Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Novell iPrint Client "GetDriverSettings()" Buffer Overflow Vulnerability

A vulnerability has been identifited in Novell iPrint Client, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error within the "GetDriverSettings()" function in nipplib.dll. This can be exploited to...
Last Update Date: 28 Oct 2011 14:59 Release Date: 28 Oct 2011 8095 Views

RISK: Medium Risk

Medium Risk

OpenLDAP "UTF8StringNormalize()" Off-by-One Denial of Service Vulnerability

A vulnerability has been identified in OpenLDAP, which can be exploited by malicious users to cause a Denial of Service.The vulnerability is caused due to an off-by-one error in the "UTF8StringNormalize()" function when NULL terminating a string. This can be...
Last Update Date: 28 Oct 2011 14:59 Release Date: 28 Oct 2011 7943 Views

RISK: Medium Risk

Medium Risk

Winamp Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which can be exploited by malicious people to compromise a user's system.An error in the in_midi.dll plugin when handling the "iOffsetMusic" value within the Creative Music Format (CMF) header can be exploited...
Last Update Date: 28 Oct 2011 14:58 Release Date: 28 Oct 2011 8167 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, conduct cross-site scripting attacks, and potentially compromise a user's system. An error within the history handling can be...
Last Update Date: 27 Oct 2011 16:48 Release Date: 27 Oct 2011 7986 Views

RISK: Medium Risk

Medium Risk

FreeType Multiple Vulnerabilities

Mulitple vulnerabilities have been identified in FreeType, which can be exploited by malicious people to compromise an application using the library. The vulnerabilities are caused due to unspecified errors.
Last Update Date: 25 Oct 2011 11:28 Release Date: 25 Oct 2011 8039 Views

RISK: Medium Risk

Medium Risk

Splunk Cross-Site Scripting and Denial of Service Vulnerabilities

Two vulnerabilities have been identified in Splunk, which can be exploited by malicious people to conduct cross-site scripting attacks and cause Denial of Service.Input passed via the "segment" parameter to prototype/segmentation_performance in the Splunk Web component is not properly sanitised before...
Last Update Date: 21 Oct 2011 11:37 Release Date: 21 Oct 2011 8199 Views

RISK: High Risk

High Risk

Novell ZENworks Configuration Management AdminStudio ActiveX Controls Vulnerabilities

Multiple vulnerabilities have been reported in Novell ZENworks Configuration Management, which can be exploited by malicious people to compromise a user's system. An unspecified error in the "DoFindReplace()" method within the SIGrid.Grid.1 ActiveX control can be exploited...
Last Update Date: 20 Oct 2011 11:30 Release Date: 20 Oct 2011 8119 Views

RISK: High Risk

High Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, and by malicious people to cause a DoS and potentially compromise a vulnerable system. These issues are caused by the errors...
Last Update Date: 20 Oct 2011 11:26 Release Date: 20 Oct 2011 8044 Views

RISK: High Risk

High Risk

Oracle Java SE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Java SE, which can be exploited by attackers to compromise a vulnerable system.
Last Update Date: 19 Oct 2011 09:58 Release Date: 19 Oct 2011 8517 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilies

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to compromise a vulnerable system.
Last Update Date: 19 Oct 2011 09:57 Release Date: 19 Oct 2011 7940 Views

RISK: Medium Risk

Medium Risk

Asterisk SIP Channel Driver Vulnerability

A vulnerability has been identified in Asterisk, which can be exploited to cause denial of service.  A remote authenticated user can cause a crash with a malformed request due to an unitialized variable. 
Last Update Date: 18 Oct 2011 17:28 Release Date: 18 Oct 2011 8046 Views

RISK: High Risk

High Risk

Opera Browser SVG Data Processing Remote Code Execution Vulnerability

A vulnerability has been identified in Opera Browser, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when processing SVG content nested within a frameset and can be exploited via a specially crafted web page...
Last Update Date: 17 Oct 2011 12:27 Release Date: 17 Oct 2011 8096 Views

