CVE-2012-2520
- EPSS 28.05%
- Published 09.10.2012 21:55:02
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 ...
CVE-2012-1849
- EPSS 59.14%
- Published 12.06.2012 22:55:01
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file,...
CVE-2012-1858
- EPSS 50.17%
- Published 12.06.2012 22:55:01
- Last modified 11.04.2025 00:51:21
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduc...