Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which can be exploited to cause cross-site scripting and security bypass. Scripting code can manipulate framed content to bypass the same-origin policy controls. A remote user can cause arbitrary scripting code to be executed by the...
Last Update Date: 26 Jan 2012 11:13 Release Date: 26 Jan 2012 7701 Views

RISK: Medium Risk

Medium Risk

OpenSSL DTLS Denial of Service Vulnerability

A vulnerability has been identified in OpenSSL. A remote user can cause denial of service conditions.   The fix to correct the Datagram Transport Layer Security (DTLS) vulnerability referenced by CVE-2011-4108 (SA12010501) introduced a flaw. A remote user can send...
Last Update Date: 20 Jan 2012 09:59 Release Date: 20 Jan 2012 7883 Views

RISK: High Risk

High Risk

McAfee GroupShield Lotus 123 v4 Parser Unspecified Vulnerability

A vulnerability has been identified in McAfee GroupShield, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to the software bundling a vulnerable Outside In library.
Last Update Date: 19 Jan 2012 13:30 Release Date: 19 Jan 2012 7879 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilies

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to conduct cross-site scripting attacks, denial of service, elevation of privilege, disclose sensitive information, data manipulation or compromise a vulnerable system.
Last Update Date: 19 Jan 2012 13:26 Release Date: 19 Jan 2012 7899 Views

RISK: Medium Risk

Medium Risk

Cisco Digital Media Manager Privilege Escalation Vulnerability

A vulnerability has identified in Cisco Digital Media Manager which could be exploited by a remote authenticated user to gain elevated privileges on the target system.The system does not properly validate unreferenced URLs. A remote authenticated user can send a specially crafted URL via TCP port 8443...
Last Update Date: 19 Jan 2012 13:26 Release Date: 19 Jan 2012 7805 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Hash Collision Denial of Service Vulnerability

A vulnerability has been identified in IBM WebSphere Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an error within a hash generation function when hashing form posts and updating a hash table. ...
Last Update Date: 18 Jan 2012 14:31 Release Date: 18 Jan 2012 8010 Views

RISK: Medium Risk

Medium Risk

IBM HTTP Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM HTTP Server, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
Last Update Date: 18 Jan 2012 14:30 Release Date: 18 Jan 2012 8009 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat Request Object Recycle Security Bypass Vulnerability

A security issue has been identified in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions.  The security issue is caused due to the request object not being recycled before processing the next request when logging certain actions. This can lead to...
Last Update Date: 18 Jan 2012 14:30 Release Date: 18 Jan 2012 8050 Views

RISK: High Risk

High Risk

ISC DHCP DHCPv6 Dynamic DNS Remote Denial of Service Vulnerability

A vulnerability has been identified in ISC DHCP, which can be exploited by malicious people to cause a segmentation fault in ISC DHCP servers using IPv6 and Dynamic DNS, resulting in denial of service to clients.  Due to improper handling of a DHCPv6 lease structure, ISC...
Last Update Date: 18 Jan 2012 14:30 Release Date: 18 Jan 2012 7853 Views

RISK: High Risk

High Risk

7-Technologies Interactive Graphical SCADA System Insecure Library Loading Vulnerability

A vulnerability has been identified in 7-Technologies Interactive Graphical SCADA System, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to the application loading certain libraries in an insecure manner, which can be exploited to...
Last Update Date: 18 Jan 2012 14:29 Release Date: 18 Jan 2012 7709 Views

RISK: Medium Risk

Medium Risk

Yahoo Messenger JPG Photo Sharing Integer Overflow Vulnerability

A vulnerability has been identified in Yahoo Messenger, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error in the "CYImage::LoadJPG()" method (YImage.dll) when allocating memory...
Last Update Date: 16 Jan 2012 11:23 Release Date: 16 Jan 2012 7839 Views

RISK: High Risk

High Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system. NULL pointer dereference errors when reading certain packet information can be exploited to cause a crash...
Last Update Date: 12 Jan 2012 10:29 Release Date: 12 Jan 2012 7792 Views

