|
210741
|
5.4 |
MEDIUM
Network
|
microsoft
|
office_online_server
|
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.
|
CWE-346
Origin Validation Error
|
CVE-2020-0695
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210742
|
8.1 |
HIGH
Network
|
microsoft
|
exchange_server
|
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0692
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210743
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0689
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210744
|
7.8 |
HIGH
Local
|
microsoft
|
office_365_proplus
|
An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the…
|
NVD-CWE-noinfo
|
CVE-2020-0697
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210745
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE I…
|
NVD-CWE-noinfo
|
CVE-2020-0691
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210746
|
8.8 |
HIGH
Network
|
microsoft
|
exchange_server
|
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
|
CWE-287
Improper Authentication
|
CVE-2020-0688
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210747
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique f…
|
CWE-269
Improper Privilege Management
|
CVE-2020-0686
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210748
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0685
|
2024-11-21 13:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210749
|
7.8 |
HIGH
Local
|
google
|
android
|
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-0417
|
2024-11-21 13:53 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210750
|
7.8 |
HIGH
Local
|
intel
|
graphics_drivers
|
Insufficient control flow management in the kernel mode driver for some Intel(R) Graphics Drivers before version 15.36.39.5145 may allow an authenticated user to potentially enable escalation of priv…
|
NVD-CWE-Other
|
CVE-2020-0544
|
2024-11-21 13:53 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|