Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41342 | Med | 0.44 | 6.8 | 0.02 | Oct 13, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2021-34534 | Med | 0.44 | 6.8 | 0.02 | Aug 12, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2021-34447 | Med | 0.44 | 6.8 | 0.02 | Jul 16, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2021-34497 | Med | 0.44 | 6.8 | 0.02 | Jul 14, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2021-34493 | Med | 0.44 | 6.7 | 0.01 | Jul 14, 2021 | Windows Partition Management Driver Elevation of Privilege Vulnerability | ||
| CVE-2021-31971 | Med | 0.44 | 6.8 | 0.02 | Jun 8, 2021 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2021-28458 | Hig | 0.44 | 7.8 | 0.02 | Apr 13, 2021 | Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability | ||
| CVE-2021-27092 | Med | 0.44 | 6.8 | 0.03 | Apr 13, 2021 | Azure AD Web Sign-in Security Feature Bypass Vulnerability | ||
| CVE-2021-27075 | Med | 0.44 | 6.8 | 0.01 | Mar 11, 2021 | Azure Virtual Machine Information Disclosure Vulnerability | ||
| CVE-2021-26854 | Med | 0.44 | 6.6 | 0.23 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-24109 | Med | 0.44 | 6.8 | 0.02 | Feb 25, 2021 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | ||
| CVE-2021-24075 | Med | 0.44 | 6.8 | 0.02 | Feb 25, 2021 | Microsoft Windows VMSwitch Denial of Service Vulnerability | ||
| CVE-2021-21140 | Med | 0.44 | 6.8 | 0.01 | Feb 9, 2021 | Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device. | ||
| CVE-2021-21135 | Med | 0.44 | 6.5 | 0.19 | Feb 9, 2021 | Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2020-17099 | Med | 0.44 | 6.8 | 0.01 | Dec 10, 2020 | Windows Lock Screen Security Feature Bypass Vulnerability | ||
| CVE-2020-17063 | Med | 0.44 | 6.8 | 0.02 | Nov 11, 2020 | Microsoft Office Online Spoofing Vulnerability | ||
| CVE-2020-17049 | Med | 0.44 | 6.6 | 0.14 | Nov 11, 2020 | A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could… | ||
| CVE-2020-16905 | Med | 0.44 | 6.8 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the… | ||
| CVE-2020-16860 | Med | 0.44 | 6.8 | 0.03 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the… | ||
| CVE-2020-0951 | Med | 0.44 | 6.7 | 0.07 | Sep 11, 2020 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by… | ||
| CVE-2020-1398 | Med | 0.44 | 6.8 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by… | ||
| CVE-2020-1333 | Med | 0.44 | 6.7 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1310 | Med | 0.44 | 6.7 | 0.01 | Jun 9, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253. | ||
| CVE-2020-1258 | Med | 0.44 | 6.7 | 0.01 | Jun 9, 2020 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1253 | Med | 0.44 | 6.7 | 0.01 | Jun 9, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310. | ||
| CVE-2020-1251 | Med | 0.44 | 6.7 | 0.01 | Jun 9, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310. | ||
| CVE-2020-1173 | Med | 0.44 | 6.8 | 0.02 | May 21, 2020 | A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who… | ||
| CVE-2020-1071 | Med | 0.44 | 6.8 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability an attacker would… | ||
| CVE-2020-0918 | Med | 0.44 | 6.8 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917. | ||
| CVE-2020-0917 | Med | 0.44 | 6.8 | 0.02 | Apr 15, 2020 | An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918. | ||
| CVE-2020-0702 | Med | 0.44 | 6.8 | 0.01 | Feb 11, 2020 | A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'. | ||
| CVE-2020-0689 | Med | 0.44 | 6.7 | 0.01 | Feb 11, 2020 | A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'. | ||
| CVE-2020-0661 | Med | 0.44 | 6.8 | 0.02 | Feb 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751. | ||
| CVE-2019-1314 | Med | 0.44 | 6.8 | 0.01 | Oct 10, 2019 | A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'. | ||
| CVE-2019-0966 | Med | 0.44 | 6.8 | 0.02 | Jul 15, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. | ||
| CVE-2019-0713 | Med | 0.44 | 6.8 | 0.02 | Jun 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,… | ||
| CVE-2019-0711 | Med | 0.44 | 6.8 | 0.02 | Jun 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,… | ||
| CVE-2019-0710 | Med | 0.44 | 6.8 | 0.02 | Jun 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,… | ||
| CVE-2019-0886 | Med | 0.44 | 6.8 | 0.02 | May 16, 2019 | An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | ||
| CVE-2019-0701 | Med | 0.44 | 6.8 | 0.02 | Apr 9, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0695. | ||
| CVE-2019-0695 | Med | 0.44 | 6.8 | 0.02 | Apr 9, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701. | ||
| CVE-2019-0690 | Med | 0.44 | 6.8 | 0.02 | Apr 9, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695,… | ||
