Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Task Scheduler Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Task Scheduler due to a known invalid task being present on certain systems. An attacker who successfully exploited the vulnerability could cause Task Scheduler to run a specially crafted application in the context of the System account. An attacker could then...
Last Update Date: 15 Apr 2015 14:59 Release Date: 15 Apr 2015 6097 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Server Elevation of Privilege Vulnerabilities

Elevation of privilege vulnerabilities exist when SharePoint Server improperly sanitizes a specially crafted request to an affected SharePoint server. An authenticated attacker could exploit these vulnerabilities by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited these ...
Last Update Date: 15 Apr 2015 14:59 Release Date: 15 Apr 2015 5996 Views

RISK: Medium Risk

Medium Risk

Microsoft Graphics Component Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows improperly processes certain, specially crafted Enhanced Metafile (EMF) image format files. An attacker who successfully exploited the vulnerability could run arbitrary code as the logged-on user. An attacker could then install...
Last Update Date: 15 Apr 2015 14:59 Release Date: 15 Apr 2015 6168 Views

RISK: High Risk

High Risk

Microsoft Windows HTTP.sys Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the HTTP protocol stack (HTTP.sys) that is caused when HTTP.sys improperly parses specially crafted HTTP requests. An attacker who successfully exploited this vulnerability could execute arbitrary code in the context of the System ...
Last Update Date: 15 Apr 2015 14:59 Release Date: 15 Apr 2015 7133 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Microsoft Office Memory Corruption VulnerabilityA remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle rich text format files in memory. Multiple Microsoft Office Component Use After Free VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Office software that are caused when the...
Last Update Date: 15 Apr 2015 14:58 Release Date: 15 Apr 2015 6271 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Memory Corruption Vulnerabilities in Internet Explorer Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the...
Last Update Date: 15 Apr 2015 14:58 Release Date: 15 Apr 2015 6055 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server SSL/TLS RC4 Vulnerability

The RC4 algorithm, as used in the TLS protocol and SSL protocol, could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability to remotely expose account credentials without requiring an active man-in-the-middle session.
Last Update Date: 15 Apr 2015 11:43 Release Date: 15 Apr 2015 6216 Views

RISK: Medium Risk

Medium Risk

Oracle Database Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Database. A remote authenticated user can gain full control of the target system, cause denial of service conditions, and access and modify data on the target system.
Last Update Date: 15 Apr 2015 11:04 Release Date: 15 Apr 2015 6047 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows NTLM Information Disclosure Vulnerability

Many software products use HTTP requests for various features such as software update checking. A malicious user can intercept such requests (such as with a MITM proxy) and use HTTP Redirect to redirect the victim a malicious SMB server. If the redirect is a file:// ...
Last Update Date: 14 Apr 2015 10:14 Release Date: 14 Apr 2015 6821 Views

RISK: High Risk

High Risk

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple products (OS X, Safari, iOS, Apple TV, Xcode), which can be exploited by remote attackers to conduct remote code execution, denial of service, sensitive information disclosure, tampering and security restriction bypass.
Last Update Date: 9 Apr 2015 10:58 Release Date: 9 Apr 2015 6207 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which could be exploited by a remote user to obtain potentially sensitive information on the target system, and bypass certificate verification.A remote user can create specially crafted HTML that, when loaded by the target user, will invoke...
Last Update Date: 9 Apr 2015 Release Date: 8 Apr 2015 5891 Views

RISK: Medium Risk

Medium Risk

Network Time Protocol daemon (ntpd) Multiple Vulnerabilities

Multiple vulnerabilities were identified in ntpd, which could be exploited by a remote user to cause denial of service conditions and bypass authentication on the target system. A remote user with knowledge of a symmetric association between two hosts can periodically send a specially crafted packet to one...
Last Update Date: 9 Apr 2015 Release Date: 8 Apr 2015 5997 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited to conduct remote code execution.
Last Update Date: 2 Apr 2015 15:30 Release Date: 2 Apr 2015 5884 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Firefox ESR and Thunderbird, which can be exploited by malicious people to disclose potentially sensitive information, conduct clickjacking and cross-site request forgery attacks, bypass certain security restrictions, and compromise a user'...
Last Update Date: 1 Apr 2015 17:47 Release Date: 1 Apr 2015 6209 Views

