Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Solaris, which can be exploited by malicious people to bypass certain security restrictions, disclose certain sensitive information, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 15 Mar 2013 10:17 Release Date: 15 Mar 2013 6249 Views

RISK: Medium Risk

Medium Risk

FFmpeg Two Vulnerabilities

Two vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise an application using the library.An error within the "msrle_decode_8_16_24_32()" function (libavcodec/msrledec.c) when decoding Microsoft...
Last Update Date: 14 Mar 2013 09:58 Release Date: 14 Mar 2013 6303 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash Player. For more information: SA13031309
Last Update Date: 13 Mar 2013 15:46 Release Date: 13 Mar 2013 6313 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system.An integer overflow error can be exploited to execute arbitrary code.A use-after-free error can be exploited...
Last Update Date: 13 Mar 2013 15:46 Release Date: 13 Mar 2013 6602 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers USB Descriptor Vulnerability

An elevation of privilege vulnerability exists when Windows USB drivers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts...
Last Update Date: 13 Mar 2013 15:20 Release Date: 13 Mar 2013 6478 Views

RISK: Medium Risk

Medium Risk

Microsoft Office for Mac Unintended Content Loading Vulnerability

An information disclosure vulnerability exists in the way that Microsoft Outlook for Mac 2008 and Microsoft Outlook for Mac 2011 load specific content tags in an HTML5 email message.
Last Update Date: 13 Mar 2013 15:20 Release Date: 13 Mar 2013 6263 Views

RISK: Medium Risk

Medium Risk

Microsoft OneNote 2010 Buffer Size Validation Vulnerability

An information disclosure vulnerability exists in the way that Microsoft OneNote allocates memory from parsing a specially crafted OneNote (.ONE) file.
Last Update Date: 13 Mar 2013 15:19 Release Date: 13 Mar 2013 6293 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Server 2010 / Foundation 2010 Multiple Vulnerabilities

Callback Function Vulnerability An elevation of privilege exists in Microsoft SharePoint Server. An attacker who successfully exploited this vulnerability could allow an attacker, after obtaining sensitive system data, elevate their access to the server. SharePoint XSS Vulnerability An elevation of privilege exists in Microsoft...
Last Update Date: 13 Mar 2013 15:19 Release Date: 13 Mar 2013 6293 Views

RISK: High Risk

High Risk

Microsoft Visio Viewer Tree Object Type Confusion Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Visio Viewer handles memory when rendering specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 13 Mar 2013 15:18 Release Date: 13 Mar 2013 6304 Views

RISK: High Risk

High Risk

Microsoft Silverlight Double Dereference Vulnerability

A remote code execution vulnerability exists in Microsoft Silverlight that can allow a specially crafted Silverlight application to access memory in an unsafe manner. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the current user. An attacker could then install...
Last Update Date: 13 Mar 2013 15:14 Release Date: 13 Mar 2013 6367 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Multiple use after free vulnerabilities exist in the way that Internet Explorer accesses an object in memory that has been deleted. These vulnerabilities may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 13 Mar 2013 15:14 Release Date: 13 Mar 2013 6352 Views

RISK: Medium Risk

Medium Risk

Corel WordPerfect Document Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Corel WordPerfect Office X6, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the wpwin16.dll module when processing WordPerfect documents and can be exploited to...
Last Update Date: 11 Mar 2013 14:12 Release Date: 11 Mar 2013 6424 Views

RISK: High Risk

High Risk

Mozilla Products HTML Editor Use-After-Free Vulnerability

A vulnerability has been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a use-after-free error within the HTML editor when content script is...
Last Update Date: 11 Mar 2013 14:11 Release Date: 11 Mar 2013 6418 Views

RISK: High Risk

High Risk

Google Chrome WebKit Type Confusion Vulnerability

A vulnerability has been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a type confusion error in WebKit and can be exploited to execute arbitrary code in the context of the sandboxed...
Last Update Date: 11 Mar 2013 14:11 Release Date: 11 Mar 2013 7369 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities were identified in Wireshark, which can be exploited by malicious people to cause denial of service. A remote user can send specially crafted data to cause the target service to hang or crash.
Last Update Date: 8 Mar 2013 09:46 Release Date: 8 Mar 2013 7514 Views

