Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Works Heap Vulnerability

A remote code execution vulnerability exists in the way that affected versions of Microsoft Works parse specially crafted Word files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 10 Oct 2012 15:38 Release Date: 10 Oct 2012 7677 Views

RISK: High Risk

High Risk

Microsoft Word Multiple Vulnerabilities

Word PAPX Section Corruption Vulnerability A remote code execution vulnerability exists in the way that Microsoft Word handles specially crafted Word files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 10 Oct 2012 15:36 Release Date: 10 Oct 2012 7786 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the...
Last Update Date: 9 Oct 2012 14:38 Release Date: 9 Oct 2012 7715 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by remote attackers to execute arbitray code.   The product contains buffer overflow and memory corruption vulnerabilites, which could lead to code execution.
Last Update Date: 9 Oct 2012 10:15 Release Date: 9 Oct 2012 7974 Views

RISK: Medium Risk

Medium Risk

McAfee Firewall Enterprise BIND Resource Record Denial of Service Vulnerability

A vulnerability has been identified in McAfee Firewall Enterprise, which can be exploited by malicious people to cause a DoS (Denial of Service).   Please refer to SA12091401 for details.
Last Update Date: 5 Oct 2012 09:41 Release Date: 5 Oct 2012 8245 Views

RISK: Medium Risk

Medium Risk

Apple OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X Server, which can be exploited to disclose sensitive information. Vulnerabilities in PostgreSQL may allow database users to read files from the file system with the privileges of the database server role account. An attacker may cause the Jabber...
Last Update Date: 4 Oct 2012 15:00 Release Date: 4 Oct 2012 7917 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark. A remote user can cause denial of service conditions. A remote user can send specially crafted HSRP data to cause the target dissector to enter an infinite loop. A remote user can send specially crafted PPP data to cause the...
Last Update Date: 4 Oct 2012 15:00 Release Date: 4 Oct 2012 7991 Views

RISK: High Risk

High Risk

Google Android Dialer TEL URL Handling Vulnerability

A vulnerability has been identified in Google Android. A remote user can cause denial of service conditions.   A remote user can create a specially crafted 'TEL' protocol URL that, when loaded by the target user, will execute unstructured supplementary service data (USSD) ...
Last Update Date: 3 Oct 2012 10:29 Release Date: 3 Oct 2012 8553 Views

RISK: Medium Risk

Medium Risk

HP-UX OpenSSL Denial of Service Vulnerability

A vulnerability has been identified in HP-UX OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) of the application using the library.The vulnerability is reported in HP-UX versions B.11.11, B...
Last Update Date: 28 Sep 2012 16:10 Release Date: 28 Sep 2012 7529 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. Certain unspecified input related to frame...
Last Update Date: 27 Sep 2012 16:28 Release Date: 27 Sep 2012 7439 Views

RISK: High Risk

High Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS and Unified Communications Manager. A remote user can cause denial of service conditions.
Last Update Date: 27 Sep 2012 16:27 Release Date: 27 Sep 2012 7106 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Insecure Library Loading Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the application loading libraries (fxdecod1.dll) in an insecure manner. This can be exploited to load...
Last Update Date: 27 Sep 2012 10:15 Release Date: 27 Sep 2012 7228 Views

RISK: High Risk

High Risk

phpMyAdmin Compromised Source Package Backdoor Vulnerability

A vulnerability has been identified in phpMyAdmin, which can be exploited by malicious people to compromise a vulnerable system.  One of the SourceForge.net mirrors, namely cdnetworks-kr-1, was being used to distribute a modified archive of phpMyAdmin, which includes a...
Last Update Date: 26 Sep 2012 11:51 Release Date: 26 Sep 2012 7470 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer 10 Multipule Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash libraries contained within Internet Explorer 10, which can be exploited by malicious people to execute arbitarty code and cause denial of service with user interaction. 
Last Update Date: 25 Sep 2012 11:58 Release Date: 25 Sep 2012 6806 Views

