Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Multiple elevation of privilege vulnerabilities exist in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6221 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows RPC Elevation of Privilege Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles specially crafted Remote Procedure Call (RPC) requests. The remote code execution can occur when the RPC Network Data Representation (NDR) Engine improperly frees memory. An authenticated attacker who successfully exploited this...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6503 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links. An attacker who successfully exploited this vulnerability could potentially access privileged registry keys and thereby elevate permissions. An attacker could then install programs; view, ...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6142 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Center Remote Code Execution Vulnerability

A vulnerability exists in Windows Media Center that could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploited this vulnerability could take control of an affected system. Customers whose...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6179 Views

RISK: High Risk

High Risk

Microsoft Windows IIS Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Windows fails to properly validate input before loading certain libraries. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6432 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Windows Shell improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take control of the affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6224 Views

RISK: High Risk

High Risk

Microsoft Windows Journal Memory Corruption Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6260 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Component Multiple Vulnerabilities

Information disclosure vulnerabilities exist when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerabilities could obtain information to further compromise the user’s system.   There are multiple ways an attacker could exploit the vulnerabilities, such as by...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6104 Views

RISK: High Risk

High Risk

Microsoft Office Multiple Vulnerabilities

Multiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user is logged on with administrative...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6081 Views

RISK: High Risk

High Risk

Microsoft JScript and VBScript Cumulative Security Update

Multiple remote code execution vulnerabilities exist in the way that the JScript and VBScript engines render when handling objects in memory in Internet Explorer. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6089 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple remote code execution vulnerabilities exist in the way that the Chakra JavaScript engine renders when handling objects in memory in Microsoft Edge. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 5969 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 6125 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 12 May 2016 09:54 Release Date: 12 May 2016 6033 Views

RISK: Medium Risk

Medium Risk

WordPress Security Update

Two vulnerabilities were identified in WordPress,  which can be exploited by malicious people to conduct cross-site scripting attacks or allow a remote attacker to take control of an affected system.
Last Update Date: 11 May 2016 10:36 Release Date: 11 May 2016 6029 Views

RISK: Extremely High Risk

Extremely High Risk

ImageMagick Input Validation Vulnerability (ImageTragick)

An input validation vulnerability has been identified in ImageMagick, which could be exploited by remoter attacker to execute arbitrary code on target system.   The vulnerability could affect web server since a common vulnerable configuration would be a web server that allows image uploads that are subsequently processed with...
Last Update Date: 5 May 2016 09:59 Release Date: 5 May 2016 6997 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities were identified in OpenSSL. Attackers can decrypt data in certain cases, cause denial of service conditions, obtain potentially sensitive information and execute arbitrary code on the target system.
Last Update Date: 5 May 2016 Release Date: 4 May 2016 6458 Views

RISK: Medium Risk

Medium Risk

Apple Xcode Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple Xcode. Exploitation of either of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 5 May 2016 Release Date: 4 May 2016 5896 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 3 May 2016 09:28 Release Date: 3 May 2016 5940 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Wireshark, remote attacker can exploit these vulnerabilities to trigger denial of service condition in the targeted system.
Last Update Date: 29 Apr 2016 Release Date: 27 Apr 2016 5959 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which could allow a remote attacker to take control of an affected system.
Last Update Date: 29 Apr 2016 Release Date: 27 Apr 2016 6142 Views

RISK: High Risk

High Risk

NTP Multiple Vulnerabilities

Multiple vulnerabilities were identified in ntp. A remote or remote authenticated user can modify time on the target system. A remote user can cause denial of service conditions on the target system. A remote user can obtain potentially sensitive information on the target system.
Last Update Date: 29 Apr 2016 14:32 Release Date: 29 Apr 2016 6528 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities was identified in PHP. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions on the target system.
Last Update Date: 29 Apr 2016 14:32 Release Date: 29 Apr 2016 5938 Views

RISK: Extremely High Risk

Extremely High Risk

Apache Struts 2 Dynamic Method Invocation (DMI) Input Validation Vulnerability

A vulnerability has been identified in Apache Struts 2, which could be exploited by remote attacker to execute arbitrary code on target server by passing a malicious expression when Dynamic Method Invocation (DMI) is enabled.   Note: From CNCERT/CC report, the exploit code...
Last Update Date: 28 Apr 2016 09:36 Release Date: 28 Apr 2016 8024 Views

RISK: Medium Risk

Medium Risk

Adobe Analytics AppMeasurement for Flash Library Cross-Site Scripting Vulnerability