RISK: Medium Risk

Medium Risk

Citrix Access Gateway Unspecified Security Bypass Vulnerability

A vulnerability has been identified in Citrix Access Gateway, which can be exploited by malicious people to bypass certain security restrictions.  The vulnerability is caused due to an unspecified error and can be exploited to gain unauthorized access to network resources.
Last Update Date: 8 Mar 2013 09:45 Release Date: 8 Mar 2013 7275 Views

RISK: Extremely High Risk

Extremely High Risk

Oracle Java Unspecified Code Execution Vulnerability

A vulnerability has been identified in Oracle Java, which can be exploited by malicious people to compromise a user's system.   A remote user can create a specially crafted applet that, when loaded by the target user, will read and write arbitrary memory in the...
Last Update Date: 6 Mar 2013 Release Date: 4 Mar 2013 9112 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Vulnerabilities

Two Java vulnerabilities has been identified in Apple Mac OS X , which can be exploited by malicious people to compromise a user's system.  For detail of the vulnerability, please refer to SA13030401.
Last Update Date: 6 Mar 2013 18:09 Release Date: 6 Mar 2013 7281 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to compromise a user's system.A use-after-free error exists in frame loader.A use-after-free error...
Last Update Date: 6 Mar 2013 18:08 Release Date: 6 Mar 2013 7182 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library. An error within the "ff_h264_decode_seq_parameter_set()" function (libavcodec/h264_ps.c) when decoding...
Last Update Date: 5 Mar 2013 16:01 Release Date: 5 Mar 2013 7644 Views

RISK: High Risk

High Risk

Kaspersky Internet Security Kaspersky Anti-Virus NDIS 6 Filter Denial of Service Vulnerability

A vulnerability has been identified in Kaspersky Internet Security, which can be exploited by malicious people to cause a DoS (Denial of Service).   The vulnerability is caused due to an error in the Kaspersky Anti-Virus NDIS 6 Filter component when handling certain IPv6 traffic, ...
Last Update Date: 5 Mar 2013 15:19 Release Date: 5 Mar 2013 7867 Views

RISK: Medium Risk

Medium Risk

Kingsoft Office Writer 2010 RTF Buffer Overflow Vulnerability

A vulnerability has been identified in Kingsoft Office, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error in Kingsoft Writer, which can be exploited to cause a buffer overflow by tricking a user...
Last Update Date: 4 Mar 2013 10:50 Release Date: 4 Mar 2013 7420 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 1 Mar 2013 09:29 Release Date: 1 Mar 2013 7301 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted Flash content that, when loaded by the target user, will execute arbitrary...
Last Update Date: 28 Feb 2013 Release Date: 27 Feb 2013 6833 Views

RISK: High Risk

High Risk

Cisco ASA NAT Connections Table Memory Exhaustion Vulnerability

A vulnerability has been identified in Cisco ASA. A remote user can cause denial of service conditions.   A remote user can send specially crafted packets through the target system to consume memory allocated for the NAT connections table, which may prevent new connections from being established until...
Last Update Date: 27 Feb 2013 17:50 Release Date: 27 Feb 2013 6744 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware products, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.An error in the handling of the NFC (...
Last Update Date: 25 Feb 2013 15:59 Release Date: 25 Feb 2013 6702 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.An unspecified error related to web audio node can be exploited to corrupt memory.A use-after-free...
Last Update Date: 25 Feb 2013 15:59 Release Date: 25 Feb 2013 6776 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Reader / Acrobat Two Vulnerabilities

Two vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted PDF file that, when loaded by the target user, will execute...
Last Update Date: 21 Feb 2013 Release Date: 15 Feb 2013 9120 Views

RISK: High Risk

High Risk

Mozilla Firefox, Thunderbird and Seamonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey, which can be exploited by remote attackers to execute arbitrary code and gather sensitive information. Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer Phishing...
Last Update Date: 21 Feb 2013 Release Date: 20 Feb 2013 6742 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Solaris, which can be exploited by malicious people to bypass certain security restrictions, disclose system information, cause a DoS (Denial of Service), and compromise a user's system.
Last Update Date: 21 Feb 2013 10:25 Release Date: 21 Feb 2013 6554 Views

RISK: High Risk

High Risk

Apple Mac OS X and Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X and Java bundled, which can be exploited by remote attackers to execute arbitrary code.
Last Update Date: 20 Feb 2013 16:24 Release Date: 20 Feb 2013 6779 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java. A remote user can cause arbitrary code to be executed, and partially modify data on the target system. A remote user can create a specially crafted Java Web Start application or Java applet that, when loaded by the...
Last Update Date: 20 Feb 2013 16:24 Release Date: 20 Feb 2013 7518 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will trigger an integer overflow, ...
Last Update Date: 14 Feb 2013 17:51 Release Date: 14 Feb 2013 7040 Views

RISK: High Risk

High Risk

BlackBerry Enterprise Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry Enterprise Server, which can be exploited by malicious people to compromise a vulnerable system.   The vulnerabilities exist in the bundled version of LibTIFF, which is used by the BlackBerry Mobile Data System Connection Service and the BlackBerry Messaging Agent.
Last Update Date: 14 Feb 2013 17:47 Release Date: 14 Feb 2013 6883 Views

RISK: High Risk

High Risk

Adobe Shockwave Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player.A remote user can cause arbitrary code to be executed on the target user's system.A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 14 Feb 2013 17:45 Release Date: 14 Feb 2013 6891 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system, and obtain potentially sensitive information. A remote user can create a specially crafted file that, when loaded by the target...
Last Update Date: 14 Feb 2013 17:43 Release Date: 14 Feb 2013 7020 Views

RISK: High Risk

High Risk

cURL Buffer Overflow Vulnerability

A vulnerability has been identified in cURL. A remote user can execute arbitrary code on the target system. A remote server can return specially crafted data via POP3, SMTP, or IMAP to trigger a buffer overflow in Curl_sasl_create_digest_md5_message() and execute arbitrary code on the target...
Last Update Date: 14 Feb 2013 17:42 Release Date: 14 Feb 2013 7128 Views

RISK: High Risk

High Risk

Microsoft Windows CSRSS Reference Count Vulnerability

An elevation of privilege vulnerability exists when the Windows CSRSS improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the local system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 14 Feb 2013 17:40 Release Date: 14 Feb 2013 6485 Views

RISK: High Risk

High Risk

Microsoft Windows TCP FIN WAIT Vulnerability

A denial of service vulnerability exists in the Windows TCP/IP stack that could cause the target system to stop responding and automatically restart. The vulnerability is caused when the TCP/IP stack improperly handles a connection termination sequence.
Last Update Date: 14 Feb 2013 17:37 Release Date: 14 Feb 2013 6866 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel Multiple Vulnerabilities

Kernel Race Condition Vulnerability An elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Feb 2013 17:33 Release Date: 14 Feb 2013 6409 Views

RISK: Medium Risk

Medium Risk

Microsoft FAST Search Server 2010 for SharePoint Multiple Vulnerabilities

Remote code execution vulnerabilities exist in FAST Search Server 2010 for SharePoint with the Advanced Filter Pack enabled. An attacker who succesfully exploited these vulnerabilities could run arbitrary code in the context of a user account with a restricted token. By default, Advanced Filter Pack in FAST...
Last Update Date: 14 Feb 2013 17:30 Release Date: 14 Feb 2013 6676 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Shift JIS Character Encoding Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a...
Last Update Date: 14 Feb 2013 17:25 Release Date: 14 Feb 2013 6472 Views

RISK: High Risk

High Risk

Microsoft Windows Media Decompression Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles media content. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a ....
Last Update Date: 14 Feb 2013 17:21 Release Date: 14 Feb 2013 6818 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Multiple Vulnerabilities

Two vulnerabilities exist in Microsoft Exchange Server through the WebReady Document Viewing feature. The more severe vulnerability, CVE-2013-0418, could allow remote code execution as the LocalService account if a user views a specially crafted file through Outlook Web Access in a browser. ...
Last Update Date: 14 Feb 2013 17:18 Release Date: 14 Feb 2013 6784 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Automation Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Object Linking and Embedding (OLE) Automation allocates memory. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 14 Feb 2013 17:16 Release Date: 14 Feb 2013 6391 Views

RISK: High Risk

High Risk

Microsoft Windows NFS Server NULL Dereference Vulnerability

A denial of service vulnerability exists when the Windows NFS server fails to properly handle a file operation on a read-only share. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding and restart.
Last Update Date: 14 Feb 2013 17:08 Release Date: 14 Feb 2013 6641 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Multiple Vulnerabilities

Elevation of privilege vulnerabilities exist when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges and read arbitrary amounts of kernel memory.
Last Update Date: 14 Feb 2013 17:06 Release Date: 14 Feb 2013 6682 Views

