|
CVE-2018-4344
|
Apple |
Multiple Products |
Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2019-8605
|
Apple |
Multiple Products |
Apple Multiple Products Use-After-Free Vulnerability A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2020-9907
|
Apple |
Multiple Products |
Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2020-3837
|
Apple |
Multiple Products |
Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2021-30983
|
Apple |
iOS and iPadOS |
Apple iOS and iPadOS Buffer Overflow Vulnerability Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2021-4034
|
Red Hat |
Polkit |
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
|
2022-06-27
|
2022-07-18 |
Known
|
|
CVE-2021-30533
|
Google |
Chromium PopupBlocker |
Google Chromium PopupBlocker Security Bypass Vulnerability Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-27
|
2022-07-18 |
Unknown
|
|
CVE-2022-29499
|
Mitel |
MiVoice Connect |
Mitel MiVoice Connect Data Validation Vulnerability The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
|
2022-06-27
|
2022-07-18 |
Known
|
|
CVE-2022-30190
|
Microsoft |
Windows |
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
|
2022-06-14
|
2022-07-05 |
Known
|
|
CVE-2016-2388
|
SAP |
NetWeaver |
SAP NetWeaver Information Disclosure Vulnerability The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
|
2022-06-09
|
2022-06-30 |
Unknown
|
|
CVE-2016-2386
|
SAP |
NetWeaver |
SAP NetWeaver SQL Injection Vulnerability SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2022-06-09
|
2022-06-30 |
Unknown
|
|
CVE-2021-38163
|
SAP |
NetWeaver |
SAP NetWeaver Unrestricted File Upload Vulnerability SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
|
2022-06-09
|
2022-06-30 |
Unknown
|
|
CVE-2006-2492
|
Microsoft |
Word |
Microsoft Word Malformed Object Pointer Vulnerability Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2007-5659
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2008-0655
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Unspecified Vulnerability Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2009-0557
|
Microsoft |
Office |
Microsoft Office Object Record Corruption Vulnerability Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2009-0563
|
Microsoft |
Office |
Microsoft Office Buffer Overflow Vulnerability Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2009-1862
|
Adobe |
Acrobat and Reader, Flash Player |
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2009-3953
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2009-4324
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2010-1297
|
Adobe |
Flash Player |
Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2010-2572
|
Microsoft |
PowerPoint |
Microsoft PowerPoint Buffer Overflow Vulnerability Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2010-2883
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2011-0609
|
Adobe |
Flash Player |
Adobe Flash Player Unspecified Vulnerability Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2011-2462
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-0151
|
Microsoft |
Windows |
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-0754
|
Adobe |
Flash Player |
Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-0767
|
Adobe |
Flash Player |
Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-1889
|
Microsoft |
XML Core Services |
Microsoft XML Core Services Memory Corruption Vulnerability Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-4969
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2012-5054
|
Adobe |
Flash Player |
Adobe Flash Player Integer Overflow Vulnerability Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2013-1331
|
Microsoft |
Office |
Microsoft Office Buffer Overflow Vulnerability Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2016-1646
|
Google |
Chromium V8 |
Google Chromium V8 Out-of-Bounds Read Vulnerability Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2016-5198
|
Google |
Chromium V8 |
Google Chromium V8 Out-of-Bounds Memory Vulnerability Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2017-5030
|
Google |
Chromium V8 |
Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2017-5070
|
Google |
Chromium V8 |
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2017-6862
|
NETGEAR |
Multiple Devices |
NETGEAR Multiple Devices Buffer Overflow Vulnerability Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2018-17463
|
Google |
Chromium V8 |
Google Chromium V8 Remote Code Execution Vulnerability Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2018-17480
|
Google |
Chromium V8 |
Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2018-4990
|
Adobe |
Acrobat and Reader |
Adobe Acrobat and Reader Double Free Vulnerability Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2018-6065
|
Google |
Chromium V8 |
Google Chromium V8 Integer Overflow Vulnerability Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2019-15271
|
Cisco |
RV Series Routers |
Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2019-5825
|
Google |
Chromium V8 |
Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-06-08
|
2022-06-22 |
Unknown
|
|
CVE-2019-7192
|
QNAP |
Photo Station |
QNAP Photo Station Improper Access Control Vulnerability QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
|
2022-06-08
|
2022-06-22 |
Known
|
|
CVE-2019-7193
|
QNAP |
QTS |
QNAP QTS Improper Input Validation Vulnerability QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
|
2022-06-08
|
2022-06-22 |
Known
|
|
CVE-2019-7194
