CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 7.4 |
High |
||
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 7.8 |
High |
||
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 7 |
High |
||
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. | 7.8 |
High |
||
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
|||
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents. | 3.5 |