Vulnerabilities > Microsoft > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2020-0717 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
local
low complexity
microsoft
5.5
2020-02-11 CVE-2020-0716 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
local
low complexity
microsoft
5.5
2020-02-11 CVE-2020-0714 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.
local
low complexity
microsoft
5.5
2020-02-11 CVE-2020-0706 Unspecified vulnerability in Microsoft Edge and Internet Explorer
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
network
low complexity
microsoft
4.3
2020-02-11 CVE-2020-0705 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability'.
local
low complexity
microsoft
5.5
2020-02-11 CVE-2020-0702 Unspecified vulnerability in Microsoft Surface HUB Firmware
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.
low complexity
microsoft
6.8
2020-02-11 CVE-2020-0698 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'.
local
low complexity
microsoft
5.5
2020-02-11 CVE-2020-0696 Unspecified vulnerability in Microsoft Office, Office 365 Proplus and Outlook
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
network
low complexity
microsoft
6.5
2020-02-11 CVE-2020-0695 Origin Validation Error vulnerability in Microsoft Office Online Server
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.
network
low complexity
microsoft CWE-346
5.4
2020-02-11 CVE-2020-0694 Cross-site Scripting vulnerability in Microsoft Sharepoint Enterprise Server 2013/2016/2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
5.4