Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities

System Drawing Information Disclosure Vulnerability An information disclosure vulnerability exists in the way the Windows Forms in .NET Framework handles pointers to unmanaged memory locations. WinForms Buffer Overflow Vulnerability An elevation of privilege vulnerability exists in the way that a Windows Forms method included in the .NET...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7561 Views

RISK: Medium Risk

Medium Risk

Microsoft System Center Operations Manager Web Console Multiple XSS Vulnerabilities

Two cross-site scripting (XSS) vulnerabilities exist in System Center Operations Manager that could allow specially crafted script code to run under the guise of the server. These are non-persistent cross-site scripting vulnerabilities that could allow an attacker to issue commands to...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7557 Views

RISK: High Risk

High Risk

Microsoft XML Core Services Multiple Vulnerabilities

MSXML Integer Truncation Vulnerability A remote code execution vulnerability exists in the way that Microsoft Windows parses XML content. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the logged-on user. MSXML XSLT Vulnerability...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7878 Views

RISK: High Risk

High Risk

Microsoft Windows Print Spooler Components Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows Print Spooler handles specially crafted print jobs. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code.
Last Update Date: 9 Jan 2013 15:08 Release Date: 9 Jan 2013 7833 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system. A local user can obtain elevated privileges on the target system. A user can bypass security restrictions. A remote...
Last Update Date: 9 Jan 2013 14:19 Release Date: 9 Jan 2013 7156 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to cause a buffer overflow. Successful exploitation may...
Last Update Date: 9 Jan 2013 14:17 Release Date: 9 Jan 2013 7244 Views

RISK: High Risk

High Risk

Symantec PGP Desktop Elevated Privileges Vulnerability

A vulnerability has been identified in Symantec PGP Desktop. A local user can obtain elevated privileges on the target system.   A local user can issue a specially crafted IOCTL 0x80022058 request to execute arbitrary code on the target system with system level privileges.  Note: Vendor patch...
Last Update Date: 8 Jan 2013 10:34 Release Date: 8 Jan 2013 7751 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Method Parameters SQL Injection Vulnerability

Multiple vulnerabilities have been identified in Ruby on Rails, which can be exploited by malicious people to conduct SQL injection attacks.   Input passed to the Active Record interface via method parameters is not properly sanitised before being used in SQL queries. This can be exploited to manipulate...
Last Update Date: 4 Jan 2013 15:41 Release Date: 4 Jan 2013 6917 Views

RISK: High Risk

High Risk

VLC Media Player HTML Subtitle Parsing Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in  VLC Media Player, which can be exploited by malicious people to compromise a user's system.   The vulnerabilities are caused due to errors when parsing HTML subtitles in modules/codec/subsdec.c and can be exploited to...
Last Update Date: 2 Jan 2013 Release Date: 31 Dec 2012 7362 Views

RISK: Medium Risk

Medium Risk

FreeType BDF Glyph Processing Buffer Overflow Vulnerability

A vulnerability has been identified in FreeType, which can be exploited by malicious people to potentially compromise an application using the library.   The vulnerability is caused due to an error in the "_bdf_parse_glyphs()" function (src/bdf/bdflib.c) when processing glyph...
Last Update Date: 28 Dec 2012 12:02 Release Date: 28 Dec 2012 6912 Views

RISK: Medium Risk

Medium Risk

GNU grep Long Line Handling Integer Overflow Vulnerability

A vulnerability has been identified in grep, which can be exploited by malicious people to potentially compromise a user's system.   The vulnerability is caused due to an integer overflow error when parsing very long lines and can be exploited to cause a heap-based buffer...
Last Update Date: 28 Dec 2012 12:02 Release Date: 28 Dec 2012 6905 Views

