Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Cisco TelePresence Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco TelePresence. A remote user on the adjacent network can send specially crafted Cisco Discovery Protocol packets to trigger a buffer overflow and execute arbitrary code on the target system with elevated privileges. (Cisco TelePresence Recording Server, Immersive Endpoint devices, ...
Last Update Date: 13 Jul 2012 Release Date: 12 Jul 2012 7333 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

 Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.A use-after-free error exists within counter handling.A use-after-free error exists within layout height tracking....
Last Update Date: 13 Jul 2012 10:55 Release Date: 13 Jul 2012 7245 Views

RISK: High Risk

High Risk

Linux Kernel IPv6 Netfilter Connection Tracking Vulnerability

A vulnerability has been identified in the Linux Kernel. A remote user can send specially crafted packets to trigger a null pointer dereference in nf_ct_frag6_reasm() and cause the target system to crash. Systems using IPv6 and also having the nf_conntrack_ipv6 kernel module loaded are affected.
Last Update Date: 13 Jul 2012 Release Date: 12 Jul 2012 7347 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft XML Core Services Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft XML Core Services handles objects in memory. The vulnerability could allow remote code execution if a user views a website that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of...
Last Update Date: 11 Jul 2012 17:19 Release Date: 11 Jul 2012 7158 Views

RISK: Medium Risk

Medium Risk

Microsoft Office for Mac Insecure Filesystem Permissions Vulnerability

An elevation of privilege vulnerability exists in the way that folder permissions are set in certain Microsoft Office for Mac installations. An attacker could place a malicious executable in the Microsoft Office 2011 folder. If a user later logs on and runs the malicious executable, attacker-...
Last Update Date: 11 Jul 2012 17:18 Release Date: 11 Jul 2012 6975 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities

HTML Sanitization Vulnerability An information disclosure vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user. XSS scriptresx.ashx Vulnerability...
Last Update Date: 11 Jul 2012 17:17 Release Date: 11 Jul 2012 7159 Views

RISK: High Risk

High Risk

Microsoft Windows TLS Protocol Vulnerability

An information disclosure vulnerability exists in TLS encryption protocol. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted TLS traffic. This vulnerability primarily impacts HTTPS traffic, since the...
Last Update Date: 11 Jul 2012 17:16 Release Date: 11 Jul 2012 7122 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Command Injection Vulnerability

A remote code execution vulnerability exists in the way Windows handles file and directory names. This vulnerability could allow remote code execution if a user opens a file or directory with a specially crafted name. If a user is logged on with administrative user rights...
Last Update Date: 11 Jul 2012 17:13 Release Date: 11 Jul 2012 7483 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerability

An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly validates parameters when creating a hook procedure. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete...
Last Update Date: 11 Jul 2012 17:11 Release Date: 11 Jul 2012 7139 Views

RISK: High Risk

High Risk

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Visual Basic for Applications handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 11 Jul 2012 17:10 Release Date: 11 Jul 2012 7491 Views

RISK: High Risk

High Risk

Microsoft Windows Data Access Components Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Data Access Components accesses an object in memory that has been improperly initialized. An attacker who successfully exploited this vulnerability could run arbitrary code on the target system. An attacker could then install programs; view, ...
Last Update Date: 11 Jul 2012 17:08 Release Date: 11 Jul 2012 7092 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Cached Object Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user...
Last Update Date: 11 Jul 2012 17:07 Release Date: 11 Jul 2012 7222 Views

RISK: High Risk

High Risk

VLC Player Buffer Overflow Vulnerability

A vulnerability has been identified in VLC Player. which can be exploited by remote user to compromise a vulnerable system. A remote user can create a specially crafted file that, when loaded by the target user, will trigger a heap overflow and execute arbitrary code on...
Last Update Date: 10 Jul 2012 Release Date: 9 Jul 2012 7945 Views

