Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

VMware ESX Server / ESXi Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server and VMware ESXi, which can be exploited by malicious users to escalated privileges, cause a DoS (Denial of Service) and potentially compromise a vulnerable system. An errors when handling RPC commands can be exploited to cause...
Last Update Date: 7 May 2012 12:39 Release Date: 7 May 2012 8018 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Mulitple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious users execute arbitrary code, cause a denial-of-service condition and bypass security restrictions.
Last Update Date: 4 May 2012 12:12 Release Date: 4 May 2012 8734 Views

RISK: Medium Risk

Medium Risk

HP Systems Insight Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Systems Insight Manager, which can be exploited by malicious, local users to potentially gain escalated privileges and by malicious people to disclose sensitive information, conduct cross-site scripting and cross-site request forgery attacks, ...
Last Update Date: 2 May 2012 12:06 Release Date: 2 May 2012 7678 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. A use-after-free error exists in floats handling and within the xml parser. An error exists within the IPC validation. ...
Last Update Date: 2 May 2012 12:03 Release Date: 2 May 2012 7691 Views

RISK: High Risk

High Risk

Oracle Database Remote Pre-authenticated TNS Poison Vulnerability

A vulnerability has been identified in Oracle Database, which can be exploited by malicious people with network access to the TNS Listener to inject commands and/or hijack connections from the client to the database server.   Note: Currently, there is no patch available for this...
Last Update Date: 30 Apr 2012 12:18 Release Date: 30 Apr 2012 8655 Views

RISK: High Risk

High Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server, which can be exploited by malicious, local users in a guest virtual machine to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise the vulnerable system.
Last Update Date: 30 Apr 2012 12:12 Release Date: 30 Apr 2012 8168 Views

RISK: Medium Risk

Medium Risk

IBM Rational Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple IBM Rational products, which can be exploited by malicious users to disclose sensitive information and conduct session fixation and script insertion attacks and by malicious people to disclose sensitive information, overwrite arbitrary files, conduct cross-site request forgery and...
Last Update Date: 27 Apr 2012 12:02 Release Date: 27 Apr 2012 7792 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Studio Linker Integer Overflow Vulnerability

A vulnerability has been identified in Microsoft Visual Studio 2008, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an integer overflow error in the linker utility (link.exe) when allocating memory based on...
Last Update Date: 27 Apr 2012 11:57 Release Date: 27 Apr 2012 7583 Views

RISK: Medium Risk

Medium Risk

Comodo Internet Security PE File Processing Vulnerability

A vulnerability has been identified in Comodo Internet Security. A remote or local user can cause denial of service conditions.A remote or local user can create a specially crafted PE file that, when loaded into memory on the target system, will cause the target system...
Last Update Date: 27 Apr 2012 11:56 Release Date: 27 Apr 2012 7533 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, disclose certain sensitive information, compromise a user's system or spoof certain web sites...
Last Update Date: 25 Apr 2012 10:54 Release Date: 25 Apr 2012 7394 Views

RISK: Medium Risk

Medium Risk

Asterisk Multiple Vulnerabilities

Multiple vulnerabilities identified in Asterisk, which a remote authenticated user can execute arbitrary code on the target system, cause denial of service conditions, and execute arbitrary shell commands on Asterisk Manager interface. A remote user can send specially crafted SIP UPDATE request to cause Asterisk to...
Last Update Date: 24 Apr 2012 11:20 Release Date: 24 Apr 2012 7476 Views

RISK: Medium Risk

Medium Risk

WordPress external libraries Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WordPress external libraries (Plupload, SWFUpload, SWFObject),  which could be exploited by malicious people to elevation of privilege, and cause a cross-site scripting attack.
Last Update Date: 23 Apr 2012 12:13 Release Date: 23 Apr 2012 7362 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which could be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 23 Apr 2012 12:10 Release Date: 23 Apr 2012 7587 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilies

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to denial of service, data manipulation, disclose sensitive information or compromise a vulnerable system.
Last Update Date: 18 Apr 2012 12:01 Release Date: 18 Apr 2012 7917 Views

RISK: Extremely High Risk

Extremely High Risk

Apple Java for Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Java for Mac OS X, which can be exploited by malicious people to compromise a vulnerable system.   Note: Exploit code is publicly available. [13/4/2012 Update]Apple published a new Java security update (Java for...
Last Update Date: 13 Apr 2012 Release Date: 5 Apr 2012 8250 Views

RISK: Medium Risk

Medium Risk

Samba Remote Procedure Call Remote Memory Corruption Vulnerability

A vulnerability has been identified in Samba. A remote user can execute arbitrary code on the target system.   A remote user can send a specially crafted RPC call to trigger a buffer overflow in the Network Data Representation (NDR) marshalling code and execute arbitrary code on...
Last Update Date: 12 Apr 2012 10:37 Release Date: 12 Apr 2012 7914 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Works File Converter Heap Overflow Vulnerability

A remote code execution vulnerability exists in Microsoft Office Works File Converter. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
Last Update Date: 11 Apr 2012 11:42 Release Date: 11 Apr 2012 7639 Views

RISK: Medium Risk

Medium Risk

Microsoft Forefront Unified Access Gateway (UAG) Unfiltered Access to UAG Default Website Vulnerability

A vulnerability exists in Microsoft Unified Access Gateway (UAG) that could allow an unauthenticated user to access the default website of the Microsoft UAG server from the external network.
Last Update Date: 11 Apr 2012 11:41 Release Date: 11 Apr 2012 7433 Views

RISK: High Risk

High Risk

Microsoft Windows Common Controls MSCOMCTL.OCX Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Windows common controls. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the...
Last Update Date: 11 Apr 2012 11:39 Release Date: 11 Apr 2012 8074 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Parameter Validation Vulnerability

A remote code execution vulnerability exists in the way that Microsoft .NET Framework validates parameters when passing data to a function. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 11 Apr 2012 11:36 Release Date: 11 Apr 2012 7593 Views

RISK: High Risk

High Risk

Microsoft Windows WinVerifyTrust Signature Validation Vulnerability

A remote code execution vulnerability exists in the Windows Authenticode Signature Verification function used for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add...
Last Update Date: 11 Apr 2012 11:34 Release Date: 11 Apr 2012 9525 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Print Feature Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer attempts to print a specially crafted HTML page. The vulnerability could allow an attacker to execute arbitrary code in the context of the current user. JScript9 Remote Code Execution Vulnerability A remote code...
Last Update Date: 11 Apr 2012 11:31 Release Date: 11 Apr 2012 8240 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted file that, when loaded by the target user, will trigger a...
Last Update Date: 11 Apr 2012 09:13 Release Date: 11 Apr 2012 7633 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to compromise an application using the library.A format string error exists within the "srt_to_ass()" function (libavcodec/srtdec.c) when parsing certain parameters.An integer overflow error...
Last Update Date: 10 Apr 2012 14:15 Release Date: 10 Apr 2012 8480 Views

RISK: Medium Risk

Medium Risk

Oracle MySQL Server Two Unspecified Vulnerabilities

Two vulnerabilities with unknown impacts have been identified in Oracle MySQL Server.   The vulnerabilities are caused due to unspecified errors. No further information is currently available.
Last Update Date: 10 Apr 2012 14:14 Release Date: 10 Apr 2012 7510 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome where some have unknown impacts while others can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. Two unspecified errors in Flash Player can be exploited to corrupt memory in the Chrome interface...
Last Update Date: 10 Apr 2012 14:13 Release Date: 10 Apr 2012 7585 Views

RISK: High Risk

High Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Last Update Date: 2 Apr 2012 11:29 Release Date: 2 Apr 2012 7544 Views

