|
273771
|
- |
|
microsoft
|
word office_web_apps office sharepoint_server office_compatibility_pack word_viewer
|
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office…
|
NVD-CWE-Other
|
CVE-2015-1649
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273772
|
- |
|
microsoft
|
.net_framework
|
ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-…
|
CWE-19
Data Processing Errors
|
CVE-2015-1648
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273773
|
- |
|
microsoft
|
windows_server_2012 windows_8.1
|
Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka…
|
CWE-20
Improper Input Validation
|
CVE-2015-1647
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273774
|
- |
|
microsoft
|
xml_core_services
|
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerabili…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1646
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273775
|
- |
|
microsoft
|
windows_7 windows_server_2008 windows_server_2003 windows_vista
|
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to execute arbitrary code via a crafted Enhanced Metafile (EMF) imag…
|
CWE-94
Code Injection
|
CVE-2015-1645
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273776
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_server_2003 windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8
|
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not pr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1644
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273777
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_server_2003 windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8
|
Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not pro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1643
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273778
|
- |
|
microsoft
|
project_server
|
Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1640
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273779
|
- |
|
microsoft
|
office
|
Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Outlook App for Mac XS…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1639
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273780
|
- |
|
microsoft
|
windows_server_2012
|
Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by l…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1638
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|