|
QNAP |
Photo Station |
QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
|
2022-06-08
|
2022-06-22 |
Known
|
|
CVE-2019-7195
|
QNAP |
Photo Station |
QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
|
2022-06-08
|
2022-06-22 |
Known
|
|
CVE-2022-26134
|
Atlassian |
Confluence Server/Data Center |
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
|
2022-06-02
|
2022-06-06 |
Known
|
|
CVE-2010-0738
|
Red Hat |
JBoss |
Red Hat JBoss Authentication Bypass Vulnerability The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2010-0840
|
Oracle |
Java Runtime Environment (JRE) |
Oracle JRE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2010-1428
|
Red Hat |
JBoss |
Red Hat JBoss Information Disclosure Vulnerability Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2012-1710
|
Oracle |
Fusion Middleware |
Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2013-0074
|
Microsoft |
Silverlight |
Microsoft Silverlight Double Dereference Vulnerability Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2013-0422
|
Oracle |
Java Runtime Environment (JRE) |
Oracle JRE Remote Code Execution Vulnerability A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2013-0431
|
Oracle |
Java Runtime Environment (JRE) |
Oracle JRE Sandbox Bypass Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2013-2423
|
Oracle |
Java Runtime Environment (JRE) |
Oracle JRE Unspecified Vulnerability Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2013-3896
|
Microsoft |
Silverlight |
Microsoft Silverlight Information Disclosure Vulnerability Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2013-3993
|
IBM |
InfoSphere BigInsights |
IBM InfoSphere BigInsights Invalid Input Vulnerability Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2013-7331
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-3153
|
Linux |
Kernel |
Linux Kernel Privilege Escalation Vulnerability The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-4077
|
Microsoft |
Input Method Editor (IME) Japanese |
Microsoft IME Japanese Privilege Escalation Vulnerability Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-2817
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-0546
|
Adobe |
Reader and Acrobat |
Adobe Reader and Acrobat Sandbox Bypass Vulnerability Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-4123
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-8439
|
Adobe |
Flash Player |
Adobe Flash Player Dereferenced Pointer Vulnerability Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2014-4148
|
Microsoft |
Windows |
Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-1671
|
Microsoft |
Windows |
Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-6175
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-8651
|
Adobe |
Flash Player |
Adobe Flash Player Integer Overflow Vulnerability Integer overflow in Adobe Flash Player allows attackers to execute code.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-4495
|
Mozilla |
Firefox |
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-1769
|
Microsoft |
Windows |
Microsoft Windows Mount Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-2425
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-2360
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-0071
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer ASLR Bypass Vulnerability Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-0016
|
Microsoft |
Windows |
Microsoft Windows TS WebProxy Directory Traversal Vulnerability Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2015-0310
|
Adobe |
Flash Player |
Adobe Flash Player ASLR Bypass Vulnerability Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2016-0034
|
Microsoft |
Silverlight |
Microsoft Silverlight Runtime Remote Code Execution Vulnerability Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
|
2022-05-25
|
2022-06-15 |
Known
|
|
CVE-2016-0984
|
Adobe |
Flash Player and AIR |
Adobe Flash Player and AIR Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2016-1010
|
Adobe |
Flash Player and AIR |
Adobe Flash Player and AIR Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2016-7256
|
Microsoft |
Windows |
Microsoft Windows Open Type Font Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2016-3393
|
Microsoft |
Windows |
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2019-3010
|
Oracle |
Solaris |
Oracle Solaris Privilege Escalation Vulnerability Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
|
2022-05-25
|
2022-06-15 |
Unknown
|
|
CVE-2016-3298
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-6367
|
Cisco |
Adaptive Security Appliance (ASA) |
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-6366
|
Cisco |
Adaptive Security Appliance (ASA) |
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-4657
|
Apple |
iOS |
Apple iOS Webkit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-4656
|
Apple |
iOS |
Apple iOS Memory Corruption Vulnerability A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-4655
|
Apple |
iOS |
Apple iOS Information Disclosure Vulnerability The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2016-3351
|
Microsoft |
Internet Explorer and Edge |
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2016-0162
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-18362
|
Kaseya |
Virtual System/Server Administrator (VSA) |
Kaseya VSA SQL Injection Vulnerability ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2017-8543
|
Microsoft |
Windows |
