Filtered by vendor Microsoft Subscriptions
Total 20250 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-8690 2 Microsoft, Paloaltonetworks 2 Windows, Cortex Xdr Agent 2024-10-15 4.4 Medium
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
CVE-2023-3955 3 Kubernetes, Microsoft, Redhat 4 Kubelet, Kubernetes, Windows and 1 more 2024-10-15 8.8 High
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
CVE-2023-28740 2 Intel, Microsoft 5 Qat Drivers, Quickassist Technology, Quickassist Technology Firmware and 2 more 2024-10-15 6.7 Medium
Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2023-48694 1 Microsoft 1 Azure Rtos Usbx 2024-10-15 6.8 Medium
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in host stack and host class, related to device linked classes, ASIX, Prolific, SWAR, audio, CDC ECM in RTOS v6.2.1 and below. The fixes have been included in USBX release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2008-5180 1 Microsoft 1 Office Communicator 2024-10-15 5.3 Medium
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
CVE-2008-4835 1 Microsoft 5 Windows 2000, Windows Server 2003, Windows Server 2008 and 2 more 2024-10-15 9.8 Critical
SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
CVE-2008-4036 1 Microsoft 4 Windows Server 2003, Windows Server 2008, Windows Vista and 1 more 2024-10-15 8.4 High
Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
CVE-2008-1083 1 Microsoft 5 Windows 2000, Windows 2003 Server, Windows Server 2008 and 2 more 2024-10-15 8.1 High
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
CVE-2023-1217 2 Google, Microsoft 2 Chrome, Windows 2024-10-15 6.5 Medium
Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CVE-2024-25707 3 Esri, Linux, Microsoft 3 Portal For Arcgis, Linux Kernel, Windows 2024-10-15 4.8 Medium
There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A user cannot be phished into clicking a link to execute code.
CVE-2006-4692 1 Microsoft 2 Windows Server 2003, Windows Xp 2024-10-15 N/A
Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
CVE-2005-3170 1 Microsoft 1 Windows 2000 2024-10-15 N/A
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
CVE-2022-41052 1 Microsoft 13 Windows 10, Windows 10 1507, Windows 10 1607 and 10 more 2024-10-15 7.8 High
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2022-38014 1 Microsoft 3 Azure Eflow, Azure Iot Edge For Linux, Windows Subsystem For Linux 2024-10-15 7 High
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2022-37967 4 Fedoraproject, Microsoft, Netapp and 1 more 12 Fedora, Windows Server 2008, Windows Server 2008 R2 and 9 more 2024-10-15 7.2 High
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-37966 4 Fedoraproject, Microsoft, Netapp and 1 more 9 Fedora, Windows Server 2008, Windows Server 2012 and 6 more 2024-10-15 8.1 High
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
CVE-2022-37955 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-10-15 7.8 High
Windows Group Policy Elevation of Privilege Vulnerability
CVE-2022-37954 1 Microsoft 9 Windows 10, Windows 10 1809, Windows 10 20h2 and 6 more 2024-10-11 7.8 High
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-35841 1 Microsoft 12 Windows 10, Windows 10 1507, Windows 10 1607 and 9 more 2024-10-11 8.8 High
Windows Enterprise App Management Service Remote Code Execution Vulnerability
CVE-2022-35833 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-10-11 7.5 High
Windows Secure Channel Denial of Service Vulnerability