Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Adobe Flash Player Execute Arbitrary Code Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attacker to execute arbitrary code on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a type...
Last Update Date: 19 Oct 2015 17:28 Release Date: 19 Oct 2015 6207 Views

RISK: High Risk

High Risk

Mozilla Firefox Cross-Origin Resource Sharing (CORS) Implementation Vulnerability

A vulnerability has identified in  Mozilla Firefox, a user can exploit this vulnerability to allow a malicious page to access private data from other origins.
Last Update Date: 16 Oct 2015 09:24 Release Date: 16 Oct 2015 6599 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

Multiple Windows Kernel Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist in the way the Windows kernel handles objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or...
Last Update Date: 14 Oct 2015 10:22 Release Date: 14 Oct 2015 6310 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user is...
Last Update Date: 14 Oct 2015 10:21 Release Date: 14 Oct 2015 6214 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Remote Code Execution Vulnerabilities

Toolbar Use After Free VulnerabilityA remote code execution vulnerability exists when Windows Shell improperly handles objects in memory. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative user rights...
Last Update Date: 14 Oct 2015 10:21 Release Date: 14 Oct 2015 6136 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Multiple Vulnerabilities

Multiple Scripting Engine Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist in the way that the VBScript and JScript engines, when handling objects in memory in Internet Explorer, render. In a web-based attack scenario, an attacker could host a specially crafted website that is designed...
Last Update Date: 14 Oct 2015 10:21 Release Date: 14 Oct 2015 6172 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Edge Information Disclosure VulnerabilityAn information disclosure vulnerability exists when Microsoft Edge improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer. Microsoft Edge XSS Filter BypassA cross-site scripting (XSS) filter bypass...
Last Update Date: 14 Oct 2015 10:20 Release Date: 14 Oct 2015 6164 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Internet Explorer Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Multiple Scripting Engine Memory Corruption VulnerabilitiesRemote code...
Last Update Date: 14 Oct 2015 10:20 Release Date: 14 Oct 2015 6100 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote attacker to execute arbitrary code and disclose sensitive information.
Last Update Date: 14 Oct 2015 09:38 Release Date: 14 Oct 2015 5942 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed, bypass security controls, and obtain potentially sensitive information on the target system.
Last Update Date: 14 Oct 2015 09:38 Release Date: 14 Oct 2015 6118 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed, bypass security controls, and obtain potentially sensitive information on the target system.
Last Update Date: 14 Oct 2015 09:37 Release Date: 14 Oct 2015 6073 Views

RISK: Medium Risk

Medium Risk

PHP Phar Extension Denial of Service Vulnerability

Two vulnerabilities were identified in PHP. A remote user can cause the target service to crash.
Last Update Date: 6 Oct 2015 09:34 Release Date: 6 Oct 2015 6061 Views

RISK: Medium Risk

Medium Risk

Cisco Wireless LAN Controller 802.11i Denial of Service Vulnerability

A vulnerability was identified in Cisco Wireless LAN Controller 802.11i. A remote user can cause denial of service conditions on the target system.
Last Update Date: 5 Oct 2015 17:43 Release Date: 5 Oct 2015 6138 Views

RISK: Extremely High Risk

Extremely High Risk

Android Stagefright 2.0 Media Library Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Android Media Library. By sending a crafted MP3 or MP4 file, remote attackers can exploit the vulnerabilities to execute arbitrary code on the target system.   Note: Vendor patch is currently unavailable. However, workaround is provided.
Last Update Date: 5 Oct 2015 17:42 Release Date: 5 Oct 2015 9141 Views

RISK: High Risk

High Risk

VMware vCenter and ESXi Multiple Vulnerabilities

Multiple vulnerabilities were identified in VMware vCenter and ESXi Server, which may allow an unauthorized remote attacker to cause denial of service and execute code on the target system.
Last Update Date: 2 Oct 2015 09:31 Release Date: 2 Oct 2015 6398 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple Safari.   A remote user can cause a Safari extension to be silently replaced on the target user's system. A remote user can return an HTTP redirect to the target connected plug-in without detection by the plugin.
Last Update Date: 2 Oct 2015 09:31 Release Date: 2 Oct 2015 5897 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS Denial of Service Vulnerability

