Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectToString resets the per-call length counter (_currentToStringLength) on every top-level call and StringBuilderOutput enforces no cumulative output-size limit. An attacker who can supply a template can render a near-limit string repeatedly in a loop, allocating approximately 1GB of memory and causing an out-of-memory condi
Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers who can supply templates can cause out-of-memory exceptions or CPU exhaustion, typically terminating the entire host process.
stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access but ReadMessageHistory denied can retrieve individual message content by ID, bypassing the intended history restriction enforced by bulk read routes.
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.