|
212211
|
7.5 |
HIGH
Network
|
microsoft
|
chakracore internet_explorer edge
|
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is un…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0768
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212212
|
5.5 |
MEDIUM
Local
|
microsoft
|
remote_desktop_connection_manager
|
An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Rem…
|
NVD-CWE-noinfo
|
CVE-2020-0765
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212213
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the syst…
|
NVD-CWE-noinfo
|
CVE-2020-0763
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212214
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the syst…
|
NVD-CWE-noinfo
|
CVE-2020-0762
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212215
|
7.5 |
HIGH
Network
|
microsoft
|
azure_devops_server team_foundation_server
|
An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Eleva…
|
NVD-CWE-noinfo
|
CVE-2020-0758
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212216
|
5.4 |
MEDIUM
Network
|
microsoft
|
team_foundation_server azure_devops_server
|
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-0700
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212217
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0690
|
2024-11-21 13:54 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212218
|
9.8 |
CRITICAL
Network
|
twistedmatrix fedoraproject debian canonical
|
twisted fedora debian_linux ubuntu_linux
|
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remai…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-10109
|
2024-11-21 13:54 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212219
|
9.8 |
CRITICAL
Network
|
twistedmatrix fedoraproject debian canonical oracle
|
twisted fedora debian_linux ubuntu_linux solaris zfs_storage_appliance_kit
|
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value wa…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-10108
|
2024-11-21 13:54 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212220
|
9.8 |
CRITICAL
Network
|
sumavision
|
enhanced_multimedia_router_firmware
|
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_us…
|
CWE-352
Origin Validation Error
|
CVE-2020-10181
|
2024-11-21 13:54 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|