RISK: High Risk

High Risk

Microsoft IIS Web Server Discloses Sensitive Information Vulnerability

A vulnerability has been identified in Microsoft IIS Web Server. which can be exploited by remote user to potentially sensitive information. A remote user can supply a specially crafted request containing the tilde ('~') character to determine whether a matching file exists within the web directory on the...
Last Update Date: 10 Jul 2012 Release Date: 9 Jul 2012 8103 Views

RISK: Medium Risk

Medium Risk

Asterisk Product Denial of Service Vulnerabilities

Multiple vulnerabilities has been identified in Asterisk, which can be exploited by remote authenticated user to denial of service attack.A remote authenticated user can respond to a re-invite with a provisional response and not send a final response to cause the remote system to fail...
Last Update Date: 10 Jul 2012 Release Date: 9 Jul 2012 7422 Views

RISK: Medium Risk

Medium Risk

Pidgin MXit Message Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Pidgin, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the "mxit_show_message()" function (libpurple/protocols/mxit/markup.c) when...
Last Update Date: 10 Jul 2012 Release Date: 9 Jul 2012 7175 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Feature Pack Security Bypass Vulnerability

A vulnerability has been identified in IBM WebSphere Application Server Feature Pack for Web Services, which can be exploited by malicious users to bypass certain security restrictions. An error related to LPTA tokens in a WS-Security policy enabled Java API for XML Web Services (JAX...
Last Update Date: 6 Jul 2012 10:34 Release Date: 6 Jul 2012 7726 Views

RISK: Medium Risk

Medium Risk

RSA Access Manager Session Replay Vulnerability

A vulnerability has been identified in RSA Access Manager. A remote user can exploit a flaw in the logout process and replay session credentials to gain access to the target system.
Last Update Date: 5 Jul 2012 10:14 Release Date: 5 Jul 2012 7432 Views

RISK: Medium Risk

Medium Risk

HP Network Node Manager i Input Validation Vulnerability

A vulnerability has been identified in HP Network Node Manager i. A remote user can conduct cross-site scripting attacks.The software does not properly filter HTML code from user-supplied input before displaying the input. A remote user can cause arbitrary scripting code to...
Last Update Date: 3 Jul 2012 18:32 Release Date: 3 Jul 2012 7342 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark which can be exploited by malicious people to cause a DoS (Denial of Service). Infinite and large loops in the ANSI MAP, ASF, BACapp, Bluetooth HCI, IEEE 802.11, IEEE 802.3, LTP...
Last Update Date: 3 Jul 2012 15:57 Release Date: 3 Jul 2012 7713 Views

RISK: Medium Risk

Medium Risk

Novell GroupWise WebAccess Directory Traversal Vulnerability

A vulnerability has been identified in Novell GroupWise WebAccess. A remote user can view files on the target system. The software does not properly validate user-supplied input in the 'User.interface' parameter. A remote user can supply a specially crafted request to...
Last Update Date: 3 Jul 2012 15:56 Release Date: 3 Jul 2012 7298 Views

RISK: Medium Risk

Medium Risk

IBM Support Assistant Multiple Vulnerabilities

Multiple vulnerabilities have been reported in IBM Support Assistant, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. For more information:SA12062501
Last Update Date: 3 Jul 2012 15:54 Release Date: 3 Jul 2012 7263 Views

RISK: Medium Risk

Medium Risk

Cisco WebEx Player Buffer Overflow Vulnerabilities

Multiple vulnerabilities have identified in Cisco WebEx Player, which can be exploited by malicious people to compromise a vulnerable system.
Last Update Date: 29 Jun 2012 08:43 Release Date: 29 Jun 2012 7250 Views

RISK: Medium Risk

Medium Risk

HP System Management Homepage Multiple Vulnerabilities

Multiple vulnerabilities have identified in HP System Management Homepage, which can be exploited by malicious people to disclose potentially sensitive information, hijack a user's session, cause a DoS (Denial of Service), bypass certain security restrictions, manipulate certain data, and compromise a...
Last Update Date: 28 Jun 2012 11:58 Release Date: 28 Jun 2012 7995 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose certain sensitive information, bypass certain security restrictions, and compromise a user's system. An unspecified error can be exploited to disclose the iFrame...
Last Update Date: 28 Jun 2012 11:55 Release Date: 28 Jun 2012 7508 Views

RISK: Medium Risk

Medium Risk

IBM DB2 Multiple Vulnerabilities

Multiple Vulnerabilities have been identified on IBM DB2 server, which could be exploited to escalate privilege, discloese sensitive infromation, and cause system crash. Vulnerability in IBM DB2 server products could allow a specially-crafted DRDA request to cause disruption to the server. The vulnerability...
Last Update Date: 26 Jun 2012 12:08 Release Date: 26 Jun 2012 7659 Views

RISK: High Risk

High Risk

IBM Lotus Expeditor Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Expeditor, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system.Input passed to unspecified parameters within the...
Last Update Date: 25 Jun 2012 11:26 Release Date: 25 Jun 2012 7934 Views

RISK: Medium Risk

Medium Risk

F5 Products Multiple Vulnerabilities

Multiple vulnerabilities has been identified in multiple F5 products, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. The vulnerability is caused due to a bundled vulnerable version of BIND. For more information: ...
Last Update Date: 22 Jun 2012 12:47 Release Date: 22 Jun 2012 7649 Views

RISK: Medium Risk

Medium Risk

Winamp AVI / IT File Processing Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which can be exploited by malicious people to compromise a user's system.An error in bmp.w5s when allocating memory using values from the "strf" chunk to process BI_RGB video data within AVI files can be...
Last Update Date: 22 Jun 2012 12:47 Release Date: 22 Jun 2012 7332 Views

RISK: Medium Risk

Medium Risk

Cisco AnyConnect Secure Mobility Client Software Update Vulnerability

Multiple vulnerabilities have been identified in Cisco AnyConnect Secure Mobility Client. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted HTML that, when loaded by the target user, will execute...
Last Update Date: 21 Jun 2012 10:47 Release Date: 21 Jun 2012 7616 Views

RISK: Medium Risk

Medium Risk

Cisco ASA 5500 Series IPv6 Processing Vulnerability

A vulnerability has been identified in Cisco ASA. A remote user can cause denial of service conditions.   A remote user can send specially crafted IPv6 data through the target device to cause the target device to reload.
Last Update Date: 21 Jun 2012 10:47 Release Date: 21 Jun 2012 7192 Views

RISK: High Risk

High Risk

Mozilla Products Use-After-Free in nsHTMLSelectElement() Vulnerability

A vulnerability has been identified in Mozilla Firefox, Thunderbird and Seamonkey. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create specially crafted HTML that, when loaded by the target user, will trigger...
Last Update Date: 20 Jun 2012 10:31 Release Date: 20 Jun 2012 7284 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes "notes" URI Handler Vulnerability

A vulnerability has been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error within the "notes" URI handler, which can be exploited to execute arbitrary commands...
Last Update Date: 20 Jun 2012 10:25 Release Date: 20 Jun 2012 7403 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Processing Denial of Service Vulnerability

A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious, local users to cause a Denial of Service.The vulnerability is caused due to an error in atmfd.dll when processing Adobe OpenType font files and can be exploited to cause a...
Last Update Date: 15 Jun 2012 17:17 Release Date: 15 Jun 2012 7378 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which can be exploited by malicious people to conduct spoofing attacks and bypass certain security restrictions. An error when displaying preferences within a small window can be exploited to e.g. execute arbitrary code by tricking a user into...
Last Update Date: 15 Jun 2012 17:16 Release Date: 15 Jun 2012 7503 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple VMware products, which can be exploited by malicious people to cause denial of service or compromise a user's system. An input validation error when parsing Checkpoint files and can be exploited to execute arbitrary code. A user with...
Last Update Date: 15 Jun 2012 17:14 Release Date: 15 Jun 2012 7025 Views