A vulnerability was identified in Cisco NX-OS. A remote authenticated user can cause the target service to temporarily stop responding to valid SNMP requests. Note: No patch is currently available.
Last Update Date: 2 Oct 2015 09:31 Release Date: 2 Oct 2015 5894 Views

RISK: High Risk

High Risk

Apple iOS Information Disclosure Vulnerability

A vulnerability was identified in Apple iOS. A physically local user can access data on the target system.A physically local user can bypass the lock screen on a locked device to obtain photos and contacts on the target system.
Last Update Date: 2 Oct 2015 09:31 Release Date: 2 Oct 2015 6029 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X. A remote user can cause arbitrary code to be executed and denial of service conditions on the target system. A remote or local user can obtain potentially sensitive information. A local user can obtain elevated privileges on the target...
Last Update Date: 2 Oct 2015 09:30 Release Date: 2 Oct 2015 5965 Views

RISK: Medium Risk

Medium Risk

Cisco IOS/IOS XE SSHv2 RSA Authentication Vulenerability

A vulnerability has been identified in Cisco IOS/IOS XE. A remote user can bypass authentication.   A remote user with knowledge of a username configured for SSHv2 RSA authentication and with access to the target user's public key can supply a specially crafted RSA private...
Last Update Date: 24 Sep 2015 10:24 Release Date: 24 Sep 2015 6593 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attacker to execute arbitrary code and disclose sensitive information.
Last Update Date: 23 Sep 2015 Release Date: 22 Sep 2015 6205 Views

RISK: Medium Risk

Medium Risk

Moodle Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Moodle. A remote user can guess password recovery tokens to gain access to the target user account, delete files and access data on the target system, and conduct cross-site scripting attacks.
Last Update Date: 23 Sep 2015 Release Date: 22 Sep 2015 5970 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox. A remote user can exploit these vulnerabilities to cause remote code execution, bypass security restriction, obtain sensitive information and spoof URLs on the target system. A local user can obtain elevated privileges on the target system.  
Last Update Date: 23 Sep 2015 09:11 Release Date: 23 Sep 2015 6187 Views

RISK: Medium Risk

Medium Risk

Apple OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X Server, which can be exploited by remoter attackers to cause denial of service and execute arbitrary code.
Last Update Date: 18 Sep 2015 10:48 Release Date: 18 Sep 2015 6036 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by remoter attackers to cause denial of service, execute arbitrary code, disclose sensitive data and conduct spoofing.
Last Update Date: 18 Sep 2015 10:48 Release Date: 18 Sep 2015 5955 Views

RISK: High Risk

High Risk

Apple Xcode Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Xcode, which can be exploited by remoter attackers to cause denial of service, bypass security restriction and disclose sensitive data.
Last Update Date: 18 Sep 2015 10:46 Release Date: 18 Sep 2015 6001 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by remoter attackers to cause denial of service, execute arbitrary code, bypass security restriction, disclose sensitive data and conduct spoofing.
Last Update Date: 18 Sep 2015 10:46 Release Date: 18 Sep 2015 6247 Views

RISK: High Risk

High Risk

VMware vCenter Server Vulnerability

A vulnerability was identified in VMware vCenter server. A remote user can expolit this vulnerability to bypass TLS certificates validation on the target system when binding to an LDAP server. A remote user that can conduct a man-in-the-middle attack can intercept...
Last Update Date: 17 Sep 2015 09:33 Release Date: 17 Sep 2015 6331 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can view files and obtain potentially sensitive information on the target system.
Last Update Date: 15 Sep 2015 09:27 Release Date: 15 Sep 2015 6107 Views

