Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Elevation of Privilege Vulnerabilities

Outlook Web App Token Spoofing Vulnerability A token spoofing vulnerability exists in Exchange Server when Microsoft Outlook Web App (OWA) fails to properly validate a request token. An attacker who successfully exploited this vulnerability could then use the vulnerability to send email that appears to come...
Last Update Date: 16 Dec 2014 Release Date: 10 Dec 2014 6449 Views

RISK: Medium Risk

Medium Risk

OpenSSL 3.0 (SSLv3) Information Disclosure Vulnerability

A vulnerability was identified in OpenSSL (SSLv3), which could be exploited by remote attackers to decrypt SSL sessions in certain cases and disclose sensitive information.
Last Update Date: 16 Dec 2014 Release Date: 16 Oct 2014 7349 Views

RISK: Medium Risk

Medium Risk

Apache mod_proxy_fcgi Denial of Service Vulnerability

A vulnerability was identified in Apache mod_proxy_fcgi. A remote user can cause denial of service conditions.A remote FastCGI server can return specially crafted response headers to trigger a buffer overflow in handle_headers() function in 'mod_proxy_fcgi.c' and cause the target Apache server to...
Last Update Date: 16 Dec 2014 09:33 Release Date: 16 Dec 2014 6225 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. For more information: SA14121008
Last Update Date: 10 Dec 2014 12:21 Release Date: 10 Dec 2014 6104 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Denial of Service Vulnerability

A vulnerability has been identified in Adobe ColdFusion, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 10 Dec 2014 12:19 Release Date: 10 Dec 2014 5887 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Multiple Vulnerabilities

Mulitple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. NOTE: The vulnerability of CVE-2014-9163 was currently...
Last Update Date: 10 Dec 2014 12:17 Release Date: 10 Dec 2014 6406 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Adobe Acrobat, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system.
Last Update Date: 10 Dec 2014 12:16 Release Date: 10 Dec 2014 5927 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited to conduct arbitrary code execution, sensitive information disclosure and tampering.
Last Update Date: 9 Dec 2014 Release Date: 4 Dec 2014 6075 Views

RISK: Medium Risk

Medium Risk

ISC BIND Denial of Service Vulnerability

A vulnerability was identified in ISC BIND. A remote user can cause denial of service conditions. Attackers can exploit the defects in delegation handling and GeoIP features to exhaust resource and cause BIND to crash.
Last Update Date: 9 Dec 2014 11:04 Release Date: 9 Dec 2014 6032 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a use-after-free error when handling CElement objects and can be exploited to cause...
Last Update Date: 9 Dec 2014 09:19 Release Date: 9 Dec 2014 6463 Views

RISK: Medium Risk

Medium Risk

VMware vSphere Product Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware vSphere product, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and cause a DoS (Denial of Service).
Last Update Date: 8 Dec 2014 12:34 Release Date: 8 Dec 2014 6127 Views

RISK: High Risk

High Risk

Microsoft Windows Denial of Service Vulnerability

A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the "xxxMenuWindowProc()" function (win32k.sys) and can be...
Last Update Date: 5 Dec 2014 10:19 Release Date: 5 Dec 2014 6261 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin Denial of Service Vulnerability

A vulnerability have been identified in phpMyAdmin, which can be exploited by malicious users to cause a DoS (Denial of Service). An error related to long passwords can be exploited to consume excessive CPU resources.
Last Update Date: 5 Dec 2014 10:04 Release Date: 5 Dec 2014 5916 Views

RISK: Medium Risk

Medium Risk

OpenVPN Deny Service Vulnerability

A vulnerability was reported in OpenVPN. A remote authenticated user can cause denial of service conditions. A remote authenticated user (TLS-authenticated using certificates) can send a specially crafted control channel packet to cause the target service to crash. Version 3.x is...
Last Update Date: 3 Dec 2014 10:05 Release Date: 3 Dec 2014 6030 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

A security issue and some vulnerabilities have been identified in Mozilla Firefox, where one has an unknown impact and others can be exploited by malicious, local users to disclose potentially sensitive information and by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and...
Last Update Date: 3 Dec 2014 10:03 Release Date: 3 Dec 2014 5865 Views

