Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

DLL Loading Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Internet Explorer improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view...
Last Update Date: 11 Feb 2016 12:23 Release Date: 11 Feb 2016 6026 Views

RISK: Medium Risk

Medium Risk

Microsoft ASP.NET Access Control Vulnerability

A vulnerability has been identified in Microsoft ASP.NET. A remote user can conduct cross-site request forgery attacks to remove two-factor authentication. Password authentication is not affected.
Last Update Date: 11 Feb 2016 11:31 Release Date: 11 Feb 2016 6135 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 11 Feb 2016 11:29 Release Date: 11 Feb 2016 6094 Views

RISK: High Risk

High Risk

Adobe Connect / Experience Manager / Photoshop CC / Bridge CC Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Connect, Experience Manager, Photoshop CC and Bridge CC. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 11 Feb 2016 11:28 Release Date: 11 Feb 2016 6106 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 11 Feb 2016 11:28 Release Date: 11 Feb 2016 6300 Views

RISK: High Risk

High Risk

Oracle Java Windows Installation Vulnerability

A vulnerability has been identified in Oracle Java SE. A remote user can cause arbitrary code to be executed on the target user's system.
Last Update Date: 11 Feb 2016 11:27 Release Date: 11 Feb 2016 6272 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Two vulnerabilities were identified in WordPress. A remote user can conduct server-side request forgery attacks. A remote user can redirect the target user's browser to an arbitrary site.
Last Update Date: 5 Feb 2016 09:28 Release Date: 5 Feb 2016 5865 Views

RISK: Medium Risk

Medium Risk

Linux Kernel Multiple Vulnerabilities

Two vulnerabilities were identified in the Linux kernel. A local user can obtain potentially sensitive information from system memory.A local user can cause denial of service conditions on the target system.
Last Update Date: 1 Feb 2016 15:13 Release Date: 1 Feb 2016 6123 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

 Two vulnerabilities were identified in OpenSSL. A remote user can recover keys in certain cases. A remote user can negotiate disabled ciphers.
Last Update Date: 29 Jan 2016 10:03 Release Date: 29 Jan 2016 6188 Views

RISK: Medium Risk

Medium Risk

Cisco Multiple Products HTTP Request Validation Vulnerability

A vulnerability has been identified in the web-based management interface of Cisco RV220W Wireless Network Security Firewall devices. Exploitation of this vulnerability could allow a remote attacker to take control of an affected device.
Last Update Date: 28 Jan 2016 09:44 Release Date: 28 Jan 2016 5878 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which could allow a remote attacker to take control of an affected system.
Last Update Date: 27 Jan 2016 09:33 Release Date: 27 Jan 2016 5980 Views

RISK: Medium Risk

Medium Risk

Xen Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Xen, a remote attacker can exploit these vulnerabilities to trigger Denial Of Service, Elevation Of Privilege, Security Restriction Bypass and disclose Sensitive Information on the targeted system.
Last Update Date: 26 Jan 2016 09:42 Release Date: 26 Jan 2016 5901 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. A remote user can bypass security controls, obtain potentially sensitive information, spoof URLs and cause arbitrary code to be executed on the target user's system.
Last Update Date: 25 Jan 2016 10:32 Release Date: 25 Jan 2016 6017 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 21 Jan 2016 Release Date: 20 Jan 2016 6371 Views

RISK: High Risk

High Risk

Cisco Multiple Products CGI Validation Vulnerability

Multiple vulnerabilities have been identified in Cisco Modular Encoding Platform D9036 software, Unified Computing System (UCS) Manager software, and Firepower 9000 Series devices. Exploitation of these vulnerabilities could allow a remote attacker to take control of an affected device.
Last Update Date: 21 Jan 2016 09:39 Release Date: 21 Jan 2016 6018 Views

RISK: High Risk

High Risk

Apple iOS / OS X / Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, OS X El Capitan and Safari. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 21 Jan 2016 09:39 Release Date: 21 Jan 2016 6021 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities were identified in ISC BIND. A remote user can cause the target service to crash.
Last Update Date: 20 Jan 2016 09:49 Release Date: 20 Jan 2016 6171 Views

