| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
| Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. |
| Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
| Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. |
| Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
| Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
| Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
| Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally. |
| Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Server allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
| Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |