Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

HP, H3C and 3COM Products OSPF Vulnerability

A vulnerability has been identified in various HP networking products including H3C and 3COM routers and switches which can be exploited by a remote unauthenticated user to cause denial of service conditions or obtain potentially sensitive information.  A remote authenticated user can send specially crafted Open Shortest Path First...
Last Update Date: 9 Aug 2013 12:06 Release Date: 9 Aug 2013 6285 Views

RISK: Medium Risk

Medium Risk

HP LaserJet Pro Printers Unauthorised Access Vulnerability

A vulnerability has been identified in certain HP LaserJet Pro printers, which could be exploited remotely to gain unauthorized access to data.
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6378 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, Seamonkey, and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, cause denial of service conditions, and conduct cross-site scripting attacks. A local user can obtain...
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6337 Views

RISK: Medium Risk

Medium Risk

ownCloud Cross-Site Scripting and Security Bypass Vulnerabilities

Two vulnerabilities have been identified in ownCloud, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions. An error within "user_webdavauth" can be exploited to bypass authorisation and gain access to otherwise restricted functionality. Certain unspecified...
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6099 Views

RISK: Medium Risk

Medium Risk

Tor Browser Bundle "onreadystatechange" Event Handling Code Execution Vulnerability

A vulnerability has been identified in Tor Browser Bundle, which can be exploited by malicious people to compromise a user's system. An error exists when handling the "onreadystatechange" event and reloading pages.
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6273 Views

RISK: High Risk

High Risk

Cisco TelePresence System Default Credentials Vulnerability

A vulnerability has been identified in Cisco TelePresence. A remote user can gain full control of the target system.   The web server contains an administrative user account with default credentials. A remote user can access the system using these authentication credentials.   Note: Vendor patch is...
Last Update Date: 8 Aug 2013 10:02 Release Date: 8 Aug 2013 6159 Views

RISK: Medium Risk

Medium Risk

PuTTY Multiple Vulnerabilities

 Vulnerabilities has been identified in PuTTY, which can be exploited by malicious people to potentially compromise a user's system. The vulnerabilities are caused due to some integer overflow errors when handling the SSH handshake and can be exploited to cause heap-based buffer overflows...
Last Update Date: 6 Aug 2013 10:26 Release Date: 6 Aug 2013 6316 Views

RISK: Medium Risk

Medium Risk

Joomla! Arbitrary File Upload Vulnerability

A vulnerability has been identified in Joomla!, which can be exploited by malicious users to compromise a vulnerable system.The vulnerability is caused due to the administrator/components/com_media/helpers/media.php script improperly validating the extension of an uploaded file. This...
Last Update Date: 5 Aug 2013 11:44 Release Date: 5 Aug 2013 7067 Views

RISK: Medium Risk

Medium Risk

Windows Phone PEAP-MS-CHAPv2 Authentication Protocol Vulnerability

A vulnerability has been identified in the PEAP-MS-CHAPv2 authentication protocol used by Windows Phone, which can be exploited by remote user can obtain authentication information.The Protected Extensible Authentication Protocol with Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAPv2...
Last Update Date: 5 Aug 2013 11:32 Release Date: 5 Aug 2013 6628 Views

RISK: Medium Risk

Medium Risk

VMware ESX/ESXi Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX/ESXi Server, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).
Last Update Date: 2 Aug 2013 18:51 Release Date: 2 Aug 2013 6272 Views