Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Office Common Control Library Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists because the MSCOMCTL common controls library used by Microsoft Office software does not properly implement Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, which helps protect users from...
Last Update Date: 14 May 2014 14:45 Release Date: 14 May 2014 5976 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Handler Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when the Windows Shell improperly handles file associations. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the Local System account. An attacker could then install programs; view, change, or...
Last Update Date: 14 May 2014 14:43 Release Date: 14 May 2014 5931 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the way that affected Microsoft Office software handles the loading of dynamic-link library (.dll) files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 14 May 2014 14:43 Release Date: 14 May 2014 6041 Views

RISK: High Risk

High Risk

Microsoft SharePoint Server Remote Code Execution Vulnerabilities

Related remote code execution vulnerabilities exist in Microsoft SharePoint Server and Microsoft Web Applications. An authenticated attacker who successfully exploited any of these related vulnerabilities could run arbitrary code in the security context of the W3WP service account. An elevation of privilege vulnerability exists in Microsoft SharePoint Server...
Last Update Date: 14 May 2014 14:42 Release Date: 14 May 2014 6278 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows iSCSI Target Processing Denial of Service Vulnerabilities

A denial of service vulnerability exists in the way that affected operating systems handle iSCSI connections. An attacker who successfully exploited the vulnerability could cause the affected service or services to stop responding.
Last Update Date: 14 May 2014 14:34 Release Date: 14 May 2014 5961 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 14 May 2014 14:28 Release Date: 14 May 2014 6079 Views

RISK: Medium Risk

Medium Risk

ISC BIND Recursive Nameservers Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error within the prefetch feature when processing certain queries, which can be exploited to trigger an assertion...
Last Update Date: 13 May 2014 Release Date: 12 May 2014 5877 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Denial of Service Vulnerability

A vulnerability has been identified in IBM WebSphere Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when handling Heartbeat messages, which can be exploited to cause a DoS...
Last Update Date: 13 May 2014 09:52 Release Date: 13 May 2014 6012 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Player Buffer Overflows Vulnerabilities

Multiple vulnerabilities have been identified in Cisco WebEx Player. A remote user can create a specially crafted file that, when loaded by the target user, will trigger a buffer overflow or memory corruption flaw and execute arbitrary code on the target system. The code will run...
Last Update Date: 8 May 2014 11:05 Release Date: 8 May 2014 6247 Views

RISK: High Risk

High Risk

OpenSSL Deny Service Vulnerability

A vulnerability was identified in OpenSSL. A remote user can cause denial of service conditions. A remote user can send specially crafted data to trigger a null pointer dereference in do_ssl3_write() and cause the target service to crash. The vulnerability resides in 'ssl/s3_pkt...
Last Update Date: 7 May 2014 Release Date: 5 May 2014 6127 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting...
Last Update Date: 7 May 2014 Release Date: 2 May 2014 6179 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco products, which can be exploited by attackers to execute arbitrary code on the target system. A local user can obtain elevated privileges on the target system. A remote user can cause denial of service conditions, obtain potentially sensitive information...
Last Update Date: 7 May 2014 Release Date: 2 May 2014 6246 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS Bypass Security Controls Vulnerability

A vulnerability was identified in Cisco NX-OS Nexus 1000V. A remote user can bypass access controls in certain cases. A remote user can can send IGMPv2 and IGMPv3 traffic to bypass 'deny' statements in access control lists (ACLs). IGMPv1 processing is not...
Last Update Date: 7 May 2014 11:21 Release Date: 7 May 2014 6018 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Use-After-Free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a use-after-free error, which can be exploited to cause memory corruption. Successful exploitation...
Last Update Date: 2 May 2014 Release Date: 28 Apr 2014 7742 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. Some of these vulnerabilities may lead to memory corruption or arbitrary code execution.
Last Update Date: 29 Apr 2014 10:30 Release Date: 29 Apr 2014 6359 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Execute Arbitrary Code Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow and...
Last Update Date: 29 Apr 2014 10:23 Release Date: 29 Apr 2014 6458 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X, which can be exploited to conduct security restriction bypass, manipulation of data, sensitive information disclosure, denial of service and remote code execution. A format string error exists when handling URLs within the CoreServicesUIAgent component, which...
Last Update Date: 25 Apr 2014 Release Date: 24 Apr 2014 6087 Views

RISK: High Risk

High Risk

Apache Struts Execute Arbitrary Code Vulnerability

A vulnerability has been identified in Apache Struts. A remote user can execute arbitrary code on the target system. A remote user can supply specially crafted 'class' parameter values to the ParametersInterceptor class to manipulate the ClassLoader and execute arbitrary code. *Note: No patch...
Last Update Date: 25 Apr 2014 10:35 Release Date: 25 Apr 2014 6279 Views

RISK: Medium Risk

Medium Risk

Wireshark RTP Dissector Crash Vulnerability

A vulnerability has been identified in Wireshark, which can be exploited to cause denial of service.   Wireshark can be made to crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Last Update Date: 24 Apr 2014 10:34 Release Date: 24 Apr 2014 6355 Views

RISK: Medium Risk

Medium Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which can be exploited by malicious people to potentially disclose sensitive information or potentially manipulate certain data and compromise a vulnerable device. An error related to SSL handling exists.Multiple errors exist within WebKit.
Last Update Date: 24 Apr 2014 10:33 Release Date: 24 Apr 2014 6108 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people to potentially disclose sensitive information or potentially manipulate certain data and compromise a vulnerable device. An error exists within the Security - Secure Transport component. Multiple errors exist within the WebKit component...
Last Update Date: 24 Apr 2014 10:33 Release Date: 24 Apr 2014 6319 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to cause denial of service, escalation of privilege, remote code execution and sensitive information disclosure.
Last Update Date: 23 Apr 2014 Release Date: 17 Apr 2014 6736 Views

RISK: Medium Risk

Medium Risk

IBM InfoSphere Streams Java Multiple Vulnerabilities

Multiple vulnerabilities were identified in IBM InfoSphere Streams, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 23 Apr 2014 10:14 Release Date: 23 Apr 2014 6151 Views

RISK: High Risk

High Risk

IBM Notes / Domino Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Notes and IBM Domino, which can be exploited by malicious, local users to disclose sensitive information, manipulate certain data, cause a DoS (Denial of Service), and gain escalated privileges, and by malicious people to conduct spoofing...
Last Update Date: 23 Apr 2014 10:14 Release Date: 23 Apr 2014 6595 Views

RISK: Extremely High Risk

Extremely High Risk

OpenSSL Heartbeat Information Disclosure Vulnerability

A vulnerability has been identified in OpenSSL. A remote, unauthenticated attacker may be able to retrieve sensitive information, such as secret keys. By leveraging this information, an attacker may be able to decrypt, spoof, or perform man-in-the-middle...
Last Update Date: 16 Apr 2014 Release Date: 8 Apr 2014 11850 Views

RISK: High Risk

High Risk

Adobe Reader for Android Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Reader Mobile. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a flaw in the...
Last Update Date: 16 Apr 2014 10:19 Release Date: 16 Apr 2014 7015 Views

RISK: High Risk

High Risk

Wireshark Libpcap CAP Files Parsing Memory Corruption Vulnerability

A vulnerability has been identified in Wireshark, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when parsing CAP files and can be exploited to cause memory corruption via a specially crafted CAP file...
Last Update Date: 11 Apr 2014 10:10 Release Date: 11 Apr 2014 6658 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress, which can be exploited by malicious people to conduct cross-site scripting and bypass certain security restrictions. An error in the cookie keyed hash value verification can be exploited to gain unauthorized access.An error when verifying the "...
Last Update Date: 11 Apr 2014 10:05 Release Date: 11 Apr 2014 6191 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Google Chrome, which can be exploited by attacker to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.An unspecified error within V8 can be exploited to conduct cross-site scripting...
Last Update Date: 9 Apr 2014 16:27 Release Date: 9 Apr 2014 6433 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.
Last Update Date: 9 Apr 2014 16:26 Release Date: 9 Apr 2014 6054 Views

RISK: High Risk

High Risk

Microsoft Publisher Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that affected versions of Microsoft Publisher parses specially crafted files. An attacker who successfully exploited this vulnerability could run arbitrary code as the current user. If the current user is logged on with administrative user rights, an attacker...
Last Update Date: 9 Apr 2014 16:25 Release Date: 9 Apr 2014 6021 Views

RISK: High Risk

High Risk

Microsoft Windows File Handling Component Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when processing .bat and .cmd files that are run from an external network. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 9 Apr 2014 16:25 Release Date: 9 Apr 2014 6329 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 9 Apr 2014 16:24 Release Date: 9 Apr 2014 6216 Views

RISK: High Risk

High Risk

Microsoft Word & Office Web Apps Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that affected Microsoft Word and Office software converts/ parses specially crafted files. An attacker who successfully exploited this vulnerability could run arbitrary code as the current user. If the current user is logged on with administrative user rights...
Last Update Date: 9 Apr 2014 16:24 Release Date: 9 Apr 2014 6163 Views

RISK: High Risk

High Risk

Microsoft Office Denial of Service Vulnerability

A vulnerability was identified in Microsoft Office. A remote user can cause denial of service conditions.   A remote user can send a specially crafted XML document that, when processed by the target application, will trigger an entity expansion flaw to consume excessive memory resources and cause...
Last Update Date: 8 Apr 2014 12:34 Release Date: 8 Apr 2014 6359 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities were identified in Cisco IOS, IOS XE and IOS XR. A remote user can cause denial of service conditions.
Last Update Date: 7 Apr 2014 11:36 Release Date: 7 Apr 2014 6131 Views

RISK: High Risk

High Risk

NTP Abused to Launch Distributed Reflection Denial of Service Attack (DRDoS)

Network Time Protocol (NTP) and other UDP-based protocols can be used to amplify denial-of-service attacks. Servers running the NTP based on implementations of ntpd prior to version 4.2.7p26 that use the default unrestricted query configuration...
Last Update Date: 3 Apr 2014 Release Date: 7 Feb 2014 9464 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can bypass sandbox controls. A remote user can create specially crafted content that, when loaded by the target...
Last Update Date: 3 Apr 2014 09:11 Release Date: 3 Apr 2014 6288 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Two vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote user to cause arbitrary code to be executed on the target user's system.A remote user can create specially crafted content that, when loaded by the target user on a...
Last Update Date: 31 Mar 2014 18:01 Release Date: 31 Mar 2014 6480 Views

RISK: High Risk

High Risk

Adobe Reader Bypass Sandbox Restrictions Vulnerabilities

Two vulnerabilities have been identified in Adobe Reader, which can be exploited by remote user to cause arbitrary code to be executed on the target user's system.A remote user can create a specially crafted PDF file that, when loaded by the target user, ...
Last Update Date: 31 Mar 2014 18:00 Release Date: 31 Mar 2014 6357 Views

RISK: High Risk

High Risk

Symantec LiveUpdate Administrator Unauthenticated Vulnerabilities

Two vulnerabilities have been identified in Symantec LiveUpdate Administrator, which can be exploited by remote user to inject SQL commands. A remote user can reset account passwords to arbitrary values.The management web interface does not properly validate user-supplied input. A remote user can...
Last Update Date: 31 Mar 2014 18:00 Release Date: 31 Mar 2014 6429 Views

RISK: Medium Risk

Medium Risk

Synology DiskStation Manager Multiple Vulnerabilities

Multiple vulnerabilities were identified in Synology DiskStation Manager, which can be exploited by malicious people to cause a DoS (Denial of Service), conduct spoofing attacks, and compromise a vulnerable system.
Last Update Date: 28 Mar 2014 09:40 Release Date: 28 Mar 2014 6008 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Multiple vunlerabilities have been identified in Cisco IOS, which can be exploited to cause denial of service.
Last Update Date: 27 Mar 2014 09:26 Release Date: 27 Mar 2014 5993 Views

RISK: Medium Risk

Medium Risk

Kaspersky Internet Security Regex Processing Vulnerability

A vulnerability has been identified in Kaspersky Internet Security. which could allow a remote user to cause denial of service conditions.A remote user can create a specially crafted file that, when scanned by the target user, will cause the anti-virus service to hang...
Last Update Date: 26 Mar 2014 Release Date: 24 Mar 2014 5977 Views

RISK: Medium Risk

Medium Risk

PHP Fileinfo libmagic AWK File Processing Denial of Service Vulnerability

A vulnerability has been identified in PHP, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error in the libmagic library bundled in the Fileinfo extension when processing certain AWK scripts, which can be...
Last Update Date: 26 Mar 2014 18:53 Release Date: 26 Mar 2014 6083 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Word RTF File Processing Vulnerability

A vulnerability has been identified in Microsoft Word. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted RTF file that, when loaded by the target user, will trigger a memory...
Last Update Date: 25 Mar 2014 09:19 Release Date: 25 Mar 2014 6228 Views

RISK: Medium Risk

Medium Risk

lighttpd Input Validation Vulnerabilities

Two vulnerabilities have been identified in lighttpd. A remote user can inject SQL commands. which could allow a remote user to access files on the target system.The software does not properly validate user-supplied input. A remote user can supply a specially crafted parameter...
Last Update Date: 24 Mar 2014 14:42 Release Date: 24 Mar 2014 6262 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Sup2T Denial of Service Vulnerability

A vulnerability has been identified in Cisco Catalyst 6500 Supervisor Engine 2T (Sup2T), which could allow an unauthenticated, remote attacker to crash the device.   The vulnerability is due to incorrect processing multicast traffic by the Sup2T. An attacker could exploit this vulnerability by sending...
Last Update Date: 21 Mar 2014 09:33 Release Date: 21 Mar 2014 6031 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. Some unspecified errors exist, which...
Last Update Date: 20 Mar 2014 17:36 Release Date: 20 Mar 2014 6002 Views

RISK: Medium Risk

Medium Risk

OpenSSH AcceptEnv Wildcard Processing Vulnerability

A vulnerability has been identified in OpenSSH, which can be exploited by a remote authenticated user to bypass environment restrictions in certain cases.When configured for environment passing (not the default), the software does not properly process wildcard characters on AcceptEnv lines in the 'sshd_config...
Last Update Date: 19 Mar 2014 17:19 Release Date: 19 Mar 2014 6289 Views

RISK: Medium Risk

Medium Risk

Apache mod_dav and mod_log_config Multiple Vulnerabilities

Two vulnerabilities have been identified in Apache, which can be exploited by a remote user to cause denial of service conditions.A remote user can send specially crafted DAV WRITE requests to trigger a flaw in mod_dav in the processing of spaces within CDATA and cause the target...
Last Update Date: 19 Mar 2014 17:19 Release Date: 19 Mar 2014 6015 Views

RISK: High Risk

High Risk

Google Chrome for Android Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome for Android, which can be exploited by malicious people to compromise a user's system.An error related to GPU command buffer can be exploited to cause memory corruption.Successful exploitation of this vulnerability may allow execution of...
Last Update Date: 18 Mar 2014 16:50 Release Date: 18 Mar 2014 6055 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Two vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.A use-after-free error exists within Blink bindings.An error within V8 can be exploited to cause a memory corruption.The...
Last Update Date: 18 Mar 2014 16:50 Release Date: 18 Mar 2014 6094 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Memory Corruption Vulnerability

A vulnerability has been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an unspecified error and can be exploited to corrupt memory.The vulnerability is reported in versions 12....
Last Update Date: 17 Mar 2014 14:51 Release Date: 17 Mar 2014 6178 Views

RISK: High Risk

High Risk

VMware vCenter Server and vSphere Update Manager Multiple Vulnerabilities

Multiple vulnerabilities were identified in VMware vSphere Update Manager and VMware vCenter, which can be exploited by malicious users to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.   For more information: SA13101702
Last Update Date: 13 Mar 2014 10:21 Release Date: 13 Mar 2014 6429 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SAMR Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when the Security Account Manager Remote (SAMR) protocol incorrectly validates user lockout state.
Last Update Date: 12 Mar 2014 12:41 Release Date: 12 Mar 2014 6252 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Driver Elevation of Privilege Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges and read arbitrary amounts of kernel memory.Win32k Information Disclosure VulnerabilityAn information disclosure vulnerability exists...
Last Update Date: 12 Mar 2014 12:40 Release Date: 12 Mar 2014 6120 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight DEP/ASLR Bypass Vulnerability

