Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

OpenOffice.org PLCF and XML Data Parsing Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice.org, which can be exploited by malicious people to compromise a user's system.An unspecified error when handling PLCF (Plex of Character Positions in File) data within DOC files can be exploited to cause memory corruption...
Last Update Date: 1 Aug 2013 Release Date: 29 Jul 2013 6207 Views

RISK: High Risk

High Risk

Symantec Web Gateway Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec Web Gateway. which can be exploited by remote user conduct cross-site scripting attacks, conduct cross-site request forgery attacks, inject SQL commands and compromise a vulnerable system.A remote user with access to the Symantec Web...
Last Update Date: 1 Aug 2013 Release Date: 29 Jul 2013 6216 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. An error within frame handling can be exploited to bypass origin policies.A type confusion error exists within V8....
Last Update Date: 1 Aug 2013 09:49 Release Date: 1 Aug 2013 6354 Views

RISK: Medium Risk

Medium Risk

TrustGo Antivirus & Mobile Security Denial-of-service Vulnerability

A vulnerability was identified in TrustGo Antivirus & Mobile Security, which can be exploited by malicious application to cause denial-of-service. TrustGo Antivirus & Mobile Security versions 1.2.7 through 1.3.5 crash if an intent is...
Last Update Date: 31 Jul 2013 09:09 Release Date: 31 Jul 2013 6588 Views

RISK: Medium Risk

Medium Risk

Adobe Digital Editions Memory Corruption Vulnerability

A vulnerability was identified in Adobe Digital Editions. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a memory corruption error...
Last Update Date: 31 Jul 2013 09:07 Release Date: 31 Jul 2013 6851 Views

RISK: High Risk

High Risk

ISC BIND RDATA Handling Assertion Failure Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).   The vulnerability is caused due to an error when parsing RDATA within a DNS query and can be exploited to trigger a REQUIRE assertion and...
Last Update Date: 30 Jul 2013 14:12 Release Date: 30 Jul 2013 6362 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Commerce Multiple Vulnerabilities

A vulnerability has been identified in IBM Websphere Commerce, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error within REST services, which can be exploited to run REST services as another user with a valid session...
Last Update Date: 30 Jul 2013 14:10 Release Date: 30 Jul 2013 6192 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server Multiple Vulnerabilities

Two vulnerabilities have been reported in Apache HTTP Server, which can be exploited by malicious people to disclose potentially sensitive information and compromise a vulnerable system.
Last Update Date: 30 Jul 2013 14:05 Release Date: 30 Jul 2013 6222 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service). An error exists in the DCP ETSI dissector. An error in the P1 dissector can be exploited to cause a crash. Some errors in...
Last Update Date: 30 Jul 2013 12:41 Release Date: 30 Jul 2013 6046 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin Multiple Vulnerabilities

Multiple vulnerabilities have been identified in phpMyAdmin, which can be exploited by malicious users to conduct script insertion and SQL injection attacks. Input passed via the "User", "Host", "db", and "Command" parameters related to the Status Monitor view is not properly sanitised...
Last Update Date: 30 Jul 2013 12:39 Release Date: 30 Jul 2013 6285 Views

RISK: High Risk

High Risk

IBM Tivoli Endpoint Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Tivoli Endpoint Manager for Remote Control, which can be exploited by malicious, local users to disclose certain sensitive information and gain escalated privileges and by malicious people to disclose potentially sensitive information, conduct spoofing attacks, bypass certain security restrictions...
Last Update Date: 26 Jul 2013 10:17 Release Date: 26 Jul 2013 6898 Views

RISK: High Risk

High Risk

Apache HTTP Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by attackers to cause a DoS (Denial of Service).Sending a MERGE request against a URI handled by mod_dav_svn with the source href (sent as part of the request body as XML...
Last Update Date: 24 Jul 2013 12:43 Release Date: 24 Jul 2013 6391 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Message Broker Java Multiple Vulnerabilities

IBM has acknowledged multiple vulnerabilities in IBM WebSphere Message Broker, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable...
Last Update Date: 24 Jul 2013 12:43 Release Date: 24 Jul 2013 6197 Views

