• No results found

MCAFEE FOUNDSTONE FSL UPDATE

N/A
N/A
Protected

Academic year: 2021

Share "MCAFEE FOUNDSTONE FSL UPDATE"

Copied!
102
0
0

Loading.... (view fulltext now)

Full text

(1)

2014-JUN-03

MCAFEE FOUNDSTONE FSL UPDATE

To better protect your environment McAfee has created this FSL check update for the Foundstone Product Suite. The following is a detailed summary of the new and updated checks included with this release.

NEW CHECKS

16673 - Microsoft Internet Explorer WeakMap Integer Divide-by-Zero Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Description

A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service. Observation

A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service.

The flaw is due to an unspecified defect. Successful exploitation by a remote attacker could result in a denial of service condition. 16661 - Intel Indeo Video ir41_32.ax Crafted File Denial of Service

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: Medium CVE: CVE-2014-3735 Description

A vulnerability in some versions of Intel Indeo Video could lead to a denial of service. Observation

A vulnerability in some versions of Intel Indeo Video could lead to a denial of service.

The flaw lies in ir41_32.ax. Successful exploitation by a remote attacker could result in a denial of service condition. 16671 - Apache Tomcat Multiple Vulnerabilities Prior To 6.0.41

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

CVE: CVE-2014-0075, CVE-2014-0096, CVE-2014-0099, CVE-2014-0119 Description

Multiple vulnerabilities are present in some versions of Apache Tomcat. Observation

Apache Tomcat is a Java application server.

(2)

exploitation could allow an attacker to obtain sensitive information or cause denial of service.

ENHANCED CHECKS

The following checks have been updated. Enhancements may include optimizations, changes that reflect new information on a vulnerability and anything else that improves upon an existing FSL check.

761 - PowerFTP Personal FTP Server Path Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

Check Version: 1.2 CVE: CVE-2001-0934 Update Details

Recommendation is updated.

780 - WebSitePro win-c-sample.exe Path Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-1999-0178 Update Details

Recommendation is updated.

852 - Oracle9iAS XSQLServlet XSQLConfig.xml disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2

CVE: CVE-2002-0568, CVE-2002-0569 DISA IAVA: 2002-T-0006,2002-T-0005 Update Details

Recommendation is updated.

856 - Lotus Domino $defaultNav Information Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-2001-0847 Update Details

(3)

875 - Microsoft IIS Anonymous Write Permissions Enabled

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

884 - Oracle WebDB Admin Backdoor Unauthorized Access

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 Update Details

Recommendation is updated.

908 - Microsoft IIS 4.0 /IISADMPWD/achg.htr Proxied Password Attack

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.524 CVE: CVE-1999-0407 Update Details

Recommendation is updated.

934 - csMailto.cgi Command Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-2002-0749 Update Details

Recommendation is updated.

956 - Compaq Web-Based Management default page

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2001-0374 Update Details

(4)

1224 - Sun Chili!Soft ASP Administration Console Default Password

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-2001-0632 Update Details

Recommendation is updated.

1248 - Oracle Web Listener Batch File Command Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-2000-0169 Update Details

Recommendation is updated.

1876 - Perl logbook.pl Command Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 Update Details

Recommendation is updated.

3048 - Morpheus FastTrack Service Identity Spoofing Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2

CVE: CVE-2002-0314, CVE-2002-0315 Update Details

Recommendation is updated.

3290 - Linksys WAP55AG Wireless Access Point User Access Vulnerability

Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High

(5)

CVE: CVE-2004-0312 Update Details

Recommendation is updated.

3382 - Campas CGI Script Information Leakage Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.3 CVE: CVE-1999-0146 Update Details

Recommendation is updated.

3386 - AdCycle Build.cgi Web Script Allows Unauthorized Access

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 CVE: CVE-2000-1161 Update Details

Recommendation is updated.

3393 - CCBill Arbitrary Code Execution Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.1 Update Details

Recommendation is updated.

3767 - Upload Lite Arbitrary File Upload and Execution Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2 Update Details

Recommendation is updated.

3823 - Alt-N MDaemon Local Privilege Escalation

(6)

(CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Check Version: 1.935 CVE: CVE-2004-2504 Update Details

Recommendation is updated.

3884 - w3who.dll ISAPI Buffer Overflow

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

Check Version: 1.1

CVE: CVE-2004-1133, CVE-2004-1134 Update Details

Recommendation is updated.

4098 - Microsoft HTML Help Workshop Buffer Overflow vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.95 CVE: CVE-2006-0564 Update Details

Recommendation is updated.

4207 - BLNews Path Parameter Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.328 CVE: CVE-2003-0394 Update Details

Recommendation is updated.

4285 - Nph-maillist Email Address Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

Check Version: 1.2284 CVE: CVE-2001-0400

(7)

Update Details

Recommendation is updated.

