| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call. |
| Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini. |
| Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) |
| Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
| Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |
| Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. |
| Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. |
| Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network. |
| Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |