Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Cisco IOS XR Fragmented Packet Processing Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote user can cause denial of service conditions.   A remote user can send specially crafted fragmented packets to the target device to cause the target route processor to be unable to transmit packets to the fabric.
Last Update Date: 24 Oct 2013 10:42 Release Date: 24 Oct 2013 6111 Views

RISK: Medium Risk

Medium Risk

Apple iOS Passcode Lock Security Bypass Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people with physical access to bypass certain security restrictions. A NULL pointer dereference error related to the emergency call button and the camera pane within the lock screen of the Passcode Lock component can...
Last Update Date: 24 Oct 2013 10:28 Release Date: 24 Oct 2013 6253 Views

RISK: High Risk

High Risk

Apple OS X and OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X and OS X Server, which can be exploited by remote attacker to conduct cross site scripting, denial of serverice, elevation of privilege, remote code execution and sensitive information disclosure   The following OS X components are found...
Last Update Date: 24 Oct 2013 10:06 Release Date: 24 Oct 2013 6152 Views

RISK: High Risk

High Risk

Node.js HTTP Server Deny Service Vulnerability

A vulnerability was identified in Node.js. A remote user can cause denial of service conditions. A remote user can send a large number of specially crafted pipelined requests to the target HTTP server component to cause excessive memory and CPU consumption on the target system.
Last Update Date: 22 Oct 2013 10:07 Release Date: 22 Oct 2013 6079 Views

RISK: Medium Risk

Medium Risk

VMware ESX/ESXi hostd-vmdb Deny Service Vulnerability

A vulnerability was identified in VMware ESX/ESXi. A remote user can cause denial of service conditions. A remote user with the ability to conduct a man-in-the-middle attack can modify management traffic to cause denial of service conditions on the hostd...
Last Update Date: 21 Oct 2013 09:59 Release Date: 21 Oct 2013 6236 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Oracle Java, which can be exploited by malicious users to manipulate certain data and by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 17 Oct 2013 14:28 Release Date: 17 Oct 2013 6535 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to denial of service, escalation of privilege, remote code execution, sensitive information disclosure and tampering.
Last Update Date: 17 Oct 2013 14:27 Release Date: 17 Oct 2013 6954 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist when Internet Explorer improperly accesses an object in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 16 Oct 2013 Release Date: 9 Oct 2013 6072 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Some vulnerabilities have been reported in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.Some errors within libavcodec/vmnc.c can be exploited to cause out of bounds read...
Last Update Date: 15 Oct 2013 16:19 Release Date: 15 Oct 2013 6019 Views

RISK: Medium Risk

Medium Risk

BlackBerry Universal Device Service Wrapper Vulnerability

A vulnerability has been identified in BlackBerry Universal Device Service, which could potentially allow an attacker to obtain escalation of privilege and then execute arbitrary code.
Last Update Date: 10 Oct 2013 10:25 Release Date: 10 Oct 2013 6044 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco products, which can be exploited by attackers to conduct cross site scripting, denial of service, elevation of privilege, security restriction bypass and sensitive information disclosure.
Last Update Date: 10 Oct 2013 10:24 Release Date: 10 Oct 2013 6244 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities

OpenType Font Parsing VulnerabilityA remote code execution vulnerability exists in the way that Windows parses specially crafted OpenType fonts (OTF). An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete...
Last Update Date: 9 Oct 2013 19:00 Release Date: 9 Oct 2013 6334 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Remote Code Execution Vulnerabilities

OpenType Font Parsing VulnerabilityA remote code execution vulnerability exists in the way that affected components handle specially crafted OpenType fonts (OTF). The vulnerability could allow remote code execution if a user visits a website hosting an XAML Browser Application (XBAP) containing a specially crafted OTF file...
Last Update Date: 9 Oct 2013 18:58 Release Date: 9 Oct 2013 6178 Views