RISK: Medium Risk

Medium Risk

Wordpress DukaPress Plugin Sensitive Information Disclosure Vulnerability

A vulnerability was identified in the DukaPress Plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information. Input passed via the "src" GET parameter to \lib\dp_image.php is not properly verified before being used to...
Last Update Date: 28 Nov 2014 09:27 Release Date: 28 Nov 2014 5896 Views

RISK: High Risk

High Risk

Microsoft Windows Kerberos Elevation of Privilege Vulnerability

A remote elevation of privilege vulnerability exists in implementations of Kerberos KDC in Microsoft Windows. The vulnerability exists when the Microsoft Kerberos KDC implementations fail to properly validate signatures, which can allow for certain aspects of a Kerberos service ticket to be forged. Microsoft received information about...
Last Update Date: 27 Nov 2014 Release Date: 19 Nov 2014 6440 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Remote Users Deny Service Vulnerability

A vulnerability was identified in Cisco IOS XR. A remote user can cause denial of service conditions. A remote user can send multiple specially crafted Locator/ID Separation Protocol (LISP) TCP sessions to cause the target LISP service to reload.
Last Update Date: 26 Nov 2014 10:07 Release Date: 26 Nov 2014 5871 Views

RISK: High Risk

High Risk

Adobe Flash Player Remote Code Execution Vulnerabilities

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a use-after...
Last Update Date: 26 Nov 2014 10:07 Release Date: 26 Nov 2014 6009 Views

RISK: Medium Risk

Medium Risk

Asterisk Multiple Vulnerbilities

Multiple vulnerabilities have been identified in Asterisk, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.Some errors related to VoIP channel drivers, DUNDi, and AMI can...
Last Update Date: 25 Nov 2014 10:47 Release Date: 25 Nov 2014 5812 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple Vulerabilities

Two vulnerabilities were identified in Drupal.A remote user can send a specially crafted request to gain access to another user's session.A remote user can send specially crafted data to the password hashing API to consume excessive memory and CPU resources, causing the target...
Last Update Date: 25 Nov 2014 10:47 Release Date: 25 Nov 2014 5830 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system. An unspecified error can be exploited to spoof the address bar...
Last Update Date: 25 Nov 2014 Release Date: 20 Nov 2014 6167 Views

RISK: Medium Risk

Medium Risk

GnuTLS ECC Certificate Processing Vulnerability

A vulnerability has been identified in GnuTLS. A remote user can cause denial of service conditions.   A remote user can send a specially crafted Elliptic Curve Cryptography (ECC) certificate or certificate signing request (CSR) that, when processed by the target application, will...
Last Update Date: 19 Nov 2014 Release Date: 13 Nov 2014 5901 Views

RISK: High Risk

High Risk

Cisco IOS Information Disclosure Vulnerability

A vulnerability was identified in Cisco IOS. A remote user can obtain potentially sensitive information.The system does not properly initialize packet buffers. A remote user can connect to the DLSw port (TCP port 2067) to obtain potentially sensitive information from previously processed packets. ...
Last Update Date: 18 Nov 2014 15:23 Release Date: 18 Nov 2014 6120 Views

RISK: High Risk

High Risk

Apple Product Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X, which may be exploited to execute arbitrary code, cause denial of service and access confidential data.Multiple vulnerabilities were identified in Apple iOS. A local user may be able to execute arbitrary code, cause denial of service...
Last Update Date: 18 Nov 2014 15:22 Release Date: 18 Nov 2014 6273 Views

RISK: High Risk

High Risk

Microsoft Kernel-Mode Driver Denial of Service Vulnerability

A denial of service vulnerability exists in the Windows kernel-mode driver that is caused by the improper handling of TrueType font objects in memory. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6114 Views

RISK: Medium Risk

Medium Risk

Microsoft IME (Japanese) Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft IME for Japanese that is caused when a vulnerable sandboxed application uses Microsoft IME (Japanese). Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft was aware of limited attacks that...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6176 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Federation Services Information Disclosure Vulnerability

