US-CERT publishes information on a wide variety of vulnerabilities. Descriptions of these vulnerabilities are available from this web page in a searchable database format, and are published as "US-CERT Vulnerability Notes". The notes are very similar to alerts, but they may have less complete information. In particular, solutions may not be available for all the vulnerabilities in this database.
Updated: 24 min 6 sec ago
VU#732115: Project Open cross-site scripting vulnerability
Project Open]po[version 3.4 and possibly earlier versions suffer from a reflective cross-site scripting(XSS)vulnerability in the account-closed.tcl script
Categories: US-CERT
VU#410281: Apple Mac OS X CoreText embedded font vulnerability
Apple Mac OS X CoreText contains a use-after-free vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#403593: Apple Mac OS X ATS data-font memory corruption vulnerability
Apple Mac OS X ATS contains a memory corruption vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#763355: 802.1X password exploit on many HTC Android devices
A user's 802.1X WiFi credentials and SSID information may be exposed to any application with basic WiFi permissions on certain HTC builds of Android.
Categories: US-CERT
VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write
Linux kernel>=2.6.39 incorrectly handles the permissions for/proc//mem. A local,authenticated attacker could exploit this vulnerability to escalate to root privileges. Exploit code is available in the wild and there have been reports of active exploitation.
Categories: US-CERT
VU#738961: Oracle Outside In contains an exploitable vulnerability in Lotus 123 v4 parser
Oracle Outside In contains an exploitable vulnerability in the Lotus 123 version 4 file parser,which can allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#659515: Wibu-Systems CodeMeter remote denial of service vulnerability
Wibu-Systems CodeMeter contains a remote denial of service vulnerability when receiving specially crafted packets.
Categories: US-CERT
VU#903934: Hash table implementations vulnerable to algorithmic complexity attacks
Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks,which can be leveraged by an unauthenticated attacker to cause a denial-of-service(DoS)condition.
Categories: US-CERT
VU#723755: WiFi Protected Setup (WPS) PIN brute force vulnerability
The WiFi Protected Setup(WPS)PIN is susceptible to a brute force attack. A design flaw that exists in the WPS specification for the PIN authentication significantly reduces the time required to brute force the entire PIN because it allows an attacker to know when the first half of the 8 digit PIN is correct. The lack of a proper lock out policy after a certain number of failed attempts to guess the PIN on many wireless routers makes this brute force attack that much more feasible.
Categories: US-CERT
VU#209659: Unbound multiple denial-of-service vulnerabilities
A specially crafted DNS query containing signed duplicate resource records or a malformed NSEC3 signed resource record may cause Unbound to crash.
Categories: US-CERT
VU#361441: Microsoft Office Publisher contains multiple exploitable vulnerabilities
Microsoft Office Publisher fails to properly validate Publisher documents,which may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#158003: Power2Go buffer overflow vulnerability
Power2Go 8 contains a buffer overflow in the handling of project(.p2g)files,which can allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#759307: Adobe Acrobat and Reader U3D memory corruption vulnerability
Adobe Reader and Acrobat fail to properly handle U3D data,which could allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#717921: Hewlett-Packard printers and scanner devices allow remote firmware updates
A vulnerability in certain Hewlett-Packard devices could allow a remote attacker to install unauthorized firmware on an affected system.
Categories: US-CERT
VU#887409: JasPer memory corruption vulnerabilities
Some versions of JasPer contain multiple vulnerabilities that may allow a remote,unauthenticated attacker to execute arbitrary code.
Categories: US-CERT
VU#796883: HomeSeer HS2 web interface multiple vulnerabilities
HomeSeer HS2 home automation software web interface contains multiple vulnerabilities.
Categories: US-CERT
VU#713012: CA Siteminder login.fcc form xss vulnerability
CA Siteminder R6 SP6 CR7,R12 SP3 CR8 and possibly previous versions,are vulnerable to a reflective cross site scripting(XSS)vulnerability.
Categories: US-CERT
VU#576355: Support Incident Tracker multiple vulnerabilities
Support Incident Tracker(or SiT!)version 3.65,and possibly earlier versions,contain multiple vulnerabilities including; malicious file uploads,SQL injection,cross-site scripting,and cross-site request forgery.
Categories: US-CERT
VU#606539: ISC BIND 9 resolver denial of service vulnerability
ISC BIND 9 resolver contains a remote packet denial of service vulnerability after logging an error in query.c.
Categories: US-CERT
VU#584363: Zenprise Device Manager CSRF vulnerability
The Zenprise Device Manager software is susceptible to a cross-site request forgery(CSRF)vulnerability that may result in the compromise of the fleet of mobile devices managed by the product.
Categories: US-CERT


