Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles window handle thread-owned objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, ...
Last Update Date: 28 Aug 2014 Release Date: 13 Aug 2014 6080 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Manager Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco Unified Communications Manager. A remote authenticated user can cause denial of service conditions and execute arbitrary commands on the target system. A remote authenticated user on a registered endpoint can send specially crafted XML data via SIP to cause the target process...
Last Update Date: 27 Aug 2014 Release Date: 13 Aug 2014 6110 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Software Packet Parsing Denial of Service Vulnerability

A vulnerability was identified in Cisco ASR 9000 Series Routers. A remote user can cause denial of service conditions. A remote user on the adjacent network can send a specially crafted packet with a multicast destination MAC address through a target device configured with NetFlow sampling to trigger...
Last Update Date: 27 Aug 2014 10:19 Release Date: 27 Aug 2014 6148 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM HTTP Server, which could be exploited by malicious people to execute arbitrary code and cause denial of service (DoS).
Last Update Date: 26 Aug 2014 09:48 Release Date: 26 Aug 2014 6035 Views

RISK: Medium Risk

Medium Risk

Drupal Notify Module Information Disclosure Security Issue

 A security issue has been identified in the Notify module for Drupal, which can be exploited by malicious users to disclose potentially sensitive information. The security issue is caused due to the module not properly verifying permissions when handling notification emails and can be exploited...
Last Update Date: 19 Aug 2014 10:17 Release Date: 19 Aug 2014 6157 Views

RISK: High Risk

High Risk

Apple Safari Memory Corruption Vulnerability

A vulnerability has been identified in Apple Safari. Multiple memory corruption issues existed in WebKit. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
Last Update Date: 15 Aug 2014 Release Date: 14 Aug 2014 6628 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been idenified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. The application bundles a vulnerable version of Adobe Flash Player. A use-after...
Last Update Date: 15 Aug 2014 Release Date: 14 Aug 2014 6439 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Internet Explorer Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist in Internet Explorer. An attacker who successfully exploited these vulnerabilities could elevate privileges in affected versions of Internet Explorer. These vulnerabilities by themselves do not allow arbitrary code to be run. However, these vulnerabilities...
Last Update Date: 13 Aug 2014 15:26 Release Date: 13 Aug 2014 6157 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Server Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in SharePoint Server. An authenticated attacker who successfully exploited this vulnerability could use a specially crafted app to run arbitrary code in the security context of the logged-on user.
Last Update Date: 13 Aug 2014 15:25 Release Date: 13 Aug 2014 6048 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Installer Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when the Windows Installer service improperly handles the repair of a previously installed application. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data...
Last Update Date: 13 Aug 2014 15:25 Release Date: 13 Aug 2014 6109 Views

RISK: Medium Risk

Medium Risk

Microsoft OneNote Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft OneNote parses specially crafted files. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker...
Last Update Date: 13 Aug 2014 15:24 Release Date: 13 Aug 2014 6086 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LRPC Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Microsoft Remote Procedure Call (LRPC). The problem is that an LRPC server may leak the message it receives from the client if the message is of a specific type and has a data view attached (which is not expected for...
Last Update Date: 13 Aug 2014 15:23 Release Date: 13 Aug 2014 6799 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Microsoft .NET Framework that could allow an attacker to bypass the Address Space Layout Randomization (ASLR) security feature, which helps protect users from a broad class of vulnerabilities. The security feature bypass by itself does not allow...
Last Update Date: 13 Aug 2014 15:14 Release Date: 13 Aug 2014 6210 Views

RISK: Medium Risk

Medium Risk

Microsoft SQL Server Elevation of Privilege Vulnerabilities

SQL Master Data Services XSS VulnerabilityAn XSS vulnerability exists in SQL Master Data Services (MDS) that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take...
Last Update Date: 13 Aug 2014 15:13 Release Date: 13 Aug 2014 6566 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Acrobat & Reader for Windows Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Acrobat and Reader. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will bypass sandbox protections...
Last Update Date: 13 Aug 2014 14:41 Release Date: 13 Aug 2014 6531 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Two vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. An unspecified error can be exploited to bypass certain security restrictions. A use-...
Last Update Date: 13 Aug 2014 14:41 Release Date: 13 Aug 2014 6232 Views

RISK: Medium Risk

Medium Risk

IBM Tivoli Endpoint Manager Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM Tivoli Endpoint Manager for Remote Control, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 13 Aug 2014 Release Date: 12 Aug 2014 6312 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple vulnerabilities

