You are here

JC3 Bulletin Archive

May 23, 2013
V-162: Apache Struts "ParameterInterceptor" Security Bypass Vulnerability

A vulnerability has been reported in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions.

May 22, 2013
V-161: IBM Maximo Asset Management Products Java Multiple Vulnerabilities

Asset and Service Mgmt Products - Potential security exposure when using JavaTM based applications due to vulnerabilities in Java Software Developer Kits.

May 21, 2013
V-160: Wireshark Multiple Bugs Let Remote Users Deny Service

Multiple vulnerabilities have been reported in Wireshark

May 20, 2013
V-159: RSA SecurID Agent Discloses Node Secret Encryption Key to Local Users

A vulnerability was reported in RSA SecurID Products.

May 17, 2013
V-158: BlackBerry Tablet OS Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been reported in BlackBerry Tablet OS, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.

May 16, 2013
V-157: Adobe Reader / Acrobat Multiple Vulnerabilities

These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system

May 15, 2013
V-156: Linux Kernel Array Bounds Checking Flaw Lets Local Users Gain Elevated Privileges

A vulnerability was reported in the Linux Kernel.

May 13, 2013
V-154: Microsoft Security Bulletin Advance Notification for May 2013

Microsoft Security Bulletin Advance Notification for May 2013. Microsoft has posted 2 Critical Bulletins and 8 Important Bulletins. Bulletins with the Maximum Severity Rating and Vulnerability Impact of "Critical" may allow remote execution of code. Microsoft will host a webcast to address customer questions on the security bulletins on May 15, 2013, at 11:00 AM Pacific Time (US & Canada).

May 10, 2013
V-153: Symantec Brightmail Gateway Input Validation Flaw Permits Cross-Site Scripting Attacks

Symantec’s Brightmail Gateway management console is susceptible to stored cross-site scripting (XSS) issues found in some of the administrative interface pages.