| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally. |
| Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network. |
| Double free in Windows Registry allows an authorized attacker to elevate privileges over a network. |
| Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. |
| Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. |
| Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
| Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
| Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. |
| Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. |
| OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. |