Overview
- Microsoft
- Windows Server 2008 R2 Service Pack 1
08 Jul 2025
Published
13 Feb 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
23.02%
KEV
Description
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
- LibRaw
- LibRaw
07 Apr 2026
Published
08 Apr 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.05%
KEV
Description
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Statistics
- 1 Post
- 1 Interaction
Last activity: 4 hours ago
Overview
- Foxit Software Inc.
- Foxit PDF Editor
01 Apr 2026
Published
02 Apr 2026
Updated
CVSS v3.1
HIGH (7.8)
EPSS
0.02%
KEV
Description
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
Statistics
- 1 Post
- 1 Interaction
Last activity: 4 hours ago
Overview
- LibRaw
- LibRaw
07 Apr 2026
Published
08 Apr 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.05%
KEV
Description
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Statistics
- 1 Post
- 1 Interaction
Last activity: 4 hours ago
Overview
- AWS
- Research and Engineering Studio (RES)
06 Apr 2026
Published
07 Apr 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.37%
KEV
Description
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name.
To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
Statistics
- 1 Post
Last activity: 20 hours ago
Overview
- AWS
- Research and Engineering Studio (RES)
06 Apr 2026
Published
07 Apr 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.10%
KEV
Description
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality.
To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
Statistics
- 1 Post
Last activity: 20 hours ago
Overview
- AWS
- Research and Engineering Studio (RES)
06 Apr 2026
Published
07 Apr 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.12%
KEV
Description
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and services via a crafted API request.
To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
Statistics
- 1 Post
Last activity: 20 hours ago