| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
| Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
| Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
| Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. |
| Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
| Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. |
| bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3. |