|
221611
|
6.5 |
MEDIUM
Network
|
microsoft
|
visual_studio
|
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
|
CWE-20
Improper Input Validation
|
CVE-2019-1079
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221612
|
5.0 |
MEDIUM
Local
|
microsoft
|
visual_studio_2017 visual_studio_2019
|
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1077
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221613
|
5.4 |
MEDIUM
Network
|
microsoft
|
team_foundation_server azure_devops_server
|
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
|
CWE-79
Cross-site Scripting
|
CVE-2019-1076
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221614
|
6.1 |
MEDIUM
Network
|
microsoft
|
asp.net_core
|
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
|
CWE-601
Open Redirect
|
CVE-2019-1075
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221615
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_7 windows_rt_8.1
|
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-…
|
CWE-200
Information Exposure
|
CVE-2019-1073
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221616
|
9.8 |
CRITICAL
Network
|
microsoft
|
team_foundation_server azure_devops_server
|
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Ex…
|
CWE-20
Improper Input Validation
|
CVE-2019-1072
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221617
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_7 windows_rt_8.1
|
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-…
|
CWE-200
Information Exposure
|
CVE-2019-1071
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221618
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server
|
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1068
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221619
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited…
|
CWE-59
Link Following
|
CVE-2019-1074
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221620
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1067
|
2024-11-21 13:35 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|