2014-JUN-03
MCAFEE FOUNDSTONE FSL UPDATE
To better protect your environment McAfee has created this FSL check update for the Foundstone Product Suite. The following is a detailed summary of the new and updated checks included with this release.
NEW CHECKS
16673 - Microsoft Internet Explorer WeakMap Integer Divide-by-Zero Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Description
A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service. Observation
A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service.
The flaw is due to an unspecified defect. Successful exploitation by a remote attacker could result in a denial of service condition. 16661 - Intel Indeo Video ir41_32.ax Crafted File Denial of Service
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: Medium CVE: CVE-2014-3735 Description
A vulnerability in some versions of Intel Indeo Video could lead to a denial of service. Observation
A vulnerability in some versions of Intel Indeo Video could lead to a denial of service.
The flaw lies in ir41_32.ax. Successful exploitation by a remote attacker could result in a denial of service condition. 16671 - Apache Tomcat Multiple Vulnerabilities Prior To 6.0.41
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
CVE: CVE-2014-0075, CVE-2014-0096, CVE-2014-0099, CVE-2014-0119 Description
Multiple vulnerabilities are present in some versions of Apache Tomcat. Observation
Apache Tomcat is a Java application server.
exploitation could allow an attacker to obtain sensitive information or cause denial of service.
ENHANCED CHECKS
The following checks have been updated. Enhancements may include optimizations, changes that reflect new information on a vulnerability and anything else that improves upon an existing FSL check.
761 - PowerFTP Personal FTP Server Path Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
Check Version: 1.2 CVE: CVE-2001-0934 Update Details
Recommendation is updated.
780 - WebSitePro win-c-sample.exe Path Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-1999-0178 Update Details
Recommendation is updated.
852 - Oracle9iAS XSQLServlet XSQLConfig.xml disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2
CVE: CVE-2002-0568, CVE-2002-0569 DISA IAVA: 2002-T-0006,2002-T-0005 Update Details
Recommendation is updated.
856 - Lotus Domino $defaultNav Information Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-2001-0847 Update Details
875 - Microsoft IIS Anonymous Write Permissions Enabled
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
884 - Oracle WebDB Admin Backdoor Unauthorized Access
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 Update Details
Recommendation is updated.
908 - Microsoft IIS 4.0 /IISADMPWD/achg.htr Proxied Password Attack
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.524 CVE: CVE-1999-0407 Update Details
Recommendation is updated.
934 - csMailto.cgi Command Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-2002-0749 Update Details
Recommendation is updated.
956 - Compaq Web-Based Management default page
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2001-0374 Update Details
1224 - Sun Chili!Soft ASP Administration Console Default Password
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-2001-0632 Update Details
Recommendation is updated.
1248 - Oracle Web Listener Batch File Command Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-2000-0169 Update Details
Recommendation is updated.
1876 - Perl logbook.pl Command Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 Update Details
Recommendation is updated.
3048 - Morpheus FastTrack Service Identity Spoofing Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2
CVE: CVE-2002-0314, CVE-2002-0315 Update Details
Recommendation is updated.
3290 - Linksys WAP55AG Wireless Access Point User Access Vulnerability
Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High
CVE: CVE-2004-0312 Update Details
Recommendation is updated.
3382 - Campas CGI Script Information Leakage Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.3 CVE: CVE-1999-0146 Update Details
Recommendation is updated.
3386 - AdCycle Build.cgi Web Script Allows Unauthorized Access
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 CVE: CVE-2000-1161 Update Details
Recommendation is updated.
3393 - CCBill Arbitrary Code Execution Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.1 Update Details
Recommendation is updated.
3767 - Upload Lite Arbitrary File Upload and Execution Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2 Update Details
Recommendation is updated.
3823 - Alt-N MDaemon Local Privilege Escalation
(CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Check Version: 1.935 CVE: CVE-2004-2504 Update Details
Recommendation is updated.
3884 - w3who.dll ISAPI Buffer Overflow
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
Check Version: 1.1
CVE: CVE-2004-1133, CVE-2004-1134 Update Details
Recommendation is updated.
4098 - Microsoft HTML Help Workshop Buffer Overflow vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.95 CVE: CVE-2006-0564 Update Details
Recommendation is updated.
4207 - BLNews Path Parameter Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.328 CVE: CVE-2003-0394 Update Details
Recommendation is updated.
4285 - Nph-maillist Email Address Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
Check Version: 1.2284 CVE: CVE-2001-0400
Update Details
Recommendation is updated.