RISK: Medium Risk

Medium Risk

PHP Remote Code Execution Vulnerability

A vulnerability was identified in PHP. A remote user can cause arbitrary code to be executed on the target system. A remote user can create a specially crafted ZIP archive file that, when loaded by the target application, will trigger an integer overflow and potentially execute...
Last Update Date: 27 Mar 2015 12:47 Release Date: 27 Mar 2015 6110 Views

RISK: High Risk

High Risk

Cisco IOS & IOS-XE Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco IOS, IOS-XE and ASR Series IOS-XE, which could be exploited by remote users to cause denial of service, arbitrary code execution and response spoofing on the target system.
Last Update Date: 26 Mar 2015 15:08 Release Date: 26 Mar 2015 6308 Views

RISK: High Risk

High Risk

OpenSSL Multiple Denial of Service Vulnerabilities

OpenSSL has released new updates addressing multiple vulnerabilities, one of which is classified as a high severity issue. Exploitation could allow a remote attacker to cause a Denial of Service attack against the server.
Last Update Date: 25 Mar 2015 Release Date: 20 Mar 2015 6271 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Autonomic Networking Infrastructure Overwrite Vulnerability

A vulnerability has been identified in Cisco IOS, which could allow an unauthenticated, remote attacker to overwrite configuration information and cause a denial of service condition on an affected device.   A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS software could allow...
Last Update Date: 25 Mar 2015 Release Date: 24 Mar 2015 5970 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, which can be exploited by remote attackers to bypass certain security restrictions and compromise a user's system.A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a flaw...
Last Update Date: 25 Mar 2015 Release Date: 23 Mar 2015 5999 Views

RISK: High Risk

High Risk

PHP Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities were identified in PHP.  A remote user can execute arbitrary code on the target system.A remote user can send specially crafted data to an application to trigger a use-after-free memory error in the unserialisation of objects in the DateTimeZone class....
Last Update Date: 20 Mar 2015 10:44 Release Date: 20 Mar 2015 6121 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by remote attacker to execute arbitrary code or prevent users from discerning a phishing attack on an affected system.
Last Update Date: 19 Mar 2015 09:36 Release Date: 19 Mar 2015 5946 Views

RISK: Medium Risk

Medium Risk

D-Link DCS-93xL Model Family Unrestricted Upload Vulnerability

A vulnerability was identified in the D-Link DCS-93xL family of devices, which allows an attacker to upload arbitrary files from the attackers system. The attacker may specify the file location to write on the device. This could lead to data being created, ...
Last Update Date: 17 Mar 2015 09:45 Release Date: 17 Mar 2015 6311 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attacker to cause remote code execution and bypass security restrictions.A remote user can bypass same-origin domain policy.A remote user can bypass file upload restrictions.A remote user...
Last Update Date: 16 Mar 2015 10:50 Release Date: 16 Mar 2015 6193 Views

RISK: High Risk

High Risk

Microsoft Windows Schannel Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Secure Channel (Schannel) that is caused by an issue in the TLS state machine whereby a client system accepts an RSA key with a shorter key length than the originally negotiated key length. The vulnerability facilitates exploitation of the publicly...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6355 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Desktop Protocol Denial of Service Vulnerability

A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker creates multiple RDP sessions that fail to properly free objects in memory. Note that the denial of service would not allow an attacker to execute code or to elevate their user rights. ...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6057 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Photo Decoder Component Information Disclosure Vulnerability

An information disclosure vulnerability exists when Windows fails to properly handle uninitialized memory when parsing certain, specially crafted JPEG XR (.JXR) image format files. The vulnerability could allow information disclosure if an attacker runs a specially crafted application on an affected system.
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6062 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Task Scheduler Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Windows Task Scheduler fails to properly validate and enforce impersonation levels. The vulnerability could allow a user with limited privileges on an affected system to leverage Task Scheduler to execute files that they do not have permissions to run.
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6071 Views

RISK: Medium Risk

Medium Risk

Microsoft NETLOGON Spoofing Vulnerability

A spoofing vulnerability exists in NETLOGON that is caused when the Netlogon service improperly establishes a secure communications channel belonging to a different machine with a spoofed computer name. To successfully exploit this vulnerability, an attacker would first have to be logged on to...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6041 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Elevation of Privilege Vulnerabilities

