Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-43492 Unspecified vulnerability in Microsoft Autoupdate
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-09-10 CVE-2024-43495 Unspecified vulnerability in Microsoft Windows 11 22H2
Windows libarchive Remote Code Execution Vulnerability
local
low complexity
microsoft
7.3
2024-08-26 CVE-2024-41879 Out-of-bounds Write vulnerability in multiple products
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe microsoft CWE-787
7.8
2024-08-23 CVE-2024-38207 Out-of-bounds Write vulnerability in Microsoft Edge Chromium
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
network
low complexity
microsoft CWE-787
6.3
2024-08-22 CVE-2024-38208 Cross-site Scripting vulnerability in Microsoft Edge
Microsoft Edge for Android Spoofing Vulnerability
network
low complexity
microsoft CWE-79
6.1
2024-08-22 CVE-2024-38209 Type Confusion vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-843
7.8
2024-08-22 CVE-2024-38210 Out-of-bounds Read vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-125
7.8
2024-08-21 CVE-2024-7965 Out-of-bounds Write vulnerability in multiple products
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google microsoft CWE-787
8.8
2024-08-21 CVE-2024-7971 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.
network
low complexity
google microsoft CWE-843
critical
9.6
2024-08-20 CVE-2024-38175 Unspecified vulnerability in Microsoft Azure Managed Instance for Apache Cassandra
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
network
low complexity
microsoft
8.8