Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Components Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the TS WebProxy Windows component. The vulnerability is caused when Windows fails to properly sanitize file paths. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3106 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows User Profile Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Windows User Profile Service (ProfSvc) validates user privilege. An authenticated attacker who successfully exploits the vulnerability could leverage the Windows User Profile Service (ProfSvc) to load registry hives associated with other user accounts and potentially execute...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3196 Views

RISK: High Risk

High Risk

Microsoft Windows Telnet Service Remote Code Execution Vulnerability

A buffer overflow vulnerability exists in Windows Telnet service that could allow remote code execution. The vulnerability is caused when the Telnet service improperly validates user input. An attacker could attempt to exploit this vulnerability by sending specially crafted telnet packets to a Windows server, and if...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3586 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Application Compatibility Cache Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Microsoft Windows Application Compatibility Infrastructure (AppCompat) improperly checks the authorization of the caller's impersonation token. An attacker could attempt to exploit this to run a privileged application. The update addresses the vulnerability by implementing proper...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3142 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system, and obtain potentially sensitive information. A remote user can create specially crafted Flash content that, when loaded by the target user...
Last Update Date: 14 Jan 2015 09:47 Release Date: 14 Jan 2015 3199 Views

RISK: High Risk

High Risk

Windows Kernel Elevation of Privilege Vulnerability

A vulnerability has been identified in Windows Kernel, which can be exploited by local user to obtain elevated privileges on the target system. The NtApphelpCacheControl() function in 'ahcache.sys' does not properly validate the caller's impersonation token for administrator privileges. A...
Last Update Date: 5 Jan 2015 10:26 Release Date: 5 Jan 2015 3521 Views

RISK: Medium Risk

Medium Risk

Docker Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Docker, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to manipulate certain data.An error when extracting images or mounting volumes can be exploited to e.g. manipulate certain...
Last Update Date: 29 Dec 2014 10:13 Release Date: 29 Dec 2014 3368 Views

RISK: High Risk

High Risk

"Misfortune Cookie" Vulnerability on Multiple Broadband Routers

Many home and office/home office (SOHO) routers have been identitied to be using vulnerable versions of the Allegro RomPager embedded web server. Allegro RomPager versions prior to 4.34 contain a vulnerability in cookie processing code that can be leveraged to grant attackers administrative...
Last Update Date: 22 Dec 2014 10:56 Release Date: 22 Dec 2014 3421 Views

RISK: Medium Risk

Medium Risk

Network Time Protocol daemon (ntpd) Multiple Vulnerabilities

The buffer overflow vulnerabilities were identified in ntpd, which may allow a remote unauthenticated attacker to execute arbitrary malicious code with the privilege level of the ntpd process. The weak default key and non-cryptographic random number generator in ntp-keygen may allow an attacker to...
Last Update Date: 22 Dec 2014 10:45 Release Date: 22 Dec 2014 3705 Views

RISK: Medium Risk

Medium Risk

WordPress Download Manager Security Bypass Vulnerability

A vulnerability has been identified in the Download Manager plugin for WordPress, which can be exploited by malicious people to bypass certain security restrictions.This vulnerability is caused due to the plugin not properly restricting access to certain administrative functionality, which can be exploited to perform otherwise...
Last Update Date: 19 Dec 2014 10:47 Release Date: 19 Dec 2014 3399 Views