    risk 0.30cvss 4.6epss 0.01

    Windows Mobile Broadband Driver Information Disclosure Vulnerability

  • CVE-2024-21340MedFeb 13, 2024
    risk 0.30cvss 4.6epss 0.01

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2023-36769MedNov 6, 2023
    risk 0.30cvss 4.6epss 0.00

    Microsoft OneNote Spoofing Vulnerability

  • CVE-2023-35394MedAug 8, 2023
    risk 0.30cvss 4.6epss 0.01

    Azure HDInsight Jupyter Notebook Spoofing Vulnerability

  • CVE-2022-41099MedNov 9, 2022
    risk 0.30cvss 4.6epss 0.04

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2022-21905MedJan 11, 2022
    risk 0.30cvss 4.6epss 0.01

    Windows Hyper-V Security Feature Bypass Vulnerability

  • CVE-2022-21900MedJan 11, 2022
    risk 0.30cvss 4.6epss 0.01

    Windows Hyper-V Security Feature Bypass Vulnerability

Page 211 of 314