|
301
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_26h1
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Update
|
CWE-122 CWE-125 CWE-416
Heap-based Buffer Overflow Out-of-bounds Read Use After Free
|
CVE-2026-44808
|
2026-06-13 02:01 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_26h1
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Update
|
CWE-20 CWE-122 CWE-416
Improper Input Validation Heap-based Buffer Overflow Use After Free
|
CVE-2026-44811
|
2026-06-13 02:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_26h1
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-44813
|
2026-06-13 01:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_11_26h1
|
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Update
|
CWE-122 CWE-125
Heap-based Buffer Overflow Out-of-bounds Read
|
CVE-2026-44814
|
2026-06-13 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
7.8 |
HIGH
Local
|
microsoft
|
windows_narrator_braille
|
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Update
|
CWE-426
Untrusted Search Path
|
CVE-2026-48565
|
2026-06-13 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
5.5 |
MEDIUM
Local
|
microsoft
|
visual_studio_code
|
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Update
|
CWE-20 CWE-23 NVD-CWE-noinfo
Improper Input Validation Relative Path Traversal
|
CVE-2026-48569
|
2026-06-13 01:57 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-52292
|
2026-06-13 01:52 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
6.5 |
MEDIUM
Network
|
gpac
|
gpac
|
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55659
|
2026-06-13 01:51 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
6.5 |
MEDIUM
Network
|
gpac
|
gpac
|
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of…
New
|
CWE-1077
Floating Point Comparison with Incorrect Operator
|
CVE-2025-55658
|
2026-06-13 01:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55657
|
2026-06-13 01:45 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|