RISK: Medium Risk

Medium Risk

IBM Rational AppScan Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Rational AppScan, which can be exploited by malicious users to disclose certain information and by malicious people to conduct spoofing and cross-site scripting attacks, disclose potentially sensitive information, hijack a user's session, conduct DNS cache...
Last Update Date: 15 Jun 2012 17:10 Release Date: 15 Jun 2012 7302 Views

RISK: Medium Risk

Medium Risk

Asterisk Skinny Channel Driver Vulnerability

A vulnerability has been identified in Asterisk. A remote authenticated user can cause denial of service conditions.A remote authenticated user with a valid SCCP ID can close a connection to the target Asterisk server when a station is in the 'Off Hook' call state to...
Last Update Date: 15 Jun 2012 17:07 Release Date: 15 Jun 2012 6468 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Java for Mac OS X, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise...
Last Update Date: 14 Jun 2012 10:15 Release Date: 14 Jun 2012 7261 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft XML Core Services Uninitialised Object Vulnerability

A vulnerability has been identified in Microsoft XML Core Services, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when attempting to access an object in memory that has not been initialised. Successful...
Last Update Date: 13 Jun 2012 15:30 Release Date: 13 Jun 2012 7266 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities

User Mode Scheduler Memory Corruption Vulnerability An elevation of privilege vulnerability exists in the way that the Windows User Mode Scheduler handles system requests. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, ...
Last Update Date: 13 Jun 2012 15:28 Release Date: 13 Jun 2012 7064 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

String Atom Class Name Handling Vulnerability An elevation of privilege vulnerability exists because of the way that Windows kernel-mode drivers manage kernel-mode driver objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install...
Last Update Date: 13 Jun 2012 15:27 Release Date: 13 Jun 2012 7059 Views

RISK: Medium Risk

Medium Risk

Microsoft Dynamics AX Enterprise Portal XSS Vulnerability

A cross-site scripting vulnerability exists in Microsoft Dynamics AX Enterprise Portal that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL that contains malicious JavaScript elements. Because of the vulnerability, when the malicious JavaScript is...
Last Update Date: 13 Jun 2012 15:25 Release Date: 13 Jun 2012 7403 Views

RISK: Medium Risk

Medium Risk

Microsoft Lync Multiple Vulnerabilities

TrueType Font Parsing Vulnerability A remote code execution vulnerability exists in the way that affected components handle shared content that contains specially crafted TrueType fonts. The vulnerability could allow remote code execution if a user views shared content that contains specially crafted TrueType fonts. An attacker who...
Last Update Date: 13 Jun 2012 15:21 Release Date: 13 Jun 2012 6941 Views

RISK: High Risk

High Risk

Microsoft Windows .NET Framework Memory Access Vulnerability

A remote code execution vulnerability exists in the Microsoft .NET Framework due to the improper execution of a function pointer. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 13 Jun 2012 15:20 Release Date: 13 Jun 2012 7007 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Center Element Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user...
Last Update Date: 13 Jun 2012 15:18 Release Date: 13 Jun 2012 7003 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Desktop Protocol Vulnerability

A remote code execution vulnerability exists in the way that the Remote Desktop Protocol accesses an object in memory that has been improperly initialized or has been deleted. An attacker who successfully exploited this vulnerability could run arbitrary code on the target system. An ...
Last Update Date: 13 Jun 2012 15:17 Release Date: 13 Jun 2012 7238 Views

RISK: High Risk

High Risk

Oracle Java SE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java SE. A remote user can execute arbitrary code on the target system. A remote user can cause denial of service conditions. A local user can partially access and modify data and partially deny service on the target system. ...
Last Update Date: 13 Jun 2012 15:10 Release Date: 13 Jun 2012 7505 Views

RISK: Medium Risk

Medium Risk

Adobe ColdFusion Component Browser Vulnerability

A vulnerability has been identified in Adobe ColdFusion. A remote user can conduct HTTP response splitting attacks. A remote user can submit a specially crafted URL to cause the target server to return a split response. A remote user can exploit this to spoof content on the...
Last Update Date: 13 Jun 2012 15:09 Release Date: 13 Jun 2012 7445 Views