RISK: High Risk

High Risk

Microsoft .NET Framework WinForms Allow Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that the .NET Framework elevates the permissions of a callback function when a particular Windows Forms object is created. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 14 Feb 2013 17:00 Release Date: 14 Feb 2013 6564 Views

RISK: High Risk

High Risk

PostgreSQL Array Index Error Vulerability

A vulnerability has been identified in PostgreSQL, which can be exploited by remote authenticated user to cause denial of service and disclose portions of system memory by sending a specially crafted SQL command to trigger an array index error.
Last Update Date: 14 Feb 2013 Release Date: 8 Feb 2013 7407 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Multiple Vulnerabilities

Two vulnerabilities have been discovered in Ruby on Rails, a Ruby framework for web application development.The blacklist provided by the attr_protected method could be bypassed with crafted requests, having an application-specific impact.In some applications, the +serialize+ helper...
Last Update Date: 14 Feb 2013 15:13 Release Date: 14 Feb 2013 6723 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to execute arbitrary code on the target system and take control of a vulnerable system.  A remote malicious user can create a specially crafted Flash content that, when loaded by the...
Last Update Date: 8 Feb 2013 17:39 Release Date: 8 Feb 2013 8045 Views

RISK: Medium Risk

Medium Risk

libssh Null Pointer Dereference Error Vulnerability

A vulnerability has been identified in libssh, which is vulnerable to a denial of service, caused by a NULL pointer dereference error when processing "Client: Diffie-Hellman Key Exchange Init" packet. A remote attacker could exploit this vulnerability to cause the application to...
Last Update Date: 7 Feb 2013 10:42 Release Date: 7 Feb 2013 7458 Views

RISK: Medium Risk

Medium Risk

Opera TLS/DTLS CBC Mode Oracle Padding Vulnerability

A vulnerability has been identified in Opera. A remote user can recover plaintext in certain cases.   For the details of the vulnerability, please refer to #2 in SA13020601.
Last Update Date: 7 Feb 2013 10:39 Release Date: 7 Feb 2013 7338 Views

RISK: Medium Risk

Medium Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL. A remote user can cause denial of service conditions, and recover plaintext in certain cases. A remote user can send specially crafted data to a system using AES-NI for TLS 1.2 or TLS 1.1...
Last Update Date: 6 Feb 2013 10:44 Release Date: 6 Feb 2013 7464 Views

RISK: Medium Risk

Medium Risk

Apple OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identifed in Apple Mac OS X Server, which can be exploited by malicious people to cause arbitrary code execution and potentially compromise a vulnerable system.
Last Update Date: 5 Feb 2013 10:07 Release Date: 5 Feb 2013 7226 Views

RISK: High Risk

High Risk

IBM Products Java Multiple Vulnerabilities

Multiple vulnerabilities have been identifed in various IBM products, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.  The application bundles a vulnerable version of IBM...
Last Update Date: 5 Feb 2013 10:06 Release Date: 5 Feb 2013 7414 Views

RISK: Extremely High Risk

Extremely High Risk

Oracle Java Multiple Vulnerabilities

 Multiple vulnerabilities have been identifed in Oracle Java, which can be exploited by malicious local users to gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, cause denial of service, and compromise a vulnerable system.
Last Update Date: 4 Feb 2013 Release Date: 3 Feb 2013 9442 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been reported in various VMware products (including ESX/ESXi Server, vCenter Server and vSphere Client, etc.), which can be exploited by malicious people to disclose system information, cause denial of service, and potentially compromise a vulnerable system.
Last Update Date: 4 Feb 2013 10:26 Release Date: 4 Feb 2013 7496 Views

RISK: High Risk

High Risk

Oracle Java Flaws Let Remote Execute Arbitrary Code Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java. which can be exploited by remote user to compromise a user's system.   A remote user can create specially crafted Java content that, when loaded by the target user, will execute arbitrary code on the target user...
Last Update Date: 3 Feb 2013 Release Date: 21 Jan 2013 7058 Views

RISK: High Risk

High Risk

Novell GroupWise Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell GroupWise, which can be exploited by malicious people to compromise a user's system.Some unspecified errors can be exploited to dereference untrusted pointers.An unspecified error exists within an ActiveX control.
Last Update Date: 1 Feb 2013 11:51 Release Date: 1 Feb 2013 7235 Views

RISK: High Risk

High Risk

Portable UPnP SDK libupnp `unique_service_name()` Multiple Vulnerabilities

Multiple vulnerabilities have been identified in libupnp (Portable UPnP SDK), which can be exploited by malicious people to execute arbitrary code on the device, cause a denial of service or compromise an application using the library.  The vulnerabilities are caused due to boundary errors within the...
Last Update Date: 1 Feb 2013 Release Date: 30 Jan 2013 7562 Views

RISK: High Risk

High Risk

VLC Media Player ASF Movie Buffer Overflow Vulnerability

A vulnerability has been identified in VLC Media Player. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted ASF movie that, when loaded by the target user, will trigger a...
Last Update Date: 31 Jan 2013 19:17 Release Date: 31 Jan 2013 6558 Views

RISK: High Risk

High Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which can be exploited by malicious people to compromise a user's system. An error when handling certain DOM events can be exploited to execute arbitrary code.An error when handling clipPaths within SVG documents can be exploited to...
Last Update Date: 31 Jan 2013 15:37 Release Date: 31 Jan 2013 6466 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. Errors in the Bluetooth HCI, CSN.1, DCP-ETSI DOCSIS CM-STAUS, IEEE...
Last Update Date: 31 Jan 2013 15:36 Release Date: 31 Jan 2013 6406 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Unspecified Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error when processing certain packets and can be exploited to slow down the processing of legitimate...
Last Update Date: 30 Jan 2013 14:40 Release Date: 30 Jan 2013 6438 Views

RISK: High Risk

High Risk

IBM WebSphere Message Broker Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Message Broker, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause denial of service, and potentially compromise a vulnerable system.   The vulnerabilities exist in the bundled version of Java. ...
Last Update Date: 30 Jan 2013 13:49 Release Date: 30 Jan 2013 6706 Views

RISK: Medium Risk

Medium Risk

Apple TV Kernel Memory Access Vulnerability

Multiple vulnerabilities have been identified in Apple TV, which can be exploited by malicious people to compromise a user's device.
Last Update Date: 30 Jan 2013 13:41 Release Date: 30 Jan 2013 6547 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's device.
Last Update Date: 30 Jan 2013 13:40 Release Date: 30 Jan 2013 7000 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails 3.0 and 2.3 JSON Parser vulnerability

A vulnerability has been identified in Ruby on Rails JSON Parser. The JSON code for Ruby on Rails which allows attackers to bypass authentication systems, inject arbitrary SQL, inject and execute arbitrary code, or perform a DoS attack on a Rails application.   The JSON Parsing...
Last Update Date: 29 Jan 2013 17:04 Release Date: 29 Jan 2013 6883 Views

RISK: High Risk

High Risk

Mass Scam Email Impersonating HKCERT Distributing Malware

HKCERT received an incident report related to a scam email on 25 Jan 2013. The scam email impersonated as HKCERT alert email sent to the public about an extremely critical vulnerability. The sender address of the scam email is "[email protected]", with the...
Last Update Date: 25 Jan 2013 20:00 Release Date: 25 Jan 2013 6648 Views

RISK: Medium Risk

Medium Risk

Barracuda Products SSH backdoor vulnerability

A vulnerability has identified in multiple Barracuda products. A remote user can gain access to the target system.The system includes several undocumented SSH user accounts that cannot be disabled and can be accessed from certain whitelisted IP ranges. At least one account can be exploited to...
Last Update Date: 25 Jan 2013 12:33 Release Date: 25 Jan 2013 6746 Views

RISK: High Risk

High Risk

Cisco Wireless LAN Controller Multipule Vulnerabilities

Multiple vulnerabilities were identified in Cisco Wireless LAN Controller. A remote authenticated user can execute arbitrary code and modify the configuration on the target system, and cause denial of service conditions.A remote user can send specially crafted IP packets to the target device configured with Wireless...
Last Update Date: 24 Jan 2013 12:17 Release Date: 24 Jan 2013 6788 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. A use-after-free error exists when handling canvas font. An error exists when validating the URL when opening new windows. An...
Last Update Date: 24 Jan 2013 12:12 Release Date: 24 Jan 2013 6747 Views

RISK: High Risk

High Risk

Schneider Electric Interactive Graphical SCADA System (IGSS) Buffer Overflow Vulnerability

A vulnerability has been identified in Schneider Electric IGSS application, which can be exploited by malicious people to execute code under administrator credentials on the target system.
Last Update Date: 23 Jan 2013 12:10 Release Date: 23 Jan 2013 6737 Views

RISK: High Risk

High Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remote attackers to cause denial of service, cross site scripting or compromise a vulnerable system.
Last Update Date: 23 Jan 2013 12:01 Release Date: 23 Jan 2013 6544 Views

RISK: High Risk

High Risk

F5 BIG-IP Input Validation Flaws Multiple Vulnerabilities

A vulnerability has been identified in F5 BIG-IP, which can be exploited by malicious people to inject SQL commands or allow an authenticated attacker to download arbitrary files from the file system on the target system.   A remote authenticated user can supply a specially crafted XML...
Last Update Date: 23 Jan 2013 11:56 Release Date: 23 Jan 2013 6667 Views

RISK: High Risk

High Risk

Lenovo ThinkPad Bluetooth with Enhanced Data Rate Software Insecure Library Loading Vulnerability

A vulnerability has been identified in Lenovo Bluetooth with Enhanced Data Rate Software, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load...
Last Update Date: 23 Jan 2013 11:45 Release Date: 23 Jan 2013 6766 Views

RISK: Medium Risk

Medium Risk

SonicWALL Products Two Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in various SonicWALL products, which can be exploited by malicious people to bypass certain security restrictions.An error when handling request for changing users password can be exploited to change the administrator's password.An error within the authentication mechanism in...
Last Update Date: 21 Jan 2013 15:24 Release Date: 21 Jan 2013 6740 Views

RISK: High Risk

High Risk

Foxit Reader Plugin For Browsers URL Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to a boundary error in the Foxit Reader plugin for browsers (npFoxitReaderPlugin.dll) when processing a URL and...
Last Update Date: 18 Jan 2013 Release Date: 9 Jan 2013 7356 Views

RISK: Medium Risk

Medium Risk

Cisco ASA 1000V Cloud Firewall H.323 Inspection Denial of Service Vulnerability

A vulnerability has been identified in Cisco ASA 1000V Cloud Firewall, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an error when inspecting H.323 packets and can be exploited to trigger a reload...
Last Update Date: 18 Jan 2013 09:45 Release Date: 18 Jan 2013 7025 Views

RISK: Extremely High Risk

Extremely High Risk

Oracle Java Unspecified Code Execution Vulnerability

A vulnerability has been identified in Oracle Java, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an unspecified error.
Last Update Date: 17 Jan 2013 Release Date: 11 Jan 2013 18582 Views

RISK: Medium Risk

Medium Risk

Samba Active Directory Domain Controller Access Control Vulnerability

A vulnerability has been identified in Samba. A remote authenticated user can gain write access to certain objects in the target directory. A remote authenticated user can send specially crafted data to trigger a buffer overflow and execute arbitrary code on the target system. The code will...
Last Update Date: 17 Jan 2013 10:00 Release Date: 17 Jan 2013 6971 Views

RISK: High Risk

High Risk

Adobe ColdFusion Multiple Vulerabilities

Multiple vulnerabilities have been identified in Adobe ColdFusion. A remote user can gain access to the target system, and obtain potentially sensitive information. A remote user can bypass authentication and take control of the target system, and gain access to restricted directories. Only systems with...
Last Update Date: 16 Jan 2013 Release Date: 8 Jan 2013 8064 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to execute arbitrary code, conduct denial of service, bypass security restriction, disclose sensitive information or take full control of target systems.
Last Update Date: 16 Jan 2013 09:34 Release Date: 16 Jan 2013 7199 Views

RISK: Medium Risk

Medium Risk

BlackBerry Tablet OS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry Tablet OS, which can be exploited by malicious people to compromise a user's system. Some errors exists due to a vulnerable bundled version of Adobe Flash Player. For more information, please refer to SA12061101, SA12081512 and...
Last Update Date: 15 Jan 2013 10:11 Release Date: 15 Jan 2013 6988 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A buffer overflow vulnerability exists in the bundled version of Adobe Flash Player. A use-after-free error...
Last Update Date: 14 Jan 2013 18:01 Release Date: 14 Jan 2013 7590 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris tcsd Denial of Service Vulnerability

A vulnerability has been identified in Oracle Solaris tcsd, which can be exploited by malicious people to cause a denial of service.
Last Update Date: 11 Jan 2013 09:48 Release Date: 11 Jan 2013 7259 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Includes Fraudulent Digital Certificates Vulnerability

