CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
Information published.
Categories: Microsoft
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a...
Information published.
Categories: Microsoft
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Information published.
Categories: Microsoft
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic...
Information published.
Categories: Microsoft
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this...
Information published.
Categories: Microsoft
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Information published.
Categories: Microsoft
CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session
Information published.
Categories: Microsoft
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed...
Information published.
Categories: Microsoft
CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62918 Microsoft Teams Spoofing Vulnerability
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Categories: Microsoft


