CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2013-5065

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2013-3897

Microsoft Internet Explorer Use-After-Free Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2013-3346

Adobe Reader and Acrobat Memory Corruption Vulnerability

Vendor: Adobe

Product: Reader and Acrobat

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2013-1675

Mozilla Firefox Information Disclosure Vulnerability

Vendor: Mozilla

Product: Firefox

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2013-1347

Microsoft Internet Explorer Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-03-03

Due Date: 2022-03-24

Description:

This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2013-0641

Adobe Reader Buffer Overflow Vulnerability

Vendor: Adobe

Product: Reader

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-120

CVE-2013-0640

Adobe Reader and Acrobat Memory Corruption Vulnerability

Vendor: Adobe

Product: Reader and Acrobat

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2013-0632

Adobe ColdFusion Authentication Bypass Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2012-4681

Ransomware

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2012-1856

Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2012-1723

Ransomware

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

Required Action:

Apply updates per vendor instructions.

CVE-2012-1535

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-0507

Ransomware

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CVE-2011-3544

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE JDK and JRE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CVE-2011-1889

Microsoft Forefront TMG Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Forefront Threat Management Gateway (TMG)

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119