Vendor: Cisco | Product: IOS software | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2017-11826 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2017-11292 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2017-0261 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2017-0001 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Graphics Device Interface (GDI) | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-8562 · CISA Known Exploited Vulnerabilities
Vendor: Siemens | Product: SIMATIC CP | An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-7855 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-7262 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Excel | A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-7193 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-5195 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-4117 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-1019 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-0099 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-7645 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-5119 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-4902 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Java SE | Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-3043 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-2590 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Java SE | An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-2545 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-2424 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: PowerPoint | Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.