A security feature bypass vulnerability exists in Silverlight due to improper implementation of Data Execution Protection (DEP) and Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the DEP/ASLR security feature, most likely during or in the course of...
Last Update Date: 12 Mar 2014 12:37 Release Date: 12 Mar 2014 6184 Views

RISK: High Risk

High Risk

Microsoft DirectShow Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft DirectShow parses specially crafted JPEG image files. The vulnerability could allow remote code execution if a user opens a specially crafted image file. An attacker who successfully exploited this vulnerability could gain the same user rights as...
Last Update Date: 12 Mar 2014 12:35 Release Date: 12 Mar 2014 6014 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a vulnerable device.The Configuration Profiles component does not properly verify expiration dates...
Last Update Date: 12 Mar 2014 12:33 Release Date: 12 Mar 2014 6295 Views

RISK: High Risk

High Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a vulnerable device.An error exists when handling code signature validation of text relocation instructions in...
Last Update Date: 12 Mar 2014 12:33 Release Date: 12 Mar 2014 5999 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. A use-after-...
Last Update Date: 12 Mar 2014 12:32 Release Date: 12 Mar 2014 6080 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Two vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to disclose potentially sensitive information and bypass certain security restrictions.An unspecified error can be exploited to bypass the same-origin policy.Another unspecified error can be exploited to disclose...
Last Update Date: 12 Mar 2014 12:32 Release Date: 12 Mar 2014 6173 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 12 Mar 2014 12:31 Release Date: 12 Mar 2014 6322 Views

RISK: Medium Risk

Medium Risk

Joomla CMS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Joomla, which can be exploited to conduct SQL injection and cross site scripting.
Last Update Date: 12 Mar 2014 Release Date: 10 Mar 2014 6057 Views

RISK: Medium Risk

Medium Risk

eClass SQL injection vulnerability

A SQL injection vulnerability has been identified in eClass IP (for secondary schools) and eClass Junior (for primary schools), which can be exploited to extract information from the database.
Last Update Date: 11 Mar 2014 14:27 Release Date: 11 Mar 2014 6714 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise an application using the library.An error in the "tak_decode_frame()" function (libavcodec/takdec.c) can be exploited...
Last Update Date: 11 Mar 2014 10:30 Release Date: 11 Mar 2014 6187 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system. An error within the NFS dissector can be exploited to cause a crash. An error within the M3UA dissector...
Last Update Date: 11 Mar 2014 10:24 Release Date: 11 Mar 2014 6039 Views

RISK: Medium Risk

Medium Risk

GnuTLS Certificate Verification Vulnerability

A vulnerability has been identified in GnuTLS, which affects certificate verification functions. An attacker could use a specially crafted X509 certificate to bypass validation checks, impersonate legitimate web sites or services, and perform man-in-the-middle attacks.
Last Update Date: 6 Mar 2014 12:13 Release Date: 6 Mar 2014 6199 Views

RISK: Medium Risk

Medium Risk

Cisco Small Business RV Series Wireless-N VPN Password Disclosure Vulnerability

A vulnerability has been identified in Cisco Small Business RV Series. A remote user can gain administrative access on the target system.   The web management interface does not properly handle authentication requests. A remote user can intercept and modify an authentication request to gain administrative privileges on...
Last Update Date: 6 Mar 2014 12:13 Release Date: 6 Mar 2014 6103 Views

RISK: Medium Risk

Medium Risk

Cisco Wireless LAN Controllers Multiple vulnerabilities

Multiple vulnerabilities have been identified in Cisco Wireless LAN Controllers. The Cisco Wireless LAN Controller (WLC) product family is affected by the following vulnerabilities: Cisco Wireless LAN Controller Denial of Service Vulnerability Cisco Wireless LAN Controller Unauthorized Access to Associated Access Points Vulnerability Cisco...
Last Update Date: 6 Mar 2014 12:12 Release Date: 6 Mar 2014 6465 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Java, which can be exploited by malicious users to disclose sensitive information, cause a DoS (Denial of Service), manipulate certain data and compromise a vulnerable system.
Last Update Date: 6 Mar 2014 12:12 Release Date: 6 Mar 2014 6051 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Some vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.A use-after-free error exists when handling SVG images.A use-after-free error exists...
Last Update Date: 5 Mar 2014 10:15 Release Date: 5 Mar 2014 6018 Views

