Vulnerabilities > Microsoft > Windows > High

DATE CVE VULNERABILITY TITLE RISK
2016-07-22 CVE-2016-4616 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4615, and CVE-2016-4619.
network
low complexity
apple microsoft CWE-119
7.5
2016-07-22 CVE-2016-4615 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.
network
low complexity
apple microsoft CWE-119
7.5
2016-07-12 CVE-2016-5308 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Symantec Client Intrusion Detection System
The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memory corruption and system crash) via a malformed Portable Executable (PE) file.
7.1
2016-06-13 CVE-2016-2826 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Firefox ESR
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
local
low complexity
microsoft mozilla CWE-264
7.2
2016-05-30 CVE-2016-4118 Permissions, Privileges, and Access Controls vulnerability in Adobe Connect
Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.
local
low complexity
microsoft adobe CWE-264
7.2
2016-05-11 CVE-2016-4106 Remote Code Execution vulnerability in Adobe Reader and Acrobat APSB16-14
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-1090.
local
low complexity
apple microsoft adobe
7.2
2016-05-11 CVE-2016-1090 Remote Code Execution vulnerability in Adobe Reader and Acrobat APSB16-14
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-4106.
local
low complexity
apple microsoft adobe
7.2
2016-05-11 CVE-2016-1087 Remote Code Execution vulnerability in Adobe Reader and Acrobat APSB16-14
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1090 and CVE-2016-4106.
local
low complexity
apple microsoft adobe
7.2
2016-03-09 CVE-2016-1008 Improper Input Validation vulnerability in Adobe products
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
adobe apple microsoft CWE-20
7.2
2016-02-10 CVE-2016-0958 Information Exposure vulnerability in Adobe Experience Manager 5.6.1/6.0.0/6.1.0
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.
network
low complexity
adobe apple linux microsoft CWE-200
7.8