RISK: Medium Risk

Medium Risk

Symantec Encryption Management Server Email Attachments Script Insertion Vulnerability

A vulnerability has been identified in Symantec Encryption Management Server, which can be exploited by malicious users to conduct script insertion attacks. Certain unspecified input related to encrypted email attachments is not properly sanitised within the Web Email Protection component before being used. This can be exploited...
Last Update Date: 24 Jul 2013 12:43 Release Date: 24 Jul 2013 6366 Views

RISK: Medium Risk

Medium Risk

HP System Management Homepage Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP System Management Homepage, which can be exploited by attackers to potentially gain escalated privileges, cause a DoS (Denial of Service), conduct cross-site scripting attacks, disclose certain sensitive information, hijack a user's session, ...
Last Update Date: 22 Jul 2013 10:54 Release Date: 22 Jul 2013 6575 Views

RISK: Medium Risk

Medium Risk

Apache Struts DefaultActionMapper Redirection and OGNL Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Apache Struts, which can be exploited by malicious people to conduct spoofing attacks and bypass certain security restrictions. Input passed via the "redirect:" and "redirectAction:" prefixing parameters is not properly verified in the DefaultActionMapper class (org....
Last Update Date: 19 Jul 2013 10:33 Release Date: 19 Jul 2013 7087 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by attackers to disclose certain sensitive information, manipulate certain data, gain escalated privileges, spoofing attacks, cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable...
Last Update Date: 19 Jul 2013 Release Date: 18 Jul 2013 6215 Views

RISK: High Risk

High Risk

Cisco Intrusion Prevention System Multiple Vulnerabilities

A vulnerability has been identified in Cisco Intrusion Prevention System, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 19 Jul 2013 10:11 Release Date: 19 Jul 2013 6190 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle products, which can be exploited by attackers to conduct denial of service, disclose sensitive information, manipulate information.
Last Update Date: 18 Jul 2013 11:53 Release Date: 18 Jul 2013 6297 Views

RISK: High Risk

High Risk

Oracle Database Multiple Vulnerabilities

Several vulnerabilities were identified in Oracle Database. A remote or remote authenticated user can execute arbitrary code on the target system. A remote authenticated user can partially access and modify data on the target system, and cause partial denial of service conditions. A local user can...
Last Update Date: 17 Jul 2013 12:59 Release Date: 17 Jul 2013 6230 Views

RISK: High Risk

High Risk

MySQL Multiple Vulnerabilities

Multiple vulnerabilities were identified in MySQL. A remote authenticated user can cause denial of service conditions. A remote user can cause partial denial of service conditions, and partially access and modify data on the target system.A remote authenticated user can exploit a flaw in the...
Last Update Date: 17 Jul 2013 12:58 Release Date: 17 Jul 2013 6328 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, where some have an unknown impact and others can be exploited by malicious people to cause a DoS (Denial of Service).A NULL pointer dereference error within the "decode_mb_info()" function (libavcodec/indeo4.c) can...
Last Update Date: 17 Jul 2013 12:57 Release Date: 17 Jul 2013 6179 Views

RISK: Medium Risk

Medium Risk

McAfee ePolicy Orchestrator Multiple Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities have been identified in McAfee ePolicy Orchestrator, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed via multiple parameters and scripts is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary...
Last Update Date: 17 Jul 2013 12:57 Release Date: 17 Jul 2013 6039 Views

RISK: Medium Risk

Medium Risk

F5 Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple F5 products, which can be exploited by malicious people to cause a DoS (Denial of Service), and compromise a user's system. BIND Recursive Lookup Two Denial of Service VulnerabilitiesThe vulnerability is caused due to a bundled...
Last Update Date: 16 Jul 2013 10:52 Release Date: 16 Jul 2013 6124 Views

RISK: Medium Risk

Medium Risk

Squid HTTP Header Port Number Handling Denial of Service Vulnerability

A vulnerability has been identified in Squid, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when handling port number values within the "Host" header of HTTP requests and can be exploited...
Last Update Date: 16 Jul 2013 10:50 Release Date: 16 Jul 2013 7692 Views

