VIA Root
VIARoot Security News Security alerts Business IT security Services Security Tools About VIARoot
HPC Logo
 > 
Vulnerabilities Alerts
[Symantec PCAnywhere] - Zero Day Initiative Advisory 12-018
symantec
Tipping Point
2012-01-25 22:15:26
Zero Day Initiative Advisory 12-018 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Symantec PCAnywhere. Authentication is not required to exploit this vulnerability. The flaw exists within the awhost32 component which is used when handling incoming connections. This process listens on TCP port 5631. When handling an authentication request the process copies the user supplied username unsafely to a fixed-length buffer of size 0x108. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the SYSTEM account.
D-Link WBR-1310 Authentication Bypass Vulnerability
D-Link
Craig Heffner
2010-12-25 10:37:44
The WBR-1310 suffers from an authentication bypass vulnerability that can be exploited by remote attackers to change administrative settings. Note that this vulnerability can be exploited via CSRF even if remote administration is disabled.
Internet Explorer Multiple Vulnerabilities : Information leak, memory corruption, code execution
IElogo
Aniway, iDefense Labs
2010-12-14 17:39:33
Multiple vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information or to compromise a user's system.
Drupal Embedded Media Field Module Arbitrary File Upload and Code Exec Vulnerability
Drupal
Justin Klein Keane
2010-12-11 07:09:08
Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and MySQL. The Drupal Embedded Media Field module (http://drupal.org/project/emfield) "will create fields for content types that can be used to display video, image, and audio files from various third party providers" Unfortunately the Embedded Media Field module contains a vulnerability that could allow arbitrary file upload and potentially code execution. The proof of concept and patch detailed below only cover the upload of an image directly to the server, but a remotely sourced image could also be used to exploit this vulnerability.
CiscoWorks Arbitrary Code Execution Vulnerability
Cisco
Cisco Security Advisory
2010-11-06 05:04:32
CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator. Cisco has released free software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability. Mitigations that limit the attack surface of this vulnerability are available.
Out-of-band Patch For ASP.NET Vulnerability Released
Microsoft
Tech Writer, Heptacube Inc.
2010-09-28 14:49:16
Microsoft made available today a patch for the recently discovered hole in their ASP.NET framework.
ASP.NET Flaw Used To Decrypt Cookies In Minutes
Microsoft
Tech Writer, Heptacube Inc.
2010-09-27 16:49:01
Researchers detailed last week at ekoparty Security Conference their findings on a flaw in Microsoft's popular framework.
Longstanding Bug Haunts Internet Explorer 8
IElogo
Tech Writer, Heptacube Inc.
2010-09-07 15:45:56
First reported in December 2009, the bug has been fixed on all major browsers but Microsoft's.
Windows Zero-Day Exploit Uses Shortcuts And USB Drives
Windows
Tech Writer, Heptacube Inc.
2010-07-16 15:42:51
The malware spreads through removable drives even if AutoPlay is disabled, installs rootkit on the computer.
Phishing On 15 US Banks Spreads With The Zeus Trojan
phishing
Tech Writer, Heptacube Inc.
2010-07-14 12:26:24
False 'Verified by Visa' and 'MasterCard SecureCode' pages harvest customers' personal data.
Koobface Returns In Facebook Direct Messages
Facebook
Tech Writer, Heptacube Inc.
2010-07-09 11:48:44
The infamous worm is back, disguised as a Flash update purportedly needed for viewing a video distributed through direct messages on Facebook.


iTunes hacks steal users' money, drive apps to the top of sales charts
Apple
Tech Writer, Heptacube Inc.
2010-07-05 15:32:23
Users of Apple's music and applications store are seeing their accounts being hacked for buying shady applications in mass.
New Windows XP flaw in Support Center
Windows
Tech Writer, Heptacube Inc.
2010-06-11 12:23:26
Internet Explorer and Windows Media Player contribute to making Windows XP's Help and Support Center vulnerable to remote attacks.
114,000 iPad users' email addresses leaked by AT&T
Apple
Tech Writer, Heptacube Inc.
2010-06-10 15:05:26
It has been reported that a flaw in AT&T's servers has allowed some white hat hackers to access network IDs and email addresses associated with iPad devices.
Spyware distributed on Mac Web sites
Apple
Tech Writer, Heptacube Inc.
2010-06-04 11:54:55
A security firm has discovered that several free Mac software Web sites are hosting spyware-bearing downloadable applications.
44 million stolen online games credentials
symantec
Tech Writer, Heptacube Inc.
2010-06-01 14:44:42
Symantec has detected a server holding 17GB of stolen user credentials for online games, gathered and verified with Trojans.
Canonical Display Driver bug found on latest 64-bit Windows versions
Windows7logo
Tech Writer, Heptacube Inc.
2010-05-19 11:30:03
Microsoft has released a security advisory concerning a bug related to the Aero desktop theme on Windows 7 and Windows Server 2008.
New Facebook Open Graph leads to user information leaks
Facebook
Tech Writer, Heptacube Inc.
2010-05-13 11:50:28
Once again, the world's top social networking Web site is in hot water for vulnerabilities allowing people to access personal information about users without their consent.
Fake Windows 7 Upgrade Advisor installs a Trojan
Windows7logo
Tech Writer, Heptacube Inc.
2010-05-11 11:39:33
Another malware distribution campaign uses social engineering to spread a Trojan horse.
Proof of Concept shows important, generalized security software design flaw
Windows
Tech Writer, Heptacube Inc.
2010-05-10 16:45:01
Researchers at Matousec have revealed that out of 34 tested security products, none has been able to prevent their proof of concept attack.
Search
Past Security Alerts
2012
2011
2010
2009
2008
Security News
Apple
Vincent A. Menard
2011-09-13 19:33:41
They can do wonderful products and they can be real pain. I hate being in the position of saying to my customer the provider I used to publish their software does not provide the requested option, specially when it comes to simple statistics. When you publish an iOS app on the App Store, it is impossible to know the number of app downloads before the last 26 weeks.
Android
Vincent A. Menard, Heptacube
2011-03-22 21:55:36
Openness is loved by android users, but the idea spreads fast into the Malware coders mind. The DroidDream app recently took Google by surprise: the app simply wipes off your phone, takes your data.
IT Directory
Gardien Virtuel
Gardien Virtuel is a leading company in the IT security field. Why choose Gardien Virtuel? * Expertise: Gardien Virtuel [...]
Wiseleap Solutions Inc.
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
IT Ration Consulting Inc.
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]