Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
126
Current result set after filter and search.
Exploited Flagged
55
Rows with a non-empty exploitation signal.
Distinct CWE
4
Unique weakness classes in this view.
Modules
104
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-476: NULL Pointer Dereference Clear filters
Release Month
May 2026
6 CVE | last update 1 day(s) ago
Release 2026-05-12 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-40414
Windows TCP/IP
Exploitation Unlikely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Windows Attack Research & Protection (WARP) with Microsoft
CVE-2026-40413
Windows TCP/IP
Exploitation Less Likely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft
CVE-2026-40405
Windows TCP/IP
Exploitation Less Likely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft
CVE-2026-40401
Windows TCP/IP
Exploitation Unlikely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Windows Attack Research & Protection (WARP) with Microsoft
CVE-2026-34350
Windows Storport Miniport Driver
Exploitation Unlikely
Windows Storport Miniport Driver Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft Offensive Research & Security Engineering
CVE-2026-34339
Windows Lightweight Directory Access Protocol (LDAP)
Exploitation Less Likely
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Aniq Fakhrul
Howard McGreehan with MSRC V&M
Release Month
April 2026
3 CVE | last update 1 day(s) ago
Release 2026-04-14 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32216
Windows Redirected Drive Buffering System
Exploitation Less Likely
Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Erik Egsgard with Field Effect
Xinyu Yu with Tsinghua University
Shuqiao Zhang with Tsinghua University
ziiiro
CVE-2026-32071
Windows Local Security Authority Subsystem Service (LSASS)
Exploitation Less Likely
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Howard McGreehan with MSRC V&M
CVE-2026-26173
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Release Month
March 2026
3 CVE | last update 1 day(s) ago
Release 2026-03-10 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-25168
Windows Graphics Component
Exploitation Less Likely
Windows Graphics Component Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
0ccbbf129444eb66344ccafb92b00df4
CVE-2026-24293
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
CVE-2026-25165
Performance Counters for Windows
Exploitation Unlikely
Performance Counters for Windows Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Release Month
February 2026
2 CVE | last update 1 day(s) ago
Release 2026-02-10 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21525
Windows Remote Access Connection Manager
Exploitation Detected
Windows Remote Access Connection Manager Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-02-10 Yes
CVE-2026-21243
Windows Lightweight Directory Access Protocol (LDAP)
Exploitation Unlikely
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-02-10 No
Reported By
MORSE (Microsoft Offensive Research and Security Engineering)
Release Month
January 2026
1 CVE | last update 1 day(s) ago
Release 2026-01-13 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-20875
Windows Local Security Authority Subsystem Service (LSASS)
Exploitation Less Likely
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Ziran Lin with Microsoft
Release Month
December 2025
3 CVE | last update 1 day(s) ago
Release 2025-12-09 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-62466
Windows Client-Side Caching
Exploitation Less Likely
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
CVE-2025-62465
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
cyanbamboo and b2ahex
CVE-2025-62463
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
cyanbamboo and b2ahex
Release Month
November 2025
5 CVE | last update 1 day(s) ago
Release 2025-11-27 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-19797
In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a
No latest release note
In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.
No CVSS vector published
2025-11-27 - -
Release 2025-11-05 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61099
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-05 - -
Release 2025-11-02 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61104
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
CVE-2025-61101
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
CVE-2025-61100
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
Release Month
October 2025
12 CVE | last update 1 day(s) ago
Release 2025-10-31 Other / OOB Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61105
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61107
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61106
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61103
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61102
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
Release 2025-10-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-55698
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
cyanbamboo
Release 2025-10-01 Other / OOB Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2016-4912
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a
No latest release note
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-01 - -
CVE-2022-47015
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to
No latest release note
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-10-01 - -
CVE-2022-4285
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a
No latest release note
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-10-01 - -
CVE-2022-47021
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause
No latest release note
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2025-10-01 - -
CVE-2020-35503
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a
No latest release note
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
2025-10-01 - -
CVE-2020-35504
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a
No latest release note
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
2025-10-01 - -
Release Month
September 2025
1 CVE | last update 1 day(s) ago
Release 2025-09-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-25177
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to
No latest release note
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
Release Month
August 2025
3 CVE | last update 1 day(s) ago
Release 2025-08-12 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-53716
Windows Local Security Authority Subsystem Service (LSASS)
Exploitation Less Likely
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
CVE-2025-53154
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
CVE-2025-53141
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Marat Gayanov with Positive Technologies
Release Month
July 2025
4 CVE | last update 1 day(s) ago
Release 2025-07-11 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-4476
Libsoup: null pointer dereference in libsoup may lead to
No latest release note
Libsoup: null pointer dereference in libsoup may lead to denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
2025-07-11 - -
Release 2025-07-08 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-49686
Windows TCP/IP Driver
Exploitation Less Likely
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
Marat Gayanov with Positive Technologies
CVE-2025-49678
NTFS
Exploitation Unlikely
NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
Bruno Botelho
CVE-2025-49694
Microsoft Brokering File System
Exploitation Less Likely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
hazard
Release Month
June 2025
1 CVE | last update 1 day(s) ago
Release 2025-06-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-33057
Windows Local Security Authority (LSA)
Exploitation Less Likely
Windows Local Security Authority (LSA) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
Anonymous
Release Month
May 2025
3 CVE | last update 1 day(s) ago
Release 2025-05-27 Monthly Preview Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-37732
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a
No latest release note
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-05-27 - -
Release 2025-05-13 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-29838
Windows ExecutionContext Driver
Exploitation Unlikely
Windows ExecutionContext Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-05-13 No
CVE-2025-29835
Windows Remote Access Connection Manager
Exploitation Unlikely
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-05-13 No
Reported By
Anonymous with Codesafe Team of Legendsec at QI-ANXIN Group
Release Month
March 2025
3 CVE | last update 1 day(s) ago
Release 2025-03-14 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-11550
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a
No latest release note
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-03-14 - -
Release 2025-03-11 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-24997
DirectX Graphics Kernel File
Exploitation Less Likely
DirectX Graphics Kernel File Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Benoît Sevens and Vlad Stolyarov of Google Threat Analysis Group
Release 2025-03-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-50608
An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote
No latest release note
An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_metrics_ng() at prom_rw_prot.c.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-04 - -
Page 1 / 3 | rows 1-50 of 126 Next