Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft RDP Remote Code Execution Vulnerability

A remote code execution vulnerability exists in how the Remote Desktop Protocol (RDP) (terminal) service handles packets. While the most likely outcome of this vulnerability is denial of the remote desktop (terminal) service (DOS), remote code execution is possible.
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6459 Views

RISK: High Risk

High Risk

Microsoft VBScript Scripting Engine Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine, when rendered in Internet Explorer, handles objects in memory. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet...
Last Update Date: 21 Jul 2015 Release Date: 15 Jul 2015 6218 Views

RISK: Medium Risk

Medium Risk

Oracle WebLogic Server Unauthorized Modification Vulnerability

Two vulnerabilities were identified in Oracle WebLogic. A remote user can modify data on the target system.
Last Update Date: 17 Jul 2015 10:10 Release Date: 17 Jul 2015 6188 Views

RISK: Medium Risk

Medium Risk

Apache Multiple Vulnerabilities

Several vulnerabilities were identified in Apache. A remote user can cause denial of service conditions on the target system. The impact of some vulnerabilities was not specified.
Last Update Date: 17 Jul 2015 10:04 Release Date: 17 Jul 2015 6327 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Use-After-Free Memory Vulnerability

A vulnerability has been identified in Adobe Flash Player, which can be exploited by remote attackers to execute arbitrary code.   Note: The vulnerability is being exploited in the wild.
Last Update Date: 16 Jul 2015 Release Date: 15 Jul 2015 6368 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products, which can be exploited by remote attackers to execute arbitrary code.
Last Update Date: 15 Jul 2015 16:37 Release Date: 15 Jul 2015 6248 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader, which can be exploited by remote attackers to disclose sensitive information, gain elevated privilege, cause denial of service and execute arbitrary code.
Last Update Date: 15 Jul 2015 16:35 Release Date: 15 Jul 2015 6384 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by remote attackers to execute arbitrary code.
Last Update Date: 15 Jul 2015 16:34 Release Date: 15 Jul 2015 6108 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Windows DLL Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Microsoft Windows improperly handles the loading of dynamic link library (DLL) files. An attacker who successfully exploited the vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 15 Jul 2015 15:11 Release Date: 15 Jul 2015 6206 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Procedure Call Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Microsoft Remote Procedure Call (RPC) that could allow an attacker to elevate privileges on a targeted system. The vulnerability is caused when Windows RPC inadvertently allows DCE/RPC connection reflection.
Last Update Date: 15 Jul 2015 15:02 Release Date: 15 Jul 2015 6356 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. Microsoft Excel ASLR Bypass VulnerabilityA security feature bypass vulnerability exists in Microsoft Excel when memory is released in an unintended manner. The vulnerability...
Last Update Date: 15 Jul 2015 15:00 Release Date: 15 Jul 2015 6126 Views

RISK: High Risk

High Risk

OpenSSL Alternative Certificate Chain Validation Vulnerability

A vulnerability was identified in OpenSSL. A remote user can bypass certificate validation on the target system. When the validation of a certificate chain fails, the system attempts to validate an alternate certificate chain but does not check the CA flag of untrusted certificates. As a...
Last Update Date: 10 Jul 2015 10:42 Release Date: 10 Jul 2015 6620 Views

RISK: Medium Risk

Medium Risk

Joomla Multiple Vulnerabilities

Multiple vulnerabilities were identified in Joomla!. A remote user can redirect the target user's browser to an arbitrary site. A remote user can conduct cross-site request forgery attacks.
Last Update Date: 8 Jul 2015 10:26 Release Date: 8 Jul 2015 6213 Views

RISK: Medium Risk

Medium Risk

ISC BIND DNSSEC Denial of Service Vulnerability

A vulnerability was identified in ISC BIND. A remote user can cause the target service to crash. A remote user can send a query to the target service for a DNS zone that contains specially crafted zone data to cause the target recursive resolver to crash. Recursive...
Last Update Date: 8 Jul 2015 10:25 Release Date: 8 Jul 2015 6277 Views

RISK: High Risk

High Risk

Mozilla Firefox and Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by remote attacker to gain elevated privileges, bypass security controls, obtain potentially sensitive information and cause arbitrary code to be executed on the target user's system.  
Last Update Date: 7 Jul 2015 Release Date: 6 Jul 2015 6228 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials Vulnerability

