Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

FreeRADIUS Remote Users Bypass Authentication Vulnerability

A vulnerability was identified in FreeRADIUS, a remote user can bypass authentication on the target system.
Last Update Date: 31 May 2017 10:43 Release Date: 31 May 2017 6291 Views

RISK: Medium Risk

Medium Risk

Trend Micro InterScan Web Security Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Trend Micro InterScan Web Security, a remote user can conduct XML external entity attacks or execute arbitrary commands on the target system.
Last Update Date: 31 May 2017 10:41 Release Date: 31 May 2017 6155 Views

RISK: Extremely High Risk

Extremely High Risk

Windows NTFS Denial of Service Vulnerability

A vulnerability was identified in Windows NTFS. A remote user can cause the target system to crash. NOTE: There is no patch available for this vulnerability.
Last Update Date: 29 May 2017 09:34 Release Date: 29 May 2017 8090 Views

RISK: Medium Risk

Medium Risk

Microsoft Malware Protection Engine Multiple Vulnerabilities

Multiple vulnerabilities were identified in Microsoft Malware Protection Engine. A remote user can cause arbitrary code to be executed on the target system. A local user can cause denial of service conditions on the target system.
Last Update Date: 29 May 2017 09:13 Release Date: 29 May 2017 6619 Views

RISK: Medium Risk

Medium Risk

Samba Remote Code Execution Vulnerability

A vulnerability was identified in Samba. A remote authenticated user can execute arbitrary code on the target system.
Last Update Date: 25 May 2017 09:56 Release Date: 25 May 2017 7408 Views

RISK: Medium Risk

Medium Risk

VMware Workstation Pro/Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware Workstation Pro/Player, a local user on the host system can cause denial of service and obtain root privileges on the host system.
Last Update Date: 22 May 2017 10:36 Release Date: 22 May 2017 6500 Views

RISK: Medium Risk

Medium Risk

Joomla SQL Injection Vulnerability

A vulnerability was identified in Joomla, which may lead to SQL injection.
Last Update Date: 18 May 2017 09:59 Release Date: 18 May 2017 6670 Views

RISK: Medium Risk

Medium Risk

Microsoft Monthly Security Update (May 2017)

Microsoft has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Browser Highly Critical Elevation of Privilege Remote Code Execution Security Restriction Bypass Spoofing Exploited Disclosed CVE-2017...
Last Update Date: 18 May 2017 Release Date: 10 May 2017 7304 Views

RISK: Medium Risk

Medium Risk

Apple Products Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in Apple Products, a remote user can exploit these vulnerabilities to perform remote code execution, disclose sensitive information, obtain elevated privileges, bypass security restriction and cause denial of service condition in the targeted system.
Last Update Date: 16 May 2017 10:07 Release Date: 16 May 2017 7117 Views

RISK: Medium Risk

Medium Risk

PostgreSQL Multiple Vulnerabilities

Multiple vulnerabilities were identified in PostgreSQL, which could remote allow an attacker to bypass security restriction and disclose sensitive information on the targeted system.
Last Update Date: 15 May 2017 10:44 Release Date: 15 May 2017 6891 Views

RISK: Extremely High Risk

Extremely High Risk

WannaCry (WannaCrypt) Ransomware Encrypts Victim Data

A new variant of ransomware known as WannaCry (WannaCrypt) is spreading quickly, through a Windows SMB vulnerability (EternalBlue and DoublePulsar). HKCERT was aware that there is a widespread overseas.   Note: The vulnerability is being exploited to spread the ransomware attack.   Impacts: ...
Last Update Date: 15 May 2017 Release Date: 13 May 2017 26750 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM SDK Java Technology Edition and Administrative Console of IBM WebSphere Application Server, which could lead to remote code execution, information disclosure, denial of service and data tampering.
Last Update Date: 12 May 2017 Release Date: 11 May 2017 7108 Views

RISK: Medium Risk

Medium Risk

Cisco Webex Meetings Server Information Disclosure Vulnerability

A vulnerability was identified in Cisco WebEx Meetings Server. A remote user can obtain sensitive meeting information on the target system.
Last Update Date: 11 May 2017 10:00 Release Date: 11 May 2017 6523 Views

RISK: Extremely High Risk

Extremely High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco products, a remote attacker can exploit these vulnerabilities to perform remote code execution, denial of service and elevation of privilege on the targeted system.
Last Update Date: 10 May 2017 Release Date: 21 Mar 2017 7277 Views

RISK: Medium Risk

Medium Risk

Adobe Monthly Security Update (May 2017)

Adobe has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Flash Player Moderately Critical Remote Code Execution   APSB17-15 Experience Manager Moderately Critical Information Disclosure   APSB17-16...
Last Update Date: 10 May 2017 09:42 Release Date: 10 May 2017 6604 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Denial Of Service Vulnerability

A vulnerability was identified in Mozilla Firefox, a remote user can exploit this vulnerability to perform remote code execution and cause denial of service condition on the targeted system.
Last Update Date: 9 May 2017 09:45 Release Date: 9 May 2017 6326 Views

RISK: Medium Risk

Medium Risk

Microsoft Remote Code Execution Vulnerability

A vulnerability was identified in Microsoft Malware Protection Engine, a remote user can exploit this vulnerability to perform remote code execution on the targeted system.
Last Update Date: 9 May 2017 09:45 Release Date: 9 May 2017 6413 Views

RISK: Medium Risk

Medium Risk

Hikvision IP Cameras Vulnerability

A vulnerability has been identified in Hikvision IP Cameras, which can be exploited by remote attacker to bypass authentication on the target system.
Last Update Date: 8 May 2017 10:55 Release Date: 8 May 2017 7781 Views

RISK: Medium Risk

Medium Risk

Dahua Digital Video Recorders and IP Cameras Vulnerability

A vulnerability has been identified in Dahua Digital Video Recorders and IP Cameras, which can be exploited by remote attacker to bypass authentication on the target system.
Last Update Date: 8 May 2017 10:46 Release Date: 8 May 2017 6245 Views

RISK: High Risk

High Risk

QNAP QTS Remote Code Execution Vulnerability

A vulnerability has been identified in QNAP Storage Devices running QTS, which can be exploited by remote attacker to execute arbitrary code or injected with XMR mining programs on the target system.
Last Update Date: 8 May 2017 10:34 Release Date: 8 May 2017 6318 Views

RISK: Medium Risk

Medium Risk

Intel AMT Escalation of Privilege Vulnerability

A vulnerability has been identified in Intel Active Management Technology (AMT), which can be exploited by remote attacker to conduct elevation of privilege on the target system.
Last Update Date: 5 May 2017 09:26 Release Date: 5 May 2017 6457 Views

RISK: Medium Risk

Medium Risk

Google Chrome Denial Of Service Vulnerability

A vulnerability was identified in Google Chrome, a remote user can exploit this vulnerability to cause a denial-of-service condition on the targeted system.
Last Update Date: 4 May 2017 09:36 Release Date: 4 May 2017 6166 Views

RISK: Medium Risk

Medium Risk

Trend Micro OfficeScan Multiple Vulnerabilities

Multiple vulnerabilities were identified in Trend Micro OfficeScan, which could allow an attacker to bypass security restriction and disclose sensitive information on the targeted system.
Last Update Date: 27 Apr 2017 10:19 Release Date: 27 Apr 2017 6235 Views

RISK: Medium Risk

Medium Risk

Linksys Router Multiple Vulnerabilities

Multiple vulnerabilities were identified in Linksys Router, which could allow an attacker to bypass security restriction, disclose sensitive information, elevate of privilege and cause a denial-of-service condition on the targeted system.
Last Update Date: 24 Apr 2017 10:13 Release Date: 24 Apr 2017 7117 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which could allow an attacker to take control of an affected system.
Last Update Date: 20 Apr 2017 11:56 Release Date: 20 Apr 2017 6232 Views

RISK: Medium Risk

Medium Risk

Cisco IOS and IOS XE Denial of Service Vulnerabilities

Multiple vulnerabilities were identified in Cisco IOS and IOS XE, which could could allow an unauthenticated, remote attacker to cause a denial of service condition.
Last Update Date: 20 Apr 2017 11:56 Release Date: 20 Apr 2017 6155 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, which allow an attacker to take control of an affected system. 
Last Update Date: 20 Apr 2017 11:55 Release Date: 20 Apr 2017 6163 Views

RISK: Medium Risk

Medium Risk

Oracle Security Update (Apr 2017)

Oracle has released Apr 2017 security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Database Moderately Critical Remote Code Execution Elevation of Privilege Denial of Service   DB (2017-04) Java SE...
Last Update Date: 19 Apr 2017 09:05 Release Date: 19 Apr 2017 6554 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Products, a remote attacker can exploit these vulnerabilities to perform remote code execution on the targeted system. Note: No patch is available for these vulnerabilities as these products have been end of life.HKCERT recommended user to upgrade end...
Last Update Date: 18 Apr 2017 10:52 Release Date: 18 Apr 2017 6846 Views

RISK: Medium Risk

Medium Risk

Juniper Junos Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in Juniper Junos, a remote attacker can exploit these vulnerabilities to perform spoofing, bypass security restriction, disclose sensitive information, elevate of privilege and perform deny of service on the targeted system.
Last Update Date: 18 Apr 2017 10:07 Release Date: 18 Apr 2017 6157 Views

RISK: Medium Risk

Medium Risk

VMware vCenter Remote Code Execution Vulnerability

A vulnerability has been identified in VMware vCenter, a remote attacker can exploit this vulnerability to perform remote code execution on the targeted system.
Last Update Date: 18 Apr 2017 09:55 Release Date: 18 Apr 2017 6203 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND, a remote attacker can exploit these vulnerabilities to cause a denial-of-service condition on the targeted system.
Last Update Date: 18 Apr 2017 09:53 Release Date: 18 Apr 2017 6185 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Monthly Security Update (Apr 2017)

Microsoft has released monthly security update for their products. NOTE: CVE-2017-0199 and CVE-2017-0210 are being actively exploited in the wild.  NOTE: CVE-2017-2605 and CVE-2017-0203 are reported being used in scattered...
Last Update Date: 13 Apr 2017 Release Date: 12 Apr 2017 6709 Views

RISK: Medium Risk

Medium Risk

Adobe Monthly Security Update (Apr 2017)

Adobe has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Adobe Campaign Moderately Critical Information Disclosure   APSB17-09 Flash Player Moderately Critical Remote Code Execution   APSB17-10...
Last Update Date: 13 Apr 2017 Release Date: 12 Apr 2017 6255 Views

RISK: Medium Risk

Medium Risk

Mozilla Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Thunderbird, which may lead to arbitrary code execution, denial of service, information disclosure and spoofing.
Last Update Date: 12 Apr 2017 10:36 Release Date: 12 Apr 2017 6167 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apache Tomcat. A remote user can obtain potentially sensitive information, access and modify data and consume excessive resources on the target system.
Last Update Date: 12 Apr 2017 10:36 Release Date: 12 Apr 2017 6415 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Office Remote Code Execution Vulnerability

A vulnerability was identified in Microsoft Office, a remote user can exploit this vulnerability to perform remote code execution on the targeted system.   Note: The vulnerability is being exploited in the wild. No patch is currently available.
Last Update Date: 11 Apr 2017 09:04 Release Date: 11 Apr 2017 7242 Views

RISK: Medium Risk

Medium Risk

Google Android Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Android. A remote user can execute  arbitrary code, cause denial of service conditions, obtain potentially sensitive information and gain elevated privileges on the target system.
Last Update Date: 10 Apr 2017 10:01 Release Date: 10 Apr 2017 6422 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS XR. A remote user can cause the target service to crash.
Last Update Date: 6 Apr 2017 09:33 Release Date: 6 Apr 2017 6208 Views

RISK: Medium Risk

Medium Risk

Apple Music for Android Information Disclosure Vulnerability

A vulnerability was identified in Apple Music for Android, which may lead to sensitive user information leakage.
Last Update Date: 6 Apr 2017 09:33 Release Date: 6 Apr 2017 6075 Views

RISK: Medium Risk

Medium Risk

Apple iOS Remote Code Execution Vulnerability

A vulnerability was identified in Apple iOS. A remote user within WiFi range can execute arbitrary code on the target system.
Last Update Date: 5 Apr 2017 09:03 Release Date: 5 Apr 2017 6176 Views

RISK: High Risk

High Risk

Windows Server 2003 IIS6.0 remote code execution Vulnerability

A vulnerability was identified in Windows Server 2003 IIS6., exploit of this vulnerability can allow remote code execution in the targeted system. Note: No patch is available for this vulnerability as Windows Server 2003 has been end of life On July 14, 2015.HKCERT...
Last Update Date: 3 Apr 2017 Release Date: 31 Mar 2017 7494 Views

RISK: Medium Risk

Medium Risk

Splunk Enterprise Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Splunk Enterprise, which can be exploited by remote attackers to obtain potentially sensitive information or conduct cross-site scripting attacks on the target system.
Last Update Date: 3 Apr 2017 10:41 Release Date: 3 Apr 2017 6255 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin Security Restriction Bypass Vulnerability

A Vulnerability was identified in phpMyAdmin, exploit of this Vulnerability can  bypass Security Restriction in the targeted system.
Last Update Date: 31 Mar 2017 09:59 Release Date: 31 Mar 2017 6794 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, a remote user can exploit these vulnerabilities to perform remote code execution on the targeted system.
Last Update Date: 31 Mar 2017 09:59 Release Date: 31 Mar 2017 6066 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in VMware ESXi server, Workstation and Fusion. An attacker could cause remote code execution, denial of service and information leakage on the target system.
Last Update Date: 30 Mar 2017 14:36 Release Date: 30 Mar 2017 6269 Views

RISK: Medium Risk

Medium Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple products, which can be exploited by remote attackers to conduct denial of service, elevation of privilege, sensitive information disclosure and remote code execution.
Last Update Date: 30 Mar 2017 Release Date: 28 Mar 2017 6659 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple iTunes, which could allow a remote attacker to denial of service, elevation of privilege , obtain potentially sensitive information or execute arbitrary code on the target system.
Last Update Date: 30 Mar 2017 Release Date: 24 Mar 2017 6050 Views

RISK: Medium Risk

Medium Risk

NTP Multiple Vulnerabilities

Multiple vulnerabilities were identified in NTP, which could cause the target service to crash.
Last Update Date: 27 Mar 2017 14:52 Release Date: 27 Mar 2017 6175 Views

RISK: Medium Risk

Medium Risk

Samba Information Disclosure Vulnerability

A vulnerability was identified in Samba. A remote authenticated user can obtain files on the target system.
Last Update Date: 27 Mar 2017 14:51 Release Date: 27 Mar 2017 6128 Views

RISK: High Risk

High Risk

SAP GUI for Windows Remote Code Execution Vulnerability

A vulnerability was identified in SAP GUI for Windows, which may allow an attacker to execute code on the user operating system.
Last Update Date: 24 Mar 2017 10:12 Release Date: 24 Mar 2017 6406 Views

RISK: Medium Risk

Medium Risk

QNAP Storage Devices Multiple Vulnerabilities

Multiple vulnerabilities were identified in QNAP Storage Devices, which could allow a remote attacker to  conduct click-jacking attacks, obtain potentially sensitive information, inject SQL commands, conduct cross-site scripting or execute arbitrary code on the target system.
Last Update Date: 23 Mar 2017 10:23 Release Date: 23 Mar 2017 6133 Views

RISK: Medium Risk

Medium Risk

OpenSSH Multiple Vulnerabilities

Two vulnerabilities were identified in OpenSSH. A remote authenticated user can modify files on the target system. A remote user may be able to decrypt messages in certain cases.
Last Update Date: 22 Mar 2017 09:54 Release Date: 22 Mar 2017 6174 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Remote Code Execution Vulnerability

A vulnerability was identified in Mozilla Firefox and Firefox ESR, which may allow a remote attacker to execute code on the target user's system.
Last Update Date: 20 Mar 2017 09:14 Release Date: 20 Mar 2017 6286 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple Vulnerabilities

Multiple vulnerabilities were identified in Drupal, which could allow a remote attacker to take control of an affected system.
Last Update Date: 17 Mar 2017 Release Date: 16 Mar 2017 6084 Views

RISK: High Risk

High Risk

D-Link Routers Multiple Vulnerabilities

Multiple vulnerabilities were identified in D-Link DIR routers. An attacker could bypass the authentication of the remote login page and obtain administrator credentials for D-Link DIR-130 and DIR-330, while one could overflow the buffer and execute arbitrary...
Last Update Date: 17 Mar 2017 Release Date: 16 Mar 2017 6198 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer & Edge Remote Code Execution Vulnerability

A vulnerability was identified in Microsoft Internet Explorer and Edge, A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 16 Mar 2017 Release Date: 27 Feb 2017 7182 Views

RISK: Medium Risk

Medium Risk

Adobe Monthly Security Update (Mar 2017)

Adobe has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Flash Player Moderately Critical Remote Code Execution   APSB17-07 Shockwave Player  Moderately Critical Elevation of Privilege   APSB17-...
Last Update Date: 15 Mar 2017 11:14 Release Date: 15 Mar 2017 6132 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Monthly Security Update (Mar 2017)