RISK: Medium Risk

Medium Risk

Microsoft Anti-Cross Site Scripting Library Bypass Vulnerability

An information disclosure vulnerability exists when the Microsoft Anti-Cross Site Scripting (AntiXSS) Library incorrectly sanitizes specially crafted HTML. An attacker who successfully exploited this vulnerability could perform a cross-site scripting (XSS) attack on a website that is using the AntiXSS Library...
Last Update Date: 11 Jan 2012 11:09 Release Date: 11 Jan 2012 7983 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SSL/TLS Protocols Vulnerability

An information disclosure vulnerability exists in SSL 3. and TLS 1. encryption protocols. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS traffic. This...
Last Update Date: 11 Jan 2012 11:06 Release Date: 11 Jan 2012 7976 Views

RISK: High Risk

High Risk

Microsoft Windows Assembly Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Packager loads ClickOnce applications embedded in Microsoft Office files.
Last Update Date: 11 Jan 2012 11:06 Release Date: 11 Jan 2012 7827 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows CSRSS due to the way that the CSRSS processes a sequence of specially crafted Unicode characters. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then...
Last Update Date: 11 Jan 2012 11:04 Release Date: 11 Jan 2012 7717 Views

RISK: High Risk

High Risk

Microsoft Windows Object Packager Insecure Executable Launching Vulnerability

A remote code execution vulnerability exists in the way that Windows registers and uses the Windows Object Packager. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 11 Jan 2012 11:03 Release Date: 11 Jan 2012 7731 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel SafeSEH Bypass Vulnerability

A security feature bypass vulnerability exists in Windows due to the way the kernel loads the structured exception handling tables. An attacker who successfully exploited this vulnerability could bypass the SafeSEH defense-in-depth mechanism to facilitate exploitation of other vulnerabilities.
Last Update Date: 11 Jan 2012 11:01 Release Date: 11 Jan 2012 8115 Views

RISK: High Risk

High Risk

Microsoft Windows Media Multiple Remote Code Execution Vulnerabilities

MIDI Remote Code Execution Vulnerability A remote code execution vulnerability exists in Windows Media Player. An attacker could exploit this vulnerability by constructing a specially crafted MIDI file that could allow remote code execution when played using Windows Media Player. An attacker who successfully exploited this vulnerability could...
Last Update Date: 11 Jan 2012 10:59 Release Date: 11 Jan 2012 7730 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Community Edition Tomcat Container Denial of Service Vulnerability

A vulnerability has been reported in IBM WebSphere Application Server Community Edition, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error within the Tomcat container and can be exploited to cause a crash...
Last Update Date: 11 Jan 2012 09:49 Release Date: 11 Jan 2012 7817 Views

RISK: High Risk

High Risk

Adobe Reader and Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which can be exploited to execute arbitrary code on the target user's system.  A remote user can create a specially crafted file that, when loaded by the target user, will execute arbitrary code on...
Last Update Date: 11 Jan 2012 09:44 Release Date: 11 Jan 2012 7801 Views

RISK: Medium Risk

Medium Risk

GnuTLS DTLS CBC Mode Plaintext Recovery Vulnerability

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to disclose potentially sensitive information.The vulnerability is caused due to the CBC mode encryption of the Datagram Transport Layer Security (DTLS) implementation exposing timing differences, which can be exploited to...
Last Update Date: 10 Jan 2012 11:32 Release Date: 10 Jan 2012 7841 Views

RISK: High Risk

High Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious users to disclose certain information and by malicious people to disclose potentially sensitive information, hijack a user's session, conduct DNS cache poisoning attacks, manipulate certain data, cause a DoS...
Last Update Date: 10 Jan 2012 11:27 Release Date: 10 Jan 2012 7777 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.A use-after-free error exists within the handling of animation frames.A boundary error within the "xmlStringLenDecodeEntities()" function (parser...
Last Update Date: 9 Jan 2012 12:42 Release Date: 9 Jan 2012 7803 Views

RISK: High Risk

High Risk

FFmpeg Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system.Errors when processing MKV and Vorbis files can be exploited to cause an out-of-bounds...
Last Update Date: 9 Jan 2012 12:41 Release Date: 9 Jan 2012 8320 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Drag and Drop Handling Same Origin Policy Bypass Vulnerability

