Search Results (4544 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-17098 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2025-08-28 5.5 Medium
Windows GDI+ Information Disclosure Vulnerability
CVE-2020-17097 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2025-08-28 3.3 Low
Windows Digital Media Receiver Elevation of Privilege Vulnerability
CVE-2020-17096 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2025-08-28 7.5 High
Windows NTFS Remote Code Execution Vulnerability
CVE-2020-17095 1 Microsoft 11 Windows 10, Windows 10 1607, Windows 10 1803 and 8 more 2025-08-28 8.5 High
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2020-17094 1 Microsoft 10 Windows 10, Windows 10 1809, Windows 10 1909 and 7 more 2025-08-28 5.5 Medium
Windows Error Reporting Information Disclosure Vulnerability
CVE-2020-17092 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2025-08-28 7.8 High
Windows Network Connections Service Elevation of Privilege Vulnerability
CVE-2020-16996 1 Microsoft 8 Windows Server 1903, Windows Server 1909, Windows Server 2004 and 5 more 2025-08-28 6.5 Medium
Kerberos Security Feature Bypass Vulnerability
CVE-2020-16964 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16963 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16962 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16961 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16960 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16959 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2020-16958 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2025-08-28 7.8 High
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2024-30039 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-08-27 5.5 Medium
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-30025 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-08-27 7.8 High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2024-30020 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-08-27 8.1 High
Windows Cryptographic Services Remote Code Execution Vulnerability
CVE-2024-30018 1 Microsoft 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more 2025-08-27 7.8 High
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30011 1 Microsoft 5 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 2 more 2025-08-27 6.5 Medium
Windows Hyper-V Denial of Service Vulnerability
CVE-2023-38545 5 Fedoraproject, Haxx, Microsoft and 2 more 19 Fedora, Libcurl, Windows 10 1809 and 16 more 2025-08-27 8.8 High
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.