|
249031
|
3.3 |
LOW
Local
|
microsoft
|
windows_10 windows_server_2016
|
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Win…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2018-0966
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249032
|
6.1 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016
|
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V In…
|
NVD-CWE-noinfo
|
CVE-2018-0964
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249033
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 201…
|
NVD-CWE-noinfo
|
CVE-2018-0963
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249034
|
5.3 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V In…
|
CWE-20
Improper Input Validation
|
CVE-2018-0957
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249035
|
5.3 |
MEDIUM
Network
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7 windows_rt_8.1
|
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Pr…
|
NVD-CWE-noinfo
|
CVE-2018-0976
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249036
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_7 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass,…
|
NVD-CWE-noinfo
|
CVE-2018-0975
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249037
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_7 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass,…
|
NVD-CWE-noinfo
|
CVE-2018-0974
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249038
|
7.5 |
HIGH
Network
|
microsoft
|
windows_10 windows_server_2016
|
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."…
|
NVD-CWE-noinfo
|
CVE-2018-0956
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249039
|
6.5 |
MEDIUM
Network
|
microsoft
|
office_compatibility_pack office word
|
An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Informatio…
|
NVD-CWE-noinfo
|
CVE-2018-0950
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249040
|
7.8 |
HIGH
Local
|
microsoft
|
excel
|
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This …
|
NVD-CWE-noinfo
|
CVE-2018-0920
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|