U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Keyword (text search): cpe:/o:microsoft:windows_10:-
There are 3,142 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2023-20564

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.

Published: August 15, 2023; 6:15:11 PM -0400
V3.1: 6.7 MEDIUM
V2.0:(not available)
CVE-2023-20560

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service.

Published: August 15, 2023; 6:15:09 PM -0400
V3.1: 4.4 MEDIUM
V2.0:(not available)
CVE-2023-36913

Microsoft Message Queuing Information Disclosure Vulnerability

Published: August 08, 2023; 2:15:20 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-36912

Microsoft Message Queuing Denial of Service Vulnerability

Published: August 08, 2023; 2:15:19 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-36911

Microsoft Message Queuing Remote Code Execution Vulnerability

Published: August 08, 2023; 2:15:17 PM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-36910

Microsoft Message Queuing Remote Code Execution Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-36909

Microsoft Message Queuing Denial of Service Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 6.5 MEDIUM
V2.0:(not available)
CVE-2023-36908

Windows Hyper-V Information Disclosure Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 6.5 MEDIUM
V2.0:(not available)
CVE-2023-36907

Windows Cryptographic Services Information Disclosure Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-36906

Windows Cryptographic Services Information Disclosure Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-36905

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-36903

Windows System Assessment Tool Elevation of Privilege Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-36900

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published: August 08, 2023; 2:15:16 PM -0400
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-27382

Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published: May 10, 2023; 10:15:32 AM -0400
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-21712

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Published: April 27, 2023; 3:15:13 PM -0400
V3.1: 8.1 HIGH
V2.0:(not available)
CVE-2023-29413

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.

Published: April 18, 2023; 5:15:09 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-29412

A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

Published: April 18, 2023; 5:15:09 PM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-29411

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

Published: April 18, 2023; 5:15:09 PM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-24859

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

Published: March 14, 2023; 1:15:16 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-24858

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

Published: March 14, 2023; 1:15:16 PM -0400
V3.1: 7.5 HIGH
V2.0:(not available)