Skip to content
COOEY
LIVE FEED
1357 events · 13 sources · newest first
2022-03-03 CISA KEV
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
2022-03-03 CISA KEV
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from...
2022-03-03 CISA KEV
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607...
2022-03-03 CISA KEV
The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
2022-03-03 CISA KEV
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
2022-03-03 CISA KEV
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
2022-03-03 CISA KEV
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
2022-03-03 CISA KEV
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
2022-03-03 CISA KEV
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
2022-03-03 CISA KEV
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.
2022-03-03 CISA KEV
Apache Tomcat Improper Privilege Management Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
2022-03-03 CISA KEV
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
2022-03-03 CISA KEV
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
2022-03-03 CISA KEV
Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
2022-03-03 CISA KEV
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
2022-03-03 CISA KEV
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
2022-03-03 CISA KEV
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.
2022-03-03 CISA KEV
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-02-25 CISA KEV
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
2022-02-25 CISA KEV
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
2022-02-25 CISA KEV
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
2022-02-22 CISA KEV
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
2022-02-22 CISA KEV
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
2022-02-15 CISA KEV
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
2022-02-15 CISA KEV
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to...
2022-02-15 CISA KEV
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
2022-02-15 CISA KEV
Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
2022-02-15 CISA KEV
Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-02-11 CISA KEV
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit,...
2022-02-10 CISA KEV
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
◀ PREV PAGE 27 / 34 NEXT ▶