RISK: Medium Risk

Medium Risk

FFmpeg Remote Code Execution Vulnerability

A vulnerability was identified in FFmpeg. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow in the mpegts_write_pmt...
Last Update Date: 3 Mar 2014 12:23 Release Date: 3 Mar 2014 6663 Views

RISK: Medium Risk

Medium Risk

Autodesk AutoCAD Remote Code Execution Vulnerabilities

Two vulnerabilities were identified in Autodesk AutoCAD. A remote user can cause arbitrary code to be executed on the target user's system.A remote user can trigger a FAS file search path flaw to cause arbitrary VBScript code to be executed on the target user'...
Last Update Date: 3 Mar 2014 12:22 Release Date: 3 Mar 2014 6301 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.   Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
Last Update Date: 27 Feb 2014 10:41 Release Date: 27 Feb 2014 5946 Views

RISK: High Risk

High Risk

Apple Safari Use-After-Free and Multiple Memory Corruption Vulnerabilities

Multiple vulnerabilities have been reported in Apple Safari, which can be exploited by malicious people to compromise a user's system.   A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a memory corruption flaw in WebKit and...
Last Update Date: 27 Feb 2014 10:41 Release Date: 27 Feb 2014 6052 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple OS X. A remote user can cause arbitrary code to be executed on the target user's system.   An application can bypass sandbox restrictions on the target system. A remote user can obtain potentially sensitive information.
Last Update Date: 27 Feb 2014 10:41 Release Date: 27 Feb 2014 5854 Views

RISK: Medium Risk

Medium Risk

Red Hat Enterprise Linux openldap Denial Of Service Vulnerability

A denial of service flaw was identified in the OpenLDAP server daemon (slapd) performed reference counting when using the rwm (rewrite/remap) overlay. A remote attacker able to query the OpenLDAP server could use this flaw to crash the server by immediately unbinding...
Last Update Date: 26 Feb 2014 14:40 Release Date: 26 Feb 2014 5871 Views

RISK: Medium Risk

Medium Risk

libpng Denial-Of-Service Vulnerability

A vulnerabiity was identified in libpng. Decoding a malformed .png file may cause the target application to become unresponsive. 
Last Update Date: 26 Feb 2014 14:35 Release Date: 26 Feb 2014 5841 Views

RISK: Medium Risk

Medium Risk

Mac OS X SSL/TLS Authentication Vulnerability

A vulnerability has been identified in Mac OS X, which can be exploited by remote user can decrypt SSL/TLS sessions in certain cases. A remote user with the ability to conduct a man-in-the-middle attack can exploit a connection authentication flaw...
Last Update Date: 25 Feb 2014 Release Date: 24 Feb 2014 6142 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by remote user to determine the installation path or cause arbitrary code to be executed on the target user's system.A remote user can create specially crafted content that, when loaded by the...
Last Update Date: 25 Feb 2014 Release Date: 24 Feb 2014 5991 Views

RISK: High Risk

High Risk

Linksys E-Series Routers Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple Linksys E-Series routers, which can be exploited by malicious people to bypass certain security restrictions. The device does not properly restrict access to tmUnblock.cgi and hndUnblock.cgi, which can be exploited to inject...
Last Update Date: 25 Feb 2014 09:32 Release Date: 25 Feb 2014 6184 Views

RISK: High Risk

High Risk

Kloxo SQL Injection Vulnerability

A vulnerability has been identified in Kloxo, which can be exploited by malicious people to take full control of the server, and remotely execute arbitrary code.   According to forum vpsBoard (https://vpsboard.com/topic/3384-kloxo-installations-compromised/), ...
Last Update Date: 24 Feb 2014 18:24 Release Date: 24 Feb 2014 6577 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Code Execution Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 21 Feb 2014 11:56 Release Date: 21 Feb 2014 6405 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Use-After-Free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by attackers to cause arbitrary code to be executed on the target user's system. A remote user can create HTML with a specially crafted Adobe Flash object that, when loaded by the...
Last Update Date: 21 Feb 2014 Release Date: 17 Feb 2014 6628 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise an application using the library. An error within the "ff_init_buffer_info()" function (libavcodec/utils.c) can be exploited...
Last Update Date: 19 Feb 2014 11:24 Release Date: 19 Feb 2014 6299 Views

