CVE-2019-1261
- EPSS 5.04%
- Published 11.09.2019 22:15:16
- Last modified 21.11.2024 04:36:21
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically ...
CVE-2019-1262
- EPSS 0.48%
- Published 11.09.2019 22:15:16
- Last modified 21.11.2024 04:36:21
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
CVE-2019-1202
- EPSS 0.6%
- Published 14.08.2019 21:15:18
- Last modified 21.11.2024 04:36:14
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, th...
CVE-2019-1006
- EPSS 2.93%
- Published 15.07.2019 19:15:16
- Last modified 21.11.2024 04:35:49
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'...
CVE-2019-1031
- EPSS 0.44%
- Published 12.06.2019 14:29:03
- Last modified 20.05.2025 18:15:38
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a spe...
CVE-2019-1033
- EPSS 0.44%
- Published 12.06.2019 14:29:03
- Last modified 20.05.2025 18:15:38
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a spe...
CVE-2019-1036
- EPSS 0.44%
- Published 12.06.2019 14:29:03
- Last modified 20.05.2025 18:15:39
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a spe...
CVE-2019-0949
- EPSS 5.81%
- Published 16.05.2019 19:29:04
- Last modified 21.11.2024 04:17:33
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950,...
CVE-2019-0950
- EPSS 5.81%
- Published 16.05.2019 19:29:04
- Last modified 21.11.2024 04:17:33
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949,...
CVE-2019-0951
- EPSS 0.49%
- Published 16.05.2019 19:29:04
- Last modified 21.11.2024 04:17:34
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949,...