RISK: High Risk

High Risk

Microsoft Windows Common Control Library Remote Code Execution Vulnerability

Comctl32 Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that the Windows common control library handles allocating memory for data structures. The vulnerability could allow remote code execution if an attacker sends a specially crafted web request to an ASP.NET web application running on...
Last Update Date: 9 Oct 2013 18:58 Release Date: 9 Oct 2013 6151 Views

RISK: High Risk

High Risk

Microsoft SharePoint Server Remote Code Execution Vulnerabilities

Microsoft Excel Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that affected Microsoft Office Services and Web Apps parse content in specially crafted files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs...
Last Update Date: 9 Oct 2013 18:57 Release Date: 9 Oct 2013 5969 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Excel parses content in Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 9 Oct 2013 18:57 Release Date: 9 Oct 2013 6067 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the way that affected Microsoft Word software parses specially crafted files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 9 Oct 2013 18:56 Release Date: 9 Oct 2013 5993 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Information Disclosure Vulnerability

An information disclosure vulnerability exists in how Silverlight handles certain objects in memory.
Last Update Date: 9 Oct 2013 18:56 Release Date: 9 Oct 2013 6165 Views

RISK: Medium Risk

Medium Risk

Adobe RoboHelp MDBMS.dll Unspecified Flaw Vulnerability

A vulnerability has been identified in Adobe RoboHelp. A remote user can execute arbitrary code on the target system.   A remote user can trigger a flaw in 'MDBMS.dll' to execute arbitrary code on the target system.
Last Update Date: 9 Oct 2013 09:34 Release Date: 9 Oct 2013 6001 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat/Reader Scripting Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary scripting code to be executed on the target user's system.   A remote user can create a specially crafted PDF file that, when loaded by the target user in a...
Last Update Date: 9 Oct 2013 09:33 Release Date: 9 Oct 2013 6047 Views

RISK: Medium Risk

Medium Risk

Corel PaintShop Pro X5 / X6 Insecure Library Loading Vulnerability

A vulnerability has been identified in Corel PaintShop Pro X5 and X6, which can be exploited by malicious people to compromise a user's system.The application loads libraries (e.g. dwmapi.dll) in an insecure manner. This can be exploited...
Last Update Date: 7 Oct 2013 12:07 Release Date: 7 Oct 2013 6133 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where can be exploited by malicious people to conduct spoofing attacks and compromise a user's system. Some race condition errors exist in Web Audio. An out-of-bounds read error exists in Window.prototype...
Last Update Date: 3 Oct 2013 10:25 Release Date: 3 Oct 2013 6081 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR UDP Memory Error Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote user can cause denial of service conditions.   A remote user can send UDP packets to the target device to consume all available packet memory and cause critical services on the device to fail.
Last Update Date: 3 Oct 2013 10:12 Release Date: 3 Oct 2013 6188 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.An error within the "pcx_decode_frame()" function (libavcodec/pcx.c) can be...
Last Update Date: 2 Oct 2013 09:57 Release Date: 2 Oct 2013 6387 Views

RISK: Medium Risk

Medium Risk

ProFTPD SFTP Integer Overflow vulnerability

A vulnerability has been identified in ProFTPD, which can be exploited by remote user can cause denial of service conditions.A remote user can send specially crafted data to trigger an integer overflow in the sftp_kbdint_recv_response() function in 'contrib/mod_sftp/kbdint.c' ...
Last Update Date: 30 Sep 2013 10:55 Release Date: 30 Sep 2013 6476 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library. Some errors within the "ff_vc1_decode_init_alloc_tables()" function (libavcodec/vc1dec.c) ...
Last Update Date: 26 Sep 2013 16:38 Release Date: 26 Sep 2013 5999 Views

RISK: High Risk

High Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS. A remote user can cause denial of service conditions. A remote user can send specially crafted multicast Network Time Protocol (NTP) packets encapsulated in a Multicast Source Discovery Protocol (MSDP) Source-Active (SA) ...
Last Update Date: 26 Sep 2013 16:38 Release Date: 26 Sep 2013 6348 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Solaris, which can be exploited by remote attackers to conduct cross site scripting, spoofing, elevation of privilege, denial of service and remote code execution.
Last Update Date: 26 Sep 2013 16:37 Release Date: 26 Sep 2013 6066 Views

RISK: Medium Risk

Medium Risk

Apache Struts "action:" Action Mapping Security Bypass Vulnerability

A vulnerability has been reported in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error related to the action mapping "action:" prefix and can be exploited to gain access to otherwise restricted functionality...
Last Update Date: 24 Sep 2013 10:42 Release Date: 24 Sep 2013 6239 Views

RISK: Medium Risk

Medium Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Apple TV, which can be exploited by malicious people with physical access to bypass certain security restrictions and by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable device.
Last Update Date: 24 Sep 2013 10:40 Release Date: 24 Sep 2013 6060 Views

RISK: Medium Risk

Medium Risk

Apple iOS Bypass Passcode Lock Vulnerability

A vulnerability has been identified in Apple iOS. A local user can bypass the passcode lock feature and access photos or make a phone call.A local user can invoke the Apple Control Center and bypass the passcode lock screen to access photos and related photo sharing applications...
Last Update Date: 23 Sep 2013 15:48 Release Date: 23 Sep 2013 7021 Views

RISK: High Risk

High Risk

Apple iTunes Memory Corruption Vulnerability

A vulnerability has been identified in Apple iTunes. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the iTunes ActiveX...
Last Update Date: 19 Sep 2013 12:18 Release Date: 19 Sep 2013 6126 Views

RISK: Medium Risk

Medium Risk

Apple OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X Server, which can be exploited by malicious users to conduct brute force and script insertion attacks, bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a vulnerable system. ...
Last Update Date: 19 Sep 2013 12:17 Release Date: 19 Sep 2013 6062 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, Thunderbird and Seamonkey. A remote user can cause arbitrary code to be executed on the target user's system, cause denial of service conditions, and conduct cross-site scripting attacks. A local user can obtain elevated...
Last Update Date: 18 Sep 2013 09:24 Release Date: 18 Sep 2013 5994 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Object Access Memory Corruption Vulnerability

A vulnerability was identified in Microsoft Internet Explorer. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a memory corruption error...
Last Update Date: 18 Sep 2013 09:24 Release Date: 18 Sep 2013 6352 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been reported in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.An error within the "avpriv_dv_produce_packet()" function (libavformat/dv.c) can be...
Last Update Date: 17 Sep 2013 10:33 Release Date: 17 Sep 2013 6162 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X. Which can be exploited by attacker to denial of service conditions, spoof IPSec servers, bypass access controls and compromise the target user's system.Some errors exist due to a bundled vulnerable version of Apache....
Last Update Date: 16 Sep 2013 14:35 Release Date: 16 Sep 2013 6277 Views

RISK: High Risk

High Risk

Apple Safari for Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari for Mac OS X, which can be exploited by malicious people to compromise a user's system.The vulnerabilities are reported in versions prior to 5.1.10 running on OS X Snow Leopard version 10....
Last Update Date: 16 Sep 2013 14:29 Release Date: 16 Sep 2013 6147 Views

RISK: Medium Risk

Medium Risk

Juniper Junos Pulse Secure Access Service / Junos Pulse Access Control Service Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Juniper Junos Pulse Secure Access Service and Juniper Junos Pulse Access Control Service, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, cause a DoS (Denial of Service), and compromise...
Last Update Date: 13 Sep 2013 09:54 Release Date: 13 Sep 2013 6122 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress which can be exploited by a remote user to execute arbitrary code on the target system in certain situations or redirect a target user to another web site. A remote authenticated user can gain elevated privileges.
Last Update Date: 13 Sep 2013 09:52 Release Date: 13 Sep 2013 5989 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark. A remote user can cause denial of service conditions, and send specially crafted data to cause the target Wireshark service to crash or hang. The Bluetooth HCI ACL dissector, NBAP dissector, MQ dissector, LDAP dissector and Netmon...
Last Update Date: 12 Sep 2013 10:48 Release Date: 12 Sep 2013 6153 Views

