Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

A security issue and some vulnerabilities have been identified in Mozilla Firefox, where one has an unknown impact and others can be exploited by malicious, local users to disclose potentially sensitive information and by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and...
Last Update Date: 3 Dec 2014 10:03 Release Date: 3 Dec 2014 3078 Views

RISK: Medium Risk

Medium Risk

Wordpress DukaPress Plugin Sensitive Information Disclosure Vulnerability

A vulnerability was identified in the DukaPress Plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information. Input passed via the "src" GET parameter to \lib\dp_image.php is not properly verified before being used to...
Last Update Date: 28 Nov 2014 09:27 Release Date: 28 Nov 2014 3095 Views

RISK: High Risk

High Risk

Microsoft Windows Kerberos Elevation of Privilege Vulnerability

A remote elevation of privilege vulnerability exists in implementations of Kerberos KDC in Microsoft Windows. The vulnerability exists when the Microsoft Kerberos KDC implementations fail to properly validate signatures, which can allow for certain aspects of a Kerberos service ticket to be forged. Microsoft received information about...
Last Update Date: 27 Nov 2014 Release Date: 19 Nov 2014 3357 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Remote Users Deny Service Vulnerability

A vulnerability was identified in Cisco IOS XR. A remote user can cause denial of service conditions. A remote user can send multiple specially crafted Locator/ID Separation Protocol (LISP) TCP sessions to cause the target LISP service to reload.
Last Update Date: 26 Nov 2014 10:07 Release Date: 26 Nov 2014 3066 Views

RISK: High Risk

High Risk

Adobe Flash Player Remote Code Execution Vulnerabilities

A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create specially crafted content that, when loaded by the target user, will trigger a use-after...
Last Update Date: 26 Nov 2014 10:07 Release Date: 26 Nov 2014 3146 Views

RISK: Medium Risk

Medium Risk

Asterisk Multiple Vulnerbilities

Multiple vulnerabilities have been identified in Asterisk, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.Some errors related to VoIP channel drivers, DUNDi, and AMI can...
Last Update Date: 25 Nov 2014 10:47 Release Date: 25 Nov 2014 3008 Views

RISK: Medium Risk

Medium Risk

Drupal Multiple Vulerabilities

Two vulnerabilities were identified in Drupal.A remote user can send a specially crafted request to gain access to another user's session.A remote user can send specially crafted data to the password hashing API to consume excessive memory and CPU resources, causing the target...
Last Update Date: 25 Nov 2014 10:47 Release Date: 25 Nov 2014 3034 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system. An unspecified error can be exploited to spoof the address bar...
Last Update Date: 25 Nov 2014 Release Date: 20 Nov 2014 3282 Views

RISK: Medium Risk

Medium Risk

GnuTLS ECC Certificate Processing Vulnerability

A vulnerability has been identified in GnuTLS. A remote user can cause denial of service conditions.   A remote user can send a specially crafted Elliptic Curve Cryptography (ECC) certificate or certificate signing request (CSR) that, when processed by the target application, will...
Last Update Date: 19 Nov 2014 Release Date: 13 Nov 2014 3075 Views

RISK: High Risk

High Risk

Cisco IOS Information Disclosure Vulnerability

A vulnerability was identified in Cisco IOS. A remote user can obtain potentially sensitive information.The system does not properly initialize packet buffers. A remote user can connect to the DLSw port (TCP port 2067) to obtain potentially sensitive information from previously processed packets. ...
Last Update Date: 18 Nov 2014 15:23 Release Date: 18 Nov 2014 3257 Views