Multiple OWA XSS VulnerabilitiesElevation of privilege vulnerabilities exist when Microsoft Exchange Server does not properly sanitize page content in Outlook Web App. An attacker could exploit these vulnerabilities by modifying certain properties within Outlook Web App and then convincing users to browse to the targeted Outlook Web App site...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6026 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, which can be exploited to cause remote code execution, elevation of privilege and sensitive information disclosure.
Last Update Date: 12 Mar 2015 09:34 Release Date: 12 Mar 2015 5950 Views

RISK: High Risk

High Risk

Cisco Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in Cisco products, which can be exploited to allow an unauthenticated, remote attacker to create a denial of service (DoS) condition, or perform a man-in-the-middle attack.
Last Update Date: 12 Mar 2015 09:32 Release Date: 12 Mar 2015 5991 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

Registry Virtualization Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in the way that Windows Registry Virtualization improperly allows a user to modify the virtual store of another user. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the account of...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 5973 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows PNG Processing Information Disclosure Vulnerability

An information disclosure vulnerability exists when Windows fails to properly handle uninitialized memory when parsing certain, specially crafted PNG image format files. The vulnerability could allow information disclosure if an attacker convinces a user to visit a website that contains specially crafted PNG images.
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6042 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Driver Elevation of Privilege Vulnerabilities

Microsoft Windows Kernel Memory Disclosure VulnerabilityAn information disclosure vulnerability exists in the Windows kernel-mode driver that could allow the disclosure of kernel memory contents to an attacker. This vulnerability is caused when the Windows kernel-mode driver fails to initialize function buffers in a manner that...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6535 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Microsoft Office Component Use After Free VulnerabilityA remote code execution vulnerability exists in Microsoft Office software that is caused when the Office software improperly handles objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 5882 Views

RISK: High Risk

High Risk

Microsoft Windows Adobe Font Driver Remote Code Execution Vulnerabilities

Adobe Font Driver Denial of Service VulnerabilityA denial of service vulnerability exists in how the Adobe Font Driver manages memory when parsing fonts. A user who visited a specially crafted website or opened a specially crafted file could be affected by this vulnerability. The update addresses this vulnerability...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6111 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

WTS Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Windows Text Services improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the logged-on user. DLL Planting Remote Code Execution VulnerabilityA remote code execution...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6113 Views

RISK: High Risk

High Risk

Microsoft Windows VBScript Scripting Engine Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine, when rendered in Internet Explorer, handles objects in memory. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 6083 Views

RISK: High Risk

High Risk

Cumulative Security Update for Internet Explorer

Multiple Memory Corruption Vulnerabilities in Internet Explorer Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the...
Last Update Date: 12 Mar 2015 Release Date: 11 Mar 2015 5988 Views

RISK: High Risk

High Risk

Apple OS X Xcode Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X Xcode, which can be exploited to cause denial of service and security restriction bypass
Last Update Date: 11 Mar 2015 10:36 Release Date: 11 Mar 2015 5872 Views

RISK: High Risk

High Risk

Apple iOS and Apple TV Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in Apple iOS and Apple TV, which can be exploited to cause remote code execution, sensitive information disclosure and denial of service.
Last Update Date: 11 Mar 2015 10:34 Release Date: 11 Mar 2015 5984 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes and Domino Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Notes and Domino, which can be exploited to cause sensitive information disclosure, security restriction bypass, denial of service, tampering and elevation of privilege.
Last Update Date: 11 Mar 2015 10:32 Release Date: 11 Mar 2015 6145 Views

RISK: High Risk

High Risk

SSL/TLS Export Cipher "Factoring RSA Export Keys" (FREAK) Vulnerability

A vulnerability has been identified in SSL/TLS. The vulnerability allows attackers to intercept HTTPS connections between vulnerable clients and servers and force them to use ‘export-grade’ cryptography, which can then be decrypted or altered, i.e. conduct a key...
Last Update Date: 9 Mar 2015 Release Date: 5 Mar 2015 9261 Views