A vulnerability was identified in Adobe Analytics AppMeasurement for Flash Library. A remote attacker can conduct cross-site scripting attacks.
Last Update Date: 25 Apr 2016 10:27 Release Date: 25 Apr 2016 6217 Views

RISK: High Risk

High Risk

Cisco Products Denial of Service Vulnerability

A vulnerability was identified in multiple Cisco products. A remote user can cause denial of service conditions. Affected products included:  Cisco WebEx Meetings Server  Cisco Jabber  Cisco Unity Connection  Cisco IP Phones  Cisco Unified Communications Manager  
Last Update Date: 22 Apr 2016 09:41 Release Date: 22 Apr 2016 6741 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 20 Apr 2016 09:03 Release Date: 20 Apr 2016 6590 Views

RISK: Extremely High Risk

Extremely High Risk

QuickTime for Windows End of Support and Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime for Windows. A remote user can cause arbitrary code to be executed on the target user's system.   Note: Vendor patch will not be provided. Apple has announced that no future security updates on QuickTime for Windows...
Last Update Date: 18 Apr 2016 08:45 Release Date: 18 Apr 2016 7521 Views

RISK: Medium Risk

Medium Risk

VMWare Products Session Hijack Vulnerability

A vulnerability was identified in multiple VMware products. A remote user can hijack the target user's session.Affected products include VMware vCenter Server, VMware vCloud Director and VMware vRealize Automation Identity Appliance.
Last Update Date: 15 Apr 2016 10:24 Release Date: 15 Apr 2016 6439 Views

RISK: Medium Risk

Medium Risk

Juniper ScreenOS Multiple Vulnerabilities

 Multiple vulnerabilities have been identified in Juniper ScreenOS, which can be exploited by malicious remote users to cause denial of service and obtain potentially sensitive information.
Last Update Date: 15 Apr 2016 10:24 Release Date: 15 Apr 2016 6353 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 14 Apr 2016 09:11 Release Date: 14 Apr 2016 6144 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows HTTP.sys Denial of Service Vulnerability

A denial of service vulnerability exists in the HTTP 2. protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2. requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system...
Last Update Date: 13 Apr 2016 12:04 Release Date: 13 Apr 2016 6227 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows CSRSS Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Microsoft Windows when the Client-Server Run-time Subsystem (CSRSS) fails to properly manage process tokens in memory.
Last Update Date: 13 Apr 2016 12:04 Release Date: 13 Apr 2016 6215 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SAM and LSAD Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols when they accept authentication levels that do not protect them adequately. The vulnerability is caused by the way the SAM and LSAD remote...
Last Update Date: 13 Apr 2016 12:04 Release Date: 13 Apr 2016 6476 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Secondary Logon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when the Windows Secondary Logon Service fails to properly manage requests in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could then install programs; view, change, or...
Last Update Date: 13 Apr 2016 12:04 Release Date: 13 Apr 2016 6840 Views

RISK: High Risk

High Risk

Microsoft Windows Hyper-V Multiple Vulnerabilties

Hyper-V Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on...
Last Update Date: 13 Apr 2016 12:03 Release Date: 13 Apr 2016 6064 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OLE Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code.
Last Update Date: 13 Apr 2016 12:03 Release Date: 13 Apr 2016 6071 Views

RISK: High Risk

High Risk

Microsoft Office Multiple Vulnerabilities

Multiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user is logged on with administrative...
Last Update Date: 13 Apr 2016 12:00 Release Date: 13 Apr 2016 6033 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft .NET Framework fails to properly validate input before loading libraries. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 13 Apr 2016 12:00 Release Date: 13 Apr 2016 6044 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Microsoft XML Core Services (MSXML) parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system.
Last Update Date: 13 Apr 2016 12:00 Release Date: 13 Apr 2016 6829 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Internet Explorer Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. DLL Loading Remote Code Execution VulnerabilityA...
Last Update Date: 13 Apr 2016 11:59 Release Date: 13 Apr 2016 6365 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple Microsoft Edge Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory. The vulnerabilities could corrupt memory that enables an attacker to execute arbitrary code in the context of the current user. Microsoft Edge Elevation of PrivilegeAn elevation of privilege vulnerability...
Last Update Date: 13 Apr 2016 11:59 Release Date: 13 Apr 2016 6073 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Component Multiple Vulnerabilities

Multiple Win32k Elevation of Privilege VulnerabilitiesElevation of privilege vulnerabilities exist when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change...
Last Update Date: 13 Apr 2016 11:59 Release Date: 13 Apr 2016 6333 Views