RISK: Medium Risk

Medium Risk

BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities were reported in BIND. A remote user can cause the target service to crash.
Last Update Date: 14 Sep 2015 Release Date: 4 Sep 2015 6052 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS Denial of Service Vulnerability

A vulnerability was identified in Cisco NX-OS. A remote user on the local network can cause the target ARP service to restart. Note: The fix is only available for Cisco Bug ID CSCut25292.
Last Update Date: 14 Sep 2015 Release Date: 4 Sep 2015 6028 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server Denial of Service Vulnerability

A vulnerability was identified in GSKit of IBM HTTP Server, which could allow denial of service.
Last Update Date: 14 Sep 2015 09:36 Release Date: 14 Sep 2015 6170 Views

RISK: High Risk

High Risk

OpenLDAP Denial Of Service Vulnerability

A vulnerability was identified in OpenLDAP. A remote user can expolit this vulnerability to  cause Denial Of Service on the target system.Note: A demonstration exploit code is available
Last Update Date: 11 Sep 2015 09:28 Release Date: 11 Sep 2015 6057 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server Stack Overflow Vulnerability

A vulnerability has been identified in IBM HTTP Server. A remote authenticated user can send specially crafted data to trigger a stack overflow and execute arbitrary code on the target system. The code will run with the privileges of the target web service.
Last Update Date: 10 Sep 2015 09:54 Release Date: 10 Sep 2015 5940 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Hyper-V bypass security restriction Vulnerability

A security feature bypass vulnerability exists in Windows Hyper-V when access control list (ACL) configuration settings are not applied correctly. To exploit the vulnerability, an attacker could run a specially crafted application that could cause Hyper-V to allow ...
Last Update Date: 9 Sep 2015 16:42 Release Date: 9 Sep 2015 6284 Views

RISK: Medium Risk

Medium Risk

Microsoft Skype for Business Server and Lync Server Multiple Vulnerabilities

1. A cross-site scripting (XSS) vulnerability, which could result in information disclosure, exists when the jQuery engine in Skype for Business Server or in Lync Server fails to properly sanitize specially crafted content. An attacker who successfully exploited this...
Last Update Date: 9 Sep 2015 16:42 Release Date: 9 Sep 2015 6515 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Multiple Vulnerabilities

1. An information disclosure vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited the vulnerability could discover stacktrace details. To exploit the vulnerability, an attacker would have to...
Last Update Date: 9 Sep 2015 16:33 Release Date: 9 Sep 2015 5970 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Task Management Multiple Vulnerabilities

1. An elevation of privilege vulnerability exists when Microsoft Windows fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security checks and gain elevated privileges on a targeted system. To exploit the...
Last Update Date: 9 Sep 2015 16:32 Release Date: 9 Sep 2015 6149 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities

1. An elevation of privilege vulnerability exists in the way that the .NET Framework validates the number of objects in memory before copying those objects into an array. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker...
Last Update Date: 9 Sep 2015 16:32 Release Date: 9 Sep 2015 6232 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Center Vulnerability

A vulnerability exists in Windows Media Center that could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploited this vulnerability could gain the same user rights...
Last Update Date: 9 Sep 2015 15:41 Release Date: 9 Sep 2015 6010 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Multiple Vulnerabilities

1.A cross-site scripting (XSS) vulnerability, which could result in spoofing, exists when SharePoint fails to properly sanitize user-supplied web requests. An attacker who successfully exploited this vulnerability could perform persistent cross-site scripting attacks and...
Last Update Date: 9 Sep 2015 15:41 Release Date: 9 Sep 2015 5971 Views

RISK: High Risk

High Risk

Microsoft Windows Journal Multiple Vulnerabilities

A denial of service vulnerability exists in Windows Journal when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause data loss on the target system. Note that the denial of service would not allow an...
Last Update Date: 9 Sep 2015 15:06 Release Date: 9 Sep 2015 6050 Views

