Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Sharepoint_server
(Microsoft)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 405 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2012-12-12 | CVE-2012-2539 | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability." | Office_compatibility_pack, Office_web_apps, Office_word_viewer, Sharepoint_server, Word | 7.8 | ||
2014-03-25 | CVE-2014-1761 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014. | Office, Office_compatibility_pack, Office_web_apps, Office_web_apps_server, Sharepoint_server, Word, Word_viewer | 7.8 | ||
2024-04-09 | CVE-2024-26251 | Microsoft SharePoint Server Spoofing Vulnerability | Sharepoint_server | 3.1 | ||
2024-03-12 | CVE-2024-21426 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Sharepoint_server | N/A | ||
2020-05-21 | CVE-2020-1023 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102. | Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server | 8.8 | ||
2020-05-21 | CVE-2020-1024 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102. | Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server | 8.8 | ||
2020-05-21 | CVE-2020-1069 | A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'. | Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server | 8.8 | ||
2020-05-21 | CVE-2020-1099 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106. | Sharepoint_enterprise_server, Sharepoint_server | 5.4 | ||
2020-05-21 | CVE-2020-1100 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106. | Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server | 5.4 | ||
2020-05-21 | CVE-2020-1101 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106. | Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server | 5.4 |