You are here

JC3 Medium Impact Assessment Bulletins

July 9, 2012
U-207: Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability

Pidgin is prone to a stack-based buffer-overflow vulnerability.

July 6, 2012
U-206: WordPress Flaws Permit Cross-Site Scripting, Cross-Site Request Forgery, and Information Disclosure Attacks

Several vulnerabilities were reported in WordPress. A remote authenticated user can conduct cross-site scripting attacks. A remote user can conduct cross-site request forgery attacks. A remote authenticated user can obtain potentially sensitive information.

July 5, 2012
U-205: RSA Access Manager Session Replay Flaw Lets Remote Users Access the System

A vulnerability was reported in RSA Access Manager. A remote user can gain access to the target system.

July 3, 2012
U-204: HP Network Node Manager i Input Validation Hole Permits Cross-Site Scripting Attacks

Potential security vulnerabilities have been identified with HP Network Node Manager I (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in cross site scripting (XSS).

June 29, 2012
U-202: Apple QuickTime Multiple Stack Overflow Vulnerabilities

Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

June 28, 2012
U-201: HP System Management Homepage Bugs Let Remote Users Deny Service

The vulnerabilities could be exploited remotely resulting in unauthorized access, disclosure of information, data modification, Denial of Service (DoS), and execution of arbitrary code.

June 27, 2012
U-200: Red Hat Directory Server Information Disclosure Security Issue and Vulnerability

If an LDAP user had changed their password, and the directory server had not been restarted since that change, an attacker able to bind to the directory server could obtain the plain text version of that user's password.

June 20, 2012
U-195: PHPlist Input Validation Flaws Permit Cross-Site Scripting and SQL Injection Attacks

The 'public_html/lists/admin' pages do not properly validate user-supplied input in the 'sortby' parameter [CVE-2012-2740]. A remote authenticated administrative user can supply a specially crafted parameter value to execute SQL commands on the underlying database.

June 8, 2012
U-186: IBM WebSphere Sensor Events Multiple Vulnerabilities

Some vulnerabilities have unknown impacts and others can be exploited by malicious people to conduct cross-site scripting attacks.