Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can bypass security controls on the target system. A remote user can spoof URLs. A remote user can conduct...
Last Update Date: 5 Sep 2016 10:54 Release Date: 5 Sep 2016 6082 Views

RISK: High Risk

High Risk

Apple OS X and Safari Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X and Safari, which could allow a remote/local attacker can execute arbitrary code and obtain elevated privileges on the target system.
Last Update Date: 5 Sep 2016 10:48 Release Date: 5 Sep 2016 6313 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple Cisco products.A remote user can cause the target interface to stop responding in Cisco Small Business 220 Series Smart Plus (Sx220) Switches.A remote user can cause the target system to restart in Cisco Wireless LAN Controller...
Last Update Date: 2 Sep 2016 10:22 Release Date: 2 Sep 2016 6160 Views

RISK: Extremely High Risk

Extremely High Risk

Apple iOS Multiple Vulnerabilites

Multiple vulnerabilities were identified in Apple iOS, which could allow a remote/local attacker can execute arbitrary code and obtain elevated privileges on the target system. Note: The vulnerability is currently being exploited in the wild
Last Update Date: 26 Aug 2016 10:30 Release Date: 26 Aug 2016 7756 Views

RISK: Medium Risk

Medium Risk

VMware Identity Manager and vRealize Automation Multiple Vulnerabilities

Two vulnerabilities were identified in VMware vRealize Automation. A local user can obtain root privileges on the target system. A remote user can execute arbitrary code on the target system. The first vulnerability also affects VMware Identity Manager.
Last Update Date: 25 Aug 2016 09:07 Release Date: 25 Aug 2016 6060 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities were identified in WordPress. A remote user can conduct cross-site request forgery attacks. A remote authenticated user can cause the target application to fail.
Last Update Date: 23 Aug 2016 09:25 Release Date: 23 Aug 2016 6151 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Microsoft Internet Explorer Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the...
Last Update Date: 19 Aug 2016 Release Date: 13 Jul 2016 6027 Views

RISK: Medium Risk

Medium Risk

Microsoft Netlogon Remote Code Execution Vulnerability

Windows Netlogon Memory Corruption Remote Code ExecutionThis security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution when Windows improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. To...
Last Update Date: 19 Aug 2016 Release Date: 15 Jun 2016 6351 Views

RISK: High Risk

High Risk

Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Firefox. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.  
Last Update Date: 19 Aug 2016 Release Date: 4 Aug 2016 6104 Views

RISK: High Risk

High Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress. Exploitation of one of these vulnerabilities could allow a remote attacker to take control of an affected system.  
Last Update Date: 19 Aug 2016 Release Date: 23 Jun 2016 6138 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server Multiple Vulnerabilities

 A vulnerability was identified in IBM HTTP Server, a attracker could exploit this  vulnerability to perform denial of service attacks on the targeted system.
Last Update Date: 19 Aug 2016 Release Date: 18 Aug 2016 6186 Views

RISK: High Risk

High Risk

Fortinet FortiGate/FortiOS Remote Code Execution Vulnerability

A vulnerability has been identified in Fortinet FortiGate/FortiOS, which could allow a remote user can execute arbitrary code on the target system.
Last Update Date: 19 Aug 2016 10:43 Release Date: 19 Aug 2016 6294 Views

RISK: High Risk

High Risk

Cisco ASA Product Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco ASA product, which could allow a attacker cause denial of service conditions, obtain root privileges or execute arbitrary code on the target system.
Last Update Date: 19 Aug 2016 10:43 Release Date: 19 Aug 2016 6712 Views

RISK: Medium Risk

Medium Risk

HTTP CONNECT and 407 Proxy "FalseCONNECT" Vulnerability

A Vulnerability was identified in HTTP CONNECT and 407 Proxy, a attacker could exploit this vulnerability to perform MITM attacks on the targeted system.
Last Update Date: 16 Aug 2016 09:34 Release Date: 16 Aug 2016 6349 Views

RISK: Medium Risk

Medium Risk

PostgreSQL Multiple Vulnerabilities

Two vulnerabilities have been identified in PostgreSQL. A remote authenticated user can cause the target service to crash or gain elevated privileges on the target system.
Last Update Date: 15 Aug 2016 10:34 Release Date: 15 Aug 2016 5994 Views

RISK: Medium Risk

Medium Risk

D-Link routers Remote Code Execution Vulnerability

D-Link DIR routers contain a stack-based buffer overflow vulnerability, which may allow a remote attacker to execute arbitrary code.
Last Update Date: 12 Aug 2016 09:09 Release Date: 12 Aug 2016 6332 Views

RISK: High Risk

High Risk

Microsoft Monthly Security Update (Aug 2016)

Microsoft has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Internet Explorer Highly Critical Remote Code ExecutionInformation Disclosure   MS16-095 Edge Highly Critical Remote Code ExecutionInformation Disclosure   MS16...
Last Update Date: 10 Aug 2016 15:23 Release Date: 10 Aug 2016 6531 Views

RISK: High Risk

High Risk

Adobe Monthly Security Update (Aug 2016)

Adobe has released monthly security update for their products:   Vulnerable Product Severity Impacts Notes Details (including CVE) Experience Manager Highly Critical Remote Code ExecutionInformation DisclosureCross-site Scripting   APSB16-27   Number of 'Extremely Critical' product(...
Last Update Date: 10 Aug 2016 14:12 Release Date: 10 Aug 2016 6311 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Foxit Reader. A remote user can cause arbitrary code to be executed, the target application to crash and obtain potentially sensitive information on the target system.
Last Update Date: 10 Aug 2016 09:40 Release Date: 10 Aug 2016 6118 Views

RISK: Medium Risk

Medium Risk

VMware Multiple Vulnerabilities

Multiple vulnerabilities were identified in VMware vCenter Server, vSphere Hypervisor (ESXi), Workstation Pro, Workstation Player, Fusion, and Tools. Exploitation of one of these vulnerabilities could allow a remote attacker to take control of an affected system.
Last Update Date: 8 Aug 2016 09:52 Release Date: 8 Aug 2016 6368 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can bypass security controls on the target system. A remote user can spoof URLs.
Last Update Date: 8 Aug 2016 09:52 Release Date: 8 Aug 2016 5925 Views

RISK: Medium Risk

Medium Risk

Joolma! Multiple Vulnerabilities

Multiple vulnerabilities were identified in Joomla!. A remote user can conduct cross-site request forgery attacks. A remote user can access data on the target system. A remote user can conduct cross-site scripting attacks.
Last Update Date: 8 Aug 2016 09:52 Release Date: 8 Aug 2016 5962 Views

RISK: Medium Risk

Medium Risk

Apple iOS Elevation of Privilege Vulnerability

A vulnerability was identified in Apple iOS. An application can gain elevated privileges on the target system. 
Last Update Date: 8 Aug 2016 09:52 Release Date: 8 Aug 2016 6425 Views

RISK: High Risk

High Risk

OpenSSH multiple vulnerabilities

Multiple vulnerabilities have been identified in OpenSSH, a remote attacker can exploit these vulnerabilities to cause denial of service condition on the targeted system. A local user can obtain elevated privileges on the target system. A remote or local user can obtain potentially sensitive information on...
Last Update Date: 2 Aug 2016 14:55 Release Date: 2 Aug 2016 6562 Views

RISK: Medium Risk

Medium Risk

Perl Multiple Vulnerabilities

Multiple vulnerabilities were identified in Perl, which may lead to remote code execution and elevation of privilege.  
Last Update Date: 29 Jul 2016 Release Date: 27 Jul 2016 6074 Views