| CVE-2018-8629 | Hig | 0.44 | 7.5 | 0.23 | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583,… | ||
| CVE-2018-8372 | Hig | 0.44 | 7.5 | 0.25 | Aug 15, 2018 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from… | ||
| CVE-2018-8266 | Hig | 0.44 | 7.5 | 0.27 | Aug 15, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,… | ||
| CVE-2018-8140 | Med | 0.44 | 6.8 | 0.02 | Jun 14, 2018 | An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. | ||
| CVE-2018-3639 | Med | 0.44 | 5.5 | 0.61 | May 22, 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,… | ||
| CVE-2018-8117 | Med | 0.44 | 6.8 | 0.01 | Apr 12, 2018 | A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to reuse an AES encryption key to send keystrokes to other keyboard devices or to read keystrokes sent by other keyboards for the affected devices, aka "Microsoft… | ||
| CVE-2017-8628 | Med | 0.44 | 6.8 | 0.02 | Sep 13, 2017 | Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability". | ||
| CVE-2017-0196 | Med | 0.44 | 6.5 | 0.18 | Jul 17, 2017 | An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." |
- risk 0.44cvss 6.8epss 0.02
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.02
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.02
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.02
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
Windows Partition Management Driver Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.02
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.44cvss 7.8epss 0.02
Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.03
Azure AD Web Sign-in Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.01
Azure Virtual Machine Information Disclosure Vulnerability
- risk 0.44cvss 6.6epss 0.23
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.02
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.02
Microsoft Windows VMSwitch Denial of Service Vulnerability
- risk 0.44cvss 6.8epss 0.01
Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.
- risk 0.44cvss 6.5epss 0.19
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- risk 0.44cvss 6.8epss 0.01
Windows Lock Screen Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.02
Microsoft Office Online Spoofing Vulnerability
- risk 0.44cvss 6.6epss 0.14
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could…
- risk 0.44cvss 6.8epss 0.01
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the…
- risk 0.44cvss 6.8epss 0.03
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the…
- risk 0.44cvss 6.7epss 0.07
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by…
- risk 0.44cvss 6.8epss 0.01
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by…
- risk 0.44cvss 6.7epss 0.01
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
- risk 0.44cvss 6.7epss 0.01
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253.
- risk 0.44cvss 6.7epss 0.01
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
- risk 0.44cvss 6.7epss 0.01
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.
- risk 0.44cvss 6.7epss 0.01
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310.
- risk 0.44cvss 6.8epss 0.02
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who…
- risk 0.44cvss 6.8epss 0.01
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability an attacker would…
- risk 0.44cvss 6.8epss 0.01
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.
- risk 0.44cvss 6.8epss 0.02
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.
- risk 0.44cvss 6.8epss 0.01
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.
- risk 0.44cvss 6.7epss 0.01
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.
- risk 0.44cvss 6.8epss 0.01
A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…
- risk 0.44cvss 6.8epss 0.02
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0695.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701.
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695,…
- risk 0.44cvss 7.5epss 0.23
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583,…
- risk 0.44cvss 7.5epss 0.25
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from…
- risk 0.44cvss 7.5epss 0.27
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,…
- risk 0.44cvss 6.8epss 0.02
An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.
- risk 0.44cvss 5.5epss 0.61
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,…
- risk 0.44cvss 6.8epss 0.01
A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to reuse an AES encryption key to send keystrokes to other keyboard devices or to read keystrokes sent by other keyboards for the affected devices, aka "Microsoft…
- risk 0.44cvss 6.8epss 0.02
Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".
- risk 0.44cvss 6.5epss 0.18
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Page 157 of 314