RISK: Medium Risk

Medium Risk

IrfanView Multiple Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in IrfanView, which can be exploited by malicious people to compromise a user's system.A boundary error when processing RLE compressed bitmap files can be exploited to cause a heap-based buffer overflow by e.g. tricking a...
Last Update Date: 2 Apr 2012 11:28 Release Date: 2 Apr 2012 8087 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct cross-site scripting and spoofing attacks and compromise a user's system.Some errors exist in the bundled version of Adobe Flash...
Last Update Date: 2 Apr 2012 Release Date: 30 Mar 2012 8331 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS, which can be exploited by attackers to cause remote code execution and denial of service. A vulnerability lets remote authenticated users bypass command authorization level controls. Zone-based firewall IP/HTTP/H.323/SIP...
Last Update Date: 30 Mar 2012 Release Date: 29 Mar 2012 7751 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A use-after-free error exists when handling the first letter. An error exists in the bundled version...
Last Update Date: 29 Mar 2012 Release Date: 23 Mar 2012 7639 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by a remote user to cause arbitrary code executed on the target user's system. A remote user can create specially crafted Flash content that, when loaded by the target user, will...
Last Update Date: 29 Mar 2012 14:49 Release Date: 29 Mar 2012 7566 Views

RISK: Medium Risk

Medium Risk

Wireshark Denial of Service Vulnerability

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).A NULL pointer dereference error in the ANSI A dissector can be exploited to cause a crash via a specially crafted packet.An error...
Last Update Date: 29 Mar 2012 14:49 Release Date: 29 Mar 2012 7475 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager, which can be exploited by attackers to cause denial of service, bypass certain security restrictions, gain escalated privileges and disclose potentially sensitive information.
Last Update Date: 29 Mar 2012 09:53 Release Date: 29 Mar 2012 7385 Views

RISK: High Risk

High Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and potentially compromise a user's system. An error when displaying the download dialog box within a small window can be exploited to...
Last Update Date: 28 Mar 2012 10:30 Release Date: 28 Mar 2012 8545 Views

RISK: Medium Risk

Medium Risk

Apache Traffic Server Host Header Buffer Overflow Vulnerability

A vulnerability has been identified in Apache Traffic Server, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to an error when parsing the "Host" HTTP header and can be exploited to cause a heap-based buffer...
Last Update Date: 27 Mar 2012 10:26 Release Date: 27 Mar 2012 7771 Views

RISK: Medium Risk

Medium Risk

GnuTLS TLS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in GnuTLS, which can be exploited by malicious people to potentially compromise an application using the library. A vulnerability in GnuTLS libtasn1 Tiny ASN.1 library is caused due to certain functions (e.g. "asn1_der_decoding()") not properly checking...
Last Update Date: 22 Mar 2012 10:36 Release Date: 22 Mar 2012 7466 Views

RISK: Medium Risk

Medium Risk

Novell ZENworks Configuration Management Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell ZENworks Configuration Management, which can be exploited to execute arbitrary code and view files on the target system. A remote user can supply a specially crafted request (PreBoot Service Opcode 0x21) to view arbitrary files on the target system...
Last Update Date: 22 Mar 2012 10:12 Release Date: 22 Mar 2012 7585 Views

RISK: High Risk

High Risk

Adobe Photoshop TIFF Image Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Photoshop, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an error when parsing TIFF images and can be exploited to cause a heap-based buffer overflow via...
Last Update Date: 22 Mar 2012 09:46 Release Date: 22 Mar 2012 7847 Views

RISK: Medium Risk

Medium Risk

VLC Media Player MMS and Real RTSP Vulnerabilities

Multiple vulnerabilities have been reported in VLC Media Player, which can be exploited by malicious people to compromise a user's system. A boundary error within the "MMSOpen()" function (modules/access/mms/mmstu.c) in the MMS access plugin...
Last Update Date: 20 Mar 2012 10:09 Release Date: 20 Mar 2012 8588 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple VMware products, which can be exploited by malicious users to disclose certain information and by malicious people to disclose potentially sensitive information, hijack a user's session, conduct DNS cache poisoning attacks, bypass certain security restrictions, manipulate...
Last Update Date: 19 Mar 2012 12:13 Release Date: 19 Mar 2012 7567 Views

RISK: High Risk

High Risk

Asterisk Denial of Service and Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. An error in the Milliwatt application within the "milliwatt_generate()" function (apps/app_milliwatt.c) ...
Last Update Date: 19 Mar 2012 12:12 Release Date: 19 Mar 2012 7438 Views

RISK: Medium Risk

Medium Risk

McAfee Email Gateway / Email and Web Security Appliance Multiple Vulnerabilities

Multiple vulnerabilities have been identified in McAfee Email Gateway / Email and Web Security Appliance. A remote user can conduct cross-site scripting attacks, obtain potentially sensitive information and view files on the target system.   The management console does not properly filter HTML code from user...
Last Update Date: 19 Mar 2012 Release Date: 16 Mar 2012 8100 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird, and SeaMonkey, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, disclose certain sensitive information, and compromise a user's system. ...
Last Update Date: 15 Mar 2012 15:01 Release Date: 15 Mar 2012 7842 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectWrite Application Denial of Service Vulnerability

A denial of service vulnerability exists in the way that DirectWrite renders a specially crafted sequence of Unicode characters. An attacker who successfully exploited this vulnerability could cause a target application to stop responding.
Last Update Date: 14 Mar 2012 12:19 Release Date: 14 Mar 2012 7470 Views

RISK: Medium Risk

Medium Risk

Microsoft Expression Design Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Expression Design handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Mar 2012 12:19 Release Date: 14 Mar 2012 7582 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Studio Add-In Vulnerability

An elevation of privilege vulnerability exists in Visual Studio due to the insecure loading of add-ins from within Visual Studio. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated privileges. An attacker could then install programs; view, change, or...
Last Update Date: 14 Mar 2012 12:18 Release Date: 14 Mar 2012 7903 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers PostMessage Function Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows kernel-mode driver manages the PostMessage function. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Mar 2012 12:18 Release Date: 14 Mar 2012 7965 Views

RISK: High Risk

High Risk

Microsoft Windows DNS Server Denial of Service Vulnerability

A denial of service vulnerability exists in the way that the DNS server improperly handles objects in memory when looking up the resource record of a domain. An attacker that successfully exploited this vulnerability could cause the DNS server on the target system to stop responding and automatically restart...
Last Update Date: 14 Mar 2012 12:17 Release Date: 14 Mar 2012 7710 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Desktop and Terminal Server Multiple Vulnerabilities

Remote Desktop Protocol Vulnerability A remote code execution vulnerability exists in the way that the Remote Desktop Protocol accesses an object in memory that has been improperly initialized or has been deleted. An attacker who successfully exploited this vulnerability could run abitrary code on the target system. ...
Last Update Date: 14 Mar 2012 12:16 Release Date: 14 Mar 2012 8149 Views

RISK: Medium Risk

Medium Risk

Citrix XenServer Workload Balancing Component Denial of Service Vulnerability

A vulnerability has been identified in Citrix XenServer, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error in the Workload Balancing component.
Last Update Date: 14 Mar 2012 09:39 Release Date: 14 Mar 2012 7855 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multipule vulnerabilities were reported in Apple Safari. A remote user can spoof URLs, bypass cookie restrictions and  obtain HTTP authentication credentials. A remote user can create a specially crafted URL containing International Domain Name (IDN) characters to load a spoofed site that appears to...
Last Update Date: 13 Mar 2012 10:37 Release Date: 13 Mar 2012 7585 Views