Multiple vulnerabilities were identified in IBM WebSphere Application Server, which could be exploited by malicious people to execute arbitrary code, modify arbitrary file and disclose potentially sensitive information. The vulnerabilities are caused by a bundled vulnerable version of Java.
Last Update Date: 13 Aug 2014 Release Date: 12 Aug 2014 6387 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress, which can be exploited by malicious users to disclose certain sensitive information or cause a DoS (Denial of Service) and potentially compromise a vulnerable system. 1) An error in the xmlrpc.php script when expanding entity references...
Last Update Date: 8 Aug 2014 12:13 Release Date: 8 Aug 2014 6406 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple Vulnerabilities

Two vulnerabilities have been identified in Drupal, which can be exploited by malicious people to cause a DoS (Denial of Service).   1) An error in xmlrpc.php when expanding entity references and can be exploited to consume large amounts of memory and cause an hang...
Last Update Date: 8 Aug 2014 12:12 Release Date: 8 Aug 2014 6315 Views

RISK: Medium Risk

Medium Risk

Symantec Endpoint Protection Elevated Prilvilege Vulnerability

A vulnerability was identified in Symantec Endpoint Protection. A local user can obtain elevated privileges on the target system. A local user can execute arbitrary commands on the target system with system level privileges.   [Updated on 7-Aug-2014] Note: Exploit code is...
Last Update Date: 7 Aug 2014 Release Date: 1 Aug 2014 6691 Views

RISK: Medium Risk

Medium Risk

Cisco IOS and IOS XE Denial of Service Vulnerability

A vulnerability was reported in Cisco IOS and IOS XE. A remote user can cause denial of service conditions.A remote user can send a specially crafted EnergyWise packet to port 43440 on the target device to cause the target device to reload.Systems configured for EnergyWise...
Last Update Date: 7 Aug 2014 10:05 Release Date: 7 Aug 2014 6766 Views

RISK: High Risk

High Risk

SynoLocker Ransomware Affecting Synology DiskStation

A recent ransomware called “SynoLocker”, which is currently affecting certain Synology NAS servers.  Based on Synology current observations, this issue only affects Synology NAS servers running some older versions of DiskStation Manager (DSM 4.3-3810 or earlier), by exploiting a security...
Last Update Date: 6 Aug 2014 20:50 Release Date: 6 Aug 2014 10017 Views

RISK: Medium Risk

Medium Risk

Ubisoft Rayman Legends Buffer Overflow Vulnerability

A vulnerability was identified in Ubisoft Rayman Legends, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error when processing certain TCP packets and can be exploited to cause a stack-based buffer overflow...
Last Update Date: 6 Aug 2014 Release Date: 4 Aug 2014 6620 Views

RISK: High Risk

High Risk

Samba Heap Overflow Vulnerability

A vulnerability was identified in Samba, which can be exploited by remote user to execute arbitrary code on the target system.A remote user can send specially crafted packets to trigger a heap overflow in the target nmbd NetBIOS name services daemon and execute arbitrary code on the...
Last Update Date: 6 Aug 2014 Release Date: 4 Aug 2014 6630 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, bypass certain security restrictions, and compromise a vulnerable system.
Last Update Date: 5 Aug 2014 09:16 Release Date: 5 Aug 2014 6554 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Meetings Server Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco Webex Meetings Server, which could be exploited by remote users to obtain sensitive information, determine valid user accounts and conduct cross site request forgery attacks. Note: No patch is currently available.
Last Update Date: 30 Jul 2014 Release Date: 29 Jul 2014 6399 Views

RISK: Medium Risk

Medium Risk

Cisco Security Manager Remote Code Execution Vulnerability

A vulnerability was identified in Cisco Security Manager. A remote user can inject SQL commands.The web framework code does not properly validate user-supplied input. A remote user can supply a specially crafted parameter value to execute SQL commands on the underlying database. Note...
Last Update Date: 29 Jul 2014 12:33 Release Date: 29 Jul 2014 6125 Views

RISK: High Risk

High Risk

Apple QuickTime Remote Code Execution Vulnerability

A vulnerability was identified in Apple QuickTime. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will trigger a memory corruption error...
Last Update Date: 28 Jul 2014 10:19 Release Date: 28 Jul 2014 6374 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, cause denial of service conditions, and spoof user interface elements.
Last Update Date: 24 Jul 2014 Release Date: 23 Jul 2014 6373 Views

