CISA Known Exploited Vulnerabilities
1549
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1530
Overdue

Showing 50 of 1549 KEV entries

View official CISA catalog

CVE-2019-0841

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0841

CVE-2019-1064

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Deployment Service handles hard links.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1064

CVE-2019-1069

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1069

CVE-2019-1129

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1129

CVE-2019-1132

7.8 ⚠️ OVERDUE

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1132

CVE-2019-1253

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1253

CVE-2019-1315

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1315

CVE-2019-1322

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1322

CVE-2019-1405

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1405

CVE-2020-5135

9.8 ⚠️ OVERDUE

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

sonicwall
Added to KEV
2022-03-15
Remediation Deadline
2022-04-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-5135

CVE-2009-3960

6.5 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

adobe
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-3960

CVE-2013-0625

9.8 ⚠️ OVERDUE

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

opengroup apple adobe +1
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0625

CVE-2013-0629

7.5 ⚠️ OVERDUE

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

opengroup apple adobe +1
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0629

CVE-2013-0631

7.5 ⚠️ OVERDUE

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.

opengroup apple adobe +1
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0631

CVE-2016-6277

8.8 ⚠️ OVERDUE

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

netgear
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-6277

CVE-2017-6077

9.8 ⚠️ OVERDUE

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

netgear
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-6077

CVE-2019-11581

9.8 ⚠️ OVERDUE

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

atlassian
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-11581

CVE-2020-8218

7.2 ⚠️ OVERDUE

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

ivanti pulsesecure
Added to KEV
2022-03-07
Remediation Deadline
2022-09-07

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-8218

CVE-2021-21973

5.3 ⚠️ OVERDUE

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

vmware
Added to KEV
2022-03-07
Remediation Deadline
2022-03-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21973

CVE-2022-26485

8.8 ⚠️ OVERDUE

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

mozilla
Added to KEV
2022-03-07
Remediation Deadline
2022-03-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-26485

CVE-2022-26486

9.6 ⚠️ OVERDUE

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

mozilla
Added to KEV
2022-03-07
Remediation Deadline
2022-03-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-26486

CVE-2002-0367

7.8 ⚠️ OVERDUE

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2002-0367

CVE-2004-0210

7.8 ⚠️ OVERDUE

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2004-0210

CVE-2008-3431

8.8 ⚠️ OVERDUE

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

oracle
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2008-3431

CVE-2008-2992

7.8 ⚠️ OVERDUE 💀 Ransomware

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

oracle adobe
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2008-2992

CVE-2009-1123

7.8 ⚠️ OVERDUE

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-1123

CVE-2009-3129

7.8 ⚠️ OVERDUE

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-3129

CVE-2010-0232

7.8 ⚠️ OVERDUE

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0232

CVE-2010-0188

7.8 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

adobe
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0188

CVE-2010-3333

7.8 ⚠️ OVERDUE

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3333

CVE-2011-0611

8.8 ⚠️ OVERDUE

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

linux oracle apple +5
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-0611

CVE-2011-1889

9.8 ⚠️ OVERDUE

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-1889

CVE-2011-3544

9.8 ⚠️ OVERDUE

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

suse oracle canonical +1
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-3544

CVE-2012-0507

9.8 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

debian oracle sun +1
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0507

CVE-2012-1723

9.8 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

oracle redhat
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1723

CVE-2012-1856

8.8 ⚠️ OVERDUE

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1856

CVE-2012-1535

7.8 ⚠️ OVERDUE

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.

linux apple opensuse +4
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1535

CVE-2012-4681

9.8 ⚠️ OVERDUE 💀 Ransomware

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

oracle redhat
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-4681

CVE-2013-0632

9.8 ⚠️ OVERDUE

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

adobe
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0632

CVE-2013-0640

7.8 ⚠️ OVERDUE

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

linux apple opensuse +4
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0640

CVE-2013-0641

7.8 ⚠️ OVERDUE

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.

linux apple opensuse +4
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-0641

CVE-2013-1347

8.8 ⚠️ OVERDUE

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-1347

CVE-2013-1675

6.5 ⚠️ OVERDUE

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

canonical opensuse redhat +2
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-1675

CVE-2013-3346

9.8 ⚠️ OVERDUE

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

adobe
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3346

CVE-2013-3897

8.8 ⚠️ OVERDUE

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3897

CVE-2013-5065

7.8 ⚠️ OVERDUE

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-5065

CVE-2014-0496

8.8 ⚠️ OVERDUE

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

apple adobe microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0496

CVE-2014-4114

7.8 ⚠️ OVERDUE

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-4114

CVE-2015-3043

9.8 ⚠️ OVERDUE

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

novell apple redhat +4
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-3043

CVE-2015-1701

7.8 ⚠️ OVERDUE 💀 Ransomware

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

microsoft
Added to KEV
2022-03-03
Remediation Deadline
2022-03-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1701