RISK: Extremely High Risk

Extremely High Risk

Seagate NAS Remote Code Execution Vulnerability

A vulnerability was identified in Seagate Business Storage 2-Bay NAS. Products in this line were found to be vulnerable to a number of issues that allow for remote code execution under the context of the root user. These vulnerabilities are exploitable without requiring any form...
Last Update Date: 3 Mar 2015 09:56 Release Date: 3 Mar 2015 6989 Views

RISK: Medium Risk

Medium Risk

TYPO3 Remote Users Bypass Authentication Vulnerability

A vulnerability was identified in TYPO3. A remote user can bypass authentication on the target system. A remote user can exploit a flaw in the rsaauth system extension to bypass authentication.
Last Update Date: 3 Mar 2015 09:45 Release Date: 3 Mar 2015 7022 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, which could be exploited by remote attackers to cause arbitrary code execution, denial of service, bypass security restrictions and disclose potentially sensitive information.A remote user can create specially crafted content that, when loaded by the target user...
Last Update Date: 27 Feb 2015 Release Date: 25 Feb 2015 6213 Views

RISK: Medium Risk

Medium Risk

Mozilla Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Thunderbird, which could be exploited by remote attackers to cause arbitrary code execution, gain elevated privileges and disclose potentially sensitive information.A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary...
Last Update Date: 27 Feb 2015 Release Date: 25 Feb 2015 6115 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error when parsing IPv6 packets and can be exploited to cause a reload of a line card...
Last Update Date: 24 Feb 2015 14:29 Release Date: 24 Feb 2015 6016 Views

RISK: Medium Risk

Medium Risk

Samba Remote Code Execution Vulnerability

A vulnerability was identified in Samba. A remote user can execute arbitrary code on the target system.A remote user can send specially crafted data followed by an anonymous netlogon packet to trigger an uninitialized memory error and execute arbitrary code on the target system. The code...
Last Update Date: 24 Feb 2015 14:28 Release Date: 24 Feb 2015 6002 Views

RISK: Medium Risk

Medium Risk

Lenovo Superfish Adware HTTPS Spoofing Vulnerability

Superfish adware installed on some Lenovo PCs install a non-unique trusted root certification authority (CA) certificate, allowing an attacker to spoof HTTPS traffic. A machine with Superfish VisualDiscovery installed will be vulnerable to SSL spoofing attacks without a warning from the browser.
Last Update Date: 23 Feb 2015 11:12 Release Date: 23 Feb 2015 6777 Views

RISK: High Risk

High Risk

Cisco ASR 5000 Series Software SNMP Processing Vulnerability

A vulnerability was identified in the Simple Network Management Protocol (SNMP) code of Cisco ASR 5500 System Architecture Evolution (SAE) Gateway could allow an unauthenticated, remote attacker to cause high CPU utilization and the SNMP process may stop responding. NOTE: ...
Last Update Date: 18 Feb 2015 09:27 Release Date: 18 Feb 2015 6110 Views

RISK: Medium Risk

Medium Risk

IBM Websphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM Websphere Application Server, which could be exploited by remote attackers to cause arbitrary code execution, denial of service, cross site scripting, sensitive information disclosure and unauthorised access.
Last Update Date: 17 Feb 2015 10:11 Release Date: 17 Feb 2015 5976 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Deny of Service Vulnerability

A vulnerability was identified in Cisco ASA. A remote user can cause denial of service conditions. A remote user can send a large number of specially crafted HTTP requests to trigger a memory leak in the WebVPN service and cause the target device to stop accepting new SSL...
Last Update Date: 13 Feb 2015 09:28 Release Date: 13 Feb 2015 5943 Views

RISK: High Risk

High Risk

Adobe Reader Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Reader, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an error within CoolType.dll and can be exploited to cause a heap-based buffer overflow. Note...
Last Update Date: 11 Feb 2015 16:36 Release Date: 11 Feb 2015 6261 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS. A local user can cause denial of service conditions.An unprivileged local user can cause issue IOS Shell commands to cause the target device to crash.
Last Update Date: 11 Feb 2015 16:35 Release Date: 11 Feb 2015 5974 Views

RISK: Medium Risk

Medium Risk

Microsoft Virtual Machine Manager Elevation of Privilege Vulnerability

A vulnerability exists in Virtual Machine Manager (VMM) when VMM improperly validates user roles. The vulnerability could allow elevation of privilege if an attacker logs on an affected system. An attacker must have valid Active Directory logon credentials and be able to log on with those...
Last Update Date: 11 Feb 2015 10:27 Release Date: 11 Feb 2015 5954 Views