RISK: High Risk

High Risk

VMware ESX / ESXi Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX and ESXi Server, which can be exploited by malicious people to  disclose sensitive information, gain escalated privileges, conduct spoofing attacks, bypass certain security features, cause a Denial of Service and compromise a vulnerable system.Multiple...
Last Update Date: 14 Oct 2011 11:53 Release Date: 14 Oct 2011 8848 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited to cause sensitive information disclosure, cross site scripting and remote code excution. These issues are caused by the errors in Safari and WebKit.
Last Update Date: 13 Oct 2011 12:45 Release Date: 13 Oct 2011 8060 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which can be exploited to cause elevation of privilege, sensitive information disclosure, security bypass, data manipulation, cross site scripting and remote code excution. These issues are caused by the errors in the following components...
Last Update Date: 13 Oct 2011 12:44 Release Date: 13 Oct 2011 9066 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS 5, which can be exploited to cause sensitive information disclosure, spoofing, cross site scripting and remote code excution. These issues are caused by the errors in the following components/functions: CalDAV Calendar CFNetwork ...
Last Update Date: 13 Oct 2011 12:43 Release Date: 13 Oct 2011 8088 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Win32k Null Pointer De-reference Vulnerability An elevation of privilege vulnerability exists in the way that Windows kernel-mode drivers validate data supplied from user mode to kernel mode. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode and take complete...
Last Update Date: 12 Oct 2011 15:28 Release Date: 12 Oct 2011 8037 Views

RISK: High Risk

High Risk

Microsoft Windows Media Center Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Windows Media Center handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 12 Oct 2011 15:25 Release Date: 12 Oct 2011 7835 Views

RISK: High Risk

High Risk

Microsoft Forefront Unified Access Gateway Multiple Vulnerabilities

ExcelTable Response Splitting XSS Vulnerability An HTTP response splitting vulnerability exists in Microsoft Forefront Unified Access Gateway (UAG) server where JavaScript can be injected back to the user in the resulting page, effectively allowing attacker-controlled JavaScript to run in the context of the user clicking...
Last Update Date: 12 Oct 2011 11:53 Release Date: 12 Oct 2011 8038 Views

RISK: High Risk

High Risk

Microsoft Active Accessibility Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Active Accessibility component handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 12 Oct 2011 11:52 Release Date: 12 Oct 2011 8022 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Scroll Event Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the logged-...
Last Update Date: 12 Oct 2011 11:51 Release Date: 12 Oct 2011 7684 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists where the Ancillary Function Driver (afd.sys) improperly validates input passed from user mode to the Windows kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this vulnerability could...
Last Update Date: 12 Oct 2011 11:51 Release Date: 12 Oct 2011 8117 Views

RISK: Medium Risk

Medium Risk

Microsoft Host Integration Server Denial of Service Vulnerabilities

Endless Loop DoS in snabase.exe Vulnerability An unauthenticated denial of service vulnerability exists in the way that Host Integration Server handles some UDP and TCP network traffic. The vulnerability could allow a remote user to cause snabase.exe, snaserver.exe, snalink.exe...
Last Update Date: 12 Oct 2011 11:47 Release Date: 12 Oct 2011 8023 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited to cause remote code execution. These issues are caused by the errors in CoreFoundation, ColorSync, CoreAudio, CoreMedia, ImageIO and WebKit.
Last Update Date: 12 Oct 2011 11:44 Release Date: 12 Oct 2011 8428 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Class Inheritance Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft .NET Framework and Silverlight framework restrict inheritance within classes. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on user. An attacker could then install...
Last Update Date: 12 Oct 2011 11:39 Release Date: 12 Oct 2011 7895 Views

RISK: Medium Risk

Medium Risk

Autonomy Keyview Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Autonomy Keyview, which can be exploited by malicious people to compromise a vulnerable system.An integer overflow error in jtdsr.dll when parsing QLST chunks within Ichitaro documents can be exploited to cause a heap-based buffer overflow.A...
Last Update Date: 10 Oct 2011 12:26 Release Date: 10 Oct 2011 8661 Views

RISK: High Risk

High Risk

IBM Raditional Appscan Products Two Vulnerabilities

Two vulnerabilities have been identified in IBM Rational AppScan, which can be exploited by malicious people to compromise a user's system. An unspecified error in the import functionality can be exploited via a specially crafted ZIP file. NOTE: This only affects the Enterprise and...
Last Update Date: 7 Oct 2011 15:11 Release Date: 7 Oct 2011 8200 Views

RISK: High Risk

High Risk

Cisco Firewall Services Module Security Bypass and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Firewall Services Module (FWSM), which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service). An error in the implementation of the system log message ID 302015 when generating a log...
Last Update Date: 7 Oct 2011 15:10 Release Date: 7 Oct 2011 8214 Views

RISK: Medium Risk

Medium Risk

Cisco Network Admission Control Directory Traversal Vulnerability

A vulnerability has been identified in Cisco Network Admission Control (NAC), which can be exploited by malicious people to disclose sensitive information. Certain input passed to the management interface via the URL is not properly verified before being used. This can be exploited to disclose the...
Last Update Date: 7 Oct 2011 15:02 Release Date: 7 Oct 2011 8243 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. A use-after-free error exists in text line box handling and the v8 bindings. An error in...
Last Update Date: 6 Oct 2011 14:21 Release Date: 6 Oct 2011 8330 Views

RISK: Medium Risk

Medium Risk

VMware Workstation / Player / Fusion UDF Filesystem Handling Buffer Overflow Vulnerability

A vulnerability has been identified in some VMware products, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when handling UDF filesystem images. This can be exploited to cause a buffer overflow via...
Last Update Date: 6 Oct 2011 14:21 Release Date: 6 Oct 2011 8645 Views

RISK: Medium Risk

Medium Risk

SSL/TLS Protocol Vulnerability

A vulnerability has idenitied in SSL/TLS using Cypher Block Chaining (CBC), which can be exploited by malicious people to conduct Man-in-the-middle attack to decrypt encrypted SSL/TLS traffic and obtain sensitive information. A proof of concept...
Last Update Date: 3 Oct 2011 Release Date: 30 Sep 2011 9379 Views

RISK: High Risk

High Risk

Apache HTTPD Range header vulnerability

A vulnerability has been identified in Apache HTTPD, which can be exploited by remote attacker to cause Denial of Service. The vulnerability can be detected by visiting the following website:http://apache-range-exploit.com/ 
Last Update Date: 3 Oct 2011 Release Date: 29 Aug 2011 10265 Views

RISK: Medium Risk

Medium Risk

Adobe Photoshop Elements 8 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Photoshop Elements 8, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 3 Oct 2011 12:27 Release Date: 3 Oct 2011 9021 Views

RISK: Medium Risk

Medium Risk

Symantec IM Manager Administrator Console Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Symantec IM Manager, which can be exploited by malicious people to conduct Code Injection, Cross-Site Scripting and SQL Injection.
Last Update Date: 3 Oct 2011 12:27 Release Date: 3 Oct 2011 8453 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS, which can be exploited by malicious people to conduct denial of service attack and compromise a user's system.
Last Update Date: 30 Sep 2011 18:32 Release Date: 30 Sep 2011 8651 Views

RISK: High Risk

High Risk

Mozilla Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Thunderbird, which can be exploited by malicious people to compromise a user's system.
Last Update Date: 30 Sep 2011 18:15 Release Date: 30 Sep 2011 8258 Views

RISK: High Risk

High Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple weaknesses and vulnerabilities have been identified in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.Some unspecified errors can be exploited to corrupt memory.An error in the implementation of the "window...
Last Update Date: 30 Sep 2011 18:12 Release Date: 30 Sep 2011 8512 Views

RISK: High Risk

High Risk

Novell GroupWise Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell GroupWise, which can be exploited by malicious people to conduct cross-site scripting attacks, denial of service attack and compromise a user's system. The GroupWise Internet Agent (GWIA) is vulnerable to a DoS exploit whereby...
Last Update Date: 27 Sep 2011 12:26 Release Date: 27 Sep 2011 8239 Views

RISK: Medium Risk

Medium Risk

Apache Tomcat HTTP DIGEST authentication Multiple Vulnerability

在 Apache Tomcat 發現多個漏洞,惡意使用者可利用漏洞繞過保安限制。HTTP DIGEST 核證被發有以下弱點:允許 replay 攻擊沒有檢查伺服...
Last Update Date: 27 Sep 2011 12:17 Release Date: 27 Sep 2011 8613 Views

RISK: High Risk

High Risk

HP TCP/IP Services for OpenVMS Multiple Vunlerabilities

Multiple vulnerabilities have been identified with HP TCP/IP Services for OpenVMS Running NTP. The vulnerabilities could be remotely exploited to execute arbitrary code or create a Denial of Service (DoS).
Last Update Date: 23 Sep 2011 09:28 Release Date: 23 Sep 2011 8072 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Vulnerability

