Page 325 of 2398 results (0.006 seconds)

CVSS: 7.0EPSS: 0%CPEs: 15EXPL: 0

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. Existe una vulnerabilidad de elevación de privilegios cuando el controlador Windows Common Log File System (CLFS) gestiona incorrectamente los objetos en la memoria. Esto también se conoce como "Windows Common Log File System Driver Elevation of Privilege Vulnerability". Esto afecta a Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10 y Windows 10 Servers. • http://www.securityfocus.com/bid/104063 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8167 • CWE-404: Improper Resource Shutdown or Release •

CVSS: 7.6EPSS: 94%CPEs: 17EXPL: 1

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177. Existe una vulnerabilidad de divulgación de información cuando Chakra revela incorrectamente el contenido de la memoria, lo que podría otorgar a un atacante información para comprometer aún más el ordenador o los datos de un usuario. Esto también se conoce como "Chakra Scripting Engine Memory Corruption Vulnerability". • https://www.exploit-db.com/exploits/45011 http://www.securityfocus.com/bid/103986 http://www.securitytracker.com/id/1040844 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8145 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 97%CPEs: 16EXPL: 1

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. Existe una vulnerabilidad de ejecución remota de código en "Microsoft COM for Windows" cuando no gestiona correctamente objetos serializados. Esto también se conoce como "Microsoft COM for Windows Remote Code Execution Vulnerability". Esto afecta a Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10 y Windows 10 Servers. • https://www.exploit-db.com/exploits/44906 http://www.securityfocus.com/bid/104030 http://www.securitytracker.com/id/1040848 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0824 • CWE-502: Deserialization of Untrusted Data •

CVSS: 5.5EPSS: 0%CPEs: 14EXPL: 0

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8141. Existe una vulnerabilidad de divulgación de información cuando el kernel de Windows gestiona incorrectamente los objetos en la memoria. Esto también se conoce como "Windows Kernel Information Disclosure Vulnerability". • http://www.securityfocus.com/bid/104040 http://www.securitytracker.com/id/1040849 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8127 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.6EPSS: 97%CPEs: 16EXPL: 7

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. Existe una vulnerabilidad de ejecución remota de código debido a la forma en la que el motor VBScript gestiona los objetos en la memoria. Esto también se conoce como "Windows VBScript Engine Remote Code Execution Vulnerability". Esto afecta a Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10 y Windows 10 Servers. • https://www.exploit-db.com/exploits/44741 https://github.com/0x09AL/CVE-2018-8174-msf https://github.com/SyFi/CVE-2018-8174 https://github.com/lisinan988/CVE-2018-8174-exp https://github.com/orf53975/Rig-Exploit-for-CVE-2018-8174 https://github.com/likescam/CVE-2018-8174-msf http://www.securityfocus.com/bid/103998 https://blog.0patch.com/2018/05/a-single-instruction-micropatch-for.html https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174 • CWE-787: Out-of-bounds Write •