Vulnerabilities > Microsoft > Windows 8 1 > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-05-12 CVE-2017-0272 Remote Code Execution vulnerability in Microsoft Windows SMB Server
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability".
network
microsoft
critical
9.3
2017-05-09 CVE-2017-0290 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
network
microsoft CWE-119
critical
9.3
2017-04-12 CVE-2017-0166 Incorrect Calculation of Buffer Size vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated.
network
microsoft CWE-131
critical
9.3
2017-04-12 CVE-2017-3058 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class.
9.3
2017-04-12 CVE-2017-3059 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object.
network
low complexity
adobe microsoft apple google linux CWE-416
critical
10.0
2017-04-12 CVE-2017-3060 Out-of-bounds Read vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser.
network
low complexity
adobe microsoft apple google linux CWE-125
critical
10.0
2017-04-12 CVE-2017-3061 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser.
network
low complexity
adobe microsoft apple google linux CWE-119
critical
10.0
2017-04-12 CVE-2017-3062 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property.
network
low complexity
adobe microsoft apple google linux CWE-416
critical
10.0
2017-04-12 CVE-2017-3063 Use After Free vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class.
network
low complexity
adobe microsoft apple google linux CWE-416
critical
10.0
2017-04-12 CVE-2017-3064 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Flash Player
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline.
9.3