A vulnerability has been identified in the Cisco Unified Communications Domain Manager Platform Software, which could allow an unauthenticated, remote attacker to login with the privileges of the root user and take full control of the affected system.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 6057 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by remote attacker to conduct denial of service attack and remote code execution.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 5904 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by remote attacker to conduct cross site scripting, denial of service attack, security restriction bypass, sensitive information disclosure, spoofing and remote code execution.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 6277 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by remote attacker to conduct cross site scripting, denial of service attack, sensitive information disclosure and remote code execution.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 5863 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which can be exploited by remote attacker to conduct denial of service attack and remote code execution.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 6060 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, which can be exploited by remote attacker to conduct denial of service attack, security restriction bypass, sensitive information disclosure and spoofing.
Last Update Date: 6 Jul 2015 Release Date: 2 Jul 2015 6102 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS Elevation Of Privilege Vulnerability

A vulnerability was identified in Cisco NX-OS. A local user can obtain elevated privileges on the target system.A local user can write a file to disk with a filename containing specially crafted characters and then invoke certain command line interface commands to obtain a shell...
Last Update Date: 3 Jul 2015 09:46 Release Date: 3 Jul 2015 5965 Views

RISK: Medium Risk

Medium Risk

Cisco ASA SNMP Processing Denial of Service Vulnerability

 A vulnerability was identified in Cisco ASA. A remote authenticated user can cause the target system to crash by continuously performing SNMP operations under high traffic rate.
Last Update Date: 3 Jul 2015 09:41 Release Date: 3 Jul 2015 6026 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remote attackers to bypass security restrictions and disclose sensitive information.
Last Update Date: 30 Jun 2015 09:34 Release Date: 30 Jun 2015 6037 Views

RISK: High Risk

High Risk

Cisco products multiple vulnerabilities

Two vulnerabilities were identified in Cisco Web Security Virtual Appliance (WSAv) and Cisco Email Security Virtual Appliance (ESAv).  A remote user can gain full control the target system and decrypt and impersonate communications between target devices. [ CVE-2015-4216, CVE-2015...
Last Update Date: 26 Jun 2015 10:29 Release Date: 26 Jun 2015 6257 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Arbitrary Code Execution Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a heap overflow and...
Last Update Date: 24 Jun 2015 09:24 Release Date: 24 Jun 2015 6522 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, where two have an unknown impact and the others can be exploited by malicious people to bypass certain security restrictions.
Last Update Date: 24 Jun 2015 09:23 Release Date: 24 Jun 2015 6116 Views

RISK: Medium Risk

Medium Risk

Cisco Product Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS and NX-OS, which could allow an attacker to cause a denial of service condition on the target system.
Last Update Date: 23 Jun 2015 09:43 Release Date: 23 Jun 2015 6042 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X. A remote user can gain elevated privileges on the target user's system in certain cases. A remote user can create an application that, when installed by the target user, will access the keychain entry of a...
Last Update Date: 23 Jun 2015 Release Date: 22 Jun 2015 6026 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple vulnerabilities

Multiple vulnerabilities have been identified in Druple OpenID module that allows malicious users tolog in as other users on the site, redirect users to third party sites and expose private user contents.
Last Update Date: 19 Jun 2015 09:44 Release Date: 19 Jun 2015 6079 Views

RISK: Medium Risk

Medium Risk

Samsung Phones Remote Code Execution Vulnerability

A vulnerability was identified in Samsung devices with pre-installed Swiftkey keyboard. A remote, unauthenticated attacker conducting a man-in-the-middle attack may be able to write arbitrary data to vulnerable devices checking for updates.
Last Update Date: 18 Jun 2015 18:12 Release Date: 18 Jun 2015 6630 Views

RISK: High Risk

High Risk

Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability

A vulnerability was identitied in the anti-spam scanner of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the anti-spam functionality of the ESA. NOTE: There is no patch available for this vulnerability.
Last Update Date: 16 Jun 2015 10:30 Release Date: 16 Jun 2015 6345 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Denial of service Vulnerability