4306 - Kootenay Web Whois Command Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.338 CVE: CVE-2000-0941 Update Details

Recommendation is updated.

4319 - GAMSoft TelSrv Long Username Denial of Service

Category: General Vulnerability Assessment -> Intrusive -> UNIX Risk Level: High

Check Version: 1.340

CVE: CVE-1999-0230, CVE-2000-0166, CVE-2000-0480, CVE-2000-0665, CVE-2001-0348 Update Details

Recommendation is updated.

4339 - MSN ActiveX Setup BBS Buffer Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.340 CVE: CVE-1999-1484 Update Details

Recommendation is updated.

4723 - Microsoft Internet Explorer Window Injection Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.1630 CVE: CVE-2004-1155 Update Details

(8)

4754 - NetGear Wireless Driver Long Beacon Stack Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.1756 CVE: CVE-2006-5972 Update Details

Recommendation is updated.

4835 - Oracle Portal HTTP Response Splitting

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.1952

CVE: CVE-2006-6697, CVE-2006-6699, CVE-2006-6703 Update Details

Recommendation is updated.

4899 - Microsoft Visual Studio .CNT Buffer Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2129

CVE: CVE-2007-0352, CVE-2007-0427 Update Details

Recommendation is updated.

4902 - Microsoft Help Workshop .CNT Files Buffer Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2128

CVE: CVE-2007-0352, CVE-2007-0427 Update Details

Recommendation is updated.

4905 - Microsoft Visual Studio .HPJ Buffer Overflow

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

(9)

Risk Level: High Check Version: 1.2816

CVE: CVE-2007-0352, CVE-2007-0427 Update Details

Recommendation is updated.

4984 - FactoSystem Weblog Multiple SQL Injection Vulnerabilities

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.2542 CVE: CVE-2002-1499 Update Details

Recommendation is updated.

4997 - Microsoft Windows Explorer DOC File Crash

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2601 CVE: CVE-2007-1347 Update Details

Recommendation is updated.

5064 - Microsoft Word wwlib.dll Heap Buffer Overflow

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2891 CVE: CVE-2007-1910 Update Details

Recommendation is updated.

5065 - Microsoft Windows HLP File Handling Heap Buffer Overflow

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.2927 CVE: CVE-2007-1912

(10)

Update Details

Recommendation is updated.

5182 - Microsoft Internet Information Services Remote DoS

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Check Version: 1.3580 CVE: CVE-2007-2897 Update Details

Recommendation is updated.

5218 - Microsoft Windows XP GDI+ .ICO Handling DoS Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.3441 CVE: CVE-2007-2237 Update Details

Recommendation is updated.

5242 - Microsoft Office MSODataSourceControl ActiveX Control Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.3444 CVE: CVE-2007-3282 Update Details

Recommendation is updated.

5431 - Microsoft Internet Explorer FTP Access Information Disclosure

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.3909 CVE: CVE-2007-4356 Update Details

(11)

5469 - VMware vstor-ws60.sys Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.4077

CVE: CVE-2007-4591, CVE-2007-4593 Update Details

Recommendation is updated.

5492 - Microsoft Windows Media Player HTML Backdooring Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.4196 CVE: CVE-2007-5095 Update Details

Recommendation is updated.

5495 - Sun JRE isInstalled.dnsResolve Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.4196 CVE: CVE-2007-5019 Update Details

Recommendation is updated.

5526 - Symantec Veritas Backup Exec For Windows Servers Unspecified Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Check Version: 1.4374 CVE: CVE-2007-5126 Update Details

Recommendation is updated.

(12)

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-0098 Update Details

Recommendation is updated.

5671 - Microsoft Visual InterDev .sln Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2008-0250, CVE-2008-1709 Update Details

Recommendation is updated.

5836 - Microsoft Works WkImgSrv.dll ActiveX Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-1898 Update Details

Recommendation is updated.

5844 - Apple QuickTime Crafted MOV File Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-2010 Update Details

Recommendation is updated.

5867 - Microsoft Internet Explorer Cross-Zone Scripting Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-2281 Update Details

(13)

5899 - Creative Software AutoUpdate Engine ActiveX Control Stack Overflow

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-0955 Update Details

Recommendation is updated.

6007 - Microsoft Internet Explorer Cookie Session Fixation

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-3173 Update Details

Recommendation is updated.

6139 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2008-4116 Update Details

Recommendation is updated.

7256 - HP LoadRunner XUpload.ocx ActiveX Control Arbitrary File Download

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2009-3693 Update Details

Recommendation is updated.

7278 - Oracle Document Capture BlackIce DEVMODE ActiveX Control Remote Command Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

(14)

Update Details

Recommendation is updated.

