THREAT OPS › Threat News
Threat Intelligence News
12309 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2021-20327 (MEDIUM 6.4) — A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Nodenvd · 2021-02-25
- [NVD] CVE-2021-21972 (CRITICAL 9.8) — The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Senvd · 2021-02-24
- [NVD] CVE-2021-20016 (CRITICAL 9.8) — A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.nvd · 2021-02-04
- [NVD] CVE-2021-24122 (MEDIUM 5.9) — When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpecnvd · 2021-01-14
- [NVD] CVE-2021-21009 (HIGH 8.6) — Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacknvd · 2021-01-13
- [NVD] CVE-2020-26977 (MEDIUM 6.5) — By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability nvd · 2021-01-07
- [NVD] CVE-2020-26975 (MEDIUM 6.5) — When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed henvd · 2021-01-07
- [Breach] Windows93 / Myspace93 — 46,105 accounts exposedhibp_breaches · 2021-01-01
- [NVD] CVE-2020-35728 (HIGH 8.1) — FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).nvd · 2020-12-27
- [NVD] CVE-2020-26964 (MEDIUM 6.8) — If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemenvd · 2020-12-09
- [NVD] CVE-2020-26957 (MEDIUM 6.5) — OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerabilnvd · 2020-12-09
- [NVD] CVE-2020-26955 (MEDIUM 6.5) — When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: Thnvd · 2020-12-09
- [NVD] CVE-2020-26954 (MEDIUM 4.3) — When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-originnvd · 2020-12-09
- [NVD] CVE-2020-17521 (MEDIUM 5.5) — Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Usnvd · 2020-12-07
- [NVD] CVE-2020-25649 (HIGH 7.5) — A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.nvd · 2020-12-03
- [NVD] CVE-2018-19953 (MEDIUM 6.1) — If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4nvd · 2020-10-28
- [NVD] CVE-2018-19949 (CRITICAL 9.8) — If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3nvd · 2020-10-28
- [NVD] CVE-2018-19943 (HIGH 8.0) — If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 202nvd · 2020-10-28
- [NVD] CVE-2020-6829 (MEDIUM 5.3) — When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been comnvd · 2020-10-28
- [NVD] CVE-2020-3992 (CRITICAL 9.8) — OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trignvd · 2020-10-20
- [NVD] CVE-2020-12401 (MEDIUM 4.7) — During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.nvd · 2020-10-08
- [NVD] CVE-2020-12400 (MEDIUM 4.7) — When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.nvd · 2020-10-08
- [NVD] CVE-2020-15671 (LOW 3.1) — When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.nvd · 2020-10-01
- [NVD] CVE-2020-15670 (HIGH 8.8) — Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80,nvd · 2020-10-01
- [NVD] CVE-2020-15666 (MEDIUM 6.5) — When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to infenvd · 2020-10-01
- [NVD] CVE-2020-15664 (MEDIUM 6.5) — By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended nvd · 2020-10-01
- [NVD] CVE-2020-3478 (HIGH 8.1) — A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device. The vulnerability is due to insufficient authorization enforcement on nvd · 2020-09-04
- [NVD] CVE-2020-3365 (MEDIUM 4.3) — A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic tnvd · 2020-09-04
- [NVD] CVE-2020-3433 (HIGH 7.8) — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials nvd · 2020-08-17
- [NVD] CVE-2020-12812 (CRITICAL 9.8) — An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.nvd · 2020-07-24
- [NVD] CVE-2020-13935 (HIGH 7.5) — The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could leanvd · 2020-07-14
- [NVD] CVE-2020-13934 (HIGH 7.5) — An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial nvd · 2020-07-14
- [NVD] CVE-2020-12414 (MEDIUM 6.5) — IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.nvd · 2020-07-09
- [NVD] CVE-2020-12404 (MEDIUM 4.3) — For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.nvd · 2020-07-09
- [NVD] CVE-2020-3236 (MEDIUM 6.7) — A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentnvd · 2020-06-18
- [NVD] CVE-2020-8619 (MEDIUM 4.9) — In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminalnvd · 2020-06-17
- [NVD] CVE-2020-14061 (HIGH 8.1) — FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectinvd · 2020-06-14
- [NVD] CVE-2020-5411 (HIGH 8.1) — When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". Spring Batch configures Jackson with global default typing ennvd · 2020-06-11
- [NVD] CVE-2020-6830 (HIGH 7.5) — For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability afnvd · 2020-05-26
- [NVD] CVE-2020-1139 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specinvd · 2020-05-21
- [NVD] CVE-2020-1138 (HIGH 7.0) — An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker would first have tonvd · 2020-05-21
- [NVD] CVE-2020-1137 (HIGH 7.8) — An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change onvd · 2020-05-21
- [NVD] CVE-2020-1136 (HIGH 7.8) — A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multnvd · 2020-05-21
- [NVD] CVE-2020-1135 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. In a local attack scenario, an attacker could exploit thinvd · 2020-05-21
- [NVD] CVE-2020-1134 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability bnvd · 2020-05-21
- [NVD] CVE-2020-1132 (HIGH 7.0) — An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, annvd · 2020-05-21
- [NVD] CVE-2020-1131 (MEDIUM 5.5) — An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability bnvd · 2020-05-21
- [NVD] CVE-2020-1126 (HIGH 8.8) — A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multnvd · 2020-05-21
- [NVD] CVE-2020-1125 (HIGH 7.0) — An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specinvd · 2020-05-21
- [NVD] CVE-2020-1124 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability bnvd · 2020-05-21