RISK: Medium Risk

Medium Risk

BlackBerry 10 OS / PlayBook OS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry 10 OS and PlayBook OS, which can be exploited by malicious people to disclose certain sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable device.   The vulnerabilities are caused due...
Last Update Date: 12 Sep 2013 10:13 Release Date: 12 Sep 2013 6295 Views

RISK: High Risk

High Risk

Microsoft Active Directory Denial of Service Vulnerability

A denial of service vulnerability exists in implementations of Active Directory Services and AD LDS that could cause the LDAP directory service to stop responding until an administrator restarts the service. The vulnerability is caused when the LDAP directory service fails to handle a specially crafted query.
Last Update Date: 11 Sep 2013 18:35 Release Date: 11 Sep 2013 6251 Views

RISK: High Risk

High Risk

Microsoft Outlook Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted S/MIME email messages. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 11 Sep 2013 14:49 Release Date: 11 Sep 2013 6127 Views

RISK: High Risk

High Risk

Microsoft SharePoint Server Remote Code Execution Vulnerabilities

SharePoint Denial of Service VulnerabilityA denial of service vulnerability exists in Microsoft SharePoint Server. An attacker who successfully exploited this vulnerability could cause the W3WP process on an affected version of SharePoint Server to stop responding, causing the SharePoint site, and any other sites running under that...
Last Update Date: 11 Sep 2013 14:49 Release Date: 11 Sep 2013 6310 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist when Internet Explorer improperly accesses an object in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 11 Sep 2013 14:48 Release Date: 11 Sep 2013 6177 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Remote Code Execution Vulnerability

A vulnerability exists in OLE that could lead to remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is...
Last Update Date: 11 Sep 2013 14:48 Release Date: 11 Sep 2013 6032 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Theme File Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that affected editions of Microsoft Windows handles certain specially crafted Windows theme files. This vulnerability could allow an attacker to execute arbitrary code if the attacker convinces a user to apply a specially crafted Windows theme. An attacker could...
Last Update Date: 11 Sep 2013 14:47 Release Date: 11 Sep 2013 6040 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerabilities

XML External Entities Resolution VulnerabilityAn information disclosure vulnerability exists in the way that Microsoft Word parses specially crafted XML files containing external entities.Multiple Memory Corruption Vulnerabilities in Microsoft WordRemote code execution vulnerabilities exist in the way that affected Microsoft Office software parses specially crafted files. An attacker...
Last Update Date: 11 Sep 2013 14:47 Release Date: 11 Sep 2013 6029 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Remote Code Execution Vulnerabilities

Microsoft Office Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Excel parses content in Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 11 Sep 2013 14:40 Release Date: 11 Sep 2013 6224 Views

RISK: Medium Risk

Medium Risk

Microsoft Access Remote Code Execution Vulnerabilties

Remote code execution vulnerabilities exist in the way that Microsoft Access parses content in Access files. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create...
Last Update Date: 11 Sep 2013 14:39 Release Date: 11 Sep 2013 6058 Views

RISK: Medium Risk

Medium Risk

Microsoft Office IME (Chinese) Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Office IME for Chinese that could allow a low-privilege user to elevate their access privileges.
Last Update Date: 11 Sep 2013 14:39 Release Date: 11 Sep 2013 6070 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilties

Multiple Win32k Multiple Fetch VulnerabilitiesElevation of privilege vulnerabilities exist when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges and read arbitrary amounts of kernel memory.Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability...
Last Update Date: 11 Sep 2013 14:36 Release Date: 11 Sep 2013 5935 Views

