Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 22322 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47450 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 7.8 HIGH
Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47451 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 7.8 HIGH
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47453 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47454 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47455 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47456 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47457 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Illustrator versions 28.7.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47458 3 Adobe, Apple, Microsoft 3 Bridge, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-45147 3 Adobe, Apple, Microsoft 3 Bridge, Macos, Windows 2024-11-14 N/A 5.5 MEDIUM
Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-47604 1 Microsoft 1 Nugetgallery 2024-11-13 N/A 8.2 HIGH
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.
CVE-2024-43601 2 Linux, Microsoft 2 Linux Kernel, Visual Studio Code 2024-11-08 N/A 7.8 HIGH
Visual Studio Code for Linux Remote Code Execution Vulnerability
CVE-2024-38190 1 Microsoft 1 Power Platform 2024-11-08 N/A 8.6 HIGH
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
CVE-2024-38204 1 Microsoft 1 Azure Functions 2024-11-08 N/A 7.5 HIGH
Improper Access Control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
CVE-2024-0129 4 Apple, Linux, Microsoft and 1 more 4 Macos, Linux Kernel, Windows and 1 more 2024-11-08 N/A 6.3 MEDIUM
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.
CVE-2024-38139 1 Microsoft 1 Dataverse 2024-11-08 N/A 8.7 HIGH
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2024-34121 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2024-11-01 N/A 7.8 HIGH
Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-8592 2 Autodesk, Microsoft 9 Autocad, Autocad Advance Steel, Autocad Architecture and 6 more 2024-11-01 N/A 7.8 HIGH
A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
CVE-2024-45182 2 Microsoft, Wibu 2 Windows, Wibukey 2024-10-29 N/A 5.5 MEDIUM
An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.
CVE-2024-38197 1 Microsoft 1 Teams 2024-10-22 N/A 6.5 MEDIUM
Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-38265 1 Microsoft 6 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 3 more 2024-10-22 N/A 8.8 HIGH
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability