Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.