Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Federation Services Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that URLs are sanitized in Active Directory Federation Services (AD FS). An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Last Update Date: 10 Jun 2015 09:53 Release Date: 10 Jun 2015 4018 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Microsoft Windows Kernel Information Disclosure VulnerabilityAn information disclosure vulnerability exists when the Windows kernel-mode driver improperly handles buffer elements under certain conditions, allowing an attacker to request the contents of specific memory addresses. An attacker who successfully exploited this vulnerability could then potentially read data that...
Last Update Date: 10 Jun 2015 09:52 Release Date: 10 Jun 2015 4091 Views

RISK: High Risk

High Risk

Microsoft Common Controls Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Common Controls when it accesses an object in memory that has not been correctly initialized or has been deleted. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. ...
Last Update Date: 10 Jun 2015 09:51 Release Date: 10 Jun 2015 4022 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Microsoft Office Uninitialized Memory Use Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could use a specially crafted file to perform actions in the security context of...
Last Update Date: 10 Jun 2015 09:50 Release Date: 10 Jun 2015 3881 Views

RISK: High Risk

High Risk

Microsoft Windows Media Player Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Media Player handles specially crafted DataObjects. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs; view, change, or...
Last Update Date: 10 Jun 2015 09:49 Release Date: 10 Jun 2015 3920 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker who successfully exploited this vulnerability to gain access to a user's browser history. Multiple Elevation of Privilege Vulnerabilities Elevation of privilege vulnerabilities exist when Internet Explorer does...
Last Update Date: 10 Jun 2015 09:48 Release Date: 10 Jun 2015 3791 Views

RISK: Medium Risk

Medium Risk

OpenSSL Double Free Memory Vulnerability

A vulnerability was identified in OpenSSL. The impact was not specified.A remote server can return a specially crafted NewSessionTicket message to a connected multi-threaded client.It may cause a double free memory error.
Last Update Date: 5 Jun 2015 09:30 Release Date: 5 Jun 2015 4190 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Multiple vulnerabilities were identified in PHP. A remote user can bypass security controls, cause denial of service conditions, and execute arbitrary code on the target system.The set_include_path(), tempnam(), rmdir(), and readlink() functions accept a null value ('/') in a...
Last Update Date: 2 Jun 2015 09:50 Release Date: 2 Jun 2015 3903 Views

RISK: Extremely High Risk

Extremely High Risk

Apple iOS Notification Unicode Character Processing Vulnerability

A vulnerability has been identified in Apple iOS, which can be exploited by a remote user to cause denial of service conditions on the target system.   A remote user can send a specially crafted string of Unicode characters to trigger a flaw in the Springboard component and cause...
Last Update Date: 28 May 2015 10:07 Release Date: 28 May 2015 5491 Views

RISK: Medium Risk

Medium Risk

PostgreSQL Multiple Vulnerabilities

Multiples vulnerabilities were identified in PostgreSQL, which can be exploited to cause remote crash, information exposure and possible side-channel key exposure.
Last Update Date: 26 May 2015 09:45 Release Date: 26 May 2015 3985 Views