RISK: Medium Risk

Medium Risk

Oracle Database Authentication Protocol Vulnerability

A vulnerability was identiified in Oracle Database. A remote user can determine user password hashes. A remote user can send a few specially crafted network packets to obtain information about the session key and cryptographic salt for a target user. The information can be used to determine...
Last Update Date: 25 Sep 2012 11:56 Release Date: 25 Sep 2012 7015 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

OnMove Use After Free Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has not been correctly initialized or has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code...
Last Update Date: 24 Sep 2012 Release Date: 18 Sep 2012 7337 Views

RISK: High Risk

High Risk

Cisco Secure Desktop WebLaunch Vulnerability

A vulnerability has been identified in Cisco Secure Desktop, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to the WebLaunch functionality not properly authenticating the validity of downloaded executables and can be exploited to download and execute...
Last Update Date: 21 Sep 2012 12:10 Release Date: 21 Sep 2012 7666 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions, gain knowledge of sensitive information, or compromise a user's system. 
Last Update Date: 21 Sep 2012 12:09 Release Date: 21 Sep 2012 7103 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which can be exploited by malicious people to execute arbitrary code, obtain sensitive information, operate with elevated privileges, cause a denial-of-service condition or compromise a user's system.
Last Update Date: 21 Sep 2012 12:09 Release Date: 21 Sep 2012 7031 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious, local users to disclose system information and gain escalated privileges, by malicious people to disclose potentially sensitive information, conducts spoofing attacks, and compromise a user's device, and by...
Last Update Date: 21 Sep 2012 12:09 Release Date: 21 Sep 2012 8401 Views

RISK: Medium Risk

Medium Risk

OpenJPEG JPEG2000 Image Processing Buffer Overflow Vulnerability

A vulnerability has been identified in OpenJPEG, which can be exploited by malicious people to potentially compromise an application using the library. The vulnerability is caused due to an error when decoding images and can be exploited to cause a heap-based buffer overflow...
Last Update Date: 20 Sep 2012 Release Date: 30 Aug 2012 7477 Views

RISK: Medium Risk

Medium Risk

SumatraPDF Document Processing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in SumatraPDF, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to unspecified errors when processing PDF files and can be exploited to corrupt memory. Successful exploitation may allow execution of arbitrary...
Last Update Date: 20 Sep 2012 10:40 Release Date: 20 Sep 2012 7538 Views

RISK: Medium Risk

Medium Risk

Google SketchUp SKP File Processing Vulnerability

A vulnerability has been identified in Google SketchUp, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when processing SKP files and can be exploited to corrupt memory. Successful exploitation may allow execution...
Last Update Date: 20 Sep 2012 10:37 Release Date: 20 Sep 2012 7261 Views

RISK: Medium Risk

Medium Risk

Windows Phone Certificate Validation Vulnerability

A vulnerability has been identified in Windows Phone 7,  a remote user can spoof secure e-mail servers in certain cases.   The software does not validate Common Name (CN) values of mail server SSL certificates when sending or retrieving email via POP3, IMAP, ...
Last Update Date: 19 Sep 2012 10:35 Release Date: 19 Sep 2012 7324 Views

RISK: Medium Risk

Medium Risk

Novell GroupWise Internet Agent Integer Overflow Vulnerability

A vulnerability has been identified in Novell GroupWise Internet Agent. A remote user can execute arbitrary code on the target system.   A remote user can send a specially crafted request with the HTTP 'Content-Length' header value of '-1' to the administration interface...
Last Update Date: 17 Sep 2012 10:06 Release Date: 17 Sep 2012 7120 Views

RISK: Medium Risk

Medium Risk

IBM AIX NFSv4 GID Enforcement Vulnerability

A vulnerability has been identified in IBM AIX NFSv4. A remote user can cause denial of service conditions.   GID in not properly enforced.
Last Update Date: 17 Sep 2012 10:05 Release Date: 17 Sep 2012 7130 Views

