|
222161
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_rt_8.1 windows_7
|
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'.
|
CWE-665
Improper Initialization
|
CVE-2019-1274
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222162
|
5.4 |
MEDIUM
Network
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vul…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1273
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222163
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitr…
|
NVD-CWE-noinfo
|
CVE-2019-1272
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222164
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-1271
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222165
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privil…
|
CWE-59
Link Following
|
CVE-2019-1270
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222166
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitr…
|
NVD-CWE-noinfo
|
CVE-2019-1269
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222167
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_7 windows_rt_8.1
|
An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation of Privilege Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1268
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222168
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_server_2019
|
An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Micro…
|
CWE-59
Link Following
|
CVE-2019-1267
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222169
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
|
CWE-79
Cross-site Scripting
|
CVE-2019-1266
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222170
|
7.5 |
HIGH
Network
|
microsoft
|
yammer
|
A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This could allow an attacker to perform functions that are restricted…
|
NVD-CWE-noinfo
|
CVE-2019-1265
|
2024-11-21 13:36 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|