Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

IBM WebSphere Portal HTTP Response Splitting Vulnerability

A vulnerability has been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct HTTP response splitting attacks.  Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers, which will...
Last Update Date: 31 May 2013 16:50 Release Date: 31 May 2013 6464 Views

RISK: High Risk

High Risk

GnuTLS TLS Record Decoding Denial of Service Vulnerability

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an out-of-bounds read error within the "_gnutls_ciphertext2compressed()" function in lib/gnutls_cipher.c...
Last Update Date: 31 May 2013 16:47 Release Date: 31 May 2013 6255 Views

RISK: High Risk

High Risk

IBM Products OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Cloudburst and IBM Service Delivery Manager, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and potentially compromise a vulnerable system...
Last Update Date: 31 May 2013 16:44 Release Date: 31 May 2013 6432 Views

RISK: High Risk

High Risk

IrfanView FlashPix PlugIn FPX Processing Integer Overflow Vulnerability

A vulnerability has been identified in the FlashPix PlugIn for IrfanView, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow error within the Fpx.dll module when processing sections of Summary Information Property...
Last Update Date: 31 May 2013 16:40 Release Date: 31 May 2013 6405 Views

RISK: Medium Risk

Medium Risk

HP-UX Directory Server Password Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Directory Server, which can be exploited by remote authenticated user or  local user to view passwords. A local user can access the plaintext password in certain cases. A remote authenticated user can view the password for a...
Last Update Date: 29 May 2013 11:52 Release Date: 29 May 2013 6255 Views

RISK: Medium Risk

Medium Risk

Apache Struts OGNL Expression Injection Vulnerability

A vulnerability has been identified in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error when handling the "includeParams" attribute, which can be exploited to modify server-side objects and e...
Last Update Date: 29 May 2013 Release Date: 28 May 2013 6817 Views

RISK: High Risk

High Risk

Cisco IOS XR SNMP UDP Packets Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when managing allocated memory within the SNMP process and can be exploited to e.g...
Last Update Date: 28 May 2013 10:10 Release Date: 28 May 2013 6591 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system. A use-after-free...
Last Update Date: 23 May 2013 11:40 Release Date: 23 May 2013 6194 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified which can be exploited by malicious users to execute arbitrary code and cause Denial of Service condition via specially crafted files.
Last Update Date: 23 May 2013 10:28 Release Date: 23 May 2013 6285 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).   An error in the RELOAD dissector (dissectors/packet-reload.c) can be exploited to trigger infinite loops and consume CPU resources...
Last Update Date: 21 May 2013 10:14 Release Date: 21 May 2013 6620 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by malicious people to conduct spoofing attacks and compromise a user's system.The application does not properly validate SSL server certificates, which can be exploited to conduct Man-in-the-...
Last Update Date: 20 May 2013 10:45 Release Date: 20 May 2013 6424 Views

RISK: Medium Risk

Medium Risk

BlackBerry Tablet OS Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry Tablet OS, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
Last Update Date: 20 May 2013 10:24 Release Date: 20 May 2013 6251 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Cisco Products, which can be exploited by remote users to cause denial of service conditions.Cisco Unified Communications Manager does not properly throttle authentication requests. A remote user can send multiple authentication requests in a short period of time to...
Last Update Date: 16 May 2013 18:38 Release Date: 16 May 2013 6477 Views

RISK: High Risk

High Risk

Kerberos kpasswd UDP Processing Vulnerability

A vulnerability has been identifitied in MIT Kerberos. A remote user can cause denial of service conditions. A remote user can send spoofed UDP packets to a target kadmind server running kpasswd to cause kpasswd to pass the UDP packets to the spoofed address and reply to the...
Last Update Date: 16 May 2013 18:34 Release Date: 16 May 2013 7632 Views

RISK: Medium Risk

Medium Risk

Linux Kernel Array Bounds Checking Vulnerability

A vulnerability has been identified in the Linux Kernel. A local user can obtain elevated privileges on the target system. On systems compiled with PERF_EVENTS support, a local user can supply a specially crafted perf_event_open() call to execute arbitrary code on the target system with root...
Last Update Date: 16 May 2013 18:33 Release Date: 16 May 2013 6775 Views

