|
CVE-2018-10561
|
Dasan |
Gigabit Passive Optical Network (GPON) Routers |
Dasan GPON Routers Authentication Bypass Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
|
2022-03-31
|
2022-04-21 |
Unknown
|
|
CVE-2018-10562
|
Dasan |
Gigabit Passive Optical Network (GPON) Routers |
Dasan GPON Routers Command Injection Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
|
2022-03-31
|
2022-04-21 |
Known
|
|
CVE-2021-21551
|
Dell |
dbutil Driver |
Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
|
2022-03-31
|
2022-04-21 |
Unknown
|
|
CVE-2021-28799
|
QNAP |
Network Attached Storage (NAS) |
QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
|
2022-03-31
|
2022-04-21 |
Known
|
|
CVE-2021-34484
|
Microsoft |
Windows |
Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
|
2022-03-31
|
2022-04-21 |
Unknown
|
|
CVE-2022-1040
|
Sophos |
Firewall |
Sophos Firewall Authentication Bypass Vulnerability An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
|
2022-03-31
|
2022-04-21 |
Unknown
|
|
CVE-2022-26871
|
Trend Micro |
Apex Central |
Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
|
2022-03-31
|
2022-04-21 |
Unknown
|
|
CVE-2010-4398
|
Microsoft |
Windows |
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
|
2022-03-28
|
2022-04-21 |
Unknown
|
|
CVE-2011-2005
|
Microsoft |
Ancillary Function Driver (afd.sys) |
Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2012-0518
|
Oracle |
Fusion Middleware |
Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2012-2034
|
Adobe |
Flash Player |
Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2012-2539
|
Microsoft |
Word |
Microsoft Word Remote Code Execution Vulnerability Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2012-5076
|
Oracle |
Java SE |
Oracle Java SE Sandbox Bypass Vulnerability The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2013-1690
|
Mozilla |
Firefox and Thunderbird |
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2013-2465
|
Oracle |
Java SE |
Oracle Java SE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2013-2551
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2013-2729
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2013-3660
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2015-1770
|
Microsoft |
Office |
Microsoft Office Uninitialized Memory Use Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2015-2419
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2015-2426
|
Microsoft |
Windows |
Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2016-0040
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2016-0151
|
Microsoft |
Client-Server Run-time Subsystem (CSRSS) |
Microsoft Windows CSRSS Security Feature Bypass Vulnerability The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2016-0189
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2016-7200
|
Microsoft |
Edge |
Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2016-7201
|
Microsoft |
Edge |
Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2017-0037
|
Microsoft |
Edge and Internet Explorer |
Microsoft Edge and Internet Explorer Type Confusion Vulnerability Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2017-0059
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Information Disclosure Vulnerability Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2017-0213
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2018-8405
|
Microsoft |
DirectX Graphics Kernel (DXGKRNL) |
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2018-8406
|
Microsoft |
DirectX Graphics Kernel (DXGKRNL) |
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2018-8440
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2019-7483
|
SonicWall |
SMA100 |
SonicWall SMA100 Directory Traversal Vulnerability In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2021-20028
|
SonicWall |
Secure Remote Access (SRA) |
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2021-26085
|
Atlassian |
Confluence Server |
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2021-34486
|
Microsoft |
Windows |
Microsoft Windows Event Tracing Privilege Escalation Vulnerability Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2021-38646
|
Microsoft |
Office |
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
|
2022-03-28
|
2022-04-18 |
Known
|
|
CVE-2022-0543
|
Redis |
Debian-specific Redis Servers |
Debian-specific Redis Server Lua Sandbox Escape Vulnerability Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2022-1096
|
Google |
Chromium V8 |
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-03-28
|
2022-04-18 |
Unknown
|
|
CVE-2005-2773
|
Hewlett Packard (HP) |
OpenView Network Node Manager |
HP OpenView Network Node Manager Remote Code Execution Vulnerability HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2009-0927
|
Adobe |
Reader and Acrobat |
Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2009-1151
|
phpMyAdmin |
phpMyAdmin |
phpMyAdmin Remote Code Execution Vulnerability Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2009-2055
|
Cisco |
IOS XR |
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2010-2861
|
Adobe |
ColdFusion |
Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2010-3035
|
Cisco |
IOS XR |
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2010-4344
|
Exim |
Exim |
Exim Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2010-4345
|
Exim |
Exim |
