Skip to content
COOEY
LIVE FEED
1602 events · 13 sources · newest first
2021-11-03 CISA KEV
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
2021-11-03 CISA KEV
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
2021-11-03 CISA KEV
Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful...
2021-11-03 CISA KEV
Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
2021-11-03 CISA KEV
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
2021-11-03 CISA KEV
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
2021-11-03 CISA KEV
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a...
2021-11-03 CISA KEV
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all...
2021-11-03 CISA KEV
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.
2021-11-03 CISA KEV
Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.
2021-11-03 CISA KEV
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all...
2021-11-03 CISA KEV
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
2021-11-03 CISA KEV
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.
2021-11-03 CISA KEV
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
2021-11-03 CISA KEV
Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
2021-11-03 CISA KEV
Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.
2021-11-03 CISA KEV
McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.
2021-11-03 CISA KEV
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
2021-11-03 CISA KEV
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
2021-11-03 CISA KEV
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
2021-11-03 CISA KEV
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
2021-11-03 CISA KEV
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
2021-11-03 CISA KEV
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request,...
2021-11-03 CISA KEV
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
2021-11-03 CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2021-11-03 CISA KEV
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web...
◀ PREV PAGE 36 / 41 NEXT ▶