RISK: Medium Risk

Medium Risk

Microsoft Malware Protection Engine File Parsing Vulnerability

A vulnerability has been identified in multiple Microsoft products, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an unspecified error when parsing certain files and can be exploited to cause memory corruption. Successful exploitation may allow execution...
Last Update Date: 16 May 2013 17:49 Release Date: 16 May 2013 6539 Views

RISK: High Risk

High Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities has been identified in IBM Java, which can be exploited by malicious, local users to disclose certain sensitive information and gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, bypass certain security restrictions, cause a...
Last Update Date: 16 May 2013 17:47 Release Date: 16 May 2013 6291 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Memory Corruption Vulnerability

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted content that, when loaded by the target user...
Last Update Date: 16 May 2013 Release Date: 15 May 2013 6676 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox / Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, conduct cross-site scripting attacks, and obtain potentially sensitive information. A local user can obtain elevated privileges on...
Last Update Date: 15 May 2013 15:06 Release Date: 15 May 2013 6151 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system, obtain potentially sensitive information, and bypass operating system blacklist controls. A remote user can create a specially crafted PDF...
Last Update Date: 15 May 2013 14:56 Release Date: 15 May 2013 6055 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

DirectX Graphics Kernel Subsystem Double Fetch VulnerabilityAn elevation of privilege vulnerability exists when the Microsoft DirectX graphics kernel subsystem (dxgkrnl.sys) improperly handles objects in memory.  Win32k Buffer Overflow VulnerabilityAn elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in...
Last Update Date: 15 May 2013 14:27 Release Date: 15 May 2013 6587 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Essentials Improper URI Handling Vulnerability

An information disclosure vulnerability exists when Windows Writer fails to properly handle a specially crafted URL. An attacker who successfully exploited the vulnerability could override Windows Writer proxy settings and overwrite files accessible to the user on the target system.
Last Update Date: 15 May 2013 14:27 Release Date: 15 May 2013 6283 Views

RISK: Medium Risk

Medium Risk

Microsoft Visio XML External Entities Resolution Vulnerability

An information disclosure vulnerability exists in the way that Microsoft Visio parses specially crafted XML files containing external entities.
Last Update Date: 15 May 2013 14:26 Release Date: 15 May 2013 6220 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Shape Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Word parses content in Word files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 15 May 2013 14:26 Release Date: 15 May 2013 6397 Views

RISK: Medium Risk

Medium Risk

Microsoft Publisher Multiple Vulnerabilities

Multiple remote code execution vulnerabilities exists in the way that Microsoft Publisher parses Publisher files. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 15 May 2013 14:26 Release Date: 15 May 2013 6197 Views

RISK: Medium Risk

Medium Risk

Microsoft Lync Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Lync control attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing a target user to accept an invitation to launch specially crafted content within a Lync or Communicator session. An...
Last Update Date: 15 May 2013 14:25 Release Date: 15 May 2013 6239 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities

XML Digital Signature Spoofing Vulnerability A spoofing vulnerability exists when the Microsoft .NET Framework fails to properly validate the signature of a specially crafted XML file. An attacker who successfully exploited this vulnerability could modify the contents of an XML file without invalidating the signature associated with...
Last Update Date: 15 May 2013 14:25 Release Date: 15 May 2013 6243 Views

RISK: High Risk

High Risk

Microsoft Windows HTTP.sys Denial of Service Vulnerability

A denial of service vulnerability exists in Windows Server 2012 and Windows 8 when the HTTP protocol stack (HTTP.sys) improperly handles a malicious HTTP header. An attacker who successfully exploited this vulnerability could trigger an infinite loop in the HTTP protocol stack by sending a...
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 6256 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Use After Free Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the...
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 6216 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer JSON Array Information Disclosure Vulnerability

An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access and read the contents of JSON data files.
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 6281 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Unspecified Use-After-Free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to a use-after-free error and can be exploited to dereference already freed memory.   Successful exploitation...
Last Update Date: 15 May 2013 Release Date: 6 May 2013 7139 Views