An information disclosure vulnerability exists when Active Directory Federation Services (AD FS) fails to properly log off a user. The vulnerability could allow unintentional information disclosure. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6065 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Microsoft Information Services (IIS) that is caused when incoming web requests are not properly compared against the "IP and domain restriction" filtering list. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 7860 Views

RISK: Medium Risk

Medium Risk

Microsoft Remote Desktop Protocol Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Remote Desktop Protocol (RDP) when RDP does not properly log failed logon attempts. The vulnerability could allow an attacker to bypass the audit logon security feature. The security feature bypass by itself does not allow arbitrary code execution. ...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6427 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Foundation Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when SharePoint Server does not properly sanitize page content in SharePoint lists. An authenticated attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on user. Microsoft received information about this vulnerability through coordinated...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6021 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that .NET Framework handles TypeFilterLevel checks for some malformed objects. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 5913 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows TCP/IP stack (tcpip.sys, tcpip6.sys) that is caused when the Windows TCP/IP stack fails to properly handle objects in memory during IOCTL processing. This vulnerability has been publicly disclosed. ...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6004 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Audio Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows audio service component. The vulnerability is caused when the Microsoft Windows Audio service improperly validates permissions under specific conditions, potentially allowing script to be run with elevated privileges. Microsoft received information about this vulnerability through coordinated vulnerability disclosure...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6070 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Double Delete Remote Code Execution VulnerabilityA remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. Microsoft received information about the vulnerability through coordinated vulnerability disclosure...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 5984 Views

RISK: High Risk

High Risk

Microsoft Schannel Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Secure Channel (Schannel) security package due to the improper processing of specially crafted packets. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6369 Views

RISK: High Risk

High Risk

Microsoft XML Core Services Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft XML Core Services (MSXML) improperly parses XML content, which can corrupt the system state in such a way as to allow an attacker to run arbitrary code. The vulnerability could allow remote code execution if a user opens...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6171 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the vulnerabilities by...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6001 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Remote Code Execution Vulnerabilities

Windows OLE Automation Array Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 6274 Views

RISK: High Risk

High Risk

Apple iOS Masque Attack

Masque attack works by luring users to install an app from a source other than the iOS App Store or their organizations’ provisioning system. In order for the attack to succeed, a user must install an untrusted app, such as one delivered through a phishing link...
Last Update Date: 17 Nov 2014 10:25 Release Date: 17 Nov 2014 6537 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, arbitrary code execution, and compromise a user's system. Several unspecified errors can also...
Last Update Date: 12 Nov 2014 17:49 Release Date: 12 Nov 2014 6223 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a user's system...
Last Update Date: 12 Nov 2014 16:56 Release Date: 12 Nov 2014 6157 Views

RISK: Medium Risk

Medium Risk

GNU Wget Arbitrary Filesystem Access Vulnerability

A vulnerability was identified in wget. A remote user can cause arbitrary files, directories, and symlinks to be created on the target user's system. A remote unauthenticated malicious FTP server, connected to the victim via wget, can create and overwrite arbitrary files...
Last Update Date: 30 Oct 2014 10:20 Release Date: 30 Oct 2014 6273 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Portal Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct cross site scripting, security restriction bypass, and sensitive information disclosure.
Last Update Date: 29 Oct 2014 09:31 Release Date: 29 Oct 2014 6064 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes / Domino Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Notes and IBM Lotus Domino, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, bypass certain security restrictions, and compromise a vulnerable system.
Last Update Date: 27 Oct 2014 12:05 Release Date: 27 Oct 2014 6391 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Vulnerability being used by Ransomware in Malvertising

Security researchers at Proofpoint discovered CryptoWall 2. ransomware used malvertising# to infect the computers with outdated Adobe flash players running on Windows.   Without having to click on anything, visitors to the impacted websites which serve Adobe Flash enabled embedded advertisement may be stealthily infected with the...
Last Update Date: 24 Oct 2014 12:08 Release Date: 24 Oct 2014 8148 Views

