Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-0718 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
5.5
2019-08-14 CVE-2019-0717 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
5.5
2019-08-14 CVE-2019-0716 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
network
low complexity
microsoft
6.8
2019-08-14 CVE-2019-0715 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
5.5
2019-08-14 CVE-2019-0714 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
5.5
2019-08-13 CVE-2019-12807 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Estsoft Alzip
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format.
6.8
2019-08-13 CVE-2019-12806 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Crosscert Unisign 2.0.4.0
UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack with arbitrary data, due to a buffer overflow in a library.
6.8
2019-08-12 CVE-2019-14935 Incorrect Permission Assignment for Critical Resource vulnerability in 3CX 15
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.
local
low complexity
3cx microsoft CWE-732
4.6
2019-08-07 CVE-2019-14743 Incorrect Permission Assignment for Critical Resource vulnerability in Valvesoftware Steam Client
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.
local
low complexity
valvesoftware microsoft CWE-732
7.2
2019-08-06 CVE-2019-5687 Incorrect Default Permissions vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor
local
low complexity
nvidia microsoft CWE-276
3.6