RISK: High Risk

High Risk

MySQL memcmp() Comparison Error Vulnerability

A vulnerability has been identified in MySQL. A remote user can bypass authentication. A remote user can trigger a flaw in comparing authentication data to bypass authentication. Versions compiled with a memcmp() function that can return an arbitrary integer (outside of -128 .. 127...
Last Update Date: 13 Jun 2012 15:08 Release Date: 13 Jun 2012 8036 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by malicious people to compromise a user's system.An error in the handling of .m3u playlists can be exploited to cause a heap-based buffer overflow via a specially crafted...
Last Update Date: 13 Jun 2012 15:07 Release Date: 13 Jun 2012 7344 Views

RISK: Medium Risk

Medium Risk

Astaro Security Gateway Cross-Site Scripting Vulnerability

A vulnerability has been identified in Astaro Security Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks.
Last Update Date: 12 Jun 2012 15:10 Release Date: 12 Jun 2012 7400 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.   The vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash Player.  Please refer to SA12061101 for more...
Last Update Date: 12 Jun 2012 15:09 Release Date: 12 Jun 2012 7272 Views

RISK: High Risk

High Risk

Check Point Endpoint Connect Insecure Library Loading Vulnerability

A vulnerability has been identified in Check Point EndPoint Connect, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to the application loading certain libraries in an insecure manner. This can be exploited to load arbitrary libraries...
Last Update Date: 12 Jun 2012 15:09 Release Date: 12 Jun 2012 7720 Views

RISK: High Risk

High Risk

IBM Lotus iNotes Upload Module ActiveX Control Buffer Overflow Vulnerability

A vulnerability has been identified in IBM Lotus iNotes Upload Module ActiveX Control, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to an error within the dwa85W.dll module and can be exploited to cause a...
Last Update Date: 11 Jun 2012 11:48 Release Date: 11 Jun 2012 7795 Views

RISK: High Risk

High Risk

F5 Products Unspecified SSH Configuration Vulnerability

A vulnerability has been identified in multiple F5 products, which can be exploited by malicious people to compromise a vulnerable system.  The security issue is caused due to an unspecified configuration error.
Last Update Date: 11 Jun 2012 11:47 Release Date: 11 Jun 2012 7516 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. An unspecified error can be exploited to corrupt memory. An unspecified error can be exploited to cause a stack...
Last Update Date: 11 Jun 2012 11:47 Release Date: 11 Jun 2012 7731 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Sensor Events Multiple Vulnerabilities

Multiple vulnerabilities have been identfied in IBM WebSphere Sensor Events, where some have unknown impacts and others can be exploited by malicious people to conduct cross-site scripting attacks. An unspecified error exists related to directory traversal. An unspecified error exists related to HTTP methods. ...
Last Update Date: 8 Jun 2012 10:04 Release Date: 8 Jun 2012 8044 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a user's...
Last Update Date: 7 Jun 2012 14:22 Release Date: 7 Jun 2012 7612 Views

RISK: Medium Risk

Medium Risk

Adobe Illustrator Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Illustrator. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can create a specially crafted file that, when loaded by the target user, will trigger a memory corruption...
Last Update Date: 6 Jun 2012 Release Date: 10 May 2012 7622 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Professional and Photoshop Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Flash Professional and Photoshop. A remote user can cause arbitrary code to be executed on the target user's system.   A remote user can trigger a buffer overflow and execute arbitrary code on the target system. The code will...
Last Update Date: 6 Jun 2012 Release Date: 10 May 2012 7534 Views

RISK: High Risk

High Risk

ISC BIND DNS Resource Records Handling Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service). The vulnerability is caused due to an error when handling DNS resource records and can be exploited to e....
Last Update Date: 5 Jun 2012 12:04 Release Date: 5 Jun 2012 7982 Views

