Vulnerabilities > Microsoft > Windows 7 > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-05-12 CVE-2017-0242 Information Exposure vulnerability in Microsoft Windows 7 and Windows Server 2008
An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2017-05-12 CVE-2017-0220 Information Exposure vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Server 2012
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259.
local
high complexity
microsoft CWE-200
4.7
2017-05-12 CVE-2017-0190 Information Exposure vulnerability in Microsoft products
The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
4.4
2017-05-12 CVE-2017-0175 Information Exposure vulnerability in Microsoft Windows 7 and Windows Server 2008
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.
local
high complexity
microsoft CWE-200
4.7
2017-04-12 CVE-2017-0192 Information Exposure vulnerability in Microsoft products
The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive information via a specially crafted document or an untrusted website, aka "ATMFD.dll Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
4.3
2017-04-12 CVE-2017-0191 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory.
network
high complexity
microsoft
5.8
2017-04-12 CVE-2017-0058 Information Exposure vulnerability in Microsoft products
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information.
local
high complexity
microsoft CWE-200
4.7
2017-03-17 CVE-2017-0128 Information Exposure vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0127.
network
low complexity
microsoft CWE-200
4.3
2017-03-17 CVE-2017-0127 Information Exposure vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0128.
network
low complexity
microsoft CWE-200
4.3
2017-03-17 CVE-2017-0126 Information Exposure vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0127, and CVE-2017-0128.
network
low complexity
microsoft CWE-200
4.3