RISK: High Risk

High Risk

ISC BIND Resource Record Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an assertion error when processing resource records having RDATA greater than 65535 bytes. This can be exploited to...
Last Update Date: 14 Sep 2012 11:38 Release Date: 14 Sep 2012 7425 Views

RISK: High Risk

High Risk

Apple iTunes WebKit Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by malicious people to compromise a user's system. Some unspecified errors exist within the WebKit component. No further information is currently available. Some vulnerabilities are caused due to a bundled vulnerable version...
Last Update Date: 14 Sep 2012 11:38 Release Date: 14 Sep 2012 7892 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by attacker to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 14 Sep 2012 Release Date: 10 Sep 2012 7275 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Presence and Jabber Extensible Communications Platform Stream Header Processing Vulnerability

A vulnerability has been identified in Cisco Unified Presence and Jabber Extensible Communications Platform. A remote user can cause denial of service conditions. A remote user can send a specially crafted Extensible Messaging and Presence Protocol (XMPP) stream header to cause the target...
Last Update Date: 13 Sep 2012 10:16 Release Date: 13 Sep 2012 7155 Views

RISK: Medium Risk

Medium Risk

Citrix XenApp Online Plug-in / Receiver Code Execution Vulnerability

A vulnerability has been identified in Citrix XenApp Online Plug-in and Citrix Receiver, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error. Successful exploitation may allow execution of arbitrary...
Last Update Date: 13 Sep 2012 10:14 Release Date: 13 Sep 2012 7397 Views

RISK: Medium Risk

Medium Risk

Microsoft System Center Configuration Manager XSS Vulnerability

A cross-site scripting (XSS) vulnerability exists in System Center Configuration Manager where code can be injected back to the user in the resulting page, effectively allowing attacker-controlled code to run in the context of the user clicking the link.
Last Update Date: 12 Sep 2012 12:36 Release Date: 12 Sep 2012 7274 Views

RISK: High Risk

High Risk

Microsoft Visual Studio Team Foundation Server XSS Vulnerability

A reflected XSS vulnerability exists in Visual Studio Team Foundation Server that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer or any web browser using Team Foundation Server web access. The script could spoof content, disclose...
Last Update Date: 12 Sep 2012 12:34 Release Date: 12 Sep 2012 7248 Views

RISK: High Risk

High Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.An error when unpacking AAC stream data can be exploited to cause a buffer overflow.An error when decoding AAC SDK can be exploited to corrupt...
Last Update Date: 11 Sep 2012 10:18 Release Date: 11 Sep 2012 7352 Views

RISK: Medium Risk

Medium Risk

Citrix XenServer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Citrix XenServer, which can be exploited by malicious people to cause a DoS (Denial of Service) and gain escalated privileges.
Last Update Date: 7 Sep 2012 10:31 Release Date: 7 Sep 2012 7262 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Unspecified Code Execution Vulnerability

A vulnerability has been identified in Apple Mac OS X Java, which can be exploited by malicious people to compromise a user's system. The vulnerability is due to the vulnerability described in SA12082801.
Last Update Date: 6 Sep 2012 09:50 Release Date: 6 Sep 2012 7444 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware Products, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 3 Sep 2012 14:17 Release Date: 3 Sep 2012 7538 Views

RISK: Medium Risk

Medium Risk

Adobe Photoshop Data Processing Buffer Overflow Vulnerability

Multiple vulnerabilities have been identified in Adobe Photoshop CS6 for Windows and Macintosh, which could be exploited by malicious people to compromise a user's system.
Last Update Date: 3 Sep 2012 14:13 Release Date: 3 Sep 2012 7374 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.An out-of-bounds read error exists when handling line breaks.A bad cast error exists...
Last Update Date: 3 Sep 2012 14:10 Release Date: 3 Sep 2012 7480 Views