RISK: Medium Risk

Medium Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which can be exploited by malicious people to disclose potentially sensitive information and conduct spoofing attacks. An error exists in Human Interface Device-class Bluetooth. An error exists in the SSL 3. protocol.
Last Update Date: 24 Oct 2014 Release Date: 22 Oct 2014 6167 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Windows OLE Object Handling Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when handling OLE objects embedded within Microsoft Office files and can be exploited to...
Last Update Date: 23 Oct 2014 09:22 Release Date: 23 Oct 2014 6934 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, where some have an unknown impact and the others can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system.
Last Update Date: 22 Oct 2014 Release Date: 20 Oct 2014 6205 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, which can be exploited by malicious users to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), gain escalated privileges and compromise a vulnerable system.The product bundles a vulnerable...
Last Update Date: 22 Oct 2014 Release Date: 20 Oct 2014 6275 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.The vulnerabilities are caused due to a bundled vulnerable version of the Adobe Flash Player.
Last Update Date: 19 Oct 2014 Release Date: 16 Oct 2014 6056 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to denial of service, escalation of privilege, sensitive information disclosure and data tampering.
Last Update Date: 16 Oct 2014 14:37 Release Date: 16 Oct 2014 6723 Views

RISK: Medium Risk

Medium Risk

Apache mod_cache Denial of Service Vulnerability

A vulnerability was identified in Apache mod_cache. A remote user can cause denial of service conditions. A remote user can send a specially crafted Content-Type header value to trigger a null pointer dereference and cause the target service to crash.
Last Update Date: 16 Oct 2014 Release Date: 15 Oct 2014 5927 Views

RISK: High Risk

High Risk

Adobe ColdFusion Multiple Vulnerabilities

Several vulnerabilities were identified in Adobe ColdFusion.A local user can bypass access control restrictions.A remote user can conduct cross-site scripting attacks.A remote user can conduct cross-site request forgery attacks.
Last Update Date: 16 Oct 2014 Release Date: 15 Oct 2014 5974 Views

RISK: High Risk

High Risk

Mozilla Firefox/ Thunderbird Multiple vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox and Thunderbird.A remote user can cause arbitrary code to be executed on the target user's system.A remote user can obtian potentially sensitive information.A remote user can bypass same-origin policy.
Last Update Date: 16 Oct 2014 Release Date: 15 Oct 2014 6184 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Remote Code Execution Vulnerabilities

Win32k.sys Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change...
Last Update Date: 15 Oct 2014 17:55 Release Date: 15 Oct 2014 6464 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows FAT32 Disk Partition Driver Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way the Windows FASTFAT system driver interacts with FAT32 disk partitions. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated privileges.
Last Update Date: 15 Oct 2014 17:51 Release Date: 15 Oct 2014 6224 Views

RISK: Medium Risk

Medium Risk

Microsoft Message Queuing Service Elevation of Privilege Vulnerability

A vulnerability exists in the Microsoft Message Queuing (MSMQ) service that could allow an attacker to elevate privileges on the targeted system.
Last Update Date: 15 Oct 2014 17:51 Release Date: 15 Oct 2014 5938 Views

RISK: Medium Risk

Medium Risk

Microsoft Word and Office Web Apps Remote Code Execution Vulnerability

A remote code execution vulnerability exists in way that Microsoft Office software parses certain properties of Microsoft Word files. If an attacker is successful in exploiting this vulnerability, and if the current user is logged on with administrative user rights, the attacker could take complete control of...
Last Update Date: 15 Oct 2014 17:51 Release Date: 15 Oct 2014 5965 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OLE Remote Code Execution Vulnerability

A vulnerability exists in Windows OLE that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If the current user...
Last Update Date: 15 Oct 2014 17:51 Release Date: 15 Oct 2014 6064 Views

RISK: Medium Risk

Medium Risk

Microsoft ASP.NET MVC Security Feature Bypass Vulnerability

A cross-site scripting (XSS) vulnerability exists in ASP.NET MVC that could allow an attacker to inject a client-side script into the user's web browser. The script could spoof content, disclose information, or take any action that the...
Last Update Date: 15 Oct 2014 17:51 Release Date: 15 Oct 2014 6528 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Remote Code Execution Vulnerabilities