RISK: Medium Risk

Medium Risk

VMware vCenter Server Appliance Directory Traversal Vulnerability

Two vulnerabilities have been identified in VMware vCenter Server Appliance, which can be exploited by remote authenticated user to view files on the target system.A remote authenticated user can supply a specially crafted request to retrieve arbitrary files from the target system.A remote authenticated user...
Last Update Date: 24 Dec 2012 11:11 Release Date: 24 Dec 2012 6996 Views

RISK: Medium Risk

Medium Risk

IBM InfoSphere Streams Java Multiple Vulnerabilities

Multiple vulnerabilities have been indentified in IBM InfoSphere Streams, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Last Update Date: 21 Dec 2012 17:21 Release Date: 21 Dec 2012 6924 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player. which can be exploited by remote user to compromise a vulnerable system. A remote user can create specially crafted Shockwave content that specifies an older version (10.x) of Shockwave and, when loaded by the...
Last Update Date: 21 Dec 2012 17:19 Release Date: 21 Dec 2012 6936 Views

RISK: High Risk

High Risk

Nagios history.cgi "get_history()" Buffer Overflow Vulnerability

A vulnerability has been identified in Nagios, which can be exploited by malicious people to compromise a vulnerable system.   The vulnerability is caused due to a boundary error within the "get_history()" function (history.c) within history.cgi when handling certain parameters, ...
Last Update Date: 20 Dec 2012 10:12 Release Date: 20 Dec 2012 8354 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Java included in Solaris, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.   For more information, please refer to...
Last Update Date: 20 Dec 2012 10:12 Release Date: 20 Dec 2012 6717 Views

RISK: Medium Risk

Medium Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been indentified in RealPlayer, which can be exploited by malicious people to compromise a user's system. An error when handling RealAudio files may result in dereferencing an invalid pointer, and can be exploited to cause a buffer overflow. Successful exploitation of...
Last Update Date: 18 Dec 2012 09:56 Release Date: 18 Dec 2012 6943 Views

RISK: Medium Risk

Medium Risk

VMware View Connection/Security Server Directory Traversal Vulnerability

A vulnerability has been identified in VMware View, which can be exploited by malicious people to disclose sensitive information. The vulnerability is caused due to an error within the View Connection Server and View Security Server and can be exploited to disclose arbitrary files via directory traversal attacks...
Last Update Date: 17 Dec 2012 10:52 Release Date: 17 Dec 2012 7026 Views

RISK: High Risk

High Risk

Adobe Camera Raw Plug-in TIFF Image Processing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Camera Raw Plug-in, which can be exploited by malicious people to compromise a user's system.An error in the "Camera Raw.8bi" plug-in when processing a LZW compressed TIFF image can be...
Last Update Date: 14 Dec 2012 11:03 Release Date: 14 Dec 2012 7143 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which can be exploited when viewing maliciously crafted PICT, TeXML, Targa or movie files and website to cause application termination or arbitrary code execution.  
Last Update Date: 13 Dec 2012 10:38 Release Date: 13 Dec 2012 7113 Views

RISK: Medium Risk

Medium Risk

Citrix XenApp XML Service Interface Vulnerability

A vulnerability has been identified in Citrix XenApp. A remote user can execute arbitrary code on the target system. A remote user can send specially crafted data to trigger a flaw in the XML Service interface and execute arbitrary code on the target system. The code will...
Last Update Date: 13 Dec 2012 10:34 Release Date: 13 Dec 2012 6979 Views

RISK: High Risk

High Risk

VLC Media Player SWF Video Decoding Use-After-Free Vulnerability

A vulnerability has been identified in VLC Media Player, which can be exploited by malicious people to potentially compromise a user's system.   The vulnerability is caused due to a use-after-free error when releasing a picture object during video decoding of Flash (...
Last Update Date: 13 Dec 2012 10:31 Release Date: 13 Dec 2012 7355 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Revoked Certificate Bypass Vulnerability

A security feature bypass vulnerability exists in Windows due to the way the IP-HTTPS Component handles certificates. An attacker who successfully exploited this vulnerability could bypass certificate validation checks.
Last Update Date: 12 Dec 2012 14:51 Release Date: 12 Dec 2012 6928 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectPlay Heap Overflow Vulnerability

