Directx
Vendor:
First CVE: Aug 27, 2003 · Active for 22 years
13
Total CVEs
More Total CVEs than 91% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
7.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Directx over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2003
22 years ago
Most Recent CVE
Dec 12, 2012
4,972 days ago
CVE Severity & Scoring
Directx13 CVEs
92%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (7.7%)
Unknown12 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.7%)
High0 (0.0%)
Unknown12 (92.3%)
User Interaction
None0 (0.0%)
Unknown12 (92.3%)
Required1 (7.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (7.7%)
Unknown12 (92.3%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1537HIGH Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Wi | May 29, 2009 | 8.8 | 87 | YES | NO |
CVE-2007-3901HIGH Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers t | Dec 12, 2007 | 8.5 | 65 | NO | YES |
CVE-2008-1444HIGH Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange ( | Jun 12, 2008 | 9.3 | 50 | NO | NO |
CVE-2012-1537HIGH Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a | Dec 12, 2012 | 9.3 | 41 | NO | NO |
CVE-2010-1880HIGH Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute | Jun 8, 2010 | 9.3 | 41 | NO | NO |
CVE-2007-3895HIGH Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file. | Dec 12, 2007 | 9.3 | 41 | NO | NO |
CVE-2010-1879HIGH Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to | Jun 8, 2010 | 9.3 | 40 | NO | NO |
CVE-2008-0011HIGH Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error che | Jun 12, 2008 | 9.3 | 40 | NO | NO |
CVE-2009-0084HIGH Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huf | Apr 15, 2009 | 9.3 | 38 | NO | NO |
CVE-2009-1539HIGH The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does no | Jul 15, 2009 | 9.3 | 37 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
1 CVE
7.7% of CVEs· 97th percentile
Metasploit
1 CVE
7.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Directx
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0c | 6 | 9.0 | 36.8% | 1 | 1 |
| 9.0b | 6 | 8.4 | 35.4% | 1 | 1 |
| 9.0a | 7 | 8.3 | 35.1% | 1 | 1 |
| 9.0 | 9 | 9.2 | 32.2% | 1 | 0 |
| 8.2 | 2 | 6.8 | 36.1% | 0 | 1 |
| 8.1b | 3 | 7.4 | 41.1% | 1 | 1 |
| 8.1a | 2 | 6.8 | 36.1% | 0 | 1 |
| 8.1 | 10 | 8.6 | 34.8% | 1 | 1 |
| 8.0a | 2 | 6.8 | 36.1% | 0 | 1 |
| 8.0 | 2 | 6.8 | 36.1% | 0 | 1 |
| 7.1 | 3 | 7.4 | 41.1% | 1 | 1 |
| 7.0a | 4 | 7.5 | 39.0% | 1 | 1 |
| 7.0 | 9 | 8.5 | 35.1% | 1 | 1 |
| 6.1 | 2 | 8.0 | 39.3% | 0 | 1 |
| 5.2 | 2 | 8.0 | 39.3% | 0 | 1 |
| 11.1 | 1 | 9.3 | 22.6% | 0 | 0 |
| 11.0 | 1 | 9.3 | 22.6% | 0 | 0 |
| 10.1 | 1 | 9.3 | 22.6% | 0 | 0 |
| 10.0 | 5 | 9.1 | 35.1% | 0 | 1 |