RISK: Medium Risk

Medium Risk

Synology DiskStation Manager Multiple Vulnerabilities

Multiple vulnerabilities were identified in Synology DiskStation Manager, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable device. The vulnerabilities are caused due to a bundled...
Last Update Date: 23 Jul 2014 Release Date: 22 Jul 2014 6455 Views

RISK: Medium Risk

Medium Risk

Tenable Nessus Web UI Information Disclosure Vulnerability

A vulnerability was identified in Tenable Nessus. A remote user can obtain potentially sensitive information.A remote user can send a specially crafted request to the '/server/properties' URL to obtain potentially sensitive information without authenticating.
Last Update Date: 23 Jul 2014 Release Date: 22 Jul 2014 6360 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service). An error within the mod_cgid module when handling certain input can be exploited to cause a hang of a child process. An error...
Last Update Date: 23 Jul 2014 Release Date: 22 Jul 2014 6346 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple vulnerabilities

Multiple vulnerabilities were identified in Drupal, which could be exploited by malicious users to cause denial of service, conduct cross site scripting and gain access to private files.
Last Update Date: 22 Jul 2014 Release Date: 18 Jul 2014 6132 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Denial of Service Vulnerability

A vulnerability was identified in Cisco ISO XR on ASR 9000 Series Router. A remote user can cause denial of service conditions. A remote user on the local network can send a stream of specially crafted Multiprotocol Label Switching (MPLS) packets to cause the target network...
Last Update Date: 22 Jul 2014 Release Date: 18 Jul 2014 6112 Views

RISK: High Risk

High Risk

Oracle Solaris Apache HTTP Server Denial of Service Vulnerabilities

Two vulnerabilities were identified in Apache HTTP Server included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 16 Jul 2014 Release Date: 15 Jul 2014 6123 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Manager Multiple Vulnerabilities

Multiple vulnerabilities haave been identified in Cisco Unified Communications Manager, which can be exploited by malicious users to manipulate certain data, disclose potentially sensitive information, and conduct cross-site scripting attacks. Note: No official solution is currently available.
Last Update Date: 16 Jul 2014 Release Date: 15 Jul 2014 5965 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Denial of Service Vulnerability

A vulnerability was identified in Cisco ASA. A remote authenticated user can cause denial of service conditions. A remote authenticated user can exploit a bounds checking flaw in the WebVPN Common Internet File System (CIFS) access function to cause the target device to reload.
Last Update Date: 16 Jul 2014 Release Date: 15 Jul 2014 5972 Views

RISK: Medium Risk

Medium Risk

MySQL Multiple Vulnerabilites

Multiple vulnerabilities were reported in MySQL. A remote authenticated or local user can partially access and modify data on the target system. A remote authenticated user can cause partial denial of service conditions.
Last Update Date: 16 Jul 2014 09:41 Release Date: 16 Jul 2014 6057 Views

RISK: Medium Risk

Medium Risk

Oracle Database Core RDBMS Multiple Vulnerabilities

Multiple vulnerabilities were identified in Oracle Database. A remote authenticated user can partially access and modify data on the target system, and cause denial of service conditions.
Last Update Date: 16 Jul 2014 09:33 Release Date: 16 Jul 2014 6083 Views

RISK: High Risk

High Risk

Oracle Java SE Multiple Vulnerabilities

Multiple vulnerabilities were identified in Oracle Java SE. A remote user can gain full control of the target system, access and modify data on the target system, and cause denial of service conditions.
Last Update Date: 16 Jul 2014 09:19 Release Date: 16 Jul 2014 6154 Views

RISK: Medium Risk

Medium Risk

Improperly Issued Digital Certificates Spoofing Vulnerability

National Informatics Centre (NIC) improperly issued a subordinate CA certificate, and that this subordinate CA certificate has been misused to issue SSL certificates for multiple sites including Google web properties. These SSL certificates could be used to spoof content, perform phishing attacks, or perform...
Last Update Date: 14 Jul 2014 Release Date: 11 Jul 2014 6379 Views

RISK: Medium Risk

Medium Risk

Cisco Products Remote Code Execution Vulnerability

A vulnerability has been identified in the Apache Struts 2 component of multiple Cisco products. The vulnerability is due to insufficient sanitization on user-supplied input in the XWorks component of the affected software. The component uses the ParameterInterceptors directive to parse the Object-Graph Navigation...
Last Update Date: 14 Jul 2014 Release Date: 11 Jul 2014 6074 Views

