CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Information published.
EPSS 0.00 CVE-2026-57432 US
Information published.
EPSS 0.00 CVE-2026-57432 US
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56000.
EPSS 0.00 CVSS 7.8 CVE-2026-56000 X.Org Server US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56001.
EPSS 0.00 CVSS 7.8 CVE-2026-56001 X.Org US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56002.
EPSS 0.00 CVSS 7.8 CVE-2026-56002 X.Org US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56003.
EPSS 0.00 CVSS 7.8 CVE-2026-56003 X.Org libXfont2 US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-55999.
EPSS 0.00 CVSS 7.8 CVE-2026-55999 X.Org US 2 zdrojů
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40400.
EPSS 0.01 CVSS 7.8 CVE-2026-40400 Microsoft US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-49805.
EPSS 0.00 CVSS 7.0 CVE-2026-49805 Microsoft US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.
EPSS 0.00 CVSS 7.8 CVE-2026-54129 Microsoft US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.
EPSS 0.00 CVSS 7.8 CVE-2026-50311 Microsoft veřejná správa US 2 zdrojů
This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-55126.
EPSS 0.01 CVSS 7.3 CVE-2026-55126 Microsoft US 2 zdrojů
This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.
EPSS 0.01 CVSS 8.1 CVE-2026-2291 dnsmasq US 2 zdrojů
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-55008 Microsoft US
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-58529 US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
EPSS 0.01 CVE-2026-55121 Microsoft US
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
EPSS 0.00 CVE-2026-56181 US
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-58638 US
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58637 US
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58634 US
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58633 US
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58632 US
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58629 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58628 US
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-58627 US
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58626 US
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58619 US
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-58617 Microsoft US
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58613 US
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-47305 US
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58594 US
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58541 Microsoft US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-58543 US
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-58542 US
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58544 US
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-58545 US
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58547 US
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58536 US
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58534 Microsoft US
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58537 Microsoft US
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58532 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-58531 US
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58540 US
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-58539 US
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-58546 US
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-58535 US
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-58533 US
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-58530 US
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.01 CVE-2026-58528 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58527 US
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-58277 Microsoft US
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-57982 US
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-57973 US
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-57968 US
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-57108 US
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-57102 US
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-57101 US
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-57096 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-57093 US
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-57088 US
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57087 Microsoft US