A vulnerability has been identified in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions.The vulnerability is caused due to an error when handling drag and drop events and can be exploited to bypass the same origin policy and e.g...
Last Update Date: 6 Jan 2012 10:37 Release Date: 6 Jan 2012 8572 Views

RISK: High Risk

High Risk

OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenSSL, which can be exploited by attackers to conduct remote code execution and denial of service. The vulnerabilities can cause the following issues:DTLS Plaintext Recovery Attack (CVE-2011-4108)Double-free in Policy Checks (...
Last Update Date: 5 Jan 2012 11:57 Release Date: 5 Jan 2012 8391 Views

RISK: Medium Risk

Medium Risk

MIT Kerberos krb5 Telnet Daemon and Client Buffer Overflow Vulnerability

A vulnerability has been identified in the telnet daemon (telnetd) and telnet client of MIT Kerberos krb5, which can be exploited by unauthenticated remote attacker to cause a buffer overflow and probably execute arbitrary code with the privileges of the telnet daemon.
Last Update Date: 4 Jan 2012 11:16 Release Date: 4 Jan 2012 8289 Views

RISK: High Risk

High Risk

Multiple programming languages and frameworks Hash Table collision denial of service vulnerability

A vulnerability has been identified in multiple web programming languages and frameworks, which can be exploited by malicious people to cause a DoS (Denial of Service). A variety of programming languages and platforms suffered from a Denial of Service (DoS) condition against storage functions of...
Last Update Date: 30 Dec 2011 18:10 Release Date: 30 Dec 2011 8961 Views

RISK: High Risk

High Risk

Microsoft ASP .NET Framework Multiple Vulnerabilities

Collisions in HashTable May Cause DoS Vulnerability A denial of service vulnerability exists in the way that ASP.NET Framework handles specially crafted requests, causing a hash collision. An attacker who successfully exploited this vulnerability could send a small number of specially crafted requests to an...
Last Update Date: 30 Dec 2011 18:08 Release Date: 30 Dec 2011 8662 Views

RISK: Medium Risk

Medium Risk

WiFi Protected Setup (WPS) PIN authentication vulnerability

A vulnerability has been identified in WiFi Protected Setup (WPS), which can be exploited by malicious people to bypass security restrictions or cause a denial of service. A design flaw that exists in the WPS specification for the PIN authentication significantly reduces the time required to brute...
Last Update Date: 30 Dec 2011 12:36 Release Date: 30 Dec 2011 19241 Views

RISK: High Risk

High Risk

Microsoft ASP.NET Hash Table Collision Denail of Service Vulnerability

A vulnerability has been identified in Microsoft ASP.NET. which can be exploited by malicious user to cause denial of service.A remote user can send specially crafted posts to cause significant performance degradation on the target server.The vulnerability occurs due to the way that...
Last Update Date: 30 Dec 2011 Release Date: 29 Dec 2011 8096 Views

RISK: Medium Risk

Medium Risk

F5 Enterprise Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in F5 Enterprise Manager, which can be exploited by malicious, local users to gain escalated privileges, by malicious users to cause a DoS (Denial of Service), and by malicious people to bypass certain security restrictions.
Last Update Date: 29 Dec 2011 15:18 Release Date: 29 Dec 2011 7934 Views

RISK: High Risk

High Risk

GNU inetutils telnetd Buffer Overflow Vulnerability

A vulnerability has been identified in GNU inetutils, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to a boundary error within the "encrypt_keyid()" function (libtelnet/encrypt.c), which can be exploited to cause...
Last Update Date: 28 Dec 2011 15:28 Release Date: 28 Dec 2011 8139 Views

RISK: Medium Risk

Medium Risk

HP Managed Printing Administration Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Managed Printing Administration, which can be exploited by malicious people to compromise a vulnerable system.An input sanitisation error in the MPAUploader.Uploader.1.UploadFiles() function can be exploited to create arbitrary files via directory traversal sequences...
Last Update Date: 28 Dec 2011 15:26 Release Date: 28 Dec 2011 7939 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Phone Message Processing Denial of Service Vulnerability