RISK: High Risk

High Risk

OpenSSH Multiple Vulnerabilities

Two vulnerabilities were identified in OpenSSH. A remote authenticated server can obtain potentially sensitive information from OpenSSH client memory on the target system or potentially execute arbitrary code on the target client system.
Last Update Date: 15 Jan 2016 10:12 Release Date: 15 Jan 2016 6483 Views

RISK: Medium Risk

Medium Risk

DHCP Denial of Service Vulnerability

 A vulnerability was identified in DHCP. A badly formed packet with an invalid IPv4 UDP length field can cause a DHCP server, client, or relay program to terminate abnormally.
Last Update Date: 15 Jan 2016 10:12 Release Date: 15 Jan 2016 6153 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Spoofing Vulnerabilities

Multiple spoofing vulnerabilities exist in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited the vulnerabilities could perform script or content injection attacks, and attempt to trick the user into disclosing sensitive information. An attacker...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 6074 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

Multiple vulnerabilities exist in Windows while validating reparse points being set by sandbox applications. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 5956 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Multiple DLL Loading Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist when Windows improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited the vulnerabilities could elevate their privileges on a targeted system. DirectShow Heap Corruption Remote Code Execution VulnerabilityA...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 6285 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Silverlight decodes strings using a malicious decoder that can return negative offsets that cause Silverlight to replace unsafe object headers with contents provided by an attacker. In a web-browsing scenario, an attacker who successfully exploited this vulnerability could...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 6118 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities

Windows GDI32.dll ASLR Bypass VulnerabilityA security feature bypass vulnerability exists in the way that the Windows graphics device interface handles objects in memory, allowing an attacker to retrieve information that could lead to an Address Space Layout Randomization (ASLR) bypass. Win32k Remote Code Execution...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 5876 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 5925 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Cumulative Security Update

A remote code execution vulnerability exists in the way that the VBScript engine renders when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 5928 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Edge Memory Corruption VulnerabilityA remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Scripting Engine Memory Corruption VulnerabilityA remote code...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 5862 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the VBScript engine renders when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 6089 Views

RISK: High Risk

High Risk

Fortinet FortiGate/FortiOS Remote Users Access Vulnerability

A vulnerability has been identified in Fortinet FortiGate/FortiOS, a remote user can gain access to the target system via SSH using an undocumented account.
Last Update Date: 14 Jan 2016 12:05 Release Date: 14 Jan 2016 6263 Views

RISK: Medium Risk

Medium Risk

ISC DHCP UDP Payload Validation Vulnerability

A vulnerability has been identified in ISC Dynamic Host Configuration Protocol (DHCP) software. Exploitation of this vulnerability may allow a remote attacker to cause a denial-of-service condition.
Last Update Date: 13 Jan 2016 10:12 Release Date: 13 Jan 2016 5999 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed, and bypass security controls on the target system.
Last Update Date: 13 Jan 2016 09:48 Release Date: 13 Jan 2016 6073 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime. Exploitation of one of these vulnerabilities may allow an attacker to take control of an affected system.
Last Update Date: 11 Jan 2016 10:17 Release Date: 11 Jan 2016 5801 Views

RISK: High Risk

High Risk

Mozilla Firefox TLS ServerKeyExchange Vulnerability

A vulnerability has been identified in Mozilla Firefox. Exploitation of this vulnerability may allow a remote attacker to obtain sensitive information from an affected system.
Last Update Date: 11 Jan 2016 10:17 Release Date: 11 Jan 2016 5921 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

 Multiple vulnerabilities were identified in PHP. A remote user can gain elevated privileges. A remote user can execute arbitrary code on the target system. A remote user can obtain potentially sensitive information on the target system.
Last Update Date: 8 Jan 2016 10:24 Release Date: 8 Jan 2016 5824 Views

RISK: Medium Risk

Medium Risk

dhcpd Multiple Vulnerabilities

 Two vulnerabilities were identified in dhcpcd. A remote user can execute arbitrary code on the target system. A remote user can cause the target service to crash.
Last Update Date: 8 Jan 2016 10:23 Release Date: 8 Jan 2016 5938 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Wireshark, remote attacker can exploit these vulnerabilities to trigger denial of service condition in the targeted system.
Last Update Date: 7 Jan 2016 Release Date: 5 Jan 2016 5905 Views