7638 - Oracle Document Capture EasyMail ActiveX Control Buffer Overflow Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2007-4607 Update Details

Recommendation is updated.

7930 - Oracle Times-Ten In-Memory Database Denial Of Service Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

8139 - PHP 4 Userland ZVAL Reference Counter Integer Overflow Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2007-1383 Update Details

Recommendation is updated.

8198 - Microsoft IIS ASP.NET Cookie Header Information Disclosure Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

8300 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1118)

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2010-1118 Update Details

(15)

Recommendation is updated.

8716 - XAMPP Insecure Default Password Disclosure Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2005-1078 Update Details

Recommendation is updated.

8724 - Unix Finger Service User Account Information Disclosure Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: High

CVE: CVE-1999-0198 Update Details

Recommendation is updated.

8725 - Unix Finger User Account Information Disclosure Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: High

CVE: CVE-1999-0197 Update Details

Recommendation is updated.

8764 - Perforce Server Multiple Vulnerabilities

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2010-0929, CVE-2010-0930, CVE-2010-0931, CVE-2010-0932, CVE-2010-0933, CVE-2010-0934, CVE-2010-0935 Update Details

Recommendation is updated.

8800 - Open Flash Chart PHP Library Arbitrary File Creation Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

CVE: CVE-2009-4140 Update Details

(16)

8872 - Callisto PhotoParade Player PhPInfo ActiveX Control Buffer Overflow Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2007-1688 Update Details

Recommendation is updated.

8919 - Macrovision InstallFromTheWeb Multiple Buffer Overflow Vulnerabilities

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2007-0320 Update Details

Recommendation is updated.

8942 - Nginx HTTP Server File Path Parse Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

9155 - IBM Access Support ActiveX Control GetXMLValue Method Buffer Overflow Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2009-0215 Update Details

Recommendation is updated.

9270 - Microsoft Visual FoxPro FPOLE.OCX ActiveX Control Remote Command Execution Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2007-5322 Update Details

(17)

Recommendation is updated.

9340 - Microsoft SQL Server SQLExecutiveCmdExec Weak Password Encryption Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Windows Risk Level: High

CVE: CVE-1999-1556 Update Details

Recommendation is updated.

9390 - IBM DB2 Shared Libraries Privilege Escalation Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2003-1052 Update Details

Recommendation is updated.

9603 - Oracle Application Server Arbitrary File Access Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2001-0326 Update Details

Recommendation is updated.

9635 - Oracle Application Server dbsnmp And nmo Programs Privilege Escalation Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2004-1707 Update Details

Recommendation is updated.

9667 - Allied Telesyn TFTP Server Long Filename Remote Buffer Overflow Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2006-6184 Update Details

(18)

9670 - Wind River Systems VxWorks WDB Target Agent Debug Service Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2010-2965 DISA IAVA: 2010-B-0075 Update Details

Recommendation is updated.

9743 - FutureSoft TFTP Server 2000 Remote Denial Of Service Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

Update Details

Recommendation is updated.

9805 - Microsoft Windows 'win32k!GreStretchBltInternal()' Local Denial Of Service Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

9815 - SMTP Server Too Long Line Denial Of Service Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

Update Details

Recommendation is updated.

9831 - TFTPUtil GUI Long Transport Mode Buffer Overflow Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2010-2028 Update Details

(19)

9835 - ProSysInfo TFTP Server TFTPDWIN Long File Name Buffer Overflow Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2006-4948 Update Details

Recommendation is updated.

9945 - glFTPd Default Credentials Unauthorized Access Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> UNIX Risk Level: High

CVE: CVE-1999-0502 Update Details

Recommendation is updated.

10061 - Atrium Mercur Messaging IMAP Service Remote Buffer Overflow Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2006-1255 Update Details

Recommendation is updated.

10088 - GuildFTPd LIST and CWD Commands Heap Overflow Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2008-4572 Update Details

Recommendation is updated.

10129 - Open&Compact FTP Server Authentication Bypass Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2010-2620 Update Details

Recommendation is updated.

(20)

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

Update Details

Recommendation is updated.

10610 - Microsoft Internet Explorer 'window.onerror' Information Disclosure

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

10672 - GIGABYTE Dldrv2 ActiveX Control Multiple Vulnerabilities

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2010-1517, CVE-2010-1518 Update Details

Recommendation is updated.

10694 - WordPress Plugin fGallery SQL Injection Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2008-0491 Update Details

Recommendation is updated.

11008 - Microsoft Windows Ipv6 Router Advertisement Denial Of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2010-4669 Update Details

Recommendation is updated.

11610 - WordPress Rating-Widget Plugin Multiple Cross-Site Scripting Vulnerabilities

(21)

Risk Level: High Update Details

Recommendation is updated.