A vulnerability has been identified in Microsoft Windows Phone, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error in the processing of messages. This can be exploited to trigger a reboot and render...
Last Update Date: 28 Dec 2011 15:20 Release Date: 28 Dec 2011 7586 Views

RISK: Medium Risk

Medium Risk

Websense Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Websense products, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a vulnerable system. An unspecified error within the report...
Last Update Date: 28 Dec 2011 15:18 Release Date: 28 Dec 2011 7848 Views

RISK: Medium Risk

Medium Risk

Android Browser Certificate Spoofing Vulnerability

A vulnerability has been identified in Android, which can be exploited by malicious people to conduct spoofing attacks.The vulnerability is caused due to Browser displaying wrong certificate information, which can be exploited to trick a user into believing to be connected to a trusted site by...
Last Update Date: 28 Dec 2011 15:02 Release Date: 28 Dec 2011 7916 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Domino Authentication Processing Denial of Service Vulnerability

A vulnerability has been identified in IBM Lotus Domino. A remote user can cause denial of service conditions.A remote user can send a specially crafted packet to the target Domino Server via Notes RPC to cause the target server to crash.The vulnerability occurs during Notes...
Last Update Date: 28 Dec 2011 14:55 Release Date: 28 Dec 2011 8003 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox / Thunderbird JAR File Handling Vulnerability

A vulnerability has been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to compromise a user's system.A malicious JAR file could be downloaded and executed if a user is convinced into holding down the "Enter" key via e...
Last Update Date: 23 Dec 2011 10:22 Release Date: 23 Dec 2011 8150 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which can be exploited by malicious people to disclose sensitive information and compromise a user's system. Some unspecified errors can be exploited to corrupt memory. An error exists within the YARR regular expression...
Last Update Date: 22 Dec 2011 12:22 Release Date: 22 Dec 2011 7736 Views

RISK: High Risk

High Risk

VLC Media Player "get_chunk_header()" Double-Free Vulnerability

A vulnerability has been identified in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a double-free error within the "get_chunk_header()" function (modules/demux/ty...
Last Update Date: 22 Dec 2011 11:08 Release Date: 22 Dec 2011 7536 Views

RISK: Medium Risk

Medium Risk

IrfanView Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IrfanView, which can be exploited by malicious people to compromise a user's system.Due to an error when processing TIFF images with certain "Rows Per Strip" and "Samples Per Pixel" values, which can be exploited...
Last Update Date: 21 Dec 2011 10:44 Release Date: 21 Dec 2011 7763 Views

RISK: High Risk

High Risk

Microsoft Windows win32k.sys Memory Corruption Vulnerability

A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g...
Last Update Date: 20 Dec 2011 11:09 Release Date: 20 Dec 2011 8041 Views

RISK: High Risk

High Risk

Tor "buf_pullup()" Buffer Overflow Vulnerability

A vulnerability has been identified in Tor, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an error within the "buf_pullup()" function (or/buffers.c) when repacking data and can be...
Last Update Date: 20 Dec 2011 11:08 Release Date: 20 Dec 2011 7516 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Acrobat and Reader PDF Data Processing Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which can be exploited to cause a crash and potentially allow attackers to take control of the affected system. Notes: Vendor supplied patch is currently unavailable.  There are reports that the vulnerability is being actively exploited...
Last Update Date: 19 Dec 2011 Release Date: 7 Dec 2011 8233 Views

RISK: Medium Risk

Medium Risk

RSA SecurID Software Token Insecure Library Loading Vulnerability

A vulnerability has identified in RSA SecurID Software Token, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading libraries (e.g. wintab32.dll) in an insecure manner. This...
Last Update Date: 16 Dec 2011 10:43 Release Date: 16 Dec 2011 7983 Views

RISK: High Risk

High Risk

GTK+ Insecure Library Loading Vulnerability

A vulnerability has been identified in GTK+, which can be exploited by malicious people to compromise an application using the library. The vulnerability is caused due to the "_gdk_input_wintab_init_check()" (gdk/win32/gdkinput-win32.c) and the "xp_theme_init()" functions (...
Last Update Date: 16 Dec 2011 Release Date: 6 Sep 2011 8316 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, and compromise a user's system. An error in regex matching, libxml, PDF parser, SVG parsing, handling YUV...
Last Update Date: 15 Dec 2011 10:39 Release Date: 15 Dec 2011 7899 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

XSS Filter Information Disclosure VulnerabilityAn information disclosure vulnerability exists in Internet Explorer. An attacker could exploit the vulnerability by constructing a specially crafted Web page that contains malicious JavaScript code. An attacker who successfully exploited this vulnerability could view content from another domain or Internet Explorer zone....
Last Update Date: 14 Dec 2011 14:53 Release Date: 14 Dec 2011 7702 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows kernel due to the way the kernel accesses an object that has not been correctly initialized. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, ...
Last Update Date: 14 Dec 2011 14:50 Release Date: 14 Dec 2011 7779 Views

RISK: High Risk

High Risk

Microsoft Windows Client/Server Runtime Subsystem Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Client/Server Run-time Subsystem (CSRSS), allowing arbitrary code to be executed in the context of another process. If this process runs with administrator privileges, an attacker could then install programs; view, change, ...
Last Update Date: 14 Dec 2011 14:49 Release Date: 14 Dec 2011 8025 Views

RISK: High Risk

High Risk

Microsoft Excel Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 14 Dec 2011 14:34 Release Date: 14 Dec 2011 7598 Views

RISK: High Risk

High Risk

Microsoft Windows Active Directory Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Active Directory. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain. An attacker could then run a specially crafted application that could exploit the vulnerability...
Last Update Date: 14 Dec 2011 12:34 Release Date: 14 Dec 2011 7772 Views

RISK: High Risk

High Risk

Microsoft Publisher Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Publisher parses Publisher files. An attacker could exploit the vulnerability by creating a specially crafted Publisher file that could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site...
Last Update Date: 14 Dec 2011 12:33 Release Date: 14 Dec 2011 7913 Views

RISK: High Risk

High Risk

Microsoft PowerPoint Remote Code Execution Vulnerabilities

PowerPoint Insecure Library Loading Vulnerability A remote code execution vulnerability exists in the way that Microsoft PowerPoint handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 14 Dec 2011 12:32 Release Date: 14 Dec 2011 8005 Views

RISK: High Risk

High Risk

Microsoft Time Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Microsoft Time component. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could...
Last Update Date: 14 Dec 2011 12:31 Release Date: 14 Dec 2011 7675 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Word handles specially crafted Word files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 14 Dec 2011 12:30 Release Date: 14 Dec 2011 7512 Views

RISK: High Risk

High Risk

Microsoft Windows OLE32 Remote Code Execution Vulnerability

A vulnerability exists in OLE that could lead to remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on...
Last Update Date: 14 Dec 2011 12:29 Release Date: 14 Dec 2011 7783 Views

RISK: High Risk

High Risk

Microsoft Office IME (Chinese) Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists due to the way that the Microsoft Office IME (Chinese) improperly exposes configuration options not designed to run on the secure desktop. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then...
Last Update Date: 14 Dec 2011 12:27 Release Date: 14 Dec 2011 7890 Views

RISK: High Risk

High Risk

Microsoft Windows Media Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Media Player and Windows Media Center handle .dvr-ms files. This vulnerability could allow an attacker to execute arbitrary code if the attacker convinces a user to open a specially crafted .dvr-ms file...
Last Update Date: 14 Dec 2011 12:27 Release Date: 14 Dec 2011 7718 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Windows kernel due to improper handling of a specially crafted TrueType font file. The vulnerability could allow an attacker to run code in kernel-mode and then install programs; view, change, or delete data; or create...
Last Update Date: 14 Dec 2011 12:26 Release Date: 14 Dec 2011 7698 Views