RISK: High Risk

High Risk

Adobe ColdFusion "filename" Arbitrary File Disclosure Vulnerability

A vulnerabilities has been identified in Adobe ColdFusion, which can be exploited by an unauthorized user to remotely retrieve files stored on the server.   Input passed via the "filename" parameter to administrator/mail/download.cfm in the CFIDE/adminapi section is not...
Last Update Date: 15 May 2013 Release Date: 10 May 2013 6515 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Customer Voice Portal Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Cisco Unified Customer Voice Portal. A remote user can execute arbitrary applications on the target system, cause denial of service conditions, view and modify files on the target system, and gain administrator access.A remote user can send a...
Last Update Date: 9 May 2013 10:05 Release Date: 9 May 2013 6240 Views

RISK: Medium Risk

Medium Risk

nginx "ngx_http_parse_chunked()" Buffer Overflow Vulnerability

A vulnerability has been identified in nginx, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the "ngx_http_parse_chunked()" function (http/ngx_http_parse.c) when parsing an HTTP chunk and can be...
Last Update Date: 8 May 2013 10:41 Release Date: 8 May 2013 6926 Views

RISK: High Risk

High Risk

IBM WebSphere Products Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere products, which can be exploited by malicious people to disclose and manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.  The applications bundle a vulnerable version of IBM Java Runtime Environment.
Last Update Date: 8 May 2013 10:37 Release Date: 8 May 2013 6981 Views

RISK: High Risk

High Risk

IBM Notes PNG Integer Overflow Vulnerability

A vulnerability has been identified in IBM Notes, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow when viewing PNG images and can be exploited to execute arbitrary code by sending an e-...
Last Update Date: 8 May 2013 10:33 Release Date: 8 May 2013 6259 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Files and Folders Enumeration Vulnerabilities

Multiple vulnerabilities have been discovered in Microsoft Internet Explorer, which can be exploited by malicious people to disclose sensitive information. The vulnerabilities are caused due to MSXML returning different errors depending on whether or not a file or directory exists. This can be exploited to check the...
Last Update Date: 7 May 2013 10:12 Release Date: 7 May 2013 6427 Views

RISK: Medium Risk

Medium Risk

Cisco Webex Meetings Server Input Validation Vulnerability

A vulnerability has been identified in Cisco Webex Meetings Server. A remote user can view certain files on the target system. The system does not properly validate user-supplied input. A remote user can supply a specially crafted HTTP request to a target WebEx node to...
Last Update Date: 6 May 2013 15:28 Release Date: 6 May 2013 6207 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR SNMP Processing Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote authenticated user can cause denial of service conditions.   A remote authenticated user can send specially crafted SNMP packets to cause the target SNMP process to restart.
Last Update Date: 6 May 2013 15:26 Release Date: 6 May 2013 6334 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Message Broker Java Multiple Vulnerabilities

IBM has acknowledged multiple vulnerabilities in IBM WebSphere Message Broker, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.   The vulnerabilities exist in the...
Last Update Date: 6 May 2013 15:26 Release Date: 6 May 2013 6378 Views

RISK: Medium Risk

Medium Risk

FortiClient VPN Client Password Disclosure Vulnerability

A vulnerability has been identified in FortiClient VPN Client, which can be exploited by remote user to obtain the target user's VPN password. A remote user that can conduct a man-in-the-middle attack and cause the VPN client to connect to...
Last Update Date: 3 May 2013 12:17 Release Date: 3 May 2013 6729 Views

RISK: Medium Risk

Medium Risk

Cisco Prime Central for Hosted Collaboration Solution Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Prime Central for Hosted Collaboration Solution, which can be exploited by remote user to conduct cross-site scripting attacks or view files on the target system.
Last Update Date: 3 May 2013 11:49 Release Date: 3 May 2013 6294 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes Mail Client Remote Code Execution Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which can be exploited by remote user to cause Java applets to be executed on the target user's system. The mail client does not filter 'applet' and 'javascript' tags in HTML-based...
Last Update Date: 3 May 2013 11:37 Release Date: 3 May 2013 6793 Views