Exim Privilege Escalation Vulnerability Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2012-1823
|
PHP |
PHP |
PHP-CGI Query String Parameter Vulnerability sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2013-2251
|
Apache |
Struts |
Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2013-4810
|
Hewlett Packard (HP) |
ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management |
HP Multiple Products Remote Code Execution Vulnerability HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2013-5223
|
D-Link |
DSL-2760U |
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2014-0130
|
Rails |
Ruby on Rails |
Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2014-3120
|
Elastic |
Elasticsearch |
Elasticsearch Remote Code Execution Vulnerability Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2014-6287
|
Rejetto |
HTTP File Server (HFS) |
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2014-6324
|
Microsoft |
Kerberos Key Distribution Center (KDC) |
Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2014-6332
|
Microsoft |
Windows |
Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-0666
|
Cisco |
Prime Data Center Network Manager (DCNM) |
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-1187
|
D-Link and TRENDnet |
Multiple Devices |
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-1427
|
Elastic |
Elasticsearch |
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-3035
|
TP-Link |
Multiple Archer Devices |
TP-Link Multiple Archer Devices Directory Traversal Vulnerability Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-4068
|
Arcserve |
Unified Data Protection (UDP) |
Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-0752
|
Rails |
Ruby on Rails |
Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-10174
|
NETGEAR |
WNR2000v5 Router |
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-11021
|
D-Link |
DCS-930L Devices |
D-Link DCS-930L Devices OS Command Injection Vulnerability setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-1555
|
NETGEAR |
Wireless Access Point (WAP) Devices |
NETGEAR Multiple WAP Devices Command Injection Vulnerability Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-4171
|
Adobe |
Flash Player |
Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2016-7892
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2017-0146
|
Microsoft |
Windows |
Microsoft Windows SMB Remote Code Execution Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2017-12615
|
Apache |
Tomcat |
Apache Tomcat on Windows Remote Code Execution Vulnerability When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2017-12617
|
Apache |
Tomcat |
Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2017-3881
|
Cisco |
IOS and IOS XE |
Cisco IOS and IOS XE Remote Code Execution Vulnerability A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2017-6316
|
Citrix |
NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server |
Citrix Multiple Products Remote Code Execution Vulnerability A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2017-6334
|
NETGEAR |
DGN2200 Devices |
NETGEAR DGN2200 Devices OS Command Injection Vulnerability dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-0125
|
Cisco |
VPN Routers |
Cisco VPN Routers Remote Code Execution Vulnerability A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-0147
|
Cisco |
Secure Access Control System (ACS) |
Cisco Secure Access Control System Java Deserialization Vulnerability A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-11138
|
Quest |
KACE System Management Appliance |
Quest KACE System Management Appliance Remote Command Execution Vulnerability The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2018-1273
|
VMware Tanzu |
Spring Data Commons |
VMware Tanzu Spring Data Commons Property Binder Vulnerability Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2018-14839
|
LG |
N1A1 NAS |
LG N1A1 NAS Remote Command Execution Vulnerability LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-6961
|
VMware |
SD-WAN Edge |
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-8373
|
Microsoft |
Internet Explorer Scripting Engine |
Microsoft Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2018-8414
|
Microsoft |
Windows |
Microsoft Windows Shell Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-0903
|
Microsoft |
Graphics Device Interface (GDI) |
Microsoft GDI Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-1003030
|
Jenkins |
Matrix Project Plugin |
Jenkins Matrix Project Plugin Remote Code Execution Vulnerability Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-10068
|
Kentico |
Xperience |
Kentico Xperience Deserialization of Untrusted Data Vulnerability Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-11043
|
PHP |
FastCGI Process Manager (FPM) |
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2019-12989
|
Citrix |
SD-WAN and NetScaler |
Citrix SD-WAN and NetScaler SQL Injection Vulnerability Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-12991
|
Citrix |
SD-WAN and NetScaler |
Citrix SD-WAN and NetScaler Command Injection Vulnerability Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-15107
|
Webmin |
Webmin |
Webmin Command Injection Vulnerability An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2019-16920
|
D-Link |
Multiple Routers |
D-Link Multiple Routers Command Injection Vulnerability Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-2616
|
Oracle |
BI Publisher (Formerly XML Publisher) |
