Количество 376 565
Количество 376 565
CVE-2026-62748
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62747
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62746
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62745
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62743
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62742
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62741
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62740
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
CVE-2026-62739
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62738
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
CVE-2026-62737
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62736
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62735
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62734
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62733
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62732
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-6272
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data.
CVE-2026-62729
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62728
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62748 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62747 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62746 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62745 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62743 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62742 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62741 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 2% Низкий | 3 дня назад | |
CVE-2026-62740 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62739 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62738 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-62737 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62736 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62735 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62734 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62733 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62732 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
CVE-2026-62730 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 3 дня назад | |
CVE-2026-6272 A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data. | 0% Низкий | 4 месяца назад | ||
CVE-2026-62729 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад | |
CVE-2026-62728 Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу