Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2017-12-27 CVE-2017-7157 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2017-12-27 CVE-2017-7156 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2017-12-25 CVE-2017-13870 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2017-12-25 CVE-2017-13866 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2017-12-25 CVE-2017-13864 Information Exposure vulnerability in Apple Icloud and Itunes
An issue was discovered in certain Apple products.
4.3
2017-12-25 CVE-2017-13856 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2017-12-16 CVE-2017-3196 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rawether Project Rawether
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets.
local
low complexity
rawether-project microsoft CWE-119
7.2
2017-12-14 CVE-2017-17671 Path Traversal vulnerability in Vbulletin
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is not blocked.
network
low complexity
vbulletin microsoft CWE-22
7.5
2017-12-09 CVE-2017-11294 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Shockwave 8.5.1.102
An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier.
network
low complexity
adobe microsoft CWE-119
critical
10.0
2017-12-06 CVE-2017-17069 Untrusted Search Path vulnerability in Amazon Audible 2.34.0/2.44.1
ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.
network
amazon microsoft CWE-426
critical
9.3