11873 - Microsoft HTML Help Stack Overflow Remote Code Execution

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

11890 - Microsoft Reader Integer Overflow

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

11898 - Microsoft Reader Heap Overflow Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

11902 - Microsoft Reader NULL Byte Write Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12012 - WordPress SocialGrid Plugin "default_services" Cross-Site Scripting Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

(22)

Recommendation is updated.

12097 - Quest Software Big Brother Arbitrary File Deletion Remote Code Execution

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

12135 - WordPress Magazeen Theme Multiple Vulnerabilities

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

12188 - HP 3COM/H3C Intelligent Management Center Img Recv Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2011-2331 Update Details

Recommendation is updated.

12577 - HP SiteScope Default Credentials Weaknesses

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

12703 - Microsoft Windows wab32res.dll Insecure Library Loading Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2010-3143 Update Details

(23)

12708 - Sunway ForceControl YRWXls.ocx ActiveX Control Buffer Overflow Vulnerability

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

12709 - Sunway ForceControl SCADA SNMP NetDBServer Integer Signedness Buffer Overflow Remote Code Execution

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

12798 - Sunway ForceControl SNMP NetDBServer Stack Buffer Overflow Remote Code Execution

Category: General Vulnerability Assessment -> Intrusive -> SCADA Risk Level: High

Update Details

Recommendation is updated.

12821 - OPC Systems.NET OPCSystemsService Denial Of Service Vulnerability

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

12842 - Snort Report target Multiple Remote Command Execution Vulnerabilities

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

12852 - A-Blog Sources Search.php SQL Injection Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

(24)

CVE: CVE-2010-4917 Update Details

Recommendation is updated.

12875 - Oracle AutoVue AutoVueX ActiveX Control Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12876 - Oracle AutoVue AutoVueX ActiveX Control ExportEdaBom Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12877 - Oracle AutoVue AutoVueX ActiveX Control Export3DBom Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12887 - IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

12897 - Microsoft Excel VBScript Validation Use After Free Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

(25)

Recommendation is updated.

12924 - Oracle DataDirect Multiple Native Wire Protocol ODBC Driver Buffer Overflow Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12929 - HP Data Protector Media Operations Directory Traversal Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12930 - HP Data Protector Media Operations Heap Buffer Overflow Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

12951 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution II

Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High

CVE: CVE-2008-7303 Update Details

Recommendation is updated.

12952 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution

Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High

CVE: CVE-2011-1516 Update Details

(26)

12962 - Microsoft Excel Window2 Record Use After Free Remote Code Execution

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13053 - Adobe Flash Player VulnDisco Step Ahead Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2011-4693, CVE-2011-4694 Update Details

Recommendation is updated.

13091 - Ipswitch WS TFTP Server Directory Traversal Information Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

Update Details

Recommendation is updated.

13144 - Microsoft Windows Media Player Null Pointer Remote Denial Of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13182 - CoCSoft Stream Down Response Buffer Overflow Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2011-5052 Update Details

(27)

13370 - Novell GroupWise Messenger nmma.exe Login Memory Corruption Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13371 - Novell GroupWise Messenger nmma.exe Arbitrary Memory Corruption Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13383 - Beckhoff TwinCAT TCatScopeView SVW And SCP File Processing Remote Code Execution

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

13423 - IBM Tivoli Provisioning Manager Express ActiveX Control Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2012-0198 Update Details

Recommendation is updated.

13424 - IBM Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

CVE: CVE-2012-0199 Update Details

(28)

13435 - Apple Safari Plug-in Unloading Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2011-3845 Update Details

Recommendation is updated.

13579 - Microsoft Visual Studio Incremental Linker Integer Overflow Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13733 - Tftpd32 DNS Server Denial Of Service Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13735 - Microsoft Wordpad Doc File Null Pointer Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13749 - Apple iOS Safari match() Buffer Denial of Service

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

(29)

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13791 - Microsoft IIS 6.0 PHP Authentication Bypass Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13792 - Microsoft IIS 7.5 .NET Authentication Bypass Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

13831 - PHP com_print_typeinfo Function Buffer Overflow Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2012-2376 Update Details

Recommendation is updated.

13986 - Apple iOS Safari match() Buffer Denial of Service

Category: Wireless Assessment -> NonIntrusive -> iOS Risk Level: High

Update Details

Recommendation is updated.

14076 - Windows Explorer BMP File Handling Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

(30)

Risk Level: High CVE: CVE-2007-1946 Update Details

Recommendation is updated.

14084 - Microsoft Index Service Ixsso.dll Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14085 - KASKAD SCADA DAServer.exe Remote Code Execution

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

14095 - Oracle Business Transaction Management Server FlashTunnelService Denial of Service

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

14125 - HP Intelligent Management Center uam.exe Stack Buffer Overflow

Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High

CVE: CVE-2012-3274 Update Details

Recommendation is updated.

14154 - EMC AutoStart Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

(31)

Update Details

Recommendation is updated.

