Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Cisco Products Apache Struts 2 Command Execution Vulnerability

A vulnerability has been identified in multiple Cisco products, which include an implementation of Apache Struts 2 component that is affected by a remote command execution vulnerability.   The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by sending...
Last Update Date: 25 Oct 2013 10:06 Release Date: 25 Oct 2013 3962 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which can be exploited by malicious people to disclose certain sensitive information, cause a DoS (Denial of Service), and potentially compromise a user's system.
Last Update Date: 24 Oct 2013 11:29 Release Date: 24 Oct 2013 3900 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system.   The vulnerabilities are caused due to a bundled vulnerable version of WebKit.
Last Update Date: 24 Oct 2013 11:28 Release Date: 24 Oct 2013 3879 Views

RISK: Medium Risk

Medium Risk

Apple Remote Desktop Format String Vulnerability

A vulnerability has been identified in Apple Remote Desktop. A remote user can execute arbitrary code on the target system. A remote user can send specially crafted VNC username data to trigger a format string flaw and execute arbitrary code on the target system. The system may...
Last Update Date: 24 Oct 2013 10:48 Release Date: 24 Oct 2013 3999 Views

RISK: Medium Risk

Medium Risk

Cisco IOS XR Fragmented Packet Processing Vulnerability

A vulnerability has been identified in Cisco IOS XR. A remote user can cause denial of service conditions.   A remote user can send specially crafted fragmented packets to the target device to cause the target route processor to be unable to transmit packets to the fabric.
Last Update Date: 24 Oct 2013 10:42 Release Date: 24 Oct 2013 4051 Views

RISK: Medium Risk

Medium Risk

Apple iOS Passcode Lock Security Bypass Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which can be exploited by malicious people with physical access to bypass certain security restrictions. A NULL pointer dereference error related to the emergency call button and the camera pane within the lock screen of the Passcode Lock component can...
Last Update Date: 24 Oct 2013 10:28 Release Date: 24 Oct 2013 4062 Views

RISK: High Risk

High Risk

Apple OS X and OS X Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple OS X and OS X Server, which can be exploited by remote attacker to conduct cross site scripting, denial of serverice, elevation of privilege, remote code execution and sensitive information disclosure   The following OS X components are found...
Last Update Date: 24 Oct 2013 10:06 Release Date: 24 Oct 2013 4104 Views

RISK: High Risk

High Risk

Node.js HTTP Server Deny Service Vulnerability

A vulnerability was identified in Node.js. A remote user can cause denial of service conditions. A remote user can send a large number of specially crafted pipelined requests to the target HTTP server component to cause excessive memory and CPU consumption on the target system.
Last Update Date: 22 Oct 2013 10:07 Release Date: 22 Oct 2013 4022 Views

RISK: Medium Risk

Medium Risk

VMware ESX/ESXi hostd-vmdb Deny Service Vulnerability

A vulnerability was identified in VMware ESX/ESXi. A remote user can cause denial of service conditions. A remote user with the ability to conduct a man-in-the-middle attack can modify management traffic to cause denial of service conditions on the hostd...
Last Update Date: 21 Oct 2013 09:59 Release Date: 21 Oct 2013 4179 Views

RISK: High Risk

High Risk

Oracle Java Multiple Vulnerabilities

Multiple vulnerabilities have been reported in Oracle Java, which can be exploited by malicious users to manipulate certain data and by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Last Update Date: 17 Oct 2013 14:28 Release Date: 17 Oct 2013 4333 Views