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system. The vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash Player. Please refer to SA11092203...
Last Update Date: 22 Sep 2011 12:21 Release Date: 22 Sep 2011 8620 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.   Note: The vulnerability (CVE-2011-2444) is reportedly being exploited in...
Last Update Date: 22 Sep 2011 12:15 Release Date: 22 Sep 2011 8759 Views

RISK: Medium Risk

Medium Risk

Cisco Identity Services Engine Database Default Credentials Vulnerability

A vulnerability has been identified in Cisco Identity Services Engine, which can be exploited by malicious people to bypass certain security restrictions.   The security issue is caused due to the appliance including an undocumented database account with default credentials. This can be exploited to...
Last Update Date: 22 Sep 2011 10:41 Release Date: 22 Sep 2011 8478 Views

RISK: Medium Risk

Medium Risk

Fraudulent SSL Digital Certificates affect multiple Internet Applications and Network devices

DigiNotar is a Dutch certification authority (CA) for issuing the SSL and EVSSL digital certificate, many internet application and network devices are preloaded the DigiNotar's root certificate in the trusted root certification authorities. The list of known fraudulent certificates issued by DigiNotarby contains some...
Last Update Date: 21 Sep 2011 Release Date: 16 Sep 2011 9127 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, disclose sensitive information, bypass certain security restrictions, and compromise a user...
Last Update Date: 20 Sep 2011 11:48 Release Date: 20 Sep 2011 8525 Views

RISK: Medium Risk

Medium Risk

Oracle Fusion Middleware & Application Server Vulnerability

 A vulnerability have been identified in Oracle Fusion Middleware & Application Server, which can be exploited by remote attacker cause denial of service attack.
Last Update Date: 19 Sep 2011 12:18 Release Date: 19 Sep 2011 9067 Views

RISK: High Risk

High Risk

Adobe Reader and Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which can be exploited by remote attacker cause the application to crash and compromise a vulnerable system.
Last Update Date: 14 Sep 2011 12:09 Release Date: 14 Sep 2011 8196 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Elevation of Privilege Vulnerabilities

XSS in SharePoint Calendar Vulnerability A cross-site scripting vulnerability exists in Microsoft SharePoint 2010 that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL containing malicious JavaScript elements. Due to the vulnerability, when the malicious JavaScript is...
Last Update Date: 14 Sep 2011 11:58 Release Date: 14 Sep 2011 7861 Views

RISK: High Risk

High Risk

Microsoft Office Multiple Remote Code Execution Vulnerabilities

Office Component Insecure Library Loading Vulnerability A remote code execution vulnerability exists in the way that Microsoft Office handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 14 Sep 2011 11:55 Release Date: 14 Sep 2011 7822 Views

RISK: High Risk

High Risk

Microsoft Excel Multiple Remote Code Execution Vulnerabilities

A remote code execution vulnerabilities exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 14 Sep 2011 11:52 Release Date: 14 Sep 2011 7934 Views

RISK: High Risk

High Risk

Microsoft Windows Components Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that certain Windows components handle the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Sep 2011 11:48 Release Date: 14 Sep 2011 7864 Views

RISK: Medium Risk

Medium Risk

Microsoft WINS Local Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in WINS, allowing arbitrary code to be executed in the context of the local system. The vulnerability is caused when the WINS server improperly processes a sequence of specially crafted packets received on the loopback interface. A local attacker who successfully...
Last Update Date: 14 Sep 2011 11:45 Release Date: 14 Sep 2011 8156 Views

RISK: High Risk

High Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system. An error within the processing of certain IKE packets can be exploited to cause an infinite loop...
Last Update Date: 12 Sep 2011 10:22 Release Date: 12 Sep 2011 8377 Views

RISK: Medium Risk

Medium Risk

WordPress DukaPress Shopping Cart Plugin Vulnerability

 A vulnerability has been identified in DukaPress Shopping Cart plugin for WordPress, which can be exploited by remote attacker to compromise a user's system.
Last Update Date: 7 Sep 2011 09:54 Release Date: 7 Sep 2011 8395 Views

RISK: High Risk

High Risk

F-Secure Gadget Resource Handler ActiveX Control "initialize()" Buffer Overflow Vulnerability

