| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. |
| Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
| Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
| Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
| Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
| A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. |
| IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. |
| Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. |
| Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. |
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
| Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
| Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
| Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |