Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2010-3333 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2010-0232 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2010-0188 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Reader and Acrobat | Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-3129 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Excel | Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-1123 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-3431 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: VirtualBox | An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-2992 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2004-0210 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2002-0367 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2022-24682 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaborate Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-11
CVE-2017-8570 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2017-0222 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2014-6352 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2022-23131 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Commerce and Magento Open Source | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2022-0609 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2019-0752 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-8174 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.