A vulnerability was identified in Cisco IOS XR Software, which could allow an unauthenticated, remote attacker to cause a denial of service condition.
Last Update Date: 16 Jun 2015 10:30 Release Date: 16 Jun 2015 6095 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM WebSphere Application Server, which cause executing arbitrary code, accessing privileged data, and providing misleading information.
Last Update Date: 16 Jun 2015 10:30 Release Date: 16 Jun 2015 6447 Views

RISK: Medium Risk

Medium Risk

OpenSSL Remote Users Deny Service and Execute Arbitrary Code Vulnerabilities

Multiple vulnerabilities were reported in OpenSSL. A remote user can cause denial of service conditions on the target system. A remote authenticated user may be able to execute arbitrary code on the target system. A remote authenticated user can send specially crafted application data to a connected...
Last Update Date: 12 Jun 2015 10:35 Release Date: 12 Jun 2015 6693 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilites were identitfied in VMware Workstation, Player, Fusion and Horizon View Client, which may cause code execution and Denial of Service.
Last Update Date: 11 Jun 2015 09:45 Release Date: 11 Jun 2015 6220 Views

RISK: Medium Risk

Medium Risk

Cisco Catalyst 6500 Series Switches Denial of Service Vulnerability

A vulnerability was identified in Cisco Catalyst 6500 Series Switches, which could allow an authenticated, remote attacker to cause a denial of service condition. NOTE: There is no patch available for this vulnerability.
Last Update Date: 11 Jun 2015 09:45 Release Date: 11 Jun 2015 6268 Views

RISK: Medium Risk

Medium Risk

IBM Notes and Domino Multiple vulnerabilities

Multiple vulnerabilities were identified in IBM SDK Java Technology Edition, Version 6 SR16FP3 IF1 that is used by IBM Notes and Domino. Remote attackers can exploit the vulnerabilities to execute arbitrary code, cause elevation of privilege and denial of service.
Last Update Date: 10 Jun 2015 09:58 Release Date: 10 Jun 2015 6283 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were reported in Adobe Flash Player. A remote user can execute arbitrary code, obtain potentially sensitive information, and bypass security controls on the target system.
Last Update Date: 10 Jun 2015 09:56 Release Date: 10 Jun 2015 6199 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Elevation of Privilege Vulnerabilities

An information disclosure vulnerability exists in Microsoft Exchange web applications when Exchange does not properly manage same-origin policy. An attacker could exploit this Server-Side Request Forgery (SSRF) vulnerability by using a specially crafted web application request.
Last Update Date: 10 Jun 2015 09:55 Release Date: 10 Jun 2015 6282 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows LoadLibrary when it fails to properly validate user input. An authenticated attacker who successfully exploited this vulnerability could elevate privileges on a targeted system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Jun 2015 09:54 Release Date: 10 Jun 2015 6141 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Federation Services Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that URLs are sanitized in Active Directory Federation Services (AD FS). An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Last Update Date: 10 Jun 2015 09:53 Release Date: 10 Jun 2015 6110 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Microsoft Windows Kernel Information Disclosure VulnerabilityAn information disclosure vulnerability exists when the Windows kernel-mode driver improperly handles buffer elements under certain conditions, allowing an attacker to request the contents of specific memory addresses. An attacker who successfully exploited this vulnerability could then potentially read data that...
Last Update Date: 10 Jun 2015 09:52 Release Date: 10 Jun 2015 6705 Views

RISK: High Risk

High Risk

Microsoft Common Controls Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Common Controls when it accesses an object in memory that has not been correctly initialized or has been deleted. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. ...
Last Update Date: 10 Jun 2015 09:51 Release Date: 10 Jun 2015 6212 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Microsoft Office Uninitialized Memory Use Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could use a specially crafted file to perform actions in the security context of...
Last Update Date: 10 Jun 2015 09:50 Release Date: 10 Jun 2015 5976 Views

RISK: High Risk

High Risk

Microsoft Windows Media Player Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Media Player handles specially crafted DataObjects. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs; view, change, or...
Last Update Date: 10 Jun 2015 09:49 Release Date: 10 Jun 2015 6672 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker who successfully exploited this vulnerability to gain access to a user's browser history. Multiple Elevation of Privilege Vulnerabilities Elevation of privilege vulnerabilities exist when Internet Explorer does...
Last Update Date: 10 Jun 2015 09:48 Release Date: 10 Jun 2015 5937 Views

RISK: Medium Risk

Medium Risk

OpenSSL Double Free Memory Vulnerability

A vulnerability was identified in OpenSSL. The impact was not specified.A remote server can return a specially crafted NewSessionTicket message to a connected multi-threaded client.It may cause a double free memory error.
Last Update Date: 5 Jun 2015 09:30 Release Date: 5 Jun 2015 6421 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP. A remote user can bypass security controls, cause denial of service conditions, and execute arbitrary code on the target system.The set_include_path(), tempnam(), rmdir(), and readlink() functions accept a null value ('/') in a...
Last Update Date: 2 Jun 2015 09:50 Release Date: 2 Jun 2015 6097 Views

RISK: Extremely High Risk

Extremely High Risk

Apple iOS Notification Unicode Character Processing Vulnerability

A vulnerability has been identified in Apple iOS, which can be exploited by a remote user to cause denial of service conditions on the target system.   A remote user can send a specially crafted string of Unicode characters to trigger a flaw in the Springboard component and cause...
Last Update Date: 28 May 2015 10:07 Release Date: 28 May 2015 7822 Views

RISK: Medium Risk

Medium Risk

PostgreSQL Multiple Vulnerabilities

Multiples vulnerabilities were identified in PostgreSQL, which can be exploited to cause remote crash, information exposure and possible side-channel key exposure.
Last Update Date: 26 May 2015 09:45 Release Date: 26 May 2015 6074 Views

RISK: Medium Risk

Medium Risk

Diffie-Hellman Key Exchange "Logjam" Vulnerability

A vulnerability has been identified in Diffie-Hellman Key Exchange (DH). The vulnerability allows attackers to intercept protocols that rely on DH and force them to use ‘export-grade’ cryptography, which can then be decrypted or altered.
Last Update Date: 22 May 2015 12:14 Release Date: 22 May 2015 6431 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Denial of Service Vulnerability

A vunlerability was identified in Cisco ASA. A remote user can cause denial of service conditions on the target system.A remote user can disrupt the multicast forwarding feature on the target system.   Note: No official solution is currently available.
Last Update Date: 22 May 2015 10:34 Release Date: 22 May 2015 6041 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote attackers to conduct spoofing and execute arbitrary code.
Last Update Date: 21 May 2015 09:34 Release Date: 21 May 2015 5961 Views

RISK: Medium Risk

Medium Risk

Moodle Multiple Vulnerabilities

Multiple vulnerabilities were idenitifed in Moodle. A remote authenticated user can obtain potentially sensitive information. A remote user can conduct cross-site scripting attacks and bypass security controls on the target system.
Last Update Date: 20 May 2015 09:13 Release Date: 20 May 2015 6097 Views

RISK: Medium Risk

Medium Risk

Microsoft Schannel Information Disclosure Vulnerability

An information disclosure vulnerability exists in Secure Channel (Schannel) when it allows the use of a weak Diffie-Hellman ephemeral (DFE) key length of 512 bits in an encrypted TLS session. Allowing 512-bit DHE keys makes DHE key exchanges weak...
Last Update Date: 19 May 2015 Release Date: 13 May 2015 6309 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

VBScript ASLR Bypass A security feature bypass exists when the VBScript engine fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. The security feature bypass...
Last Update Date: 15 May 2015 Release Date: 13 May 2015 6096 Views

RISK: High Risk

High Risk

Microsoft Windows Journal Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6118 Views

RISK: High Risk

High Risk

Microsoft Font Drivers Remote Code Execution Vulnerabilities

OpenType Font Parsing VulnerabilityAn information disclosure vulnerability exists in Microsoft Windows when the Windows DirectWrite library improperly handles OpenType fonts. An attacker who successfully exploited this vulnerability could potentially read data which was not intended to be disclosed. Note that this vulnerability would not allow an attacker to...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6401 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Server Remote Code Execution Vulnerabilities

Remote code execution vulnerabilities exist when SharePoint Server improperly sanitizes specially crafted page content. An authenticated attacker could attempt to exploit these vulnerabilities by sending specially crafted page content to a SharePoint server. The attacker who successfully exploited these vulnerabilities could run arbitrary code...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6178 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerabilities

Remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory.  Exploitation of these vulnerabilities requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6081 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Elevation of Privilege Vulnerabilities

.NET XML Decryption Denial of Service VulnerabilityA denial of service vulnerability exists in Microsoft .NET Framework that could allow an unauthenticated attacker to degrade the performance of a .NET-enabled website and disrupt the availability of applications that use Microsoft .NET Framework. The vulnerability...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6206 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Silverlight that is caused when Silverlight improperly allows applications that are intended to run at a low integrity level (very limited permissions) to be executed at a medium integrity level (permissions of the current user) or higher. ...
Last Update Date: 13 May 2015 14:41 Release Date: 13 May 2015 6172 Views

RISK: Medium Risk

Medium Risk

Microsoft Service Control Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows Service Control Manager (SCM) when the SCM improperly verifies impersonation levels. An attacker who successfully exploited this vulnerability could gain elevated privileges and make calls to SCM for which they lack sufficient privilege. The update addresses the...
Last Update Date: 13 May 2015 14:40 Release Date: 13 May 2015 6444 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Multiple Microsoft Windows Kernel Memory Disclosure VulnerabilitiesInformation disclosure vulnerabilities exist when the Windows kernel-mode driver leaks private address information during a function call, which could allow the disclosure of kernel memory contents revealing information about the system to an attacker. The information disclosure vulnerabilities by themselves...
Last Update Date: 13 May 2015 14:37 Release Date: 13 May 2015 6537 Views

RISK: Medium Risk

Medium Risk

Microsoft Kernel Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when the Windows kernel fails to properly validate a memory address, allowing an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass. An attacker who successfully exploited this vulnerability...
Last Update Date: 13 May 2015 14:37 Release Date: 13 May 2015 6091 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Scripting Engines Security Feature Bypass Vulnerabilities

VBScript ASLR BypassA security feature bypass exists when the VBScript engine fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. The security feature bypass by itself...
Last Update Date: 13 May 2015 14:36 Release Date: 13 May 2015 6153 Views

RISK: Medium Risk

Medium Risk

Microsoft Management Console File Format Denial of Service Vulnerability

A denial of service vulnerability exists when Windows attempts to access a specially crafted .msc file to retrieve the icon information, and then fails to properly validate a destination buffer, resulting in a denial of service. An unauthenticated attacker could exploit this ...
Last Update Date: 13 May 2015 14:36 Release Date: 13 May 2015 6029 Views

RISK: High Risk

High Risk

Adobe Reader and Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which can be exploited by remote attacker to execute arbitrary code, bypass security restriction, cause denial of service condition, and disclose sensitive information.
Last Update Date: 13 May 2015 09:37 Release Date: 13 May 2015 6316 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attacker to run arbitrary code, bypass security restriction and disclose sensitive information.
Last Update Date: 13 May 2015 09:37 Release Date: 13 May 2015 6526 Views

RISK: High Risk

High Risk

Mozilla Firefox and Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Firefox ESR and Thunderbird. Remote attacker can exploit the vulnerabilities to cause denial of service and sensitive information disclosure.
Last Update Date: 13 May 2015 09:37 Release Date: 13 May 2015 6187 Views

RISK: Medium Risk

Medium Risk

Cisco Wireless LAN Controller Denial of Service Vulnerability

A vulnerability has been identified in Cisco Wireless LAN Controller (WLC). A remote user on the adjacent network can cause denial of service conditions on the target system. A remote user can send specially crafted data to trigger a flaw in the wireless web authentication subsystem...
Last Update Date: 12 May 2015 11:14 Release Date: 12 May 2015 6083 Views

RISK: Medium Risk

Medium Risk

Huawei Ethernet Switch Denial of Service Vulnerability

A vulnerability has been identified in multiple Huawei Ethernet Switches, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 8 May 2015 10:24 Release Date: 8 May 2015 6172 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple Safari. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can obtain potentially sensitive information on the target system. A remote user can spoof user interface elements.
Last Update Date: 8 May 2015 10:24 Release Date: 8 May 2015 5720 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Request Body Processing Vulnerability