RISK: Medium Risk

Medium Risk

Samba and Samba3x Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Samba and Samba3x, which could be exploited by malicious people to cause denial of service.
Last Update Date: 11 Jul 2014 Release Date: 10 Jul 2014 5905 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat6 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache Tomecat6, which could be exploited by attackers to cause denial of service conditions and circumvent security restrictions to disclose sensitive information.
Last Update Date: 11 Jul 2014 Release Date: 10 Jul 2014 6043 Views

RISK: Medium Risk

Medium Risk

Microsoft Service Bus Denial of Service Vulnerability

A denial of service vulnerability exists in Microsoft Service Bus for Windows Server. An authenticated attacker who successfully exploited the vulnerability could cause the Service Bus to stop responding for incoming AMQP messages.
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 6022 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectShow Elevation of Privilege Vulnerability

A vulnerability exists in DirectShow that could allow an elevation of privilege.
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 5871 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Elevation of Privilege Vulnerability

A vulnerability exists in the Ancillary Function Driver (AFD) that could allow elevation of privilege. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 5965 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows On-Screen Keyboard Elevation of Privilege Vulnerability

A vulnerability exists in the On-Screen Keyboard that could allow a local elevation of privilege.
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 5861 Views

RISK: High Risk

High Risk

Microsoft Windows Journal Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Journal parses specially crafted files. The vulnerability could lead to remote code execution if a user opens a specially crafted Journal file. If a user is logged on with administrative rights, an attacker who successfully exploited...
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 5984 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Extended Validation (EV) Certificate Vulnerability

A security feature bypass vulnerability exists in Internet Explorer because Extended Validation (EV) SSL Certificate guidelines, which disallow the use of wildcard certificates, are not properly enforced. An attacker could bypass EV SSL certificate guidelines by using a wildcard certificate. EV SSL certificates issued...
Last Update Date: 9 Jul 2014 17:19 Release Date: 9 Jul 2014 5962 Views

RISK: Medium Risk

Medium Risk

AVG Secure Search ActiveX Control Insecure Method Vulnerability

A vulnerability was identified in AVG Secure Search toolbar. It includes an ActiveX control that provides a number of unsafe methods, which may allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the user. Note: The product is affected in Internet...
Last Update Date: 9 Jul 2014 Release Date: 8 Jul 2014 5924 Views

RISK: Medium Risk

Medium Risk

NetIQ Security Manager "DumpToFile()" Remote Code Execution Vulnerability

A vulnerability has been identified in NetIQ Security Manager, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the "DumpToFile()" method within the NQMcsVarSet ActiveX control, which can be...
Last Update Date: 9 Jul 2014 Release Date: 8 Jul 2014 5986 Views

RISK: Medium Risk

Medium Risk

JBoss Enterprise Application Platform Multiple vulnerabilities

Multiple vulnerabilities were identified in Red Hat JBoss Enterprise Application Platform 6.2.4, which could be exploited by remote attackers to cause denial of service, bypass security restrictions and disclose sensitive information.
Last Update Date: 9 Jul 2014 Release Date: 8 Jul 2014 5886 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions. An error when handling JSONP callbacks can be exploited to provide arbitrary, otherwise restricted SWF files using certain JSONP endpoints ...
Last Update Date: 9 Jul 2014 09:36 Release Date: 9 Jul 2014 5972 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Domain Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Unified Communications Domain Manager. A remote user can gain root access on the target system, and access and modify settings. A remote authenticated user can obtain elevated privileges on the target system. A remote authenticated user can submit a...
Last Update Date: 7 Jul 2014 Release Date: 3 Jul 2014 5950 Views

RISK: Medium Risk

Medium Risk

RealPlayer MP4 File Atom Handling Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error when handling atoms in MP4 files and can be exploited to cause a buffer overflow via an MP4 file...
Last Update Date: 4 Jul 2014 14:13 Release Date: 4 Jul 2014 5997 Views

RISK: High Risk

High Risk

Apple Products Multiple Vulnerabilities

A vulnerability was identified in Apple TV. A local user can make purchases without authorization.Multiple vulnerabilities were identified in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A local application can obtain elevated privileges...
Last Update Date: 2 Jul 2014 14:53 Release Date: 2 Jul 2014 6815 Views

