|
222761
|
6.1 |
MEDIUM
Network
|
microsoft
|
power_bi_report_server sql_server_2017_reporting_services sql_server_2019_reporting_services
|
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Micro…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1332
|
2024-11-21 13:36 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222762
|
5.3 |
MEDIUM
Network
|
openssl opensuse oracle canonical fedoraproject debian tenable
|
openssl leap peoplesoft_enterprise_peopletools mysql_enterprise_monitor enterprise_manager_ops_center ubuntu_linux fedora debian_linux log_correlation_engine
|
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024,…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-1551
|
2024-11-21 13:36 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222763
|
7.8 |
HIGH
Local
|
microsoft
|
office
|
A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1457
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222764
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Co…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-1456
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222765
|
9.8 |
CRITICAL
Network
|
microsoft
|
office_365_proplus office
|
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and…
|
NVD-CWE-noinfo
|
CVE-2019-1449
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222766
|
7.8 |
HIGH
Local
|
microsoft
|
excel office office_365_proplus
|
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2019-1448
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222767
|
5.4 |
MEDIUM
Network
|
microsoft
|
office_online_server
|
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is uni…
|
CWE-346
Origin Validation Error
|
CVE-2019-1447
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222768
|
5.5 |
MEDIUM
Local
|
microsoft
|
excel office office_365 office_online_server sharepoint_enterprise_server excel_services
|
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
|
CWE-200
Information Exposure
|
CVE-2019-1446
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222769
|
5.4 |
MEDIUM
Network
|
microsoft
|
office_online_server
|
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is uni…
|
CWE-346
Origin Validation Error
|
CVE-2019-1445
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222770
|
5.5 |
MEDIUM
Local
|
microsoft
|
sharepoint_server
|
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering creden…
|
CWE-346
Origin Validation Error
|
CVE-2019-1442
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|