Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Schneider Electric Telvent SAGE Remote Terminal Unit DoS Vulnerability

A vulnerability has been identified in Schneider Electric Telvent SAGE Remote Terminal Unit, which can be exploited by a remote user can cause denial of service conditions.   A remote user can send specially crafted DNP3 data to interrupt communications and cause the target service to temporarily consume excessive...
Last Update Date: 4 Feb 2014 16:15 Release Date: 4 Feb 2014 6047 Views

RISK: Medium Risk

Medium Risk

cURL Information Disclosure Vulnerability

A vulnerability has been identified in libcURL, which can be exploited by a remote user to obtain information from the wrong session.   When responding to an NTLM-authenticated HTTP or HTTPS request, the system may use the wrong connection (a connection authenticated with different credentials...
Last Update Date: 4 Feb 2014 16:14 Release Date: 4 Feb 2014 6041 Views

RISK: Medium Risk

Medium Risk

VLC Media Player Buffer Overflow Vulnerability

A vulnerability has been identified in VLC Media Player, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 4 Feb 2014 16:09 Release Date: 4 Feb 2014 5897 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious users to disclose sensitive information, manipulate certain data, cause a DoS (Denial of Service) and compromise a vulnerable system.
Last Update Date: 4 Feb 2014 16:08 Release Date: 4 Feb 2014 6000 Views

RISK: High Risk

High Risk

Yahoo Mail Account Credential Theft

On 30 Jan 2014, Yahoo has identified a coordinated effort to gain unauthorized access to Yahoo Mail accounts. Yahoo has prompted affected users to reset passwords, and issued a notice on the attack.   Yahoo claimed that the list of usernames and passwords that were used to...
Last Update Date: 4 Feb 2014 11:50 Release Date: 4 Feb 2014 6265 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Meetings Server Elevated Privileges Vulnerability

A vulnerability has been identified in WebEx Meetings Server. A remote authenticated user can gain elevated privileges.   A remote authenticated user can send a specially crafted URL to join meetings they are not authorized to attend or to end meetings for which they are not the host.   ...
Last Update Date: 30 Jan 2014 14:39 Release Date: 30 Jan 2014 6149 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco products, which can be exploited by attackers to conduct cross-site scripting attacks, access the target database, execute commands without proper authorization, cause denial of service conditions, and gain elevated privileges on the target system.
Last Update Date: 29 Jan 2014 18:44 Release Date: 29 Jan 2014 6100 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome where some have an unknown impact and others can be exploited by malicious people to compromise a user's system.Some unspecified errors exist. No further information is currently available.A use-after-free error...
Last Update Date: 29 Jan 2014 18:44 Release Date: 29 Jan 2014 6193 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.   The...
Last Update Date: 29 Jan 2014 Release Date: 28 Jan 2014 6083 Views

RISK: High Risk

High Risk

Apple Pages Double Free Memory Vulnerability

A vulnerability was identified in Apple Pages. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted Microsoft Word file that, when loaded by the target user, will trigger a double...
Last Update Date: 29 Jan 2014 Release Date: 27 Jan 2014 6082 Views

RISK: High Risk

High Risk

Apple iTunes Multiple vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes. A remote user can execute arbitrary code on the target system. A remote authenticated user can write files outside of the target SMB directory. A local user can bypass security restrictions.
Last Update Date: 24 Jan 2014 12:29 Release Date: 24 Jan 2014 6811 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple vulnerabilities

Multiple vulnerabilities have been identified in Drupal, which can be exploited by malicious users to bypass certain security restrictions and hijack another user's account.
Last Update Date: 23 Jan 2014 Release Date: 22 Jan 2014 5882 Views

RISK: Medium Risk

Medium Risk

JBoss Web Framework Kit Information Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in Red Hat JBoss Web Framework Kit, which can be exploited by malicious users to disclose potentially sensitive information. An error related to the InterfaceGenerator handler within JBoss Seam Remoting can be exploited to gain knowledge of all classes and methods within...
Last Update Date: 22 Jan 2014 17:51 Release Date: 22 Jan 2014 6072 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by attackers to cause denial of service and cross site request forgery.
Last Update Date: 20 Jan 2014 11:01 Release Date: 20 Jan 2014 6029 Views

RISK: Medium Risk

Medium Risk

Microsoft Dynamics AX Query Filter DoS Vulnerability

A denial of service vulnerability exists in Microsoft Dynamics AX that could allow an attacker to cause an AOS instance to become unresponsive.
Last Update Date: 15 Jan 2014 17:46 Release Date: 15 Jan 2014 5916 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Win32k Window Handle Vulnerability

An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly uses window handle thread-owned objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated privileges.
Last Update Date: 15 Jan 2014 17:46 Release Date: 15 Jan 2014 5922 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel NDProxy Vulnerability

An elevation of privilege vulnerability exists in the NDProxy component of the Windows kernel due to improper validation of input passed from user mode to the kernel. The vulnerability could allow an attacker to run code in kernel mode. An attacker who successfully exploited this vulnerability could run...
Last Update Date: 15 Jan 2014 17:45 Release Date: 15 Jan 2014 5960 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Multiple Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist in the way that affected Microsoft Office software parses specially crafted files. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 15 Jan 2014 17:45 Release Date: 15 Jan 2014 6150 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which can be exploited by malicious people to compromise a user's system.Two unspecified errors can be exploited to corrupt memory.A use-after-free error can be exploited to dereference already freed...
Last Update Date: 15 Jan 2014 12:32 Release Date: 15 Jan 2014 6010 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Security Bypass Vulnerability

A vulnerability has been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an unspecified error and can be exploited to bypass certain security protections. Additionally a weakness exists, ...
Last Update Date: 15 Jan 2014 12:31 Release Date: 15 Jan 2014 6091 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to denial of service, escalation of privilege, remote code execution and sensitive information disclosure.
Last Update Date: 15 Jan 2014 12:28 Release Date: 15 Jan 2014 6144 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system. A use-after-free error exists within web workers. A use-after...
Last Update Date: 15 Jan 2014 11:02 Release Date: 15 Jan 2014 5922 Views

RISK: Medium Risk

Medium Risk

ISC BIND Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by a remote user to cause denial of service (DoS) conditions.   A remote user can send a specially crafted query to an authoritative nameserver serving NSEC3-signed zones to cause the BIND service...
Last Update Date: 15 Jan 2014 Release Date: 14 Jan 2014 6066 Views

RISK: Medium Risk

Medium Risk

Symantec Endpoint Protection Elevated Privilege Vulnerabilities

Multiple vulnerabilities have been identified in Symantec Endpoint Protection, which can be exploited by local user obtain elevated privileges on the vulnerable system.A local user can exploit an authentication flaw in the Management Console to gain the privileges of another user.A local user can bypass...
Last Update Date: 13 Jan 2014 15:31 Release Date: 13 Jan 2014 6291 Views

RISK: Medium Risk

Medium Risk

Schneider Electric PACiS SUI WebHMI "SetActiveXGUID" Buffer Overflow Vulnerability

A vulnerability has been identified in Schneider Electric PACiS SUI, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 10 Jan 2014 Release Date: 9 Jan 2014 6123 Views

RISK: Medium Risk

Medium Risk

Cisco NX-OS BGP Update Message Processing Vulnerability

A vulnerability has been identified in Cisco NX-OS. A remote user can cause denial of service conditions.   A remote user can send specially crafted BGP update data to cause all BGP sessions on the target device (configured with a VPNv4, VPNv6, or IPv6...
Last Update Date: 10 Jan 2014 Release Date: 9 Jan 2014 5954 Views

RISK: Medium Risk

Medium Risk

OpenSSL TLS Handshake Null Pointer Exception Vulnerability

A vulnerability has been identified in OpenSSL. A remote user can cause denial of service conditions.   A remote server can send specially crafted TLS handshake data to trigger a null pointer exception and cause the target client to crash.
Last Update Date: 8 Jan 2014 17:40 Release Date: 8 Jan 2014 6116 Views

RISK: High Risk

High Risk

Linksys Router Authentication Bypass Backdoor Vulnerability

A vulnerability has been identified in several Linksys Routers, which can be exploited by remote user can gain administrative access.A remote user can send specially crafted data to TCP port 32764 to execute commands on the target system with administrative privileges. Note: Vulnerability has no...
Last Update Date: 6 Jan 2014 12:33 Release Date: 6 Jan 2014 7105 Views

