You are here

JC3 Medium Impact Assessment Bulletins

August 21, 2012
U-240: Apple Remote Desktop Encryption Failure Lets Remote Users Obtain Potentially Sensitive Information

A remote user can monitor potentially sensitive information..

August 20, 2012
U-239: Apple iPhone SMS Processing Flaw Lets Remote Users Spoof SMS Source Addresses

A remote user can spoof SMS source addresses.

August 17, 2012
U-238: HP Service Manager Input Validation Flaw Permits Cross-Site Scripting Attacks

Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 7.11, 9.21, and 9.30, and HP Service Center Web Tier 6.28, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

August 16, 2012
U-237: Mozilla Firefox CVE-2012-1950 Address Bar URI Spoofing Vulnerability

To exploit this issue, an attacker must entice an unsuspecting user to follow a crafted URI.

August 15, 2012
U-236: Microsoft JScript and VBScript Engine Integer Overflow Lets Remote Users Execute Arbitrary Code

Execution of arbitrary code via network A remote user can cause arbitrary code to be executed on the target

August 14, 2012
U-234: Oracle MySQL User Login Security Bypass Vulnerability

Oracle MySQL is prone to a security bypass vulnerability Attackers can exploit this issue to bypass certain security restrictions.

August 13, 2012
U-233: Oracle Database INDEXTYPE CTXSYS.CONTEXT Bug Lets Remote Authenticated Users Gain Elevated Privileges

A remote authenticated user with 'Create Table' privileges can gain 'SYS' privileges on the target system.

August 10, 2012
U-232: Xen p2m_teardown() Bug Lets Local Guest OS Users Deny Service on the Host OS

A vulnerability was reported in Xen. A local user on a guest operating system can cause denial of service conditions on the host.

August 9, 2012
U-231: Cisco ASA SIP and WebVPN Bugs Let Remote Users Deny Service

Two vulnerabilities were reported in Cisco ASA. A remote or remote authenticated user can cause denial of service conditions.

August 8, 2012
U-230: Sudo on Red Hat Enterprise Linux %postun Symlink Flaw Lets Local Users Gain Elevated Privileges

An updated sudo package that fixes one security issue and several bugs is now available for Red Hat Enterprise Linux 5.