RISK: High Risk

High Risk

Novell iPrint Client Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in Novell iPrint Client, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to cause a stack-based buffer overflow. Successful exploitation may...
Last Update Date: 3 May 2013 11:28 Release Date: 3 May 2013 6243 Views

RISK: High Risk

High Risk

HP Service Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Service Manager, which can be exploited by attacker to gain escalated privileges, conduct cross-site scripting attacks, disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system...
Last Update Date: 2 May 2013 11:28 Release Date: 2 May 2013 6471 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Deny Service Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote authenticated user can cause denial of service conditions. A remote authenticated user can send specially crafted SNMP packets to trigger a memory leak in the SNMP process and consume all memory allocated to the process. The...
Last Update Date: 30 Apr 2013 10:44 Release Date: 30 Apr 2013 6603 Views

RISK: High Risk

High Risk

VMware vCenter Server Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware vCenter Server products, which can be exploited by attacker to bypass certain security restrictions, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.The authentication mechanism...
Last Update Date: 29 Apr 2013 18:29 Release Date: 29 Apr 2013 6694 Views

RISK: High Risk

High Risk

Citrix NetScaler / Access Gateway Security Bypass Vulnerability

A vulnerability has been identified in Citrix NetScaler and Access Gateway, which can be exploited by malicious user to access internal network resources. Note: Firmware versions 10. through 10..74.4 are also affected when deployed in a double hop configuration only.
Last Update Date: 29 Apr 2013 11:29 Release Date: 29 Apr 2013 6704 Views

RISK: Medium Risk

Medium Risk

F-Secure Products ActiveX Component Code Execution Vulnerability

A vulnerability has been identified in multiple F-Secure products, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error within a bundled ActiveX control, which can be exploited to execute arbitrary SQL statements...
Last Update Date: 26 Apr 2013 17:19 Release Date: 26 Apr 2013 6536 Views

RISK: Medium Risk

Medium Risk

WordPress WP Super Cache Plugin PHP Code Execution Vulnerability

A vulnerability has been identified in the WP Super Cache plugin for WordPress, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the plugin not properly sanitising certain tags and can be exploited to insert and execute arbitrary PHP...
Last Update Date: 26 Apr 2013 14:46 Release Date: 26 Apr 2013 7236 Views

RISK: Medium Risk

Medium Risk

Cisco ASA and FWSM Time-Range Object Access List Bypass Vulnerability

A vulnerability in the implementation of the time-range object could allow an unauthenticated, remote attacker to bypass access lists that are using the time-range option. The vulnerability is due to improper implementation of the code for the time-range object, ...
Last Update Date: 25 Apr 2013 10:54 Release Date: 25 Apr 2013 6881 Views

RISK: High Risk

High Risk

Oracle Java Reflection API Vulnerability

A vulnerability has been identified in Oracle Java. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted Java application that, when loaded and approved by the target user, will trigger...
Last Update Date: 25 Apr 2013 10:41 Release Date: 25 Apr 2013 7214 Views

RISK: Medium Risk

Medium Risk

McAfee ePolicy Orchestrator Multiple Vulnerabilities

Multiple vulnerabilities was identifited in McAfee ePolicy Orchestrator, which can be exploited by malicious people to disclose certain sensitive information and compromise a user's system.
Last Update Date: 24 Apr 2013 10:13 Release Date: 24 Apr 2013 6445 Views

RISK: High Risk

High Risk

Hitachi Cosminexus Products Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Hitachi Cosminexus products, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable...
Last Update Date: 22 Apr 2013 09:58 Release Date: 22 Apr 2013 6846 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Java Vulnerabilities

Multiple Java vulnerabilities has been identifitied in Mac OS X, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 18 Apr 2013 16:24 Release Date: 18 Apr 2013 6442 Views

RISK: Medium Risk

Medium Risk

Cisco TelePresence H.264 Processing Vulnerability

A vulnerability was identified in Cisco TelePresence. A remote user can cause denial of service conditions. A remote user can send a specially crafted H.264 bit stream within a Real-Time Transport Protocol (RTP) packet to trigger a flaw in the digital signal...
Last Update Date: 18 Apr 2013 16:24 Release Date: 18 Apr 2013 6815 Views