RISK: Medium Risk

Medium Risk

Microsoft Graphics Component Information Disclosure Vulnerability

An information disclosure vulnerability exists when Windows fails to properly handle uninitialized memory when parsing certain, specially crafted TIFF image format files. The vulnerability could allow information disclosure if an attacker runs a specially crafted application on an affected system.
Last Update Date: 11 Feb 2015 10:26 Release Date: 11 Feb 2015 5951 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when it fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security checks and gain elevated privileges on a targeted system. This vulnerability can be exploited only in...
Last Update Date: 11 Feb 2015 10:25 Release Date: 11 Feb 2015 5895 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Group Policy Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Group Policy application of Security Configuration policies that could cause Group Policy settings on a targeted system to revert to their default, and potentially less secure, state. An attacker could accomplish this by way of a man-in...
Last Update Date: 11 Feb 2015 10:24 Release Date: 11 Feb 2015 5944 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Microsoft Office when it fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. The security feature bypass by itself...
Last Update Date: 11 Feb 2015 10:23 Release Date: 11 Feb 2015 5972 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerabilities

Excel Remote Code Execution VulnerabilityA remote code execution vulnerability exists in Microsoft Excel that is caused when Excel improperly handles objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code.Office...
Last Update Date: 11 Feb 2015 10:22 Release Date: 11 Feb 2015 5918 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Security Update

Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the vulnerabilities by...
Last Update Date: 11 Feb 2015 10:20 Release Date: 11 Feb 2015 5968 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Remote Code Execution Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in the Windows kernel-mode driver (Win32k.sys) that is caused when it improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker could then install...
Last Update Date: 11 Feb 2015 10:19 Release Date: 11 Feb 2015 6272 Views

RISK: High Risk

High Risk

Microsoft Windows Group Policy Remote Code Execution Vulnerability

A remote code execution vulnerability exists in how Group Policy receives and applies policy data when a domain-joined system connects to a domain controller. To exploit this vulnerability, an attacker would have to convince a victim with a domain-configured system to connect to an...
Last Update Date: 11 Feb 2015 10:18 Release Date: 11 Feb 2015 6008 Views

RISK: Medium Risk

Medium Risk

Cisco ASA WebVPN Denial of Service Vulnerability

A vulnerability has been identified in Cisco Adaptive Security Appliance (ASA), which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error in the Proxy Bypass Content Rewriter implementation within WebVPN and can be exploited...
Last Update Date: 10 Feb 2015 09:45 Release Date: 10 Feb 2015 5821 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can exploited by remote attackers to bypass certain security restrictions, and compromise a user's system.
Last Update Date: 9 Feb 2015 11:35 Release Date: 9 Feb 2015 5883 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted Flash content that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 6 Feb 2015 Release Date: 3 Feb 2015 6610 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the...
Last Update Date: 6 Feb 2015 10:00 Release Date: 6 Feb 2015 6200 Views

RISK: High Risk

High Risk

Clam AntiVirus Heap Overflows Vulnerabilities

Multiple vulnerabilities have been identified in ClamAV, which can exploited by remote attackers to trigger a heap out-of-bounds error with unspecified impact.A heap out of bounds condition with crafted Yoda's crypter files.A heap out of bounds condition with crafted...
Last Update Date: 4 Feb 2015 Release Date: 2 Feb 2015 6056 Views

RISK: Medium Risk

Medium Risk

VLC Multimedia Player and Streamer Multiple vulnerabilities

Multiple vulnerabilities were identified in VLC multimedia player and streamer. These could allow remote attackers to cause a denial of service (crash) or arbitrary code execution via crafted MP4 files.
Last Update Date: 4 Feb 2015 09:59 Release Date: 4 Feb 2015 6009 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cross-Site Scripting Attack Vulnerability

A vulnerability was identified in Microsoft Internet Explorer. A remote user can conduct cross-site scripting attacks.A remote user can create specially crafted HTML that, when loaded by a target user, will bypass the Microsoft Internet Explorer same origin domain policy and execute arbitrary...
Last Update Date: 3 Feb 2015 11:53 Release Date: 3 Feb 2015 6279 Views