Oracle BI Publisher Unauthorized Access Vulnerability Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2019-6340
|
Drupal |
Core |
Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-1631
|
Juniper |
Junos OS |
Juniper Junos OS Path Traversal Vulnerability A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-1956
|
Apache |
Kylin |
Apache Kylin OS Command Injection Vulnerability Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-2021
|
Palo Alto Networks |
PAN-OS |
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2020-2506
|
QNAP Systems |
Helpdesk |
QNAP Helpdesk Improper Access Control Vulnerability QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-25223
|
Sophos |
SG UTM |
Sophos SG UTM Remote Code Execution Vulnerability A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-5410
|
VMware Tanzu |
Spring Cloud Configuration (Config) Server |
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-7247
|
OpenBSD |
OpenSMTPD |
OpenSMTPD Remote Code Execution Vulnerability smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-9054
|
Zyxel |
Multiple Network-Attached Storage (NAS) Devices |
Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2020-9377
|
D-Link |
DIR-610 Devices |
D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2021-22941
|
Citrix |
ShareFile |
Citrix ShareFile Improper Access Control Vulnerability Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2021-42237
|
Sitecore |
XP |
Sitecore XP Remote Command Execution Vulnerability Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2022-21999
|
Microsoft |
Windows |
Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
|
2022-03-25
|
2022-04-15 |
Known
|
|
CVE-2022-26143
|
Mitel |
MiCollab, MiVoice Business Express |
MiCollab, MiVoice Business Express Access Control Vulnerability A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2022-26318
|
WatchGuard |
Firebox and XTM Appliances |
WatchGuard Firebox and XTM Appliances Arbitrary Code Execution On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
|
2022-03-25
|
2022-04-15 |
Unknown
|
|
CVE-2015-2546
|
Microsoft |
Win32k |
Microsoft Win32k Memory Corruption Vulnerability The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2016-3309
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2017-0101
|
Microsoft |
Windows |
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2018-8120
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-0543
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-0841
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1064
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1069
|
Microsoft |
Task Scheduler |
Microsoft Task Scheduler Privilege Escalation Vulnerability A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1129
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1132
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
|
2022-03-15
|
2022-04-05 |
Unknown
|
|
CVE-2019-1253
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1315
|
Microsoft |
Windows |
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1322
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2019-1405
|
Microsoft |
Windows |
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2020-5135
|
SonicWall |
SonicOS |
SonicWall SonicOS Buffer Overflow Vulnerability A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
|
2022-03-15
|
2022-04-05 |
Known
|
|
CVE-2009-3960
|
Adobe |
BlazeDS |
Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
|
2022-03-07
|
2022-09-07 |
Known
|
|
CVE-2013-0625
|
Adobe |
ColdFusion |
Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2013-0629
|
Adobe |
ColdFusion |
Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2013-0631
|
Adobe |
ColdFusion |
Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2016-6277
|
NETGEAR |
Multiple Routers |
NETGEAR Multiple Routers Remote Code Execution Vulnerability NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2017-6077
|
NETGEAR |
Wireless Router DGN2200 |
NETGEAR DGN2200 Remote Code Execution Vulnerability NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2019-11581
|
Atlassian |
Jira Server and Data Center |
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2020-8218
|
Pulse Secure |
Pulse Connect Secure |
Pulse Connect Secure Code Injection Vulnerability A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
|
2022-03-07
|
2022-09-07 |
Unknown
|
|
CVE-2021-21973
|
VMware |
vCenter Server and Cloud Foundation |
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
|
2022-03-07
|
2022-03-21 |
Unknown
|
|
CVE-2022-26485
|
Mozilla |
Firefox |
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
|
2022-03-07
|
2022-03-21 |
Unknown
|
|
CVE-2022-26486
|
Mozilla |
Firefox |
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
|
2022-03-07
|
2022-03-21 |
Unknown
|
|
CVE-2002-0367
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2004-0210
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2008-2992
|
Adobe |
Acrobat and Reader |
Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2008-3431
|
Oracle |
VirtualBox |
Oracle VirtualBox Insufficient Input Validation Vulnerability An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2009-1123
|
Microsoft |
Windows |
Microsoft Windows Improper Input Validation Vulnerability The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2009-3129
|
Microsoft |
Excel |