4306 - Kootenay Web Whois Command Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.338 CVE: CVE-2000-0941 Update Details
Recommendation is updated.
4319 - GAMSoft TelSrv Long Username Denial of Service
Category: General Vulnerability Assessment -> Intrusive -> UNIX Risk Level: High
Check Version: 1.340
CVE: CVE-1999-0230, CVE-2000-0166, CVE-2000-0480, CVE-2000-0665, CVE-2001-0348 Update Details
Recommendation is updated.
4339 - MSN ActiveX Setup BBS Buffer Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.340 CVE: CVE-1999-1484 Update Details
Recommendation is updated.
4723 - Microsoft Internet Explorer Window Injection Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.1630 CVE: CVE-2004-1155 Update Details
4754 - NetGear Wireless Driver Long Beacon Stack Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.1756 CVE: CVE-2006-5972 Update Details
Recommendation is updated.
4835 - Oracle Portal HTTP Response Splitting
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.1952
CVE: CVE-2006-6697, CVE-2006-6699, CVE-2006-6703 Update Details
Recommendation is updated.
4899 - Microsoft Visual Studio .CNT Buffer Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2129
CVE: CVE-2007-0352, CVE-2007-0427 Update Details
Recommendation is updated.
4902 - Microsoft Help Workshop .CNT Files Buffer Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2128
CVE: CVE-2007-0352, CVE-2007-0427 Update Details
Recommendation is updated.
4905 - Microsoft Visual Studio .HPJ Buffer Overflow
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2816
CVE: CVE-2007-0352, CVE-2007-0427 Update Details
Recommendation is updated.
4984 - FactoSystem Weblog Multiple SQL Injection Vulnerabilities
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.2542 CVE: CVE-2002-1499 Update Details
Recommendation is updated.
4997 - Microsoft Windows Explorer DOC File Crash
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2601 CVE: CVE-2007-1347 Update Details
Recommendation is updated.
5064 - Microsoft Word wwlib.dll Heap Buffer Overflow
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2891 CVE: CVE-2007-1910 Update Details
Recommendation is updated.
5065 - Microsoft Windows HLP File Handling Heap Buffer Overflow
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.2927 CVE: CVE-2007-1912
Update Details
Recommendation is updated.
5182 - Microsoft Internet Information Services Remote DoS
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Check Version: 1.3580 CVE: CVE-2007-2897 Update Details
Recommendation is updated.
5218 - Microsoft Windows XP GDI+ .ICO Handling DoS Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.3441 CVE: CVE-2007-2237 Update Details
Recommendation is updated.
5242 - Microsoft Office MSODataSourceControl ActiveX Control Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.3444 CVE: CVE-2007-3282 Update Details
Recommendation is updated.
5431 - Microsoft Internet Explorer FTP Access Information Disclosure
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.3909 CVE: CVE-2007-4356 Update Details
5469 - VMware vstor-ws60.sys Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.4077
CVE: CVE-2007-4591, CVE-2007-4593 Update Details
Recommendation is updated.
5492 - Microsoft Windows Media Player HTML Backdooring Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.4196 CVE: CVE-2007-5095 Update Details
Recommendation is updated.
5495 - Sun JRE isInstalled.dnsResolve Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.4196 CVE: CVE-2007-5019 Update Details
Recommendation is updated.
5526 - Symantec Veritas Backup Exec For Windows Servers Unspecified Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Check Version: 1.4374 CVE: CVE-2007-5126 Update Details
Recommendation is updated.
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-0098 Update Details
Recommendation is updated.
5671 - Microsoft Visual InterDev .sln Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2008-0250, CVE-2008-1709 Update Details
Recommendation is updated.
5836 - Microsoft Works WkImgSrv.dll ActiveX Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-1898 Update Details
Recommendation is updated.
5844 - Apple QuickTime Crafted MOV File Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-2010 Update Details
Recommendation is updated.
5867 - Microsoft Internet Explorer Cross-Zone Scripting Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-2281 Update Details
5899 - Creative Software AutoUpdate Engine ActiveX Control Stack Overflow
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-0955 Update Details
Recommendation is updated.
6007 - Microsoft Internet Explorer Cookie Session Fixation
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-3173 Update Details
Recommendation is updated.
6139 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2008-4116 Update Details
Recommendation is updated.
7256 - HP LoadRunner XUpload.ocx ActiveX Control Arbitrary File Download
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2009-3693 Update Details
Recommendation is updated.
7278 - Oracle Document Capture BlackIce DEVMODE ActiveX Control Remote Command Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Update Details
Recommendation is updated.
