Vulnerabilities > Microsoft > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-12-20 CVE-2016-7278 Information Exposure vulnerability in Microsoft Internet Explorer 10/11/9
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-12-20 CVE-2016-7267 Improper Input Validation vulnerability in Microsoft Excel 2010/2013/2016
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
local
low complexity
microsoft CWE-20
5.5
2016-12-20 CVE-2016-7258 Information Exposure vulnerability in Microsoft Windows 10 and Windows Server 2016
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-12-20 CVE-2016-7257 Information Exposure vulnerability in Microsoft products
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
6.5
2016-12-20 CVE-2016-7219 Information Exposure vulnerability in Microsoft products
The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Crypto Driver Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-12-20 CVE-2016-7206 Cross-site Scripting vulnerability in Microsoft Edge
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7280.
network
low complexity
microsoft CWE-79
6.1
2016-11-10 CVE-2016-7252 Information Exposure vulnerability in Microsoft SQL Server 2016
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
6.5
2016-11-10 CVE-2016-7251 Cross-site Scripting vulnerability in Microsoft SQL Server 2016
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
network
low complexity
microsoft CWE-79
6.1
2016-11-10 CVE-2016-7244 Improper Access Control vulnerability in Microsoft Office 2007
Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
local
low complexity
microsoft CWE-284
5.5
2016-11-10 CVE-2016-7237 Improper Access Control vulnerability in Microsoft products
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."
network
low complexity
microsoft CWE-284
6.5