Vendor: Adobe | Product: Flash Player and AIR | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2016-0034 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2015-0310 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2015-0016 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-0071 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-2360 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-2425 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-1769 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-4495 · CISA Known Exploited Vulnerabilities
Vendor: Mozilla | Product: Firefox | Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-8651 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Integer overflow in Adobe Flash Player allows attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2015-6175 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-1671 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-4148 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-8439 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2014-4123 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-0546 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Reader and Acrobat | Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-2817 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-4077 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Input Method Editor (IME) Japanese | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege…
Read full source summary
Vendor: Microsoft | Product: Input Method Editor (IME) Japanese | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-3153 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-7331 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.