Vendor: IBM | Product: InfoSphere BigInsights | Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2013-3896 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2013-2423 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Java Runtime Environment (JRE) | A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-0074 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2012-1710 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Fusion Middleware | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2010-1428 · CISA Known Exploited Vulnerabilities
Vendor: Red Hat | Product: JBoss | Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2010-0840 · CISA Known Exploited Vulnerabilities
Vendor: Red Hat | Product: JBoss | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2018-8611 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2018-19953 · CISA Known Exploited Vulnerabilities
Vendor: QNAP | Product: Network Attached Storage (NAS) | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2018-19943 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv1 server | The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0022 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: XML Core Services | Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0005 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0149 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0210 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-8291 · CISA Known Exploited Vulnerabilities
Vendor: Artifex | Product: Ghostscript | Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.