A remote code execution vulnerability exists in the way that DirectPlay handles specially crafted content. The vulnerability could allow remote code execution if an attacker convinces a user to view a specially crafted Office document with embedded content. An attacker who successfully exploited this vulnerability could take complete...
Last Update Date: 12 Dec 2012 14:51 Release Date: 12 Dec 2012 7067 Views

RISK: High Risk

High Risk

Microsoft Windows Filename Parsing Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows parses filenames. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 12 Dec 2012 14:51 Release Date: 12 Dec 2012 7675 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Denial of Service Vulnerability

A denial of service vulnerability exists in Microsoft Exchange Server when Exchange improperly handles RSS feeds. The vulnerability could cause the Information Store service on the affected system to become unresponsive until the process is forcibly terminated. This unresponsive condition could cause Exchange databases to dismount, and...
Last Update Date: 12 Dec 2012 14:50 Release Date: 12 Dec 2012 6937 Views

RISK: High Risk

High Risk

Microsoft Word RTF `listoverridecount` Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that affected Microsoft Office software parses specially crafted Rich Text Format (RTF) data. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 12 Dec 2012 14:50 Release Date: 12 Dec 2012 7706 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

InjectHTMLStream Use After Free Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current...
Last Update Date: 12 Dec 2012 14:31 Release Date: 12 Dec 2012 7617 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Bypass Sandbox Restrictions Vulnerability

A vulnerability has been identified in Adobe ColdFusion. A local user can obtain elevated privileges on the target system.  A remote authenticated user or a local user may be able to violate sandbox permissions in a shared hosting environment.
Last Update Date: 12 Dec 2012 14:13 Release Date: 12 Dec 2012 6873 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user. A buffer...
Last Update Date: 12 Dec 2012 14:07 Release Date: 12 Dec 2012 6863 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.   The vulnerabilities exist in the bundled version of Java.   For more information, please refer to SA12111501.
Last Update Date: 11 Dec 2012 10:14 Release Date: 11 Dec 2012 7795 Views

RISK: Medium Risk

Medium Risk

ISC BIND DNS64 REQUIRE Assertion Failure Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the DNS64 IPv6 transition mechanism when handling certain queries, which can be exploited to trigger...
Last Update Date: 7 Dec 2012 Release Date: 6 Dec 2012 7892 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Multiple Vulnerabilities

Some vulnerabilities have been identified in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).An error within the NIO connector when transferring files using sendfile over HTTPS can be exploited to trigger an infinite...
Last Update Date: 7 Dec 2012 Release Date: 6 Dec 2012 8069 Views

RISK: High Risk

High Risk

Opera GIF Image Handling Buffer Underflow Vulnerability

A vulnerability has been identified in Opera, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an error when decoding image data and can be exploited to cause a heap-based buffer underflow via a...
Last Update Date: 7 Dec 2012 Release Date: 6 Dec 2012 7924 Views

RISK: Medium Risk

Medium Risk

F5 FirePass SSL VPN Remote Code Execution Vulnerability

Multiple vulnerabilities have been identified in F5 FirePass, which can be exploited by malicious user to include and execute PHP code on the target system.   The 'CitrixAuth.php' script does not properly validate user-supplied input in the 'sessionId' parameter. A...
Last Update Date: 5 Dec 2012 10:26 Release Date: 5 Dec 2012 8077 Views

RISK: Medium Risk

Medium Risk

Oracle MySQL Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in MySQL, which can be exploited by malicious users to cause a DoS (Denial of Service) and compromise a vulnerable system and by malicious people to conduct brute force attacks.An error when processing a database name within certain functions when...
Last Update Date: 4 Dec 2012 11:15 Release Date: 4 Dec 2012 8047 Views