.NET ClickOnce Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in Microsoft .NET Framework that could allow an attacker to elevate privileges on the targeted system..NET Framework Remote Code Execution VulnerabilityA remote code execution vulnerability exists in the way that Microsoft .NET Framework improperly...
Last Update Date: 15 Oct 2014 17:50 Release Date: 15 Oct 2014 6299 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Elevation of Privilege Vulnerabilities in Internet ExplorerElevation of privilege vulnerabilities exist within Internet Explorer. An attacker who successfully exploited these vulnerabilities could elevate privileges in affected versions of Internet Explorer. These vulnerabilities by themselves do not allow arbitrary code to be run. However, these vulnerabilities...
Last Update Date: 15 Oct 2014 17:50 Release Date: 15 Oct 2014 6041 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system.An unspecified error can be exploited to corrupt memory and subsequently execute arbitrary code.Another unspecified error can be...
Last Update Date: 15 Oct 2014 16:39 Release Date: 15 Oct 2014 6138 Views

RISK: Medium Risk

Medium Risk

Python Multiple Integer Overflow Vulnerabilities

Some vulnerabilities have been identified in Python, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. Successful exploitation of these vulnerabilities may allow execution of arbitrary code.
Last Update Date: 15 Oct 2014 Release Date: 14 Oct 2014 6258 Views

RISK: Medium Risk

Medium Risk

Joomla Denial Of Service Vulnerability

A vulnerability has been identified in Joomla!, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error. No further information is currently available.
Last Update Date: 13 Oct 2014 18:56 Release Date: 13 Oct 2014 6067 Views

RISK: Medium Risk

Medium Risk

Bugzilla Multiple Vulnerabilities

A security issue and some vulnerabilities have been identified in Bugzilla, which can be exploited by malicious users to disclose potentially sensitive information and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.An error within the flagmail email...
Last Update Date: 13 Oct 2014 18:55 Release Date: 13 Oct 2014 6257 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Multiple vulnerabilities

Multiple vulnerabilities were identified in Cisco ASA. A remote authenticated user can execute arbitrary code on the target system. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting attacks. A local user can gain elevated privileges.
Last Update Date: 10 Oct 2014 14:58 Release Date: 10 Oct 2014 6161 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a vulnerable system. Some errors related to V8 and IPC can be exploited to execute arbitrary code outside the sandbox...
Last Update Date: 9 Oct 2014 10:08 Release Date: 9 Oct 2014 6430 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server mod_cache Denial of Service Vulnerability

A vulnerability has been identified in Apache HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to a NULL pointer dereference error within the "cache_merge_headers_out()" function (modules/cache/cache_util....
Last Update Date: 7 Oct 2014 09:19 Release Date: 7 Oct 2014 6772 Views

RISK: Medium Risk

Medium Risk

Fake CODE4HK Mobile Application Attack

A fake mobile application named CODE4HK claiming to coordinating the Occupy Central pro-democracy movement has circulated online since 16 Sep 2014. Malicious behaviours were identified in a fake CODE4HK mobile application, which can cause information disclosure. [UPDATE 2014-10-03]A security...
Last Update Date: 3 Oct 2014 Release Date: 18 Sep 2014 7607 Views

RISK: Extremely High Risk

Extremely High Risk

Beware of Web defacement attacks targeting Hong Kong

1. Multiple Hong Kong websites were found defaced. They were injected with the logo and slogan of the attacker claimed to be from "OpHongKong hosted by Anonymous". These websites covered different small private businesses. 2. The attacks used security vulnerabilities of the web server...
Last Update Date: 2 Oct 2014 21:01 Release Date: 2 Oct 2014 9757 Views

RISK: Extremely High Risk

Extremely High Risk

GNU Bash "Shellshock" Vulnerability

A vulnerability has been identified in bash (GNU Bourne-Again Shell), related to how environment variables are processed. The vulnerability is now known as "Shellshock".   In many common configurations, this vulnerability is exploitable over the network, especially if bash has been configured...
Last Update Date: 30 Sep 2014 Release Date: 25 Sep 2014 9557 Views