RISK: High Risk

High Risk

Glibc Buffer Overflow "GHOST" vulnerability

A vulnerability was identified in Glibc. A remote user can execute arbitrary code on the target system. A local user can obtain elevated privileges on the target system. A remote or local user can send specially crafted data to trigger a buffer overflow in __nss_hostname_digits_dots() and...
Last Update Date: 30 Jan 2015 09:43 Release Date: 30 Jan 2015 6218 Views

RISK: High Risk

High Risk

Apple Products (OS X, Safari, iOS and Apple TV) Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, Safari, iOS and Apple TV, which can cause remote code execution and security restriction bypass.
Last Update Date: 29 Jan 2015 15:29 Release Date: 29 Jan 2015 6091 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities ws identified in Adobe Flash Player. A remote user can bypass the memory address randomization security feature and cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted Flash content that, when loaded by...
Last Update Date: 28 Jan 2015 Release Date: 23 Jan 2015 6676 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP. A remote user can execute arbitrary code on the target system and cause denial of service conditions. A user can create a specially crafted PHP file that will trigger a use-after-free memory error in the PHP unserialize() ...
Last Update Date: 27 Jan 2015 09:32 Release Date: 27 Jan 2015 6168 Views

RISK: High Risk

High Risk

Symantec Critical System Protection Multiple Vulnerabilities

Multiple vulnerabilities were identified in Symantec Critical System Protection. A remote authenticated user can execute arbitrary code on the target system, inject SQL commands, and obtain potentially sensitive information. A remote user can conduct cross-site scripting attacks. A local user can bypass security...
Last Update Date: 21 Jan 2015 10:45 Release Date: 21 Jan 2015 6171 Views

RISK: High Risk

High Risk

MySQL Multiple Vulnerabilites

Multiple vulnerabilities were identified in MySQL. A remote user can cause partial denial of service conditions, partially access and modify data on the target system.
Last Update Date: 21 Jan 2015 10:42 Release Date: 21 Jan 2015 6081 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Oracle Products.Multiple vulnerabilities were identified in Oracle Fusion Middleware. A remote user can gain elevated privileges, partially access and modify data on the target system. A remote or local user can cause partial denial of service conditions.Several vulnerabilities...
Last Update Date: 21 Jan 2015 10:39 Release Date: 21 Jan 2015 6354 Views

RISK: Medium Risk

Medium Risk

Moodle Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Moodle, which can be exploited by malicious users to bypass certain security restrictions, conduct script insertion attacks, conduct cross-site request forgery attacks and cause a DoS (Denial of Service).
Last Update Date: 20 Jan 2015 10:28 Release Date: 20 Jan 2015 6019 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, conduct cross-site request forgery attacks, and obtain potentially sensitive information. A remote user can create specially crafted...
Last Update Date: 15 Jan 2015 11:53 Release Date: 15 Jan 2015 6004 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the WebDAV kernel-mode driver (mrxdav.sys) when it fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security and gain elevated privileges on a targeted system...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6275 Views

RISK: Medium Risk

Medium Risk

Network Policy Server Denial of Service Vulnerability

This is a denial of service vulnerability. An unauthenticated attacker who successfully exploited this vulnerability could send specially crafted username strings to an Internet Authentication Service (IAS) or Network Policy Server (NPS), causing a denial of service condition for RADIUS authentication on the IAS or...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6067 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Error Reporting Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Windows Error Reporting (WER) that allows administrative users to view the memory contents of processes protected by "Protected Process Light." "Protected Process Light" inhibits debugging of critical system processes by arbitrary users on the system, even administrative...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6245 Views

RISK: Medium Risk

Medium Risk

Network Location Awareness Service Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Network Location Awareness (NLA) service that could unintentionally relax the firewall policy and/or configuration of certain services. This could increase the surface exposed to an attacker. The vulnerability is caused when the NLA service fails to...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6111 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Components Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the TS WebProxy Windows component. The vulnerability is caused when Windows fails to properly sanitize file paths. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6092 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows User Profile Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Windows User Profile Service (ProfSvc) validates user privilege. An authenticated attacker who successfully exploits the vulnerability could leverage the Windows User Profile Service (ProfSvc) to load registry hives associated with other user accounts and potentially execute...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6206 Views

