Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-0971 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-434
8.8
2020-04-15 CVE-2020-0970 Out-of-bounds Write vulnerability in Microsoft Chakracore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-04-15 CVE-2020-0969 Out-of-bounds Write vulnerability in Microsoft Chakracore and Edge
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-04-15 CVE-2020-0968 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-04-15 CVE-2020-0967 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-787
8.8
2020-04-15 CVE-2020-0966 Unspecified vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-04-15 CVE-2020-0965 Unspecified vulnerability in Microsoft products
A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8
2020-04-15 CVE-2020-0964 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-04-15 CVE-2020-0961 Unspecified vulnerability in Microsoft Office and Office 365 Proplus
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8
2020-04-15 CVE-2020-0960 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8