RISK: High Risk

High Risk

Google Chrome Two Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome,  where one has an unknown impact and the other can be exploited by malicious people to compromise a user's system. An error exists when handling file paths. A use-after-free error exists when handling...
Last Update Date: 3 Dec 2012 11:39 Release Date: 3 Dec 2012 7832 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service). An error in the USB dissector (epan/dissectors/packet-usb.c) can be exploited to cause an infinite loop and...
Last Update Date: 30 Nov 2012 Release Date: 29 Nov 2012 7157 Views

RISK: Medium Risk

Medium Risk

Apple TV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which can be exploit by malicious user to execute arbitrary code, access privilaged data and cause denial of service. An information disclosure issue existed in the handling of APIs related to kernel extensions. Responses containing a OSBundleMachOHeaders key...
Last Update Date: 30 Nov 2012 10:46 Release Date: 30 Nov 2012 6882 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where one has an unknown impact and others can be exploited by malicious people to compromise a user's system.A use-after-free error exists in SVG filters.An out-of-bounds read...
Last Update Date: 28 Nov 2012 10:08 Release Date: 28 Nov 2012 6822 Views

RISK: High Risk

High Risk

Samsung Printer firmware contains a backdoor administrator account vulnerability

A vulnerability has been identified on Samsung Printer firmware, which can be exploited by remote attacker to take control of an affected device.   Samsung printers (as well as some Dell printers manufactured by Samsung) contain a hardcoded SNMP full read-write community string that...
Last Update Date: 27 Nov 2012 10:58 Release Date: 27 Nov 2012 6999 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere DataPower XC10 Appliance Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere DataPower XC10 Appliance, which can be exploited by remote authenticated user can gain administrative privileges or cause denial of service conditions. A remote authenticated user can send specially crafted data to execute arbitrary JMX operations on the target system. ...
Last Update Date: 23 Nov 2012 11:06 Release Date: 23 Nov 2012 7091 Views

RISK: Medium Risk

Medium Risk

Oracle Solaris Libxml2 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Libxml2 included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Last Update Date: 22 Nov 2012 13:34 Release Date: 22 Nov 2012 6832 Views

RISK: Medium Risk

Medium Risk

Symantec Products KeyView File Processing Vulnerabilities

Multiple vulnerabilities have been identified in Symantec products, which can be exploited by malicious people to compromise a vulnerable system.   For more information, please refer to SA12112201.
Last Update Date: 22 Nov 2012 13:33 Release Date: 22 Nov 2012 7079 Views

RISK: Medium Risk

Medium Risk

Autonomy KeyView File Processing Vulnerabilities

Multiple vulnerabilities have been identified in Autonomy KeyView, which can be exploited by malicious people to compromise a vulnerable system. The vulnerabilities are caused due to errors when processing unspecified file formats and can be exploited to corrupt memory.  Successful exploitation may allow execution of arbitrary code...
Last Update Date: 22 Nov 2012 13:33 Release Date: 22 Nov 2012 7132 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which can be exploited by malicious people to execute arbitrary code, perform cross-site scripting (XSS) attack,and disclose sensitive information
Last Update Date: 21 Nov 2012 10:48 Release Date: 21 Nov 2012 6963 Views

RISK: High Risk

High Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which can be exploited by malicious people to disclose certain sensitive information and compromise a user's system.The vulnerability is caused due to an error when handling HTTP responses and can be exploited to cause a heap-based...
Last Update Date: 21 Nov 2012 10:47 Release Date: 21 Nov 2012 7162 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Denial of Service Vulnerability

A vulnerability has been identified in Adobe ColdFusion, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error when running on Internet Information Services (IIS).
Last Update Date: 21 Nov 2012 10:25 Release Date: 21 Nov 2012 7154 Views

RISK: Medium Risk

Medium Risk

Splunk Multiple Vulnerabilities

Some vulnerabilities have been identified in Splunk, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service). Certain unspecified input passed to the Splunk Web component is not properly sanitised before being returned to the user...
Last Update Date: 20 Nov 2012 17:36 Release Date: 20 Nov 2012 7026 Views

RISK: High Risk

High Risk

Apple Mac OS X Remote Code Execution Vulnerability

A vulnerability has been identified in Apple Mac OS X, which can be exploited by remote attackers to execute arbitrary code.  Note: Currently, no patch is avaliable. 
Last Update Date: 20 Nov 2012 17:26 Release Date: 20 Nov 2012 7089 Views

RISK: High Risk

High Risk

Apache Tomcat Multiple Vunerabilities

Multipule vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service). An error within the "parseHeaders()" function (InternalNioInputBuffer.java) when parsing request headers does not properly...
Last Update Date: 20 Nov 2012 Release Date: 7 Nov 2012 8122 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server, which can be exploited by malicious, local users to potentially disclose sensitive information and by malicious people to disclose potentially sensitive information, conduct spoofing and cross-site scripting attacks, and cause a DoS (Denial of...
Last Update Date: 19 Nov 2012 10:44 Release Date: 19 Nov 2012 7046 Views

RISK: High Risk

High Risk

IBM Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various IBM products, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.   The vulnerabilities are caused due to the application bundling a vulnerable version of Java. For details, please refer...
Last Update Date: 16 Nov 2012 18:00 Release Date: 16 Nov 2012 7499 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.   Some errors in the "invoke()" (java.lang.reflect.Method), "getDeclaredMethods()" (java.lang....
Last Update Date: 15 Nov 2012 10:25 Release Date: 15 Nov 2012 7281 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

CFormElement Use After Free Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary...
Last Update Date: 14 Nov 2012 17:21 Release Date: 14 Nov 2012 6993 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Remote Code Execution Multiple Vulnerabilities

Windows Briefcase Integer Underflow Vulnerability A remote code execution vulnerability exists in the Briefcase feature in Windows. An attacker could exploit the vulnerability by convincing a user to open a specially crafted briefcase. An attacker who successfully exploited this vulnerability could execute arbitrary code...
Last Update Date: 14 Nov 2012 17:21 Release Date: 14 Nov 2012 6913 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) Two Information Disclosure Vulnerabilities

Password Disclosure Vulnerability An information disclosure vulnerability exists when Microsoft Internet Information Services (IIS) fails to properly protect log files. FTP Command Injection VulnerabiliyAn information disclosure vulnerability exists in the way that Microsoft Internet Information Services (IIS) FTP Service negotiates encrypted ...
Last Update Date: 14 Nov 2012 17:21 Release Date: 14 Nov 2012 6980 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Multiple Vulnerabilities

Reflection Bypass Vulnerability An elevation of privilege vulnerability exists in the way that .NET Framework validates the permissions of certain objects performing reflection. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 14 Nov 2012 17:20 Release Date: 14 Nov 2012 6866 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Three Vulnerabilities

Win32k Use After Free Vulnerability An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change...
Last Update Date: 14 Nov 2012 17:20 Release Date: 14 Nov 2012 7048 Views

RISK: High Risk

High Risk

Microsoft Office Excel Multiple Vulnerabilities

Excel SerAuxErrBar Heap Overflow Vulnerability A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 14 Nov 2012 17:18 Release Date: 14 Nov 2012 6820 Views

RISK: Medium Risk

Medium Risk

VMware Workstation / Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware Workstation and VMware Player, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a user's system. An error due to insecure permissions being assigned to process threads when creating...
Last Update Date: 14 Nov 2012 Release Date: 12 Nov 2012 7179 Views

RISK: High Risk

High Risk

IrfanView TIFF Image Decompression Buffer Overflow Vulnerability

A vulnerability has been identified in IrfanView, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error when processing JPEG compressed TIFF images and can be exploited to cause a heap-based buffer overflow via...
Last Update Date: 14 Nov 2012 Release Date: 12 Nov 2012 7260 Views