Microsoft Excel Featheader Record Memory Corruption Vulnerability Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2010-0188
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2010-0232
|
Microsoft |
Windows |
Microsoft Windows Kernel Exception Handler Vulnerability The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2010-3333
|
Microsoft |
Office |
Microsoft Office Stack-based Buffer Overflow Vulnerability A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2011-0611
|
Adobe |
Flash Player |
Adobe Flash Player Remote Code Execution Vulnerability Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2011-1889
|
Microsoft |
Forefront Threat Management Gateway (TMG) |
Microsoft Forefront TMG Remote Code Execution Vulnerability A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2011-3544
|
Oracle |
Java SE JDK and JRE |
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2012-0507
|
Oracle |
Java SE |
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2012-1535
|
Adobe |
Flash Player |
Adobe Flash Player Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2012-1723
|
Oracle |
Java SE |
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2012-1856
|
Microsoft |
Office |
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2012-4681
|
Oracle |
Java SE |
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2013-0632
|
Adobe |
ColdFusion |
Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-0640
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Memory Corruption Vulnerability An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-0641
|
Adobe |
Reader |
Adobe Reader Buffer Overflow Vulnerability A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-1347
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Remote Code Execution Vulnerability This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-1675
|
Mozilla |
Firefox |
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-3346
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-3897
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2013-5065
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2014-0496
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2014-4114
|
Microsoft |
Windows |
Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-1642
|
Microsoft |
Office |
Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-1701
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2015-2387
|
Microsoft |
ATM Font Driver |
Microsoft ATM Font Driver Privilege Escalation Vulnerability ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-2424
|
Microsoft |
PowerPoint |
Microsoft PowerPoint Memory Corruption Vulnerability Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-2545
|
Microsoft |
Office |
Microsoft Office Malformed EPS File Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-2590
|
Oracle |
Java SE |
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-3043
|
Adobe |
Flash Player |
Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-4902
|
Oracle |
Java SE |
Oracle Java SE Integrity Check Vulnerability Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-5119
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2015-7645
|
Adobe |
Flash Player |
Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2016-0099
|
Microsoft |
Windows |
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2016-1019
|
Adobe |
Flash Player |
Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2016-4117
|
Adobe |
Flash Player |
Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
|
2022-03-03
|
2022-03-24 |
Known
|
|
CVE-2016-5195
|
Linux |
Kernel |
Linux Kernel Race Condition Vulnerability Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2016-7193
|
Microsoft |
Office |
Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2016-7262
|
Microsoft |
Excel |
Microsoft Office Security Feature Bypass Vulnerability A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2016-7855
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2016-8562
|
Siemens |
SIMATIC CP |
Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-0001
|
Microsoft |
Graphics Device Interface (GDI) |
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-0261
|
Microsoft |
Office |
Microsoft Office Use-After-Free Vulnerability Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-11292
|
Adobe |
Flash Player |
Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-11826
|
Microsoft |
Office |
Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12231
|
Cisco |
IOS software |
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12232
|
Cisco |
IOS software |
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12233
|
Cisco |
IOS software |
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12234
|
Cisco |
IOS software |
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12235
|
Cisco |
IOS software |
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12237
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12238
|
Cisco |
Catalyst 6800 Series Switches |
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12240
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-12319
|
Cisco |
IOS XE Software |
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6627
|
Cisco |
IOS and IOS XE Software |
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6663
|
Cisco |
IOS and IOS XE Software |
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6736
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6737
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6738