RISK: Medium Risk

Medium Risk

MIT Kerberos Denial of Service Vulnerability

A vulnerability was identified in Kerberos. A remote authenticated user can cause denial of service conditions on the target system.  
Last Update Date: 29 Jul 2016 Release Date: 27 Jul 2016 5830 Views

RISK: Medium Risk

Medium Risk

Cisco Nexus 1000v AVS Input Validation Vulnerability

A vulnerability has been identified in Cisco Nexus 1000v Application Virtual Switch (AVS). A remote user can cause denial of service conditions on the target system.
Last Update Date: 28 Jul 2016 15:43 Release Date: 28 Jul 2016 6077 Views

RISK: Medium Risk

Medium Risk

IBM DB2 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM DB2. Exploitation of some of these vulnerabilities may allow a local attacker to take control of an affected system.
Last Update Date: 28 Jul 2016 15:43 Release Date: 28 Jul 2016 6041 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.  
Last Update Date: 26 Jul 2016 Release Date: 22 Jul 2016 5963 Views

RISK: High Risk

High Risk

OpenSSH Password Validation Vulnerability

A vulnerability has been identified in OpenSSH, which could allow a remote attacker to disclose sensitive information by sending large passwords.  
Last Update Date: 26 Jul 2016 10:13 Release Date: 26 Jul 2016 6519 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 20 Jul 2016 15:14 Release Date: 20 Jul 2016 6208 Views

RISK: Medium Risk

Medium Risk

ISC BIND Denial of Service Vulnerability

 A vulnerability was identified in BIND. A remote user can cause the target service to crash.
Last Update Date: 20 Jul 2016 15:14 Release Date: 20 Jul 2016 5945 Views

RISK: High Risk

High Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple tvOS, iOS, watchOS, OS X El Capitan, Safari, and iTunes. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 19 Jul 2016 11:05 Release Date: 19 Jul 2016 6126 Views

RISK: High Risk

High Risk

Web Servers CGI Multiple Vulnerabilities

Multiple vulnerabilities were identified in web servers running CGI, a attacker can exploited these vulnerabilities to redirect the target CGI application requests to an arbitrary web proxy in certain cases. Note: for certain products, please apply mitigation according to the vendor advice if patch is...
Last Update Date: 19 Jul 2016 11:00 Release Date: 19 Jul 2016 6053 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP, which can be exploited to cause denial of service condition and remote code execution on the target system.
Last Update Date: 18 Jul 2016 09:22 Release Date: 18 Jul 2016 5964 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Two vulnerabilities were identified in two Cisco products. Exploitation of one of these vulnerabilities could allow an unauthenticated remote attacker to take control of an affected system.
Last Update Date: 15 Jul 2016 10:09 Release Date: 15 Jul 2016 5960 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Brackets, ColdFusion, Creative Cloud Desktop Application, DNG Software Development Kit and Flash Player, which could be exploited by attackers to cross-site scripting, information disclosure and remote code execution.   Note: The Flash Player vulnerability is...
Last Update Date: 14 Jul 2016 Release Date: 15 Jun 2016 6693 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Secure Boot Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Windows Secure Boot improperly applies an affected policy. An attacker who successfully exploited this vulnerability could disable code integrity checks, allowing test-signed executables and drivers to be loaded on a target device. In addition, an attacker could...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6579 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities

Windows File System Security Feature BypassA security feature bypass vulnerability exists in the Windows kernel that could allow an attacker to exploit time of check time of use (TOCTOU) issues in file path-based checks from a low integrity application. An attacker who successfully exploited this...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6038 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Information Disclosure Vulnerability

An information disclosure vulnerability exists when .NET Framework improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity declaration.
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6124 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Multiple Win32k Elevation of Privilege VulnerabilitiesElevation of privilege vulnerabilities exist when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6076 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Secure Kernel Mode Information Disclosure Vulnerability

 An information disclosure vulnerability exists when Windows Secure Kernel Mode improperly handles objects in memory. A locally-authenticated attacker who successfully exploited this vulnerability could be able to read sensitive information on the target system.
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6001 Views

