Show filters
4,015 Total Results
Displaying 61-70 of 4,015
Sort by:
Attacker Value
High

CVE-2021-26899

Disclosure Date: March 11, 2021 (last updated November 28, 2024)
Windows UPnP Device Host Elevation of Privilege Vulnerability
2
Attacker Value
Moderate

CVE-2020-1301 Windows SMB Remote Code Execution Vulnerability

Disclosure Date: June 09, 2020 (last updated October 06, 2023)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
Attacker Value
Unknown

CVE-2019-6111

Disclosure Date: January 31, 2019 (last updated November 08, 2023)
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
Attacker Value
Very Low

CVE-2024-49113

Disclosure Date: December 12, 2024 (last updated January 15, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
1
Attacker Value
Very Low

CVE-2024-43452

Disclosure Date: November 12, 2024 (last updated January 06, 2025)
Windows Registry Elevation of Privilege Vulnerability
1
Attacker Value
Unknown

CVE-2024-21302

Disclosure Date: August 08, 2024 (last updated September 18, 2024)
Summary: Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Microsoft is developing a security update to mitigate this threat, but it is not yet available. Guidance to help customers reduce the risks associated with this vulnerability and to protect their systems until the mitigation is available in a Windows security update is provided in the Recommended Actions section of this CVE. This CVE will be updated when the mitigation is available in a Windows security update. We highly encourage customers to subscribe to Security Upda…
Attacker Value
High

CVE-2024-35250

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Attacker Value
High

CVE-2024-30088

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Windows Kernel Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2022-41033

Disclosure Date: October 11, 2022 (last updated January 11, 2025)
Windows COM+ Event System Service Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2021-44142

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.