RISK: Medium Risk

Medium Risk

Opera Truncated Dialog Box Vulnerability

A vulnerability has been identified in Opera, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error when displaying a dialog box's buttons within a small window. This can be exploited to download...
Last Update Date: 31 Aug 2012 10:43 Release Date: 31 Aug 2012 7535 Views

RISK: Extremely High Risk

Extremely High Risk

Oracle Java Unspecified Code Execution Vulnerability

A vulnerability has been identified in Oracle Java, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to download and execute arbitrary programs. Successful exploitation allows execution of arbitrary...
Last Update Date: 31 Aug 2012 Release Date: 28 Aug 2012 8029 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / Seamonkey Multiple Vulnerabilities

Multiple vulnerabilities were reported in Mozilla Firefox, Thunderbird and Seamonkey. A remote user can cause arbitrary code to be executed, obtain potentially sensitive information and conduct cross-site scripting attacks on the target user's system. A local user can obtain elevated privileges on...
Last Update Date: 30 Aug 2012 12:18 Release Date: 30 Aug 2012 7257 Views

RISK: Medium Risk

Medium Risk

Symantec Messaging Gateway Multiple Vulnerabilities

Multiple vulnerabilities were identified in Symantec Messaging Gateway, which could be exploited by remote attacker to access the target system, conduct cross-site scripting or cross-site request forgery attacks or obtain potentially sensitive information. A remote authenticated user can modify the application.
Last Update Date: 29 Aug 2012 14:42 Release Date: 29 Aug 2012 8080 Views

RISK: High Risk

High Risk

LibreOffice/OpenOffice.org XML Manifest Encryption Handling Heap Overflows Vulnerability

A vulnerability was reported in LibreOffice/OpenOffice.org. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted Open Document Format for Office Applications (ODF) format file that, ...
Last Update Date: 29 Aug 2012 Release Date: 2 Aug 2012 7734 Views

RISK: Medium Risk

Medium Risk

McAfee Host Data Loss Prevention KeyView File Processing Vulnerabilities

Multiple vulnerabilities have been identified in McAfee Host Data Loss Prevention (HDLP), which can be exploited by malicious people to compromise a vulnerable system. 
Last Update Date: 27 Aug 2012 12:27 Release Date: 27 Aug 2012 7369 Views

RISK: High Risk

High Risk

Samsung Kies MASetupCaller ActiveX Control Insecure Method Vulnerabilities

Multiple vulnerabilities have been identified in Samsung Kies, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 27 Aug 2012 12:27 Release Date: 27 Aug 2012 7326 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Memory Corruption Vulnerability

A vulnerability has been identified in Foxit Reader. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted PDF file that, when loaded by the target user, will trigger a...
Last Update Date: 23 Aug 2012 10:09 Release Date: 23 Aug 2012 7213 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which can be exploited by remote attackers to cause denial of service, cross site scripting and disclosure of sensitive information.
Last Update Date: 23 Aug 2012 10:09 Release Date: 23 Aug 2012 7291 Views

RISK: High Risk

High Risk

Google Chrome Adobe Flash Player Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to gain knowledge of potentially sensitive information or compromise a user's system. The vulnerabilities are caused due to the application bundling a vulnerable version of Adobe Flash Player. ...
Last Update Date: 23 Aug 2012 10:08 Release Date: 23 Aug 2012 7406 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in the Adobe Flash Player which could be exploited by attackers to cause a crash and potentially  take control of the affected system.
Last Update Date: 22 Aug 2012 12:55 Release Date: 22 Aug 2012 7596 Views

RISK: Medium Risk

Medium Risk

Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2) Information Disclosure Vulnerability

Cryptographic weaknesses have been identified in the Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2) which could be exploited by attackers to obtain user credentials. Those credentials could then be re-used to authenticate the attacker to network resources, and the attacker...
Last Update Date: 22 Aug 2012 12:53 Release Date: 22 Aug 2012 8695 Views