A vulnerability was identified in Microsoft Windows. One fraudulent digital certificate issued by TURKTRUST Inc., which is a CA present in the Trusted Root Certification Authorities Store, could be used to spoof content, perform phishing attacks, or perform man-in-the-middle...
Last Update Date: 10 Jan 2013 Release Date: 4 Jan 2013 8121 Views

RISK: High Risk

High Risk

Asterisk Two Denial of Service Vulnerabilities

Two vulnerabilities have been identified in Asterisk, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service). An error when handling TCP sessions can be exploited to cause a stack overflow and crash the service. An error when handling...
Last Update Date: 10 Jan 2013 Release Date: 4 Jan 2013 7898 Views

RISK: Medium Risk

Medium Risk

VMware ESXi glibc Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESXi, which can be exploited by malicious users to cause a DoS (Denial of Service), potentially gain escalated privileges or compromise a vulnerable system.
Last Update Date: 10 Jan 2013 Release Date: 24 Dec 2012 7131 Views

RISK: Medium Risk

Medium Risk

IBM Tivoli Remote Control / IBM Tivoli Endpoint Manager for Remote Control Java Multiple Vulnerabilities

Multiple vulnerabilities have been indentified in IBM Tivoli Remote Control and IBM Tivoli Endpoint Manager for Remote Control, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
Last Update Date: 10 Jan 2013 Release Date: 21 Dec 2012 7279 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server for z/OS Arbitrary Command Execution Vulnerability

A vulnerability has been reported in IBM WebSphere Application Server for z/OS, which can be exploited by malicious people to compromise a vulnerable system.   The vulnerability is caused due to an unspecified error within the HTTP Server and can be exploited to execute arbitrary commands.
Last Update Date: 10 Jan 2013 Release Date: 21 Dec 2012 7122 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Multiple Font Parsing Vulnerabilities

OpenType Font Parsing Vulnerability A remote code execution vulnerability exists in the way that affected components handle a specially crafted OpenType font file. The vulnerability could allow remote code execution if a user opens a specially crafted OpenType font file. An attacker who successfully exploited this vulnerability could...
Last Update Date: 10 Jan 2013 Release Date: 12 Dec 2012 7793 Views

RISK: High Risk

High Risk

Blue Coat Products OpenSSL DER Format Data Processing Vulnerabilities

Multiple vulnerabilities have been identified in Blue Coat IntelligenceCenter and ProxySG, which can be exploited by malicious people to potentially compromise a vulnerable system.   The vulnerabilities exist in the bundled version of OpenSSL. The vulnerability is caused due to a type casting error in the "asn1_d2i_read_bio...
Last Update Date: 10 Jan 2013 Release Date: 12 Dec 2012 7001 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey. Remoter attackers can exploit the vulnerabilities to conduct remote code execution, elevation of privilege, sensitive information disclosure or modification and spoofing.
Last Update Date: 10 Jan 2013 Release Date: 9 Jan 2013 7276 Views

RISK: High Risk

High Risk

Ruby on Rails Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Ruby on Rails. A remote user can generate unsafe queries, bypass authentication systems, inject SQL commands, inject and execute arbitrary code, and cause denial of service conditions. A remote user can supply a specially crafted data to exploit...
Last Update Date: 10 Jan 2013 10:42 Release Date: 10 Jan 2013 7440 Views

RISK: Medium Risk

Medium Risk

HP OpenVMS Java Vulnerability

Multiple vulnerabilities have been identified in HP OpenVMS, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system. For more information, please refer to SA12101802.
Last Update Date: 9 Jan 2013 16:16 Release Date: 9 Jan 2013 7532 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Driver Improper Message Handling Vulnerability

An elevation of privilege vulnerability exists when the Windows kernel improperly handles window broadcast messages. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new...
Last Update Date: 9 Jan 2013 16:01 Release Date: 9 Jan 2013 7803 Views

RISK: High Risk

High Risk

Microsoft Open Data Protocol Denial of Service Vulnerability

A denial of service vulnerability exists in the OData specification that could allow denial of service. The vulnerability could cause the server or service to stop responding and restart.
Last Update Date: 9 Jan 2013 15:10 Release Date: 9 Jan 2013 7056 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the way that the Microsoft Windows SSL/TLS (Secure Socket Layer and Transport Layer Security) handle the SSL version 3 (SSLv3) and TLS protocols. The vulnerability could allow security feature bypass if an attacker injects specially crafted...
Last Update Date: 9 Jan 2013 15:10 Release Date: 9 Jan 2013 7728 Views