Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2016-12-20 CVE-2016-7280 Cross-site Scripting vulnerability in Microsoft Edge
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7206.
network
low complexity
microsoft CWE-79
6.1
2016-12-20 CVE-2016-7279 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
network
high complexity
microsoft CWE-119
7.5
2016-12-20 CVE-2016-7278 Information Exposure vulnerability in Microsoft Internet Explorer 10/11/9
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-12-20 CVE-2016-7277 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Office 2016
Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
network
low complexity
microsoft CWE-119
critical
9.6
2016-12-20 CVE-2016-7276 Out-of-bounds Read vulnerability in Microsoft Office and Office for mac
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-125
7.1
2016-12-20 CVE-2016-7275 Data Processing Errors vulnerability in Microsoft Office 2010/2013/2016
Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
local
low complexity
microsoft CWE-19
7.8
2016-12-20 CVE-2016-7274 Data Processing Errors vulnerability in Microsoft products
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-19
8.8
2016-12-20 CVE-2016-7273 Data Processing Errors vulnerability in Microsoft Windows 10 and Windows Server 2016
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-19
8.8
2016-12-20 CVE-2016-7272 Data Processing Errors vulnerability in Microsoft products
The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-19
8.8
2016-12-20 CVE-2016-7271 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 10 and Windows Server 2016
The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual trust level (VTL) protection mechanism via a crafted application, aka "Secure Kernel Mode Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-264
7.8