Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

IBM WebSphere Portal HTTP Response Splitting Vulnerability

A vulnerability has been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct HTTP response splitting attacks.  Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers, which will...
Last Update Date: 31 May 2013 16:50 Release Date: 31 May 2013 3598 Views

RISK: High Risk

High Risk

GnuTLS TLS Record Decoding Denial of Service Vulnerability

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an out-of-bounds read error within the "_gnutls_ciphertext2compressed()" function in lib/gnutls_cipher.c...
Last Update Date: 31 May 2013 16:47 Release Date: 31 May 2013 3391 Views

RISK: High Risk

High Risk

IBM Products OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Cloudburst and IBM Service Delivery Manager, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and potentially compromise a vulnerable system...
Last Update Date: 31 May 2013 16:44 Release Date: 31 May 2013 3382 Views

RISK: High Risk

High Risk

IrfanView FlashPix PlugIn FPX Processing Integer Overflow Vulnerability

A vulnerability has been identified in the FlashPix PlugIn for IrfanView, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow error within the Fpx.dll module when processing sections of Summary Information Property...
Last Update Date: 31 May 2013 16:40 Release Date: 31 May 2013 3505 Views

RISK: Medium Risk

Medium Risk

HP-UX Directory Server Password Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Directory Server, which can be exploited by remote authenticated user or  local user to view passwords. A local user can access the plaintext password in certain cases. A remote authenticated user can view the password for a...
Last Update Date: 29 May 2013 11:52 Release Date: 29 May 2013 3449 Views

RISK: Medium Risk

Medium Risk

Apache Struts OGNL Expression Injection Vulnerability

A vulnerability has been identified in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error when handling the "includeParams" attribute, which can be exploited to modify server-side objects and e...
Last Update Date: 29 May 2013 Release Date: 28 May 2013 3715 Views

RISK: High Risk

High Risk

Cisco IOS XR SNMP UDP Packets Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when managing allocated memory within the SNMP process and can be exploited to e.g...
Last Update Date: 28 May 2013 10:10 Release Date: 28 May 2013 3606 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system. A use-after-free...
Last Update Date: 23 May 2013 11:40 Release Date: 23 May 2013 3360 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified which can be exploited by malicious users to execute arbitrary code and cause Denial of Service condition via specially crafted files.
Last Update Date: 23 May 2013 10:28 Release Date: 23 May 2013 3510 Views

RISK: Medium Risk

Medium Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).   An error in the RELOAD dissector (dissectors/packet-reload.c) can be exploited to trigger infinite loops and consume CPU resources...
Last Update Date: 21 May 2013 10:14 Release Date: 21 May 2013 3662 Views