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6739
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6740
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6743
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-6744
|
Cisco |
IOS software |
Cisco IOS Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2017-8540
|
Microsoft |
Malware Protection Engine |
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
|
2022-03-03
|
2022-03-24 |
Unknown
|
|
CVE-2018-0151
|
Cisco |
IOS and IOS XE Software |
Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0154
|
Cisco |
IOS Software |
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0155
|
Cisco |
Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches |
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0156
|
Cisco |
IOS Software and Cisco IOS XE Software |
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0158
|
Cisco |
IOS Software and Cisco IOS XE Software |
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0159
|
Cisco |
IOS Software and Cisco IOS XE Software |
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0161
|
Cisco |
IOS Software |
Cisco IOS Software Resource Management Errors Vulnerability A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0167
|
Cisco |
IOS, XR, and XE Software |
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0172
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0173
|
Cisco |
IOS and IOS XE Software |
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0174
|
Cisco |
IOS XE Software |
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0175
|
Cisco |
IOS, XR, and XE Software |
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0179
|
Cisco |
IOS Software |
Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-0180
|
Cisco |
IOS Software |
Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-8298
|
ChakraCore |
ChakraCore scripting engine |
ChakraCore Scripting Engine Type Confusion Vulnerability The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2018-8581
|
Microsoft |
Exchange Server |
Microsoft Exchange Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
|
2022-03-03
|
2022-03-17 |
Known
|
|
CVE-2019-1297
|
Microsoft |
Excel |
Microsoft Excel Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2019-1652
|
Cisco |
Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers |
Cisco Small Business Routers Improper Input Validation Vulnerability A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2019-16928
|
Exim |
Exim Internet Mailer |
Exim Out-of-bounds Write Vulnerability Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2020-11899
|
Treck TCP/IP stack |
IPv6 |
Treck TCP/IP stack Out-of-Bounds Read Vulnerability The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2020-1938
|
Apache |
Tomcat |
Apache Tomcat Improper Privilege Management Vulnerability Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2021-41379
|
Microsoft |
Windows |
Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
|
2022-03-03
|
2022-03-17 |
Known
|
|
CVE-2022-20699
|
Cisco |
Small Business RV160, RV260, RV340, and RV345 Series Routers |
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2022-20700
|
Cisco |
Small Business RV160, RV260, RV340, and RV345 Series Routers |
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2022-20701
|
Cisco |
Small Business RV160, RV260, RV340, and RV345 Series Routers |
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2022-20703
|
Cisco |
Small Business RV160, RV260, RV340, and RV345 Series Routers |
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2022-20708
|
Cisco |
Small Business RV160, RV260, RV340, and RV345 Series Routers |
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
|
2022-03-03
|
2022-03-17 |
Unknown
|
|
CVE-2014-6352
|
Microsoft |
Windows |
Microsoft Windows Code Injection Vulnerability Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
|
2022-02-25
|
2022-08-25 |
Unknown
|
|
CVE-2017-0222
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
|
2022-02-25
|
2022-08-25 |
Unknown
|
|
CVE-2017-8570
|
Microsoft |
Office |
Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
|
2022-02-25
|
2022-08-25 |
Unknown
|
|
CVE-2022-24682
|
Synacor |
Zimbra Collaborate Suite (ZCS) |
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
|
2022-02-25
|
2022-03-11 |
Known
|
|
CVE-2022-23134
|
Zabbix |
Frontend |
Zabbix Frontend Improper Access Control Vulnerability Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
|
2022-02-22
|
2022-03-08 |
Unknown
|
|
CVE-2022-23131
|
Zabbix |
Frontend |
Zabbix Frontend Authentication Bypass Vulnerability Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
|
2022-02-22
|
2022-03-08 |
Unknown
|
|
CVE-2013-3906
|
Microsoft |
Graphics Component |
Microsoft Graphics Component Memory Corruption Vulnerability Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
|
2022-02-15
|
2022-08-15 |
Unknown
|
|
CVE-2014-1761
|
Microsoft |
Word |
Microsoft Word Memory Corruption Vulnerability Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
|
2022-02-15
|
2022-08-15 |
Unknown
|
|
CVE-2017-9841
|
PHPUnit |
PHPUnit |
PHPUnit Command Injection Vulnerability PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
|
2022-02-15
|
2022-08-15 |
Unknown
|
|
CVE-2018-15982
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
|
2022-02-15
|
2022-08-15 |
Known
|
|
CVE-2018-20250
|
RARLAB |
WinRAR |
