Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Spoofing Vulnerabilities

Multiple spoofing vulnerabilities exist in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited the vulnerabilities could perform script or content injection attacks, and attempt to trick the user into disclosing sensitive information. An attacker...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 4020 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerabilities

Multiple vulnerabilities exist in Windows while validating reparse points being set by sandbox applications. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3945 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Code Execution Vulnerabilities

Multiple DLL Loading Elevation of Privilege VulnerabilitiesMultiple elevation of privilege vulnerabilities exist when Windows improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited the vulnerabilities could elevate their privileges on a targeted system. DirectShow Heap Corruption Remote Code Execution VulnerabilityA...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 4027 Views

RISK: Medium Risk

Medium Risk

Microsoft Silverlight Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Silverlight decodes strings using a malicious decoder that can return negative offsets that cause Silverlight to replace unsafe object headers with contents provided by an attacker. In a web-browsing scenario, an attacker who successfully exploited this vulnerability could...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3889 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities

Windows GDI32.dll ASLR Bypass VulnerabilityA security feature bypass vulnerability exists in the way that the Windows graphics device interface handles objects in memory, allowing an attacker to retrieve information that could lead to an Address Space Layout Randomization (ASLR) bypass. Win32k Remote Code Execution...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3846 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesMultiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3851 Views

RISK: Medium Risk

Medium Risk

Microsoft JScript and VBScript Cumulative Security Update

A remote code execution vulnerability exists in the way that the VBScript engine renders when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3879 Views

RISK: High Risk

High Risk

Microsoft Edge Cumulative Security Update

Microsoft Edge Memory Corruption VulnerabilityA remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. Scripting Engine Memory Corruption VulnerabilityA remote code...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 3830 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the VBScript engine renders when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user...
Last Update Date: 15 Jan 2016 Release Date: 13 Jan 2016 4030 Views

RISK: High Risk

High Risk

Fortinet FortiGate/FortiOS Remote Users Access Vulnerability

A vulnerability has been identified in Fortinet FortiGate/FortiOS, a remote user can gain access to the target system via SSH using an undocumented account.
Last Update Date: 14 Jan 2016 12:05 Release Date: 14 Jan 2016 4181 Views