7638 - Oracle Document Capture EasyMail ActiveX Control Buffer Overflow Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2007-4607 Update Details
Recommendation is updated.
7930 - Oracle Times-Ten In-Memory Database Denial Of Service Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
8139 - PHP 4 Userland ZVAL Reference Counter Integer Overflow Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2007-1383 Update Details
Recommendation is updated.
8198 - Microsoft IIS ASP.NET Cookie Header Information Disclosure Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
8300 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1118)
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2010-1118 Update Details
Recommendation is updated.
8716 - XAMPP Insecure Default Password Disclosure Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2005-1078 Update Details
Recommendation is updated.
8724 - Unix Finger Service User Account Information Disclosure Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: High
CVE: CVE-1999-0198 Update Details
Recommendation is updated.
8725 - Unix Finger User Account Information Disclosure Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: High
CVE: CVE-1999-0197 Update Details
Recommendation is updated.
8764 - Perforce Server Multiple Vulnerabilities
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2010-0929, CVE-2010-0930, CVE-2010-0931, CVE-2010-0932, CVE-2010-0933, CVE-2010-0934, CVE-2010-0935 Update Details
Recommendation is updated.
8800 - Open Flash Chart PHP Library Arbitrary File Creation Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
CVE: CVE-2009-4140 Update Details
8872 - Callisto PhotoParade Player PhPInfo ActiveX Control Buffer Overflow Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2007-1688 Update Details
Recommendation is updated.
8919 - Macrovision InstallFromTheWeb Multiple Buffer Overflow Vulnerabilities
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2007-0320 Update Details
Recommendation is updated.
8942 - Nginx HTTP Server File Path Parse Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
9155 - IBM Access Support ActiveX Control GetXMLValue Method Buffer Overflow Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2009-0215 Update Details
Recommendation is updated.
9270 - Microsoft Visual FoxPro FPOLE.OCX ActiveX Control Remote Command Execution Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2007-5322 Update Details
Recommendation is updated.
9340 - Microsoft SQL Server SQLExecutiveCmdExec Weak Password Encryption Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Windows Risk Level: High
CVE: CVE-1999-1556 Update Details
Recommendation is updated.
9390 - IBM DB2 Shared Libraries Privilege Escalation Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2003-1052 Update Details
Recommendation is updated.
9603 - Oracle Application Server Arbitrary File Access Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2001-0326 Update Details
Recommendation is updated.
9635 - Oracle Application Server dbsnmp And nmo Programs Privilege Escalation Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2004-1707 Update Details
Recommendation is updated.
9667 - Allied Telesyn TFTP Server Long Filename Remote Buffer Overflow Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2006-6184 Update Details
9670 - Wind River Systems VxWorks WDB Target Agent Debug Service Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2010-2965 DISA IAVA: 2010-B-0075 Update Details
Recommendation is updated.
9743 - FutureSoft TFTP Server 2000 Remote Denial Of Service Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
Update Details
Recommendation is updated.
9805 - Microsoft Windows 'win32k!GreStretchBltInternal()' Local Denial Of Service Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
9815 - SMTP Server Too Long Line Denial Of Service Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
Update Details
Recommendation is updated.
9831 - TFTPUtil GUI Long Transport Mode Buffer Overflow Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2010-2028 Update Details
9835 - ProSysInfo TFTP Server TFTPDWIN Long File Name Buffer Overflow Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2006-4948 Update Details
Recommendation is updated.
9945 - glFTPd Default Credentials Unauthorized Access Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> UNIX Risk Level: High
CVE: CVE-1999-0502 Update Details
Recommendation is updated.
10061 - Atrium Mercur Messaging IMAP Service Remote Buffer Overflow Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2006-1255 Update Details
Recommendation is updated.
10088 - GuildFTPd LIST and CWD Commands Heap Overflow Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2008-4572 Update Details
Recommendation is updated.
10129 - Open&Compact FTP Server Authentication Bypass Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2010-2620 Update Details
Recommendation is updated.
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
Update Details
Recommendation is updated.
10610 - Microsoft Internet Explorer 'window.onerror' Information Disclosure
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
10672 - GIGABYTE Dldrv2 ActiveX Control Multiple Vulnerabilities
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2010-1517, CVE-2010-1518 Update Details
Recommendation is updated.
10694 - WordPress Plugin fGallery SQL Injection Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2008-0491 Update Details
Recommendation is updated.
11008 - Microsoft Windows Ipv6 Router Advertisement Denial Of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2010-4669 Update Details
Recommendation is updated.