RISK: Medium Risk

Medium Risk

Apache Web Server Multiple Vulnerabilities

Two vulnerabilities have been identified in Apache which allow a remote user to conduct cross-site scripting attacks or obtain potentially sensitive information.  A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the...
Last Update Date: 22 Aug 2012 12:24 Release Date: 22 Aug 2012 7298 Views

RISK: Medium Risk

Medium Risk

Apple Remote Desktop Information Disclosure Vulnerability

A vulnerability has been identified in Apple Remote Desktop, which may disclose sensitive information to malicious people.  The security issue is caused due to data being transmitted unencrypted without producing a warning when connecting to a third-party VNC server with "Encrypt all network data" ...
Last Update Date: 22 Aug 2012 12:21 Release Date: 22 Aug 2012 7378 Views

RISK: High Risk

High Risk

IBM Lotus Domino HTTP Response Splitting and Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Domino, which can be exploited by malicious people to conduct HTTP response splitting and cross-site scripting attacks. Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary...
Last Update Date: 21 Aug 2012 13:26 Release Date: 21 Aug 2012 7805 Views

RISK: Medium Risk

Medium Risk

McAfee Security for Microsoft SharePoint / Microsoft Exchange Outside In Vulnerabilities

Multiple vulnerabilities have been identified in McAfee Security for Microsoft SharePoint and McAfee Security for Microsoft Exchange, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to the software bundling a vulnerable Outside In library. For more...
Last Update Date: 21 Aug 2012 10:09 Release Date: 21 Aug 2012 7321 Views

RISK: Medium Risk

Medium Risk

HP Serviceguard Denial of Service Vulnerability

A vulnerability had been identified in HP Serviceguard. A remote user can cause denial of service conditions.
Last Update Date: 20 Aug 2012 10:57 Release Date: 20 Aug 2012 7455 Views

RISK: Medium Risk

Medium Risk

PostgreSQL "xml_parse()" and "xslt_process()" Vulnerabilities

Two vulnerabilities have been identified in PostgreSQL, which can be exploited by malicious people to disclose certain sensitive information and compromise a user's system.An error within the "xml_parse()" function when parsing DTD data within XML documents can be exploited to read arbitrary files...
Last Update Date: 20 Aug 2012 10:56 Release Date: 20 Aug 2012 7598 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark. A remote user can execute arbitrary code on the target system and cause denial of service conditions. A remote user can trigger a divide by zero error in the DCP ETSI dissector and the pcap-ng file parser. A...
Last Update Date: 16 Aug 2012 12:30 Release Date: 16 Aug 2012 6542 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Software Route Processor Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR Software, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper processing of crafted packets by Cisco 9000 Series Aggregation Services Routers (...
Last Update Date: 16 Aug 2012 12:17 Release Date: 16 Aug 2012 7321 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Use After Free Vulnerability

An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 15 Aug 2012 17:01 Release Date: 15 Aug 2012 7138 Views

RISK: High Risk

High Risk

Microsoft Office CGM File Format Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted Computer Graphics Metafile (CGM) graphics files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 15 Aug 2012 17:00 Release Date: 15 Aug 2012 7172 Views

RISK: High Risk

High Risk

Microsoft Visio DXF File Format Buffer Overflow Vulnerability

This is a remote code execution vulnerability. An attacker who successfully exploited this vulnerability could run arbitrary code as the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could...
Last Update Date: 15 Aug 2012 17:00 Release Date: 15 Aug 2012 7127 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Multiple Vulnerabilities

Remote code execution vulnerabilities exist in Microsoft Exchange Server through the WebReady Document Viewing feature. These vulnerabilities could allow remote code execution as Local System if a user views a specially crafted file through Outlook Web Access in a browser. An attacker who successfully exploited the vulnerabilities could...
Last Update Date: 15 Aug 2012 16:59 Release Date: 15 Aug 2012 6960 Views