14158 - EMC AlphaStor Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

Update Details

Recommendation is updated.

14181 - Oracle Business Transaction Management SOAP Web Service Directory Traversal Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

14250 - QNX FTPD Denial of Service

Category: General Vulnerability Assessment -> NonIntrusive -> SCADA Risk Level: High

Update Details

Recommendation is updated.

14260 - CYME Power Engineering ChartFX Client Server ActiveX Control Array Indexing Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14294 - Microsoft Office Picture Manager Memory Corruption Remote Code Execution

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

(32)

14324 - RealNetworks RealPlayer 3GP File Handling Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14352 - Microsoft Office Excel WriteAV Remote Code Execution

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14452 - Sunsolve sscd_suncourier.pl Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2002-0436 Update Details

Recommendation is updated.

14455 - WordPress AdWizz Plugin "link" Cross-Site Scripting Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

14515 - VideoLAN VLC Media Player SWF File Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14527 - Adobe Flash Player FLV File Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

(33)

Risk Level: High Update Details

Recommendation is updated.

14539 - Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2012-6270, CVE-2012-6271 Update Details

Recommendation is updated.

14540 - Microsoft Internet Explorer Remote Stack Overflow Vulnerability

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14789 - Oracle Java SE Reflection API Remote Code Execution I

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14790 - Oracle Java SE Reflection API Remote Code Execution II

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14806 - HMS Netbiter Config Utility Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

(34)

Update Details

Recommendation is updated.

14865 - Kaspersky Internet Security Kaspersky Anti-Virus NDIS 6 Filter Denial of Service Vulnerability

Category: Windows Host Assessment -> Anti-Virus Software (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

14922 - PostgreSQL Command-Line Switch Error Messages Data Directory Denial of Service

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

CVE: CVE-2013-1899 Update Details

Recommendation is updated.

15010 - Schneider Electric Vijeo Web Gate Server Denial Of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

15105 - MOXA Mass Configuration Tool Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

15303 - MOXA AWK Search Utility Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

(35)

Recommendation is updated.

15423 - DotNetNuke DNNArticle Module "categoryid" SQL Injection Vulnerability

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High

CVE: CVE-2013-5117 Update Details

Recommendation is updated.

15542 - (MS13-067) Microsoft SharePoint MAC Disabled Remote Code Execution (2834052)

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2013-1330 DISA IAVA: 2013-A-0174 Microsoft ID: MS13-067 Microsoft KB: 2834052 Update Details

Recommendation is updated.

15780 - EATON VURemote Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

15782 - Moore Industries NCS Configuration Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

15794 - McAfee Web Reporter Tomcat EJBInvokerServlet Marshalled Object Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

(36)

CVE: CVE-2012-0874 Update Details

Recommendation is updated.

15845 - NETGEAR WNDR3700v4 ping6 Diagnostic Page Command Injection Vulnerability

Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High

Update Details

Recommendation is updated.

15905 - FirebirdSQL Firebird Null Pointer Denial of Service I

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

15960 - Symantec Workspace Streaming EJBInvokerServlet / JMXInvokerServlet Marshalled Object Vulnerability

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High Update Details

Recommendation is updated.

15975 - Microsoft Word Embedded Image Fork Bomb Denial of Service

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2013-6801 Update Details

Recommendation is updated.

16164 - McAfee Email Gateway Multiple SQL Injection and Remote Command Execution Vulnerabilities

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

(37)

Update Details

Recommendation is updated.

16205 - HP 2620 Switches /html/json.html Admin Account Manipulation Cross-Site Request Forgery

Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: High

CVE: CVE-2013-6852 Update Details

Recommendation is updated.

16258 - Eaton Network Shutdown Module Pi3Web WebServer Denial of Service

Category: General Vulnerability Assessment -> NonIntrusive -> SCADA Risk Level: High

Update Details

Recommendation is updated.

16262 - Inductive Automation Ignition Gateway OPC-UA Server Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

16426 - Linksys Multiple E-Series Routers Security Bypass Vulnerability

Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High

CVE: CVE-2013-5122 Update Details

Recommendation is updated.

16445 - Delta Electronics WPLSoft DVPSimulator.exe Buffer Overflow Remote Code Execution

Category: General Vulnerability Assessment -> Intrusive -> SCADA Risk Level: High

Update Details

(38)

16463 - Adobe Reader Multiple Remote Code Execution Vulnerabilities

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2014-0511, CVE-2014-0512 DISA IAVA: 2014-A-0070

Update Details

Recommendation is updated.

16558 - Microsoft Windows Unspecified Flaw Kernel Local Privilege Escalation

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2014-1766 Update Details

Recommendation is updated.

