Vulnerabilities > Microsoft > Windows > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-10-16 CVE-2019-19513 Out-of-bounds Write vulnerability in Un4Seen Bassmidi
The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability.
network
low complexity
un4seen microsoft CWE-787
critical
10.0
2020-01-10 CVE-2012-4603 Improper Input Validation vulnerability in Citrix Receiver and Xenapp Online
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.
network
citrix microsoft CWE-20
critical
9.3
2020-01-09 CVE-2012-2950 Unrestricted Upload of File with Dangerous Type vulnerability in Gatewaygeomatics Mapserver
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.
9.3
2019-09-05 CVE-2019-1939 Improper Privilege Management vulnerability in Cisco Webex Teams
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system.
network
cisco microsoft CWE-269
critical
9.3
2019-08-16 CVE-2019-7958 Incorrect Permission Assignment for Critical Resource vulnerability in Adobe Creative Cloud
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.
network
low complexity
adobe apple microsoft CWE-732
critical
10.0
2019-08-16 CVE-2019-7959 Improper Input Validation vulnerability in Adobe Creative Cloud
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnerability.
network
low complexity
adobe apple microsoft CWE-20
critical
10.0
2019-08-06 CVE-2019-5684 Out-of-bounds Write vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.
network
low complexity
nvidia microsoft CWE-787
critical
10.0
2019-08-06 CVE-2019-5685 Out-of-bounds Write vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.
network
low complexity
nvidia microsoft CWE-787
critical
10.0
2019-07-26 CVE-2019-13382 Link Following vulnerability in Techsmith Snagit 2019.1.2
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name.
network
techsmith microsoft CWE-59
critical
9.3
2019-07-11 CVE-2019-12574 Untrusted Search Path vulnerability in Londontrustmedia Private Internet Access VPN Client 1.0
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges.
9.3