CVE-2019-1295
- EPSS 38.46%
- Veröffentlicht 11.09.2019 22:15:18
- Zuletzt bearbeitet 21.11.2024 04:36:25
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
CVE-2019-1296
- EPSS 38.46%
- Veröffentlicht 11.09.2019 22:15:18
- Zuletzt bearbeitet 21.11.2024 04:36:25
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
CVE-2019-1257
- EPSS 24.14%
- Veröffentlicht 11.09.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:36:21
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-129...
CVE-2019-1260
- EPSS 11.22%
- Veröffentlicht 11.09.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:36:21
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
CVE-2019-1261
- EPSS 5.04%
- Veröffentlicht 11.09.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:36:21
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically ...
CVE-2019-1202
- EPSS 0.6%
- Veröffentlicht 14.08.2019 21:15:18
- Zuletzt bearbeitet 21.11.2024 04:36:14
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, th...
CVE-2019-1203
- EPSS 0.53%
- Veröffentlicht 14.08.2019 21:15:18
- Zuletzt bearbeitet 21.11.2024 04:36:14
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a spe...
CVE-2019-1201
- EPSS 12.4%
- Veröffentlicht 14.08.2019 21:15:17
- Zuletzt bearbeitet 21.11.2024 04:36:13
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security...
CVE-2019-1134
- EPSS 0.58%
- Veröffentlicht 15.07.2019 19:15:21
- Zuletzt bearbeitet 28.02.2025 21:15:14
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
CVE-2019-1006
- EPSS 2.93%
- Veröffentlicht 15.07.2019 19:15:16
- Zuletzt bearbeitet 21.11.2024 04:35:49
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'...