Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
127
Current result set after filter and search.
Exploited Flagged
107
Rows with a non-empty exploitation signal.
Distinct CWE
8
Unique weakness classes in this view.
Modules
81
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-190: Integer Overflow or Wraparound Clear filters
Release Month
March 2023
8 CVE | last update 1 day(s) ago
Release 2023-03-14 Patch Tuesday Count 7
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-24871
Windows Bluetooth Service
Exploitation Less Likely
Windows Bluetooth Service Remote Code Execution Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
goodbyeselene
CVE-2023-24908
Remote Procedure Call Runtime
Exploitation Less Likely
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
CVE-2023-24869
Remote Procedure Call Runtime
Exploitation Less Likely
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
CVE-2023-23405
Remote Procedure Call Runtime
Exploitation Less Likely
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
CVE-2023-24909
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
kap0k
CVE-2023-24906
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Reported By
Adel from MSRC's V&M
CVE-2023-24863
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Reported By
kap0k
Release 2023-03-10 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-25155
Integer Overflow in several Redis commands can lead to
No latest release note
Integer Overflow in several Redis commands can lead to denial of service.
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2023-03-10 - -
Release Month
February 2023
5 CVE | last update 1 day(s) ago
Release 2023-02-14 Patch Tuesday Count 4
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21803
Windows iSCSI Discovery Service
Exploitation Less Likely
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-02-14 No
Reported By
CVE-2023-21802
Windows Media
Exploitation Less Likely
Windows Media Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-02-14 No
Reported By
CVE-2023-21823
Windows Graphics Component
Exploitation Detected
Windows Graphics Component Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
2023-02-14 Yes
Reported By
Genwei Jiang and Dhanesh Kizhakkinan of Mandiant
Dhanesh Kizhakkinan with Mandiant
CVE-2023-21797
Microsoft ODBC Driver
Exploitation Less Likely
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-02-14 No
Reported By
Anonymous
Release 2023-02-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-38725
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a
No latest release note
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2023-02-04 - -
Release Month
January 2023
6 CVE | last update 1 day(s) ago
Release 2023-01-17 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-22895
The bzip2 crate before 0.4.4 for Rust allow attackers to cause a
No latest release note
The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2023-01-17 - -
Release 2023-01-10 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21765
Windows Print Spooler
Exploitation Less Likely
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
lm0963, l1nk3d, and renyimen with From TianGong Team of Legendsec at Qi'anxin Group
CVE-2023-21557
Windows Lightweight Directory Access Protocol (LDAP)
Exploitation Less Likely
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE)
CVE-2023-21754
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
CVE-2023-21730
Microsoft Cryptographic Services
Exploitation Less Likely
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE)
CVE-2023-21561
Microsoft Cryptographic Services
Exploitation Less Likely
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE)
Release Month
March 2022
1 CVE | last update 1 day(s) ago
Release 2022-03-05 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3607
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory resulting in a
No latest release note
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
2022-03-05 - -
Release Month
October 2021
2 CVE | last update 1 day(s) ago
Release 2021-10-22 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-41991
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly.
No latest release note
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-10-22 - -
CVE-2021-41990
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator.
No latest release note
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-10-22 - -
Release Month
August 2021
1 CVE | last update 1 day(s) ago
Release 2021-08-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-35942
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a
No latest release note
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
2021-08-03 - -
Release Month
July 2021
1 CVE | last update 1 day(s) ago
Release 2021-07-30 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2015-4645
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a
No latest release note
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input which triggers a stack-based buffer overflow.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2021-07-30 - -
Release Month
September 2020
2 CVE | last update 1 day(s) ago
Release 2020-09-25 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-5931
Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a
No latest release note
Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request which triggers a heap-based buffer overflow.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
2020-09-25 - -
Release 2020-09-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-12829
In QEMU through 5.0.0 an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host resulting in a
No latest release note
In QEMU through 5.0.0 an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host resulting in a denial of service.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
2020-09-09 - -
Release Month
August 2020
1 CVE | last update 1 day(s) ago
Release 2020-08-18 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-11869
An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process resulting in a
No latest release note
An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process resulting in a denial of service.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
2020-08-18 - -
Prev Page 3 / 3 | rows 101-127 of 127