|
248901
|
3.3 |
LOW
Local
|
microsoft
|
word office_web_apps sharepoint_server office office_web_apps_server sharepoint_enterprise_server office_online_server
|
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Shar…
|
CWE-125 CWE-908
Out-of-bounds Read Use of Uninitialized Resource
|
CVE-2018-0919
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248902
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_enterprise_server
|
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vu…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0917
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248903
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0915
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248904
|
7.8 |
HIGH
Local
|
microsoft
|
excel office
|
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and Microsoft Office 2016 for Mac allow a security feature bypas…
|
NVD-CWE-noinfo
|
CVE-2018-0907
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248905
|
7.8 |
HIGH
Local
|
microsoft
|
access office
|
Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memor…
|
NVD-CWE-noinfo
|
CVE-2018-0903
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248906
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0916
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248907
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0914
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248908
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0913
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248909
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0912
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248910
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0911
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|