RISK: High Risk

High Risk

Microsoft Office Multiple Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 5914 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Print Spooler Multiple Vulnerabilities

Windows Print Spooler Remote Code Execution VulnerabilityA remote code execution vulnerability exists when the Windows Print Spooler service does not properly validate print drivers while installing a printer from servers. An attacker who successfully exploited this vulnerability could use it to execute arbitrary code and take control of an...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6125 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Cumulative Security Update

Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the JScript and VBScript engines render when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6000 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Edge Security Feature BypassA security feature bypass exists when Microsoft Edge does not properly implement Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, after which the attacker could load additional malicious code in the process in an...
Last Update Date: 14 Jul 2016 Release Date: 13 Jul 2016 6010 Views

RISK: High Risk

High Risk

Drupal Contributed Modules Arbitrary PHP Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Drupal contributed modules, which could be exploited by attackers to execute arbitrary code.
Last Update Date: 14 Jul 2016 09:25 Release Date: 14 Jul 2016 5973 Views

RISK: Medium Risk

Medium Risk

Symantec and Norton Anti-virus Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Symantec and Norton anti-virus products. Exploitation of these vulnerabilities could allow a remote attacker to take control of an affected system.
Last Update Date: 14 Jul 2016 Release Date: 6 Jul 2016 5928 Views

RISK: Medium Risk

Medium Risk

Apache HTTPD Client Certificate Authentication Bypassing Vulnerability

A vulnerability was identified in Apache HTTPD web server. A remote user can bypass client certificate authentication. Systems using the mod_http2 module and with the h2 and h2c protocols activated in the configuration are affected.
Last Update Date: 14 Jul 2016 Release Date: 6 Jul 2016 5963 Views

RISK: High Risk

High Risk

Adobe Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat, Flash Player, Reader, and XMP Tookit for Java. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 13 Jul 2016 09:40 Release Date: 13 Jul 2016 6291 Views

RISK: Medium Risk

Medium Risk

Samba Signing Security Protection Downgrade Vulnerability

A vulnerability was identified in Samba. A remote user can downgrade client signing security controls on the target system and impersonate the target server.
Last Update Date: 8 Jul 2016 09:17 Release Date: 8 Jul 2016 5822 Views

RISK: Medium Risk

Medium Risk

GIMP XCF File Parsing Vulnerability

A vulnerability has been identified in GNU Image Manipulation Program (GIMP). A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 7 Jul 2016 10:13 Release Date: 7 Jul 2016 6195 Views

RISK: High Risk

High Risk

Apple Airport Remote Code Execution Vulnerability

A vulnerability was identified in Apple Airport Base Station. A remote user can execute arbitrary code on the target system.
Last Update Date: 30 Jun 2016 Release Date: 22 Jun 2016 6106 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XE Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS XE. A remote authenticated user can cause the target device to restart.
Last Update Date: 30 Jun 2016 Release Date: 22 Jun 2016 6034 Views

RISK: Medium Risk

Medium Risk

Symantec Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec products. Exploitation of some of these vulnerabilities may allow an attacker to take control of an affected system and cause a denial-of-service condition.
Last Update Date: 30 Jun 2016 09:01 Release Date: 30 Jun 2016 6572 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Denial of Service Vulnerability

 A vulnerability has been identified in Apache Tomcat, which can be exploited to cause denial of service in the target system.
Last Update Date: 24 Jun 2016 09:42 Release Date: 24 Jun 2016 6135 Views

RISK: Medium Risk

Medium Risk

mDNSResponder Multiple Vulnerabilities

Multiple vulnerabilities were identified in mDNSResponder. A remote user can exploit these vulnerabilities to perform remote code execution and cause denial of service conditions on the target system. 
Last Update Date: 21 Jun 2016 09:34 Release Date: 21 Jun 2016 6159 Views

