|
209801
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated …
|
NVD-CWE-noinfo
|
CVE-2020-16935
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209802
|
7.0 |
HIGH
Local
|
microsoft
|
office 365_apps office_2013_click-to-run
|
<p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elev…
|
NVD-CWE-noinfo
|
CVE-2020-16934
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209803
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019 word office 365_apps
|
<p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a speciall…
|
NVD-CWE-noinfo
|
CVE-2020-16933
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209804
|
7.8 |
HIGH
Local
|
microsoft
|
excel office_web_apps office office_online_server 365_apps
|
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability coul…
|
CWE-908 CWE-909
Use of Uninitialized Resource Missing Initialization of Resource
|
CVE-2020-16932
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209805
|
7.8 |
HIGH
Local
|
microsoft
|
excel office_web_apps office office_online_server 365_apps
|
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability coul…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-16931
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209806
|
7.8 |
HIGH
Local
|
microsoft
|
office 365_apps
|
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability coul…
|
CWE-824 CWE-787
Access of Uninitialized Pointer Out-of-bounds Write
|
CVE-2020-16930
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209807
|
7.8 |
HIGH
Local
|
microsoft
|
excel_web_app excel office_web_apps office sharepoint_server sharepoint_enterprise_server office_online_server 365_apps
|
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability coul…
|
CWE-416
Use After Free
|
CVE-2020-16929
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209808
|
7.8 |
HIGH
Local
|
microsoft
|
office 365_apps
|
<p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elev…
|
NVD-CWE-noinfo
|
CVE-2020-16928
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209809
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
<p>A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfull…
|
NVD-CWE-noinfo
|
CVE-2020-16927
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209810
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbi…
|
NVD-CWE-noinfo
|
CVE-2020-16924
|
2024-11-21 14:07 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|