Microsoft has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Internet Explorer Extremely Critical Remote Code ExecutionInformation DisclosureSecurity Restriction BypassElevation of Privilege Exploits in the wild MS17-006 Edge ...
Last Update Date: 15 Mar 2017 11:13 Release Date: 15 Mar 2017 6980 Views

RISK: Medium Risk

Medium Risk

VMware Products Remote Code Execution Vulnerability

A vulnerability was identified in VMware Workstation and Fusion, which may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Last Update Date: 15 Mar 2017 11:13 Release Date: 15 Mar 2017 6314 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Elevation of Privilege Vulnerability

A vulnerability was identified in IBM WebSphere Application Server. A remote user can gain elevated privileges.
Last Update Date: 15 Mar 2017 11:12 Release Date: 15 Mar 2017 6169 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Google has released Chrome version 57..2987.98 for Windows, Mac, and Linux. This version addresses multiple vulnerabilities that, if exploited, may allow an attacker to take control of an affected system.
Last Update Date: 10 Mar 2017 09:33 Release Date: 10 Mar 2017 6084 Views

RISK: Medium Risk

Medium Risk

Wireshark Denial of Service Vulnerability

A vulnerability was identified in Wireshark. A remote user can cause the target service to crash.
Last Update Date: 9 Mar 2017 12:22 Release Date: 9 Mar 2017 6026 Views

RISK: Medium Risk

Medium Risk

Google Android Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Android. A remote user can execute  arbitrary code, cause denial of service conditions, obtain potentially sensitive information and gain elevated privileges on the target system.
Last Update Date: 9 Mar 2017 12:22 Release Date: 9 Mar 2017 6092 Views

RISK: Extremely High Risk

Extremely High Risk

Apache Struts2 Remote Code Execution Vulnerability

 A vulnerability has been identified in Apache Struts2, which can be exploited by remote attacker to take control of an affected system.   NOTE: This vulnerability is being actively exploited in the wild.
Last Update Date: 8 Mar 2017 11:53 Release Date: 8 Mar 2017 7311 Views

RISK: Medium Risk

Medium Risk

Symantec Endpoint Protection Multiple Vulnerabilities

Two vulnerabilities were identified in Symantec Endpoint Protection. A local user can obtain elevated privileges on the target system. A remote user can modify data on the target system in certain cases.
Last Update Date: 8 Mar 2017 09:56 Release Date: 8 Mar 2017 6227 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were reported in Firefox. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Last Update Date: 8 Mar 2017 09:54 Release Date: 8 Mar 2017 6072 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities were reported in WordPress, a remote attacker could exploit these vulnerabilities to perform remote code execution on the targeted system.
Last Update Date: 7 Mar 2017 09:02 Release Date: 7 Mar 2017 5946 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remote attacker to cause denial of service and bypass security restriction.
Last Update Date: 6 Mar 2017 Release Date: 1 Mar 2017 6155 Views

RISK: Medium Risk

Medium Risk

cURL OCSP Stapling Verification Vulnerability

A vulnerability has been identified in cURL. A remote user can bypass security controls on the target system by exploiting the TLS Certificate Status Request extension checking not properly processed.
Last Update Date: 23 Feb 2017 09:03 Release Date: 23 Feb 2017 6291 Views

RISK: High Risk

High Risk

Microsoft Monthly Security Update (Jan 2017)

Microsoft has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Edge Highly Critical Elevation of Privilege Scattered Exploits MS17-001 Windows (Local Security Authority Subsystem Service) Highly Critical...
Last Update Date: 22 Feb 2017 Release Date: 11 Jan 2017 6328 Views

RISK: Medium Risk

Medium Risk

Microsoft Monthly Security Update (Feb 2017)

Microsoft has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Adobe Flash Player (bundled in Windows) Moderately Critical Remote Code Execution   MS17-005   Number of 'Extremely Critical' product...
Last Update Date: 22 Feb 2017 10:05 Release Date: 22 Feb 2017 6444 Views

RISK: Medium Risk

Medium Risk

ImageMagick Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in ImageMagick, a remoter attacker can exploit these vulnerabilities to execute arbitrary code and cause Denial Of Service condition  on the targeted system. These vulnerabilities could affect web server since a common vulnerable configuration would be a web server that...
Last Update Date: 21 Feb 2017 09:17 Release Date: 21 Feb 2017 6027 Views