RISK: High Risk

High Risk

Cisco IronPort Appliance Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IronPort Web Security Appliance and Cisco IronPort Email Security Appliance, which can be exploited by malicious people to compromise a vulnerable device.   The vulnerabilities are caused due to a bundled vulnerable version of Sophos Engine.
Last Update Date: 14 Nov 2012 Release Date: 12 Nov 2012 7460 Views

RISK: High Risk

High Risk

Sophos Anti-Virus Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sophos Anti-Virus, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct cross-site scripting attacks and compromise a user's system. An integer overflow error when scanning a...
Last Update Date: 9 Nov 2012 Release Date: 6 Nov 2012 7085 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which can be exploited by malicious people to compromise a user's system. A boundary error when processing a PICT file can be exploited to cause a buffer overflow. An error when processing a PICT file can be...
Last Update Date: 9 Nov 2012 11:26 Release Date: 9 Nov 2012 7031 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. The application bundles a vulnerable version of Adobe Flash Player. For more information, please refer to SA12110801.An...
Last Update Date: 8 Nov 2012 11:56 Release Date: 8 Nov 2012 8007 Views

RISK: Medium Risk

Medium Risk

Cisco Secure Access Control System Password Validation Vulnerability

A vulnerability has been identified in Cisco Secure Access Control System. A remote user can bypass TACACS+ authentication. The system does not properly validate user-supplied passwords when TACACS+ is the authentication protocol and the Cisco Secure Access Control System (ACS) is configured...
Last Update Date: 8 Nov 2012 11:24 Release Date: 8 Nov 2012 7081 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted Flash content that, when loaded by the target user, will execute arbitrary code...
Last Update Date: 8 Nov 2012 10:23 Release Date: 8 Nov 2012 7980 Views

RISK: Medium Risk

Medium Risk

VLC media player denial of service vulnerability

A vulnerability was identified in VLC media player, which can be exploited by malicious people to cause denial of service condition.   When parsing an invalid PNG image file, a buffer overflow might occur. If successful, a malicious third party could trigger an invalid memory access...
Last Update Date: 7 Nov 2012 12:58 Release Date: 7 Nov 2012 8206 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, where some have unknown impacts and other can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.An unspecified error when handling CORS (Cross...
Last Update Date: 7 Nov 2012 12:53 Release Date: 7 Nov 2012 7776 Views

RISK: Medium Risk

Medium Risk

Symantec Antivirus products CAB files Vulnerability

A vulnerability has been identified in multiple Symantec Antivirus products, which can be exploited by a remote, unauthenticated attacker to execute arbitrary code with SYSTEM privileges.  The CAB file decomposer component that is used by multiple Symantec Antivirus products fails to properly handle malformed CAB files, ...
Last Update Date: 6 Nov 2012 10:33 Release Date: 6 Nov 2012 8133 Views

RISK: High Risk

High Risk

Apple iOS Multiple vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by attacker to bypass the screen lock, access potentially sensitive information or compromise a user's system.A remote user can create specially crafted HTML that, when loaded by the target user, ...
Last Update Date: 5 Nov 2012 Release Date: 2 Nov 2012 8050 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to compromise a user's system. A race condition error exists within the webkit component when handling JavaScript arrays and can be exploited to execute arbitrary code. A use-after...
Last Update Date: 5 Nov 2012 09:38 Release Date: 5 Nov 2012 7835 Views

RISK: Medium Risk

Medium Risk

Cisco Prime Data Center Network Manager JBoss RMI Services Vulnerability

A vulnerability has been identified in Cisco Prime Data Center Network Manager, which can be exploited by remote user to execute arbitrary commands on the target system.   A remote user can send specially crafted data to JBoss Application Server Remote Method Invocation (RMI) services to execute...
Last Update Date: 1 Nov 2012 11:37 Release Date: 1 Nov 2012 7718 Views