RISK: High Risk

High Risk

Microsoft Windows Includes Some Invalid Certificates Vulnerability

A vulnerability was identified in Microsoft Windows. A remote user may be able to spoof code signing signatures. The operating system includes some invalid intermediate certificates. The invalid certificates and their thumbprints are: Microsoft Enforced Licensing Intermediate PCA: 2a 83 e9 02 05 91 a5...
Last Update Date: 5 Jun 2012 12:03 Release Date: 5 Jun 2012 7324 Views

RISK: Medium Risk

Medium Risk

Cisco Firewall Services Module Protocol Independent Multicast (PIM) Denial of Service Vulnerability

A vulnerability has been identified in Cisco Firewall Services Module. A remote user can cause denial of service conditions. A remote user can send a specially crafted Protocol Independent Multicast (PIM) message to cause the target device to reload. Devices with multicast routing enabled are...
Last Update Date: 4 Jun 2012 Release Date: 15 Mar 2012 7902 Views

RISK: High Risk

High Risk

Cisco ASA Multiple Vulnerabilities

A vulnerability has been identified in Cisco ASA. A remote user can cause arbitrary code to be executed on the target user's system or cause denial of service conditions. A remote user can create HTML that, when loaded by the target user, will execute...
Last Update Date: 4 Jun 2012 Release Date: 15 Mar 2012 7675 Views

RISK: Medium Risk

Medium Risk

IBM AIX `TCP large send offload´ Denial of Service Vulnerability

A vulnerability has been reported in AIX, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the TCP stack when the "TCP large send offload" option is enabled and can be...
Last Update Date: 4 Jun 2012 Release Date: 7 Feb 2012 8334 Views

RISK: High Risk

High Risk

PHP-CGI query string parameter vulnerability

A vulnerability has been identified in PHP, which can be exploited by remote users to disclose certain sensitive information or compromise a vulnerable system.   The vulnerability is caused due to an error when parsing certain QUERY_STRING parameters. This can be exploited to e.g. disclose...
Last Update Date: 4 Jun 2012 Release Date: 7 May 2012 11776 Views

RISK: High Risk

High Risk

VMware ESX/ESXi Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX/ESXi Server, which can be exploited by malicious, local users to disclose potentially sensitive and system information, bypass certain security restrictions, cause a DoS (Denial of Service), and gain escalated privileges, by malicious people...
Last Update Date: 4 Jun 2012 Release Date: 1 Feb 2012 8684 Views

RISK: Medium Risk

Medium Risk

HP Network Automation Unspecified Security Bypass Vulnerability

A vulnerability has been identified in HP Network Automation, which can be exploited by malicious people to bypass certain security restrictions.  The vulnerability is caused due to an unspecified error and can be exploited to gain unauthorised access.
Last Update Date: 4 Jun 2012 Release Date: 1 Feb 2012 7899 Views

RISK: Medium Risk

Medium Risk

IrfanView Formats PlugIn Multiple Buffer Overflow Vulnerability

Multiple vulnerabilities have been identified in IrfanView Formats PlugIn, which can be exploited by malicious people to compromise a user's system. Due to an error within the ECW plugin (NCSEcw.dll) when decompressing images and can be exploited to cause a heap-...
Last Update Date: 4 Jun 2012 Release Date: 1 Jun 2012 7839 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 4 Jun 2012 10:43 Release Date: 4 Jun 2012 7462 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Packet Processing Flaw Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote user can cause denial of service conditions.   A remote user can send a specially crafted packet to the target device to cause the route processor to be unable to transmit route processor-based protocol packets to...
Last Update Date: 31 May 2012 15:29 Release Date: 31 May 2012 7186 Views

RISK: Medium Risk

Medium Risk

IBM Java 7 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious users to disclose certain information and by malicious people to disclose potentially sensitive information, hijack a user's session, conduct DNS cache poisoning attacks, manipulate certain data, cause a DoS...
Last Update Date: 31 May 2012 15:29 Release Date: 31 May 2012 7245 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have unknown impacts and others can be exploited by malicious people to compromise a user's system.An unspecified error exists in the v8 garbage collection, which may result in a crash.An out-...
Last Update Date: 25 May 2012 10:28 Release Date: 25 May 2012 7432 Views