RISK: Medium Risk

Medium Risk

Node.js V8 Stack Overflow Denial of Service Vulnerability

A vulnerability has been identified in Node.js, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the bundled V8 library when handling certain recursive work loads, which can be...
Last Update Date: 26 Sep 2014 Release Date: 5 Sep 2014 6471 Views

RISK: Medium Risk

Medium Risk

Mozilla Network Security Services (NSS) ASN.1 Verification Vulnerability

A vulnerability has been identified in Mozilla Network Security Services (NSS). A remote user can forge digital certificates.   The library does not properly parse ASN.1 values in a digital signature. A user can conduct a Bleichenbacher attack variant against the RSA algorithm to create...
Last Update Date: 26 Sep 2014 Release Date: 25 Sep 2014 6427 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Software and Cisco IOS XE Software Multiple Denial of Service Vulnerabilities

Mulitple vulnerabilities were identified in Cisco IOS Software and Cisco IOS XE Software, which could be exploited by an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Last Update Date: 26 Sep 2014 11:10 Release Date: 26 Sep 2014 6643 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities were reported in Cisco IOS XR. A remote user can cause denial of service conditions.   A remote user can send a specially crafted RSVP packet to cause the target RSVP process to reload, a specially crafted SNMPv2 packet to cause the target snmpd process to...
Last Update Date: 23 Sep 2014 09:49 Release Date: 23 Sep 2014 6294 Views

RISK: Medium Risk

Medium Risk

Apple Safari Security Issue and Multiple Vulnerabilities

A security issue and multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to disclose sensitive information and compromise a user's system.The application does not properly restrict password autofill functionality for untrusted websites, which can...
Last Update Date: 19 Sep 2014 16:40 Release Date: 19 Sep 2014 6635 Views

RISK: High Risk

High Risk

Apple iOS Security Issue and Multiple Vulnerabilities

A security issue and multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people with physical access to disclose potentially sensitive information and bypass certain security restrictions and by malicious people to disclose certain sensitive information and compromise a vulnerable device.An unspecified...
Last Update Date: 19 Sep 2014 16:38 Release Date: 19 Sep 2014 6682 Views

RISK: Medium Risk

Medium Risk

Apple OS X Multiple Vulnerabilities

Apple has issued a security update for Mac OS X, which fixes a weakness, a security issue, and some vulnerabilities.The product bundles a vulnerable version of PHP.An unspecified error related to Bluetooth can be exploited to execute arbitrary code with escalated privileges....
Last Update Date: 19 Sep 2014 16:36 Release Date: 19 Sep 2014 6329 Views

RISK: High Risk

High Risk

Google Android Browser Access Control Vulnerability

A vulnerability has been identified in Google Android Browser. A remote user can bypass same origin policy.   A remote user can create specially crafted HTML that, when loaded by a target user, will cause arbitrary scripting code to be executed by the target user's...
Last Update Date: 19 Sep 2014 Release Date: 18 Sep 2014 6306 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities were identified in Adobe Acrobat and Adobe Reader. A remote user can cause arbitrary code to be executed on the target user's system, cause denial of service conditions, and conduct cross-site scripting attacks.
Last Update Date: 17 Sep 2014 09:51 Release Date: 17 Sep 2014 6381 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Arbitrary JSP Code Upload Vulnerability

A vulnerability has been identified in Apache Tomcat. A remote user can execute arbitrary code on the target system in certain cases. A remote user can upload arbitrary JSP code and then cause the code to be executed in certain limited cases.
Last Update Date: 17 Sep 2014 Release Date: 11 Sep 2014 6451 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Internet Explorer Resource Information Disclosure VulnerabilityAn information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications in use on a target and use the information to avoid detection.Multiple Memory...
Last Update Date: 10 Sep 2014 14:56 Release Date: 10 Sep 2014 6161 Views