RISK: High Risk

High Risk

Microsoft Graphics Component Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in the Microsoft Graphics Component. A Remote user can expolit vulnerabilities to allow Remote Code Execution on the targeted system. Win32k Elevation of Privilege VulnerabilityKernel ASLR Bypass Vulnerability
Last Update Date: 9 Sep 2015 15:06 Release Date: 9 Sep 2015 5786 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Service Denial of Service Vulnerability

A vulnerability has been identified in the Microsoft Active Directory. A Remote user can expolit vulnerability to allow denial of service on the targeted system.
Last Update Date: 9 Sep 2015 14:42 Release Date: 9 Sep 2015 5760 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Multiple Vulnerabilities have been identified in the Microsoft Edge. A Remote user can expolit vulnerabilities to allow remote code execution and elevation Of Privilege on the targeted system.
Last Update Date: 9 Sep 2015 14:40 Release Date: 9 Sep 2015 5870 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Vulnerabilities have been identified in the Internet Explorer. A Remote user can expolit vulnerabilities to allow remote code execution and elevation Of Privilege on the targeted system.
Last Update Date: 9 Sep 2015 14:40 Release Date: 9 Sep 2015 5960 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Memory Corruption Vulnerability

Multiple vulnerabilities have been reported in Adobe Shockwave Player. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted content that, when loaded by the target user, will trigger a memory corruption...
Last Update Date: 9 Sep 2015 12:28 Release Date: 9 Sep 2015 6053 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. A remote user may be allowed to take control of the targeted system.
Last Update Date: 2 Sep 2015 12:39 Release Date: 2 Sep 2015 6048 Views

RISK: Medium Risk

Medium Risk

OpenSSH Security Restriction Bypass Vulnerability

A vulnerability was identified in OpenSSH. A remote authenticated user can bypass security restrictions.A remote authenticated root user can bypass the 'PermitRootLogin=prohibit-password' security control and login to the target system via SSH.
Last Update Date: 2 Sep 2015 Release Date: 26 Aug 2015 6473 Views

RISK: High Risk

High Risk

Apple QuickTime for Windows Memory Corruption Vulnerabilities

Two vulnerabilities have been identified in Apple QuickTime for Windows. which can be exploited by remote attacker to cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user...
Last Update Date: 2 Sep 2015 Release Date: 24 Aug 2015 5908 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were reported in Mozilla Firefox. A remote user can bypass security controls and cause arbitrary code to be executed on the target user's system.
Last Update Date: 31 Aug 2015 Release Date: 28 Aug 2015 6018 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS. A remote user can cause arbitrary code execution, obtain potentially sensitive information and denial of service on the target system. A local user can bypass security restrictions. An application can gain elevated privileges.
Last Update Date: 20 Aug 2015 Release Date: 17 Aug 2015 6335 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Object Access Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted web page that, when loaded by the target user, will trigger a...
Last Update Date: 20 Aug 2015 Release Date: 19 Aug 2015 6633 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, which can be exploited by remote attacker to conduct remote code execution, obtain potentially sensitive information, denial of service attack and unauthorized file modification.   A local user can gain system privileges on the target system....
Last Update Date: 20 Aug 2015 Release Date: 17 Aug 2015 6040 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remoter attackers to conduct elevation of privilege, disclose sensitive information and provide spoof information.
Last Update Date: 20 Aug 2015 09:16 Release Date: 20 Aug 2015 5912 Views

RISK: High Risk

High Risk

Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Safari. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 14 Aug 2015 15:40 Release Date: 14 Aug 2015 6038 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Elevation of Privilege Vulnerabilities

Multiple RyuJIT Optimization Elevation of Privilege VulnerabilitiesElevation of privilege vulnerabilities exist in Microsoft .NET Framework when the RyuJIT compiler improperly optimizes certain parameters resulting in a code generation error. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6150 Views

RISK: Medium Risk

Medium Risk

Microsoft Edge Cumulative Security Update

Multiple Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. ASLR BypassA security feature bypass vulnerability exists when Microsoft...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 5956 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerabilities

Windows Object Manager Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in Windows Object Manager when it fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security and gain elevated privileges on a targeted system. Windows...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6068 Views

RISK: Medium Risk

Medium Risk

Microsoft WebDAV Information Disclosure Vulnerability

An information disclosure vulnerability exists in the Microsoft Web Distributed Authoring and Versioning (WebDAV) client that is caused when it explicitly allows the use of Secure Socket Layer (SSL) 2.. An attacker who successfully exploited this vulnerability could decrypt portions of encrypted traffic.
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 5988 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Unsafe Command Line Parameter Passing Vulnerability

An information disclosure vulnerability exists in Microsoft Windows, Internet Explorer, and Microsoft Office when files at a medium integrity level become accessible to Internet Explorer running in Enhanced Protection Mode (EPM).
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6063 Views

RISK: Medium Risk

Medium Risk

Microsoft UDDI Services Elevation of Privilege Vulnerability

An elevation of privilege exists in Microsoft Windows when the Universal Description, Discovery, and Integration (UDDI) Services improperly validate or sanitize the search parameter in a FRAME tag. An attacker who successfully exploited this vulnerability could leak authorization cookies or unexpectedly redirect a user to...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6068 Views

RISK: Medium Risk

Medium Risk

Microsoft System Center Operations Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft System Center Operations Manager that is caused by the improper validation of input. An attacker who successfully exploited this vulnerability could inject a client-side script into the user's browser. The script could spoof content, disclose...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 5909 Views

RISK: Medium Risk

Medium Risk

Microsoft Mount Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when the Mount Manager component improperly processes symbolic links. An attacker who successfully exploited this vulnerability could write a malicious binary to disk and execute it.
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6207 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Information Disclosure Vulnerabilities

Multiple MSXML Information Disclosure VulnerabilitiesInformation disclosure vulnerabilities exist when Microsoft XML Core Services (MSXML) explicitly allows the use of Secure Sockets Layer (SSL) 2.. An attacker who successfully exploited these vulnerabilities could decrypt portions of encrypted network information traffic. MSXML Information Disclosure VulnerabilityAn...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6059 Views

RISK: High Risk

High Risk

Microsoft Server Message Block Remote Code Execution Vulnerability

An authenticated remote code execution vulnerability exists in Windows that is caused when Server Message Block (SMB) improperly handles certain logging activities, resulting in memory corruption. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6124 Views

RISK: High Risk

High Risk

Microsoft RDP Remote Code Execution Vulnerabilities

Remote Desktop Session Host Spoofing Vulnerability A spoofing vulnerability exists when the Remote Desktop Session Host (RDSH) improperly validates certificates during authentication. An attacker who successfully exploited this vulnerability could impersonate the client session. Remote Desktop Protocol DLL Planting Remote Code Execution Vulnerability A...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6030 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6117 Views

RISK: High Risk

High Risk

Microsoft Graphics Component Remote Code Execution Vulnerabilities

Multiple OpenType Font Parsing VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. An attacker who successfully exploited these vulnerabilities could take complete control of the affected system. An attacker could then install programs; view...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6565 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Multiple ASLR Bypass VulnerabilitiesSecurity feature bypass vulnerabilities exist when...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 5936 Views

RISK: Medium Risk

Medium Risk

Android AOSP SMS Messaging App Multiple Vulnerabilities

Two vulnerabilities were identified in Google Android, which affect the non-customized version (i.e. original) of the messaging app. One could cause the app to crash while the other could allow an attacker to tamper with the received status and date of...
Last Update Date: 13 Aug 2015 10:40 Release Date: 13 Aug 2015 6263 Views

RISK: Medium Risk

Medium Risk

GnuTLS DistinguishedName Decoding Vulnerability

A vulnerability has been identified in GnuTLS. A remote user can cause the target service to crash.   A remote user can create a certificate with a specially crafted DistinguishedName (DN) entry that, when decoded by the target application, will trigger a double free memory...
Last Update Date: 12 Aug 2015 12:02 Release Date: 12 Aug 2015 6273 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Firefox, Firefox ESR, and Firefox OS. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 12 Aug 2015 11:38 Release Date: 12 Aug 2015 5961 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attacker to execute arbitrary code on target system.
Last Update Date: 12 Aug 2015 11:38 Release Date: 12 Aug 2015 6418 Views