RISK: Medium Risk

Medium Risk

Apache Structs Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apache Structs. A remote user can exploit these vulnerabilities to perform remote code execution and CSRF (Cross-site request forgery) attack on the target system.
Last Update Date: 21 Jun 2016 09:32 Release Date: 21 Jun 2016 6110 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, which may allow a remote attacker to obtain sensitive information from an affected system.
Last Update Date: 20 Jun 2016 10:14 Release Date: 20 Jun 2016 5980 Views

RISK: High Risk

High Risk

Microsoft Windows Search Component Denial of Service Vulnerability

Windows Search Component Denial of Service VulnerabilityThis vulnerability occurs when the Windows Search component fails to properly handle certain objects in memory. An attacker who successfully exploited this vulnerability could cause server performance to degrade sufficiently to cause a denial of service condition. To exploit this vulnerability, ...
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6350 Views

RISK: High Risk

High Risk

Microsoft Active Directory Denial of Service Vulnerability

Active Directory Denial of Service VulnerabilityA denial of service vulnerability exists in Active Directory when an authenticated attacker creates multiple machine accounts. An attacker who successfully exploited this vulnerability could cause the Active Directory service to become non-responsive.
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6127 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows PDF Multiple Vulnerabilities

Multiple Windows PDF Information Disclosure VulnerabilitiesInformation disclosure vulnerabilities exist in Microsoft Windows when a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could read information in the context of the current user. Windows PDF Remote Code Execution VulnerabilityA remote code execution...
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6254 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Multiple Vulnerabilities

Microsoft Exchange Information Disclosure VulnerabilityAn email filter bypass exists in the way that Microsoft Exchange parses HTML messages that could allow information disclosure. An attacker who successfully exploited the vulnerability could identify, fingerprint, and track a user online if the user views email messages using Outlook Web...
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6264 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Diagnostic Hub Elevation of Privilege Vulnerability

Windows Diagnostics Hub Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library loading behavior. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. ...
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6272 Views

RISK: Medium Risk

Medium Risk

Microsoft WPAD Elevation of Privilege Vulnerabilities

Windows WPAD Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in Microsoft Windows when the Web Proxy Auto Discovery (WPAD) protocol falls back to a vulnerable proxy discovery process. An attacker who successfully exploited this vulnerability could bypass security and gain elevated privileges on a targeted...
Last Update Date: 15 Jun 2016 17:47 Release Date: 15 Jun 2016 6554 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Server Elevation of Privilege Vulnerability

Windows SMB Server Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) when an attacker forwards an authentication request intended for another service running on the same machine. An attacker who successfully exploited this vulnerability could execute arbitrary...
Last Update Date: 15 Jun 2016 17:43 Release Date: 15 Jun 2016 6527 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Component Multiple Vulnerabilities

Windows Graphics Component Information Disclosure Vulnerability An information disclosure vulnerability exists when the Windows Graphics Component (GDI32.dll) fails to properly handle objects in memory, allowing an attacker to retrieve information that could lead to an Address Space Layout Randomization (ASLR) bypass. ...
Last Update Date: 15 Jun 2016 17:43 Release Date: 15 Jun 2016 6199 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Group Policy Elevation of Privilege Vulnerability

Group Policy Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
Last Update Date: 15 Jun 2016 17:43 Release Date: 15 Jun 2016 6194 Views

RISK: High Risk

High Risk

Microsoft Office Multiple Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 15 Jun 2016 17:43 Release Date: 15 Jun 2016 6007 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Multiple Win32k Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; ...
Last Update Date: 15 Jun 2016 17:36 Release Date: 15 Jun 2016 6102 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Use After Free VulnerabilityA remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows...
Last Update Date: 15 Jun 2016 17:36 Release Date: 15 Jun 2016 6199 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Cumulative Security Update