RISK: Medium Risk

Medium Risk

Microsoft FrontPage Information Disclosure Vulnerability

An information disclosure vulnerability exists in FrontPage that could allow an attacker to disclose the contents of a file on a target system.
Last Update Date: 11 Sep 2013 14:35 Release Date: 11 Sep 2013 6317 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Service Control Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Service Control Manager (SCM) handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 11 Sep 2013 14:35 Release Date: 11 Sep 2013 6165 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system. Another unspecified error can be exploited to cause memory corruption. An unspecified error can be exploited to cause memory corruption. ...
Last Update Date: 11 Sep 2013 14:34 Release Date: 11 Sep 2013 5960 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Two vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system.An unspecified error can be exploited to cause memory corruption.Another unspecified error can be exploited to cause memory corruption.Successful exploitation of...
Last Update Date: 11 Sep 2013 14:34 Release Date: 11 Sep 2013 5969 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Adobe Reader and Adobe Acrobat, which can be exploited by malicious people to compromise a user's system.Some unspecified errors can be exploited to cause a stack overflow and execute arbitrary code.Some unspecified errors can be exploited to...
Last Update Date: 11 Sep 2013 14:33 Release Date: 11 Sep 2013 6011 Views

RISK: Medium Risk

Medium Risk

GOM Player Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in GOM Player, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an unspecified error and can be exploited to cause a buffer overflow.
Last Update Date: 11 Sep 2013 10:07 Release Date: 11 Sep 2013 6267 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server for z/OS JAX-WS WS-Security Vulnerability

A vulnerability has been identified in IBM WebSphere Application Server for z/OS, which is caused due to an unspecified error when using JAX-WS WS-Security configured for XML Digital Signature. No further information is currently available.
Last Update Date: 6 Sep 2013 09:52 Release Date: 6 Sep 2013 6155 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious people to conduct cross-site scripting attacks, cross-site request forgery attacks, cause denial of service conditions or compromise a vulnerable system.
Last Update Date: 5 Sep 2013 Release Date: 30 Aug 2013 6195 Views

RISK: High Risk

High Risk

Polaris Products DOCX Buffer Overflow Vulnerability

A DOCX buffer overflow vulnerability has been identified in Polaris Office for Android and Samsung Galaxy S4 Polaris Viewer, which can be exploited by malicious people to compromise a vulnerable device.   Note: Vendor patch is currenlty unavailable.
Last Update Date: 5 Sep 2013 09:46 Release Date: 5 Sep 2013 6161 Views

RISK: Medium Risk

Medium Risk

cPanel Multiple Vulnerabilities

Multiple vulnerabilities have been identified in cPanel, which can be exploited by malicious, local users to disclose potentially sensitive information, bypass certain security restrictions, manipulate certain data, and gain escalated privileges and by malicious users to conduct script insertion attacks, bypass certain security restrictions...
Last Update Date: 4 Sep 2013 09:49 Release Date: 4 Sep 2013 6201 Views

RISK: Medium Risk

Medium Risk

Asterisk Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Asterisk. A remote user can cause denial of service conditions. A remote user can send a SIP ACK with SDP that is received after the channel has been terminated to cause the target service to crash. A remote user can send...
Last Update Date: 29 Aug 2013 09:35 Release Date: 29 Aug 2013 6193 Views

RISK: Medium Risk

Medium Risk

Spring Framework Multiple XML Entity References Information Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in Spring Framework, which can be exploited by malicious people to disclose potentially sensitive information. The vulnerabilities are caused due to an error when processing XML data, which can be exploited to e.g. disclose contents of certain local files...
Last Update Date: 28 Aug 2013 09:29 Release Date: 28 Aug 2013 6094 Views

RISK: Medium Risk

Medium Risk

RealPlayer Multiple Vulnerabilities

Two vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.An error when handling filenames in RMP can be exploited to cause a stack-based buffer overflow.An error when parsing RealMedia files can be...
Last Update Date: 27 Aug 2013 10:16 Release Date: 27 Aug 2013 6179 Views

RISK: Medium Risk

Medium Risk

VMware Workstation and Player vmware-mount Command Vulnerability

A vulnerability has been identified in VMware Workstation and Player on Debian-based systems. which can be exploited by local user on the host operating system can obtain root privileges on the target system.On Debian-based host systens, a local user can exploit a...
Last Update Date: 26 Aug 2013 10:26 Release Date: 26 Aug 2013 6131 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Unified Communications Manager. A remote authenticated user can execute arbitrary code on the target system, and cause denial of service conditions. A remote user can send a large number of TCP connections to ports 5060 or 5061 to trigger a...
Last Update Date: 22 Aug 2013 10:10 Release Date: 22 Aug 2013 6066 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious, local users to disclose potentially sensitive information and by malicious people to compromise a user's system. An error exists when handling file paths. The application creates certain shared memory files...
Last Update Date: 22 Aug 2013 09:57 Release Date: 22 Aug 2013 6155 Views

RISK: High Risk

High Risk

RedHat Linux Kernel Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RedHat Linux Kernal, which can be exploited by malicious people to cause root compromise, access privileged data, and denial of service.A flaw was found in the way the Linux kernel's Stream Control Transmission Protocol (...
Last Update Date: 21 Aug 2013 18:50 Release Date: 21 Aug 2013 6356 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service).A NULL pointer dereference error within the "decode_frame()" function (libavcodec/dxa.c) can be exploited to cause a crash....
Last Update Date: 21 Aug 2013 18:49 Release Date: 21 Aug 2013 6056 Views

RISK: High Risk

High Risk

IBM HTTP Server Multiple Vulnerabilities

The vulnerabilities are identified in IBM HTTP Server versions 8... through 8...6, which can be exploited by malicious people to disclose certain sensitive information, cause a DoS (Denial of Service), and compromise a vulnerable system...
Last Update Date: 21 Aug 2013 18:38 Release Date: 21 Aug 2013 6304 Views

RISK: Medium Risk

Medium Risk

PHP SSL Client Certificate Verification and Session Fixation Vulnerabilities

Multiple vulnerabilities have been identified in PHP, which can be exploited by malicious people to conduct spoofing and session hijacking attacks.
Last Update Date: 20 Aug 2013 12:43 Release Date: 20 Aug 2013 6235 Views

RISK: High Risk

High Risk

Avant Browser Rendering Engines Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Avant Browser, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct spoofing attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system.   For...
Last Update Date: 20 Aug 2013 12:41 Release Date: 20 Aug 2013 6620 Views

RISK: High Risk

High Risk

IBM Notes / Domino Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Notes and Domino, which can be exploited by malicious, local users to disclose certain sensitive data, manipulate certain data, and gain escalated privileges and by malicious people to conduct spoofing attacks, disclose certain sensitive information, manipulate certain...
Last Update Date: 20 Aug 2013 12:38 Release Date: 20 Aug 2013 6700 Views

RISK: High Risk

High Risk

Kingsoft Writer 2012 WPS file Buffer Overflow Vulnerability

A vulnerability has been identified in Kingsoft Writer 2012, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error in when handling font names and can be exploited to cause a stack-based buffer...
Last Update Date: 19 Aug 2013 09:39 Release Date: 19 Aug 2013 6268 Views

RISK: Medium Risk

Medium Risk

HP Service Manager / Service Center Unspecified Security Bypass Vulnerability

A vulnerability has been identified in HP Service Manager and Service Center, which can be exploited by malicious people to bypass certain security restrictions.  The vulnerability is caused due to an unspecified error.
Last Update Date: 16 Aug 2013 09:37 Release Date: 16 Aug 2013 6057 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server mod_rewrite Arbitrary Command Execution Vulnerability

IBM has acknowledged a vulnerability in IBM HTTP Server, which can be exploited by malicious people to compromise a vulnerable system.
Last Update Date: 14 Aug 2013 16:16 Release Date: 14 Aug 2013 6042 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Server AD FS Information Disclosure Vulnerability

An information disclosure vulnerability exists in Active Directory Federation Services (AD FS) that could allow the unintentional disclosure of account information.
Last Update Date: 14 Aug 2013 15:52 Release Date: 14 Aug 2013 6062 Views

RISK: High Risk

High Risk

Microsoft Windows ICMPv6 Vulnerability

A denial of service vulnerability exists in the Windows TCP/IP stack that could cause the target system to stop responding until restarted. The vulnerability is caused when the TCP/IP stack does not properly allocate memory for incoming ICMPv6 packets.
Last Update Date: 14 Aug 2013 15:51 Release Date: 14 Aug 2013 6178 Views

RISK: High Risk

High Risk

Microsoft Windows NAT Denial of Service Vulnerability

A denial of service vulnerability exists in the Windows NAT Driver that could cause the target system to stop responding until restarted.
Last Update Date: 14 Aug 2013 15:50 Release Date: 14 Aug 2013 6055 Views

RISK: High Risk

High Risk

ThinkVantage Access Connections Insecure Library Loading Vulnerability

A vulnerability has been discovered in ThinkVantage Access Connections, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to the application loading libraries (mfc71enu.dll and mfc71loc.dll) in an insecure manner. This...
Last Update Date: 14 Aug 2013 15:49 Release Date: 14 Aug 2013 6031 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ASLR Security Feature Bypass Vulnerability

A security feature vulnerability exists in Windows due to improper implementation of Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, most likely during or in the course of exploiting a remote code execution vulnerability. The attacker could...
Last Update Date: 14 Aug 2013 15:48 Release Date: 14 Aug 2013 6254 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Procedure Call Vulnerability

An elevation of privilege vulnerability exists in the way that Windows handles asynchronous RPC requests. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Aug 2013 15:46 Release Date: 14 Aug 2013 6137 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Oracle Outside In Contains Multiple Exploitable Vulnerabilities

Two of the three vulnerabilities addressed in this bulletin, CVE-2013-2393 and CVE-2013-3776, exist in Exchange Server 2007, Exchange Server 2010, and Exchange Server 2013 through the WebReady Document Viewing feature. The vulnerabilities could allow remote code execution...
Last Update Date: 14 Aug 2013 15:44 Release Date: 14 Aug 2013 6111 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Uniscribe Font Parsing Engine Memory Corruption Vulnerability

A remote code execution vulnerability exists in the Unicode Scripts Processor included in affected versions of Microsoft Windows. An attacker who successfully exploited this vulnerability could run arbitrary code as the current user.
Last Update Date: 14 Aug 2013 15:42 Release Date: 14 Aug 2013 6066 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Vulnerabilities

Internet Explorer Process Integrity Level Assignment VulnerabilityAn elevation of privilege vulnerability exists in the way that Internet Explorer handles process integrity level assignment in specific cases. An attacker who successfully exploited this vulnerability could allow arbitrary code to execute with elevated privileges.EUC-JP Character Encoding VulnerabilityAn...
Last Update Date: 14 Aug 2013 15:41 Release Date: 14 Aug 2013 6096 Views

RISK: High Risk

High Risk

HP, H3C and 3COM Products OSPF Vulnerability

A vulnerability has been identified in various HP networking products including H3C and 3COM routers and switches which can be exploited by a remote unauthenticated user to cause denial of service conditions or obtain potentially sensitive information.  A remote authenticated user can send specially crafted Open Shortest Path First...
Last Update Date: 9 Aug 2013 12:06 Release Date: 9 Aug 2013 6249 Views

RISK: Medium Risk

Medium Risk

HP LaserJet Pro Printers Unauthorised Access Vulnerability

A vulnerability has been identified in certain HP LaserJet Pro printers, which could be exploited remotely to gain unauthorized access to data.
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6341 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Mozilla Firefox, Seamonkey, and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, cause denial of service conditions, and conduct cross-site scripting attacks. A local user can obtain...
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6296 Views

