Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2012-0151 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2011-2462 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Reader and Acrobat | The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2011-0609 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2010-2883 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2010-2572 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: PowerPoint | Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2010-1297 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2009-4324 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-3953 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-1862 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader, Flash Player | Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2009-0563 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-0557 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2008-0655 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2007-5659 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2006-2492 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Word | Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2022-26134 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server/Data Center | Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions…
Read full source summary
Vendor: Atlassian | Product: Confluence Server/Data Center | Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. | Federal remediation due: 2022-06-06
CVE-2019-3010 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Solaris | Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-3393 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-7256 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-1010 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player and AIR | Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.