|
266261
|
8.8 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_10 windows_8.1
|
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords vi…
|
CWE-285
Improper Authorization
|
CVE-2016-3352
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266262
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3350
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266263
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_10 windows_8.1
|
The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Wi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3349
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266264
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3348
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266265
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10
|
Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka "Windows Permissions Enforcement Elevat…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3346
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266266
|
8.8 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 a…
|
CWE-284
Improper Access Control
|
CVE-2016-3345
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266267
|
3.3 |
LOW
Local
|
microsoft
|
windows_10
|
The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosu…
|
CWE-200
Information Exposure
|
CVE-2016-3344
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266268
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a diffe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3330
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266269
|
3.1 |
LOW
Network
|
microsoft
|
edge internet_explorer
|
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
|
CWE-200
Information Exposure
|
CVE-2016-3325
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266270
|
8.8 |
HIGH
Network
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corru…
|
NVD-CWE-noinfo
|
CVE-2016-3324
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|