RISK: Medium Risk

Medium Risk

HP Data Protector Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Data Protector, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.The vulnerabilities are caused due to unspecified errors.
Last Update Date: 6 Jan 2014 12:29 Release Date: 6 Jan 2014 6040 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL. A remote user may be able to conduct man-in-the-middle attacks and cause denial of service conditions. The DTLS retransmission implementation does not properly maintain data structures for digest and encryption contexts. A remote user...
Last Update Date: 3 Jan 2014 10:44 Release Date: 3 Jan 2014 6078 Views

RISK: Medium Risk

Medium Risk

cPanel Multiple Vulnerabilities

Multiple vulnerabilities were identified in cPanel. A remote authenticated user can execute arbitrary code on the target system. A remote user can conduct cross-site scripting attacks. A remote user can obtain potentially sensitive information.
Last Update Date: 24 Dec 2013 11:53 Release Date: 24 Dec 2013 5998 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server / ESXi Virtual Machine File Descriptors Security Bypass Vulnerability

A vulnerability has been identified in VMware ESX Server and VMware ESXi, which can be exploited by malicious users to bypass certain security restrictions. The vulnerability is caused due to an error when handling certain Virtual Machine file descriptors, which can be exploited to gain read and...
Last Update Date: 24 Dec 2013 11:51 Release Date: 24 Dec 2013 6645 Views

RISK: Medium Risk

Medium Risk

RealPlayer RMP File Handling Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error when handling .RMP files and can be exploited to cause a heap-based buffer overflow.   Successful...
Last Update Date: 24 Dec 2013 11:44 Release Date: 24 Dec 2013 6179 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Manager DRS Vulnerability

A vulnerability has been identified in Cisco Unified Communications Manager. A remote authenticated user can obtain potentially sensitive information.   A remote authenticated user can exploit a flaw in the disaster recovery system (DRS) to obtain potentially sensitive information about DRS-related devices contained...
Last Update Date: 24 Dec 2013 Release Date: 20 Dec 2013 6046 Views

RISK: Medium Risk

Medium Risk

Apple Motion MOTN Files Processing Integer Overflow Vulnerability

A vulnerability has been identified in Apple Motion, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an integer overflow error when processing MOTN files and can be exploited to cause an out-of-bounds...
Last Update Date: 23 Dec 2013 15:57 Release Date: 23 Dec 2013 5986 Views

RISK: Medium Risk

Medium Risk

Google Picasa RAW Image Parsing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Picasa, which can be exploited by malicious people to compromise a user's system.An integer underflow error within the Picasa3.exe module when parsing JPEG tags can be exploited to cause a heap-based buffer overflow via...
Last Update Date: 23 Dec 2013 12:26 Release Date: 23 Dec 2013 6141 Views

RISK: Medium Risk

Medium Risk

Splunk Enterprise Data Processing Vulnerability

A vulnerability has been identified in Splunk Enterprise. A remote user can cause denial of service conditions.   A remote user can send specially crafted data to cause the target server to become unavailable.   Systems configured as data 'receivers' on the listening or receiving port...
Last Update Date: 20 Dec 2013 10:09 Release Date: 20 Dec 2013 5819 Views

RISK: Medium Risk

Medium Risk

Asterisk Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Asterisk, which can be exploited by malicious people to escalate privileges and cause a DoS (Denial of Service). A 16 bit SMS message that contains an odd message length value will cause the message decoding loop to run forever. ...
Last Update Date: 19 Dec 2013 18:10 Release Date: 19 Dec 2013 5843 Views

RISK: High Risk

High Risk

RealOne RMP File Heap Overflow Vulnerability

A vulnerability has been identified in RealPlayer. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted RMP file that, when loaded by the target user, will trigger a heap overflow...
Last Update Date: 19 Dec 2013 18:04 Release Date: 19 Dec 2013 5886 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).An error within the SIP dissector (epan/dissectors/packet-sip.c) can be exploited to cause an infinite loop....
Last Update Date: 19 Dec 2013 17:59 Release Date: 19 Dec 2013 5829 Views