RISK: Medium Risk

Medium Risk

Google Chrome Three Unspecified Code Execution Vulnerabilities

Three vulnerabilities have been reported in Google Chrome, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to unspecified errors when loading certain plug-ins and handling GPU memory. No further information is currently available.
Last Update Date: 13 Mar 2012 10:32 Release Date: 13 Mar 2012 7655 Views

RISK: High Risk

High Risk

VMware ESX Server / VirtualCenter Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ESX Server and VirtualCenter, which can be exploited by malicious users to disclose certain information and by malicious people to disclose potentially sensitive information, hijack a user's session, conduct DNS cache poisoning attacks, manipulate certain data, cause...
Last Update Date: 12 Mar 2012 11:06 Release Date: 12 Mar 2012 7645 Views

RISK: High Risk

High Risk

Google Chrome Code Execution Vulnerabilities

Two vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.   The vulnerabilities are caused due to unspecified errors when handling certain JavaScript and navigating history.   Successful exploitation allows execution of arbitrary code.
Last Update Date: 12 Mar 2012 11:03 Release Date: 12 Mar 2012 7635 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have identified in Apple iOS. A remote user can conduct cross-site scripting attacks, obtain potentially sensitive information and cause arbitrary code to be executed on the target user's system. A local user can bypass the screen lock.A remote user...
Last Update Date: 9 Mar 2012 11:28 Release Date: 9 Mar 2012 8367 Views

RISK: Medium Risk

Medium Risk

Joomla! Multiple Vulnerabilities

Two vulnerabilities have been identified in Joomla!, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks. Certain input passed to the Highlight plugin is not properly sanitised before being returned to the user. This can be exploited to execute...
Last Update Date: 8 Mar 2012 12:15 Release Date: 8 Mar 2012 7721 Views

RISK: High Risk

High Risk

Apple Safari Plug-in Unloading Vulnerability

A vulnerability has been identified in Apple Safari, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to plug-ins being unloaded when navigating to a new page while the user interacts with the plug-in...
Last Update Date: 8 Mar 2012 12:15 Release Date: 8 Mar 2012 7728 Views

RISK: High Risk

High Risk

FreeType Multilpe Vulnerabilities

Multiple vulnerabilities have been identified in FreeType, which can be exploited by malicious people to potentially compromise an application using the library. An error in src/type1/t1parse.c when processing dictionaries can be exploited to cause heap-based memory corruption via a specially...
Last Update Date: 8 Mar 2012 12:14 Release Date: 8 Mar 2012 7913 Views

RISK: High Risk

High Risk

RSA SecurID Software Token Converter Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in RSA SecurID Software Token Converter, which can be exploited by malicious people to compromise a user's system. An unspecified error can be exploited to cause a buffer overflow.Successful exploitation may allow execution of arbitrary code.
Last Update Date: 8 Mar 2012 12:12 Release Date: 8 Mar 2012 7838 Views

RISK: High Risk

High Risk

BlackBerry OS / Tablet OS Unspecified WebKit Vulnerability

A vulnerability has been identified in BlackBerry OS and BlackBerry Tablet OS, which can be exploited by malicious people to compromise a vulnerable device. The vulnerability is caused due to an unspecified error in the WebKit browser engine. Successful exploitation may allow execution of arbitrary code. ...
Last Update Date: 7 Mar 2012 09:45 Release Date: 7 Mar 2012 7760 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited to cause a crash and potentially allow an attacker to take control of the affected system or cause a denial-of-service condition. A memory corruption vulnerability in Matrix3D that could lead to...
Last Update Date: 6 Mar 2012 11:13 Release Date: 6 Mar 2012 7799 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multipule vulnerabilities have been identified in Google Chrome, where one has an unknown impact and others can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. A use-after-free...
Last Update Date: 6 Mar 2012 11:12 Release Date: 6 Mar 2012 7754 Views

RISK: Medium Risk

Medium Risk

Novell GroupWise Client Address Book Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Novell GroupWise Client, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an error when processing Novell Address Book (".nab") files and can be exploited to cause a heap...
Last Update Date: 6 Mar 2012 Release Date: 2 Mar 2012 7639 Views