RISK: High Risk

High Risk

eClass SQL Injection Vulnerability

A SQL injection vulnerability has been identified in eClass IP (for secondary schools) and eClass Junior (for primary schools), which can be exploited to extract information from the database.
Last Update Date: 30 Jun 2014 10:44 Release Date: 30 Jun 2014 6637 Views

RISK: Medium Risk

Medium Risk

JBoss Multiple Products Remote Code Execution Vulnerability

A vulnerability was identified in Red Hat JBoss Web Framework Kit, Enterprise Application Platform and Enterprise Web Platform. The vulnerability is caused due to an error related to Seam logging, which can be exploited to execute arbitrary code via specially crafted authentication headers.
Last Update Date: 27 Jun 2014 11:52 Release Date: 27 Jun 2014 6127 Views

RISK: Medium Risk

Medium Risk

JBoss Enterprise Application Platform Multiple vulnerabilities

Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform, which could be exploited by remote attackers to cause denial of service and gain access to confidential data.
Last Update Date: 27 Jun 2014 11:52 Release Date: 27 Jun 2014 5846 Views

RISK: Medium Risk

Medium Risk

Cisco IOS IPsec Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS, which can be exploited by malicious users to cause a DoS (Denial of Service). The vulnerability is caused due to an error when processing IPsec packets and can be exploited to cause a reload of the device.
Last Update Date: 27 Jun 2014 11:52 Release Date: 27 Jun 2014 5971 Views

RISK: Medium Risk

Medium Risk

GnuPG do_uncompress() Compressed Data Processing Flaw

A vulnerability has been identified in GnuPG. A remote user can cause denial of service conditions.   A remote user can send specially crafted compressed data packets to trigger a flaw in do_uncompress() and cause the target process to enter an infinite loop.
Last Update Date: 27 Jun 2014 Release Date: 26 Jun 2014 5759 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Meeting Server Information Disclosure Vulnerability

A vulnerability was identified in Cisco WebEx Meeting Server, which could be exploited by an authenticated, remote attacker to access sensitive information. An attacker could send a crafted URL request to a vulnerable device to disclose the meeting information.
Last Update Date: 26 Jun 2014 Release Date: 24 Jun 2014 6107 Views

RISK: Medium Risk

Medium Risk

Samba Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Samba, which can be exploited by malicious users to cause a DoS (Denial of Service).An error in the "sys_recvfrom()" function (source3/lib/system.c) can be exploited to trigger an infinite loop within...
Last Update Date: 26 Jun 2014 Release Date: 24 Jun 2014 6070 Views

RISK: High Risk

High Risk

McAfee Multiple Products OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities were identified in multiple McAfee products, which can be exploited by malicious, local users to disclose certain sensitive information and by malicious by people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable...
Last Update Date: 25 Jun 2014 09:56 Release Date: 25 Jun 2014 6086 Views

RISK: High Risk

High Risk

Parallels Plesk Panel Multiple Vulnerabilities

Two vulnerabilities were identified in Parallels Plesk Panel, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose potentially sensitive information. An error when parsing XML entities can be exploited to e.g. disclose data from local...
Last Update Date: 20 Jun 2014 09:23 Release Date: 20 Jun 2014 6005 Views

RISK: Medium Risk

Medium Risk

Cisco ASA WebVPN Interface Input Validation Vulnerability

A vulnerability has been identified in Cisco ASA. A remote user can obtain potentially sensitive information from the target system. A remote user can create a specially crafted Javascript file that, when loaded by the target authenticated user, will obtain potentially sensitive information from the target...
Last Update Date: 20 Jun 2014 Release Date: 19 Jun 2014 6032 Views

RISK: Medium Risk

Medium Risk

ISC BIND Denial of Service Vulnerability

A vulnerability was identified in ISC BIND. A remote user can cause denial of service conditions.A remote user can send a specially crafted query to trigger a flaw in EDNS option processing and cause the target service to crash.Both authoritative and recursive servers are affected...
Last Update Date: 18 Jun 2014 Release Date: 13 Jun 2014 5897 Views

RISK: Medium Risk

Medium Risk

PHP5 Remote Code Execution Vuilnerability

A vulnerability was identified in PHP, which causes a heap-based buffer overflow in the DNS TXT record parsing. A malicious server or man-in-the-middle attacker could possibly use this flaw to execute arbitrary code as the PHP interpreter if a PHP...
Last Update Date: 18 Jun 2014 12:34 Release Date: 18 Jun 2014 6175 Views