RISK: High Risk

High Risk

Symantec Endpoint Protection Manager Remote Code Execution Vulnerability

A vulnerability has been identified in Symantec Endpoint Protection Manager, which could be exploited by malicious users to execute arbitrary code.   The management console for Symantec Endpoint Protection Manager does not properly handle external XML data, which could potentially allow unauthorized access to restricted server-side...
Last Update Date: 19 Feb 2014 11:23 Release Date: 19 Feb 2014 6740 Views

RISK: Medium Risk

Medium Risk

Microsoft MSXML Information Disclosure Vulnerability

An information disclosure vulnerability exists that could allow an attacker to read files on the local file system of a user, or read content of web domains where a user is currently authenticated. An attacker could exploit this vulnerability when a user views specially crafted web content that...
Last Update Date: 12 Feb 2014 12:17 Release Date: 12 Feb 2014 6229 Views

RISK: Medium Risk

Medium Risk

Microsoft TCP/IP Version 6 (IPv6) Denial of Service Vulnerability

A denial of service vulnerability exists in Windows in the IPv6 implementation of TCP/IP. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.
Last Update Date: 12 Feb 2014 12:17 Release Date: 12 Feb 2014 6125 Views

RISK: High Risk

High Risk

Microsoft Graphics Component Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that affected Windows components handle specially crafted 2D geometric figures. The vulnerability could allow remote code execution if a user views files containing such specially crafted figures using Internet Explorer. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 12 Feb 2014 12:17 Release Date: 12 Feb 2014 6124 Views

RISK: High Risk

High Risk

Microsoft Forefront Protection Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Forefront Protection for Exchange. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the configured service account.
Last Update Date: 12 Feb 2014 12:16 Release Date: 12 Feb 2014 6155 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities

POST Request DoS VulnerabilityA denial of service vulnerability exists in Microsoft ASP.NET that could allow an attacker to cause an ASP.NET server to become unresponsive.Type Traversal VulnerabilityAn elevation of privilege vulnerability exists in the Microsoft.NET Framework that could allow an attacker to...
Last Update Date: 12 Feb 2014 12:16 Release Date: 12 Feb 2014 6620 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Internet Explorer Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists within Internet Explorer during validation of local file installation and during secure creation of registry keys.VBScript Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The...
Last Update Date: 12 Feb 2014 12:16 Release Date: 12 Feb 2014 6135 Views

RISK: High Risk

High Risk

Microsoft VBScript Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. If the current user is logged on with...
Last Update Date: 12 Feb 2014 12:16 Release Date: 12 Feb 2014 6205 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Memory Corruption Vulnerabilities

Two vulnerabilities have been identified in Adobe Shockwave Player. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted Shockwave content that, when loaded by the target user, will trigger a memory...
Last Update Date: 12 Feb 2014 12:16 Release Date: 12 Feb 2014 6444 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Integer Underflow Vulnerability

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger an integer underflow and...
Last Update Date: 7 Feb 2014 Release Date: 5 Feb 2014 6966 Views

RISK: Medium Risk

Medium Risk

OpenLDAP Deny of Service Vulnerability

A vulnerability was identified in OpenLDAP. A remote user can cause denial of service conditions. A remote user can send specially crafted search request and then immediately unbind from the server to cause the target slapd service to crash.
Last Update Date: 6 Feb 2014 Release Date: 5 Feb 2014 6152 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. Errors when handling discarded images within the "RasterImage" class, terminating a...
Last Update Date: 6 Feb 2014 15:27 Release Date: 6 Feb 2014 6411 Views

RISK: High Risk

High Risk

MySQL Remote Code Execution Vulnerability

A vulnerability was reported in MySQL, which can be exploited by a remote user to execute arbitrary code on the target system.   A remote server can send a specially crafted server version number string to trigger a buffer overflow in 'client/mysql.cc' ...
Last Update Date: 4 Feb 2014 16:15 Release Date: 4 Feb 2014 6427 Views