|
222771
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_rt_8.1 windows_7
|
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is u…
|
CWE-200
Information Exposure
|
CVE-2019-1046
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222772
|
6.8 |
MEDIUM
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_7 windows_server_2019
|
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1043
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222773
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique fro…
|
NVD-CWE-noinfo
|
CVE-2019-1041
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222774
|
5.9 |
MEDIUM
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019 windows_7
|
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering V…
|
NVD-CWE-noinfo
|
CVE-2019-1040
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222775
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2019 windows_7 windows_rt_8.1
|
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted …
|
CWE-665
Improper Initialization
|
CVE-2019-1039
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222776
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer edge
|
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-1038
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222777
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation project_server sharepoint_enterprise_server sharepoint_server
|
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1036
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222778
|
7.8 |
HIGH
Local
|
microsoft
|
office_online_server office office_365_proplus sharepoint_server
|
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is un…
|
NVD-CWE-noinfo
|
CVE-2019-1035
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222779
|
7.8 |
HIGH
Local
|
microsoft
|
word office_web_apps sharepoint_server office office_365_proplus sharepoint_enterprise_server office_online_server
|
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is un…
|
NVD-CWE-noinfo
|
CVE-2019-1034
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222780
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation project_server sharepoint_enterprise_server sharepoint_server
|
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1033
|
2024-11-21 13:35 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|