- [NVD] CVE-2020-1123 (MEDIUM 5.5) — A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could cause a system to stop responding. To exploit the vulnerability, an attacker would finvd · 2020-05-21
- [NVD] CVE-2020-1121 (HIGH 7.0) — An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; viewnvd · 2020-05-21
- [NVD] CVE-2020-1118 (HIGH 8.6) — A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnnvd · 2020-05-21
- [NVD] CVE-2020-1117 (HIGH 8.8) — A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, channvd · 2020-05-21
- [NVD] CVE-2020-1116 (MEDIUM 5.5) — An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To explonvd · 2020-05-21
- [NVD] CVE-2020-1114 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete dnvd · 2020-05-21
- [NVD] CVE-2020-1113 (MEDIUM 5.3) — A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could thennvd · 2020-05-21
- [NVD] CVE-2020-1112 (HIGH 8.5) — An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder. To nvd · 2020-05-21
- [NVD] CVE-2020-1111 (HIGH 7.8) — An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; viewnvd · 2020-05-21
- [NVD] CVE-2020-1110 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or denvd · 2020-05-21
- [NVD] CVE-2020-1109 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or denvd · 2020-05-21
- [NVD] CVE-2020-1108 (HIGH 7.5) — A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be expnvd · 2020-05-21
- [NVD] CVE-2020-1107 (MEDIUM 5.4) — A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePointnvd · 2020-05-21
- [NVD] CVE-2020-1106 (MEDIUM 6.1) — A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an anvd · 2020-05-21
- [NVD] CVE-2020-1105 (MEDIUM 5.4) — A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePointnvd · 2020-05-21
- [NVD] CVE-2020-1104 (MEDIUM 5.4) — A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePointnvd · 2020-05-21
- [NVD] CVE-2020-1103 (MEDIUM 6.5) — An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Microsoft SharePoint Senvd · 2020-05-21
- [NVD] CVE-2020-1102 (HIGH 8.8) — A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool anvd · 2020-05-21
- [NVD] CVE-2020-1101 (MEDIUM 5.4) — A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an anvd · 2020-05-21
- [NVD] CVE-2020-1100 (MEDIUM 5.4) — A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an anvd · 2020-05-21
- [NVD] CVE-2020-1099 (MEDIUM 5.4) — A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an anvd · 2020-05-21
- [NVD] CVE-2020-1096 (MEDIUM 4.2) — A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfulnvd · 2020-05-21
- [NVD] CVE-2020-1093 (HIGH 7.5) — A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploitenvd · 2020-05-21
- [NVD] CVE-2020-1092 (HIGH 7.5) — A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploitednvd · 2020-05-21
- [NVD] CVE-2020-1090 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specinvd · 2020-05-21
- [NVD] CVE-2020-1088 (HIGH 7.8) — An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gainvd · 2020-05-21
- [NVD] CVE-2020-1087 (HIGH 7.8) — An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker couldnvd · 2020-05-21
- [NVD] CVE-2020-1086 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specinvd · 2020-05-21
- [NVD] CVE-2020-1084 (MEDIUM 5.5) — A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. To exploit this vulnerability, nvd · 2020-05-21
- [NVD] CVE-2020-1082 (HIGH 7.8) — An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gainvd · 2020-05-21
- [NVD] CVE-2020-1081 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers. An authenticated attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. To explnvd · 2020-05-21
- [NVD] CVE-2020-1079 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete data; or create new accnvd · 2020-05-21
- [NVD] CVE-2020-1078 (HIGH 7.8) — An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. To exploit the vulnerability, an attacker would require unprivileged execution on the victim system. After successfully exploiting the vnvd · 2020-05-21
- [NVD] CVE-2020-1077 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specinvd · 2020-05-21
- [NVD] CVE-2020-1076 (MEDIUM 5.5) — A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected systnvd · 2020-05-21
- [NVD] CVE-2020-1075 (MEDIUM 5.5) — An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. A attacker could exploit this vulnerabnvd · 2020-05-21
- [NVD] CVE-2020-1072 (MEDIUM 5.5) — An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker woulnvd · 2020-05-21
- [NVD] CVE-2020-1071 (MEDIUM 6.8) — An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability an attacker would nnvd · 2020-05-21
- [NVD] CVE-2020-1070 (HIGH 7.8) — An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could thennvd · 2020-05-21
- [NVD] CVE-2020-1069 (HIGH 8.8) — A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in tnvd · 2020-05-21
- [NVD] CVE-2020-1068 (HIGH 7.8) — An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could explnvd · 2020-05-21
- [NVD] CVE-2020-1067 (HIGH 7.8) — A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker who has a nvd · 2020-05-21
- [NVD] CVE-2020-1066 (HIGH 7.8) — An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnnvd · 2020-05-21
- [NVD] CVE-2020-1065 (MEDIUM 4.2) — A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfunvd · 2020-05-21
- [NVD] CVE-2020-1064 (HIGH 7.5) — A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully envd · 2020-05-21
- [NVD] CVE-2020-1063 (MEDIUM 5.4) — A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an nvd · 2020-05-21
- [NVD] CVE-2020-1062 (HIGH 7.5) — A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploitednvd · 2020-05-21
- [NVD] CVE-2020-1061 (HIGH 7.5) — A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfullynvd · 2020-05-21
- [NVD] CVE-2020-1060 (HIGH 7.5) — A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploitenvd · 2020-05-21
- [NVD] CVE-2020-1059 (MEDIUM 4.3) — A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content nvd · 2020-05-21