RISK: High Risk

High Risk

Microsoft Windows JavaScript Integer Overflow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the JScript and VBScript engines calculate the size of an object in memory during a copy operation. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current...
Last Update Date: 15 Aug 2012 16:59 Release Date: 15 Aug 2012 7153 Views

RISK: High Risk

High Risk

Microsoft Windows Networking Components Multiple Vulnerabilities

Remote Administration Protocol Denial of Service Vulnerability A denial of service vulnerability exists in Windows networking components. The vulnerability is due to the service not properly handling specially crafted RAP requests. An attacker who successfully exploited this vulnerability could cause some of the Windows networking component to...
Last Update Date: 15 Aug 2012 16:56 Release Date: 15 Aug 2012 7160 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Layout Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Asynchronous...
Last Update Date: 15 Aug 2012 16:56 Release Date: 15 Aug 2012 6530 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Desktop Protocol Vulnerability

A remote code execution vulnerability exists in the way that the Remote Desktop Protocol accesses an object in memory after it has been deleted. An attacker who successfully exploited this vulnerability could run arbitrary code on the target system. An attacker could then install programs; view, ...
Last Update Date: 15 Aug 2012 16:50 Release Date: 15 Aug 2012 7045 Views

RISK: High Risk

High Risk

Microsoft Windows Common Controls MSCOMCTL.OCX Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Windows common controls. An attacker could exploit the vulnerability by constructing a specially crafted document or webpage. When a user opens the document or views the webpage, the vulnerability could allow remote code execution. An attacker who successfully...
Last Update Date: 15 Aug 2012 16:49 Release Date: 15 Aug 2012 7826 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Adobe Acrobat, which can be exploited by malicious people to compromise a user's system. An unspecified error can be exploited to cause a stack-based buffer overflow. An unspecified error can be exploited to cause...
Last Update Date: 15 Aug 2012 15:46 Release Date: 15 Aug 2012 7848 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 15 Aug 2012 12:00 Release Date: 15 Aug 2012 7331 Views

RISK: High Risk

High Risk

Adobe Flash Player Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system.  NOTE: The vulnerability is currently being actively exploited in targeted attacks via Word documents against the Windows version.
Last Update Date: 15 Aug 2012 11:59 Release Date: 15 Aug 2012 7477 Views

RISK: High Risk

High Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Java, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, and cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks...
Last Update Date: 15 Aug 2012 11:59 Release Date: 15 Aug 2012 7383 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere MQ Multiple Vulnerabilities

Two vulnerabilities have been identified in IBM WebSphere MQ, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to conduct cross-site request forgery attacks. The application allows users to perform certain actions via HTTP requests without performing any validity...
Last Update Date: 14 Aug 2012 14:33 Release Date: 14 Aug 2012 7446 Views

RISK: Medium Risk

Medium Risk

McAfee FireWall Enterprise ISC BIND Vulnerabilities

Two vulnerabilities has been identified in McAfee Firewall Enterprise, which can be exploited by malicious people to conduct spoofing attacks and cause a DoS (Denial of Service).
Last Update Date: 14 Aug 2012 14:33 Release Date: 14 Aug 2012 7299 Views

RISK: Medium Risk

Medium Risk

Cisco IOS SSL VPN Portal Reloading Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS, which can be exploited by malicious users to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error when reloading the SSL VPN portal page and can be exploited to cause a crash. ...
Last Update Date: 14 Aug 2012 14:32 Release Date: 14 Aug 2012 7441 Views

RISK: High Risk

High Risk

Google Chrome PDF Viewer Vulnerability

A vulnerability has been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. A use-after-free error and and an out-of-bounds write error exist within the PDF viewer.
Last Update Date: 10 Aug 2012 09:50 Release Date: 10 Aug 2012 7582 Views

