Sharepoint Foundation
by Microsoft
CVEs (231)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26418 | Med | 0.30 | 4.6 | 0.01 | May 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-24104 | Med | 0.30 | 4.6 | 0.01 | Mar 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1717 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1641 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1205 | Med | 0.30 | 4.6 | 0.02 | Sep 11, 2020 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected… | ||
| CVE-2020-1444 | Med | 0.29 | 4.3 | 0.09 | Jul 14, 2020 | A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | ||
| CVE-2019-1202 | Med | 0.29 | 4.4 | 0.02 | Aug 14, 2019 | An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a… | ||
| CVE-2022-21968 | Med | 0.28 | 4.3 | 0.02 | Feb 9, 2022 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2020-17015 | Med | 0.28 | 4.3 | 0.02 | Nov 11, 2020 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-31171 | Med | 0.27 | 4.1 | 0.01 | May 11, 2021 | Microsoft SharePoint Information Disclosure Vulnerability | ||
| CVE-2020-16942 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2020-16941 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2023-23395 | Low | 0.20 | 3.1 | 0.01 | Mar 14, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2013-0081 | 0.06 | — | 0.74 | Sep 11, 2013 | Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of… | |||
| CVE-2011-1892 | 0.06 | — | 0.38 | Sep 15, 2011 | Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove… | |||
| CVE-2013-3180 | 0.05 | — | 0.66 | Sep 11, 2013 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability." | |||
| CVE-2013-3179 | 0.04 | — | 0.14 | Sep 11, 2013 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability." | |||
| CVE-2010-3324 | 0.04 | — | 0.25 | Sep 17, 2010 | The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the… | |||
| CVE-2013-0085 | 0.03 | — | 0.34 | Mar 13, 2013 | Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability." | |||
| CVE-2015-1682 | 0.02 | — | 0.19 | May 13, 2015 | Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011,… |
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected…
- risk 0.29cvss 4.3epss 0.09
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
- risk 0.29cvss 4.4epss 0.02
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a…
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.27cvss 4.1epss 0.01
Microsoft SharePoint Information Disclosure Vulnerability
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.20cvss 3.1epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- CVE-2013-0081Sep 11, 2013risk 0.06cvss —epss 0.74
Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of…
- CVE-2011-1892Sep 15, 2011risk 0.06cvss —epss 0.38
Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove…
- CVE-2013-3180Sep 11, 2013risk 0.05cvss —epss 0.66
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."
- CVE-2013-3179Sep 11, 2013risk 0.04cvss —epss 0.14
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
- CVE-2010-3324Sep 17, 2010risk 0.04cvss —epss 0.25
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the…
- CVE-2013-0085Mar 13, 2013risk 0.03cvss —epss 0.34
Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
- CVE-2015-1682May 13, 2015risk 0.02cvss —epss 0.19
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011,…
Page 10 of 12