This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2013-09-11
Product Sharepoint Server Last view 2021-04-13
Version 2010 Type Application
Update sp2  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:microsoft:sharepoint_server

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
7.8 2021-04-13 CVE-2021-28453

Microsoft Word Remote Code Execution Vulnerability

7.8 2021-01-12 CVE-2021-1716

Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1715.

7.8 2021-01-12 CVE-2021-1715

Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1716.

7.8 2020-12-10 CVE-2020-17122

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.

5.4 2020-11-11 CVE-2020-17060

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17016.

6.5 2020-10-16 CVE-2020-16953

An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory, aka 'Microsoft SharePoint Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16941, CVE-2020-16942, CVE-2020-16948, CVE-2020-16950.

7.8 2020-10-16 CVE-2020-16929

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16930, CVE-2020-16931, CVE-2020-16932.

8.8 2020-09-11 CVE-2020-1576

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1453, CVE-2020-1595.

4.3 2020-09-11 CVE-2020-1440

A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data, aka 'Microsoft SharePoint Server Tampering Vulnerability'. This CVE ID is unique from CVE-2020-1523.

8.8 2020-09-11 CVE-2020-1218

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1338.

5.5 2020-08-17 CVE-2020-1583

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1503.

5.4 2020-08-17 CVE-2020-1580

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1573.

5.5 2020-08-17 CVE-2020-1505

An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

5.5 2020-08-17 CVE-2020-1503

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1583.

5.4 2020-08-17 CVE-2020-1501

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1499, CVE-2020-1500.

5.4 2020-08-17 CVE-2020-1500

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1499, CVE-2020-1501.

8.8 2020-08-17 CVE-2020-1495

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1496, CVE-2020-1498, CVE-2020-1504.

5.4 2020-07-14 CVE-2020-1456

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.

5.4 2020-07-14 CVE-2020-1451

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1456.

5.4 2020-07-14 CVE-2020-1450

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1451, CVE-2020-1456.

8.8 2020-07-14 CVE-2020-1447

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

8.8 2020-07-14 CVE-2020-1446

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

8.8 2020-07-14 CVE-2020-1439

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

5.5 2020-07-14 CVE-2020-1342

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.

7.8 2020-07-14 CVE-2020-1147

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CWE : Common Weakness Enumeration

%idName
30% (25) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
20% (17) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
14% (12) CWE-20 Improper Input Validation
10% (9) CWE-200 Information Exposure
6% (5) CWE-125 Out-of-bounds Read
3% (3) CWE-787 Out-of-bounds Write
3% (3) CWE-94 Failure to Control Generation of Code ('Code Injection')
2% (2) CWE-399 Resource Management Errors
1% (1) CWE-502 Deserialization of Untrusted Data
1% (1) CWE-494 Download of Code Without Integrity Check
1% (1) CWE-416 Use After Free
1% (1) CWE-284 Access Control (Authorization) Issues
1% (1) CWE-269 Improper Privilege Management
1% (1) CWE-264 Permissions, Privileges, and Access Controls
1% (1) CWE-254 Security Features

SAINT Exploits

Description Link
Microsoft Word RTF Object Confusion More info here
Microsoft SharePoint Picker.aspx deserialization vulnerability More info here

ExploitDB Exploits

id Description
32793 MS14-017 Microsoft Word RTF Object Confusion

Information Assurance Vulnerability Management (IAVM)