RISK: Medium Risk

Medium Risk

Symantec Endpoint Protection Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec Endpoint Protection, which can be exploited by a remote user to cause remote code execution, denial of service and elevation of privilege. A remote authenticated user can conduct network scans of the target Symantec Endpoint Protection Manager host to cause...
Last Update Date: 24 May 2012 11:05 Release Date: 24 May 2012 7408 Views

RISK: High Risk

High Risk

Novell iPrint Server `attributes-natural-language´ Buffer Overflow Vulnerability

A vulnerability has been identified in Novell Open Enterprise Server, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error when handling the "attributes-natural-language" attribute and can be exploited to cause...
Last Update Date: 22 May 2012 Release Date: 3 Feb 2012 7878 Views

RISK: High Risk

High Risk

PHP `php_register_variable_ex()´ Code Execution Vulnerability

A vulnerability has been identified in PHP, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a logic error within the "php_register_variable_ex()" function (php_variables.c) when hashing form posts and updating a hash table...
Last Update Date: 22 May 2012 Release Date: 6 Feb 2012 7620 Views

RISK: Medium Risk

Medium Risk

libpng `png_decompress_chunk()´ Integer Overflow Vulnerability

A vulnerability has been identified in libpng, which can be exploited by malicious people to potentially compromise an application using the library.The vulnerability is caused due to an integer overflow error within the "png_decompress_chunk()" function (pngrutil.c) when uncompressing certain chunks, ...
Last Update Date: 22 May 2012 Release Date: 17 Feb 2012 8395 Views

RISK: High Risk

High Risk

OpenSSL `asn1_d2i_read_bio()´ DER Format Data Processing Vulnerability

A vulnerability has been identified in OpenSSL, which can be exploited by malicious people to potentially compromise an application using the library.The vulnerability is caused due to a type casting error in the "asn1_d2i_read_bio()" function when processing DER format data and can be exploited to...
Last Update Date: 22 May 2012 Release Date: 20 Apr 2012 8018 Views

RISK: Medium Risk

Medium Risk

Samba LSA RPC `take ownership´ Privilege Security Bypass Vulnerability

A vulnerability has been identified in Samba, which can be exploited by malicious users to bypass certain security restrictions. The security issue is caused due to improper application of security checks in the CreateAccount, OpenAccount, AddAccountRights, and RemoveAccountRights remote procedure calls (RPC...
Last Update Date: 22 May 2012 Release Date: 2 May 2012 7782 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server `httpOnly´ Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).An error when handling the "%{cookiename}C" log format string when using a threaded MPM can...
Last Update Date: 22 May 2012 Release Date: 30 Jan 2012 7880 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have unknown impacts and others can be exploited by malicious people to bypass certain security restrictions, and compromise a user's system. An error exists when loading links from internal pages, and related...
Last Update Date: 17 May 2012 18:00 Release Date: 17 May 2012 7493 Views

RISK: Medium Risk

Medium Risk

OpenOffice.org Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice.org. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will trigger an integer...
Last Update Date: 17 May 2012 15:44 Release Date: 17 May 2012 7393 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 17 May 2012 15:43 Release Date: 17 May 2012 7193 Views

RISK: Medium Risk

Medium Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.   An error within the handling of MP4 files can be exploited to corrupt memory, the parsing of RealMedia ASMRuleBook can be exploited to execute arbitrary code...
Last Update Date: 17 May 2012 15:42 Release Date: 17 May 2012 7357 Views

RISK: Medium Risk

Medium Risk

Adobe Photoshop CS5 Collada File Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Photoshop CS5, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to a boundary error in the U3D.8BI plug-in when processing certain Collada file elements. This...
Last Update Date: 16 May 2012 11:52 Release Date: 16 May 2012 7462 Views