RISK: Medium Risk

Medium Risk

Cisco Unified MeetingPlace Web Conferencing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Unified MeetingPlace Web Conferencing, which can be exploited by remote user to cause a DoS (Denial of Service) and disclose sensitive information. A remote user can send specially crafted HTTP POST data to trigger a buffer overflow and cause...
Last Update Date: 1 Nov 2012 11:34 Release Date: 1 Nov 2012 7827 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey, which can be exploited by remote user to conduct cross-site scripting attacks or compromise a user's system. A remote user can exploit the valueOf() method of window.location to, ...
Last Update Date: 1 Nov 2012 Release Date: 29 Oct 2012 7384 Views

RISK: Medium Risk

Medium Risk

CA ARCserve Backup Multiple Vulnerabilities

Multiple vulnerabilities have been identified in CA ARCserve Backup. A remote user can execute arbitrary code on the target system and cause denial of service conditions. A remote user can send specially crafted RPC requests to execute arbitrary code on the target system. The code will run...
Last Update Date: 1 Nov 2012 Release Date: 22 Oct 2012 7089 Views

RISK: Medium Risk

Medium Risk

3Com, HP, and H3C Routers and Switches SNMP Configuration Vulnerability

A vulnerability was identified in 3Com, HP, and H3C routers and switches. A remote user can take administrative actions on the target system. A remote user with knowledge of the SNMP public community string can access potentially sensitive data (e.g., user names...
Last Update Date: 25 Oct 2012 16:09 Release Date: 25 Oct 2012 7986 Views

RISK: High Risk

High Risk

ISC BIND Record Handling Lockup Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when handling queries for certain records and can be exploited to cause the named process to lockup...
Last Update Date: 25 Oct 2012 Release Date: 11 Oct 2012 7063 Views

RISK: Medium Risk

Medium Risk

F5 FirePass SQL Injection and Redirection Vulnerabilities

Multiple vulnerabilities have been identified in F5 FirePass, which can be exploited by malicious people to conduct spoofing and SQL injection attacks. Input passed via the "refreshURL" parameter to my.activation.cns.php3 is not properly verified before being used to redirect users...
Last Update Date: 24 Oct 2012 11:24 Release Date: 24 Oct 2012 7468 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow...
Last Update Date: 24 Oct 2012 11:23 Release Date: 24 Oct 2012 7020 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which can be exploited by malicious people to compromise a user's system.   For details, please refer to SA12101802.  
Last Update Date: 22 Oct 2012 10:21 Release Date: 22 Oct 2012 6896 Views

RISK: High Risk

High Risk

Novell ZENworks Asset Management Arbitrary Files Disclosure Vulnerability

A vulnerability has been identified in Novell ZENworks Asset Management. A remote user can view arbitrary files on the target system.   A remote user can use hard-coded credentials when invoking a maintenance function to read files on the target system with System privileges. The HandleMaintenanceCalls...
Last Update Date: 19 Oct 2012 09:55 Release Date: 19 Oct 2012 7090 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities were identified in Oracle Java Runtime Environment (JRE). A remote user can take full control of the target system. A remote user can access and modify data and cause partial denial of service conditions on the target system. A remote user can create specially...
Last Update Date: 19 Oct 2012 Release Date: 18 Oct 2012 7714 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to conduct cross-site scripting attacks, denial of service, bypass security restriction, disclose sensitive information and tampering. 
Last Update Date: 18 Oct 2012 14:45 Release Date: 18 Oct 2012 7176 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Java for Mac OS X, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system. For more information:: SA12101802
Last Update Date: 18 Oct 2012 14:40 Release Date: 18 Oct 2012 6951 Views

RISK: High Risk

High Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities were identified in Solaris. A local user can obtain root privileges on the target system. A remote user can cause denial of service conditions. A local user can cause denial of service conditions. A remote user can send specially crafted data to cause denial...
Last Update Date: 18 Oct 2012 14:37 Release Date: 18 Oct 2012 7137 Views

