Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Mass Scam Email Impersonating HKCERT Distributing Malware

HKCERT received an incident report related to a scam email on 25 Jan 2013. The scam email impersonated as HKCERT alert email sent to the public about an extremely critical vulnerability. The sender address of the scam email is "[email protected]", with the...
Last Update Date: 25 Jan 2013 20:00 Release Date: 25 Jan 2013 6672 Views

RISK: Medium Risk

Medium Risk

Barracuda Products SSH backdoor vulnerability

A vulnerability has identified in multiple Barracuda products. A remote user can gain access to the target system.The system includes several undocumented SSH user accounts that cannot be disabled and can be accessed from certain whitelisted IP ranges. At least one account can be exploited to...
Last Update Date: 25 Jan 2013 12:33 Release Date: 25 Jan 2013 6770 Views

RISK: High Risk

High Risk

Cisco Wireless LAN Controller Multipule Vulnerabilities

Multiple vulnerabilities were identified in Cisco Wireless LAN Controller. A remote authenticated user can execute arbitrary code and modify the configuration on the target system, and cause denial of service conditions.A remote user can send specially crafted IP packets to the target device configured with Wireless...
Last Update Date: 24 Jan 2013 12:17 Release Date: 24 Jan 2013 6816 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. A use-after-free error exists when handling canvas font. An error exists when validating the URL when opening new windows. An...
Last Update Date: 24 Jan 2013 12:12 Release Date: 24 Jan 2013 6774 Views

RISK: High Risk

High Risk

Schneider Electric Interactive Graphical SCADA System (IGSS) Buffer Overflow Vulnerability

A vulnerability has been identified in Schneider Electric IGSS application, which can be exploited by malicious people to execute code under administrator credentials on the target system.
Last Update Date: 23 Jan 2013 12:10 Release Date: 23 Jan 2013 6768 Views

RISK: High Risk

High Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remote attackers to cause denial of service, cross site scripting or compromise a vulnerable system.
Last Update Date: 23 Jan 2013 12:01 Release Date: 23 Jan 2013 6571 Views

RISK: High Risk

High Risk

F5 BIG-IP Input Validation Flaws Multiple Vulnerabilities

A vulnerability has been identified in F5 BIG-IP, which can be exploited by malicious people to inject SQL commands or allow an authenticated attacker to download arbitrary files from the file system on the target system.   A remote authenticated user can supply a specially crafted XML...
Last Update Date: 23 Jan 2013 11:56 Release Date: 23 Jan 2013 6694 Views

RISK: High Risk

High Risk

Lenovo ThinkPad Bluetooth with Enhanced Data Rate Software Insecure Library Loading Vulnerability

A vulnerability has been identified in Lenovo Bluetooth with Enhanced Data Rate Software, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load...
Last Update Date: 23 Jan 2013 11:45 Release Date: 23 Jan 2013 6792 Views

RISK: Medium Risk

Medium Risk

SonicWALL Products Two Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in various SonicWALL products, which can be exploited by malicious people to bypass certain security restrictions.An error when handling request for changing users password can be exploited to change the administrator's password.An error within the authentication mechanism in...
Last Update Date: 21 Jan 2013 15:24 Release Date: 21 Jan 2013 6766 Views

RISK: High Risk

High Risk

Foxit Reader Plugin For Browsers URL Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to a boundary error in the Foxit Reader plugin for browsers (npFoxitReaderPlugin.dll) when processing a URL and...
Last Update Date: 18 Jan 2013 Release Date: 9 Jan 2013 7381 Views