Vulnerabilities > Microsoft > Windows RT 8 1 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-11 CVE-2020-1033 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory.
local
low complexity
microsoft
4.0
2020-09-11 CVE-2020-0941 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
local
low complexity
microsoft
5.5
2020-09-11 CVE-2020-0921 Unspecified vulnerability in Microsoft products
Microsoft Graphics Component Denial of Service Vulnerability
local
low complexity
microsoft
5.5
2020-09-11 CVE-2020-0875 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls.
local
low complexity
microsoft
5.5
2020-08-17 CVE-2020-1485 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory.
local
low complexity
microsoft
5.5
2020-08-17 CVE-2020-1383 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled.
local
low complexity
microsoft
5.5
2020-08-17 CVE-2020-1379 Out-of-bounds Write vulnerability in Microsoft products
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
local
low complexity
microsoft CWE-787
5.5
2020-07-29 CVE-2020-15707 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow.
6.4
2020-07-29 CVE-2020-15706 Use After Free vulnerability in multiple products
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass.
6.4
2020-07-29 CVE-2020-15705 Improper Verification of Cryptographic Signature vulnerability in multiple products
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed.
6.4