product of microsoft

windows server 2012

438 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-85880
Severity high Exploited yes
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-85360
Severity high
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
CVE-2026-84001
Severity high
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2026-84000
Severity high
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-83996
Severity high
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-83995
Severity high
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-83992
Severity high
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-83989
Severity high
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
CVE-2026-81355
Severity high
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-80096
Severity high
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.
CVE-2026-78523
Severity high
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to…
CVE-2026-78516
Severity medium
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78508
Severity medium
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information…
CVE-2026-78453
Severity medium
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-78449
Severity high
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
CVE-2026-78446
Severity medium
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
CVE-2026-78445
Severity critical
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
CVE-2026-77905
Severity high
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-77904
Severity high
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
CVE-2026-77899
Severity high
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77895
Severity high
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized…
CVE-2026-77894
Severity high
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77893
Severity high
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-77892
Severity medium
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVE-2026-77891
Severity medium
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a…
CVE-2026-77890
Severity high
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a…
CVE-2026-77889
Severity high
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a…
CVE-2026-77888
Severity high
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVE-2026-77887
Severity medium
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77886
Severity high
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77505
Severity high
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-77504
Severity high
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2026-77503
Severity high
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77502
Severity high
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77501
Severity high
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a…
CVE-2026-77499
Severity high
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77498
Severity high
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-77495
Severity high
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a…
CVE-2026-77494
Severity high
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-77493
Severity critical
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2026-77492
Severity medium
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-77491
Severity medium
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-73025
Severity critical
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-73024
Severity high
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73023
Severity high
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-73019
Severity medium
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVE-2026-73018
Severity high
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73016
Severity high
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73013
Severity high
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-73012
Severity high
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-73009
Severity critical
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-72987
Severity high
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVE-2026-72986
Severity high
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-72985
Severity medium
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
CVE-2026-72983
Severity critical
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-72982
Severity critical
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
CVE-2026-72981
Severity high
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-72979
Severity critical
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to…
CVE-2026-72978
Severity high
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
CVE-2026-72967
Severity high
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
CVE-2026-72966
Severity medium
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.
CVE-2026-72965
Severity high
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-72959
Severity high
Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.
CVE-2026-72957
Severity high
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
CVE-2026-72954
Severity high
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-72950
Severity critical
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-72948
Severity high
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
CVE-2026-72944
Severity high
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
CVE-2026-72943
Severity high
Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.
CVE-2026-72942
Severity medium
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
CVE-2026-72939
Severity medium
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2026-72937
Severity medium
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-72935
Severity medium
Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.
CVE-2026-72933
Severity high
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
CVE-2026-72932
Severity high
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to…
CVE-2026-72931
Severity medium
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
CVE-2026-72930
Severity high
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
CVE-2026-72927
Severity high
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-71353
Severity high
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a…
CVE-2026-71352
Severity high
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-71351
Severity high
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-71350
Severity medium
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-71349
Severity medium
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-71348
Severity medium
Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.
CVE-2026-71345
Severity high
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.
CVE-2026-71343
Severity high
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-71342
Severity high
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
CVE-2026-71341
Severity medium
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-71339
Severity medium
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
CVE-2026-71338
Severity medium
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
CVE-2026-71336
Severity high
Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.
CVE-2026-71334
Severity high
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-71333
Severity high
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an…
CVE-2026-71330
Severity high
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-71329
Severity medium
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-70587
Severity high
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.
CVE-2026-70586
Severity high
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.
CVE-2026-70585
Severity high
Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges…
CVE-2026-70584
Severity high
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an…
CVE-2026-70582
Severity medium

← Previous 1 of 5 Next →