| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
| Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network. |
| Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. |
| Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. |
| Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
| Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges. |
| Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. |
| Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection. |
| A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information. |