16559 - Microsoft Internet Explorer Multiple Sandbox Bypass and Use-After-Free Vulnerabilities

Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High

CVE: CVE-2014-1762, CVE-2014-1763, CVE-2014-1764, CVE-2014-1765 Update Details

Recommendation is updated.

16584 - McAfee Email And Web Security Appliance Multiple Unspecified Vulnerabilities

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High

Update Details

Recommendation is updated.

16620 - Paessler PRTG Network Monitor Server.exe Denial of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

(39)

16628 - FrameFlow Server Monitor Unspecified Defect Denial Of Service

Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High

Update Details

Recommendation is updated.

16632 - VideoLAN VLC Media Player libpng_plugin.dll Denial of Service

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2014-3441 Update Details

Recommendation is updated.

16641 - Nullsoft Winamp Malformed .FLV File Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2014-3442 Update Details

Recommendation is updated.

16648 - RealNetworks RealPlayer GetGUID Function Remote Code Execution

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: High CVE: CVE-2014-3444 Update Details

Recommendation is updated.

16651 - IceWarp Mail Server Preauth Buffer Overflow Remote Code Execution

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High

Update Details

(40)

38132 - Apple QuickTime Crafted MOV File Code Execution

Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High

CVE: CVE-2008-2010 Update Details

Recommendation is updated.

38159 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability

Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High

CVE: CVE-2008-4116 Update Details

Recommendation is updated.

38208 - Apple Mac OS X AppleTalk 'zip-notify' Buffer Overflow Vulnerability

Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High

CVE: CVE-2009-1236 Update Details

Recommendation is updated.

87313 - Fedora Linux 16 FEDORA-2013-1130 Update Is Not Installed

Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High

CVE: CVE-2013-1348, CVE-2013-1397 Update Details

Risk is updated.

87368 - Fedora Linux 18 FEDORA-2013-1167 Update Is Not Installed

Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High

CVE: CVE-2013-1397 Update Details Risk is updated.

(41)

87383 - Fedora Linux 17 FEDORA-2013-0985 Update Is Not Installed

Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High

CVE: CVE-2013-1397 Update Details Risk is updated.

187491 - Fedora Linux 19 FEDORA-2013-23720 Update Is Not Installed

Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High

CVE: CVE-2013-2298 Update Details Risk is updated.

187493 - Fedora Linux 20 FEDORA-2013-23734 Update Is Not Installed

Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High

CVE: CVE-2013-2298 Update Details Risk is updated.

642 - Microsoft IIS ExAir Denial-of-Service

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

CVE: CVE-1999-0449 Update Details

Recommendation is updated.

762 - PowerFTP Personal FTP Server Directory Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium

Check Version: 1.3 CVE: CVE-2002-1544 Update Details

(42)

763 - PowerFTP Personal FTP Server Tilde Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium

Check Version: 1.2 Update Details

Recommendation is updated.

826 - D-Link DWL-1000AP Wireless Access Point SNMP Public Community String Category: Wireless Assessment -> NonIntrusive -> Wireless

Risk Level: Medium Check Version: 1.2 CVE: CVE-2001-1221 Update Details

Recommendation is updated.

845 - Apache Win32 PHP.EXE Remote File Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

CVE: CVE-2002-2029 Update Details

Recommendation is updated.

859 - Compaq Survey Utility Anonymous Login

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

CVE: CVE-1999-0771 Update Details

Recommendation is updated.

872 - Lotus Domino Web Server statrep.nsf Anonymous Access Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2 Update Details

(43)

935 - FormMail.pl Detected

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.3 CVE: CVE-2001-0357 Update Details

Recommendation is updated.

937 - Apple Airport Base Station WEP Key Disclosure Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: Medium

Check Version: 1.4598 Update Details

Recommendation is updated.

1014 - Microsoft ASP.NET Application Trace Enabled

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Update Details

Recommendation is updated.

1039 - Omnicron OmniHTTPd Long Request Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: Medium

CVE: CVE-2001-0613 Update Details

Recommendation is updated.

1041 - MyWebServer Buffer Overflow

Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: Medium

CVE: CVE-2002-1003 Update Details

(44)

1056 - Multiple Vendor Access Point Information Leakage Category: Wireless Assessment -> NonIntrusive -> Wireless

Risk Level: Medium Check Version: 1.2 Update Details

Recommendation is updated.

1212 - RedHat Linux Apache Remote Username Enumeration Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.941 CVE: CVE-2001-1013 Update Details

Recommendation is updated.

1408 - Novell NetWare Webservers Denial-of-Service

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.3 CVE: CVE-1999-0929 Update Details

Recommendation is updated.

1413 - Sun JavaServer Default Admin Password

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.3 Update Details

Recommendation is updated.

1956 - Intel Express 8100 Router Fragmented ICMP Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network

Risk Level: Medium Check Version: 1.3383 CVE: CVE-2000-0451 Update Details

(45)

1958 - Efficient Networks 5861 Router NMap Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium

Check Version: 1.4598 CVE: CVE-2003-1250 Update Details

Recommendation is updated.

