Vulnerability index

Browse CVEs

203 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Windows 10 HIGH 7.8
CVE-2019-0730

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 7.8
CVE-2019-0731

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,950 2019-04-09
Windows 10 MEDIUM 5.5
CVE-2019-0796

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,600 2019-04-09
Skype HIGH 7.8
CVE-2016-5720

Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…

Mitigation only
Fix from $1,950 2017-01-23
Windows 10 HIGH 7.8
CVE-2016-7260

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 7.8
CVE-2016-7271

The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual t…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.8
CVE-2016-7275

Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted appl…

Mitigation only
Fix from $1,950 2016-12-20
Sql Server HIGH 8.8
CVE-2016-7254EPSS 12%

Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gai…

Mitigation only
Fix from $1,950 2016-11-10
Sql Server HIGH 8.8
CVE-2016-7253EPSS 12%

The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote a…

Mitigation only
Fix from $1,950 2016-11-10
Sql Server HIGH 8.8
CVE-2016-7250EPSS 12%

Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users…

Mitigation only
Fix from $1,950 2016-11-10
Sql Server HIGH 8.8
CVE-2016-7249EPSS 12%

Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via …

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7246

The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows…

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7238

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows…

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7222

Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname …

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7221

Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an…

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7215

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.3
CVE-2016-7211

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-7188

The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local…

No fix yet
Fix from $1,950 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-7185

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

No fix yet
Fix from $1,950 2016-10-14
Live Meeting HIGH 7.8
CVE-2016-3396EPSS 24%

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…

Mitigation only
Fix from $1,950 2016-10-14
Edge MEDIUM 5.3
CVE-2016-3388EPSS 28%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain…

No fix yet
Fix from $1,600 2016-10-14
Edge HIGH 7.5
CVE-2016-3387EPSS 20%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain…

No fix yet
Fix from $1,950 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-3341EPSS 7%

The kernel-mode drivers in Transaction Manager in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, …

Mitigation only
Fix from $1,950 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-3270EPSS 7%

The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

Mitigation only
Fix from $1,950 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-3266EPSS 6%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-10-14
Windows 10 MEDIUM 5.5
CVE-2016-3373EPSS 17%

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windo…

No fix yet
Fix from $1,600 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3355

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 20…

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3349

The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to …

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3348EPSS 13%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3346

Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafte…

Mitigation only
Fix from $1,950 2016-09-14