11610 - WordPress Rating-Widget Plugin Multiple Cross-Site Scripting Vulnerabilities
Risk Level: High Update Details
Recommendation is updated.
11873 - Microsoft HTML Help Stack Overflow Remote Code Execution
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
11890 - Microsoft Reader Integer Overflow
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
11898 - Microsoft Reader Heap Overflow Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
11902 - Microsoft Reader NULL Byte Write Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12012 - WordPress SocialGrid Plugin "default_services" Cross-Site Scripting Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Recommendation is updated.
12097 - Quest Software Big Brother Arbitrary File Deletion Remote Code Execution
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
12135 - WordPress Magazeen Theme Multiple Vulnerabilities
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
12188 - HP 3COM/H3C Intelligent Management Center Img Recv Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2011-2331 Update Details
Recommendation is updated.
12577 - HP SiteScope Default Credentials Weaknesses
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
12703 - Microsoft Windows wab32res.dll Insecure Library Loading Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2010-3143 Update Details
12708 - Sunway ForceControl YRWXls.ocx ActiveX Control Buffer Overflow Vulnerability
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
12709 - Sunway ForceControl SCADA SNMP NetDBServer Integer Signedness Buffer Overflow Remote Code Execution
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
12798 - Sunway ForceControl SNMP NetDBServer Stack Buffer Overflow Remote Code Execution
Category: General Vulnerability Assessment -> Intrusive -> SCADA Risk Level: High
Update Details
Recommendation is updated.
12821 - OPC Systems.NET OPCSystemsService Denial Of Service Vulnerability
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
12842 - Snort Report target Multiple Remote Command Execution Vulnerabilities
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
12852 - A-Blog Sources Search.php SQL Injection Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2010-4917 Update Details
Recommendation is updated.
12875 - Oracle AutoVue AutoVueX ActiveX Control Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12876 - Oracle AutoVue AutoVueX ActiveX Control ExportEdaBom Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12877 - Oracle AutoVue AutoVueX ActiveX Control Export3DBom Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12887 - IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
12897 - Microsoft Excel VBScript Validation Use After Free Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12924 - Oracle DataDirect Multiple Native Wire Protocol ODBC Driver Buffer Overflow Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12929 - HP Data Protector Media Operations Directory Traversal Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12930 - HP Data Protector Media Operations Heap Buffer Overflow Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
12951 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution II
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High
CVE: CVE-2008-7303 Update Details
Recommendation is updated.
12952 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High
CVE: CVE-2011-1516 Update Details
12962 - Microsoft Excel Window2 Record Use After Free Remote Code Execution
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13053 - Adobe Flash Player VulnDisco Step Ahead Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2011-4693, CVE-2011-4694 Update Details
Recommendation is updated.
13091 - Ipswitch WS TFTP Server Directory Traversal Information Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
Update Details
Recommendation is updated.
13144 - Microsoft Windows Media Player Null Pointer Remote Denial Of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13182 - CoCSoft Stream Down Response Buffer Overflow Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2011-5052 Update Details
13370 - Novell GroupWise Messenger nmma.exe Login Memory Corruption Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13371 - Novell GroupWise Messenger nmma.exe Arbitrary Memory Corruption Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13383 - Beckhoff TwinCAT TCatScopeView SVW And SCP File Processing Remote Code Execution
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
13423 - IBM Tivoli Provisioning Manager Express ActiveX Control Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2012-0198 Update Details
Recommendation is updated.
13424 - IBM Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2012-0199 Update Details
13435 - Apple Safari Plug-in Unloading Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2011-3845 Update Details
Recommendation is updated.
13579 - Microsoft Visual Studio Incremental Linker Integer Overflow Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13733 - Tftpd32 DNS Server Denial Of Service Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13735 - Microsoft Wordpad Doc File Null Pointer Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13749 - Apple iOS Safari match() Buffer Denial of Service
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13791 - Microsoft IIS 6.0 PHP Authentication Bypass Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13792 - Microsoft IIS 7.5 .NET Authentication Bypass Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
13831 - PHP com_print_typeinfo Function Buffer Overflow Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2012-2376 Update Details
Recommendation is updated.
13986 - Apple iOS Safari match() Buffer Denial of Service
Category: Wireless Assessment -> NonIntrusive -> iOS Risk Level: High
Update Details
Recommendation is updated.
14076 - Windows Explorer BMP File Handling Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2007-1946 Update Details
Recommendation is updated.
