VYPR

Windows DirectX

by Microsoft

CVEs (15)

  • CVE-2025-55698HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.01

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

  • CVE-2025-62573HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60716HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59506HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55678HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53135HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62465MedDec 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

  • CVE-2025-62463MedDec 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

  • CVE-2025-50172MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.01

    Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.

  • CVE-2025-60723MedNov 11, 2025
    risk 0.41cvss 6.3epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.

  • CVE-2003-0346Aug 27, 2003
    risk 0.03cvss epss 0.33

    Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer…

  • CVE-2026-58629HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50382HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

  • CVE-2026-50353HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49807MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.