RISK: Medium Risk

Medium Risk

HP Network Node Manager i Cross-Site Scripting Vulnerability

A vulnerability was identified in HP Network Node Manager i. A remote user can conduct cross-site scripting attacks.The software does not properly filter HTML code from user-supplied input before displaying the input. A remote user can create a specially crafted URL that...
Last Update Date: 8 Aug 2012 Release Date: 7 Aug 2012 7509 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious users to execute arbitrary code, disclose potentially sensitive information or cause denial of service.
Last Update Date: 8 Aug 2012 09:45 Release Date: 8 Aug 2012 7372 Views

RISK: High Risk

High Risk

IBM AIX and Virtual I/O Server OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL included in IBM AIX and Virtual I/O Server, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise an application using the library.
Last Update Date: 3 Aug 2012 13:30 Release Date: 3 Aug 2012 7765 Views

RISK: High Risk

High Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system. An error when handling certain DOM elements can be exploited to bypass the HTML sanitizer and conduct cross-site...
Last Update Date: 3 Aug 2012 13:29 Release Date: 3 Aug 2012 7757 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. An error when handling renders can be exploited to bypass the cross-process policy and cause interference. This vulnerability...
Last Update Date: 2 Aug 2012 18:30 Release Date: 2 Aug 2012 7425 Views

RISK: High Risk

High Risk

Citrix Access Gateway Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Citrix Access Gateway. A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a buffer overflow in the Citrix Access Gateway Plug-in for Windows ActiveX control and execute arbitrary code on the...
Last Update Date: 2 Aug 2012 18:30 Release Date: 2 Aug 2012 7465 Views

RISK: High Risk

High Risk

MIT Kerberos Key Distribution Center Heap Overflow Vulnerability

Two vulnerabilities have been identified in the Kerberos KDC, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. By sending a specially crafted AS-REQ, an unauthenticated remote attacker can cause the KDC to abnormally terminate or...
Last Update Date: 1 Aug 2012 11:27 Release Date: 1 Aug 2012 7588 Views

RISK: High Risk

High Risk

Apple Safari for Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari for Mac OS X, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, disclose sensitive information, bypass certain security restrictions, and compromise a user's system. ...
Last Update Date: 27 Jul 2012 13:57 Release Date: 27 Jul 2012 7700 Views

RISK: High Risk

High Risk

Apple Xcode Two Vulnerabilities

A vulnerability have been identified in Apple Xcode, which can be exploited by malicious people to disclose potentially sensitive information, hijack a user's session, and bypass certain security restrictions.A design error exists within the implementation of SSL 3. and TLS 1....
Last Update Date: 27 Jul 2012 13:55 Release Date: 27 Jul 2012 7229 Views

RISK: Medium Risk

Medium Risk

ISC DHCP Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ISC DHCP, which can be exploited by remoter user to cause denial of service. A remote user on the local network can send a specially crafted client identifier parameter value to trigger a buffer overflow and cause the target service to crash...
Last Update Date: 26 Jul 2012 12:03 Release Date: 26 Jul 2012 7142 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND, which can be exploited by remote user to cause denial of service. On systems configured for DNSSEC validation, a remote user can cause the cache of failing queries to be used before fully initialized, triggering an assertion failure...
Last Update Date: 26 Jul 2012 12:02 Release Date: 26 Jul 2012 7184 Views

RISK: High Risk

High Risk

Invensys Wonderware Products Insecure Library Loading Vulnerability

A vulnerability has been identified in multiple Invensys Wonderware products, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load an arbitrary library...
Last Update Date: 25 Jul 2012 15:02 Release Date: 25 Jul 2012 7311 Views

RISK: High Risk

High Risk

Siemens SIMATIC STEP 7 / PCS 7 Insecure Library Loading Vulnerability

A vulnerability has been identified in Siemens SIMATIC STEP 7 and PCS 7, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load...
Last Update Date: 25 Jul 2012 15:01 Release Date: 25 Jul 2012 7711 Views