1965 - Lucent Router UDP Information Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium

Check Version: 1.3383 CVE: CVE-2002-2148 Update Details

Recommendation is updated.

2367 - Sun Java App Server PE 8.0 Path Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Update Details

Recommendation is updated.

3012 - 3com 3CDaemon FTP Remote Format String

Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium

Check Version: 1.2 CVE: CVE-2005-0276 Update Details

Recommendation is updated.

3052 - Grokster FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.2 CVE: CVE-2003-0397

(46)

Update Details

Recommendation is updated.

3053 - IMesh FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.1 CVE: CVE-2003-0397 Update Details

Recommendation is updated.

3054 - Morpheus FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.2 CVE: CVE-2003-0397 Update Details

Recommendation is updated.

3055 - Kazaa FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.2 CVE: CVE-2003-0397 Update Details

Recommendation is updated.

3180 - RealPlayer RealMedia ".rm" Security Bypass Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.3193 Update Details

(47)

3372 - Abe Zimmerman xml.cgi Remote File Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium Check Version: 1.2 CVE: CVE-2001-1209 Update Details

Recommendation is updated.

3861 - Home FTP Information Disclosure Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: Medium Check Version: 1.935

CVE: CVE-2005-2726, CVE-2005-2727, CVE-2006-0355, CVE-2006-0356 Update Details

Recommendation is updated.

4173 - Visual Studio 6.0 Project Name Buffer Overflow Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.226 CVE: CVE-2006-1043 Update Details

Recommendation is updated.

4227 - AlienForm2 Directory Traversal Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: Medium

Check Version: 1.328 CVE: CVE-2002-0934 Update Details

Recommendation is updated.

4295 - Way-BOARD CGI Information Disclosure

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

(48)

Check Version: 1.2161 CVE: CVE-2001-0214 Update Details

Recommendation is updated.

4299 - BroadVision One-To-One Enterprise Information Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.338 CVE: CVE-2001-0031 Update Details

Recommendation is updated.

4307 - Armada Master Index search.cgi Directory Traversal Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2161 CVE: CVE-2000-0924 Update Details

Recommendation is updated.

4329 - WindMail Metacharacter Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2280 CVE: CVE-2000-0242 Update Details

Recommendation is updated.

4330 - Caldera OpenLinux rpm_query Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2161 CVE: CVE-2000-0192 Update Details

(49)

4335 - PowerScripts PlusMail CGI password file Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2167 CVE: CVE-2000-0074 Update Details

Recommendation is updated.

4345 - OmniHTTPD visadmin.exe Denial of Service

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.338 CVE: CVE-1999-0970 Update Details

Recommendation is updated.

4348 - Alibaba web server CGI Vulnerability

Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

Check Version: 1.2273 CVE: CVE-1999-0885 Update Details

Recommendation is updated.

4721 - Microsoft Internet Explorer Popup Address Bar Spoofing Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.1621 CVE: CVE-2006-5544 Update Details

Recommendation is updated.

4973 - Microsoft Internet Explorer HTML Tag Information Disclosure Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

(50)

Check Version: 1.2437 CVE: CVE-2007-3406 Update Details

Recommendation is updated.

4986 - Microsoft Windows Vista Local Privilege Escalation Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.2513 Update Details

Recommendation is updated.

5433 - Microsoft DXMedia SDK ActiveX Remote Code Execution Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.3926 CVE: CVE-2007-4336 Update Details

Recommendation is updated.

5457 - Microsoft Internet Saved Web Page Cross-Site Scripting Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4019 CVE: CVE-2007-4478 Update Details

Recommendation is updated.

5458 - Sony MicroVault USB Fingerprint Hidden Folder Vulnerability Category: Windows Host Assessment -> Trojans, Backdoors, Viruses, and Malware (CATEGORY REQUIRES CREDENTIALS)

Risk Level: Medium Check Version: 1.4063 CVE: CVE-2007-4785 Update Details

(51)

Recommendation is updated.

5488 - Microsoft Visual Studio PDWizard Remote Code Execution Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4153 CVE: CVE-2007-4891 Update Details

Recommendation is updated.

5511 - Microsoft Internet Explorer OnKeyDown Focus Information Disclosure Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4361 CVE: CVE-2007-5158 Update Details

Recommendation is updated.

5540 - Xunlei Web Thunder DPClient.Vod.1 ActiveX Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4469 CVE: CVE-2007-5064 Update Details

Recommendation is updated.

5563 - Mozilla Firefox Data URL Scheme Design Flaw Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4594 Update Details

Recommendation is updated.

(52)

Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: Medium Check Version: 1.4653 CVE: CVE-2007-5911 Update Details

Recommendation is updated.