A vulnerability has been identified in the F-Secure Gadget Resource Handler ActiveX Control, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the handling of the "initialize()" ...
Last Update Date: 25 Aug 2011 09:25 Release Date: 25 Aug 2011 8450 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and potentially compromise a user's system. An error related to the command line can lead to "URL parsing confusion". Note: This vulnerability affects...
Last Update Date: 24 Aug 2011 12:22 Release Date: 24 Aug 2011 8506 Views

RISK: High Risk

High Risk

RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which can be exploited by malicious people to compromise a user's system. A use-after-free error exists in pngu3267.dll within the handling of displayed dialog boxes when navigating away from a web page. ...
Last Update Date: 18 Aug 2011 12:04 Release Date: 18 Aug 2011 9013 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, disclose certain sensitive information, and compromise a vulnerable system.   Firefox 3.6.x/Thunderbird 3.1.x: Some...
Last Update Date: 18 Aug 2011 12:01 Release Date: 18 Aug 2011 8982 Views

RISK: High Risk

High Risk

Mass Injection Attacks Targeting osCommerce Vulnerabilities

Multiple vulnerabilities have been identified in osCommerce application, which can be exploited by hackers to inject malicious content in vulnerable osCommerce websites.   A large scale injection attack targeting osCommerce websites is reported.  Injected "<iframe>" and "<script>" pointing to malicious links will infect computers...
Last Update Date: 12 Aug 2011 Release Date: 2 Aug 2011 11983 Views

RISK: High Risk

High Risk

Google Chrome Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose sensitive information and compromise a user's system. The vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash Player.   For more information, please...
Last Update Date: 11 Aug 2011 10:32 Release Date: 11 Aug 2011 8930 Views

RISK: High Risk

High Risk

BlackBerry Enterprise Server PNG and TIFF Image Processing Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry Enterprise Server, which can be exploited by malicious people to compromise a vulnerable system. An unspecified error within the BlackBerry MDS Connection Service when processing PNG and TIFF images can be exploited when a specially crafted...
Last Update Date: 11 Aug 2011 10:31 Release Date: 11 Aug 2011 8898 Views

RISK: High Risk

High Risk

Check Point SSL VPN On-Demand Applications Unspecified Vulnerability

A vulnerability have been identified in Check Point SSL VPN On-Demand applications, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error in the helper application (e.g...
Last Update Date: 11 Aug 2011 10:29 Release Date: 11 Aug 2011 9009 Views

RISK: High Risk

High Risk

Adobe Photoshop CS5 Code Execution Vulnerability

A vulnerability has been identified in Adobe Photoshop CS5 and CS5.1, which can be exploited by malicious people to take control of the affected system by convincing a user to open a malicious .GIF file.
Last Update Date: 10 Aug 2011 12:33 Release Date: 10 Aug 2011 9000 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to run malicious code on the affected system.
Last Update Date: 10 Aug 2011 12:32 Release Date: 10 Aug 2011 8576 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited by malicious people to take control of the affected system.
Last Update Date: 10 Aug 2011 12:28 Release Date: 10 Aug 2011 8976 Views

RISK: Medium Risk

Medium Risk

Microsoft Report Viewer Controls XSS Vulnerability

An information disclosure vulnerability exists in the way that the Microsoft Report Viewer control improperly validates parameters within a data source. An attacker who successfully exploited this vulnerability could inject a client-side script in the user's browser. The script could...
Last Update Date: 10 Aug 2011 12:26 Release Date: 10 Aug 2011 8795 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Chart Control Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that Microsoft Chart controls incorrectly handle special characters within a specially crafted URI. An attacker who successfully exploited this vulnerability would be able to read the contents of any file within the web site...
Last Update Date: 10 Aug 2011 12:25 Release Date: 10 Aug 2011 8396 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Desktop Protocol Vulnerability

A denial of service vulnerability exists in the way that the Remote Desktop Protocol accesses an object in memory that has been improperly initialized or has been deleted. An attacker who successfully exploited this vulnerability could cause the target system to stop responding and automatically...
Last Update Date: 10 Aug 2011 12:23 Release Date: 10 Aug 2011 8441 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Stack Multiple Denial of Service Vulnerabilities

ICMP Denial of Service Vulnerability A denial of service vulnerability exists in the Windows TCP/IP stack that is caused when the TCP/IP stack improperly handles a sequence of specially crafted ICMP messages. An attacker who successfully exploited this vulnerability could cause the target system to...
Last Update Date: 10 Aug 2011 12:21 Release Date: 10 Aug 2011 8809 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Vulnerability