Multiple Scripting Engine Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in the way that the JScript 9, JScript, and VBScript engines render when handling objects in memory in Internet Explorer. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code...
Last Update Date: 15 Jun 2016 17:36 Release Date: 15 Jun 2016 6106 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Microsoft Internet Explorer Memory Corruption Vulnerabilities Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited...
Last Update Date: 15 Jun 2016 17:36 Release Date: 15 Jun 2016 6098 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Edge Security Feature BypassA security feature bypass exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker who exploited the bypass could trick a user into loading a page containing malicious content. Multiple Scripting...
Last Update Date: 15 Jun 2016 17:29 Release Date: 15 Jun 2016 6163 Views

RISK: High Risk

High Risk

VMware NSX, vCNS and vRealize Log Insight Multiple Vulnerabilities

Multiple vulnerabilities were identified in VMware NSX, vCNS and vRealize Log Insight. Exploitation of one of these vulnerabilities could allow a remote attacker to take control of an affected system.
Last Update Date: 13 Jun 2016 10:41 Release Date: 13 Jun 2016 6248 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which may allow a remote attacker to take control of an affected system.
Last Update Date: 8 Jun 2016 12:14 Release Date: 8 Jun 2016 6680 Views

RISK: Extremely High Risk

Extremely High Risk

CryptXXX Ransomware Encrypts Victim Data

A ransomware known as CryptXXX has been spreading quickly through compromised websites. HKCERT has received several CryptXXX infection reports from victims since mid-May 2016.   How CryptXXX was spread Compromised website: Most victims were infected by visiting compromised websites. Those websites mainly targeted...
Last Update Date: 7 Jun 2016 Release Date: 3 Jun 2016 11028 Views

RISK: High Risk

High Risk

NTP Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ntp, a remote attacker can exploit these vulnerabilities to cause denial of service and tampering in the targeted system.
Last Update Date: 7 Jun 2016 09:09 Release Date: 7 Jun 2016 6389 Views

RISK: High Risk

High Risk

WordPress WP Mobile Detector Remote Code Execution Vulnerability

A vulnerability has been identified in WP Mobile Detector, a WordPress plugin. Exploitation of this vulnerability could allow an attacker to take control of an affected website. Note: This vulnerability is currently being exploited in the wild.
Last Update Date: 6 Jun 2016 09:36 Release Date: 6 Jun 2016 6290 Views

RISK: High Risk

High Risk

Apache Structs Multiple Vulnerabilities

 Multiple vulnerabilities were identified in Apache Struct. A remote user can execute arbitrary code on the target system.A remote user can cause denial of service conditions on the target system.
Last Update Date: 3 Jun 2016 17:38 Release Date: 3 Jun 2016 6483 Views

RISK: Medium Risk

Medium Risk

nginx Denial of Service Vulnerability

 A vulnerability was identified in nginx. A remote user can cause denial of service conditions on the target system.
Last Update Date: 3 Jun 2016 17:37 Release Date: 3 Jun 2016 6508 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 3 Jun 2016 17:36 Release Date: 3 Jun 2016 6239 Views

RISK: Medium Risk

Medium Risk

VLC Media Player QuickTime IMA Files Processing Vulnerability

A vulnerability has been identified in VLC Media Player. A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 2 Jun 2016 09:12 Release Date: 2 Jun 2016 6289 Views

RISK: Medium Risk

Medium Risk

Cisco Security Appliances Denial of Service Vulnerability

A vulnerability was identified in Cisco Email Security Appliance (ESA) and Web Security Appliance (WSA). A remote user can cause the target service to crash. The vulnerability resides in the Clam AntiVirus (ClamAV) component.
Last Update Date: 2 Jun 2016 Release Date: 1 Jun 2016 6233 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, which may allow a remote attacker to take control of an affected system.
Last Update Date: 30 May 2016 Release Date: 27 May 2016 6037 Views

