Vulnerabilities > Microsoft > Windows > High

DATE CVE VULNERABILITY TITLE RISK
2014-05-14 CVE-2014-0519 Permissions, Privileges, and Access Controls vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0518, and CVE-2014-0520.
network
low complexity
adobe apple microsoft linux CWE-264
7.5
2014-05-14 CVE-2014-0518 Permissions, Privileges, and Access Controls vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0519, and CVE-2014-0520.
network
low complexity
adobe apple microsoft linux CWE-264
7.5
2014-05-14 CVE-2014-0517 Permissions, Privileges, and Access Controls vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0518, CVE-2014-0519, and CVE-2014-0520.
network
low complexity
adobe apple microsoft linux CWE-264
7.5
2014-05-14 CVE-2014-0516 Permissions, Privileges, and Access Controls vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
network
low complexity
adobe apple microsoft linux CWE-264
7.5
2014-02-24 CVE-2013-6652 Path Traversal vulnerability in Google Chrome
Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for ..
network
low complexity
google microsoft CWE-22
7.5
2014-02-21 CVE-2014-0499 Permissions, Privileges, and Access Controls vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
network
low complexity
adobe apple microsoft linux CWE-264
7.8
2014-01-16 CVE-2013-6643 Improper Authentication vulnerability in multiple products
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.
network
low complexity
google apple linux opensuse microsoft debian CWE-287
7.5
2013-06-26 CVE-2013-1700 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
local
low complexity
mozilla microsoft CWE-264
7.2
2013-04-05 CVE-2013-0683 Configuration vulnerability in Cogentdatahub products
The DataSim and DataPid demonstration clients in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote servers to cause a denial of service (incorrect pointer access and client crash) via malformed data in a formatted text command.
7.1
2013-04-05 CVE-2013-0682 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cogentdatahub products
Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 do not properly handle exceptions, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed data in a formatted text command, leading to out-of-bounds access to (1) heap or (2) stack memory.
network
low complexity
cogentdatahub microsoft CWE-119
7.5