RISK: High Risk

High Risk

HP-UX Multiple Java Vulnerabilities

Multiple Java vulnerabilities has been identified in HP-UX, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 18 Apr 2013 16:24 Release Date: 18 Apr 2013 6546 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities was identifited in Oracle Products, which can be exploited to execute arbitrary code on the target system, partially access and modify data, obtain elevated privileges on the target system, and cause denial of service conditions.
Last Update Date: 18 Apr 2013 16:24 Release Date: 18 Apr 2013 6996 Views

RISK: High Risk

High Risk

Apple Safari WebKit Type Confusion Vulnerability

A vulnerability has been identified in Apple Safari, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 18 Apr 2013 16:24 Release Date: 18 Apr 2013 6438 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java, which can be exploited by malicious people to elevation of privilege, cause a DoS (Denial of Service), and compromise a user's system. A remote user can create a specially crafted Java applet or Java Web...
Last Update Date: 17 Apr 2013 11:07 Release Date: 17 Apr 2013 7350 Views

RISK: High Risk

High Risk

IBM Tivoli System Automation Application Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Tivoli System Automation Application Manager, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, and cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, ...
Last Update Date: 12 Apr 2013 10:45 Release Date: 12 Apr 2013 6674 Views

RISK: High Risk

High Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Solaris C Library, ISC BIND and Python included in Solaris, which can be exploited by malicious people to disclose potentially sensitive information, hijack a user's session, and cause a DoS (Denial of Service).
Last Update Date: 12 Apr 2013 10:39 Release Date: 12 Apr 2013 6606 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco products.A remote user can cause denial of service conditions.A remote user can gain access to the target system.
Last Update Date: 12 Apr 2013 Release Date: 11 Apr 2013 6468 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe ColdFusion, which can be exploited by malicious users to bypass certain security restrictions and malicious people to conduct spoofing attacks.An unspecified error can be exploited to impersonate an authenticated user.An unspecified error can be exploited to gain access...
Last Update Date: 11 Apr 2013 11:21 Release Date: 11 Apr 2013 6321 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system. An unspecified error can be exploited to cause a buffer overflow. An unspecified error can be exploited to corrupt memory.
Last Update Date: 11 Apr 2013 11:21 Release Date: 11 Apr 2013 6240 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been indentified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system.An integer overflow error can be exploited to execute arbitrary code.Some unspecified errors can be exploited to cause memory corruption...
Last Update Date: 11 Apr 2013 Release Date: 10 Apr 2013 6413 Views

RISK: High Risk

High Risk

Microsoft Antimalware Improper Pathname Vulnerability

This is an elevation of privilege vulnerability. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take complete control of the system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Apr 2013 12:31 Release Date: 10 Apr 2013 6214 Views

RISK: High Risk

High Risk

Microsoft HTML Sanitization Component Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks on affected systems and run script in the security context of the current user.
Last Update Date: 10 Apr 2013 12:31 Release Date: 10 Apr 2013 6324 Views

RISK: High Risk

High Risk

Microsoft Kernel-Mode Driver Elevation Of Privilege Vulnerabilities

An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges and read arbitrary amounts of kernel memory. A denial of service vulnerability exists when Windows fails to handle a...
Last Update Date: 10 Apr 2013 12:30 Release Date: 10 Apr 2013 6451 Views

RISK: High Risk

High Risk

Microsoft Windows CSRSS Memory Corruption Vulnerability

An elevation of privilege vulnerability exists when the Windows CSRSS improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the local system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 6158 Views

RISK: High Risk

High Risk

Microsoft Active Directory Memory Consumption Vulnerability

A denial of service vulnerability exists in implementations of Active Directory that could cause the service to stop responding. The vulnerability is caused when the LDAP service fails to handle a specially crafted query.
Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 6255 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

An elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges and read arbitrary amounts of kernel memory.
Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 6230 Views

RISK: High Risk

High Risk

Microsoft SharePoint Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that SharePoint Server enforces access controls on specific SharePoint Lists.
Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 6292 Views