RISK: High Risk

High Risk

Mozilla Firefox PDF Viewer Same-Origin Bypass Vulnerability

A vulnerability was identified in Mozilla Firefox. A remote user can obtain files from the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will bypass same-origin policy and inject arbitrary JavaScript into...
Last Update Date: 10 Aug 2015 09:30 Release Date: 10 Aug 2015 6261 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress, which can be exploited by remote attackers to conduct cross site script and SQL injection attack.
Last Update Date: 7 Aug 2015 Release Date: 6 Aug 2015 6024 Views

RISK: Medium Risk

Medium Risk

ISC BIND TKEY Query Processing Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by remote attacker to cause denial of service condition.
Last Update Date: 7 Aug 2015 Release Date: 30 Jul 2015 6247 Views

RISK: High Risk

High Risk

Android Denial of Service Vulnerability

A vulnerability was identified in the mediaserver service of Android devices that could potentially allow attackers to perform Denial of Service (DoS) attacks. This exploitation requires a user to be tricked to install a malicious app or visit a malicious website. Note: No patch is...
Last Update Date: 5 Aug 2015 11:12 Release Date: 5 Aug 2015 6352 Views

RISK: Medium Risk

Medium Risk

VMware Product Privilege Escalation Vulnerability

A vulnerability has been identified in VMware Workstation, Player and Horizon View Client for Windows, which can allow an unauthenticated attacker to cause privilege escalation.
Last Update Date: 5 Aug 2015 Release Date: 13 Jul 2015 6167 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash ActionScript 3 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. Note: A Proof of Concept exploit code is publicly available and the vulnerability has no patch available.
Last Update Date: 5 Aug 2015 Release Date: 13 Jul 2015 6655 Views

RISK: High Risk

High Risk

ISC BIND Zone Data Validation Vulnerability

A vulnerability has been identified in ISC BIND, which may allow a remote attacker to cause a denial of service condition.
Last Update Date: 5 Aug 2015 Release Date: 9 Jul 2015 6179 Views

RISK: High Risk

High Risk

Adobe Type Manager Privilege Escalation Vulnerability

A vulnerability has been identified in Adobe Type Manager module, which can allow an attacker to obtain SYSTEM privileges on an affected Windows system.   Note: Vendor patch is currently unavailable.
Last Update Date: 5 Aug 2015 Release Date: 9 Jul 2015 6321 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed, bypass security controls, and obtain potentially sensitive information on the target system.   Note: Vulnerability CVE-2015-5119 is being exploited in the wild.
Last Update Date: 5 Aug 2015 Release Date: 9 Jul 2015 6872 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

VBScript Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the VBScript engine, when rendered in Internet Explorer, handles objects in memory. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this...
Last Update Date: 3 Aug 2015 Release Date: 15 Jul 2015 6647 Views

RISK: Medium Risk

Medium Risk

BIOS Implementations Multiple Vulnerabilities

Multiple BIOS implementations fail to properly set write protections after waking from sleep, leading to the possibility of an arbitrary BIOS image reflash.
Last Update Date: 31 Jul 2015 10:39 Release Date: 31 Jul 2015 6571 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Mobile Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Internet Explorer Mobile. which can be exploited by remote attackers to execute arbitrary code on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code...
Last Update Date: 31 Jul 2015 Release Date: 27 Jul 2015 6292 Views

RISK: Medium Risk

Medium Risk

Cisco ASR 1000 Series Routers Denial of Service Vulnerability

A vulnerability was identified in Cisco ASR 1000 series routers. A remote user can cause the target device to reload.
Last Update Date: 31 Jul 2015 10:34 Release Date: 31 Jul 2015 6305 Views