RISK: High Risk

High Risk

Opera URL Parsing Code Execution Vulnerability

A vulnerability has been identified in Opera, which can be exploited by remote attacker to compromise a user's system. An out-of-bounds write error when parsing the URL can be exploited to corrupt memory via a specially crafted URL.
Last Update Date: 14 May 2012 11:06 Release Date: 14 May 2012 7659 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which can be exploited by malicious people to execute arbitrary code, obtain sensitive information, operate with elevated privileges, cause a denial-of-service condition or compromise a user's system.
Last Update Date: 11 May 2012 11:25 Release Date: 11 May 2012 7425 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.
Last Update Date: 11 May 2012 11:22 Release Date: 11 May 2012 7383 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system. Several unspecified error can be exploited to corrupt memory. Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
Last Update Date: 10 May 2012 18:54 Release Date: 10 May 2012 7340 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Two Serialization Vulnerabilities

.NET Framework Serialization Vulnerability A remote code execution vulnerability exists in the Microsoft .NET Framework due to the improper serialization of untrusted input. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 9 May 2012 18:07 Release Date: 9 May 2012 7423 Views

RISK: High Risk

High Risk

Microsoft Office, Windows, .NET Framework, and Silverlight Multiple Vulnerabilities

TrueType Font Parsing Vulnerability A remote code execution vulnerability exists in the way that affected components handle a specially crafted TrueType font file. The vulnerability could allow remote code execution if a user opens a specially crafted TrueType font file. An attacker who successfully exploited this vulnerability...
Last Update Date: 9 May 2012 17:35 Release Date: 9 May 2012 7661 Views

RISK: High Risk

High Risk

Microsoft Windows Partition Manager Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in the way that Windows Partition Manager handles device relations requests. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create...
Last Update Date: 9 May 2012 17:32 Release Date: 9 May 2012 7307 Views

RISK: High Risk

High Risk

Microsoft Windows TCP/IP Stack Two Vulnerabilities

Windows Firewall Bypass Vulnerability A security feature bypass vulnerability exists in Windows due to the way that Windows Firewall handles outbound broadcast packets. An attacker who successfully exploited this vulnerability could bypass the Windows Firewall defense-in-depth mechanism to facilitate exploitation of other vulnerabilities.   ...
Last Update Date: 9 May 2012 16:12 Release Date: 9 May 2012 7300 Views

RISK: High Risk

High Risk

Microsoft Visio Viewer VSD File Format Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Visio validates attributes when handling specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 9 May 2012 16:06 Release Date: 9 May 2012 7469 Views

RISK: High Risk

High Risk

Microsoft Office Excel Multiple Vulnerabilities

Excel File Format Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 9 May 2012 15:57 Release Date: 9 May 2012 7348 Views

RISK: High Risk

High Risk

Microsoft Word RTF Mismatch Vulnerability

A remote code execution vulnerability exists in the way that affected Microsoft Office software parses specially crafted Rich Text Format (RTF) data. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 9 May 2012 15:55 Release Date: 9 May 2012 7421 Views

RISK: Medium Risk

Medium Risk

Apple iOS Remote Code Execution and Address Bar Urls Spoofing Vulnerabilities

Two vulnerabilities were identified in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can spoof the address bar URL. A remote user can create a specially crafted file that, when loaded by...
Last Update Date: 8 May 2012 12:40 Release Date: 8 May 2012 8462 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X FileVault Plain Text Password Logging Vulnerability

A security issue has been identified in Apple Mac OS X, which can be exploited by malicious people with physical access to bypass certain security restrictions.   The security issue is caused due to the debug switch being enabled within FileVault when using "Legacy ...
Last Update Date: 8 May 2012 12:33 Release Date: 8 May 2012 8259 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Object Confusion Vulnerability

A vulnerability has been identified in Adobe Flash Player, which can be exploited by remote users to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Last Update Date: 7 May 2012 12:40 Release Date: 7 May 2012 7778 Views