CISA's list that day
3 March 2022
On CISA added 95 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Adobe Acrobat and Reader, Oracle VirtualBox and 33 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2008-2992Reader and Acrobat Input Validation | Adobe Acrobat and Reader | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| CVE-2009-3129Featheader Record Memory Corruption | Microsoft Excel | Patch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| CVE-2010-0188Arbitrary Code Execution | Adobe Reader and Acrobat | Patch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| CVE-2010-3333Stack-based Buffer Overflow | Microsoft Office | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| CVE-2011-0611Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2011-3544Java SE Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE JDK and JRE | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| CVE-2012-0507Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| CVE-2012-1535Arbitrary Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| CVE-2012-1723Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| CVE-2012-4681Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2013-0632Authentication Bypass | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| CVE-2013-1347Remote Code Execution | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry | 0.78 | ||
| CVE-2013-3346Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| CVE-2013-3897Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| CVE-2014-4114Object Linking & Embedding (OLE) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| CVE-2015-1701Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| CVE-2015-3043Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| CVE-2015-5119Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2016-4117Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| CVE-2019-1652Small Business Routers Improper Input Validation | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| CVE-2020-1938Improper Privilege Management | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2010-0232Kernel Exception Handler | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.29 | ||
| CVE-2013-5065Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.35 | ||
| CVE-2016-0099Secondary Logon Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.37 | ||
| CVE-2022-20699Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch this weekMetasploit module; EPSS 0.72 | 0.72 | ||
| CVE-2013-0640Memory Corruption | Adobe Reader and Acrobat | Patch this weekEPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2015-7645Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry | 0.65 | ||
| CVE-2016-5195Race Condition | Linux Kernel | Patch this weekEPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| CVE-2017-8540Improper Restriction of Operations | Microsoft Malware Protection Engine | Patch this weekEPSS 0.72; verified Exploit-DB entry | 0.72 | ||
| CVE-2018-8298Type Confusion | ChakraCore ChakraCore scripting engine | Patch this weekEPSS 0.75; verified Exploit-DB entry | 0.75 | ||
| CVE-2012-1856MSCOMCTL.OCX Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.72 | 0.72 | ||
| CVE-2015-2545Malformed EPS File | Microsoft Office | Patch this weekEPSS 0.86 | 0.86 | ||
| CVE-2016-7193Memory Corruption | Microsoft Office | Patch this weekEPSS 0.58 | 0.58 | ||
| CVE-2016-7262Office Security Feature Bypass | Microsoft Excel | Patch this weekEPSS 0.58 | 0.58 | ||
| CVE-2017-0261Use-After-Free | Microsoft Office | Patch this weekEPSS 0.78 | 0.78 | ||
| CVE-2017-6736SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch this weekEPSS 0.70 | 0.70 | ||
| CVE-2017-11826Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.81 | 0.81 | ||
| CVE-2015-1642Memory Corruption | Microsoft Office | Patch this weekEPSS 0.53 | 0.53 | ||
| CVE-2018-8581Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use | 0.27 | ||
| CVE-2016-1019Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use | 0.22 | ||
| CVE-2021-41379Installer Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.19 | ||
| CVE-2004-0210Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.07 | ||
| CVE-2008-3431Insufficient Input Validation | Oracle VirtualBox | Patch soonVerified Exploit-DB entry | 0.07 | ||
| CVE-2002-0367Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.05 | ||
| CVE-2011-1889Forefront TMG Remote Code Execution | Microsoft Forefront Threat Management Gateway (TMG) | Patch soon | 0.49 | ||
| CVE-2013-0641Buffer Overflow | Adobe Reader | Patch soon | 0.32 | ||
| CVE-2014-0496Use-After-Free | Adobe Reader and Acrobat | Patch soon | 0.40 | ||
| CVE-2015-2387Privilege Escalation | Microsoft ATM Font Driver | Patch soon | 0.35 | ||
| CVE-2015-2424Memory Corruption | Microsoft PowerPoint | Patch soon | 0.40 | ||
| CVE-2017-6737SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.45 | ||
| CVE-2019-16928Out-of-bounds Write | Exim Exim Internet Mailer | Patch soon | 0.42 | ||
| CVE-2015-2590and Java SE Embedded Remote Code Execution | Oracle Java SE | Patch soon | 0.25 | ||
| CVE-2016-7855Use-After-Free | Adobe Flash Player | Patch soon | 0.25 | ||
| CVE-2019-1297Remote Code Execution | Microsoft Excel | Patch soon | 0.22 | ||
| CVE-2020-11899Out-of-Bounds Read | Treck TCP/IP stack IPv6 | Patch soon | 0.18 | ||
| CVE-2015-4902Integrity Check | Oracle Java SE | Patch soon | 0.14 | ||
| CVE-2017-12240DHCP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| CVE-2018-0151IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| CVE-2022-20708Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.15 | ||
| CVE-2017-6738SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| CVE-2017-6739SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| CVE-2017-6740SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| CVE-2017-6743SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| CVE-2017-11292Type Confusion | Adobe Flash Player | Patch soon | 0.12 | ||
| CVE-2018-0156Smart Install Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.09 | ||
| CVE-2022-20701Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.10 | ||
| CVE-2022-20703Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.09 | ||
| CVE-2017-6744SNMP Remote Code Execution | Cisco IOS software | Patch soon | 0.07 | ||
| CVE-2017-12231Network Address Translation Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| CVE-2017-12233Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| CVE-2017-12234Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| CVE-2017-12235for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| CVE-2017-12237Internet Key Exchange Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.07 | ||
| CVE-2018-0154Integrated Services Module for VPN Denial-of-Service | Cisco IOS Software | Patch soon | 0.07 | ||
| CVE-2018-0155Catalyst Bidirectional Forwarding Detection Denial-of-Service | Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Patch soon | 0.08 | ||
| CVE-2018-0158IOS and XE Software Internet Key Exchange Memory Leak | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| CVE-2018-0172Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| CVE-2018-0173Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| CVE-2018-0174IOS Software and Cisco IOS XE Software Improper Input Validation | Cisco IOS XE Software | Patch soon | 0.08 | ||
| CVE-2013-1675Information Disclosure | Mozilla Firefox | Patch soon | 0.07 | ||
| CVE-2017-6627IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.06 | ||
| CVE-2018-0159IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| CVE-2017-12319Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service | Cisco IOS XE Software | Patch soon | 0.05 | ||
| CVE-2022-20700Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.06 | ||
| CVE-2009-1123Improper Input Validation | Microsoft Windows | Patch soon | 0.05 | ||
| CVE-2018-0179Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| CVE-2018-0180Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| CVE-2018-0161Resource Management Errors | Cisco IOS Software | Patch soon | 0.04 | ||
| CVE-2016-85621543-1 Improper Privilege Management | Siemens SIMATIC CP | Patch soon | 0.04 | ||
| CVE-2018-0167Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| CVE-2018-0175Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| CVE-2017-0001Privilege Escalation | Microsoft Graphics Device Interface (GDI) | Patch soon | 0.03 | ||
| CVE-2017-6663IOS Software and Cisco IOS XE Software Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.02 | ||
| CVE-2017-12232for Cisco Integrated Services Routers Denial-of-Service | Cisco IOS software | Patch soon | 0.02 | ||
| CVE-2017-12238VPLS Denial-of-Service | Cisco Catalyst 6800 Series Switches | Patch soon | 0.02 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.