14084 - Microsoft Index Service Ixsso.dll Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14085 - KASKAD SCADA DAServer.exe Remote Code Execution
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
14095 - Oracle Business Transaction Management Server FlashTunnelService Denial of Service
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
14125 - HP Intelligent Management Center uam.exe Stack Buffer Overflow
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous Risk Level: High
CVE: CVE-2012-3274 Update Details
Recommendation is updated.
14154 - EMC AutoStart Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Update Details
Recommendation is updated.
14158 - EMC AlphaStor Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
Update Details
Recommendation is updated.
14181 - Oracle Business Transaction Management SOAP Web Service Directory Traversal Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
14250 - QNX FTPD Denial of Service
Category: General Vulnerability Assessment -> NonIntrusive -> SCADA Risk Level: High
Update Details
Recommendation is updated.
14260 - CYME Power Engineering ChartFX Client Server ActiveX Control Array Indexing Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14294 - Microsoft Office Picture Manager Memory Corruption Remote Code Execution
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
14324 - RealNetworks RealPlayer 3GP File Handling Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14352 - Microsoft Office Excel WriteAV Remote Code Execution
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14452 - Sunsolve sscd_suncourier.pl Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2002-0436 Update Details
Recommendation is updated.
14455 - WordPress AdWizz Plugin "link" Cross-Site Scripting Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
14515 - VideoLAN VLC Media Player SWF File Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14527 - Adobe Flash Player FLV File Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14539 - Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2012-6270, CVE-2012-6271 Update Details
Recommendation is updated.
14540 - Microsoft Internet Explorer Remote Stack Overflow Vulnerability
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14789 - Oracle Java SE Reflection API Remote Code Execution I
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14790 - Oracle Java SE Reflection API Remote Code Execution II
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14806 - HMS Netbiter Config Utility Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
14865 - Kaspersky Internet Security Kaspersky Anti-Virus NDIS 6 Filter Denial of Service Vulnerability
Category: Windows Host Assessment -> Anti-Virus Software (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
14922 - PostgreSQL Command-Line Switch Error Messages Data Directory Denial of Service
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
CVE: CVE-2013-1899 Update Details
Recommendation is updated.
15010 - Schneider Electric Vijeo Web Gate Server Denial Of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
15105 - MOXA Mass Configuration Tool Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
15303 - MOXA AWK Search Utility Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Recommendation is updated.
15423 - DotNetNuke DNNArticle Module "categoryid" SQL Injection Vulnerability
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: High
CVE: CVE-2013-5117 Update Details
Recommendation is updated.
15542 - (MS13-067) Microsoft SharePoint MAC Disabled Remote Code Execution (2834052)
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2013-1330 DISA IAVA: 2013-A-0174 Microsoft ID: MS13-067 Microsoft KB: 2834052 Update Details
Recommendation is updated.
15780 - EATON VURemote Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
15782 - Moore Industries NCS Configuration Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
15794 - McAfee Web Reporter Tomcat EJBInvokerServlet Marshalled Object Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
CVE: CVE-2012-0874 Update Details
Recommendation is updated.
15845 - NETGEAR WNDR3700v4 ping6 Diagnostic Page Command Injection Vulnerability
Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High
Update Details
Recommendation is updated.
15905 - FirebirdSQL Firebird Null Pointer Denial of Service I
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
15960 - Symantec Workspace Streaming EJBInvokerServlet / JMXInvokerServlet Marshalled Object Vulnerability
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High Update Details
Recommendation is updated.
15975 - Microsoft Word Embedded Image Fork Bomb Denial of Service
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2013-6801 Update Details
Recommendation is updated.
16164 - McAfee Email Gateway Multiple SQL Injection and Remote Command Execution Vulnerabilities
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
16205 - HP 2620 Switches /html/json.html Admin Account Manipulation Cross-Site Request Forgery
Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: High
CVE: CVE-2013-6852 Update Details
Recommendation is updated.
16258 - Eaton Network Shutdown Module Pi3Web WebServer Denial of Service
Category: General Vulnerability Assessment -> NonIntrusive -> SCADA Risk Level: High
Update Details
Recommendation is updated.
16262 - Inductive Automation Ignition Gateway OPC-UA Server Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
16426 - Linksys Multiple E-Series Routers Security Bypass Vulnerability
Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: High
CVE: CVE-2013-5122 Update Details
Recommendation is updated.
16445 - Delta Electronics WPLSoft DVPSimulator.exe Buffer Overflow Remote Code Execution
Category: General Vulnerability Assessment -> Intrusive -> SCADA Risk Level: High
Update Details
16463 - Adobe Reader Multiple Remote Code Execution Vulnerabilities
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2014-0511, CVE-2014-0512 DISA IAVA: 2014-A-0070
Update Details
Recommendation is updated.