RISK: Medium Risk

Medium Risk

Linux Kernel fib6_add_rt2node() Router Advertisement Processing Denial of Service vulnerability

A vulnerability was identified in the Linux Kernel. A remote user can cause denial of service conditions. A remote router advertisement speaker can modify the advertised expiration in certain cases to trigger a flaw in fib6_add_rt2node() and cause the target system to crash.
Last Update Date: 16 Jul 2013 10:46 Release Date: 16 Jul 2013 6159 Views

RISK: Medium Risk

Medium Risk

PHP xml_parse_into_struct() Heap Overflow Vulnerability

A vulnerability was reported in PHP. A remote user can execute arbitrary code on the target system.  A remote user can send specially crafted nested XML to trigger a heap overflow in xml_parse_into_struct() and execute arbitrary code on the target system. The code will run with...
Last Update Date: 16 Jul 2013 10:46 Release Date: 16 Jul 2013 6149 Views

RISK: Medium Risk

Medium Risk

Juniper JunOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Juniper JUNOS.  which can be exploited by remote user can obtain potentially sensitive information, cause denial of service conditions or execute arbitrary code.A remote user can send specially crafted PIM packets when PIM and NAT are enabled on SRX devices...
Last Update Date: 15 Jul 2013 10:39 Release Date: 15 Jul 2013 6565 Views

RISK: High Risk

High Risk

Avant Browser Rendering Engines Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Avant Browser, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system.   For more information, please refer...
Last Update Date: 12 Jul 2013 12:07 Release Date: 12 Jul 2013 6249 Views

RISK: Medium Risk

Medium Risk

JBoss RichFaces Deserialization Vulnerability

A vulnerability has been identified in JBoss, which can be exploited by remote user to execute arbitrary code on the target system.  A remote user can send specially crafted data to trigger a flaw in the way RichFaces ResourceBuilderImpl handles deserialization and potentially execute arbitrary code on the...
Last Update Date: 12 Jul 2013 11:52 Release Date: 12 Jul 2013 7133 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products. which can be exploited by remote user to conduct cross-site scripting attacks or login to the target system.
Last Update Date: 12 Jul 2013 11:51 Release Date: 12 Jul 2013 6023 Views

RISK: Medium Risk

Medium Risk

HP Network Node Manager I (NNMi) Unspecified Vulnerability

A vulnerability has been identified in HP Network Node Manager I (NNMi), which can be exploited by remote user to partially access and modify data and cause partial denial of service conditions on the target system.
Last Update Date: 12 Jul 2013 11:51 Release Date: 12 Jul 2013 6341 Views

RISK: High Risk

High Risk

Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerabilities

TrueType Font Parsing VulnerabilityA remote code execution vulnerability exists in the way that affected components handle specially crafted TrueType font files. The vulnerability could allow remote code execution if a user opens a specially crafted TrueType font file. An attacker who successfully exploited this vulnerability could take complete...
Last Update Date: 10 Jul 2013 15:14 Release Date: 10 Jul 2013 6298 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities

Win32k Memory Allocation VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated privileges. Win32k Dereference VulnerabilityAn elevation of privilege vulnerability exists in the way that the...
Last Update Date: 10 Jul 2013 15:14 Release Date: 10 Jul 2013 6412 Views

RISK: Medium Risk

Medium Risk

Microsoft GDI+ Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that affected Windows components and other affected software handle specially crafted TrueType font files. The vulnerability could allow remote code execution if a user views shared content that embeds TrueType font files. An attacker who successfully exploited this vulnerability...
Last Update Date: 10 Jul 2013 15:14 Release Date: 10 Jul 2013 6206 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Vulnerabilities

Shift JIS Character Encoding VulnerabilityA cross-site-scripting (XSS) vulnerability exists in Internet Explorer that could allow information disclosure. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a user viewed the webpage. An attacker...
Last Update Date: 10 Jul 2013 15:14 Release Date: 10 Jul 2013 6159 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft DirectShow parses GIF image files. This vulnerability could allow remote code execution if a user opened a specially crafted GIF file. If a user is logged on with administrative user rights, an attacker who successfully exploited...
Last Update Date: 10 Jul 2013 15:13 Release Date: 10 Jul 2013 6323 Views

RISK: High Risk

High Risk

Microsoft Windows Media Format Runtime Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way Windows Media Format Runtime handles certain media files. This vulnerability could allow an attacker to execute arbitrary code if the attacker convinces a user to open a specially crafted media file. An attacker could then install programs; view...
Last Update Date: 10 Jul 2013 15:13 Release Date: 10 Jul 2013 6360 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows 7 Defender Improper Pathname Vulnerability

This is an elevation of privilege vulnerability. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take complete control of the system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Jul 2013 15:13 Release Date: 10 Jul 2013 6103 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multipule vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious, local users to disclose potentially sensitive data and by malicious people to bypass certain security restrictions, conduct spoofing attacks, disclose certain sensitive data, and...
Last Update Date: 10 Jul 2013 14:26 Release Date: 10 Jul 2013 6405 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system. An unspecified error can be exploited to cause a heap-based buffer overflow. An unspecified error can be exploited to cause memory corruption...
Last Update Date: 10 Jul 2013 14:25 Release Date: 10 Jul 2013 6194 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Unspecified Memory Corruption Vulnerability

A vulnerability has been reported in Adobe Shockwave Player, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an unspecified error and can be exploited to corrupt memory. Successful exploitation may allow execution of arbitrary code.
Last Update Date: 10 Jul 2013 14:25 Release Date: 10 Jul 2013 6138 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Multiple Vulnerabilities

Multiple vulnerability have been identified in Adobe ColdFusion, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an unspecified error and can be exploited to invoke public methods on ColdFusion Components (CFC) using WebSockets...
Last Update Date: 10 Jul 2013 14:25 Release Date: 10 Jul 2013 6165 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Community Edition Serialized Object Handling Vulnerability

A vulnerability has been identified in IBM WebSphere Application Server Community Edition, which can be exploited by malicious people to compromise a vulnerable system. The application bundles a vulnerable version of Geronimo.
Last Update Date: 10 Jul 2013 12:43 Release Date: 10 Jul 2013 6275 Views

RISK: High Risk

High Risk

VLC Media Player MKV Parsing Integer Overflow Vulnerability

A vulnerability has been identified in VLC Media Player , which can be exploited by malicious people to potentially compromise a user's system.   The vulnerability is caused due to an integer overflow error within the libmkv_plugin.dll module when parsing MKV files, which can be...
Last Update Date: 10 Jul 2013 12:43 Release Date: 10 Jul 2013 6667 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise an application using the library. An error within the "decode_subframe()" function (libavcodec/wmaprodec.c) can be exploited...
Last Update Date: 9 Jul 2013 11:25 Release Date: 9 Jul 2013 6467 Views

RISK: Medium Risk

Medium Risk

cPanel cpanellogd Multiple Vulnerabilities

Two vulnerabilities have been identified in cPanel, which can be exploited by malicious users to gain escalated privileges. Two unspecified errors exist within cpanellogd when creating an archive of the user domain's access logs in the user's home directory and can be exploited to...
Last Update Date: 9 Jul 2013 10:37 Release Date: 9 Jul 2013 6300 Views

RISK: High Risk

High Risk

Corel PDF Fusion Multiple Vulnerabilities

Two vulnerabilities have been identified in Corel PDF Fusion, which can be exploited by malicious people to compromise a user's system. The application loads a library (wintab32.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking...
Last Update Date: 9 Jul 2013 10:37 Release Date: 9 Jul 2013 6121 Views

RISK: High Risk

High Risk

IrfanView ANI File Processing Integer Overflow Vulnerability

A vulnerability has been identified in IrfanView, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error when parsing ANI images and can be exploited to cause a heap-based buffer overflow.
Last Update Date: 8 Jul 2013 09:53 Release Date: 8 Jul 2013 6174 Views

RISK: High Risk

High Risk

RealPlayer HTML Processing Denial of Service Vulnerability

A vulnerability has been identified in RealPlayer, which can be exploited by remote user to cause denial of service attack.  A remote user can create a specially crafted HTML that, when loaded by the target user, will cause the target user's application to consume...
Last Update Date: 5 Jul 2013 09:52 Release Date: 5 Jul 2013 6190 Views