A vulnerability has been identified in Apache Tomcat, which exists in the processing of request body. Remote attackers can exploit the vulnerability to conduct denial of service attack.
Last Update Date: 7 May 2015 09:48 Release Date: 7 May 2015 6018 Views

RISK: Medium Risk

Medium Risk

Splunk Multiple Vulnerabilities

Several vulnerabilities were identified in Splunk. A remote user can conduct cross-site scripting attacks and obtain potentially sensitive information on the target system.
Last Update Date: 6 May 2015 10:07 Release Date: 6 May 2015 6104 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote attackers to execute arbitrary code.
Last Update Date: 5 May 2015 Release Date: 30 Apr 2015 5926 Views

RISK: Medium Risk

Medium Risk

LibreOffice HWP Filter Memory Corruption Vulnerability

A vulnerability has been identified in LibreOffice, which can be exploited by malicious people to potentially compromise a user's system.The vulnerability is caused due to an error related to the HWP filter, which can be exploited to cause a memory corruption...
Last Update Date: 5 May 2015 Release Date: 28 Apr 2015 6087 Views

RISK: High Risk

High Risk

Apache OpenOffice HWP Filter Memory Corruption Vulnerability

A vulnerability has been identified in Apache OpenOffice, which can be exploited by malicious people to potentially compromise a user's system.The vulnerability is caused due to an error related to the HWP filter, which can be exploited to cause a memory...
Last Update Date: 5 May 2015 Release Date: 28 Apr 2015 6026 Views

RISK: Medium Risk

Medium Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X Server. A remote user can bypass custom firewall rules and security controls on the target system.The firewall configuration files reference an incorrect path value. As a result, the system may not properly enforce custom firewall rules....
Last Update Date: 5 May 2015 Release Date: 28 Apr 2015 5964 Views

RISK: Medium Risk

Medium Risk

WordPress Cross-Site Scripting Vulnerability

A vulnerability was identified in WordPress. A remote user can conduct cross-site scripting attacks. A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the WordPress software, access data recently submitted...
Last Update Date: 5 May 2015 Release Date: 28 Apr 2015 5837 Views

RISK: Medium Risk

Medium Risk

Clam AntiVirus Multiple Vulnerabilities

Multiple vulnerabilities were identified in Clam AntiVirus. A remote user can cause denial of service conditions on the target system. A remote user can create a specially crafted file that, when processed by the target application, will cause the application to enter an infinite loop or...
Last Update Date: 5 May 2015 10:00 Release Date: 5 May 2015 5923 Views

RISK: Medium Risk

Medium Risk

libcurl Multiple Vulnerabilities

Multiple vulnerabilities were identified in cURL. A remote user can execute arbitrary code, cause denial of service conditions, and obtain potentially sensitive information on the target system.
Last Update Date: 5 May 2015 09:57 Release Date: 5 May 2015 5840 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identifed in WordPress, a weblog manager, that could allow remote attackers to upload files with invalid or unsafe names, mount social engineering attacks or compromise a site via cross-site scripting, and inject SQL commands.
Last Update Date: 5 May 2015 09:55 Release Date: 5 May 2015 5909 Views

RISK: High Risk

High Risk

Apple OS X Elevation of Privilege Vulnerability

A vulnerability was identified in Apple OS X. A local user can obtain root privileges on the target system.A local user can exploit a flaw in the checking of XPC entitlements to gain administrative privileges. Note: No solution is currently available.
Last Update Date: 24 Apr 2015 Release Date: 22 Apr 2015 5878 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server. A remote attacker can gain elevated privileges and obtain potentially sensitive information on the target system.
Last Update Date: 24 Apr 2015 Release Date: 23 Apr 2015 6090 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system, bypass security protections, and obtain potentially sensitive information on the target system.
Last Update Date: 24 Apr 2015 Release Date: 15 Apr 2015 5937 Views