Microsoft Windows Search Remote Code Execution Vulnerability Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-8291
|
Artifex |
Ghostscript |
Artifex Ghostscript Type Confusion Vulnerability Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-0210
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-0149
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-0005
|
Microsoft |
Windows |
Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-0022
|
Microsoft |
XML Core Services |
Microsoft XML Core Services Information Disclosure Vulnerability Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2017-0147
|
Microsoft |
SMBv1 server |
Microsoft Windows SMBv1 Information Disclosure Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2018-19943
|
QNAP |
Network Attached Storage (NAS) |
QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2018-19949
|
QNAP |
Network Attached Storage (NAS) |
QNAP NAS File Station Command Injection Vulnerability A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2018-19953
|
QNAP |
Network Attached Storage (NAS) |
QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
|
2022-05-24
|
2022-06-14 |
Known
|
|
CVE-2018-8611
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
|
2022-05-24
|
2022-06-14 |
Unknown
|
|
CVE-2018-8589
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2018-5002
|
Adobe |
Flash Player |
Adobe Flash Player Stack-based Buffer Overflow Vulnerability Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-1130
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
|
2022-05-23
|
2022-06-13 |
Known
|
|
CVE-2019-1385
|
Microsoft |
Windows |
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
|
2022-05-23
|
2022-06-13 |
Known
|
|
CVE-2019-18426
|
Meta Platforms |
WhatsApp |
WhatsApp Cross-Site Scripting Vulnerability A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-8720
|
WebKitGTK |
WebKitGTK |
WebKitGTK Memory Corruption Vulnerability WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-11708
|
Mozilla |
Firefox and Thunderbird |
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-11707
|
Mozilla |
Firefox and Thunderbird |
Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-13720
|
Google |
Chrome WebAudio |
Google Chrome WebAudio Use-After-Free Vulnerability Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-0880
|
Microsoft |
Windows |
Microsoft Windows Privilege Escalation Vulnerability A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-0703
|
Microsoft |
Windows |
Microsoft Windows SMB Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-5786
|
Google |
Chrome Blink |
Google Chrome Blink Use-After-Free Vulnerability Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-0676
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-7287
|
Apple |
iOS |
Apple iOS Memory Corruption Vulnerability Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2019-7286
|
Apple |
Multiple Products |
Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2020-0638
|
Microsoft |
Update Notification Manager |
Microsoft Update Notification Manager Privilege Escalation Vulnerability Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
|
2022-05-23
|
2022-06-13 |
Known
|
|
CVE-2020-1027
|
Microsoft |
Windows |
Microsoft Windows Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2021-30883
|
Apple |
Multiple Products |
Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2021-0920
|
Android |
Kernel |
Android Kernel Race Condition Vulnerability Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2021-1048
|
Android |
Kernel |
Android Kernel Use-After-Free Vulnerability Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2022-20821
|
Cisco |
IOS XR |
Cisco IOS XR Open Port Vulnerability Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.
|
2022-05-23
|
2022-06-13 |
Unknown
|
|
CVE-2022-22947
|
VMware |
Spring Cloud Gateway |
VMware Spring Cloud Gateway Code Injection Vulnerability Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
|
2022-05-16
|
2022-06-06 |
Unknown
|
|
CVE-2022-30525
|
Zyxel |
Multiple Firewalls |
Zyxel Multiple Firewalls OS Command Injection Vulnerability A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
|
2022-05-16
|
2022-06-06 |
Unknown
|
|
CVE-2022-1388
|
F5 |
BIG-IP |
F5 BIG-IP Missing Authentication Vulnerability F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
|
2022-05-10
|
2022-05-31 |
Known
|
|
CVE-2014-0160
|
OpenSSL |
OpenSSL |
OpenSSL Information Disclosure Vulnerability The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
|
2022-05-04
|
2022-05-25 |
Unknown
|
|
CVE-2014-0322
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
|
2022-05-04
|
2022-05-25 |
Unknown
|
|
CVE-2014-4113
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
|
2022-05-04
|
2022-05-25 |
Unknown
|
|
CVE-2019-8506
|
Apple |
Multiple Products |
Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
|
2022-05-04
|
2022-05-25 |
Unknown
|
|
CVE-2021-1789
|
Apple |
Multiple Products |
Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
|
2022-05-04
|
2022-05-25 |
Unknown
|
|
CVE-2019-1003029
|
Jenkins |
Script Security Plugin |
Jenkins Script Security Plugin Sandbox Bypass Vulnerability Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2021-40450
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2021-41357
|
Microsoft |
Win32k |
Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2022-0847
|
Linux |
Kernel |
Linux Kernel Privilege Escalation Vulnerability Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2022-21919
|
Microsoft |
Windows |
Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2022-26904
