|
221551
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Co…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-1456
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221552
|
9.8 |
CRITICAL
Network
|
microsoft
|
office_365_proplus office
|
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and…
|
NVD-CWE-noinfo
|
CVE-2019-1449
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221553
|
7.8 |
HIGH
Local
|
microsoft
|
excel office office_365_proplus
|
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1448
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221554
|
5.4 |
MEDIUM
Network
|
microsoft
|
office_online_server
|
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is uni…
|
CWE-346
Origin Validation Error
|
CVE-2019-1447
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221555
|
5.5 |
MEDIUM
Local
|
microsoft
|
excel office office_365 office_online_server sharepoint_enterprise_server excel_services
|
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
|
CWE-200
Information Exposure
|
CVE-2019-1446
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221556
|
5.4 |
MEDIUM
Network
|
microsoft
|
office_online_server
|
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is uni…
|
CWE-346
Origin Validation Error
|
CVE-2019-1445
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221557
|
5.5 |
MEDIUM
Local
|
microsoft
|
sharepoint_server
|
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering creden…
|
CWE-346
Origin Validation Error
|
CVE-2019-1442
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221558
|
6.5 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-1443
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221559
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_7
|
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-1441
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221560
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019…
|
CWE-200
Information Exposure
|
CVE-2019-1440
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|