RISK: High Risk

High Risk

Adobe Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Creative Cloud Desktop Application and RoboHelp Server, which could be exploited by remote attackers to execute arbitrary code and disclose sensitive information.
Last Update Date: 13 Apr 2016 11:26 Release Date: 13 Apr 2016 6305 Views

RISK: High Risk

High Risk

Samba 'Badlock' Vulnerabilities

Multiple vulnerabilities, known as Badlock, have been identified in Samba. Exploitation of these vulnerabilities may allow a remote attacker to take control of an affected system or create a denial-of-service condition.
Last Update Date: 13 Apr 2016 10:15 Release Date: 13 Apr 2016 6700 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Content Validation Vulnerability

A vulnerability has been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 7 Apr 2016 08:54 Release Date: 7 Apr 2016 6926 Views

RISK: Extremely High Risk

Extremely High Risk

Locky Ransomware Encrypts Victim Data

A new variant of ransomware known as Locky has been spreading quickly, through massive spam campaigns and compromised websites. HKCERT has received a lot of reports from victims.  How Locky was spread Spam email Some victims were infected by opening attachments in spam emails: ...
Last Update Date: 6 Apr 2016 Release Date: 18 Mar 2016 14971 Views

RISK: Medium Risk

Medium Risk

Squid Cache Multiple Vulnerabilties

Mulitple vulnerabilities were identified in Squid. A remote user can cause denial of service conditions. A local user can obtain potentially sensitive information from system memory.
Last Update Date: 5 Apr 2016 12:06 Release Date: 5 Apr 2016 6442 Views

RISK: Medium Risk

Medium Risk

Linux Kernel Denial of Service Vulnerability

A vulnerability was identified in the Linux kernel. A local user can corrupt the target filesystem and cause denial of service condition.
Last Update Date: 5 Apr 2016 12:06 Release Date: 5 Apr 2016 6287 Views

RISK: Medium Risk

Medium Risk

Red Hat JBoss Remote Code Execution Vulnerability

 A vulnerability was identified in Red Hat JBoss. A remote user can execute arbitrary code on the target system.
Last Update Date: 1 Apr 2016 09:15 Release Date: 1 Apr 2016 6327 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. A remote attacker can exploit these vulnerabilities to perform remote code execution on the targeted system.
Last Update Date: 29 Mar 2016 10:13 Release Date: 29 Mar 2016 6277 Views

RISK: Medium Risk

Medium Risk

Oracle Java SE Remote Code Execution Vulnerability

A vulnerabilities has been identified in Oracle Java SE. A remote attacker can exploit this vulnerability to take control of an affected system.
Last Update Date: 29 Mar 2016 10:13 Release Date: 29 Mar 2016 6363 Views

RISK: Medium Risk

Medium Risk

MIT Kerberos Remote Code Execution Vulnerability

A Vulnerability has been identified in MIT Kerberos, a remote user can exploit this vulnerability to perform remote code execution on the targeted system.
Last Update Date: 29 Mar 2016 10:09 Release Date: 29 Mar 2016 6447 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco products. Exploitation of these vulnerabilities could allow a remote attacker to create a denial-of-service condition.
Last Update Date: 24 Mar 2016 09:43 Release Date: 24 Mar 2016 6500 Views

RISK: Medium Risk

Medium Risk

Apple products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple products:iOS, watchOS, tvOS, Xcode, OS X El Capitan, OS X Server 5.1, and SafariA remote attacker can exploit these vulnerabilities to perform remote code execution and take control on the targeted system.
Last Update Date: 23 Mar 2016 Release Date: 22 Mar 2016 6930 Views

RISK: Medium Risk

Medium Risk

Moodle Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Moodle, A remote user can exploit these vulnerabilities to obtain potentially sensitive information, bypass security controls, conduct Cross-Site Scripting attack on the targeted system.
Last Update Date: 22 Mar 2016 09:49 Release Date: 22 Mar 2016 6722 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which could potentially allow an attacker to take control of the affected system.   Note: One of the vulnerabilities was being used in limited, targeted attacks.
Last Update Date: 17 Mar 2016 Release Date: 11 Mar 2016 7079 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.
Last Update Date: 11 Mar 2016 09:47 Release Date: 11 Mar 2016 6658 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6160 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Security Feature Bypass Vulnerability

null
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6253 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability

This security update resolves an elevation of privilege vulnerability in Microsoft Windows when the Windows USB Mass Storage Class driver fails to properly validate objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6276 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Secondary Logon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could then install programs; ...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6846 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when Microsoft Windows fails to properly sanitize handles in memory. An attacker who successfully exploited the vulnerability could run arbitrary code as System. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6173 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6220 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple Microsoft Edge Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Microsoft Edge Information Disclosure VulnerabilityAn information...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6039 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Library Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Windows fails to properly validate input before loading certain libraries. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 5904 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows PDF Library Remote Code Execution Vulnerabilities

Multiple remote code execution vulnerabilities exist in Microsoft Windows if a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user.
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6173 Views

RISK: High Risk

High Risk

Adobe Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat, Reader and Digital Editions. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6329 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 10 Mar 2016 09:36 Release Date: 10 Mar 2016 6413 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Multiple Win32k elevation of privilege vulnerabilities exist when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6083 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OLE Remote Code Execution Vulnerabilities

Multiple remote code execution vulnerabilities exist when Microsoft Windows OLE fails to properly validate user input. An attacker could use the vulnerabilities to execute malicious code.
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6015 Views

RISK: Medium Risk

Medium Risk

Samba Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Samba. A remote user can cause the target service to crash, obtain potentially sensitive information on the target system, and overwrite access control lists.
Last Update Date: 10 Mar 2016 09:26 Release Date: 10 Mar 2016 6217 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Remote Code Execution Vulnerabilities

Multiple remote code execution vulnerabilities exist in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens specially crafted media content that is hosted on a website. To exploit the vulnerabilities, an attacker could host media content on a website...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 5996 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphic Fonts Remote Code Execution Vulnerabilities

OpenType Font Parsing VulnerabilityA denial of service vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could cause a denial of service condition. For systems...
Last Update Date: 10 Mar 2016 Release Date: 9 Mar 2016 6113 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 9 Mar 2016 17:35 Release Date: 9 Mar 2016 6412 Views

RISK: Medium Risk

Medium Risk

ISC DHCP Server TCP Connection Validation Vulnerability

A vulnerability has been identified in ISC DHCP server. Exploitation of this vulnerability may allow a remote attacker to cause a denial-of-service condition.
Last Update Date: 9 Mar 2016 17:35 Release Date: 9 Mar 2016 6240 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by attacker to cause bypass security controls, obtain potentially sensitive information or arbitrary code to be executed on the target user's system.
Last Update Date: 7 Mar 2016 10:44 Release Date: 7 Mar 2016 5974 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabiliies were identified in multiple Cisco Products. A vulnerability was identified in Cisco NX-OS on Nexus 3000 Series devices. A remote user can gain root access to the target system. A vulnerability was identified in Cisco NX-OS. A remote user can...
Last Update Date: 3 Mar 2016 09:32 Release Date: 3 Mar 2016 6017 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities were discovered in OpenSSL. A remote user can decrypt TLS sessions in certain cases. Other vulnerabilities could cause denial of service on the target system.   TLS sessions could be decrypted by using a server supporting SSLv2. This cross-protocol attack is known as...
Last Update Date: 2 Mar 2016 14:22 Release Date: 2 Mar 2016 6534 Views

RISK: Medium Risk

Medium Risk

avast! Products Heap Overflow Vulnerability

A vulnerability was identified in avast! Products, A local user can gain system privileges on the target system.
Last Update Date: 29 Feb 2016 Release Date: 25 Feb 2016 5971 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by attacker to cause denial of service or obtain elevated privileges on the target system.
Last Update Date: 29 Feb 2016 10:47 Release Date: 29 Feb 2016 6068 Views

RISK: Medium Risk

Medium Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which can be exploited by remote user to take control of the target system.
Last Update Date: 26 Feb 2016 09:21 Release Date: 26 Feb 2016 6086 Views

RISK: Medium Risk

Medium Risk

Linux Kernel Arbitrary Code Execution/ Denial of Service Vulnerability

A vulnerability was identified in Linux Kernel. A physically local user can cause denial of service conditions or execute arbitrary code on the target system.
Last Update Date: 24 Feb 2016 09:22 Release Date: 24 Feb 2016 6154 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache Tomcat. A remote user can exploit these vulnerabilities to bypass Security Restriction, elevation of Privilege and obtain sensitive Information on the target user's system.
Last Update Date: 23 Feb 2016 09:35 Release Date: 23 Feb 2016 6344 Views

RISK: Medium Risk

Medium Risk

GNU glibc Buffer Overflow vulnerability

A vulnerability has been identified in GNU glibc, which contains a buffer overflow vulnerability in the DNS resolver. Exploitation of this vulnerability may allow a remote attacker to take control of an affected system.
Last Update Date: 18 Feb 2016 13:34 Release Date: 18 Feb 2016 6141 Views