RISK: High Risk

High Risk

Apple OS X Multiple Vulnerabilities

A security issue and multiple vulnerabilities have been identified in Apple OS X, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system The security issue and vulnerability is caused due to a bundled vulnerable version of Apple Safari...
Last Update Date: 18 Dec 2013 12:05 Release Date: 18 Dec 2013 5993 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

A security issue and multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.An error related to origin tracking can be exploited to autofill a form in a subframe...
Last Update Date: 18 Dec 2013 12:04 Release Date: 18 Dec 2013 6229 Views

RISK: Medium Risk

Medium Risk

IrfanView GIF Image Processing Buffer Overflow Vulnerability

A vulnerability has been identified in IrfanView, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error when handling the LZW code stream within GIF files and can be exploited to cause a...
Last Update Date: 18 Dec 2013 12:03 Release Date: 18 Dec 2013 6086 Views

RISK: Medium Risk

Medium Risk

HP LaserJet Printers Denial of Service Vulnerability

A vulnerability has been identified in HP LaserJet Printers. which can be exploited by remote user can cause denial of service conditions. A remote user can send specially crafted data to cause partial denial of service conditions on the target printer.
Last Update Date: 16 Dec 2013 10:27 Release Date: 16 Dec 2013 6308 Views

RISK: High Risk

High Risk

Microsoft Graphics Component Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that affected Windows components and other affected software handle specially crafted TIFF files. The vulnerability could allow remote code execution if a user views TIFF files in shared content. An attacker who successfully exploited this vulnerability could take complete...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5971 Views

RISK: High Risk

High Risk

Microsoft Windows WinVerifyTrust Signature Validation Vulnerability

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 8593 Views

RISK: High Risk

High Risk

Microsoft Scripting Runtime Object Library Use-After-Free Vulnerability

This is a remote code execution vulnerability in the Microsoft Scripting Runtime Object Library. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6167 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Page Content Vulnerabilities

Remote code execution vulnerabilities exist in Microsoft SharePoint Server. An authenticated attacker who successfully exploited these vulnerabilities could run arbitrary code in the security context of the W3WP service account.
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5795 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Win32k Memory Corruption VulnerabilityAn elevation of privilege vulnerability exists in the way that the Win32k.sys kernel-mode driver validates address values in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated privileges.Win32k Use After Free VulnerabilityAn elevation of privilege...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6121 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LRPC Client Buffer Overrun Vulnerability

An elevation of privilege vulnerability exists in Microsoft Local Remote Procedure Call (LRPC) where an attacker spoofs an LRPC Server and uses a specially crafted LPC port message to cause a stack-based buffer overflow condition on the LRPC client. LRPC internally uses Microsoft Local Procedure...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6338 Views

RISK: Medium Risk

Medium Risk

ASP.NET SignalR XSS Vulnerability

An elevation of privilege vulnerability exists in ASP.NET SignalR that could allow an attacker access to resources in the context of the targeted user.
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6733 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Token Hijacking Vulnerability

An information disclosure vulnerability exists when affected Microsoft Office software does not properly handle a specially crafted response while attempting to open an Office file hosted on the malicious website. An attacker who successfully exploited this vulnerability could ascertain access tokens used to authenticate the current user on a...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5977 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Remote Code Execution Vulnerabilities

Oracle Outside In Contains Multiple Exploitable VulnerabilitiesTwo of the vulnerabilities addressed in this bulletin, CVE-2013-5763 and CVE-2013-5791, exist in Exchange Server 2007, Exchange Server 2010, and Exchange Server 2013 through the WebReady Document Viewing feature. The vulnerabilities...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6132 Views

RISK: Medium Risk

Medium Risk

Microsoft Office HXDS ASLR Vulnerability

A security feature bypass exists in an Office shared component that does not properly implement Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, after which the attacker could load additional malicious code in the process in an attempt...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5972 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Elevation of Privilege Vulnerabilities in Internet ExplorerElevation of privilege vulnerabilities exist within Internet Explorer during validation of local file installation and during secure creation of registry keys.Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5853 Views