RISK: Medium Risk

Medium Risk

OpenSSL renegotiation Vulnerability

A vulnerability was identified in OpenSSL, which can be exploited by remote attacker to crash the target service.
Last Update Date: 20 Feb 2017 10:32 Release Date: 20 Feb 2017 6164 Views

RISK: Medium Risk

Medium Risk

Trend Micro InterScan Web Security Virtual Appliance Multiple Vulnerabilities

Multiple vulnerabilities were identified in Trend Micro InterScan Web Security Virtual Appliance,  which can be exploited by remote attacker to conduct cross-site scripting attacks, gain elevated privileges and execute arbitrary commands on the target system.
Last Update Date: 20 Feb 2017 10:31 Release Date: 20 Feb 2017 5962 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows GDI32.DLL Vulnerability

A vulnerablity was identified in Microsoft Windows, a local user can exploit this vulnerability to obtain potentially sensitive information on the targeted system.   Note: No patch is currently available.
Last Update Date: 17 Feb 2017 09:49 Release Date: 17 Feb 2017 6319 Views

RISK: High Risk

High Risk

Adobe Monthly Security Update (Feb 2017)

Adobe has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Flash Player Highly Critical Remote Code Execution   APSB17-04 Digital Editions Moderately Critical Remote Code Execution   APSB17-...
Last Update Date: 15 Feb 2017 09:38 Release Date: 15 Feb 2017 6324 Views

RISK: Medium Risk

Medium Risk

ISC BIND Denial of Service Vulnerability

A vulnerability was identified in ISC BIND. A remote user can cause the target service to crash in certain cases.
Last Update Date: 10 Feb 2017 11:18 Release Date: 10 Feb 2017 6137 Views

RISK: Medium Risk

Medium Risk

Google Android Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Android. A remote user can execute  arbitrary code, cause denial of service conditions and obtain potentially sensitive information on the target system. An application can obtain elevated privileges on the target system.
Last Update Date: 10 Feb 2017 11:17 Release Date: 10 Feb 2017 6331 Views

RISK: High Risk

High Risk

Microsoft Windows Server Message Block SMBv3 Denial of Service Vulnerability

Microsoft Windows contains a memory corruption bug in the handling of SMB traffic, which may allow a remote, unauthenticated attacker to cause a denial of service or potentially execute arbitrary code on a vulnerable system.   Note: Exploit code for this vulnerability is publicly available.Note...
Last Update Date: 10 Feb 2017 Release Date: 3 Feb 2017 6198 Views

RISK: Medium Risk

Medium Risk

Linux Kernel IPv6 Out-of-bounds Memory Read Vulnerability

A vulnerability has been identified in the Linux kernel. A remote user can obtain potentially sensitive information or cause denial of service conditions on the target system by sending specially crafted data to trigger an out-of-bounds memory read access in ip6gre_err().
Last Update Date: 9 Feb 2017 11:43 Release Date: 9 Feb 2017 6036 Views

RISK: Medium Risk

Medium Risk

Cisco ASR 1000 Series Router Denial of Service Vulnerability

A vulnerability in Simple Network Management Protocol (SNMP) functions of Cisco ASR 1000 Series Aggregation Services Routers could allow an authenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
Last Update Date: 3 Feb 2017 10:39 Release Date: 3 Feb 2017 6035 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities have been identified in PHP, which could allow a remote or local user can cause denial of service conditions, obtain potentially sensitive information or execute arbitrary code on the target system.
Last Update Date: 3 Feb 2017 Release Date: 23 Jan 2017 5872 Views

RISK: High Risk

High Risk

Tcpdump Multiple Vulnerabilities

Multiple vulnerabilities were identified in Tcpdump. A remote user can cause arbitrary code to be executed or the service to crash on the target system.   Note: The vendor is working on the fix.
Last Update Date: 2 Feb 2017 10:54 Release Date: 2 Feb 2017 6050 Views