RISK: High Risk

High Risk

LibreOffice Multiple Vulnerabilities

Multiple vulnerabilities have been identified in LibreOffice. A remote user can cause arbitrary code to be executed on the target user's system.   Note: Vendor patch is currently not available.
Last Update Date: 18 Feb 2016 09:57 Release Date: 18 Feb 2016 6163 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox ESR Remote Code Execution Vulnerability

A vulnerability was identified in Mozilla Firefox. A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 17 Feb 2016 09:42 Release Date: 17 Feb 2016 6150 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Denial of Service Vulnerabilities

.NET Framework Stack Overflow Denial of Service VulnerabilityA denial of service vulnerability exists when .NET Framework fails to properly handle certain Extensible Stylesheet Language Transformations (XSLT). An attacker who successfully exploited this vulnerability could cause server performance to degrade significantly enough to cause a denial of...
Last Update Date: 17 Feb 2016 Release Date: 11 Feb 2016 6414 Views

RISK: Medium Risk

Medium Risk

ISC BIND NXDOMAIN Redirection Processing Vulnerability

A vulnerability has been identified in BIND. A remote user can cause the target service to crash.
Last Update Date: 17 Feb 2016 Release Date: 11 Feb 2016 5960 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Bypass Security Restrictions Vulnerability

A vulnerability has been identified in Mozilla Firefox, exploitation of this vulnerability could allow a remote attacker bypass security controls on the target system.
Last Update Date: 15 Feb 2016 10:25 Release Date: 15 Feb 2016 6174 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Internet Key Exchange Buffer Overflow Vulnerability

A vulnerability has been identified in Cisco ASA software. Exploitation of this vulnerability could allow a remote attacker to take control of an affected system.
Last Update Date: 12 Feb 2016 Release Date: 11 Feb 2016 6461 Views

RISK: High Risk

High Risk

Microsoft NPS RADIUS Server Denial of Service Vulnerabilty

A denial of service vulnerability exists when a Network Policy Server (NPS) improperly handles a Remote Authentication Dial-In User Service (RADIUS) authentication request. An unauthenticated attacker who successfully exploited this vulnerability could send specially crafted username strings to a Network Policy Server (...
Last Update Date: 11 Feb 2016 12:26 Release Date: 11 Feb 2016 6521 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Federation Services Denial of Service Vulnerability

A denial of service vulnerability exists when Active Directory Federation Services (ADFS) attempts to process certain input during forms-based authentication. An attacker who successfully exploits this vulnerability by sending certain input during forms-based authentication could cause the server...
Last Update Date: 11 Feb 2016 12:26 Release Date: 11 Feb 2016 6033 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or...
Last Update Date: 11 Feb 2016 12:25 Release Date: 11 Feb 2016 6066 Views

RISK: Medium Risk

Medium Risk

Microsoft Remote Desktop Protocol Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Remote Desktop Protocol (RDP) when an attacker logs on to the target system using RDP and sends specially crafted data over the authenticated connection. An attacker who successfully exploited this vulnerability could execute code with elevated privileges. An attacker...
Last Update Date: 11 Feb 2016 12:25 Release Date: 11 Feb 2016 6081 Views

RISK: Medium Risk

Medium Risk

Microsoft WebDAV Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Microsoft Web Distributed Authoring and Versioning (WebDAV) client when WebDAV improperly validates input. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated permissions.
Last Update Date: 11 Feb 2016 12:24 Release Date: 11 Feb 2016 5992 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption Vulnerabilities Multiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the...
Last Update Date: 11 Feb 2016 12:24 Release Date: 11 Feb 2016 5960 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Windows Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 11 Feb 2016 12:24 Release Date: 11 Feb 2016 5958 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Journal Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is...
Last Update Date: 11 Feb 2016 12:24 Release Date: 11 Feb 2016 5878 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows PDF Library Remote Code Execultion Vulnerabilities

Microsoft Windows Reader VulnerabilityA remote code execution vulnerability exists in Microsoft Windows when a specially crafted file is opened in Windows Reader. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on...
Last Update Date: 11 Feb 2016 12:23 Release Date: 11 Feb 2016 6044 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Browser Spoofing VulnerabilityA spoofing vulnerability exists when a Microsoft browser does not properly parse HTTP responses. An attacker who successfully exploited this vulnerability could trick a user by redirecting them to a specially crafted website. The specially crafted website could spoof content or be used as a...
Last Update Date: 11 Feb 2016 12:23 Release Date: 11 Feb 2016 5794 Views