Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,134 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network. |
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. |
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. |
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. |
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. |
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Server allows an authorized attacker to elevate privileges locally. |
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification...Show more |
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection.
This issue affects CSM (Customer Service Management): before 8.0.3. |
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic li...Show more |
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to...Show more |