RISK: High Risk

High Risk

Cisco Products Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS XR Software, Cisco IOS XE Software, and Cisco NX-OS Software, which could allow an unauthenticated, remote attacker to cause an affected device to stop processing IPv6 traffic, leading to a denial of service (DoS...
Last Update Date: 30 May 2016 Release Date: 27 May 2016 6095 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin Multiple Vulnerabilities

Multiple vulnerabilities were identified in phpMyAdmin. A remote user can conduct cross-site scripting attacks and obtain potentially sensitive information on the target system. 
Last Update Date: 30 May 2016 09:43 Release Date: 30 May 2016 6116 Views

RISK: Medium Risk

Medium Risk

Wireshark Denial of Service Vulnerabilities

Multiple vulnerabilities were identified in Wireshark, which could result in denial of service.
Last Update Date: 25 May 2016 Release Date: 24 May 2016 6054 Views

RISK: Medium Risk

Medium Risk

Trend Micro InterScan Web Security Remote Code Execution Vulnerabilties

Multiple vulnerabilties were identified in Trend Micro InterScan Web Security, which could allow attackers to execute arbitrary code on affected versions.
Last Update Date: 25 May 2016 09:38 Release Date: 25 May 2016 5957 Views

RISK: Medium Risk

Medium Risk

Xen Elevation of Privilege Vulnerability

 A vulnerability has been identified in Xen, which can be exploited by guest users to elevate privileges inside the guest.
Last Update Date: 20 May 2016 09:07 Release Date: 20 May 2016 5939 Views

RISK: High Risk

High Risk

VMware products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Vmware products. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 19 May 2016 09:43 Release Date: 19 May 2016 6032 Views

RISK: Medium Risk

Medium Risk

Moodle Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Moodle, A remote user can exploit these vulnerabilities to conduct cross-site request forgery attacks, access data and modify data on the targeted system.
Last Update Date: 18 May 2016 09:12 Release Date: 18 May 2016 5975 Views

RISK: High Risk

High Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple tvOS, iOS, watchOS, OS X El Capitan, Safari, and iTunes. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 17 May 2016 09:12 Release Date: 17 May 2016 6325 Views

RISK: Medium Risk

Medium Risk

7-Zip Multiple Vulnerabilities

 Two vulnerabilities were identified in 7-Zip. A remote user can cause arbitrary code to be executed on the target system.
Last Update Date: 13 May 2016 09:59 Release Date: 13 May 2016 7320 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. Note: This vulnerability is being actively exploited in the wild.
Last Update Date: 13 May 2016 Release Date: 11 May 2016 6523 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Multiple Vulnerability

 Multiple vulnerabilities were identified in Adobe ColdFusion. A remote user can bypass security controls on the target system. A remote user can conduct cross-site scripting attacks.
Last Update Date: 12 May 2016 Release Date: 11 May 2016 5966 Views

RISK: High Risk

High Risk

Adobe Acrobat and Reader Multiple Vulnerabilities

 Multiple vulnerabilities were identified in Adobe Acrobat and Reader. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can bypass security controls on the target system. A remote user can obtain potentially sensitive information on...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6435 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows RDP Information Disclosure Vulnerability

An information disclosure vulnerability exists in Microsoft Windows when a USB disk mounted over Remote Desktop Protocol (RDP) via Microsoft RemoteFX is not correctly tied to the session of the mounting user. An attacker who successfully exploited this vulnerability could obtain access to file and directory information...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6837 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Hypervisor Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Windows incorrectly allows certain kernel-mode pages to be marked as Read, Write, Execute (RWX) even with Hypervisor Code Integrity (HVCI) enabled.   To exploit this vulnerability, an attacker could run a specially crafted application...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 7291 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework TLS/SSL Information Disclosure Vulnerability

An information disclosure vulnerability exists in the TLS/SSL protocol, implemented in the encryption component of Microsoft .NET Framework. An attacker who successfully exploited this vulnerability could decrypt encrypted SSL/TLS traffic.   To exploit the vulnerability, an attacker would first have to inject...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6316 Views