|
Microsoft |
Windows |
Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-25
|
2022-05-16 |
Unknown
|
|
CVE-2022-29464
|
WSO2 |
Multiple Products |
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
|
2022-04-25
|
2022-05-16 |
Known
|
|
CVE-2022-22718
|
Microsoft |
Windows |
Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
|
2022-04-19
|
2022-05-10 |
Unknown
|
|
CVE-2019-3568
|
Meta Platforms |
WhatsApp |
WhatsApp VOIP Stack Buffer Overflow Vulnerability A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
|
2022-04-19
|
2022-05-10 |
Unknown
|
|
CVE-2018-6882
|
Synacor |
Zimbra Collaboration Suite (ZCS) |
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
|
2022-04-19
|
2022-05-10 |
Known
|
|
CVE-2007-3010
|
Alcatel |
OmniPCX Enterprise |
Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2010-5330
|
Ubiquiti |
AirOS |
Ubiquiti AirOS Command Injection Vulnerability Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2014-0780
|
InduSoft |
Web Studio |
InduSoft Web Studio NTWebServer Directory Traversal Vulnerability InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2016-4523
|
Trihedral |
VTScada (formerly VTS) |
Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2018-7841
|
Schneider Electric |
U.motion Builder |
Schneider Electric U.motion Builder SQL Injection Vulnerability A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2019-16057
|
D-Link |
DNS-320 Storage Device |
D-Link DNS-320 Remote Code Execution Vulnerability The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
|
2022-04-15
|
2022-05-06 |
Known
|
|
CVE-2019-3929
|
Crestron |
Multiple Products |
Crestron Multiple Products Command Injection Vulnerability Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2022-1364
|
Google |
Chromium V8 |
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2022-22960
|
VMware |
Multiple Products |
VMware Multiple Products Privilege Escalation Vulnerability VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
|
2022-04-15
|
2022-05-06 |
Unknown
|
|
CVE-2022-22954
|
VMware |
Workspace ONE Access and Identity Manager |
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
|
2022-04-14
|
2022-05-05 |
Known
|
|
CVE-2014-9163
|
Adobe |
Flash Player |
Adobe Flash Player Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-0311
|
Adobe |
Flash Player |
Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-0313
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-2502
|
Microsoft |
Internet Explorer |
Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-3113
|
Adobe |
Flash Player |
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-5122
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2015-5123
|
Adobe |
Flash Player |
Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
|
2022-04-13
|
2022-05-04 |
Unknown
|
|
CVE-2018-20753
|
Kaseya |
Virtual System/Server Administrator (VSA) |
Kaseya VSA Remote Code Execution Vulnerability Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
|
2022-04-13
|
2022-05-04 |
Known
|
|
CVE-2018-7602
|
Drupal |
Core |
Drupal Core Remote Code Execution Vulnerability A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
|
2022-04-13
|
2022-05-04 |
Known
|
|
CVE-2022-24521
|
Microsoft |
Windows |
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-13
|
2022-05-04 |
Known
|
|
CVE-2017-11317
|
Telerik |
User Interface (UI) for ASP.NET AJAX |
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2020-2509
|
QNAP |
QNAP Network-Attached Storage (NAS) |
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2021-22600
|
Linux |
Kernel |
Linux Kernel Privilege Escalation Vulnerability Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2021-27852
|
Checkbox |
Checkbox Survey |
Checkbox Survey Deserialization of Untrusted Data Vulnerability Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2021-39793
|
Google |
Pixel |
Google Pixel Out-of-Bounds Write Vulnerability Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2021-42278
|
Microsoft |
Active Directory |
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-11
|
2022-05-02 |
Known
|
|
CVE-2021-42287
|
Microsoft |
Active Directory |
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
|
2022-04-11
|
2022-05-02 |
Known
|
|
CVE-2022-23176
|
WatchGuard |
Firebox and XTM |
WatchGuard Firebox and XTM Privilege Escalation Vulnerability WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
|
2022-04-11
|
2022-05-02 |
Unknown
|
|
CVE-2017-0148
|
Microsoft |
SMBv1 server |
Microsoft SMBv1 Server Remote Code Execution Vulnerability The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
|
2022-04-06
|
2022-04-27 |
Known
|
|
CVE-2021-31166
|
Microsoft |
HTTP Protocol Stack |
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
|
2022-04-06
|
2022-04-27 |
Unknown
|
|
CVE-2021-3156
|
Sudo |
Sudo |
Sudo Heap-Based Buffer Overflow Vulnerability Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
|
2022-04-06
|
2022-04-27 |
Unknown
|
|
CVE-2021-45382
|
D-Link |
Multiple Routers |
D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
|
2022-04-04
|
2022-04-25 |
Unknown
|
|
CVE-2022-22674
|
Apple |
macOS |
Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
|
2022-04-04
|
2022-04-25 |
Unknown
|
|
CVE-2022-22675
|
Apple |
macOS |
Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
|
2022-04-04
|
2022-04-25 |
Unknown
|
|
CVE-2022-22965
|
VMware |
Spring Framework |
Spring Framework JDK 9+ Remote Code Execution Vulnerability Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
|
2022-04-04
|
2022-04-25 |
Unknown
|