You are here

JC3 High Impact Assessment Bulletins

July 12, 2012
U-211: EMC Celerra/VNX/VNXe Access Control Bug Lets Remote Authenticated Users Access Files/Directories

A vulnerability was reported in EMC Celerra/VNX/VNXe. A remote authenticated user can access files and directories on the target file system.

July 10, 2012
U-209: Microsoft Security Bulletin Advance Notification for July 2012

Microsoft Security Bulletin Advance Notification for July 2012. Microsoft has posted 3 Critical Bulletins and 6 Important Bulletins. Bulletins with the Maximum Severity Rating and Vulnerability Impact of "Critical" may allow remote execution of code. Microsoft is hosting a webcast to address customer questions on these bulletins on July 11, 2012, at 11:00 AM Pacific Time (US & Canada).

July 10, 2012
U-208: HP Operations Agent Bugs Let Remote Users Execute Arbitrary Code

Two vulnerabilities were reported in HP Operations Agent. A remote user can execute arbitrary code on the target system

July 2, 2012
U-203: HP Photosmart Bug Lets Remote Users Deny Service

A vulnerability was reported in HP Photosmart. A remote user can cause denial of service conditions.

June 26, 2012
U-199: Drupal Drag & Drop Gallery Module Arbitrary File Upload Vulnerability

The vulnerability is caused due to the sites/all/modules/dragdrop_gallery/upload.php script improperly validating uploaded files, which can be exploited to execute arbitrary PHP code by uploading a PHP file with e.g. an appended ".gif" file extension.

June 25, 2012
U-198: IBM Lotus Expeditor Multiple Vulnerabilities

The vulnerabilities can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system..

June 22, 2012
U-197: Cisco Adaptive Security Appliances Denial of Service Vulnerability

The vulnerability is caused due to an unspecified error when handling IPv6 transit traffic and can be exploited to cause a reload of the affected device.

June 21, 2012
U-196: Cisco AnyConnect VPN Client Two Vulnerabilities

Two vulnerabilities have been reported in Cisco AnyConnect VPN Client, which can be exploited by malicious people to compromise a user's system.

June 18, 2012
U-193: NetBSD System Call Return Value Validation Flaw Lets Local Users Gain Elevated Privileges

On Intel CPUs, the sysret instruction can be manipulated into returning to specific non-canonical addresses, which may yield a CPU reset. We cannot currently rule out with utter confidence that this vulnerability could not also be used to execute code with kernel privilege instead of crashing the system.

June 15, 2012
U-192 VMware Workstation/Player VM Remote Device Bug Lets Local or Remote Users Deny Service

A local or remote user can cause denial of service conditions on the target virtual system.