Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2023-38039 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.
network
low complexity
haxx fedoraproject microsoft CWE-770
7.5
2023-09-12 CVE-2023-38155 Unspecified vulnerability in Microsoft Azure Devops Server
Azure DevOps Server Remote Code Execution Vulnerability
network
high complexity
microsoft
8.1
2023-09-12 CVE-2023-4863 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
8.8
2023-09-05 CVE-2023-4762 Type Confusion vulnerability in multiple products
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
network
low complexity
google debian fedoraproject microsoft CWE-843
8.8
2023-08-26 CVE-2023-36741 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
network
high complexity
microsoft
7.5
2023-08-22 CVE-2020-19725 Use After Free vulnerability in Microsoft Z3
There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8.
local
low complexity
microsoft CWE-416
7.8
2023-08-08 CVE-2023-35391 Unspecified vulnerability in Microsoft .Net
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
network
low complexity
microsoft
7.5
2023-08-08 CVE-2023-36899 Unspecified vulnerability in Microsoft .Net Framework
ASP.NET Elevation of Privilege Vulnerability
network
low complexity
microsoft
8.8
2023-08-08 CVE-2023-36905 Unspecified vulnerability in Microsoft products
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
network
low complexity
microsoft
7.5
2023-08-08 CVE-2023-36906 Unspecified vulnerability in Microsoft products
Windows Cryptographic Services Information Disclosure Vulnerability
network
low complexity
microsoft
7.5