|
210151
|
5.4 |
MEDIUM
Network
|
microsoft
|
dynamics_365
|
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated at…
|
CWE-79
Cross-site Scripting
|
CVE-2020-16859
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210152
|
5.4 |
MEDIUM
Network
|
microsoft
|
dynamics_365
|
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated at…
|
CWE-79
Cross-site Scripting
|
CVE-2020-16858
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210153
|
7.1 |
HIGH
Network
|
microsoft
|
dynamics_365_for_finance_and_operations
|
<p>A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gai…
|
NVD-CWE-noinfo
|
CVE-2020-16857
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210154
|
7.8 |
HIGH
Local
|
microsoft
|
visual_studio visual_studio_2019 visual_studio_2017
|
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the…
|
NVD-CWE-noinfo
|
CVE-2020-16856
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210155
|
5.5 |
MEDIUM
Local
|
microsoft
|
office
|
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker w…
|
CWE-125 CWE-908
Out-of-bounds Read Use of Uninitialized Resource
|
CVE-2020-16855
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210156
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_8.1 windows_server_2019
|
<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to f…
|
NVD-CWE-noinfo
|
CVE-2020-16854
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210157
|
7.1 |
HIGH
Local
|
microsoft
|
onedrive
|
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could …
|
CWE-59
Link Following
|
CVE-2020-16853
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210158
|
7.1 |
HIGH
Local
|
microsoft
|
onedrive
|
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could …
|
NVD-CWE-noinfo
|
CVE-2020-16852
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210159
|
7.1 |
HIGH
Local
|
microsoft
|
onedrive
|
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could …
|
CWE-59
Link Following
|
CVE-2020-16851
|
2024-11-21 14:07 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210160
|
8.1 |
HIGH
Network
|
razer
|
chroma_sdk
|
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps…
|
CWE-362
Race Condition
|
CVE-2020-16602
|
2024-11-21 14:07 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|