RISK: High Risk

High Risk

Microsoft Malware Protection Engine Denial of Service Vulnerability

A vulnerability was identified in Microsoft Malware Protection Engine. A remote or local user can cause denial of service conditions. A user can create a specially crafted file that, when scanned by the Microsoft Malware Protection Engine, will prevent the engine from monitoring the system(...
Last Update Date: 18 Jun 2014 12:34 Release Date: 18 Jun 2014 6204 Views

RISK: High Risk

High Risk

VMware vCenter Server Appliance Elevated Privileges Vulnerability

A vulnerability was identified in VMware vCenter Server Appliance. A remote authenticated user can execute commands on the target system with elevated privileges. A remote authenticated user can send specially crafted data to escape a chroot jail via the Ruby vSphere Console (RVC) and execute commands...
Last Update Date: 18 Jun 2014 12:25 Release Date: 18 Jun 2014 6081 Views

RISK: High Risk

High Risk

Oracle Database Elevation of User Privilege Vulnerabilities

Multiple vulnerabilities were identified in Oracle Database. A remote authenticated user can obtain elevated privileges on the target database.A remote authenticated user with 'CREATE SESSION' privileges can exploit flaws in the Java VM to gain administrator privileges on the target database. Note: No...
Last Update Date: 17 Jun 2014 09:42 Release Date: 17 Jun 2014 6162 Views

RISK: High Risk

High Risk

Cisco Products OpenSSL SSL/TLS Vulnerabilities

OpenSSL SSL/TLS vulnerabilities were identified in multiple Cisco products, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system. The vulnerabilities are caused due to...
Last Update Date: 13 Jun 2014 14:18 Release Date: 13 Jun 2014 6810 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox / Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can conduct clickjacking attacks. A remote user can create specially crafted content that, when loaded by the...
Last Update Date: 13 Jun 2014 Release Date: 12 Jun 2014 5940 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. The application bundles a vulnerable version of the Adobe Flash Player...
Last Update Date: 11 Jun 2014 14:34 Release Date: 11 Jun 2014 6021 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.
Last Update Date: 11 Jun 2014 14:34 Release Date: 11 Jun 2014 6103 Views

RISK: Medium Risk

Medium Risk

Microsoft Remote Desktop Tampering Vulnerability

A tampering vulnerability exists in the Remote Desktop Protocol. The vulnerability may allow an attacker to modify the traffic content of an active RDP session.
Last Update Date: 11 Jun 2014 14:33 Release Date: 11 Jun 2014 6065 Views

RISK: Medium Risk

Medium Risk

Microsoft TCP Protocol Denial of Service Vulnerability

A denial of service vulnerability exists in the Windows TCP/IP networking protocol. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.
Last Update Date: 11 Jun 2014 14:33 Release Date: 11 Jun 2014 5903 Views

RISK: Medium Risk

Medium Risk

Microsoft Lync Server Information Disclosure Vulnerability

An information disclosure vulnerability exists when Lync Server fails to properly sanitize specially crafted content. An attacker who successfully exploited this vulnerability could potentially execute scripts in the user’s browser to obtain information from web sessions.
Last Update Date: 11 Jun 2014 14:32 Release Date: 11 Jun 2014 6020 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that Microsoft Windows parses XML content. The vulnerability may allow an attacker to access information not otherwise allowed.
Last Update Date: 11 Jun 2014 14:32 Release Date: 11 Jun 2014 5874 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that affected Microsoft Office software parses specially crafted files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 11 Jun 2014 14:32 Release Date: 11 Jun 2014 5874 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Cumulative Security Update

TLS Server Certificate Renegotiation VulnerabilityAn information disclosure vulnerability exists in the way that Internet Explorer handles negotiation of certificates in a TLS session. An attacker who successfully exploited this vulnerability could hijack a mutually authenticated TLS connection between Internet Explorer and an arbitrary target server.Internet Explorer Information...
Last Update Date: 11 Jun 2014 14:31 Release Date: 11 Jun 2014 6035 Views

RISK: High Risk

High Risk

Microsoft Graphics Component Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the way that affected components handle specially crafted font files. The vulnerability could allow remote code execution if a user opens a specially crafted file or webpage. An attacker who successfully exploited this vulnerability could take complete control of an affected...
Last Update Date: 11 Jun 2014 14:31 Release Date: 11 Jun 2014 5950 Views