id Description
2015-A-0194 Multiple Vulnerabilities in Microsoft Office (MS15-081)
Severity: Category II - VMSKEY: V0061307
2015-A-0163 Multiple Vulnerabilities in Microsoft Office (MS15-070)
Severity: Category II - VMSKEY: V0061121
2015-A-0104 Microsoft SharePoint Remote Code Execution Vulnerability (MS15-047)
Severity: Category II - VMSKEY: V0060645
2015-A-0103 Multiple Vulnerabilities in Microsoft Office Products (MS15-046)
Severity: Category II - VMSKEY: V0060643
2015-A-0090 Multiple Vulnerabilities in Microsoft Office (MS15-033)
Severity: Category II - VMSKEY: V0059895
2015-A-0052 Multiple Vulnerabilities in Microsoft Office (MS15-022)
Severity: Category II - VMSKEY: V0058999
2014-A-0190 Microsoft Word and Office Remote Code Execution Vulnerability (MS14-081)
Severity: Category II - VMSKEY: V0057701
2014-A-0074 Multiple Vulnerabilities in Microsoft Office SharePoint Server
Severity: Category II - VMSKEY: V0050449
2014-A-0049 Multiple Vulnerabilities in Microsoft Office
Severity: Category II - VMSKEY: V0048675
2014-A-0006 Multiple Vulnerabilities in Microsoft Office and Web Apps
Severity: Category II - VMSKEY: V0043406
2013-A-0231 Multiple Vulnerabilities in Microsoft Exchange Server
Severity: Category I - VMSKEY: V0042592
2013-B-0136 Microsoft SharePoint Remote Code Execution Vulnerability
Severity: Category II - VMSKEY: V0042583
2013-B-0116 Microsoft SharePoint Remote Code Execution Vulnerabilities
Severity: Category II - VMSKEY: V0040765
2013-B-0114 Multiple Vulnerabilities in Microsoft Office Excel
Severity: Category II - VMSKEY: V0040757
2013-A-0178 Multiple Vulnerabilities in Microsoft Office
Severity: Category II - VMSKEY: V0040289
2013-A-0171 Multiple Remote Code Execution Vulnerabilities in Microsoft Excel
Severity: Category I - VMSKEY: V0040295
2013-A-0174 Multiple Remote Code Execution Vulnerabilities in Microsoft SharePoint Server
Severity: Category II - VMSKEY: V0040292

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2020-11-03 Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt
RuleID : 55862 - Type : SERVER-WEBAPP - Revision : 2
2020-09-17 Microsoft Windows .NET API XML unsafe deserialization attempt
RuleID : 54790 - Type : SERVER-WEBAPP - Revision : 1
2020-09-17 Microsoft Windows .NET API XML unsafe deserialization attempt
RuleID : 54789 - Type : SERVER-WEBAPP - Revision : 1
2020-09-03 Microsoft Windows .NET API XML unsafe deserialization attempt
RuleID : 54684 - Type : SERVER-WEBAPP - Revision : 1
2020-09-02 Microsoft Windows .NET API XML unsafe deserialization attempt
RuleID : 54629 - Type : SERVER-WEBAPP - Revision : 2
2020-08-13 Microsoft Windows .NET API XML unsafe deserialization attempt
RuleID : 54511 - Type : SERVER-WEBAPP - Revision : 1
2019-08-29 Win.Backdoor.Agent webshell inbound request attempt
RuleID : 51368-community - Type : MALWARE-BACKDOOR - Revision : 2
2019-10-01 Win.Backdoor.Agent webshell inbound request attempt
RuleID : 51368 - Type : MALWARE-BACKDOOR - Revision : 2
2019-07-23 Microsoft Office Excel malicious cce value following a PtgMemFunc token
RuleID : 50462 - Type : FILE-OFFICE - Revision : 1
2019-07-23 Microsoft Office Excel malicious cce value following a PtgMemFunc token
RuleID : 50461 - Type : FILE-OFFICE - Revision : 1
2019-12-19 Win.Backdoor.Chopper webshell inbound request attempt
RuleID : 50277-community - Type : MALWARE-BACKDOOR - Revision : 4
2019-07-02 Win.Backdoor.Chopper webshell inbound request attempt
RuleID : 50277 - Type : MALWARE-BACKDOOR - Revision : 4
2019-12-19 Win.Backdoor.Chopper webshell inbound request attempt
RuleID : 50276-community - Type : MALWARE-BACKDOOR - Revision : 3
2019-07-02 Win.Backdoor.Chopper webshell inbound request attempt
RuleID : 50276 - Type : MALWARE-BACKDOOR - Revision : 3
2019-07-02 Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt
RuleID : 50275 - Type : SERVER-WEBAPP - Revision : 1
2019-05-21 Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt
RuleID : 49861 - Type : SERVER-WEBAPP - Revision : 4
2019-03-26 Microsoft Office Word styleWithEffects use-after-free attempt
RuleID : 49254 - Type : FILE-OFFICE - Revision : 4
2019-03-26 Microsoft Office Word styleWithEffects use-after-free attempt
RuleID : 49253 - Type : FILE-OFFICE - Revision : 4
2019-03-05 Microsoft Office XML nested num tag double-free attempt
RuleID : 49049 - Type : FILE-OFFICE - Revision : 1
2019-03-05 Microsoft Office XML nested num tag double-free attempt
RuleID : 49048 - Type : FILE-OFFICE - Revision : 1
2018-12-14 Microsoft Office directory entry remote code execution attempt
RuleID : 48379 - Type : FILE-OFFICE - Revision : 1
2018-12-14 Microsoft Office directory entry remote code execution attempt
RuleID : 48378 - Type : FILE-OFFICE - Revision : 1
2018-08-16 Microsoft Office Excel fileVersion use-after-free attempt
RuleID : 47204 - Type : FILE-OFFICE - Revision : 1
2018-08-16 Microsoft Office Excel fileVersion use-after-free attempt
RuleID : 47203 - Type : FILE-OFFICE - Revision : 1
2018-08-16 Microsoft Office Excel fileVersion use-after-free attempt
RuleID : 47202 - Type : FILE-OFFICE - Revision : 2