RISK: Medium Risk

Medium Risk

Winamp AVI / IT File Processing Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which can be exploited by malicious people to compromise a user's system. An integer overflow error in the in_avi.dll plugin when allocating memory using the number of streams header value can be exploited to cause a heap...
Last Update Date: 13 Dec 2011 11:37 Release Date: 13 Dec 2011 7833 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an unspecified error. Successful exploitation allows execution of arbitrary code.   Notes: Vendor supplied patch is currently...
Last Update Date: 9 Dec 2011 10:28 Release Date: 9 Dec 2011 7980 Views

RISK: High Risk

High Risk

Foxit Reader Unspecified Memory Corruption Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error.
Last Update Date: 8 Dec 2011 10:07 Release Date: 8 Dec 2011 7823 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Opera, where one has an unknown impact and others can be exploited by malicious people to bypass certain security features, disclose potentially sensitive information, and hijack a user's session. An unspecified error exists. No further information is...
Last Update Date: 7 Dec 2011 14:26 Release Date: 7 Dec 2011 8207 Views

RISK: Medium Risk

Medium Risk

Blue Coat ProxyAV libpng Buffer Overflow Vulnerability

Multiple vulnerabilities have identified in Blue Coat ProxyAV, which can be exploited by malicious people to compromise a vulnerable device.An error within progressive applications when handling image row data can be exploited to potentially cause a buffer overflow by e.g. providing one additional image...
Last Update Date: 6 Dec 2011 11:43 Release Date: 6 Dec 2011 8170 Views

RISK: Medium Risk

Medium Risk

Serv-U FTPS Server Command Channel SSL Negotiation and FTP Server Directory Traversal Vulnerability

Two vulnerability have been identified in Serv-U, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information and manipulate certain data.The vulnerability is caused due to the FTPS server leaving the command channel in an operational state, ...
Last Update Date: 6 Dec 2011 Release Date: 2 Dec 2011 8053 Views

RISK: Medium Risk

Medium Risk

HP LaserJet Printers / Digital Senders Unauthorized Firmware Update Vulnerability

A vulnerability has been identified in various HP LaserJet Printers and HP Digital Senders, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error within the Remote Firmware Update (RFU) mechanism, which does not check...
Last Update Date: 2 Dec 2011 15:27 Release Date: 2 Dec 2011 10003 Views

RISK: High Risk

High Risk

Schneider Electric Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple Schneider Electric products, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, and compromise a user's system. Two errors in the TeeChart ActiveX control can be exploited to...
Last Update Date: 30 Nov 2011 10:18 Release Date: 30 Nov 2011 8182 Views

RISK: High Risk

High Risk

Siemens Automation License Manager Denial of Service and ActiveX Control Vulnerabilities

Multiple vulnerabilities have identified in Siemens Automation License Manager, which can be exploited by malicious people to cause a DoS (Denial of Service) and manipulate certain data.An error in almsrvx.exe when processing certain requests can be exploited to cause an unhandled exception and...
Last Update Date: 29 Nov 2011 10:41 Release Date: 29 Nov 2011 8284 Views

RISK: Medium Risk

Medium Risk

Novell NetWare XNFS.NLM "xdrDecodeString()" Buffer Overflow Vulnerability

A vulnerability has been identified in Novell NetWare, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the "xdrDecodeString()" function in XNFS.NLM when processing certain NFS requests. This can...
Last Update Date: 25 Nov 2011 10:01 Release Date: 25 Nov 2011 7710 Views

RISK: High Risk

High Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious users to disclose potentially sensitive information, cause a DoS (Denial of Service), and compromise a vulnerable system. For more information, please refer to SA11101902.
Last Update Date: 24 Nov 2011 09:40 Release Date: 24 Nov 2011 8182 Views

RISK: High Risk

High Risk

Cisco Security Agent Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Security Agent, which can be exploited by unauthenticated attacker to perform remote code execution on the affected device. These  vulnerabilities are in a third-party library (Oracle Outside In). 
Last Update Date: 22 Nov 2011 14:30 Release Date: 22 Nov 2011 7974 Views

RISK: Medium Risk

Medium Risk

Novell Open Enterprise Server iPrint Client "GetDriverSettings()" Buffer Overflow Vulnerability

