Show filters
243 Total Results
Displaying 171-180 of 243
Sort by:
Attacker Value
Unknown
CVE-2019-1257
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
0
Attacker Value
Unknown
CVE-2019-1260
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
0
Attacker Value
Unknown
CVE-2019-1295
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
0
Attacker Value
Unknown
CVE-2019-1296
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
0
Attacker Value
Unknown
CVE-2019-1203
Disclosure Date: August 14, 2019 (last updated May 30, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user.
The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.
0
Attacker Value
Unknown
CVE-2019-1202
Disclosure Date: August 14, 2019 (last updated May 30, 2024)
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user.
To exploit this vulnerability, the attacker could run a specially crafted application.
The security update corrects how SharePoint handles session objects to prevent user session hijacking.
0
Attacker Value
Unknown
CVE-2019-1201
Disclosure Date: August 14, 2019 (last updated May 30, 2024)
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user.
To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software.
Two possible email attack scenarios exist for this vulnerability:
• With the first email attack scenario, an attacker could send a specially crafted email message to the user and wait for the user to click on the message. When the message renders via Microsoft Word in the Outlook Preview Pane, an attack could be triggered.
• With the second scenario, an attacker could attach a specially crafted file to an email, send it to a user, and convince them to open it.
In a web-based at…
0
Attacker Value
Unknown
CVE-2019-1134
Disclosure Date: July 15, 2019 (last updated November 27, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
0
Attacker Value
Unknown
CVE-2019-1006
Disclosure Date: July 15, 2019 (last updated November 27, 2024)
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
0
Attacker Value
Unknown
CVE-2019-1036
Disclosure Date: June 12, 2019 (last updated November 27, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-1031, CVE-2019-1032, CVE-2019-1033.
0