RISK: Medium Risk

Medium Risk

Avant Browser Rendering Engines Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Avant Browser, where some have an unknown impact and others can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. For more information:SA13051510SA13060601
Last Update Date: 4 Jul 2013 08:56 Release Date: 4 Jul 2013 6271 Views

RISK: Medium Risk

Medium Risk

Lookout! Mobile Security Denial-of-service Vulnerability

A vulnerability has been identified in Lookout! Mobile Security, which can be exploited by malicious people to cause a denial-of-service attack. Lookout! Mobile Security (version 8.14.1-7fe5f1) crashes if an intent is sent to com...
Last Update Date: 3 Jul 2013 12:44 Release Date: 3 Jul 2013 6277 Views

RISK: Medium Risk

Medium Risk

Symantec Security Information Manager Console Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec Security Information Manager, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to disclose sensitive information and conduct cross-site scripting attacks.Certain unspecified input passed to the Java Console is not properly...
Last Update Date: 3 Jul 2013 12:39 Release Date: 3 Jul 2013 6439 Views

RISK: High Risk

High Risk

Apple OS X QuickTime Buffer Overflows Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the...
Last Update Date: 3 Jul 2013 12:39 Release Date: 3 Jul 2013 6324 Views

RISK: High Risk

High Risk

Kingsoft Spreadsheets Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Kingsoft Spreadsheets, which can be exploited by malicious people to potentially compromise a user's system.   Some errors within the etxrw.dll module when processing spreadsheet files can be exploited to cause a heap-based buffer overflow...
Last Update Date: 27 Jun 2013 11:12 Release Date: 27 Jun 2013 6413 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox / Thunderbird, which can be exploited by attackers to conduct cross site scripting, elevation of privilege, sensitive information disclosure and remote code execution.
Last Update Date: 27 Jun 2013 Release Date: 26 Jun 2013 6435 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Email Security Appliance, Web Security Appliance, ASA Next-Generation Firewall and Content Security Management Appliance, which can be exploited by attackers to conduct denial of service and remote code execution.
Last Update Date: 27 Jun 2013 10:58 Release Date: 27 Jun 2013 6329 Views

RISK: Medium Risk

Medium Risk

WordPress Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress. A remote authenticated user can obtain elevated privileges on the target application, conduct cross-site scripting and request forgery attacks, and determine the upload path. A remote user can conduct server-side request forgery (SSRF) ...
Last Update Date: 26 Jun 2013 10:56 Release Date: 26 Jun 2013 6298 Views

RISK: Medium Risk

Medium Risk

cURL Heap Overflow Vulnerability

A vulnerability has been identified in libcurl. A remote user can execute arbitrary code on the target system. A remote user can send specially crafted data to trigger a heap overflow in curl_easy_unescape() and execute arbitrary code on the target system. The code will run with...
Last Update Date: 25 Jun 2013 10:17 Release Date: 25 Jun 2013 6200 Views

RISK: Medium Risk

Medium Risk

Cisco TelePresence Systems Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco TelePresence Systems products, which can be exploited by malicious people to compromise a vulnerable system or cause a DoS (Denial of Service).
Last Update Date: 21 Jun 2013 10:09 Release Date: 21 Jun 2013 6233 Views

RISK: Medium Risk

Medium Risk

VLC Media Player Unspecified Vulnerabilities

Multiple vulnerabilities have been identified in VLC Media Player. The vulnerabilities are caused due to unspecified errors. No further information is currently available.
Last Update Date: 21 Jun 2013 10:05 Release Date: 21 Jun 2013 6335 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Commerce Information Disclosure Vulnerability

A vulnerability has been identified in IBM WebSphere Commerce, which can be exploited by a remote user to obtain potentially sensitive information. A remote user with the ability to monitor network communications can conduct an oracle padding attack against the 'krypto' parameter to decrypt user data...
Last Update Date: 21 Jun 2013 10:01 Release Date: 21 Jun 2013 6279 Views