RISK: High Risk

High Risk

Google Android Multiple Vulnerabilities

Multiple vulnerabilities were idenitifed in Google Android, which could be exploited to cause denial of service, obtain sensitive information, obtain elevated privilege and execute arbitrary code on the target system.
Last Update Date: 7 Jan 2016 09:25 Release Date: 7 Jan 2016 6002 Views

RISK: Medium Risk

Medium Risk

Samba Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Samba , remote attacker can exploit these vulnerabilities to trigger denial of service, access confidential data and provide misleading information in the targeted system.    
Last Update Date: 6 Jan 2016 Release Date: 5 Jan 2016 6113 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple vulnerabilities

Multiple vulerabilities were identified in Adobe Flash Player. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system. CVE-2015-8651 is being used in limited, targeted attacks.
Last Update Date: 6 Jan 2016 Release Date: 29 Dec 2015 6704 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XE Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS XE. A remote user on the local network can cause the target system to crash.
Last Update Date: 28 Dec 2015 10:08 Release Date: 28 Dec 2015 5979 Views

RISK: High Risk

High Risk

Joomla Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Joomla. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected website.
Last Update Date: 24 Dec 2015 09:11 Release Date: 24 Dec 2015 5981 Views

RISK: Medium Risk

Medium Risk

VMWare products Multiple Vulnerabilities

Oracle JRE is updated in VMware products to address critical security issue that existed in earlier releases of Oracle JRE.VMware products that use Flex BlazeDS may be affected by a flaw the processing of XML External Entity (XXE) requests. A crafted XML request sent to...
Last Update Date: 23 Dec 2015 Release Date: 22 Dec 2015 6158 Views

RISK: Medium Risk

Medium Risk

Juniper ScreenOS Multiple Vulnerabilities

 Multiple vulnerabilities were identified in Juniper ScreenOS. An unauthorized remote attacker could gain privileged access to the device and compromise the confidentiality and integrity of its data.
Last Update Date: 23 Dec 2015 Release Date: 22 Dec 2015 6239 Views

RISK: High Risk

High Risk

Apache TomEE Remote Code Execution Vulnerability

A vulnerability was identified in Apache TomEE, which could allow remote attackers to execute arbitrary code. Note: No patch is currently available.
Last Update Date: 22 Dec 2015 Release Date: 16 Dec 2015 5956 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Firefox ESR. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 22 Dec 2015 Release Date: 16 Dec 2015 6106 Views

RISK: Medium Risk

Medium Risk

BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities were identified in ISC BIND. A remote user can cause the target service to crash.
Last Update Date: 22 Dec 2015 Release Date: 16 Dec 2015 5899 Views

RISK: High Risk

High Risk

Google Chrome Multiple vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 22 Dec 2015 Release Date: 16 Dec 2015 5830 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache HTTPComponents that are used in IBM WebSphere Application Server. Although IBM WebSphere Application server is not vulnerable to these, other products or applications that use these libraries could be vulnerable.
Last Update Date: 17 Dec 2015 09:21 Release Date: 17 Dec 2015 5926 Views

RISK: High Risk

High Risk

Joomla Remote Code Execution Vulnerability

A vulnerability has been identified in Joomla, which can be exploited by malicious users to perform remote code execution. This vulnerability is being actively exploited.
Last Update Date: 15 Dec 2015 09:50 Release Date: 15 Dec 2015 5943 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by remote attacker to execute arbitrary code.
Last Update Date: 14 Dec 2015 16:07 Release Date: 14 Dec 2015 5731 Views

RISK: Medium Risk

Medium Risk

Fortinet Product OpenSSL Multiple vulnerabilities

Multiple vulnerabilities have been identified in Fortinet product. A remote attacker can cause denial of service attack.
Last Update Date: 14 Dec 2015 15:16 Release Date: 14 Dec 2015 5937 Views

RISK: High Risk

High Risk

Google Chrome Multiple vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 10 Dec 2015 09:30 Release Date: 10 Dec 2015 5865 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were reported in Adobe Flash Player. A remote user can cause arbitrary code to be executed and bypass security controls on the target system.
Last Update Date: 9 Dec 2015 15:23 Release Date: 9 Dec 2015 6397 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Multiple elevation of privilege vulnerabilities exist due to the way the Windows kernel handles objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create...
Last Update Date: 9 Dec 2015 14:00 Release Date: 9 Dec 2015 6055 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Center Multiple Vulnerabilities