RISK: High Risk

High Risk

PHP OpenSSL Extension X.509 Certificate Parsing Memory Corruption Vulnerability

A vulnerability was reported in PHP. A remote user can execute arbitrary code on the target system.  A remote user can send a specially crafted certificate to trigger a memory corruption flaw in openssl_x509_parse() and execute arbitrary code on the target system. The code will run...
Last Update Date: 12 Dec 2013 09:51 Release Date: 12 Dec 2013 5826 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. Some unspecified errors exist, ...
Last Update Date: 11 Dec 2013 10:17 Release Date: 11 Dec 2013 6017 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Memory Corruption Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system.   Unspecified errors can be exploited to cause memory corruption.   Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
Last Update Date: 11 Dec 2013 10:00 Release Date: 11 Dec 2013 5862 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system. A type confusion error exists. A use-after-free error when unloading the Flash Player module can be exploited...
Last Update Date: 11 Dec 2013 09:59 Release Date: 11 Dec 2013 5905 Views

RISK: High Risk

High Risk

Microsoft Windows Includes An Invalid Certificate Vulnerability

A vulnerability was reported in Microsoft Windows. A remote user may be able to spoof SSL certificates. The operating system includes an invalid subordinate certificate issued by Directorate General of the Treasury (DG Tresor), subordinate to the Government of France CA (ANSSI). The invalid...
Last Update Date: 10 Dec 2013 10:11 Release Date: 10 Dec 2013 6697 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 9 Dec 2013 09:47 Release Date: 9 Dec 2013 5828 Views

RISK: Medium Risk

Medium Risk

GIMP XWD Plugin "load_image()" Buffer Overflow Vulnerability

A vulnerability have been reported in GIMP, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the "load_image()" function (plug-ins/common/file-xwd....
Last Update Date: 6 Dec 2013 11:33 Release Date: 6 Dec 2013 5795 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct spoofing and session fixation attacks and compromise a user's system.An error when handling the 302 HTTP status in sync can be...
Last Update Date: 6 Dec 2013 11:33 Release Date: 6 Dec 2013 6027 Views

RISK: Medium Risk

Medium Risk

JBoss Enterprise Application Platform Multiple Vulnerbilities

Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform. A remote authenticated user can bypass security controls. A local user can obtain elevated privileges on the target system. The HawtJNI Library class writes native libraries to a predictable file name in the '/tmp' directory...
Last Update Date: 5 Dec 2013 10:01 Release Date: 5 Dec 2013 5876 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Multiple Vulnerability

Multiple vulnerabilities were identified in Ruby on Rails. A remote user can cause denial of service conditions, conduct cross-site scripting attacks, and generate unsafe queries. Several scripts do not properly filter HTML code from user-supplied input before displaying the input. A...
Last Update Date: 4 Dec 2013 09:30 Release Date: 4 Dec 2013 5986 Views

RISK: High Risk

High Risk

D-Link Router Authentication Bypass Backdoor Vulnerability

A vulnerability was reported in D-Link Routers. A remote user can gain administrative access on the target device.   A remote user can send a specially crafted HTTP request with the HTTP User-Agent set to 'xmlset_roodkcableoj28840ybtide' to bypass authentication and gain administrative access...
Last Update Date: 3 Dec 2013 Release Date: 15 Oct 2013 7151 Views

RISK: High Risk

High Risk

Microsoft Windows NDProxy.sys Privilege Escalation Vulnerability

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.   The vulnerability is caused due to an input validation error within the NDPROXY (NDProxy.sys) kernel component and can be exploited to execute arbitrary...
Last Update Date: 29 Nov 2013 10:39 Release Date: 29 Nov 2013 6004 Views

RISK: High Risk

High Risk

Cisco IOS IPSec ICMP Vulnerability

A vulnerability has been identified in Cisco IOS. A remote user can cause denial of service conditions.   A remote user can send specially crafted ICMP packets to the target device to modify the IPSec tunnel MTU or path MTU and potentially cause IPSec tunnels to drop...
Last Update Date: 26 Nov 2013 10:05 Release Date: 26 Nov 2013 5990 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.   The vulnerabilities are...
Last Update Date: 26 Nov 2013 09:55 Release Date: 26 Nov 2013 5837 Views

RISK: High Risk

High Risk

Ruby Floating Point Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Ruby, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to an error when converting strings to floating point values and can be exploited to cause a heap-based buffer overflow via a...
Last Update Date: 25 Nov 2013 10:03 Release Date: 25 Nov 2013 6058 Views

RISK: Medium Risk

Medium Risk

JPEGView Buffer Overflow Vulnerability

A vulnerability has been identified JPEGView, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to a sign extension error within the JPEGView.exe module and can be exploited to cause a buffer overflow via a...
Last Update Date: 22 Nov 2013 10:33 Release Date: 22 Nov 2013 6627 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Drupal, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct brute force, spoofing, and cross-site scripting attacks.The application generates security related strings using the cryptographically weak mt_rand() ...
Last Update Date: 22 Nov 2013 10:30 Release Date: 22 Nov 2013 6145 Views

RISK: High Risk

High Risk

Mozilla Firefox / Seamonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox. A remote user can cause denial of service conditions and bypass security controls. When the verifylog feature is used when validating certificates, the system will use certificates that specify incompatible key usage constraints. On 64-bit systems...
Last Update Date: 20 Nov 2013 10:54 Release Date: 20 Nov 2013 6221 Views

RISK: Medium Risk

Medium Risk

nginx URI Parsing Vulnerability

A vulnerability has been identified in nginx. A remote user can bypass security restrictions.   A remote user can supply a specially crafted request containing an unescaped space character to potentially bypass security restrictions.
Last Update Date: 20 Nov 2013 10:35 Release Date: 20 Nov 2013 6837 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.   The vulnerabilities are caused due to some unspecified errors and can be exploited to corrupt memory.   Successful exploitation may allow execution of arbitrary code.
Last Update Date: 18 Nov 2013 09:32 Release Date: 18 Nov 2013 6192 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, and compromise a user's system.A use-after-free error exists in speech input elements.A use-...
Last Update Date: 14 Nov 2013 10:50 Release Date: 14 Nov 2013 6253 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Digital Signatures Denial of Service Vulnerability

A denial of service vulnerability exists in implementations of X.509 certificate parsing that could cause an affected web service to stop responding. The vulnerability is caused when the X.509 certificate validation operation fails to handle a specially crafted X.509 certificate.
Last Update Date: 13 Nov 2013 17:05 Release Date: 13 Nov 2013 6167 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook S/MIME AIA Vulnerability

An information disclosure vulnerability exists when Microsoft Outlook does not properly handle the expansion of S/MIME certificate metadata. An attacker who successfully exploited this vulnerability could ascertain system information, such as the IP address and open TCP ports, from the target system and other systems...
Last Update Date: 13 Nov 2013 17:04 Release Date: 13 Nov 2013 6211 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Windows kernel-mode driver improperly handles copying data between kernel and user memory.
Last Update Date: 13 Nov 2013 17:04 Release Date: 13 Nov 2013 6157 Views

RISK: Medium Risk

Medium Risk

Microsoft Hyper-V Address Corruption Vulnerability

An elevation of privilege vulnerability exists in Hyper-V on Windows 8 and Windows Server 2012. An attacker who successfully exploited this vulnerability could execute arbitrary code as System in another virtual machine (VM) on the shared Hyper-V host. An attacker would not...
Last Update Date: 13 Nov 2013 17:03 Release Date: 13 Nov 2013 6160 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerabilities

WPD File Format Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that affected Microsoft Office software parses specially crafted WordPerfect document (.wpd) files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 13 Nov 2013 17:03 Release Date: 13 Nov 2013 6252 Views

RISK: Medium Risk

Medium Risk

Microsoft ActiveX InformationCardSigninHelper Vulnerability

A remote code execution vulnerability exists in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited...
Last Update Date: 13 Nov 2013 17:03 Release Date: 13 Nov 2013 6811 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Device Interface Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) processes specially crafted Windows Write files in WordPad. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 13 Nov 2013 17:02 Release Date: 13 Nov 2013 6189 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Cumulative Security Update

Internet Explorer Information Disclosure VulnerabilityAn information disclosure vulnerability exists in the way that Internet Explorer handles specially crafted web content when generating print previews. An attacker who successfully exploited this vulnerability could gather information from any page that the victim is viewing.Internet Explorer Information Disclosure VulnerabilityAn information...
Last Update Date: 13 Nov 2013 17:02 Release Date: 13 Nov 2013 6042 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer ActiveX Control Code Execution Vulnerability

A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error within an ActiveX control. Successful exploitation allows execution of arbitrary code. For detail of the vulnerability...
Last Update Date: 13 Nov 2013 Release Date: 12 Nov 2013 6598 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Adobe ColdFusion, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions. Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary...
Last Update Date: 13 Nov 2013 09:33 Release Date: 13 Nov 2013 5992 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system.   Unspecified errors can be exploited to cause memory corruption.
Last Update Date: 13 Nov 2013 09:32 Release Date: 13 Nov 2013 6131 Views

RISK: Medium Risk

Medium Risk

OpenSSH AES-GCM Memory Corruption Vulnerability

A vulnerability has been identified in OpenSSH. A remote authenticated user can bypass access control restrictions.   A remote authenticated user can send specially crafted data to trigger a memory corruption flaw when an AES-GCM cipher is selected during key exchange to execute arbitrary code on...
Last Update Date: 12 Nov 2013 10:28 Release Date: 12 Nov 2013 6382 Views

RISK: Medium Risk

Medium Risk

Cisco IOS SIP Processing Vulnerability

A vulnerability has been identified in Cisco IOS. A remote user can cause denial of service conditions.   A remote user can send specially crafted, valid SIP messages via IPv4 or IPv6 to the target device to trigger a memory leak, causing the system to become unstable...
Last Update Date: 8 Nov 2013 10:25 Release Date: 8 Nov 2013 5837 Views

RISK: Medium Risk

Medium Risk

ISC BIND Windows Netmask Processing Vulnerability

A vulnerability has been identified in BIND. A remote user on the local network can bypass access control restrictions.   On Windows-based systems, an all zero netmask may cause a match on any IPv4 address. A remote user on the local network may be able...
Last Update Date: 8 Nov 2013 10:24 Release Date: 8 Nov 2013 5913 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system. Unspecified errors can be exploited...
Last Update Date: 8 Nov 2013 10:24 Release Date: 8 Nov 2013 5881 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Graphics Component Remote Code Execution Vulnerability

A vulnerability was identified in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted TIFF image file that, when loaded by the target user, will trigger a memory...
Last Update Date: 6 Nov 2013 09:35 Release Date: 6 Nov 2013 6286 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).An error within the IEEE 802.15.4 dissector can be exploited to cause a crash.An error within the NBAP dissector can...
Last Update Date: 5 Nov 2013 10:17 Release Date: 5 Nov 2013 5952 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to conduct spoofing attacks and compromise a user's system. Some unspecified errors and an error when handling workers with direct proxies within the JavaScript engine can...
Last Update Date: 31 Oct 2013 15:28 Release Date: 31 Oct 2013 6031 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS XE. A remote user can cause denial of service conditions. A remote user can send specially crafted ICMP error packets through the target device to trigger a flaw in the Zone-Based Firewall (ZBFW) TCP or UDP...
Last Update Date: 31 Oct 2013 15:27 Release Date: 31 Oct 2013 5809 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Google Chrome, where two have an unknown impact and others can be exploited by malicious people to compromise a user's system.A use-after-free error exists in XHR.A use-after-free error exists...
Last Update Date: 30 Oct 2013 Release Date: 17 Oct 2013 6180 Views

RISK: Medium Risk

Medium Risk

Cisco Products Apache Struts 2 Command Execution Vulnerability

A vulnerability has been identified in multiple Cisco products, which include an implementation of Apache Struts 2 component that is affected by a remote command execution vulnerability.   The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by sending...
Last Update Date: 25 Oct 2013 10:06 Release Date: 25 Oct 2013 5990 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by malicious people to disclose certain sensitive information, cause a DoS (Denial of Service), and potentially compromise a user's system.
Last Update Date: 24 Oct 2013 11:29 Release Date: 24 Oct 2013 5939 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system.   The vulnerabilities are caused due to a bundled vulnerable version of WebKit.
Last Update Date: 24 Oct 2013 11:28 Release Date: 24 Oct 2013 5919 Views

RISK: Medium Risk

Medium Risk

Apple Remote Desktop Format String Vulnerability

A vulnerability has been identified in Apple Remote Desktop. A remote user can execute arbitrary code on the target system. A remote user can send specially crafted VNC username data to trigger a format string flaw and execute arbitrary code on the target system. The system may...
Last Update Date: 24 Oct 2013 10:48 Release Date: 24 Oct 2013 6162 Views