| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. |
| External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. |
| Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally. |
| Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. |
| Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
| Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the '
Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. |
| bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3. |