Media Center Library Parsing RCE Vulnerability A vulnerability exists in Windows Media Center that could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploited this vulnerability could take control...
Last Update Date: 9 Dec 2015 14:00 Release Date: 9 Dec 2015 6095 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows PGM Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows Pragmatic General Multicast (PGM) protocol that is caused when an attacker-induced race condition results in references to memory contents that have already been freed. An attacker who successfully exploited this vulnerability could execute code with elevated...
Last Update Date: 9 Dec 2015 14:00 Release Date: 9 Dec 2015 5958 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Multiple remote code execution vulnerabilities exist when Windows improperly validates input before loading libraries. An attacker who successfully exploited the vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts...
Last Update Date: 9 Dec 2015 14:00 Release Date: 9 Dec 2015 6098 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption Vulnerabilities Multiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the...
Last Update Date: 9 Dec 2015 13:55 Release Date: 9 Dec 2015 6126 Views

RISK: Medium Risk

Medium Risk

Microsoft Uniscribe Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Windows Uniscribe improperly parses specially crafted fonts. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
Last Update Date: 9 Dec 2015 13:55 Release Date: 9 Dec 2015 6276 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Multiple Vulnerabilities

Microsoft Silverlight RCE Vulnerability A remote code execution vulnerability exists when Microsoft Silverlight incorrectly handles certain open and close requests that can result in read- and write-access violations. Multiple Microsoft Silverlight Information Disclosure Vulnerabilities Multiple information disclosure vulnerabilities exist when Silverlight fails to properly...
Last Update Date: 9 Dec 2015 13:55 Release Date: 9 Dec 2015 6509 Views

RISK: Medium Risk

Medium Risk

Microsoft Graphics Component Remote Code Execution Vulnerabilities

Multiple remote code execution vulnerabilities exist when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited these vulnerabilities could install programs; view, change, or delete data; or create new accounts with full user rights.
Last Update Date: 9 Dec 2015 13:55 Release Date: 9 Dec 2015 6124 Views

RISK: High Risk

High Risk

Microsoft Windows DNS Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly parse requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows servers that are configured as DNS...
Last Update Date: 9 Dec 2015 13:54 Release Date: 9 Dec 2015 6204 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Cumulative Security Update

Scripting Engine Information Disclosure Vulnerability An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data. Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability...
Last Update Date: 9 Dec 2015 13:54 Release Date: 9 Dec 2015 6158 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple Microsoft Edge Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Microsoft Browser Elevation of Privilege VulnerabilityAn...
Last Update Date: 9 Dec 2015 13:54 Release Date: 9 Dec 2015 6294 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Internet Explorer Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Multiple Microsoft Browser XSS Filter Bypass...
Last Update Date: 9 Dec 2015 13:54 Release Date: 9 Dec 2015 6383 Views

RISK: High Risk

High Risk

Apple Multiple OS and Applications Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, tvOS, OS X, watchOS, Safari and Xcode, which can be exploited by remote attacker to execute arbitrary code.
Last Update Date: 9 Dec 2015 12:42 Release Date: 9 Dec 2015 6380 Views

RISK: Medium Risk

Medium Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL. A remote user can cause the target service to crash and obtain potentially sensitive information on the target system.A remote server can send a specially crafted ServerKeyExchange for an anonymous DH ciphersuite with the value of p set to to...
Last Update Date: 9 Dec 2015 Release Date: 7 Dec 2015 6150 Views

RISK: High Risk

High Risk

Apache OpenOffice Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apache OpenOffice, which can be exploited by remote attacker to execute arbitrary code on the target system.A remote user can create a specially crafted document that, when loaded by the target user, will trigger a bug in the handling...
Last Update Date: 7 Dec 2015 Release Date: 9 Nov 2015 6053 Views

