|
210751
|
9.8 |
CRITICAL
Network
|
microsoft
|
.net_framework
|
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
|
CWE-91
Blind XPath Injection
|
CVE-2020-0646
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210752
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-0644
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210753
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_rt_8.1 windows_server_2008 windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_7 windows_server_2019
|
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targete…
|
NVD-CWE-noinfo
|
CVE-2020-0643
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210754
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is uniqu…
|
CWE-416
Use After Free
|
CVE-2020-0642
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210755
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the sy…
|
NVD-CWE-noinfo
|
CVE-2020-0641
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210756
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer
|
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0640
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210757
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_rt_8.1 windows_server_2008 windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_7 windows_server_2019
|
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Infor…
|
NVD-CWE-noinfo
|
CVE-2020-0639
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210758
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim sys…
|
NVD-CWE-noinfo
|
CVE-2020-0638
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210759
|
6.5 |
MEDIUM
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019
|
An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0637
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210760
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2016 windows_10
|
An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0636
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|