RISK: High Risk

High Risk

Chrome for Android OpenSSL Security Vulnerability

A vulnerability was identified in Chrome for Android, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, and compromise a vulnerable system.
Last Update Date: 10 Jun 2014 10:17 Release Date: 10 Jun 2014 6184 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system. An error when handling SSL/TLS handshakes can be exploited...
Last Update Date: 6 Jun 2014 11:01 Release Date: 6 Jun 2014 6414 Views

RISK: Medium Risk

Medium Risk

GnuTLS "read_server_hello()" Remote Code Execution Vulnerability

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to compromise an application using the library. The vulnerability is caused due to a boundary error within the "read_server_hello()" function (lib/gnutls_handshake.c) and can be ...
Last Update Date: 5 Jun 2014 Release Date: 3 Jun 2014 6139 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel Denial of Service Vulnerabilities

Two vulnerabilities have been identified in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service). An error within win32k.sys when initializing the touch injection context can be exploited to cause a crash. An...
Last Update Date: 5 Jun 2014 Release Date: 3 Jun 2014 6317 Views

RISK: Medium Risk

Medium Risk

McAfee Network Data Loss Prevention Vulnerabilities

Multiple vulnerabilities were identified in McAfee Network Data Loss Prevention (DLP). A remote user can cause denial of service conditions, inject SQL commands and conduct click-jacking attacks.A remote user can send a specially crafted RAR file to trigger a segmentation fault and make...
Last Update Date: 4 Jun 2014 09:12 Release Date: 4 Jun 2014 6100 Views

RISK: Medium Risk

Medium Risk

PHP CDF Processing Vulnerability

Two vulnerabilities were identified in PHP. A remote user can cause denial of service conditions.A remote user can send a specially crafted CDF file to cause performance degradation via file_printf() calls.A remote user can send a specially crafted CDF file to trigger an infinite...
Last Update Date: 4 Jun 2014 09:12 Release Date: 4 Jun 2014 6232 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Multiple Vulnerabilities

A vulnerability was identified in Apache Tomcat. A remote authenticated user can bypass security restrictions and cause denial of service conditions.
Last Update Date: 30 May 2014 Release Date: 28 May 2014 6187 Views

RISK: Medium Risk

Medium Risk

cPanel 'cgiemail' Character Injection Vulnerability

A vulnerability was identified in cPanel. A remote user can send SPAM via the system. A remote user can inject newline characters via certain parameters to modify email fields and send SPAM to arbitrary destination addresses via cgiemail.
Last Update Date: 30 May 2014 Release Date: 28 May 2014 6108 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Java Multiple Vulnerabilities

Two vulnerabilities were identified in IBM WebSphere Application Server, which can be exploited by malicious people to disclose and manipulate certain data. The vulnerabilities are caused due to a bundled vulnerable version of IBM Java.
Last Update Date: 30 May 2014 10:12 Release Date: 30 May 2014 6102 Views

RISK: Medium Risk

Medium Risk

Tor Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Tor, which could be exploited by attackers to cause a denial of service, gain knowledge of sensitive information or execute arbitrary code. 1. A heap overflow error when processing malformed data, which could be exploited to...
Last Update Date: 30 May 2014 Release Date: 19 Jan 2011 10071 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Solaris, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing, session fixation, and script insertion attacks, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system...
Last Update Date: 27 May 2014 11:13 Release Date: 27 May 2014 5971 Views

RISK: Medium Risk

Medium Risk

Apple OS X Server Ruby Floating Point Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Apple OS X Server, which can be exploited by malicious people to compromise a vulnerable system.
Last Update Date: 26 May 2014 Release Date: 22 May 2014 5948 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer 8 CMarkup use-after-free vulnerability

A vulnerability has been identified in Microsoft Internet Explorer 8, which can be exploited by remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Last Update Date: 26 May 2014 Release Date: 22 May 2014 6439 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks and compromise a user's system.A use-after-free error exists within styles.An integer overflow error exists within...
Last Update Date: 26 May 2014 Release Date: 22 May 2014 6039 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco NX-OS. A remote user can execute arbitrary code, obtain elevated privileges and cause denial of service conditions on the target system.
Last Update Date: 23 May 2014 09:39 Release Date: 23 May 2014 5748 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari. A remote user can cause arbitrary code to be executed on the target user's system and bypass same origin policy restrictions.
Last Update Date: 23 May 2014 09:38 Release Date: 23 May 2014 6127 Views