RISK: Medium Risk

Medium Risk

Multi-vendor IP camera web interface authentication bypass Vulnerability

A vulnerability has been identified in web interface for IP cameras from several vendors including Foscam and Wansview, which can be exploited by malicious people to cause an authentication bypass. By visiting specific URLs, an attacker may be able to perform any function a normal user can...
Last Update Date: 16 Oct 2012 10:05 Release Date: 16 Oct 2012 8945 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. The protected "location" object is accessible by other domain objects, which can be...
Last Update Date: 15 Oct 2012 11:27 Release Date: 15 Oct 2012 7617 Views

RISK: High Risk

High Risk

Google Chrome Two Vulnerabilities

Two vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A use-after-free error in Webkit's SVG (Scalable Vector Graphics) functionality can be exploited...
Last Update Date: 12 Oct 2012 11:39 Release Date: 12 Oct 2012 7689 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities reported in Mozilla Firefox, Seamonkey and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, inject scripting code, and spoof portions of the page. A remote user can create specially crafted content that, ...
Last Update Date: 12 Oct 2012 Release Date: 11 Oct 2012 7188 Views

RISK: Medium Risk

Medium Risk

OpenVMS Secure Web Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified with HP Secure Web Server (SWS) for OpenVMS. The vulnerabilities could be remotely exploited to create a Denial of Service (DoS), unauthorized access, or unauthorized disclosure of information.
Last Update Date: 11 Oct 2012 14:31 Release Date: 11 Oct 2012 7057 Views

RISK: Medium Risk

Medium Risk

Cisco ASA Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco ASA. A remote user can execute arbitrary code on the target system, and cause denial of service conditions. A remote user can send specially crafted DHCP data via IPv4 to the DHCP server on the target device or through the...
Last Update Date: 11 Oct 2012 11:42 Release Date: 11 Oct 2012 7331 Views

RISK: Medium Risk

Medium Risk

Cisco Firewall Services Module Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Firewall Services Module. A remote user can execute arbitrary code on the target system, and cause denial of service conditions. A remote user can send specially crafted DCERPC data through the target device to trigger a stack overflow in the...
Last Update Date: 11 Oct 2012 11:40 Release Date: 11 Oct 2012 7215 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Player Buffer Overflow Vulnerability

Multiple vulnerabilities have been identified in Cisco WebEx Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted WRF file that, when loaded by the target user, will trigger a buffer...
Last Update Date: 11 Oct 2012 10:49 Release Date: 11 Oct 2012 7319 Views

RISK: High Risk

High Risk

Microsoft SQL Server Reflected XSS Vulnerability

A reflected XSS vulnerability exists in SQL Server Report Manager that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take...
Last Update Date: 10 Oct 2012 15:45 Release Date: 10 Oct 2012 6853 Views

RISK: High Risk

High Risk

Microsoft Windows Kerberos NULL Dereference Vulnerability

A denial of service vulnerability exists when the Microsoft Kerberos implementation fails to properly handle a specially crafted session. An attacker who successfully exploited this vulnerability could cause the system to stop responding and restart.
Last Update Date: 10 Oct 2012 15:44 Release Date: 10 Oct 2012 6910 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel Integer Overflow Vulnerability

An elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts...
Last Update Date: 10 Oct 2012 15:42 Release Date: 10 Oct 2012 6945 Views

RISK: Medium Risk

Medium Risk

Microsoft FAST Search Server 2010 for SharePoint Multiple Vulnerabilities

Remote code execution vulnerabilities exist in FAST Search Server 2010 for SharePoint using the Advanced Filter Pack, an attacker could run arbitrary code in the context of a user account with a restricted token. By default, Advanced Filter Pack in FAST is disabled.
Last Update Date: 10 Oct 2012 15:40 Release Date: 10 Oct 2012 7659 Views

RISK: High Risk

High Risk

Microsoft Office and SharePoint Products HTML Sanitization Vulnerability

An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Last Update Date: 10 Oct 2012 15:39 Release Date: 10 Oct 2012 7853 Views