16558 - Microsoft Windows Unspecified Flaw Kernel Local Privilege Escalation
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2014-1766 Update Details
Recommendation is updated.
16559 - Microsoft Internet Explorer Multiple Sandbox Bypass and Use-After-Free Vulnerabilities
Category: Windows Host Assessment -> Patches and Hotfixes (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High
CVE: CVE-2014-1762, CVE-2014-1763, CVE-2014-1764, CVE-2014-1765 Update Details
Recommendation is updated.
16584 - McAfee Email And Web Security Appliance Multiple Unspecified Vulnerabilities
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High
Update Details
Recommendation is updated.
16620 - Paessler PRTG Network Monitor Server.exe Denial of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
16628 - FrameFlow Server Monitor Unspecified Defect Denial Of Service
Category: Windows Host Assessment -> SCADA (CATEGORY REQUIRES CREDENTIALS) Risk Level: High
Update Details
Recommendation is updated.
16632 - VideoLAN VLC Media Player libpng_plugin.dll Denial of Service
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2014-3441 Update Details
Recommendation is updated.
16641 - Nullsoft Winamp Malformed .FLV File Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2014-3442 Update Details
Recommendation is updated.
16648 - RealNetworks RealPlayer GetGUID Function Remote Code Execution
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: High CVE: CVE-2014-3444 Update Details
Recommendation is updated.
16651 - IceWarp Mail Server Preauth Buffer Overflow Remote Code Execution
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: High
Update Details
38132 - Apple QuickTime Crafted MOV File Code Execution
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High
CVE: CVE-2008-2010 Update Details
Recommendation is updated.
38159 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High
CVE: CVE-2008-4116 Update Details
Recommendation is updated.
38208 - Apple Mac OS X AppleTalk 'zip-notify' Buffer Overflow Vulnerability
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes Risk Level: High
CVE: CVE-2009-1236 Update Details
Recommendation is updated.
87313 - Fedora Linux 16 FEDORA-2013-1130 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High
CVE: CVE-2013-1348, CVE-2013-1397 Update Details
Risk is updated.
87368 - Fedora Linux 18 FEDORA-2013-1167 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High
CVE: CVE-2013-1397 Update Details Risk is updated.
87383 - Fedora Linux 17 FEDORA-2013-0985 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High
CVE: CVE-2013-1397 Update Details Risk is updated.
187491 - Fedora Linux 19 FEDORA-2013-23720 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High
CVE: CVE-2013-2298 Update Details Risk is updated.
187493 - Fedora Linux 20 FEDORA-2013-23734 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes Risk Level: High
CVE: CVE-2013-2298 Update Details Risk is updated.
642 - Microsoft IIS ExAir Denial-of-Service
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
CVE: CVE-1999-0449 Update Details
Recommendation is updated.
762 - PowerFTP Personal FTP Server Directory Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium
Check Version: 1.3 CVE: CVE-2002-1544 Update Details
763 - PowerFTP Personal FTP Server Tilde Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium
Check Version: 1.2 Update Details
Recommendation is updated.
826 - D-Link DWL-1000AP Wireless Access Point SNMP Public Community String Category: Wireless Assessment -> NonIntrusive -> Wireless
Risk Level: Medium Check Version: 1.2 CVE: CVE-2001-1221 Update Details
Recommendation is updated.
845 - Apache Win32 PHP.EXE Remote File Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
CVE: CVE-2002-2029 Update Details
Recommendation is updated.
859 - Compaq Survey Utility Anonymous Login
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
CVE: CVE-1999-0771 Update Details
Recommendation is updated.
872 - Lotus Domino Web Server statrep.nsf Anonymous Access Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2 Update Details
935 - FormMail.pl Detected
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.3 CVE: CVE-2001-0357 Update Details
Recommendation is updated.
937 - Apple Airport Base Station WEP Key Disclosure Category: Wireless Assessment -> NonIntrusive -> Wireless Risk Level: Medium
Check Version: 1.4598 Update Details
Recommendation is updated.
1014 - Microsoft ASP.NET Application Trace Enabled
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Update Details
Recommendation is updated.
1039 - Omnicron OmniHTTPd Long Request Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: Medium
CVE: CVE-2001-0613 Update Details
Recommendation is updated.
