|
210011
|
6.1 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_7 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_server_2008 windows_8.1 windows_server_2019
|
<p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerabili…
|
NVD-CWE-noinfo
|
CVE-2020-1598
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210012
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2016 windows_10
|
<p>An elevation of privilege vulnerability exists when the Windows InstallService improperly handles memory.</p>
<p>To exploit this vulnerability, an attacker would first have to gain execution on th…
|
NVD-CWE-noinfo
|
CVE-2020-1532
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210013
|
5.4 |
MEDIUM
Adjacent
|
microsoft
|
windows_10 windows_7 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_server_2008 windows_8.1 windows_server_2019
|
<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-1596
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210014
|
9.9 |
CRITICAL
Network
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-1595
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210015
|
7.8 |
HIGH
Local
|
microsoft
|
excel office 365_apps
|
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability coul…
|
NVD-CWE-noinfo
|
CVE-2020-1594
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210016
|
7.6 |
HIGH
Network
|
microsoft
|
windows_10 windows_7 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_server_2008 windows_8.1 windows_server_2019
|
<p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected…
|
NVD-CWE-noinfo
|
CVE-2020-1593
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210017
|
4.4 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2019 windows_server_2016
|
<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p>
<p>To exploit this vulnerability, an authenticated attacker could run a special…
|
CWE-665
Improper Initialization
|
CVE-2020-1592
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210018
|
6.6 |
MEDIUM
Local
|
microsoft
|
windows_server_2019 windows_10 windows_server_2016
|
<p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerabili…
|
NVD-CWE-noinfo
|
CVE-2020-1590
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210019
|
4.4 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_7 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_server_2008 windows_8.1 windows_server_2019
|
<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to f…
|
NVD-CWE-noinfo
|
CVE-2020-1589
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210020
|
8.5 |
HIGH
Network
|
microsoft
|
sharepoint_foundation sharepoint_server sharepoint_enterprise_server
|
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-1576
|
2024-11-21 14:10 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|