5601 - Microsoft Windows Pseudo-Random Number Generator Design Flaw Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Check Version: 1.4818 CVE: CVE-2007-6043 Update Details

Recommendation is updated.

5888 - Mozilla Firefox JSFrame Vulnerability Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)

Risk Level: Medium CVE: CVE-2008-2419 Update Details

Recommendation is updated.

6006 - Yahoo Messenger VBscript Remote Denial of Service Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Update Details

Recommendation is updated.

6242 - Microsoft Windows Vista TCP/IP Buffer Overflow Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2008-5229 Update Details

(53)

Recommendation is updated.

6558 - Mozilla Firefox XUL/XML Parser Corruption Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2009-1232 Update Details

Recommendation is updated.

6567 - Mozilla Firefox location.hash Denial-of-Service Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2008-5715 Update Details

Recommendation is updated.

6626 - Safari For Windows XML Tag Denial Of Service Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2009-1233 Update Details

Recommendation is updated.

6980 - Apache HTTPD suexec Multiple Local Privilege Escalation Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium

CVE: CVE-2007-1741, CVE-2007-1742, CVE-2007-1743 Update Details

Recommendation is updated.

6982 - Microsoft Internet Explorer findText Parsing Denial-of-Service Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

(54)

Update Details

Recommendation is updated.

7129 - Microsoft Wordpad Memory Exhaustion Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Update Details

Recommendation is updated.

7139 - Microsoft Internet Explorer URL Spoofing Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2009-3003 Update Details

Recommendation is updated.

7750 - Oracle Reports Server Multiple Cross Site Scripting Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium CVE: CVE-2005-2379 Update Details

Recommendation is updated.

8095 - IBM Lotus Domino Server nserver.exe Crash Denial Of Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium

CVE: CVE-2009-3087 Update Details

Recommendation is updated.

8126 - Apache mod_perl File Descriptor Leakage Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium

(55)

Recommendation is updated.

8129 - Apache HTTP Server mod_rewrite Security Bypass Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium CVE: CVE-2001-1072 Update Details

Recommendation is updated.

8205 - Sendmail Long IDENT Logging Circumvention Weakness Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX

Risk Level: Medium CVE: CVE-2002-2423 Update Details

Recommendation is updated.

8213 - Microsoft Virtual PC Hypervisor Memory Protection Security Bypass Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Update Details

Recommendation is updated.

8233 - Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium CVE: CVE-2002-1745 Update Details

Recommendation is updated.

8299 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1117) Category: Windows Host Assessment -> Patches and Hotfixes

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

CVE: CVE-2010-1117 Update Details

(56)

Recommendation is updated.

8380 - Microsoft IIS Sample Application Cross Site Scripting Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium Update Details

Recommendation is updated.

8499 - Sun Java System Directory Server LDAP Search Request Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous

Risk Level: Medium CVE: CVE-2010-0313 Update Details

Recommendation is updated.

8502 - Microsoft Office Communicator (Beta) SIP Denial Of Service Vulnerability Category: Windows Host Assessment -> Miscellaneous

(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium

Update Details

Recommendation is updated.

8634 - Sun Java System Web Server WebDAV LOCK Request File Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Web Server

Risk Level: Medium Update Details

Recommendation is updated.

8666 - Cisco IOS HTTP Server Cross Site Scripting Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium

CVE: CVE-2009-0470 Update Details

References

Related documents

l Microsoft Internet Explorer 11 (not supported on Windows Server 2012) l Google Chrome. l Mozilla Firefox (requires hardware acceleration, not supported

Microsoft, Microsoft Windows, Active Directory, ActiveSync, Internet Explorer, Windows Mobile, Windows Server, Windows XP, SQL Server, Windows XP Tablet PC Edition and Windows

Java has been enabled click “OK” Restart your browser to make to change effective (if applicable).. Page 12 of 13 If Label thermal printing does not work correctly and no

STELIOS ANDREOU, MICHAEL FOTIADIS, AND KOSTAS KOTSAKIS Dikili Tash II (ending ca. 3200 B.C.), and between the Early Bronze Age and the later Bronze

and Microsoft SUS allows you to update operating systems using Microsoft SUS (Windows 2000, XP, .NET, IIS, IE, Windows Media) and service packs, Microsoft application patches,

A remote code execution vulnerability is present in some versions of BlackBerry Enterprise Server... The flaw is due to how TIFF images

13765 - (MS12-037) Microsoft Internet Explorer HTML Sanitization Information Disclosure (2699988) Category: Windows Host Assessment -> Patches and Hotfixes. (CATEGORY

For questions regarding applying Microsoft Updates or EndoWorks Patches, please contact Olympus Technical Assistance Center.. NOTE: Do not update Internet Explorer (IE) to a