Skip to content
COOEY
LIVE FEED
1581 events · 4 sources · newest first
2022-03-28 CISA KEV
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-28 CISA KEV
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
2022-03-28 CISA KEV
Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
2022-03-28 CISA KEV
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code...
2022-03-28 CISA KEV
Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
2022-03-28 CISA KEV
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
2022-03-28 CISA KEV
afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
2022-03-28 CISA KEV
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
2022-03-28 CISA KEV
Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
2022-03-28 CISA KEV
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws...
2022-03-28 CISA KEV
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
2022-03-28 CISA KEV
JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
2022-03-28 CISA KEV
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-03-25 CISA KEV
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
2022-03-25 CISA KEV
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
2022-03-25 CISA KEV
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
2022-03-25 CISA KEV
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
2022-03-25 CISA KEV
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
2022-03-25 CISA KEV
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
2022-03-25 CISA KEV
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
2022-03-25 CISA KEV
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
2022-03-25 CISA KEV
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
2022-03-25 CISA KEV
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
2022-03-25 CISA KEV
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
2022-03-25 CISA KEV
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
2022-03-25 CISA KEV
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
2022-03-25 CISA KEV
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
◀ PREV PAGE 29 / 40 NEXT ▶