VU#542123: ISC BIND 9 resolver cache vulnerability
ISC BIND 9 resolver contains a vulnerability that could allow a attacker to keep a domain name in the cache even after it has been deleted from registration.
Categories: US-CERT
VU#732115: Project Open cross-site scripting vulnerability
Project Open]po[version 3.4 and possibly earlier versions suffer from a reflective cross-site scripting(XSS)vulnerability in the account-closed.tcl script
Categories: US-CERT
VU#732115: Project Open cross-site scripting vulnerability
Project Open]po[version 3.4 and possibly earlier versions suffer from a reflective cross-site scripting(XSS)vulnerability in the account-closed.tcl script
Categories: US-CERT
VU#410281: Apple Mac OS X CoreText embedded font vulnerability
Apple Mac OS X CoreText contains a use-after-free vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#403593: Apple Mac OS X ATS data-font memory corruption vulnerability
Apple Mac OS X ATS contains a memory corruption vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#410281: Apple Mac OS X CoreText embedded font vulnerability
Apple Mac OS X CoreText contains a use-after-free vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#403593: Apple Mac OS X ATS data-font memory corruption vulnerability
Apple Mac OS X ATS contains a memory corruption vulnerability that may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#763355: 802.1X password exploit on many HTC Android devices
A user's 802.1X WiFi credentials and SSID information may be exposed to any application with basic WiFi permissions on certain HTC builds of Android.
Categories: US-CERT
VU#763355: 802.1X password exploit on many HTC Android devices
A user's 802.1X WiFi credentials and SSID information may be exposed to any application with basic WiFi permissions on certain HTC builds of Android.
Categories: US-CERT
VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write
Linux kernel>=2.6.39 incorrectly handles the permissions for/proc//mem. A local,authenticated attacker could exploit this vulnerability to escalate to root privileges. Exploit code is available in the wild and there have been reports of active exploitation.
Categories: US-CERT
VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write
Linux kernel>=2.6.39 incorrectly handles the permissions for/proc//mem. A local,authenticated attacker could exploit this vulnerability to escalate to root privileges. Exploit code is available in the wild and there have been reports of active exploitation.
Categories: US-CERT
VU#738961: Oracle Outside In contains an exploitable vulnerability in Lotus 123 v4 parser
Oracle Outside In contains an exploitable vulnerability in the Lotus 123 version 4 file parser,which can allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#659515: Wibu-Systems CodeMeter remote denial of service vulnerability
Wibu-Systems CodeMeter contains a remote denial of service vulnerability when receiving specially crafted packets.
Categories: US-CERT
VU#903934: Hash table implementations vulnerable to algorithmic complexity attacks
Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks,which can be leveraged by an unauthenticated attacker to cause a denial-of-service(DoS)condition.
Categories: US-CERT
VU#723755: WiFi Protected Setup (WPS) PIN brute force vulnerability
The WiFi Protected Setup(WPS)PIN is susceptible to a brute force attack. A design flaw that exists in the WPS specification for the PIN authentication significantly reduces the time required to brute force the entire PIN because it allows an attacker to know when the first half of the 8 digit PIN is correct. The lack of a proper lock out policy after a certain number of failed attempts to guess the PIN on many wireless routers makes this brute force attack that much more feasible.
Categories: US-CERT
VU#209659: Unbound multiple denial-of-service vulnerabilities
A specially crafted DNS query containing signed duplicate resource records or a malformed NSEC3 signed resource record may cause Unbound to crash.
Categories: US-CERT
VU#361441: Microsoft Office Publisher contains multiple exploitable vulnerabilities
Microsoft Office Publisher fails to properly validate Publisher documents,which may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#158003: Power2Go buffer overflow vulnerability
Power2Go 8 contains a buffer overflow in the handling of project(.p2g)files,which can allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#759307: Adobe Acrobat and Reader U3D memory corruption vulnerability
Adobe Reader and Acrobat fail to properly handle U3D data,which could allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT
VU#717921: Hewlett-Packard printers and scanner devices allow remote firmware updates
A vulnerability in certain Hewlett-Packard devices could allow a remote attacker to install unauthorized firmware on an affected system.
Categories: US-CERT



