Entries for the ‘Security Advisory’ Category

March 2010: three new Cisco vulnerabilities

On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Manager Vulerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media [...]

February 2010: four new Cisco vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:

TCP Connection Exhaustion Denial of Service Vulnerability
Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities
Skinny Client Control Protocol (SCCP) [...]

3 new Cisco critical vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:

Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime

Multiple Cisco WebEx WRF Player Vulnerabilities

The The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory:  Multiple Cisco WebEx WRF Player Vulnerabilities.
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted [...]

Transport Layer Security Renegotiation Vulnerability

Security researchers Marsh Ray and Steve Dispensa unveiled the TLS (Transport Layer Security) flaw on Wednesday, following the disclosure of separate, but similar, security findings. TLS and its predecessor, SSL (Secure Sockets Layer), are typically used by online retailers and banks to provide security for web transactions. Ray explained in a blog post on Thursday [...]

Cisco Unified Presence Denial of Service Vulnerabilities

On Octobert 14, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: Cisco Unified Presence Denial of Service Vulnerabilities.
Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that may cause an interruption to presence services. These vulnerabilities were discovered internally by Cisco, and there are no workarounds.
Vulnerable [...]

Sep.23, 2009: 11 new Cisco critical vulnerabilities!!

On September 23, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 11 important vulnerability advisories.
Cisco Unified Communications Manager Express Vulnerability
Cisco IOS® devices that are configured for Cisco Unified Communications Manager Express (CME) and the Extension Mobility feature are vulnerable to a buffer overflow vulnerability. Successful exploitation of this vulnerability may result [...]

TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products

On September 8, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products.
Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of [...]

Aug.30, 2009: 3 new Cisco critical vulnerabilities

In the last 2 weeks, three new security advisory has been published by PSIRT: Cisco IOS XR Software Border Gateway Protocol Vulnerabilities, Cisco Unified Communications Manager Denial of Service Vulnerabilities and Firewall Services Module Crafted ICMP Message Vulnerability.
1) Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software contains multiple vulnerabilities in the Border [...]

Jul.29, 2009: 2 new Cisco critical vulnerabilities

On July 29, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories.
1) Active Template Library (ATL) Vulnerability
Certain Cisco products that use Microsoft Active Template Libraries (ATL) and headers may be vulnerable to remote code execution. In some instances, the vulnerability may be exploited against Microsoft Internet Explorer to [...]