RISK: High Risk

High Risk

Cisco Products Multiple Vulnerabilities

Mulitple vulnerabilities have been identified in various Cisco products, which can be exploited by malicious users execute arbitrary code, cause a denial-of-service condition, operate with escalated privileges and bypass security restrictions. 
Last Update Date: 1 Mar 2012 14:45 Release Date: 1 Mar 2012 8187 Views

RISK: High Risk

High Risk

Cisco Small Business SRP520 / SRP540 Series Multiple Vulnerabilities

Mulitple vulnerabilities have been identified in Cisco Small Business SRP520 / SRP540 series, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to bypass certain security restrictions.
Last Update Date: 27 Feb 2012 10:05 Release Date: 27 Feb 2012 7890 Views

RISK: High Risk

High Risk

IBM AIX ICMP Packet Handling Denial of Service Vulnerability

A vulnerability has identified in IBM AIX. A remote user can send a specially crafted ICMP packet to cause the target service to crash.
Last Update Date: 27 Feb 2012 10:03 Release Date: 27 Feb 2012 8054 Views

RISK: Medium Risk

Medium Risk

Blackberry PlayBook Samba File Sharing Remote Code Execution Vulnerability

A vulnerability has identified in Blackberry PlayBook. A remote user can execute arbitrary code on the target system.If Wi-Fi file sharing is enabled, a remote user on the wireless network can send specially crafted data to trigger a Samba flaw and execute arbitrary code...
Last Update Date: 24 Feb 2012 10:27 Release Date: 24 Feb 2012 7779 Views

RISK: Extremely High Risk

Extremely High Risk

Symantec pcAnywhere Denial of Service Vulnerability

A vulnerability has been identified in Symantec pcAnywhere, which can be exploited to cause denial of service conditions. A remote user can send specially crafted data to TCP port 5631 to cause the target awhost32 service to crash. Note:Vendor supplied patch is not available....
Last Update Date: 23 Feb 2012 10:21 Release Date: 23 Feb 2012 7885 Views

RISK: High Risk

High Risk

Mozilla Product libpng Integer Overflow Vulnerability

A vulnerability has been identified in Mozilla Firefox, Thunderbird, and Seamonkey, which can be exploited by malicious people to potentially compromise a user's system.   For more information: libpng "png_decompress_chunk()" Integer Overflow Vulnerability
Last Update Date: 20 Feb 2012 11:21 Release Date: 20 Feb 2012 8020 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to compromise a user's system.An integer overflow error exists in PDF codecs.A use-after-free error exists within counter...
Last Update Date: 17 Feb 2012 14:30 Release Date: 17 Feb 2012 7909 Views

RISK: High Risk

High Risk

Adobe Flash Player Cross Site Scripting and Other Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited to cause a crash and potentially allow an attacker to take control of the affected system.   This update also resolves cross-site scripting vulnerability that could be used to take actions on a...
Last Update Date: 16 Feb 2012 10:21 Release Date: 16 Feb 2012 7766 Views

RISK: High Risk

High Risk

Microsoft Windows Indeo Codec Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Indeo Codec handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 15 Feb 2012 12:50 Release Date: 15 Feb 2012 7494 Views

RISK: High Risk

High Risk

Microsoft Visio Viewer Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Visio Viewer validates attributes when handling specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 15 Feb 2012 12:49 Release Date: 15 Feb 2012 7568 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Copy and Paste Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted web page that could allow information...
Last Update Date: 15 Feb 2012 12:06 Release Date: 15 Feb 2012 7570 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

GDI Access Violation Vulnerability A remote code execution vulnerability exists in the Windows kernel due to improper validation of input passed from user mode through the kernel component of GDI. The vulnerability could allow an attacker to run code in kernel-mode and then install programs; ...
Last Update Date: 15 Feb 2012 12:05 Release Date: 15 Feb 2012 7565 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Color Control Panel Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Color Control Panel handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 15 Feb 2012 12:04 Release Date: 15 Feb 2012 7482 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities

XSS in inplview.aspx Vulnerability A cross-site scripting vulnerability exists in Microsoft SharePoint 2010 that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL containing malicious JavaScript elements. Due to the vulnerability, when the malicious JavaScript...
Last Update Date: 15 Feb 2012 12:02 Release Date: 15 Feb 2012 7544 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Multiple Vulnerabilities

AfdPoll Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists where the Ancillary Function Driver (afd.sys) improperly validates input passed from user mode to the Windows kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker...
Last Update Date: 15 Feb 2012 12:01 Release Date: 15 Feb 2012 7688 Views

RISK: High Risk

High Risk

Microsoft .NET Framework and Microsoft Silverlight Multiple Vulnerabilities

.NET Framework Unmanaged Objects Vulnerability A remote code execution vulnerability exists in Microsoft .NET Framework and Silverlight that can allow a specially crafted Microsoft .NET Framework application to access memory in an unsafe manner. An attacker who successfully exploited this vulnerability could run arbitrary code...
Last Update Date: 15 Feb 2012 11:45 Release Date: 15 Feb 2012 7422 Views

RISK: High Risk

High Risk

Microsoft Windows C Run-Time Library Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that the msvcrt DLL calculates the size of a buffer in memory, allowing data to be copied into memory that has not been properly allocated. This vulnerability could allow remote code execution if a user opens a specially crafted...
Last Update Date: 15 Feb 2012 11:44 Release Date: 15 Feb 2012 7799 Views

RISK: High Risk

High Risk

Oracle Java SE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java SE, which can be exploited by attackers to execute arbitrary code, cause denial of service, and manipulate data. A remote user can send specially crafted data to execute arbitrary code on the target system or cause complete denial...
Last Update Date: 15 Feb 2012 10:26 Release Date: 15 Feb 2012 7854 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system. An unspecified error in the Shockwave 3D Asset can be exploited to corrupt memory. An unspecified error can be exploited to cause a heap...
Last Update Date: 15 Feb 2012 10:07 Release Date: 15 Feb 2012 7540 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird / SeaMonkey XBL Binding Use-After-Free Vulnerability

A vulnerability has been identified in multiple Mozilla products, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a use-after-free error in the "nsXBLDocumentInfo::ReadPrototypeBindings()" method when handling XBL bindings...
Last Update Date: 14 Feb 2012 10:23 Release Date: 14 Feb 2012 7767 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to bypass certain security restrictions, manipulate certain data, and compromise a user's system. An unspecified error exists within clipboard monitoring after a...
Last Update Date: 10 Feb 2012 14:52 Release Date: 10 Feb 2012 8014 Views

RISK: Medium Risk

Medium Risk

MySQL Unspecified Code Execution Vulnerability

A vulnerability has been identified in MySQL, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to an unspecified error. Successful exploitation allows execution of arbitrary code.
Last Update Date: 10 Feb 2012 14:40 Release Date: 10 Feb 2012 7577 Views

RISK: High Risk

High Risk

Novell iPrint Client Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell iPrint Client, which can be exploited by malicious people to compromise a user's system. An unspecified error exists in nipplib.dll within the "GetDriverSettings(." function. An unspecified error exists within the "GetPrinterURLList2(." function...
Last Update Date: 10 Feb 2012 14:38 Release Date: 10 Feb 2012 7538 Views

RISK: Medium Risk

Medium Risk

Mulitple QQ products for Android Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mulitple QQ products for Android, which can be exploited by malicious people to bypass certain security restrictions.The vulnerabilities are caused due to an unspecified error and can be exploited to disclose and manipulate certain sensitive information like e.g. ...
Last Update Date: 10 Feb 2012 14:35 Release Date: 10 Feb 2012 8418 Views