1041 - MyWebServer Buffer Overflow
Category: General Vulnerability Assessment -> Intrusive -> Web Server Risk Level: Medium
CVE: CVE-2002-1003 Update Details
1056 - Multiple Vendor Access Point Information Leakage Category: Wireless Assessment -> NonIntrusive -> Wireless
Risk Level: Medium Check Version: 1.2 Update Details
Recommendation is updated.
1212 - RedHat Linux Apache Remote Username Enumeration Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.941 CVE: CVE-2001-1013 Update Details
Recommendation is updated.
1408 - Novell NetWare Webservers Denial-of-Service
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.3 CVE: CVE-1999-0929 Update Details
Recommendation is updated.
1413 - Sun JavaServer Default Admin Password
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.3 Update Details
Recommendation is updated.
1956 - Intel Express 8100 Router Fragmented ICMP Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network
Risk Level: Medium Check Version: 1.3383 CVE: CVE-2000-0451 Update Details
1958 - Efficient Networks 5861 Router NMap Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium
Check Version: 1.4598 CVE: CVE-2003-1250 Update Details
Recommendation is updated.
1965 - Lucent Router UDP Information Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium
Check Version: 1.3383 CVE: CVE-2002-2148 Update Details
Recommendation is updated.
2367 - Sun Java App Server PE 8.0 Path Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Update Details
Recommendation is updated.
3012 - 3com 3CDaemon FTP Remote Format String
Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium
Check Version: 1.2 CVE: CVE-2005-0276 Update Details
Recommendation is updated.
3052 - Grokster FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.2 CVE: CVE-2003-0397
Update Details
Recommendation is updated.
3053 - IMesh FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.1 CVE: CVE-2003-0397 Update Details
Recommendation is updated.
3054 - Morpheus FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.2 CVE: CVE-2003-0397 Update Details
Recommendation is updated.
3055 - Kazaa FastTrack P2P Supernode Packet Handler Buffer Overrun Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.2 CVE: CVE-2003-0397 Update Details
Recommendation is updated.
3180 - RealPlayer RealMedia ".rm" Security Bypass Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.3193 Update Details
3372 - Abe Zimmerman xml.cgi Remote File Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium Check Version: 1.2 CVE: CVE-2001-1209 Update Details
Recommendation is updated.
3861 - Home FTP Information Disclosure Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: Medium Check Version: 1.935
CVE: CVE-2005-2726, CVE-2005-2727, CVE-2006-0355, CVE-2006-0356 Update Details
Recommendation is updated.
4173 - Visual Studio 6.0 Project Name Buffer Overflow Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.226 CVE: CVE-2006-1043 Update Details
Recommendation is updated.
4227 - AlienForm2 Directory Traversal Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Risk Level: Medium
Check Version: 1.328 CVE: CVE-2002-0934 Update Details
Recommendation is updated.
4295 - Way-BOARD CGI Information Disclosure
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2161 CVE: CVE-2001-0214 Update Details
Recommendation is updated.
4299 - BroadVision One-To-One Enterprise Information Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.338 CVE: CVE-2001-0031 Update Details
Recommendation is updated.
4307 - Armada Master Index search.cgi Directory Traversal Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2161 CVE: CVE-2000-0924 Update Details
Recommendation is updated.
4329 - WindMail Metacharacter Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2280 CVE: CVE-2000-0242 Update Details
Recommendation is updated.
4330 - Caldera OpenLinux rpm_query Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2161 CVE: CVE-2000-0192 Update Details
4335 - PowerScripts PlusMail CGI password file Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2167 CVE: CVE-2000-0074 Update Details
Recommendation is updated.
4345 - OmniHTTPD visadmin.exe Denial of Service
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.338 CVE: CVE-1999-0970 Update Details
Recommendation is updated.
4348 - Alibaba web server CGI Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Check Version: 1.2273 CVE: CVE-1999-0885 Update Details
Recommendation is updated.
4721 - Microsoft Internet Explorer Popup Address Bar Spoofing Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.1621 CVE: CVE-2006-5544 Update Details
Recommendation is updated.
4973 - Microsoft Internet Explorer HTML Tag Information Disclosure Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.2437 CVE: CVE-2007-3406 Update Details
Recommendation is updated.
4986 - Microsoft Windows Vista Local Privilege Escalation Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.2513 Update Details
Recommendation is updated.
5433 - Microsoft DXMedia SDK ActiveX Remote Code Execution Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.3926 CVE: CVE-2007-4336 Update Details
Recommendation is updated.
5457 - Microsoft Internet Saved Web Page Cross-Site Scripting Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4019 CVE: CVE-2007-4478 Update Details
Recommendation is updated.
