Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Windows HTTP.sys Denial of Service Vulnerability

A denial of service vulnerability exists in Windows Server 2012 and Windows 8 when the HTTP protocol stack (HTTP.sys) improperly handles a malicious HTTP header. An attacker who successfully exploited this vulnerability could trigger an infinite loop in the HTTP protocol stack by sending a...
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 4140 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Use After Free Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the...
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 4141 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer JSON Array Information Disclosure Vulnerability

An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access and read the contents of JSON data files.
Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 4221 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Unspecified Use-After-Free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.   The vulnerability is caused due to a use-after-free error and can be exploited to dereference already freed memory.   Successful exploitation...
Last Update Date: 15 May 2013 Release Date: 6 May 2013 5064 Views

RISK: High Risk

High Risk

Adobe ColdFusion "filename" Arbitrary File Disclosure Vulnerability

A vulnerabilities has been identified in Adobe ColdFusion, which can be exploited by an unauthorized user to remotely retrieve files stored on the server.   Input passed via the "filename" parameter to administrator/mail/download.cfm in the CFIDE/adminapi section is not...
Last Update Date: 15 May 2013 Release Date: 10 May 2013 4307 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Customer Voice Portal Multiple Vulnerabilities

Multiple vulnerabilities has been identified in Cisco Unified Customer Voice Portal. A remote user can execute arbitrary applications on the target system, cause denial of service conditions, view and modify files on the target system, and gain administrator access.A remote user can send a...
Last Update Date: 9 May 2013 10:05 Release Date: 9 May 2013 4176 Views

RISK: Medium Risk

Medium Risk

nginx "ngx_http_parse_chunked()" Buffer Overflow Vulnerability

A vulnerability has been identified in nginx, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the "ngx_http_parse_chunked()" function (http/ngx_http_parse.c) when parsing an HTTP chunk and can be...
Last Update Date: 8 May 2013 10:41 Release Date: 8 May 2013 4430 Views

RISK: High Risk

High Risk

IBM WebSphere Products Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM WebSphere products, which can be exploited by malicious people to disclose and manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.  The applications bundle a vulnerable version of IBM Java Runtime Environment.
Last Update Date: 8 May 2013 10:37 Release Date: 8 May 2013 4831 Views

RISK: High Risk

High Risk

IBM Notes PNG Integer Overflow Vulnerability

A vulnerability has been identified in IBM Notes, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow when viewing PNG images and can be exploited to execute arbitrary code by sending an e-...
Last Update Date: 8 May 2013 10:33 Release Date: 8 May 2013 4199 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Files and Folders Enumeration Vulnerabilities

Multiple vulnerabilities have been discovered in Microsoft Internet Explorer, which can be exploited by malicious people to disclose sensitive information. The vulnerabilities are caused due to MSXML returning different errors depending on whether or not a file or directory exists. This can be exploited to check the...
Last Update Date: 7 May 2013 10:12 Release Date: 7 May 2013 4354 Views