Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Windows Number Of NVD 3854 CRITICAL 65 HIGH 2644 MEDIUM 1087 LOW 58
URL https://www.microsoft.com/
Explanation For business, developer, and desktop operating system products, 10 years of support at the supported Service Pack level (with a minimum of 5 years of mainstream support, followed by a minimum of 5 years of extended support).
You may need to deploy the latest updates to be eligible for support.
For some products, the support organization may be less than 10 years.

For consumer and multimedia products, five years of mainstream support at the supported Service Pack level.

The above text is excerpted from Microsoft's Fixed Lifecycle Policy.
Tag
  • 商用ライセンス有り
  • Microsoft

Add Information URL
No Type Name URL
1 https://www.microsoft.com/ja-jp/atlife/article-windows10-portal-eos.aspx
2 https://support.microsoft.com/help/14085/fixed-lifecycle-policy
3 https://support.microsoft.com/help/30881/modern-lifecycle-policy
4 https://support.microsoft.com//lifecycle/search
5 https://support.microsoft.com/ja-jp/hub/4095338/microsoft-lifecycle-policy
6 https://support.microsoft.com/ja-jp/help/4057281/windows-7-support-ended-on-january-14-2020
7 https://docs.microsoft.com/ja-jp/windows/release-information/
8 https://docs.microsoft.com/ja-jp/lifecycle/faq/extended-security-updates

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
3831 Windows 11 23H2 Oct. 31, 2023 Oct. 4, 2021 15 425 130 3
3832 Windows 10 (Enterprise, Education, Pro, Pro for Workstations, IoT, Home) 22H2 Oct. 18, 2022 July 29, 2015 Oct. 14, 2025 57 2049 872 33
3833 Windows Phone 8.1 June 24, 2014 July 11, 2017 0 0 0 0
3834 Windows RT 8.1 Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 27 1228 494 38
3835 Windows Embedded 8.1 Pro Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 30 1296 503 34
3836 Windows 8.1 Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 30 1296 503 34
3837 Windows Phone 7.8 Feb. 9, 2013 Oct. 14, 2014 0 0 0 0
3838 Windows 8 Oct. 30, 2012 Jan. 12, 2016 0 167 56 24
3839 Windows Embedded Standard 7(Service Pack 1適用) July 29, 2010 Oct. 13, 2015 Oct. 13, 2020 0 0 0 0
3840 Windows 7 Oct. 22, 2009 Jan. 13, 2015 April 9, 2013 Jan. 14, 2020 29 1407 538 31
3841 Windows Vista Jan. 25, 2007 April 10, 2012 April 13, 2010 April 11, 2017 1 264 67 20
3842 Windows XP Embedded Jan. 30, 2002 Jan. 12, 2016 2 287 85 0
3843 Windows XP Dec. 31, 2001 April 8, 2014 2 287 85 0
3844 Windows Millennium Edition Dec. 31, 2000 Dec. 31, 2003 July 11, 2006 0 1 1 0
3845 Microsoft Windows 2000 Professional March 31, 2000 June 30, 2005 July 13, 2010 2 40 19 0
3846 Windows 98 Second Edition June 30, 1999 June 30, 2002 July 11, 2006 1 1 1 0
3847 Windows 98 Standard Edition June 30, 1998 June 30, 2002 July 11, 2006 1 2 2 0
3848 Windows 95 Aug. 24, 1995 Dec. 31, 2001 0 3 2 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
3831 -
7.1
HIGH The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router adv… NVD-CWE-Other
CVE-2007-0066 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_xp:-:sp1
2026-04-23 09:35
2008-01-9
Show GitHub Exploit DB Packet Storm
3832 -
9.3
HIGH Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reali… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4675 cpe:2.3:o:microsoft:windows_vista:-:* 2026-04-23 09:35
2007-11-8
Show GitHub Exploit DB Packet Storm
3833 -
9.3
HIGH Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRg… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4676 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_vista:-:*
2026-04-23 09:35
2007-11-8
Show GitHub Exploit DB Packet Storm
3834 -
9.3
HIGH Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, re… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4677 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_vista:-:*
2026-04-23 09:35
2007-11-8
Show GitHub Exploit DB Packet Storm
3835 -
4.3
MEDIUM Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5145 cpe:2.3:o:microsoft:windows_xp:-:* 2026-04-23 09:35
2007-10-1
Show GitHub Exploit DB Packet Storm
3836 -
7.1
HIGH Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an… CWE-189
CWE-399
Numeric Errors
 Resource Management Errors
CVE-2007-5133 cpe:2.3:o:microsoft:windows_xp:-:*
cpe:2.3:o:microsoft:windows_vista:-:*
2026-04-23 09:35
2007-09-28
Show GitHub Exploit DB Packet Storm
3837 -
7.1
HIGH Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers… CWE-362
Race Condition
CVE-2007-3091 cpe:2.3:o:microsoft:windows_vista:-:sp2
cpe:2.3:o:microsoft:windows_vista:-:sp1
cpe:2.3:o:microsoft:windows_vista…
2026-04-23 09:35
2007-06-7
Show GitHub Exploit DB Packet Storm
3838 5.5
7.1
MEDIUM
Local
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero,… CWE-369
 Divide By Zero
CVE-2007-2237 cpe:2.3:o:microsoft:windows_xp:-:sp2 2026-04-23 09:35
2007-06-7
Show GitHub Exploit DB Packet Storm
3839 -
5.1
MEDIUM Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arb… CWE-88
Argument Injection
CVE-2006-4692 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_xp:-:sp1
2026-04-23 09:35
2006-10-11
Show GitHub Exploit DB Packet Storm
3840 -
5.4
MEDIUM Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url f… NVD-CWE-Other
CVE-2006-3351 cpe:2.3:o:microsoft:windows_xp:ibm_oem_version:sp1
cpe:2.3:o:microsoft:windows_xp:ibm_oem_version:*
2018-10-19 01:46
2006-07-6
Show GitHub Exploit DB Packet Storm