5458 - Sony MicroVault USB Fingerprint Hidden Folder Vulnerability Category: Windows Host Assessment -> Trojans, Backdoors, Viruses, and Malware (CATEGORY REQUIRES CREDENTIALS)
Risk Level: Medium Check Version: 1.4063 CVE: CVE-2007-4785 Update Details
Recommendation is updated.
5488 - Microsoft Visual Studio PDWizard Remote Code Execution Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4153 CVE: CVE-2007-4891 Update Details
Recommendation is updated.
5511 - Microsoft Internet Explorer OnKeyDown Focus Information Disclosure Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4361 CVE: CVE-2007-5158 Update Details
Recommendation is updated.
5540 - Xunlei Web Thunder DPClient.Vod.1 ActiveX Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4469 CVE: CVE-2007-5064 Update Details
Recommendation is updated.
5563 - Mozilla Firefox Data URL Scheme Design Flaw Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4594 Update Details
Recommendation is updated.
Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: Medium Check Version: 1.4653 CVE: CVE-2007-5911 Update Details
Recommendation is updated.
5601 - Microsoft Windows Pseudo-Random Number Generator Design Flaw Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Check Version: 1.4818 CVE: CVE-2007-6043 Update Details
Recommendation is updated.
5888 - Mozilla Firefox JSFrame Vulnerability Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS)
Risk Level: Medium CVE: CVE-2008-2419 Update Details
Recommendation is updated.
6006 - Yahoo Messenger VBscript Remote Denial of Service Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Update Details
Recommendation is updated.
6242 - Microsoft Windows Vista TCP/IP Buffer Overflow Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2008-5229 Update Details
Recommendation is updated.
6558 - Mozilla Firefox XUL/XML Parser Corruption Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2009-1232 Update Details
Recommendation is updated.
6567 - Mozilla Firefox location.hash Denial-of-Service Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2008-5715 Update Details
Recommendation is updated.
6626 - Safari For Windows XML Tag Denial Of Service Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2009-1233 Update Details
Recommendation is updated.
6980 - Apache HTTPD suexec Multiple Local Privilege Escalation Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium
CVE: CVE-2007-1741, CVE-2007-1742, CVE-2007-1743 Update Details
Recommendation is updated.
6982 - Microsoft Internet Explorer findText Parsing Denial-of-Service Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Update Details
Recommendation is updated.
7129 - Microsoft Wordpad Memory Exhaustion Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Update Details
Recommendation is updated.
7139 - Microsoft Internet Explorer URL Spoofing Vulnerability Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2009-3003 Update Details
Recommendation is updated.
7750 - Oracle Reports Server Multiple Cross Site Scripting Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium CVE: CVE-2005-2379 Update Details
Recommendation is updated.
8095 - IBM Lotus Domino Server nserver.exe Crash Denial Of Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Risk Level: Medium
CVE: CVE-2009-3087 Update Details
Recommendation is updated.
8126 - Apache mod_perl File Descriptor Leakage Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: Medium
Recommendation is updated.
8129 - Apache HTTP Server mod_rewrite Security Bypass Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium CVE: CVE-2001-1072 Update Details
Recommendation is updated.
8205 - Sendmail Long IDENT Logging Circumvention Weakness Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX
Risk Level: Medium CVE: CVE-2002-2423 Update Details
Recommendation is updated.
8213 - Microsoft Virtual PC Hypervisor Memory Protection Security Bypass Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Update Details
Recommendation is updated.
8233 - Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium CVE: CVE-2002-1745 Update Details
Recommendation is updated.
8299 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1117) Category: Windows Host Assessment -> Patches and Hotfixes
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
CVE: CVE-2010-1117 Update Details
Recommendation is updated.
8380 - Microsoft IIS Sample Application Cross Site Scripting Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium Update Details
Recommendation is updated.
8499 - Sun Java System Directory Server LDAP Search Request Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous
Risk Level: Medium CVE: CVE-2010-0313 Update Details
Recommendation is updated.
8502 - Microsoft Office Communicator (Beta) SIP Denial Of Service Vulnerability Category: Windows Host Assessment -> Miscellaneous
(CATEGORY REQUIRES CREDENTIALS) Risk Level: Medium
Update Details
Recommendation is updated.
8634 - Sun Java System Web Server WebDAV LOCK Request File Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Web Server
Risk Level: Medium Update Details
Recommendation is updated.
8666 - Cisco IOS HTTP Server Cross Site Scripting Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network Risk Level: Medium
CVE: CVE-2009-0470 Update Details