Product:

Sharepoint_server

(Microsoft)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 402
Date Id Summary Products Score Patch Annotated
2024-07-09 CVE-2024-38023 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint_server 7.2
2024-07-09 CVE-2024-38024 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint_server 7.2
2024-07-09 CVE-2024-38094 Microsoft SharePoint Remote Code Execution Vulnerability Sharepoint_server 7.2
2012-12-12 CVE-2012-2539 Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability." Office_compatibility_pack, Office_web_apps, Office_word_viewer, Sharepoint_server, Word 7.8
2019-08-14 CVE-2019-1205 A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of... Office, Office_365_proplus, Office_online_server, Sharepoint_server 7.8
2024-06-11 CVE-2024-30100 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint_server 7.8
2023-05-09 CVE-2023-24955 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint_enterprise_server, Sharepoint_server 7.2
2023-06-14 CVE-2023-29357 Microsoft SharePoint Server Elevation of Privilege Vulnerability Sharepoint_server 9.8
2019-08-14 CVE-2019-1201 A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of... Office, Office_365_proplus, Office_online_server, Office_web_apps, Office_web_apps_server, Sharepoint_enterprise_server, Sharepoint_server, Word 7.8
2019-08-14 CVE-2019-1202 An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a specially crafted application. The security update corrects how SharePoint handles session objects to prevent user session hijacking. Sharepoint_enterprise_server, Sharepoint_foundation, Sharepoint_server 4.4