RISK: High Risk

High Risk

Microsoft RDP ActiveX Control Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Remote Desktop ActiveX control, mstscax.dll, attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing the user to visit a specially crafted webpage. An attacker who successfully...
Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 7542 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Use After Free Vulnerabilities

Remote code execution vulnerabilities exist in the way that Internet Explorer accesses an object in memory that has been deleted. These vulnerabilities may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 10 Apr 2013 12:20 Release Date: 10 Apr 2013 7060 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple vulnerabilities

Multiple vulnerabilities have been identified in Java Runtime Environment (JRE) and Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote unauthorized access, disclosure of information, and other exploits.
Last Update Date: 9 Apr 2013 10:16 Release Date: 9 Apr 2013 7064 Views

RISK: High Risk

High Risk

Mozilla Firefox for Android Stack Corruption Vulnerability

A vulnerability has been identified in Mozilla Firefox for Android, which can be exploited to potentially compromise a user's device. The vulnerability is caused due to an unspecified error related to plug-in code and can be exploited to cause stack corruption.
Last Update Date: 5 Apr 2013 10:56 Release Date: 5 Apr 2013 7078 Views

RISK: Medium Risk

Medium Risk

HP-UX Tomcat Servlet Engine Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Tomcat Servlet Engine, which can be exploited by malicious, local users to bypass certain security restrictions, disclose sensitive information, or cause a DoS (Denial of Service), by malicious users to disclose sensitive information and manipulate...
Last Update Date: 3 Apr 2013 10:59 Release Date: 3 Apr 2013 7323 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey, which can be exploited by remote attackers to conduct a cross-site scripting attack, elevation of privilege or execute arbitrary code.
Last Update Date: 3 Apr 2013 10:56 Release Date: 3 Apr 2013 7157 Views

RISK: Medium Risk

Medium Risk

Splunk Web Input Validation Vulnerability

A vulnerability was identified in Splunk Web. A remote user can conduct cross-site scripting attacks.   Splunk Web does not properly filter HTML code from user-supplied input before displaying the input. A remote user can cause arbitrary scripting code to be executed by the...
Last Update Date: 2 Apr 2013 15:13 Release Date: 2 Apr 2013 7167 Views

RISK: Medium Risk

Medium Risk

VMware ESX / ESXi libxml2 Buffer Underflow Vulnerability

A vulnerability has been reported in VMware ESX and ESXi, which can be exploited by malicious people to compromise a vulnerable system. For more information see vulnerability #2 in:SA12071601
Last Update Date: 2 Apr 2013 15:07 Release Date: 2 Apr 2013 7107 Views

RISK: High Risk

High Risk

McAfee Firewall Enterprise BIND Regular Expression Handling Denial of Service Vulnerability

A vulnerability has been identified in McAfee Firewall Enterprise, which can be exploited by malicious people to cause a DoS (Denial of Service). For more information:SA13032804 Note:  No patch is currently avaliable
Last Update Date: 2 Apr 2013 15:06 Release Date: 2 Apr 2013 7013 Views

RISK: Medium Risk

Medium Risk

ISC DHCP Denial of service Vulnerability

A vulnerability has been identified in ISC DHCP, which can be exploited by malicious user to to cause denial of service. Exploitation of a memory exhaustion bug in libdns is theoretically possible in ISC DHCP 4.2, which uses the library from BIND 9 for...
Last Update Date: 2 Apr 2013 15:00 Release Date: 2 Apr 2013 7089 Views

RISK: Medium Risk

Medium Risk

ISC BIND Regular Expression Handling Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error when handling regular expressions. This can be exploited to exhaust memory resources and render the...
Last Update Date: 28 Mar 2013 11:36 Release Date: 28 Mar 2013 6507 Views

RISK: Medium Risk

Medium Risk

HP OpenVMS SSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified HP OpenVMS, which can be exploited by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service) of the application using the library.
Last Update Date: 28 Mar 2013 11:36 Release Date: 28 Mar 2013 6142 Views

RISK: High Risk

High Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS, which can be exploited by remote user to cause denial of service conditions.
Last Update Date: 28 Mar 2013 11:35 Release Date: 28 Mar 2013 6211 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A use-after-free error exists in Web Audio. An out-of-bounds read error exists...
Last Update Date: 28 Mar 2013 11:34 Release Date: 28 Mar 2013 6115 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

