Latest CVE Feed
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.