A vulnerability has been identified in Novell Open Enterprise Server, which can be exploited by malicious people to compromise a user's system.   For more information, please refer to SA11102803.
Last Update Date: 22 Nov 2011 14:27 Release Date: 22 Nov 2011 7734 Views

RISK: High Risk

High Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system.  Successful exploitation of the vulnerabilities may allow execution of arbitrary code.     An unspecified error related to RealVideo rendering can be exploited to cause a heap-...
Last Update Date: 22 Nov 2011 14:26 Release Date: 22 Nov 2011 8537 Views

RISK: Medium Risk

Medium Risk

Juniper Junos IPv6 Over IPv4 Tunnel Security Policy Bypass Vulnerability

A vulnerability has been identified in Juniper Junos, which can be exploited by malicious people to bypass certain security restrictions.The vulnerability is caused due to an error when enforcing security policies on IPv6 over IPv4 tunnels. This can lead to certain security policies not being enforced...
Last Update Date: 18 Nov 2011 15:00 Release Date: 18 Nov 2011 8105 Views

RISK: High Risk

High Risk

Google Chrome V8 Memory Corruption Vulnerability

A vulnerability has been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an error in V8 (JavaScript engine) and can be exploited to cause an out of bounds write and...
Last Update Date: 18 Nov 2011 14:59 Release Date: 18 Nov 2011 8500 Views

RISK: High Risk

High Risk

ISC BIND Recursive Query Processing Denial of Service Vulnerability

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error when processing recursive queries. NOTE: The vulnerability is currently being actively exploited.
Last Update Date: 17 Nov 2011 11:48 Release Date: 17 Nov 2011 8473 Views

RISK: Medium Risk

Medium Risk

FreeType CID-keyed Font Parsing Vulnerabilities

Multiple vulnerabilities have been identified in FreeType, which can be exploited by malicious people to compromise an application using the library.  The vulnerabilities are caused due to errors in src/cid/cidload.c when parsing CID-keyed Type 1 fonts. This can be...
Last Update Date: 16 Nov 2011 10:22 Release Date: 16 Nov 2011 8100 Views

RISK: Medium Risk

Medium Risk

Joomla! Security Bypass and Cross-Site Scripting Vulnerability

Two vulnerability have been identified in Joomla!, which can be exploited by malicious people to bypass certain security restrictions and conduct cross-site scripting attacks. Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML...
Last Update Date: 15 Nov 2011 12:26 Release Date: 15 Nov 2011 8343 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. The application bundles a vulnerable version of the Adobe Flash player.For details, please refer to HKCERT security bulletin...
Last Update Date: 15 Nov 2011 12:22 Release Date: 15 Nov 2011 7984 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by attackers to take control of the affected system. 
Last Update Date: 14 Nov 2011 Release Date: 11 Nov 2011 8469 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple Vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people to obtain sensitive information and execute arbitrary code on the affected system. A remote user can create a specially crafted FreeType font that, when loaded by the target user, will execute...
Last Update Date: 14 Nov 2011 Release Date: 11 Nov 2011 8116 Views

RISK: Medium Risk

Medium Risk

ProFTPD Response Pool Use-After-Free Vulnerability

A vulnerability has been identified in ProFTPD, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to a use-after-free error when handling response pool allocation lists and can be exploited to corrupt memory.Successful exploitation...
Last Update Date: 14 Nov 2011 Release Date: 11 Nov 2011 8200 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Java for Apple Mac OS X, which can be exploited by malicious users to disclose certain information and by malicious people to disclose potentially sensitive information, hijack a user's session, conduct DNS cache poisoning attacks, manipulate certain data...
Last Update Date: 10 Nov 2011 11:25 Release Date: 10 Nov 2011 7858 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Application Server Web Services Feature Pack Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Application Server Web Services Feature Pack, which can be exploited by malicious people to cause a Denial of Service (DoS).WSRMModule holds on to AxisService references and eventually causes OutOfMemory error.org.apache.commons.logging...
Last Update Date: 10 Nov 2011 Release Date: 8 Nov 2011 8299 Views