WinRAR Absolute Path Traversal Vulnerability WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
|
2022-02-15
|
2022-08-15 |
Known
|
|
CVE-2018-8174
|
Microsoft |
Windows |
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
|
2022-02-15
|
2022-08-15 |
Known
|
|
CVE-2019-0752
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Type Confusion Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
|
2022-02-15
|
2022-08-15 |
Known
|
|
CVE-2022-0609
|
Google |
Chromium Animation |
Google Chromium Animation Use-After-Free Vulnerability Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-02-15
|
2022-03-01 |
Unknown
|
|
CVE-2022-24086
|
Adobe |
Commerce and Magento Open Source |
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
|
2022-02-15
|
2022-03-01 |
Unknown
|
|
CVE-2022-22620
|
Apple |
iOS, iPadOS, and macOS |
Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
|
2022-02-11
|
2022-02-25 |
Unknown
|
|
CVE-2014-4404
|
Apple |
OS X |
Apple OS X Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2015-1130
|
Apple |
OS X |
Apple OS X Authentication Bypass Vulnerability The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2015-1635
|
Microsoft |
HTTP.sys |
Microsoft HTTP.sys Remote Code Execution Vulnerability Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2015-2051
|
D-Link |
DIR-645 Router |
D-Link DIR-645 Router Remote Code Execution Vulnerability D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2016-3088
|
Apache |
ActiveMQ |
Apache ActiveMQ Improper Input Validation Vulnerability The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2017-0144
|
Microsoft |
SMBv1 |
Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
|
2022-02-10
|
2022-08-10 |
Known
|
|
CVE-2017-0145
|
Microsoft |
SMBv1 |
Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
|
2022-02-10
|
2022-08-10 |
Known
|
|
CVE-2017-0262
|
Microsoft |
Office |
Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2017-0263
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2017-10271
|
Oracle |
WebLogic Server |
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
|
2022-02-10
|
2022-08-10 |
Known
|
|
CVE-2017-8464
|
Microsoft |
Windows |
Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2017-9791
|
Apache |
Struts 1 |
Apache Struts 1 Improper Input Validation Vulnerability The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2018-1000861
|
Jenkins |
Jenkins Stapler Web Framework |
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability A code execution vulnerability exists in the Stapler web framework used by Jenkins
|
2022-02-10
|
2022-08-10 |
Unknown
|
|
CVE-2020-0796
|
Microsoft |
SMBv3 |
Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
|
2022-02-10
|
2022-08-10 |
Known
|
|
CVE-2021-36934
|
Microsoft |
Windows |
Microsoft Windows SAM Local Privilege Escalation Vulnerability If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
|
2022-02-10
|
2022-02-24 |
Unknown
|
|
CVE-2022-21882
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
|
2022-02-04
|
2022-02-18 |
Known
|
|
CVE-2014-7169
|
GNU |
Bourne-Again Shell (Bash) |
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
|
2022-01-28
|
2022-07-28 |
Unknown
|
|
CVE-2014-6271
|
GNU |
Bourne-Again Shell (Bash) |
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
|
2022-01-28
|
2022-07-28 |
Unknown
|
|
CVE-2014-1776
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
|
2022-01-28
|
2022-07-28 |
Unknown
|
|
CVE-2017-5689
|
Intel |
Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability |
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
|
2022-01-28
|
2022-07-28 |
Unknown
|
|
CVE-2020-0787
|
Microsoft |
Windows |
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
|
2022-01-28
|
2022-07-28 |
Known
|
|
CVE-2020-5722
|
Grandstream |
UCM6200 |
Grandstream Networks UCM6200 Series SQL Injection Vulnerability Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
|
2022-01-28
|
2022-07-28 |
Unknown
|
|
CVE-2021-20038
|
SonicWall |
SMA 100 Appliances |
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
|
2022-01-28
|
2022-02-11 |
Known
|
|
CVE-2022-22587
|
Apple |
iOS and macOS |
Apple Memory Corruption Vulnerability Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
|
2022-01-28
|
2022-02-11 |
Unknown
|
|
CVE-2021-35247
|
SolarWinds |
Serv-U |
SolarWinds Serv-U Improper Input Validation Vulnerability SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
|
2022-01-21
|
2022-02-04 |
Unknown
|
|
CVE-2018-8453
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
|
2022-01-21
|
2022-07-21 |
Known
|
|
CVE-2012-0391
|
Apache |
Struts 2 |
Apache Struts 2 Improper Input Validation Vulnerability The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
|
2022-01-21
|
2022-07-21 |
Unknown
|
|
CVE-2006-1547
|
Apache |
Struts 1 |
Apache Struts 1 ActionForm Denial-of-Service Vulnerability ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
|
2022-01-21
|
2022-07-21 |
Unknown
|
|
CVE-2020-13927
|
Apache |
Airflow's Experimental API |
Apache Airflow's Experimental API Authentication Bypass The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
|
2022-01-18
|
2022-07-18 |
Unknown
|
|
CVE-2020-11978
|
Apache |
Airflow |
Apache Airflow Command Injection A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
|
2022-01-18
|
2022-07-18 |
Unknown
|
|
CVE-2020-13671
|
Drupal |
Drupal core |
Drupal core Un-restricted Upload of File Improper sanitization in the extension file names is present in Drupal core.
