Skip to content
COOEY
LIVE FEED
1602 events · 13 sources · newest first
2022-04-13 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
2022-04-11 CISA KEV
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
2022-04-11 CISA KEV
Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
2022-04-11 CISA KEV
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
2022-04-11 CISA KEV
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
2022-04-11 CISA KEV
Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
2022-04-11 CISA KEV
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
2022-04-06 CISA KEV
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
2022-04-06 CISA KEV
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
2022-04-04 CISA KEV
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
2022-04-04 CISA KEV
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
2022-04-04 CISA KEV
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
2022-04-04 CISA KEV
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
2022-03-31 CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
2022-03-31 CISA KEV
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
2022-03-31 CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-03-31 CISA KEV
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
2022-03-31 CISA KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
2022-03-28 CISA KEV
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
2022-03-28 CISA KEV
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
2022-03-28 CISA KEV
afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
2022-03-28 CISA KEV
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
2022-03-28 CISA KEV
Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
2022-03-28 CISA KEV
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws...
2022-03-28 CISA KEV
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code...
2022-03-28 CISA KEV
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
2022-03-28 CISA KEV
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.
2022-03-28 CISA KEV
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
2022-03-28 CISA KEV
JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
2022-03-28 CISA KEV
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
2022-03-28 CISA KEV
Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
2022-03-28 CISA KEV
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
2022-03-28 CISA KEV
Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-28 CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
◀ PREV PAGE 29 / 41 NEXT ▶