RISK: Medium Risk

Medium Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities were identified in OpenSSL. A remote user can cause the target service to crash and obtain potentially sensitive information on the target system.
Last Update Date: 27 Jan 2017 11:04 Release Date: 27 Jan 2017 5974 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome. A remote user can conduct cross-site scripting attacks, spoof the user interface, obtain potentially sensitive information, bypass security controls and cause arbitrary code to be executed on the target user's system.
Last Update Date: 27 Jan 2017 11:04 Release Date: 27 Jan 2017 5857 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities were identified in WordPress, which may lead to SQL injection and cross site scripting.
Last Update Date: 27 Jan 2017 09:39 Release Date: 27 Jan 2017 5917 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin Multiple Vulnerabilities

Multiple vulnerabilities have been identified in phpMyAdmin, which can be exploited by remote attacker to execute arbitrary code, cause denial of service and disclose sensitive information.
Last Update Date: 26 Jan 2017 09:04 Release Date: 26 Jan 2017 6861 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Browser Extension Remote Code Execution Vulnerability

Cisco has released security updates to address a vulnerability in its WebEx browser extensions. Exploitation of this vulnerability could allow a remote attacker to take control of an affected system.
Last Update Date: 25 Jan 2017 10:40 Release Date: 25 Jan 2017 6015 Views

RISK: Medium Risk

Medium Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities were reported in Apple products, a remote attacker can exploit these vulnerabilities to perform Cross Site Scripting, Elevation Of Privilege, Remote Code Execution, Security Restriction Bypass,  Denial Of Service attack and disclose sensitive information on the targeted system. For detail, please...
Last Update Date: 25 Jan 2017 Release Date: 24 Jan 2017 6261 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Mozilla has released a security update to address multiple vulnerabilities in Firefox and Firefox ESR. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 25 Jan 2017 10:25 Release Date: 25 Jan 2017 6101 Views

RISK: High Risk

High Risk

QNAP Storage Devices Remote Users Access Vulnerability

A vulnerability was identified in QNAP Storage Devices, a remote user can gain access to the target system.
Last Update Date: 23 Jan 2017 10:17 Release Date: 23 Jan 2017 6000 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Meetings Server Multiple vulnerabilities

Multiple vulnerabilities have been identified in Cisco WebEx Meetings Server, which could allow an unauthenticated, remote attacker to disclose sensitive information, and conduct a cross-site request forgery (CSRF) attack.
Last Update Date: 20 Jan 2017 09:20 Release Date: 20 Jan 2017 6025 Views

RISK: Medium Risk

Medium Risk

Cisco IOS and IOx Information Disclosure Vulnerability

A vulnerability was identified in the web-based management interface of Cisco IOS and Cisco IOx. An unauthenticated, remote attacker could view confidential information.
Last Update Date: 19 Jan 2017 11:25 Release Date: 19 Jan 2017 5898 Views

RISK: Medium Risk

Medium Risk

Symantec Products Remote Code Execution Vulnerability

A vulnerability was identified in Norton Download Manager. A remote user can cause arbitrary code to be executed on the target user's system.Products like Symantec Endpoint Protection Cloud, Norton Anti-Virus and Norton Internet Security are equipped with this download manager and so...
Last Update Date: 19 Jan 2017 11:25 Release Date: 19 Jan 2017 6214 Views

RISK: High Risk

High Risk

Oracle Security Update (Jan 2017)

Oracle has released Jan 2017 security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Database Highly Critical Information DisclosureRemote Code ExecutionDenial of ServiceData Manipulation   DB (2017-01) Java SE Highly Critical ...
Last Update Date: 18 Jan 2017 09:53 Release Date: 18 Jan 2017 7662 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND. A remote attacker could exploit any of these vulnerabilities to cause a denial-of-service condition.
Last Update Date: 13 Jan 2017 09:42 Release Date: 13 Jan 2017 5944 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities were identified in WordPress, which may lead to remote code exection, cross site scripting, cross site request forgery and information disclosure.
Last Update Date: 12 Jan 2017 10:54 Release Date: 12 Jan 2017 5930 Views

RISK: Medium Risk

Medium Risk

GnuTLS Remote Code Execution Vulnerabilities

Multiple vulnerabilities were identified in GnuTLS. A remote user can execute arbitrary code on the target system.
Last Update Date: 12 Jan 2017 08:59 Release Date: 12 Jan 2017 5952 Views

RISK: Medium Risk

Medium Risk

OpenSSL Information Disclosure Vulnerability

A vulnerability was identified in OpenSSL. A local user can recover ECDSA P-256 private keys.   Note: Currently no patch is available.
Last Update Date: 11 Jan 2017 09:57 Release Date: 11 Jan 2017 6044 Views