RISK: Medium Risk

Medium Risk

Dell eDellRoot Certificate Spoofing Vulnerability

A vulnerability was identified in Dell Foundation Services of Dell systems. It installs the eDellRoot certificate that includes a private key on Microsoft Windows systems. This allows attackers to create trusted certificates and perform impersonation, man-in-the-middle (MiTM), and passive...
Last Update Date: 7 Dec 2015 Release Date: 25 Nov 2015 6581 Views

RISK: High Risk

High Risk

Google Chrome Multiple vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome.Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 3 Dec 2015 09:23 Release Date: 3 Dec 2015 5930 Views

RISK: High Risk

High Risk

Adobe Products Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Adobe ColdFusion, LiveCycle Data Services, and Adobe Premiere Clip.A remote attacker may exploit these vulnerabilities to take control on the targeted system.
Last Update Date: 18 Nov 2015 11:11 Release Date: 18 Nov 2015 6281 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Schannel Spoofing Vulnerability

A spoofing vulnerability exists in Microsoft Windows that is caused by a weakness in all supported versions of the TLS protocol. An attacker who successfully exploited this vulnerability could impersonate a victim on any other server that uses the same credentials as those used between the client and server...
Last Update Date: 17 Nov 2015 Release Date: 11 Nov 2015 6231 Views

RISK: High Risk

High Risk

ntp multiple vulnerabilities

 Multiple vulnearabilities were found in ntp, which can be exploited by malicious remote users to crash the ntp daemon.
Last Update Date: 17 Nov 2015 Release Date: 3 Nov 2015 6172 Views

RISK: High Risk

High Risk

Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability

A vulnerability was identified in Cisco IOS. A remote user can bypass access controls on the target system. A remote user connected to a tunnel interface can bypass the access control lists (ACLs) when the physical interface ACLs permit the traffic to pass.
Last Update Date: 17 Nov 2015 Release Date: 16 Nov 2015 6399 Views

RISK: Medium Risk

Medium Risk

Xen Denial of Service Vulnerabilities

 Multiple vulnerabilities have been identified in Xen, which can be exploited by malicious HVM guest administors to cause a denial of services.
Last Update Date: 17 Nov 2015 09:50 Release Date: 17 Nov 2015 6159 Views

RISK: High Risk

High Risk

Google Chrome Multiple vulnerabilities

Multiple vulnerabilities in Google Chrome and Chrome OS. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 12 Nov 2015 10:25 Release Date: 12 Nov 2015 6165 Views

RISK: Medium Risk

Medium Risk

Microsoft Skype for Business Server and Microsoft Lync Information Dislcosure Vulnerability

An information disclosure vulnerability exists when Skype for Business and Microsoft Lync clients improperly sanitize specially crafted content. An attacker who successfully exploited the vulnerability could execute HTML and JavaScript content in the Skype for Business or Lync context. The attacker could use this vulnerability to open a...
Last Update Date: 11 Nov 2015 16:51 Release Date: 11 Nov 2015 6247 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kerberos Security Feature Bypass Vulnerability

A security feature bypass exists in Windows when Kerberos fails to check the password change of a user signing into a workstation. An attacker could bypass Kerberos authentication on a target machine and decrypt drives protected by BitLocker.
Last Update Date: 11 Nov 2015 16:50 Release Date: 11 Nov 2015 6492 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IPSec Denial of Service Vulnerability

A denial of service vulnerability exists in Windows when the Internet Protocol Security (IPSec) service improperly handles encryption negotiation. An attacker who successfully exploited the vulnerability could cause the system to become nonresponsive.
Last Update Date: 11 Nov 2015 16:50 Release Date: 11 Nov 2015 6162 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Winsock Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when Winsock makes a call to a memory address without verifying that the address is valid. An attacker who successfully exploited this vulnerability could gain elevated privileges on a targeted system.
Last Update Date: 11 Nov 2015 16:49 Release Date: 11 Nov 2015 6299 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Elevation of Privilege Vulnerabilities