RISK: Medium Risk

Medium Risk

Symantec Endpoint Protection Manager Buffer Overflow Vulnerability

A vulnerability has been identified  in Symantec Endpoint Protection Manager. A remote user can execute arbitrary code on the target system.   A remote user can send specially crafted data to trigger a buffer overflow in 'Secars.dll' and execute arbitrary code on...
Last Update Date: 20 Jun 2013 19:04 Release Date: 20 Jun 2013 6086 Views

RISK: High Risk

High Risk

Cisco ASA CX TCP Traffic Denial of Service Vulnerability

A vulnerability processing TCP traffic has been identified on Cisco ASA CX, which could allow an unauthenticated, remote attacker to cause a reload of the affected device.   The vulnerability is due to invalid parsing of TCP packet data forwarded to Cisco ASA CX by the Cisco ASA...
Last Update Date: 20 Jun 2013 19:04 Release Date: 20 Jun 2013 6245 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Java Vulnerability

Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious, local users to disclose certain sensitive information, manipulate certain data, and gain escalated privileges and by malicious people to conduct spoofing...
Last Update Date: 20 Jun 2013 19:03 Release Date: 20 Jun 2013 6236 Views

RISK: Medium Risk

Medium Risk

Apache XML Security Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache XML Security, which can be exploited by malicious people to conduct spoofing attacks, cause a DoS (Denial of Service), and compromise an application using the library.An error when processing certain XPointer expressions within the XML Signature Reference...
Last Update Date: 19 Jun 2013 10:16 Release Date: 19 Jun 2013 6181 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities were identified in Oracle Java. A remote user can cause arbitrary code to be executed on the target user's system. A local user can obtain elevated privileges on the target system. A remote or local user can cause denial of service conditions. ...
Last Update Date: 19 Jun 2013 10:08 Release Date: 19 Jun 2013 6471 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WebSphere Application Server, which can be exploited by malicious people to execute Arbitrary Code/Commands, access privileged data, cross-site scripting, unauthorised access, and access confidential data.
Last Update Date: 18 Jun 2013 10:41 Release Date: 18 Jun 2013 6281 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in wireshark which can be exploited by malicious people to causedenial of service or the execution of arbitrary code.
Last Update Date: 18 Jun 2013 10:37 Release Date: 18 Jun 2013 6191 Views

RISK: Medium Risk

Medium Risk

Cisco ASA CX Denial of Service Vulnerability

A vulnerability was identified in Cisco ASA CX. A remote user can cause denial of service conditions. The Cisco ASA CX does not properly parse TCP packet data forwarded by the Cisco ASA. A remote user can send specially crafted TCP data to cause the target device...
Last Update Date: 18 Jun 2013 10:35 Release Date: 18 Jun 2013 6224 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.An error within the "format_line()" function (libavutil/log.c) can be...
Last Update Date: 17 Jun 2013 16:56 Release Date: 17 Jun 2013 6497 Views

RISK: Medium Risk

Medium Risk

Avira AntiVir PDF Processing Vulnerability

A vulnerability had identified in Avira AntiVir. A remote user can cause denial of service conditions.A remote user can send a specially crafted PDF file to cause the target antivirus engine to enter an infinite loop.
Last Update Date: 14 Jun 2013 12:24 Release Date: 14 Jun 2013 6345 Views

RISK: Medium Risk

Medium Risk

BlackBerry 10 OS and BlackBerry PlayBook OS Adobe Flash Player Vulnerability

A vulnerability has been identified in BlackBerry 10 OS and BlackBerry PlayBook OS, which can be exploited by malicious people to compromise a user's device.The vulnerability is caused due to a vulnerable bundled version of Adobe Flash Player.
Last Update Date: 14 Jun 2013 12:23 Release Date: 14 Jun 2013 6985 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Print Spooler Vulnerability

An elevation of privilege vulnerability exists in the way that Microsoft Windows Print Spooler handles memory when a printer is deleted.
Last Update Date: 14 Jun 2013 Release Date: 13 Jun 2013 6254 Views

