Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-399 · Resource managementDefinition on MITRE ↗Clear

18 results

CVE-2010-0806
2026-05-20
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-399 · Resource management
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2026-06-03
CVE-2013-3893
2025-08-12
Microsoft Internet Explorer Resource Management Errors Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-399 · Resource management
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2025-09-02
CVE-2014-0502
2024-09-17
Adobe Flash Player Double Free Vulnerablity
Adobe

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

CWE-399 · Resource management
Refsadobe.comnvd.nist.gov
Federal remediation due 2024-10-08
CVE-2009-4324
2022-06-08
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-2539
2022-03-28
Microsoft Word Remote Code Execution Vulnerability
Microsoft

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2018-0180
2022-03-03
Cisco IOS Software Denial-of-Service Vulnerability
Cisco

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0179
2022-03-03
Cisco IOS Software Denial-of-Service Vulnerability
Cisco

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0161
2022-03-03
Cisco IOS Software Resource Management Errors Vulnerability
Cisco

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0156
2022-03-03
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Cisco

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0154
2022-03-03
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
Cisco

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2017-6627
2022-03-03
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
Cisco / IOS and IOS XE Software

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12238
2022-03-03
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Cisco

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12237
2022-03-03
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
Cisco

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12232
2022-03-03
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
Cisco

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12231
2022-03-03
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
Cisco

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2014-0496
2022-03-03
Adobe Reader and Acrobat Use-After-Free Vulnerability
Adobe

Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2013-3897
2022-03-03
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2015-1641
2021-11-03
Microsoft Office Memory Corruption Vulnerability
Microsoft

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-05-03