RISK: Medium Risk

Medium Risk

Microsoft Lync Server Denial of Service Vulnerabilities

Lync Denial of Service VulnerabilityA denial of service vulnerability exists in Lync Server. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.Lync XSS Information Disclosure VulnerabilityA reflected cross-site scripting (XSS) vulnerability, which could result in information...
Last Update Date: 10 Sep 2014 12:41 Release Date: 10 Sep 2014 6053 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR DHCPv6 Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS XR. A remote user can cause denial of service conditions. A remote user can send a specially crafted DHCPv6 packet to cause the target DHCPv6 service to crash. Successful exploitation requires the device to be configured as DHCPv6 server.
Last Update Date: 10 Sep 2014 12:40 Release Date: 10 Sep 2014 6217 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A use-after-free error exists in rendering may allow execution of...
Last Update Date: 10 Sep 2014 12:40 Release Date: 10 Sep 2014 6090 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Task Scheduler Vulnerability

An elevation of privilege vulnerability exists in how Windows Task Scheduler improperly conducts integrity checks on tasks. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or...
Last Update Date: 10 Sep 2014 12:39 Release Date: 10 Sep 2014 6049 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. Multiple unspecified errors can be exploited to corrupt memory, bypass the same origin policy...
Last Update Date: 10 Sep 2014 12:39 Release Date: 10 Sep 2014 6300 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Unspecified Vulnerabilities

Multiple vulnerabilities with an unknown impact have been identified in Adobe Reader and Adobe Acrobat. No further information is currently available. NOTE: No official solution is currently available. Adobe is planning to release an update within the week of the 15th September 2014.
Last Update Date: 10 Sep 2014 12:39 Release Date: 10 Sep 2014 6157 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Denial of Service Vulnerability

A denial of service vulnerability exists in the way that Microsoft .NET Framework handles specially crafted requests, causing a hash collision. An attacker who successfully exploited this vulnerability could send a small number of specially crafted requests to a .NET server, causing performance to degrade...
Last Update Date: 10 Sep 2014 12:38 Release Date: 10 Sep 2014 6132 Views

RISK: Medium Risk

Medium Risk

LibreOffice Multiple Vulnerabilities

Multiple vulnerabilities have been identified in LibreOffice, which can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system.
Last Update Date: 5 Sep 2014 Release Date: 4 Sep 2014 6006 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system. Some unspecified errors can be exploited to cause memory corruption.A use-after-free error during...
Last Update Date: 5 Sep 2014 Release Date: 4 Sep 2014 6177 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server Multiple vulnerabilities

Multiple vulnerabilities were identified in Apache HTTP Server, which could be exploited by malicious people to execute arbitrary code and cause denial of service (DoS). 
Last Update Date: 5 Sep 2014 11:27 Release Date: 5 Sep 2014 6610 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR IPv6 Packets Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when processing certain IP version 6 packets, which can be exploited to cause...
Last Update Date: 5 Sep 2014 11:25 Release Date: 5 Sep 2014 6124 Views

RISK: Medium Risk

Medium Risk

IBM Notes / Domino Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM Notes and IBM Domino, which can be exploited by malicious, local users to manipulate certain data and cause a DoS (Denial of Service), and by malicious people to disclose sensitive information, manipulate certain data, cause...
Last Update Date: 29 Aug 2014 10:40 Release Date: 29 Aug 2014 6112 Views

RISK: High Risk

High Risk

Microsoft Windows Media Center Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Windows Media Center, which could be exploited by convincing a user to open a specially crafted Microsoft Office file.
Last Update Date: 29 Aug 2014 Release Date: 13 Aug 2014 5878 Views

RISK: Medium Risk

Medium Risk

WinSCP Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WinSCP, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a user's system.
Last Update Date: 28 Aug 2014 Release Date: 25 Aug 2014 6346 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system. Some errors within V8, IPC, sync, and extensions can be exploited to execute...
Last Update Date: 28 Aug 2014 17:17 Release Date: 28 Aug 2014 5941 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles window handle thread-owned objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, ...
Last Update Date: 28 Aug 2014 Release Date: 13 Aug 2014 6070 Views