Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Cisco Multiple Products CGI Validation Vulnerability

Multiple vulnerabilities have been identified in Cisco Modular Encoding Platform D9036 software, Unified Computing System (UCS) Manager software, and Firepower 9000 Series devices. Exploitation of these vulnerabilities could allow a remote attacker to take control of an affected device.
Last Update Date: 21 Jan 2016 09:39 Release Date: 21 Jan 2016 3221 Views

RISK: High Risk

High Risk

Apple iOS / OS X / Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, OS X El Capitan and Safari. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Last Update Date: 21 Jan 2016 09:39 Release Date: 21 Jan 2016 3240 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities were identified in ISC BIND. A remote user can cause the target service to crash.
Last Update Date: 20 Jan 2016 09:49 Release Date: 20 Jan 2016 3273 Views

RISK: High Risk

High Risk

OpenSSH Multiple Vulnerabilities

Two vulnerabilities were identified in OpenSSH. A remote authenticated server can obtain potentially sensitive information from OpenSSH client memory on the target system or potentially execute arbitrary code on the target client system.
Last Update Date: 15 Jan 2016 10:12 Release Date: 15 Jan 2016 3562 Views

RISK: Medium Risk

Medium Risk

DHCP Denial of Service Vulnerability

 A vulnerability was identified in DHCP. A badly formed packet with an invalid IPv4 UDP length field can cause a DHCP server, client, or relay program to terminate abnormally.
Last Update Date: 15 Jan 2016 10:12 Release Date: 15 Jan 2016 3363 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Spoofing Vulnerabilities

Multiple spoofing vulnerabilities exist in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited the vulnerabilities could perform script or content injection attacks, and attempt to trick the user into disclosing sensitive information. An attacker...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3259 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

Multiple vulnerabilities exist in Windows while validating reparse points being set by sandbox applications. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3196 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Multiple DLL Loading Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist when Windows improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited the vulnerabilities could elevate their privileges on a targeted system. DirectShow Heap Corruption Remote Code Execution VulnerabilityA...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3250 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Silverlight decodes strings using a malicious decoder that can return negative offsets that cause Silverlight to replace unsafe object headers with contents provided by an attacker. In a web-browsing scenario, an attacker who successfully exploited this vulnerability could...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3115 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities

Windows GDI32.dll ASLR Bypass VulnerabilityA security feature bypass vulnerability exists in the way that the Windows graphics device interface handles objects in memory, allowing an attacker to retrieve information that could lead to an Address Space Layout Randomization (ASLR) bypass. Win32k Remote Code Execution...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3060 Views