Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Splunk Web Cross-Site Scripting Vulnerabilty

A vulnerability was identified in Splunk Web, which can be exploited by a remote user to conduct cross-site scripting attacks.
Last Update Date: 31 May 2013 16:59 Release Date: 31 May 2013 4311 Views

RISK: High Risk

High Risk

Cisco NX-OS Nexus 1000v Multiple Vulnerabilies

Multiple vulnerabilities have been identified in the Cisco Nexus 1000v, which can be exploited by a remote user to monitor or inject traffic, gain control of a target system, bypass security restrictions or cause denial of service conditions.   NOTE: Currently, there is no patch...
Last Update Date: 31 May 2013 16:56 Release Date: 31 May 2013 4265 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server mod_rewrite Vulnerability

A vulnerability has been identified in Apache HTTP Server, which can be exploited by malicious people to compromise a vulnerable system.  The "do_rewritelog()" function (modules/mappers/mod_rewrite.c) does not properly handle certain escape sequences when writing to the log file...
Last Update Date: 31 May 2013 16:52 Release Date: 31 May 2013 4443 Views

RISK: Medium Risk

Medium Risk

IBM WebSphere Portal HTTP Response Splitting Vulnerability

A vulnerability has been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct HTTP response splitting attacks.  Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers, which will...
Last Update Date: 31 May 2013 16:50 Release Date: 31 May 2013 4361 Views

RISK: High Risk

High Risk

GnuTLS TLS Record Decoding Denial of Service Vulnerability

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an out-of-bounds read error within the "_gnutls_ciphertext2compressed()" function in lib/gnutls_cipher.c...
Last Update Date: 31 May 2013 16:47 Release Date: 31 May 2013 4160 Views

RISK: High Risk

High Risk

IBM Products OpenSSL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Cloudburst and IBM Service Delivery Manager, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and potentially compromise a vulnerable system...
Last Update Date: 31 May 2013 16:44 Release Date: 31 May 2013 4146 Views

RISK: High Risk

High Risk

IrfanView FlashPix PlugIn FPX Processing Integer Overflow Vulnerability

A vulnerability has been identified in the FlashPix PlugIn for IrfanView, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow error within the Fpx.dll module when processing sections of Summary Information Property...
Last Update Date: 31 May 2013 16:40 Release Date: 31 May 2013 4285 Views

RISK: Medium Risk

Medium Risk

HP-UX Directory Server Password Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX Directory Server, which can be exploited by remote authenticated user or  local user to view passwords. A local user can access the plaintext password in certain cases. A remote authenticated user can view the password for a...
Last Update Date: 29 May 2013 11:52 Release Date: 29 May 2013 4219 Views

RISK: Medium Risk

Medium Risk

Apache Struts OGNL Expression Injection Vulnerability

A vulnerability has been identified in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to an error when handling the "includeParams" attribute, which can be exploited to modify server-side objects and e...
Last Update Date: 29 May 2013 Release Date: 28 May 2013 4471 Views

RISK: High Risk

High Risk

Cisco IOS XR SNMP UDP Packets Processing Denial of Service Vulnerability

A vulnerability has been identified in Cisco IOS XR, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when managing allocated memory within the SNMP process and can be exploited to e.g...
Last Update Date: 28 May 2013 10:10 Release Date: 28 May 2013 4375 Views