|
Vulnerabilities Alerts
|
[Symantec PCAnywhere] - Zero Day Initiative Advisory 12-018
|
 |
Tipping Point |
2012-01-25 22:15:26 |
Zero Day Initiative Advisory 12-018 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Symantec PCAnywhere. Authentication is not required to exploit this vulnerability. The flaw exists within the awhost32 component which is used when handling incoming connections. This process listens on TCP port 5631. When handling an authentication request the process copies the user supplied username unsafely to a fixed-length buffer of size 0x108. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the SYSTEM account. |
D-Link WBR-1310 Authentication Bypass Vulnerability
|
 |
Craig Heffner |
2010-12-25 10:37:44 |
The WBR-1310 suffers from an authentication bypass vulnerability that can be exploited by remote
attackers to change administrative settings. Note that this vulnerability can be exploited via CSRF even
if remote administration is disabled. |
Drupal Embedded Media Field Module Arbitrary File Upload and Code Exec Vulnerability
|
 |
Justin Klein Keane |
2010-12-11 07:09:08 |
Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and MySQL. The Drupal Embedded Media Field module (http://drupal.org/project/emfield) "will create fields for content types that can be used to display video, image, and audio files from various third party providers" Unfortunately the Embedded Media Field module contains a vulnerability that could allow arbitrary file upload and potentially code execution. The proof of concept and patch detailed below only cover the upload of an image directly to the server, but a remotely sourced image could also be used to exploit this vulnerability. |
CiscoWorks Arbitrary Code Execution Vulnerability
|
 |
Cisco Security Advisory |
2010-11-06 05:04:32 |
CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator.
Cisco has released free software updates that address this
vulnerability.
There are no workarounds that mitigate this vulnerability.
Mitigations that limit the attack surface of this vulnerability are
available. |
Koobface Returns In Facebook Direct Messages
|
 |
Tech Writer, Heptacube Inc. |
2010-07-09 11:48:44 |
The infamous worm is back, disguised as a Flash update purportedly needed for viewing a video distributed through direct messages on Facebook. |
New Windows XP flaw in Support Center
|
 |
Tech Writer, Heptacube Inc. |
2010-06-11 12:23:26 |
Internet Explorer and Windows Media Player contribute to making Windows XP's Help and Support Center vulnerable to remote attacks. |
114,000 iPad users' email addresses leaked by AT&T
|
 |
Tech Writer, Heptacube Inc. |
2010-06-10 15:05:26 |
It has been reported that a flaw in AT&T's servers has allowed some white hat hackers to access network IDs and email addresses associated with iPad devices. |
Spyware distributed on Mac Web sites
|
 |
Tech Writer, Heptacube Inc. |
2010-06-04 11:54:55 |
A security firm has discovered that several free Mac software Web sites are hosting spyware-bearing downloadable applications. |
44 million stolen online games credentials
|
 |
Tech Writer, Heptacube Inc. |
2010-06-01 14:44:42 |
Symantec has detected a server holding 17GB of stolen user credentials for online games, gathered and verified with Trojans. |
New Facebook Open Graph leads to user information leaks
|
 |
Tech Writer, Heptacube Inc. |
2010-05-13 11:50:28 |
Once again, the world's top social networking Web site is in hot water for vulnerabilities allowing people to access personal information about users without their consent. |
|
|
|
Search
|
|
|
|
|
|
Past Security Alerts
|
2012 2011 2010 2009 2008
|
|
Security News
|
|
 |
Vincent A. Menard |
2011-09-13 19:33:41 |
They can do wonderful products and they can be real pain. I hate being in the position of saying to my customer the provider I used to publish their software does not provide the requested option, specially when it comes to simple statistics. When you publish an iOS app on the App Store, it is impossible to know the number of app downloads before the last 26 weeks. |
|
 |
Vincent A. Menard, Heptacube |
2011-03-22 21:55:36 |
Openness is loved by android users, but the idea spreads fast into the Malware coders mind. The DroidDream app recently took Google by surprise: the app simply wipes off your phone, takes your data. |
|
|
IT Directory
|
| Gardien Virtuel | |
|
Gardien Virtuel is a leading company in the IT security field.
Why choose Gardien Virtuel?
* Expertise: Gardien Virtuel [...]
|
| Wiseleap Solutions Inc. | |
|
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
|
| IT Ration Consulting Inc. | |
|
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]
|
|
|