An elevation of privilege vulnerability exists in the Client/Server Run-time Subsystem (CSRSS), allowing arbitrary code to be executed in the context of another process. If this process runs with administrator privileges, an attacker could then install programs; view...
Last Update Date: 10 Aug 2011 12:20 Release Date: 10 Aug 2011 6539 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Access Service NDISTAPI Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Remote Access Service NDISTAPI driver. The vulnerability is caused when the NDISTAPI driver improperly validates user-supplied input when passing data from user mode to the Windows kernel. A local attacker who successfully exploited this vulnerability could execute arbitrary...
Last Update Date: 10 Aug 2011 11:56 Release Date: 10 Aug 2011 8357 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Desktop Web Access Vulnerability

A reflected XSS vulnerability exists in Remote Desktop Web Access that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. This script could spoof content, disclose information, or take any action that the user could take...
Last Update Date: 10 Aug 2011 11:54 Release Date: 10 Aug 2011 8499 Views

RISK: High Risk

High Risk

Microsoft Visio Multiple Remote Code Execution Vulnerabilities

pStream Release RCE Vulnerability A remote code execution vulnerability exists in the way that Microsoft Visio validates objects in memory when parsing specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs...
Last Update Date: 10 Aug 2011 11:53 Release Date: 10 Aug 2011 8358 Views

RISK: High Risk

High Risk

Microsoft Windows Data Access Components Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Windows Data Access Tracing component handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 10 Aug 2011 11:52 Release Date: 10 Aug 2011 8516 Views

RISK: High Risk

High Risk

Microsoft Windows DNS Server Multiple Vulnerabilities

DNS NAPTR Query Vulnerability A remote code execution vulnerability exists in the way that the Windows DNS Server improperly handles a specially crafted NAPTR query string in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the system. An attacker could...
Last Update Date: 10 Aug 2011 11:52 Release Date: 10 Aug 2011 8666 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Window Open Race Condition Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that may have been corrupted due to a race condition. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the...
Last Update Date: 10 Aug 2011 11:47 Release Date: 10 Aug 2011 8309 Views

RISK: High Risk

High Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system. An error within the processing of GIF files can be exploited to cause a heap-based buffer overflow by tricking a user into opening a...
Last Update Date: 9 Aug 2011 Release Date: 5 Aug 2011 8739 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a user's system. An unspecified error exists when confirming an extension install via a browser dialog.An unspecified...
Last Update Date: 4 Aug 2011 09:57 Release Date: 4 Aug 2011 9192 Views

RISK: High Risk

High Risk

Apple iWork Numbers / Pages Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iWork, which can be exploited by malicious people to compromise a user's system. An error in iWork Numbers when handling Excel files can be exploited to cause a buffer overflow via a specially crafted file. An error in...
Last Update Date: 27 Jul 2011 09:21 Release Date: 27 Jul 2011 16371 Views

RISK: High Risk

High Risk

Oracle Solaris Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player included in Solaris, which can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system.   For more information, please refer to SA11051601
Last Update Date: 26 Jul 2011 12:16 Release Date: 26 Jul 2011 9221 Views

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, and compromise a user's system. An error within...
Last Update Date: 22 Jul 2011 12:12 Release Date: 22 Jul 2011 8833 Views

RISK: High Risk

High Risk

Foxit Reader ActiveX Control "OpenFile()" Buffer Overflow Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the FoxitReaderOCX ActiveX control when processing the "OpenFile()" method. This can be exploited...
Last Update Date: 22 Jul 2011 11:45 Release Date: 22 Jul 2011 9031 Views

RISK: High Risk

High Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious and local users to cause a DoS (Denial of Service), gain escalated privileges or potentially compromise a vulnerable system. An unspecified error in fingerd can be exploited to cause the system to...
Last Update Date: 21 Jul 2011 10:21 Release Date: 21 Jul 2011 8826 Views

RISK: High Risk

High Risk

Google Picasa JPEG Image Processing Code Execution Vulnerability

A vulnerability has been identified in Google Picasa, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when handling certain properties of an image file and can be exploited to execute arbitrary...
Last Update Date: 21 Jul 2011 10:13 Release Date: 21 Jul 2011 8831 Views

