Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Double Delete Remote Code Execution VulnerabilityA remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. Microsoft received information about the vulnerability through coordinated vulnerability disclosure...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3076 Views

RISK: High Risk

High Risk

Microsoft Schannel Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Secure Channel (Schannel) security package due to the improper processing of specially crafted packets. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3363 Views

RISK: High Risk

High Risk

Microsoft XML Core Services Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft XML Core Services (MSXML) improperly parses XML content, which can corrupt the system state in such a way as to allow an attacker to run arbitrary code. The vulnerability could allow remote code execution if a user opens...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3226 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the vulnerabilities by...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3044 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Remote Code Execution Vulnerabilities

Windows OLE Automation Array Remote Code Execution VulnerabilityA remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this...
Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3241 Views

RISK: High Risk

High Risk

Apple iOS Masque Attack

Masque attack works by luring users to install an app from a source other than the iOS App Store or their organizations’ provisioning system. In order for the attack to succeed, a user must install an untrusted app, such as one delivered through a phishing link...
Last Update Date: 17 Nov 2014 10:25 Release Date: 17 Nov 2014 3338 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, arbitrary code execution, and compromise a user's system. Several unspecified errors can also...
Last Update Date: 12 Nov 2014 17:49 Release Date: 12 Nov 2014 3204 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a user's system...
Last Update Date: 12 Nov 2014 16:56 Release Date: 12 Nov 2014 3287 Views

RISK: Medium Risk

Medium Risk

GNU Wget Arbitrary Filesystem Access Vulnerability

A vulnerability was identified in wget. A remote user can cause arbitrary files, directories, and symlinks to be created on the target user's system. A remote unauthenticated malicious FTP server, connected to the victim via wget, can create and overwrite arbitrary files...
Last Update Date: 30 Oct 2014 10:20 Release Date: 30 Oct 2014 3347 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Portal Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct cross site scripting, security restriction bypass, and sensitive information disclosure.
Last Update Date: 29 Oct 2014 09:31 Release Date: 29 Oct 2014 3260 Views