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2018-12-13 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macos_ms18_dec_office.nasl - Type: ACT_GATHER_INFO
2018-03-13 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macos_ms18_mar_office.nasl - Type: ACT_GATHER_INFO
2017-08-08 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_aug_office_sharepoint.nasl - Type: ACT_GATHER_INFO
2017-07-11 Name: An application installed on the remote Windows host is affected by multiple r...
File: smb_nt_ms17_jul_office_web.nasl - Type: ACT_GATHER_INFO
2017-07-11 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_jul_office_sharepoint.nasl - Type: ACT_GATHER_INFO
2017-07-11 Name: An application installed on the remote Windows host is affected by multiple r...
File: smb_nt_ms17_jul_office.nasl - Type: ACT_GATHER_INFO
2017-07-11 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macosx_ms17_july_office.nasl - Type: ACT_GATHER_INFO
2017-06-14 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_jun_office_web.nasl - Type: ACT_GATHER_INFO
2017-06-14 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_jun_office_sharepoint.nasl - Type: ACT_GATHER_INFO
2017-06-14 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_jun_office.nasl - Type: ACT_GATHER_INFO
2017-06-13 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macosx_ms17_june_office.nasl - Type: ACT_GATHER_INFO
2017-05-10 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_may_office.nasl - Type: ACT_GATHER_INFO
2017-04-12 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms17_apr_office.nasl - Type: ACT_GATHER_INFO
2017-03-15 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macosx_ms17-014_office.nasl - Type: ACT_GATHER_INFO
2017-03-15 Name: An application installed on the remote host is affected by multiple vulnerabi...
File: smb_nt_ms17-014.nasl - Type: ACT_GATHER_INFO
2016-12-14 Name: An application installed on the remote host is affected by multiple vulnerabi...
File: smb_nt_ms16-148.nasl - Type: ACT_GATHER_INFO
2016-12-14 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macosx_ms16-148_office.nasl - Type: ACT_GATHER_INFO
2016-11-16 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macosx_ms16-133_office.nasl - Type: ACT_GATHER_INFO
2016-11-08 Name: An application installed on the remote host is affected by multiple vulnerabi...
File: smb_nt_ms16-133.nasl - Type: ACT_GATHER_INFO
2016-10-12 Name: An application installed on the remote host is affected by a remote code exec...
File: smb_nt_ms16-121.nasl - Type: ACT_GATHER_INFO
2016-10-12 Name: An application installed on the remote Mac OS X host is affected by a remote ...
File: macosx_ms16-121_office.nasl - Type: ACT_GATHER_INFO
2016-07-12 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms16-088.nasl - Type: ACT_GATHER_INFO
2016-07-12 Name: An application installed on the remote Mac OS X host is affected by multiple ...
File: macosx_ms16-088_office.nasl - Type: ACT_GATHER_INFO
2016-06-15 Name: An application installed on the remote Windows host is affected by multiple v...
File: smb_nt_ms16-070.nasl - Type: ACT_GATHER_INFO
2016-06-15 Name: An application installed on the remote Mac OS X host is affected by a remote ...
File: macosx_ms16-070_office.nasl - Type: ACT_GATHER_INFO