.NET Information Disclosure VulnerabilityAn information disclosure vulnerability exists in the .NET Framework DTD parsing of certain specially crafted XML files. An attacker who successfully exploited this vulnerability could gain read access to local files on the target system. .NET Elevation of Privilege VulnerabilityAn elevation of privilege...
Last Update Date: 11 Nov 2015 16:49 Release Date: 11 Nov 2015 6512 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows NDIS Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when NDIS fails to check the length of a buffer prior to copying memory into it. An attacker who successfully exploited this vulnerability could gain elevated privileges on a targeted system.
Last Update Date: 11 Nov 2015 16:48 Release Date: 11 Nov 2015 6249 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 11 Nov 2015 16:48 Release Date: 11 Nov 2015 6248 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Multiple Windows Kernel Memory Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or...
Last Update Date: 11 Nov 2015 16:47 Release Date: 11 Nov 2015 6213 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Journal Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited the vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative...
Last Update Date: 11 Nov 2015 16:47 Release Date: 11 Nov 2015 6119 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple Microsoft Edge Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory. The vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Microsoft Browser ASLR BypassA security feature...
Last Update Date: 11 Nov 2015 16:46 Release Date: 11 Nov 2015 5979 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Internet Explorer Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Scripting Engine Memory Corruption VulnerabilityA remote...
Last Update Date: 11 Nov 2015 16:46 Release Date: 11 Nov 2015 6156 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed and modify files on the target system.
Last Update Date: 11 Nov 2015 10:27 Release Date: 11 Nov 2015 6464 Views

RISK: Extremely High Risk

Extremely High Risk

Apache Commons Java Library Remote Code Execution Vulnerability

A vulnerability was identified in Apache Commons Components. A remote user can execute arbitrary code on the target system.  
Last Update Date: 10 Nov 2015 11:36 Release Date: 10 Nov 2015 6368 Views

RISK: Medium Risk

Medium Risk

LibreOffice Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in LibreOffice, A remote user can exploit these vulnerabilities to perform remote code execution and obtain files on the target system. A remote user can create content that, when loaded by the target user, will execute arbitrary code and obtain files...
Last Update Date: 6 Nov 2015 10:30 Release Date: 6 Nov 2015 6062 Views

RISK: High Risk

High Risk

MIT Kerberos Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in MIT Kerberos, a remote user can exploit these vulnerabilities to crash the target service of system.
Last Update Date: 6 Nov 2015 10:29 Release Date: 6 Nov 2015 6024 Views

RISK: High Risk

High Risk

Google Android Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Android. A remote user can cause arbitrary code to be executed on the target user's system. An application can gain elevated privileges.
Last Update Date: 5 Nov 2015 10:32 Release Date: 5 Nov 2015 6069 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Firefox and Firefox ESR. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 5 Nov 2015 10:31 Release Date: 5 Nov 2015 5932 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Shockwave Player, which could allow lead to remote code execution.
Last Update Date: 5 Nov 2015 Release Date: 28 Oct 2015 5920 Views

RISK: Medium Risk

Medium Risk

PHP Phar Extension Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP Phar Extension, which could lead to denial of service and information disclosure.
Last Update Date: 5 Nov 2015 Release Date: 28 Oct 2015 5990 Views

RISK: Medium Risk

Medium Risk

IBM Websphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM Websphere Application Server, which could allow elevation of privilege, unauthorized access and information disclosure.
Last Update Date: 4 Nov 2015 09:24 Release Date: 4 Nov 2015 5859 Views

RISK: High Risk

High Risk

Joomla Multiple SQL injection vulnerabilities

Multiple vulnerabilities were identified in Joomla, which can be exploited by unauthorized remote user to gain administrator privileges by hijacking the administrator session. Following exploitation of the vulnerability, the attacker may gain full control of the web site and execute additional attacks.
Last Update Date: 27 Oct 2015 09:57 Release Date: 27 Oct 2015 6123 Views

RISK: High Risk

High Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 22 Oct 2015 17:34 Release Date: 22 Oct 2015 6075 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 22 Oct 2015 17:34 Release Date: 22 Oct 2015 6256 Views

RISK: Medium Risk

Medium Risk

Apple Keynote, Apple Pages, Apple Numbers and Apple iWork Multiple vulnerabilities

Multiple vulnerabilities have been identified in Apple Keynote, Apple Pages, Apple Numbers and Apple iWork, which can be exploited by remote attacker to execute arbitrary code and obtain potentially sensitive information on the target system.
Last Update Date: 19 Oct 2015 17:28 Release Date: 19 Oct 2015 5946 Views