RISK: High Risk

High Risk

Microsoft SQL Server Remote Code Execution Vulnerabilities

SQL Server Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in Microsoft SQL Server when it improperly casts pointers to an incorrect class. An attacker could exploit the vulnerability if their credentials allow access to an affected SQL server database. An attacker who successfully exploited...
Last Update Date: 31 Jul 2015 Release Date: 15 Jul 2015 11031 Views

RISK: Extremely High Risk

Extremely High Risk

Android Stagefright Media Library Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Android Stagefright Media Library. By sending crafted MMS or media files to target system, remote attackers can exploit the vulnerabilities by to execute arbitrary code on the target system.   Note: Proof of concept or exploit code may be available in...
Last Update Date: 29 Jul 2015 11:09 Release Date: 29 Jul 2015 11048 Views

RISK: Medium Risk

Medium Risk

Microsoft OLE Elevation of Privilege Vulnerabilities

Elevation of privilege vulnerabilities exists in Microsoft Windows OLE when it fails to properly validate user input. The vulnerabilities by themselves do not allow arbitrary code to be run. The vulnerabilities would have to be used in conjunction with another vulnerability that allows remote code execution. An...
Last Update Date: 28 Jul 2015 Release Date: 15 Jul 2015 6405 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote attackers to execute arbitrary code, bypass security controls, obtain potentially sensitive information, spoof URLs and conduct cross-site scripting attacks.
Last Update Date: 24 Jul 2015 Release Date: 23 Jul 2015 6255 Views

RISK: Medium Risk

Medium Risk

Cisco Products Denial of Service Vulnerabilities

A vulnerability was identified in Cisco ASR 9000 Series Routers. A remote user can cause the target service to reload. A vulnerability was identified in Cisco IOS and IOS XE. A remote user can cause the target system to crash.
Last Update Date: 24 Jul 2015 10:16 Release Date: 24 Jul 2015 6123 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Font Driver Remote Code Execution Vulnerability

A vulnerability was found in the Windows Adobe Type Manager Library. A remote user can trigger arbitrary code execution on the target system.A remote user can create a specially crafted OpenType font file that, when loaded by the target user, will trigger a flaw in...
Last Update Date: 22 Jul 2015 Release Date: 21 Jul 2015 6961 Views

RISK: Medium Risk

Medium Risk

Microsoft Malicious Software Removal Tool Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Microsoft Malicious Software Removal Tool (MSRT) when it fails to properly handle a race condition involving a DLL-planting scenario. An authenticated attacker who successfully exploited this vulnerability could elevate privileges on a target system. An attacker...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6498 Views

RISK: Medium Risk

Medium Risk

Microsoft ATM Font Driver Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Adobe Type Manager Font Driver (ATMFD) when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6204 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Installer Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in some cases in the Windows Installer service when it improperly runs custom action scripts. An attacker who successfully exploited this vulnerability could elevate privileges on a targeted system. An attacker could then install programs; view, change, or delete...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6286 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Driver Elevation of Privilege Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists due to the way the Windows kernel-mode driver handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6227 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Component Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows graphics component when it fails to properly process bitmap conversions. An authenticated attacker who successfully exploited this vulnerability could elevate privileges on a targeted system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6280 Views

RISK: Medium Risk

Medium Risk

Microsoft Netlogon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Netlogon that is caused when the service improperly establishes a secure communications channel to a primary domain controller (PDC). To successfully exploit this vulnerability, an attacker would first need to have access to a PDC on a target network. ...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6216 Views

RISK: High Risk

High Risk

Microsoft Windows Hyper-V Remote Code Execution Vulnerabilities

Multiple Internet Explorer Information Disclosure VulnerabilitiesA remote code execution vulnerability exists in Windows Hyper-V in a host context if an authenticated and privileged user on a guest virtual machine hosted by Hyper-V runs a specially crafted application. Hyper-V System Data Structure VulnerabilityA remote...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6390 Views