RISK: High Risk

High Risk

Citrix Access Gateway Plug-in ActiveX Control Code Execution Vulnerabilities

Some vulnerabilities have identified in Citrix Access Gateway Plug-in for Windows, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to unspecified errors in the ActiveX control.
Last Update Date: 15 Jul 2011 11:12 Release Date: 15 Jul 2011 8958 Views

RISK: High Risk

High Risk

Apple iOS FreeType PostScript Type1 Font Parsing Vulnerability

A vulnerability has identified in Apple iOS, which can be exploited by malicious people to compromise a vulnerable system.  The vulnerability is caused due to the use of the vulnerable FreeType code.
Last Update Date: 15 Jul 2011 11:03 Release Date: 15 Jul 2011 9023 Views

RISK: High Risk

High Risk

VLC Media Player RealMedia and AVI File Parsing Vulnerabilities

Two vulnerabilities have identified  in VLC Media Player, which can be exploited by malicious people to compromise a user's system.An integer overflow error when parsing a RealAudio data block within RealMedia (RM) files can be exploited to cause a heap-based...
Last Update Date: 14 Jul 2011 15:53 Release Date: 14 Jul 2011 8690 Views

RISK: High Risk

High Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have identified in IBM Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 14 Jul 2011 15:51 Release Date: 14 Jul 2011 8548 Views

RISK: High Risk

High Risk

Microsoft Visio Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Visio handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 13 Jul 2011 11:25 Release Date: 13 Jul 2011 8438 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Multiple Vulnerabilities

CSRSS Local EOP AllocConsole Vulnerability An elevation of privilege vulnerability exists in Windows CSRSS due to the way that the CSRSS subsystem assigns memory for specific user transactions. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 13 Jul 2011 11:23 Release Date: 13 Jul 2011 8329 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Win32k Use After Free Vulnerability An elevation of privilege vulnerability exists due to the way that Windows kernel-mode drivers manage kernel-mode driver objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 13 Jul 2011 11:22 Release Date: 13 Jul 2011 8220 Views

RISK: High Risk

High Risk

Microsoft Windows Bluetooth Stack Vulnerability

A remote code execution vulnerability exists in the Windows Bluetooth 2.1 Stack due to the way an object in memory is accessed when it has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a series of specially crafted Bluetooth...
Last Update Date: 13 Jul 2011 11:21 Release Date: 13 Jul 2011 8385 Views

RISK: High Risk

High Risk

Sun Java JRE Insecure Executable Loading Vulnerability

A vulnerability has identified in Sun Java, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading an executable file in an insecure manner when an out of memory condition occurs. This can be...
Last Update Date: 12 Jul 2011 12:21 Release Date: 12 Jul 2011 8779 Views

RISK: High Risk

High Risk

Microsoft Visio Insecure Library Loading Vulnerability

A vulnerability has been identified in Microsoft Visio, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the application loading libraries (e.g. mfc71enu.dll and mfc71loc.dll) in an insecure manner. ...
Last Update Date: 11 Jul 2011 10:41 Release Date: 11 Jul 2011 8669 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an error when handling UPDATE requests and can be exploited to terminate the named process by sending specially crafted...
Last Update Date: 6 Jul 2011 11:22 Release Date: 6 Jul 2011 8767 Views

RISK: High Risk

High Risk

vsftpd Compromised Source Packages Backdoor Vulnerability

A vulnerability has been identified in vsftpd, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the distribution of backdoored vsftpd version 2.3.4 source code packages (vsftpd-2.3.4....
Last Update Date: 5 Jul 2011 10:58 Release Date: 5 Jul 2011 14768 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Vulnerability

Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.   For more...
Last Update Date: 30 Jun 2011 10:14 Release Date: 30 Jun 2011 8658 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. An error when handling a NPAPI string can be exploited to cause an out-of-bounds read. A use-after-free...
Last Update Date: 30 Jun 2011 10:10 Release Date: 30 Jun 2011 8659 Views

RISK: High Risk

High Risk

Winamp Multiple Vulnerabilities

Multiple vulnerabilities have identified in Winamp, which can be exploited by malicious people to potentially compromise a user's system. An error in vp6.w5s when parsing media files encoded with the On2 TrueMotion VP6 codec where the "version" field value is greater than...
Last Update Date: 28 Jun 2011 14:42 Release Date: 28 Jun 2011 8872 Views