VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2019-1443MedNov 12, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain…

  • CVE-2019-1432MedNov 12, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1411.

  • CVE-2019-1411MedNov 12, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.

  • CVE-2019-1376MedOct 10, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313.

  • CVE-2019-1366HigOct 10, 2019
    risk 0.43cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1308, CVE-2019-1335.

  • CVE-2019-1356MedOct 10, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.

  • CVE-2019-1335HigOct 10, 2019
    risk 0.43cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1308, CVE-2019-1366.

  • CVE-2019-1313MedOct 10, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376.

  • CVE-2019-1308HigOct 10, 2019
    risk 0.43cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1335, CVE-2019-1366.

  • CVE-2019-1307HigOct 10, 2019
    risk 0.43cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1308, CVE-2019-1335, CVE-2019-1366.

  • CVE-2019-1166MedOct 10, 2019
    risk 0.43cvss 5.9epss 0.68

    A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.

  • CVE-2019-1299MedSep 11, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.

  • CVE-2019-1286MedSep 11, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252.

  • CVE-2019-1209MedSep 11, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.

  • CVE-2019-1116MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099,…

  • CVE-2019-1108MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.11

    An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.

  • CVE-2019-1101MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099,…

  • CVE-2019-1100MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099,…

  • CVE-2019-1099MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1100,…

  • CVE-2019-1098MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1099, CVE-2019-1100,…

  • CVE-2019-1095MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100,…

  • CVE-2019-1094MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100,…

  • CVE-2019-1084MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…

  • CVE-2019-1079MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.

  • CVE-2019-1025MedJun 12, 2019
    risk 0.43cvss 6.5epss 0.05

    A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected…

  • CVE-2019-1023MedJun 12, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. In a web-based…

  • CVE-2019-0990MedJun 12, 2019
    risk 0.43cvss 6.5epss 0.05

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…

  • CVE-2019-0972MedJun 12, 2019
    risk 0.43cvss 6.5epss 0.06

    This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a…

  • CVE-2019-7090MedMay 24, 2019
    risk 0.43cvss 6.5epss 0.05

    Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful…

  • CVE-2019-0971MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.08

    An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure…

  • CVE-2019-0961MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0882.

  • CVE-2019-0956MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.

  • CVE-2019-0930MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.

  • CVE-2019-0921MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.03

    An spoofing vulnerability exists when Internet Explorer improperly handles URLs, aka 'Internet Explorer Spoofing Vulnerability'.

  • CVE-2019-0882MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0961.

  • CVE-2019-0819MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'.

  • CVE-2019-0758MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.12

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.

  • CVE-2019-11397MedMay 14, 2019
    risk 0.43cvss 6.5epss 0.05

    GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.

  • CVE-2019-0861HigApr 9, 2019
    risk 0.43cvss 7.5epss 0.11

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812,…

  • CVE-2019-0860HigApr 9, 2019
    risk 0.43cvss 7.5epss 0.11

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812,…

  • CVE-2019-0857MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.04

    A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.

  • CVE-2019-0849MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.10

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0802.

  • CVE-2019-0835MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft Scripting Engine Information Disclosure Vulnerability'.

  • CVE-2019-0833MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'.

  • CVE-2019-0812HigApr 9, 2019
    risk 0.43cvss 7.5epss 0.19

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0829,…

  • CVE-2019-0810HigApr 9, 2019
    risk 0.43cvss 7.5epss 0.12

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0812, CVE-2019-0829,…

  • CVE-2019-0802MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.10

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0849.

  • CVE-2019-0764MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.04

    A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'.

  • CVE-2019-0821MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704.

  • CVE-2019-0804MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'.

Page 161 of 314