Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Apache Tomcat Request Object Recycle Security Bypass Vulnerability

A security issue has been identified in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions.  The security issue is caused due to the request object not being recycled before processing the next request when logging certain actions. This can lead to...
Last Update Date: 18 Jan 2012 14:30 Release Date: 18 Jan 2012 5669 Views

RISK: High Risk

High Risk

ISC DHCP DHCPv6 Dynamic DNS Remote Denial of Service Vulnerability

A vulnerability has been identified in ISC DHCP, which can be exploited by malicious people to cause a segmentation fault in ISC DHCP servers using IPv6 and Dynamic DNS, resulting in denial of service to clients.  Due to improper handling of a DHCPv6 lease structure, ISC...
Last Update Date: 18 Jan 2012 14:30 Release Date: 18 Jan 2012 5788 Views

RISK: High Risk

High Risk

7-Technologies Interactive Graphical SCADA System Insecure Library Loading Vulnerability

A vulnerability has been identified in 7-Technologies Interactive Graphical SCADA System, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to the application loading certain libraries in an insecure manner, which can be exploited to...
Last Update Date: 18 Jan 2012 14:29 Release Date: 18 Jan 2012 5650 Views

RISK: Medium Risk

Medium Risk

Yahoo Messenger JPG Photo Sharing Integer Overflow Vulnerability

A vulnerability has been identified in Yahoo Messenger, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error in the "CYImage::LoadJPG()" method (YImage.dll) when allocating memory...
Last Update Date: 16 Jan 2012 11:23 Release Date: 16 Jan 2012 5729 Views

RISK: High Risk

High Risk

Wireshark Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system. NULL pointer dereference errors when reading certain packet information can be exploited to cause a crash...
Last Update Date: 12 Jan 2012 10:29 Release Date: 12 Jan 2012 5622 Views

RISK: Medium Risk

Medium Risk

Microsoft Anti-Cross Site Scripting Library Bypass Vulnerability

An information disclosure vulnerability exists when the Microsoft Anti-Cross Site Scripting (AntiXSS) Library incorrectly sanitizes specially crafted HTML. An attacker who successfully exploited this vulnerability could perform a cross-site scripting (XSS) attack on a website that is using the AntiXSS Library...
Last Update Date: 11 Jan 2012 11:09 Release Date: 11 Jan 2012 5628 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SSL/TLS Protocols Vulnerability

An information disclosure vulnerability exists in SSL 3. and TLS 1. encryption protocols. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS traffic. This...
Last Update Date: 11 Jan 2012 11:06 Release Date: 11 Jan 2012 5816 Views

RISK: High Risk

High Risk

Microsoft Windows Assembly Execution Vulnerability

A remote code execution vulnerability exists in the way that Windows Packager loads ClickOnce applications embedded in Microsoft Office files.
Last Update Date: 11 Jan 2012 11:06 Release Date: 11 Jan 2012 5741 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the Windows CSRSS due to the way that the CSRSS processes a sequence of specially crafted Unicode characters. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then...
Last Update Date: 11 Jan 2012 11:04 Release Date: 11 Jan 2012 5580 Views

RISK: High Risk

High Risk

Microsoft Windows Object Packager Insecure Executable Launching Vulnerability

A remote code execution vulnerability exists in the way that Windows registers and uses the Windows Object Packager. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 11 Jan 2012 11:03 Release Date: 11 Jan 2012 5569 Views