Skip to content
COOEY
LIVE FEED
1683 events · 4 sources · newest first
2021-11-03 CISA KEV
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to...
2021-11-03 CISA KEV
Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
2021-11-03 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
2021-11-03 CISA KEV
Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web...
2021-11-03 CISA KEV
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
2021-11-03 CISA KEV
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple...
2021-11-03 CISA KEV
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
2021-11-03 CISA KEV
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in...
2021-11-03 CISA KEV
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
2021-11-03 CISA KEV
PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.
2021-11-03 CISA KEV
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
2021-11-03 CISA KEV
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to...
2021-11-03 CISA KEV
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
2021-11-03 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
2021-11-03 CISA KEV
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
2021-11-03 CISA KEV
Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).
2021-11-03 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
2021-11-03 CISA KEV
SonicWall SSLVPN SMA100 SQL Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
2021-11-03 CISA KEV
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which...
2021-11-03 CISA KEV
Ivanti Pulse Connect Secure Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
2021-11-03 CISA KEV
VMware vCenter Server Improper Input Validation Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
2021-11-03 CISA KEV
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
2021-11-03 CISA KEV
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves...
2021-11-03 CISA KEV
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page....
2021-11-03 CISA KEV
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
2021-11-03 CISA KEV
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
2021-11-03 CISA KEV
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
2021-11-03 CISA KEV
Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.
2021-11-03 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
2021-11-03 CISA KEV
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
2021-11-03 CISA KEV
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
2021-11-03 CISA KEV
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
2021-11-03 CISA KEV
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
2021-11-03 CISA KEV
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request,...
2021-11-03 CISA KEV
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
◀ PREV PAGE 40 / 43 NEXT ▶