RISK: High Risk

High Risk

Apple iOS SSL Certification Processing Deny of Service Vulnerability

A vulnerability was identified in Apple iOS. A remote user can cause denial of service conditions on the target system in certain cases. A remote user with control of a wireless network that the target device is connected to can create a specially crafted SSL certificate that, ...
Last Update Date: 24 Apr 2015 10:11 Release Date: 24 Apr 2015 6001 Views

RISK: Medium Risk

Medium Risk

wpa_supplicant Remote Code Execution Vulnearability

 A vulnerability has been identified in wpa_supplicant. A remote user can cause denial of service conditions, obtain potentially sensitive information, or potentially execute arbitrary code on the target system. A remote user on the wireless network can send specially crafted SSID data to trigger a...
Last Update Date: 24 Apr 2015 10:09 Release Date: 24 Apr 2015 6030 Views

RISK: High Risk

High Risk

Mozilla Firefox Remote Code Execution Vulnerability

A vulnerability was identified in Mozilla Firefox. A remote user can cause arbitrary code to be executed on the target user's system.A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a race condition when a...
Last Update Date: 23 Apr 2015 Release Date: 22 Apr 2015 6062 Views

RISK: High Risk

High Risk

Microsoft Windows Unspecified System Privileges Vulnerability

A vulnerability was identified in Microsoft Windows. A local user can obtain system privileges on the target system. A local user can run a specially crafted program to execute a callback to use data from the system token and execute code with System privileges. NOTE: There...
Last Update Date: 21 Apr 2015 09:57 Release Date: 21 Apr 2015 6188 Views

RISK: High Risk

High Risk

MySQL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in MySQL. A remote user can cause denial of service conditions, and can partially access and modify data on the target system.
Last Update Date: 17 Apr 2015 Release Date: 16 Apr 2015 5978 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote attackers to execute arbitrary code and bypass security restriction.
Last Update Date: 17 Apr 2015 Release Date: 16 Apr 2015 5764 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java. A remote user can take full control of the target system, and cause denial of service conditions on the target system.
Last Update Date: 17 Apr 2015 Release Date: 16 Apr 2015 6061 Views

RISK: Medium Risk

Medium Risk

SQLite Multiple Vulnerabilities

Mutiple vulnerabilities have been identified in SQLite, which can be exploited by malicious remote users to cause a denial of service, system compromise, or other unknown impacts.
Last Update Date: 17 Apr 2015 09:22 Release Date: 17 Apr 2015 6162 Views

RISK: High Risk

High Risk

Microsoft Windows Hyper-V Denial of Service Vulnerability

A denial of service vulnerability exists in Hyper-V when an authenticated attacker runs a specially crafted application in a virtual machine (VM) session. Note that the denial of service does not allow an attacker to execute code or elevate user rights on other VMs running...
Last Update Date: 15 Apr 2015 15:00 Release Date: 15 Apr 2015 6384 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Information Disclosure Vulnerability

An information disclosure vulnerability exists in ASP.NET that is caused when ASP.NET improperly handles certain requests on systems that have custom error messages disabled. An attacker who successfully exploited the vulnerability would be able to view parts of a web configuration file, which could...
Last Update Date: 15 Apr 2015 15:00 Release Date: 15 Apr 2015 6248 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Federation Services Information Disclosure Vulnerability

An information disclosure vulnerability exists when Active Directory Federation Services (AD FS) fails to properly log off a user. The vulnerability could allow unintentional information disclosure. An attacker who successfully exploited this vulnerability could gain access to a user's information by reopening an application...
Last Update Date: 15 Apr 2015 15:00 Release Date: 15 Apr 2015 6321 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Security Feature Bypass Vulnerability

A same-origin policy security feature bypass vulnerability exists in Microsoft XML Core Services (MSXML) whereby cross-domain data access could be possible in a document type declaration (DTD) scenario. An attacker who successfully exploited this vulnerability could access sensitive user information, ...
Last Update Date: 15 Apr 2015 15:00 Release Date: 15 Apr 2015 6058 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerabilities

NtCreateTransactionManager Type Confusion VulnerabilityAn elevation of privilege vulnerability exists when Microsoft Windows fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security checks and gain elevated privileges on a targeted system. Windows MS-DOS device name...
Last Update Date: 15 Apr 2015 15:00 Release Date: 15 Apr 2015 6118 Views