RISK: Medium Risk

Medium Risk

VMware vCenter Chargeback Manager File Upload Handling Vulnerability

A vulnerability has been identified in VMware vCenter Chargeback Manager, which can be exploited by malicious people to compromise a vulnerable system.   The vulnerability is caused due to an unspecified error when handling file uploads and can be exploited to execute code.
Last Update Date: 13 Jun 2013 19:27 Release Date: 13 Jun 2013 6260 Views

RISK: Medium Risk

Medium Risk

McAfee Email and Web Security Appliance / Email Gateway ISC BIND Vulnerability

A vulnerability has been identified in McAfee Email and Web Security Appliance and McAfee Email Gateway, which can be exploited by malicious people to cause a DoS (Denial of Service).   For more information, please refer to SA13060604.
Last Update Date: 13 Jun 2013 19:27 Release Date: 13 Jun 2013 6279 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Memory Corruption Vulnerability

A vulnerability has been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to cause memory corruption.
Last Update Date: 13 Jun 2013 19:26 Release Date: 13 Jun 2013 6759 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office parses specially crafted Office files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 13 Jun 2013 19:26 Release Date: 13 Jun 2013 6267 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Integer Overflow Vulnerability

A denial of service vulnerability exists in the way that the Windows TCP/IP driver improperly handles packets during TCP connection. An attacker who successfully exploited this vulnerability could cause the target system to stop responding.
Last Update Date: 13 Jun 2013 19:26 Release Date: 13 Jun 2013 6515 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could disclose information from kernel addresses.
Last Update Date: 13 Jun 2013 19:26 Release Date: 13 Jun 2013 6181 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

A remote code execution vulnerability exists when Internet Explorer improperly processes script while debugging a webpage. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a...
Last Update Date: 13 Jun 2013 19:26 Release Date: 13 Jun 2013 6182 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. An error in the CAPWAP dissector (dissectors/packet-capwap.c) can be exploited to...
Last Update Date: 11 Jun 2013 10:12 Release Date: 11 Jun 2013 6233 Views

RISK: High Risk

High Risk

Cisco IOS XR SNMP Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by a remote user to cause denial of service conditions.  A remote user can send a large number of UDP packets to SNMP port 162 to trigger a memory leak in the SNMP process and...
Last Update Date: 10 Jun 2013 10:26 Release Date: 10 Jun 2013 6467 Views

RISK: Medium Risk

Medium Risk

PHP php_quot_print_encode() Buffer Overflow Vulnerability

A vulnerability has been identified in PHP, which can be exploited by malicious people to compromise a vulnerable system.  The vulnerability is caused due to an error within the "php_quot_print_encode()" function (ext/standard/quot_print.c) when parsing passed strings, which...
Last Update Date: 10 Jun 2013 10:25 Release Date: 10 Jun 2013 6410 Views

RISK: High Risk

High Risk

Parallels Plesk Panel Arbitrary PHP Code Execution Vulnerability

A vulnerability has been identified in Parallels Plesk Panel, which can be exploited by malicious people to compromise a vulnerable system.  The vulnerability is caused due to an unspecified error and can be exploited to execute arbitrary PHP code.   Successful exploitation requires a ScriptAlias for the php...
Last Update Date: 10 Jun 2013 Release Date: 7 Jun 2013 6658 Views

RISK: Medium Risk

Medium Risk

Symantec Web Gateway `l´ Cross-Site Scripting Vulnerability

A vulnerability has been identified in Symantec Web Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks.   Input passed via the "l" parameter to spywall/timer.php is not properly sanitised before being returned to the user. ...
Last Update Date: 7 Jun 2013 Release Date: 8 May 2012 7508 Views

RISK: High Risk

High Risk

PHP com_print_typeinfo Remote Code Execution Vulnerability

A vulnerability has been identified in PHP, which can be exploited by malicious people to compromise a vulnerable system. It is due to the vulnerability in the com_print_typeinfo function. The php engine needs to execute the malicious code, which can include any shellcode like the the...
Last Update Date: 7 Jun 2013 Release Date: 22 May 2012 9234 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Facebook Plugin Insecure Library Loading Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system.  The bundled Facebook plug-in (facebook_plugin.fpi) loads libraries (e.g. dwmapi.dll) in an insecure manner...
Last Update Date: 7 Jun 2013 Release Date: 24 Aug 2012 7513 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Meetings Server Information Disclosure Vulnerability

A vulnerability has been identified in Cisco WebEx Meetings Server, which can be exploited by malicious people to potentially disclose sensitive information.  The vulnerability is caused due to an error when authenticating some user requests, which can be exploited to disclose event passwords and host keys.
Last Update Date: 7 Jun 2013 10:17 Release Date: 7 Jun 2013 6379 Views

RISK: Medium Risk

Medium Risk

IBM InfoSphere Information Server Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM InfoSphere Information Server, which can be exploited by malicious, local users to disclose potentially sensitive information and by malicious people to disclose certain sensitive information, manipulate certain data, and cause a DoS (Denial of Service).  The application...
Last Update Date: 7 Jun 2013 10:17 Release Date: 7 Jun 2013 6406 Views

RISK: High Risk

High Risk

ISC BIND Recursive Query Handling Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).   The vulnerability is caused due to an error when handling recursive query for zones, which can be exploited to cause a crash.
Last Update Date: 7 Jun 2013 Release Date: 6 Jun 2013 6510 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. Some vulnerabilities are caused due to a bundled vulnerable version of...
Last Update Date: 7 Jun 2013 Release Date: 6 Jun 2013 6321 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X. A remote user can execute arbitrary code on the target system. A remote authenticated user can write files outside of the target SMB directory. A local user can bypass security restrictions. A local user with access to...
Last Update Date: 6 Jun 2013 18:55 Release Date: 6 Jun 2013 6294 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. An unspecified error can be exploited to pass a bad handle to renderer. An unspecified error within dev tools API, Skia GPU handling and...
Last Update Date: 6 Jun 2013 18:55 Release Date: 6 Jun 2013 6478 Views

RISK: Medium Risk

Medium Risk

HP Data Protector Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Data Protector, which can be exploited by malicious people to compromise a vulnerable system. The vulnerabilities are caused due to unspecified errors.
Last Update Date: 5 Jun 2013 10:09 Release Date: 5 Jun 2013 6428 Views

RISK: Medium Risk

Medium Risk

Linux Kernel iSCSI Heap Overflow Vulnerability

A vulnerability was identified in the Linux Kernel. A remote user can execute arbitrary code on the target system. On systems with an iSCSI target configured and listening on the network, a remote user can send specially crafted data to trigger a buffer overflow and execute arbitrary...
Last Update Date: 4 Jun 2013 10:22 Release Date: 4 Jun 2013 6475 Views

RISK: Medium Risk

Medium Risk

JBoss Enterprise Application Platform Multiple Vulnerabilities

Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform. XML encryption backwards compatibility attacks were found against various frameworks, including Apache CXF. An attacker could force a server to use insecure, legacy cryptosystems, even when secure cryptosystems were enabled on endpoints...
Last Update Date: 31 May 2013 Release Date: 30 May 2013 6317 Views

RISK: Medium Risk

Medium Risk

Splunk Web Cross-Site Scripting Vulnerabilty

A vulnerability was identified in Splunk Web, which can be exploited by a remote user to conduct cross-site scripting attacks.
Last Update Date: 31 May 2013 16:59 Release Date: 31 May 2013 6369 Views

RISK: High Risk

High Risk

Cisco NX-OS Nexus 1000v Multiple Vulnerabilies

Multiple vulnerabilities have been identified in the Cisco Nexus 1000v, which can be exploited by a remote user to monitor or inject traffic, gain control of a target system, bypass security restrictions or cause denial of service conditions.   NOTE: Currently, there is no patch...
Last Update Date: 31 May 2013 16:56 Release Date: 31 May 2013 6352 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server mod_rewrite Vulnerability

A vulnerability has been identified in Apache HTTP Server, which can be exploited by malicious people to compromise a vulnerable system.  The "do_rewritelog()" function (modules/mappers/mod_rewrite.c) does not properly handle certain escape sequences when writing to the log file...
Last Update Date: 31 May 2013 16:52 Release Date: 31 May 2013 6783 Views