Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.