RISK: Medium Risk

Medium Risk

ISC BIND Deleted Domain Name Resolving Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to bypass certain security restrictions.The vulnerability is caused due to an error within the cache update policy, which does not properly handle revoked domain names. This can be exploited to...
Last Update Date: 9 Feb 2012 10:01 Release Date: 9 Feb 2012 7620 Views

RISK: High Risk

High Risk

HP-UX Apache Tomcat Servlet Engine Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Apache running Tomcat Servlet Engine, which can be exploited by malicious people to cause a DoS (Denial of Service).
Last Update Date: 8 Feb 2012 11:09 Release Date: 8 Feb 2012 7711 Views

RISK: High Risk

High Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.  An unspecified error exists in rvrender when processing RMFF flags.  An unspecified error exists when processing RV20 frame size array.  An unspecified error exists when...
Last Update Date: 8 Feb 2012 11:08 Release Date: 8 Feb 2012 7844 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which can be exploited to cause cross site scripting, denial of service, elevation of privilege, sensitive information disclosure and remote code excution. These issues are caused by the errors in the following...
Last Update Date: 2 Feb 2012 11:31 Release Date: 2 Feb 2012 7665 Views

RISK: High Risk

High Risk

Apache Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache, which can be exploited to cause denial of service, elevation of privilege, sensitive information disclosure and remote code excution. These issues are caused by the errors in mod_setenvif, mod_log_config, scoreboard, mod_proxy, error responses and...
Last Update Date: 2 Feb 2012 10:11 Release Date: 2 Feb 2012 7867 Views

RISK: High Risk

High Risk

Mozilla Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which can be exploited by malicious people to conduct cross-site scripting attacks, execute arbitrary code and take complete control of an affected system.
Last Update Date: 1 Feb 2012 12:08 Release Date: 1 Feb 2012 7866 Views

RISK: Medium Risk

Medium Risk

Samba smbd Memory Leak Vulnerability

A vulnerability has been identified in Samba smbd, which can be exploited by remote attacker to cause a denial of service.   The vulnerability is caused due to memory leaks on every connection attempt to smbd daemon.  A remote user can attempt to connect to the target server...
Last Update Date: 1 Feb 2012 12:07 Release Date: 1 Feb 2012 8526 Views

RISK: High Risk

High Risk

EMC NetWorker Packets Processing Remote Buffer Overflow Vulnerability

A vulnerability has been identified in EMC NetWorker Server, which can be exploited by remote unauthenticated user to cause a denial of service or, possibly, arbitrary code execution.
Last Update Date: 1 Feb 2012 12:04 Release Date: 1 Feb 2012 7729 Views

RISK: Medium Risk

Medium Risk

Cisco IronPort Appliances telnetd Buffer Overflow Vulnerability

A vulnerability has been identified in some Cisco IronPort Appliances, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to a boundary error within the "encrypt_keyid()" function (crypto/heimdal/appl/telnet/libtelnet/...
Last Update Date: 31 Jan 2012 11:46 Release Date: 31 Jan 2012 7878 Views

RISK: Medium Risk

Medium Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.A boundary error within the DV decoder can be exploited to cause an out-of-...
Last Update Date: 31 Jan 2012 11:45 Release Date: 31 Jan 2012 8852 Views

RISK: High Risk

High Risk

Symantec pcAnywhere / IT Management Suite Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec pcAnywhere and IT Management Suite, which can be exploited by malicious, local users to perform certain actions with escalated privileged and by malicious people to compromise a vulnerable system.Insecure file permissions on certain files, which can be exploited...
Last Update Date: 26 Jan 2012 12:27 Release Date: 26 Jan 2012 7914 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. A use-after-free error exists within the handling of DOM and DOM selections. An uninitialised value exists within Skia. An error...
Last Update Date: 26 Jan 2012 12:24 Release Date: 26 Jan 2012 7609 Views