Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
29
Current result set after filter and search.
Exploited Flagged
2
Rows with a non-empty exploitation signal.
Distinct CWE
1
Unique weakness classes in this view.
Modules
29
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-770: Allocation of Resources Without Limits or Throttling Clear filters
Release Month
May 2026
1 CVE | last update 1 day(s) ago
Release 2026-05-07 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32934
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to
No latest release note
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
No CVSS vector published
2026-05-07 - -
Release Month
April 2026
1 CVE | last update 1 day(s) ago
Release 2026-04-02 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-4897
Polkit: polkit
No latest release note
Polkit: polkit: denial of service via unbounded input processing through standard input
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2026-04-02 - -
Release Month
January 2026
1 CVE | last update 1 day(s) ago
Release 2026-01-16 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-0897
Keras via Excessive Memory Allocation in HDF5 Metadata
No latest release note
Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-01-16 - -
Release Month
December 2025
1 CVE | last update 1 day(s) ago
Release 2025-12-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-68156
Expr has
No latest release note
Expr has Denial of Service via Unbounded Recursion in Builtin Functions
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-12-19 - -
Release Month
November 2025
1 CVE | last update 1 day(s) ago
Release 2025-11-15 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-12748
Libvirt
No latest release note
Libvirt: denial of service in xml parsing
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-11-15 - -
Release Month
October 2025
1 CVE | last update 1 day(s) ago
Release 2025-10-01 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-5835
libplist allows attackers to cause a
No latest release note
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-01 - -
Release Month
September 2025
1 CVE | last update 1 day(s) ago
Release 2025-09-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-32049
Libsoup
No latest release note
Libsoup: denial of service attack to websocket server
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
Release Month
August 2025
1 CVE | last update 1 day(s) ago
Release 2025-08-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-50172
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
cyanbamboo and b2ahex
Release Month
March 2025
4 CVE | last update 1 day(s) ago
Release 2025-03-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential
No latest release note
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
2025-03-19 - -
Release 2025-03-14 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21690
scsi: storvsc: Ratelimit warning logs to prevent VM
No latest release note
scsi: storvsc: Ratelimit warning logs to prevent VM denial of service
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
Release 2025-03-08 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-22869
Potential
No latest release note
Potential denial of service in golang.org/x/crypto
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-08 - -
Release 2025-03-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27144
Go JOSE's Parsing Vulnerable to
No latest release note
Go JOSE's Parsing Vulnerable to Denial of Service
No CVSS vector published
2025-03-04 - -
Release Month
October 2024
1 CVE | last update 1 day(s) ago
Release 2024-10-08 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-43567
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
Release Month
September 2024
1 CVE | last update 1 day(s) ago
Release 2024-09-11 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-6337
Vault May be Vulnerable to a
No latest release note
Vault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP Requests
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-09-11 - -
Release Month
February 2024
1 CVE | last update 1 day(s) ago
Release 2024-02-29 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-50658
The jose2go component before 1.6.0 for Go allows attackers to cause a
No latest release note
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-02-29 - -
Release Month
June 2023
1 CVE | last update 1 day(s) ago
Release 2023-06-07 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-2253
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n` causing the allocation of a massive string array possibly causing a
No latest release note
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n` causing the allocation of a massive string array possibly causing a denial of service through excessive use of memory.
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2023-06-07 - -
Release Month
May 2023
1 CVE | last update 1 day(s) ago
Release 2023-05-17 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-26964
An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result the memory and CPU usage are high which can lead to a
No latest release note
An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result the memory and CPU usage are high which can lead to a Denial of Service (DoS).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2023-05-17 - -
Release Month
December 2022
1 CVE | last update 1 day(s) ago
Release 2022-12-21 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-23524
Helm vulnerable to
No latest release note
Helm vulnerable to Denial of service through string value parsing
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2022-12-21 - -
Release Month
September 2022
2 CVE | last update 1 day(s) ago
Release 2022-09-13 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-36049
Flux2 Helm Controller
No latest release note
Flux2 Helm Controller denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2022-09-13 - -
Release 2022-09-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-36055
Helm
No latest release note
Denial of service in Helm
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2022-09-09 - -
Release Month
January 2022
3 CVE | last update 1 day(s) ago
Release 2022-01-19 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-22207
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows
No latest release note
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2022-01-19 - -
CVE-2020-25650
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory
No latest release note
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2022-01-19 - -
CVE-2020-25652
A flaw was found in the spice-vdagentd daemon where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon resulting in a
No latest release note
A flaw was found in the spice-vdagentd daemon where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon resulting in a denial of service. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and prior.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2022-01-19 - -
Release Month
October 2021
1 CVE | last update 1 day(s) ago
Release 2021-10-01 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-21035
In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a
No latest release note
In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-10-01 - -
Release Month
June 2021
2 CVE | last update 1 day(s) ago
Release 2021-06-06 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2019-5737
In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a
No latest release note
In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121 addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
Release 2021-06-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3527
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single large transfer request to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack resulting in a
No latest release note
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single large transfer request to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack resulting in a denial of service.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2021-06-04 - -
Release Month
November 2020
1 CVE | last update 1 day(s) ago
Release 2020-11-11 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak potentially leading to a
No latest release note
Some HTTP/2 implementations are vulnerable to a header leak potentially leading to a denial of service
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2020-11-11 - -
Release Month
August 2020
2 CVE | last update 1 day(s) ago
Release 2020-08-18 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2016-4074
The jv_dump_term function in jq 1.5 allows remote attackers to cause a
No latest release note
The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2020-08-18 - -
CVE-2019-14834
A vulnerability was found in dnsmasq before version 2.81 where the memory leak allows remote attackers to cause a
No latest release note
A vulnerability was found in dnsmasq before version 2.81 where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
2020-08-18 - -