RISK: Medium Risk

Medium Risk

Google Android DNS Resolver Vulnerability

A vulnerability has been identified in Google Android, which can be exploited by remote user to return spoofed DNS responses and poison the DNS cache on the target system.
Last Update Date: 25 Jul 2012 15:00 Release Date: 25 Jul 2012 7398 Views

RISK: High Risk

High Risk

Wireshark PPP and NFS Dissector Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service). An error within the PPP dissector can be exploited to cause a crash via a specially crafted packet. An error within the NFS dissector can...
Last Update Date: 25 Jul 2012 14:59 Release Date: 25 Jul 2012 7459 Views

RISK: High Risk

High Risk

Microsoft Exchange and FAST Search Server 2010 for SharePoint Mulitple Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Exchange and FAST Search Server 2010 for SharePoint shipped with third-party component, Oracle Outside In libraries, which can be exploited by malicious people to take control of the server process that is parsing a specially crafted file.
Last Update Date: 25 Jul 2012 14:57 Release Date: 25 Jul 2012 7112 Views

RISK: Medium Risk

Medium Risk

Symantec Multiple Products Insecure Library Loading Vulnerability

A vulnerability has been identified in Symantec Backup Exec System Recovery 2010 and Symantec System Recovery 2011, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the applications loading libraries (e.g. imapi....
Last Update Date: 24 Jul 2012 14:28 Release Date: 24 Jul 2012 7308 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Two vulnerabilities have been identified in PHP, which can be exploited by malicious people to bypass certain security restrictions and execute arbitrary code on the target system. The vulnerability is caused due to an error within the SQLite extension and can be exploited to bypass the "open_basedir...
Last Update Date: 23 Jul 2012 10:47 Release Date: 23 Jul 2012 7305 Views

RISK: High Risk

High Risk

HP StorageWorks File Migration Agent Buffer Overflow Vulnerabilities

Two vulnerabilities have been identified in HP StorageWorks File Migration Agent, which can be exploited by malicious people to compromise a vulnerable system. A boundary error in HsmCfgSvc.exe service when processing CIFS archive names can be exploited to cause a stack-based buffer overflow via...
Last Update Date: 20 Jul 2012 10:25 Release Date: 20 Jul 2012 7333 Views

RISK: Medium Risk

Medium Risk

Cisco Nexus Series Switches IP Stack Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco NX-OS, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error within the IP stack processing when obtaining layer 4 (UDP or TCP) information...
Last Update Date: 18 Jul 2012 Release Date: 17 Feb 2012 7811 Views

RISK: High Risk

High Risk

Mozilla Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which can be exploited by remote users to execute arbitrary code, spoof web sites, obtain information, and conduct cross- site scripting attacks.
Last Update Date: 18 Jul 2012 11:30 Release Date: 18 Jul 2012 7217 Views

RISK: High Risk

High Risk

Oracle Products Multiple vulnerabilities

Several vulnerabilities were identified in Oracle Products. A remote user can partially access and modify data on the target system. A remote user can cause partial denial of service conditions.
Last Update Date: 18 Jul 2012 11:29 Release Date: 18 Jul 2012 7546 Views

RISK: Medium Risk

Medium Risk

libexif Multiple Vulnerabilities

Multiple vulnerabilities have been identified in libexif, which can be exploited by malicious people to disclose certain sensitive information, cause a DoS (Denial of Service), and compromise an application using the library.An out-of-bounds read error within the "exif_entry_get_value()" ...
Last Update Date: 16 Jul 2012 11:50 Release Date: 16 Jul 2012 7515 Views

RISK: Medium Risk

Medium Risk

VMware ESXi libxml2 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESXi, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Last Update Date: 16 Jul 2012 11:50 Release Date: 16 Jul 2012 7309 Views