|
211131
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps
|
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerabilit…
|
CWE-426
Untrusted Search Path
|
CVE-2020-1458
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
7.8 |
HIGH
Local
|
microsoft
|
office 365_apps project_2016
|
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.
|
CWE-346
Origin Validation Error
|
CVE-2020-1449
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
8.8 |
HIGH
Network
|
microsoft
|
word office_web_apps word_rt sharepoint_enterprise_server office sharepoint_server office_online_server
|
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is un…
|
NVD-CWE-noinfo
|
CVE-2020-1448
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
8.8 |
HIGH
Network
|
microsoft
|
word office_web_apps sharepoint_server office word_rt sharepoint_enterprise_server office_online_server 365_apps
|
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is un…
|
NVD-CWE-noinfo
|
CVE-2020-1447
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
8.8 |
HIGH
Network
|
microsoft
|
word office_web_apps sharepoint_server office word_rt sharepoint_enterprise_server office_online_server 365_apps
|
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is un…
|
NVD-CWE-noinfo
|
CVE-2020-1446
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
5.5 |
MEDIUM
Local
|
microsoft
|
word office sharepoint_enterprise_server office_online_server 365_apps office_web_apps
|
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is uniqu…
|
NVD-CWE-noinfo
|
CVE-2020-1445
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
4.3 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-1444
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulner…
|
NVD-CWE-noinfo
|
CVE-2020-1443
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
6.1 |
MEDIUM
Network
|
microsoft
|
office_web_apps office_online_server
|
A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-1442
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_foundation sharepoint_server sharepoint_enterprise_server
|
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Re…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-1439
|
2024-11-21 14:10 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|