See how microsoft compares to other vendors in security performance
pip absolute path traversal during download from malicious package indexes
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1.
The HTTP/1.1 handler in cowboyhttp enforces the maxheaders limit by counting the number of distinct header names in a map (maps:size(Headers)). When a request contains multiple header lines with the same name, the values are concatenated into a single ever-growing binary stored under that one map key (", " for regular headers, "; " for cookies), so the map size stays at one and the maxheaders cap (default 100) is never reached. Because no accumulator bounds the total number of header lines or the total byte size of the header block (only per-line maxheadernamelength and maxheadervaluelength apply), an unauthenticated client can send an arbitrary number of header lines with the same name and grow the connection process's binary memory to arbitrary size within the request window.
The impact per connection is bounded by requesttimeout (default 5 seconds, not reset by header data), and by maxheapsize when set (the offending connection process is killed once its heap grows past the limit). When maxheapsize is left at the default (unset), sustained abuse can drive the Erlang VM into out-of-memory conditions.
This issue affects cowboy from 2.0.0-pre.4 before 2.18.0.
undici vulnerable to Denial of Service via orphaned RetryHandler response body
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauthpassword of the file src/userauth.c. Such manipulation of the argument usernamelen/passwordlen leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
Microsoft Office Excel Information Disclosure Vulnerability
Microsoft Windows Search Component Information Disclosure Vulnerability
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Microsoft Excel Information Disclosure Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Microsoft Office Information Disclosure Vulnerability
Microsoft Office Word Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Microsoft Office Word Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Microsoft Office PowerPoint Information Disclosure Vulnerability
Microsoft Office Outlook Information Disclosure Vulnerability