|
2022-01-18
|
2022-07-18 |
Unknown
|
|
CVE-2020-14864
|
Oracle |
Intelligence Enterprise Edition |
Oracle Business Intelligence Enterprise Edition Path Transversal Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
|
2022-01-18
|
2022-07-18 |
Unknown
|
|
CVE-2021-22991
|
F5 |
BIG-IP Traffic Management Microkernel |
F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-21315
|
Npm package |
System Information Library for Node.JS |
System Information Library for Node.JS Command Injection In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-21975
|
VMware |
vRealize Operations Manager API |
VMware Server Side Request Forgery in vRealize Operations Manager API Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
|
2022-01-18
|
2022-02-01 |
Known
|
|
CVE-2021-33766
|
Microsoft |
Exchange Server |
Microsoft Exchange Server Information Disclosure Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-40870
|
Aviatrix |
Aviatrix Controller |
Aviatrix Controller Unrestricted Upload of File Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-25298
|
Nagios |
Nagios XI |
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-25297
|
Nagios |
Nagios XI |
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-25296
|
Nagios |
Nagios XI |
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-32648
|
October CMS |
October CMS |
October CMS Improper Authentication In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
|
2022-01-18
|
2022-02-01 |
Unknown
|
|
CVE-2021-27860
|
FatPipe |
WARP, IPVPN, and MPVPN software |
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.
|
2022-01-10
|
2022-01-24 |
Unknown
|
|
CVE-2019-7609
|
Elastic |
Kibana |
Kibana Arbitrary Code Execution Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2017-1000486
|
Primetek |
Primefaces Application |
Primetek Primefaces Remote Code Execution Vulnerability Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2015-7450
|
IBM |
WebSphere Application Server and Server Hypervisor Edition |
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2019-10149
|
Exim |
Mail Transfer Agent (MTA) |
Exim Mail Transfer Agent (MTA) Improper Input Validation Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2019-1579
|
Palo Alto Networks |
PAN-OS |
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
|
2022-01-10
|
2022-07-10 |
Known
|
|
CVE-2018-13383
|
Fortinet |
FortiOS and FortiProxy |
Fortinet FortiOS and FortiProxy Out-of-bounds Write A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
|
2022-01-10
|
2022-07-10 |
Known
|
|
CVE-2018-13382
|
Fortinet |
FortiOS and FortiProxy |
Fortinet FortiOS and FortiProxy Improper Authorization An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
|
2022-01-10
|
2022-07-10 |
Known
|
|
CVE-2019-9670
|
Synacor |
Zimbra Collaboration Suite (ZCS) |
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2019-2725
|
Oracle |
WebLogic Server |
Oracle WebLogic Server, Injection Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
|
2022-01-10
|
2022-07-10 |
Known
|
|
CVE-2013-3900
|
Microsoft |
WinVerifyTrust function |
Microsoft WinVerifyTrust function Remote Code Execution A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2019-1458
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
|
2022-01-10
|
2022-07-10 |
Known
|
|
CVE-2020-6572
|
Google |
Chrome Media |
Google Chrome Media Use-After-Free Vulnerability Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
|
2022-01-10
|
2022-07-10 |
Unknown
|
|
CVE-2021-36260
|
Hikvision |
Security cameras web server |
Hikvision Improper Input Validation A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
|
2022-01-10
|
2022-01-24 |
Unknown
|
|
CVE-2021-22017
|
VMware |
vCenter Server |
VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
|
2022-01-10
|
2022-01-24 |
Unknown
|