RISK: Medium Risk

Medium Risk

ownCloud Cross-Site Scripting and Security Bypass Vulnerabilities

Two vulnerabilities have been identified in ownCloud, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions. An error within "user_webdavauth" can be exploited to bypass authorisation and gain access to otherwise restricted functionality. Certain unspecified...
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6069 Views

RISK: Medium Risk

Medium Risk

Tor Browser Bundle "onreadystatechange" Event Handling Code Execution Vulnerability

A vulnerability has been identified in Tor Browser Bundle, which can be exploited by malicious people to compromise a user's system. An error exists when handling the "onreadystatechange" event and reloading pages.
Last Update Date: 8 Aug 2013 Release Date: 7 Aug 2013 6243 Views

RISK: High Risk

High Risk

Cisco TelePresence System Default Credentials Vulnerability

A vulnerability has been identified in Cisco TelePresence. A remote user can gain full control of the target system.   The web server contains an administrative user account with default credentials. A remote user can access the system using these authentication credentials.   Note: Vendor patch is...
Last Update Date: 8 Aug 2013 10:02 Release Date: 8 Aug 2013 6125 Views

RISK: Medium Risk

Medium Risk

PuTTY Multiple Vulnerabilities

 Vulnerabilities has been identified in PuTTY, which can be exploited by malicious people to potentially compromise a user's system. The vulnerabilities are caused due to some integer overflow errors when handling the SSH handshake and can be exploited to cause heap-based buffer overflows...
Last Update Date: 6 Aug 2013 10:26 Release Date: 6 Aug 2013 6278 Views

RISK: Medium Risk

Medium Risk

Joomla! Arbitrary File Upload Vulnerability

A vulnerability has been identified in Joomla!, which can be exploited by malicious users to compromise a vulnerable system.The vulnerability is caused due to the administrator/components/com_media/helpers/media.php script improperly validating the extension of an uploaded file. This...
Last Update Date: 5 Aug 2013 11:44 Release Date: 5 Aug 2013 6911 Views

RISK: Medium Risk

Medium Risk

Windows Phone PEAP-MS-CHAPv2 Authentication Protocol Vulnerability

A vulnerability has been identified in the PEAP-MS-CHAPv2 authentication protocol used by Windows Phone, which can be exploited by remote user can obtain authentication information.The Protected Extensible Authentication Protocol with Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAPv2...
Last Update Date: 5 Aug 2013 11:32 Release Date: 5 Aug 2013 6592 Views

RISK: Medium Risk

Medium Risk

VMware ESX/ESXi Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX/ESXi Server, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).
Last Update Date: 2 Aug 2013 18:51 Release Date: 2 Aug 2013 6233 Views

RISK: High Risk

High Risk

McAfee Firewall Enterprise BIND RDATA Handling Assertion Failure Denial of Service Vulnerability

A vulnerability has been identified in McAfee Firewall Enterprise, which can be exploited by malicious people to cause a DoS (Denial of Service).   For details, please refer to SA13073005.
Last Update Date: 2 Aug 2013 18:40 Release Date: 2 Aug 2013 6234 Views

RISK: Medium Risk

Medium Risk

Cisco Products Command Injection and Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious users and malicious people to compromise a vulnerable system.
Last Update Date: 2 Aug 2013 18:39 Release Date: 2 Aug 2013 6307 Views

RISK: High Risk

High Risk

Cisco Products OSPF Vulnerability

A vulnerability has been identified in various Cisco products, which can be exploited by an unauthenticated attacker to take full control of the OSPF Autonomous System (AS) domain routing table, blackhole traffic, and intercept traffic.  The attacker could trigger this vulnerability by injecting crafted...
Last Update Date: 2 Aug 2013 18:35 Release Date: 2 Aug 2013 6499 Views