HP has issued an update for Java in HP-UX. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.   For more...
Last Update Date: 27 Mar 2013 12:36 Release Date: 27 Mar 2013 6250 Views

RISK: Medium Risk

Medium Risk

CoreFTP buffer overflow vulnerability

A vulnerability has been identified in CoreFTP. A remote user can cause arbitrary code to be executed on the target user's system.The vulnerability is caused due to a buffer overflow error when parsing long directory names from a malicious FTP server. The LIST, ...
Last Update Date: 27 Mar 2013 Release Date: 22 Mar 2013 6472 Views

RISK: High Risk

High Risk

IBM Lotus Notes/Domino Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Notes/Domino, which can be exploited by malicious users to disclose certain sensitive information, cause a DoS (Denial of Service) and compromise a vulnerable system.   IBM Lotus Notes The application bundles a vulnerable version of...
Last Update Date: 25 Mar 2013 11:27 Release Date: 25 Mar 2013 6857 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the...
Last Update Date: 21 Mar 2013 09:53 Release Date: 21 Mar 2013 6304 Views

RISK: Medium Risk

Medium Risk

Google Picasa Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Picasa, which can be exploited by malicious people to compromise a user's system. A sign extension error when processing the color table of a BMP image can be exploited to cause a heap-based buffer overflow via a...
Last Update Date: 21 Mar 2013 09:53 Release Date: 21 Mar 2013 6311 Views

RISK: Medium Risk

Medium Risk

Samba Active Directory Domain Controller File Permission Vulnerability

A vulnerability has been identified in Samba. A remote authenticated user can access files on certain shares. When additional CIFS file shares are created on the Samba Active Directory domain controller, the system uses world-writable permissions on non-default CIFS shares for the initial...
Last Update Date: 20 Mar 2013 14:58 Release Date: 20 Mar 2013 6288 Views

RISK: Medium Risk

Medium Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS. A local user can obtain elevated privileges on the target system.A local user can exploit a flaw in the handling of Mach-O executable files with overlapping segments to execute unsigned code on the target system.A...
Last Update Date: 20 Mar 2013 14:58 Release Date: 20 Mar 2013 6572 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Ruby on Rails, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).An error when handling keys to a hash in Active Record can be exploited to potentially convert...
Last Update Date: 20 Mar 2013 14:57 Release Date: 20 Mar 2013 6416 Views

RISK: Medium Risk

Medium Risk

RealPlayer MP4 Processing Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when processing MP4 files and can be exploited to cause a heap-based buffer overflow via a specially...
Last Update Date: 19 Mar 2013 09:45 Release Date: 19 Mar 2013 7187 Views

RISK: Medium Risk

Medium Risk

Novell Messenger / Groupwise Messenger Client Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in Novell Messenger and Novell Groupwise Messenger Client, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error within the client and can be exploited to cause a buffer overflow...
Last Update Date: 18 Mar 2013 11:39 Release Date: 18 Mar 2013 6569 Views

RISK: High Risk

High Risk

TP-LINK Router Administrative Web Interface Backdoor Vulnerability

A vulnerability has been identified in certain TP-LINK routers, which can be exploited by remote attackers to execute arbitrary code on target system.   Certain TP-LINK routers provide access to an administrative web interface which does not require authentication (start_art.html). Remote...
Last Update Date: 15 Mar 2013 10:54 Release Date: 15 Mar 2013 8811 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari. A remote user can cause arbitrary code to be executed on the target user's system, and bypass authentication.  A remote user can create specially crafted HTML that, when loaded by the target user, will execute...
Last Update Date: 15 Mar 2013 10:18 Release Date: 15 Mar 2013 6301 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mac OS X. A remote user can cause arbitrary code to be executed on the target user's system, and bypass authentication. A remote user may be able to bypass AppleID authentication when multiple users fail the AppleID certificate validation...
Last Update Date: 15 Mar 2013 10:18 Release Date: 15 Mar 2013 6402 Views