|
251
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45457
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
8.4 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-843
Type Confusion
|
CVE-2026-45456
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
3.3 |
LOW
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45455
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-22
Path Traversal
|
CVE-2026-45454
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45453
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
- |
|
-
|
-
|
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes…
New
|
CWE-416
Use After Free
|
CVE-2026-45447
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
- |
|
-
|
-
|
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV
(RFC 8452) mishandle the authentication of AAD (Additional Authenticated
Data) with an empty ciphertext allowing a forgery of …
New
|
CWE-325
Missing Required Cryptographic Step
|
CVE-2026-45446
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
- |
|
-
|
-
|
Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one-shot interface, the application-supplied
initialisation vector (IV) is silently discarded.
Impact sum…
New
|
CWE-325
Missing Required Cryptographic Step
|
CVE-2026-45445
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44824
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
New
|
CWE-197 CWE-416
Numeric Truncation Error Use After Free
|
CVE-2026-44823
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|