Vendor: PHP | Product: PHP | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4345 · CISA Known Exploited Vulnerabilities
Vendor: Exim | Product: Exim | Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4344 · CISA Known Exploited Vulnerabilities
Vendor: Exim | Product: Exim | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-3035 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS XR | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-2861 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: ColdFusion | A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-2055 · CISA Known Exploited Vulnerabilities
Vendor: phpMyAdmin | Product: phpMyAdmin | Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-0927 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SonicOS | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1405 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1322 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1315 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1253 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1132 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1129 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1069 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Task Scheduler | A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1064 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0841 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0543 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.