RISK: High Risk

High Risk

Mozilla Products Multiple vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to execute arbitrary code and take complete control of an affected system.
Last Update Date: 9 Nov 2011 12:39 Release Date: 9 Nov 2011 8082 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by attackers to run malicious code on the affected system.
Last Update Date: 9 Nov 2011 12:34 Release Date: 9 Nov 2011 7776 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TrueType Font Parsing Vulnerability

A denial of service vulnerability exists in the Microsoft Windows kernel. This vulnerability is caused when the Windows kernel improperly processes a specifically crafted TrueType font file. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding and restart.
Last Update Date: 9 Nov 2011 12:32 Release Date: 9 Nov 2011 8074 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory LDAPS Authentication Bypass Vulnerability

An elevation of privilege vulnerability exists in Active Directory when configured to use LDAP over SSL (LDAPS). An attacker could exploit this vulnerability by using a previously revoked certificate to authenticate to the Active Directory domain and gain access to network resources or run code under the privileges...
Last Update Date: 9 Nov 2011 12:29 Release Date: 9 Nov 2011 8203 Views

RISK: High Risk

High Risk

Microsoft Windows Mail / Windows Meeting Space Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Windows Mail and Windows Meeting Space handle the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 9 Nov 2011 12:26 Release Date: 9 Nov 2011 7972 Views

RISK: High Risk

High Risk

Microsoft Windows TCP/IP Reference Counter Overflow Vulnerability

A remote code execution vulnerability exists in the Windows TCP/IP stack due to the processing of a continuous flow of specially crafted UDP packets. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view...
Last Update Date: 9 Nov 2011 12:22 Release Date: 9 Nov 2011 7923 Views

RISK: High Risk

High Risk

Microsoft Windows TrueType Font Parsing Code Execution Vulnerability

A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious people to  compromise a vulnerable system. The vulnerability is caused due to an error within the Win32k kernel-mode driver (win32k.sys) when parsing TrueType fonts.
Last Update Date: 7 Nov 2011 10:48 Release Date: 7 Nov 2011 8235 Views

RISK: High Risk

High Risk

phpMyadmin XML Entity References Information Disclosure Vulnerability

A vulnerability has been identified in phpMyAdmin, which can be exploited by malicious users to disclose potentially sensitive information.The vulnerability is caused due to an error within libraries/import/xml.php when processing XML data, which can be exploited to e.g...
Last Update Date: 4 Nov 2011 10:22 Release Date: 4 Nov 2011 8048 Views

RISK: High Risk

High Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system. An error related to an uninitialised variable within the CSN.1 dissector can be exploited to cause a crash...
Last Update Date: 3 Nov 2011 11:18 Release Date: 3 Nov 2011 7912 Views

RISK: Medium Risk

Medium Risk

D-Link Products SSH Server Buffer Overflow Vulnerability

A vulnerability has been identified in multiple D-Link products, which can be exploited by malicious people to cause a DoS (Denial of Service) a vulnerable device. The vulnerability is caused due to an unspecified error within the Secure Shell (SSH) server and...
Last Update Date: 31 Oct 2011 12:47 Release Date: 31 Oct 2011 8167 Views

RISK: High Risk

High Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in multiple products, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, bypass certain security restrictions, conduct spoofing attacks, conduct DNS cache poisoning attacks, cause a DoS (Denial of Service...
Last Update Date: 31 Oct 2011 12:47 Release Date: 31 Oct 2011 7989 Views

RISK: Medium Risk

Medium Risk

Cisco Security Agent Outside In Technology File Processing Vulnerabilities

Two vulnerabilities identified in Cisco Security Agent, which can be exploited by malicious people to compromise a vulnerable system.An unspecified error exists in the vswk6.dll and sccut.dll modules when handling Lotus 123 files.A second unspecified error exists in the vswk6....
Last Update Date: 28 Oct 2011 15:00 Release Date: 28 Oct 2011 7985 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Quicktime, which can be exploited by malicious people to compromise a user's system.An integer overflow error when handling PICT files can be exploited via a specially crafted .pict file.A signedness error when handling font tables...
Last Update Date: 28 Oct 2011 15:00 Release Date: 28 Oct 2011 8032 Views