Skip to main content

Vendor/product archive

microsoft / windows_media_player CVEs

Beta · best-effort

53 CVEs tagged to microsoft / windows_media_player17 Critical, 17 High, 17 Medium, 2 Low, 0 Unrated.

CVE-2017-11768

Published Nov 15, 2017

Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows…

CVSS 2.5 · Low

CVE-2015-1728

Published Jun 10, 2015

Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2671

Published Mar 31, 2014

Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1042

Published Mar 23, 2010

Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0718

Published Feb 26, 2010

Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a craf…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1331

Published Apr 17, 2009

Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demons…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5745

Published Dec 29, 2008

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a deni…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3009

Published Dec 10, 2008

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) i…

CVSS 10.0 · Critical

CVE-2008-4927

Published Nov 4, 2008

Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, relat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6236

Published Dec 4, 2007

Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3035

Published Aug 14, 2007

Unspecified vulnerability in Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header i…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3037

Published Aug 14, 2007

Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4288

Published Aug 9, 2007

Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 53 CVEsPage 1 of 3