RISK: High Risk

High Risk

Microsoft Windows Telnet Service Remote Code Execution Vulnerability

A buffer overflow vulnerability exists in Windows Telnet service that could allow remote code execution. The vulnerability is caused when the Telnet service improperly validates user input. An attacker could attempt to exploit this vulnerability by sending specially crafted telnet packets to a Windows server, and if...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6835 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Application Compatibility Cache Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Microsoft Windows Application Compatibility Infrastructure (AppCompat) improperly checks the authorization of the caller's impersonation token. An attacker could attempt to exploit this to run a privileged application. The update addresses the vulnerability by implementing proper...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 6150 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system, and obtain potentially sensitive information. A remote user can create specially crafted Flash content that, when loaded by the target user...
Last Update Date: 14 Jan 2015 09:47 Release Date: 14 Jan 2015 6101 Views

RISK: High Risk

High Risk

Windows Kernel Elevation of Privilege Vulnerability

A vulnerability has been identified in Windows Kernel, which can be exploited by local user to obtain elevated privileges on the target system. The NtApphelpCacheControl() function in 'ahcache.sys' does not properly validate the caller's impersonation token for administrator privileges. A...
Last Update Date: 5 Jan 2015 10:26 Release Date: 5 Jan 2015 6496 Views

RISK: Medium Risk

Medium Risk

Docker Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Docker, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to manipulate certain data.An error when extracting images or mounting volumes can be exploited to e.g. manipulate certain...
Last Update Date: 29 Dec 2014 10:13 Release Date: 29 Dec 2014 6316 Views

RISK: High Risk

High Risk

"Misfortune Cookie" Vulnerability on Multiple Broadband Routers

Many home and office/home office (SOHO) routers have been identitied to be using vulnerable versions of the Allegro RomPager embedded web server. Allegro RomPager versions prior to 4.34 contain a vulnerability in cookie processing code that can be leveraged to grant attackers administrative...
Last Update Date: 22 Dec 2014 10:56 Release Date: 22 Dec 2014 6682 Views

RISK: Medium Risk

Medium Risk

Network Time Protocol daemon (ntpd) Multiple Vulnerabilities

The buffer overflow vulnerabilities were identified in ntpd, which may allow a remote unauthenticated attacker to execute arbitrary malicious code with the privilege level of the ntpd process. The weak default key and non-cryptographic random number generator in ntp-keygen may allow an attacker to...
Last Update Date: 22 Dec 2014 10:45 Release Date: 22 Dec 2014 6659 Views

RISK: Medium Risk

Medium Risk

WordPress Download Manager Security Bypass Vulnerability

A vulnerability has been identified in the Download Manager plugin for WordPress, which can be exploited by malicious people to bypass certain security restrictions.This vulnerability is caused due to the plugin not properly restricting access to certain administrative functionality, which can be exploited to perform otherwise...
Last Update Date: 19 Dec 2014 10:47 Release Date: 19 Dec 2014 6649 Views

RISK: Medium Risk

Medium Risk

Microsoft Graphics Component Information Disclosure Vulnerability

An information disclosure vulnerability exists in the Microsoft Graphics Component that could allow an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. The vulnerability is caused when the Microsoft Graphics Component improperly handles the decoding of JPEG images in memory. ...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6077 Views

RISK: High Risk

High Risk

VBScript Scripting Engine Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine, when rendered in Internet Explorer, handles objects in memory. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6142 Views

RISK: High Risk

High Risk

Microsoft Excel Remote Code Execution Vulnerabilities

Global Free Remote Code Execution in Excel Vulnerability A remote code execution vulnerability exists in how Microsoft Excel improperly handles objects in memory while parsing specially crafted Office files. System memory may be corrupted in such a way that an attacker could execute arbitrary code. An attacker...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6194 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6070 Views

RISK: High Risk

High Risk

Microsoft Word and Office Web Apps Remote Code Execution Vulnerabilities

Invalid Index Remote Code Execution Vulnerability A remote code execution vulnerability exists in how Microsoft Word improperly handles objects in memory while parsing specially crafted Office files. System memory may be corrupted in such a way that an attacker could execute arbitrary code. An attacker who successfully...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6090 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Memory Corruption Vulnerabilities in Internet Explorer Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6069 Views