Skip to main content

Vendor/product archive

microsoft / silverlight CVEs

Beta · best-effort

32 CVEs tagged to microsoft / silverlight16 Critical, 12 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2017-8527

Published Jun 15, 2017

Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server…

CVSS 8.8 · High

CVE-2017-0283

Published Jun 15, 2017

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Mic…

CVSS 8.8 · High

CVE-2016-3209

Published Oct 14, 2016

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Window…

CVSS 5.5 · Medium

CVE-2016-3367

Published Sep 14, 2016

StringBuilder in Microsoft Silverlight 5 before 5.1.50709.0 does not properly allocate memory for string-insert and string-append operations, which allows remote attackers to exec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0034

Published Jan 13, 2016

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (objec…

CVSS 8.8 · High
evidence mentions
12
Buzz score
63.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-6166

Published Dec 9, 2015

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified ope…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6165

Published Dec 9, 2015

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6114

Published Dec 9, 2015

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2464

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 a…

CVSS 9.3 · Critical

CVE-2015-2463

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 a…

CVSS 9.3 · Critical

CVE-2015-2456

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-2455

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-2435

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-1715

Published May 13, 2015

Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-level restrictions via a crafted Silverlight application, aka "Microsoft Silverlig…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1671

Published May 13, 2015

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2…

CVSS 7.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2014-0319

Published Mar 12, 2014

Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 allow attackers to bypass the DEP and ASLR protection mechanisms via unspecified…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3896

Published Oct 9, 2013

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2013-3178

Published Jul 10, 2013

Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3129

Published Jul 10, 2013

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows X…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2013-0074

Published Mar 13, 2013

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arb…

CVSS 7.8 · High
evidence mentions
8
Buzz score
56.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2012-0176

Published May 9, 2012

Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2