Sharepoint Server
by Microsoft
CVEs (679)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-5026 | 0.01 | — | 0.09 | Nov 10, 2008 | Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS)… | |||
| CVE-2004-0379 | 0.01 | — | 0.08 | May 4, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts. | |||
| CVE-2003-0904 | 0.01 | — | 0.08 | Jan 20, 2004 | Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.… | |||
| CVE-2026-62826 | Med | 0.00 | 4.6 | 0.01 | Jul 16, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-58277 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-56192 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-56157 | Med | 0.00 | 5.4 | 0.01 | Jul 14, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55142 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55135 | Med | 0.00 | 4.6 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55134 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55132 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55130 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55128 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55127 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55126 | Hig | 0.00 | 7.3 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55125 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55124 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55121 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55055 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55052 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
- CVE-2008-5026Nov 10, 2008risk 0.01cvss —epss 0.09
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS)…
- CVE-2004-0379May 4, 2004risk 0.01cvss —epss 0.08
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
- CVE-2003-0904Jan 20, 2004risk 0.01cvss —epss 0.08
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.…
- risk 0.00cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 8.8epss 0.01
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.4epss 0.01
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 5.5epss 0.01
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.8epss 0.01
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.01
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.01
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 8.8epss 0.01
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Page 33 of 34