Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.
Monthly Archives: June 2015
CVE-2015-4208 (webex_meeting_center)
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.
CVE-2015-4211 (anyconnect_secure_mobility_client)
Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.
CVE-2015-4212 (webex_meeting_center)
Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credentials, aka Bug ID CSCut17466.
CVE-2015-4214 (unified_meetingplace)
Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.
CVE-2015-4213 (nx-os)
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
CVE-2015-4215 (wireless_lan_controller_software)
Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of service (device crash) by triggering an exception during attempted forwarding of unspecified IPv6 packets to a non-IPv6 device, aka Bug ID CSCuj01046.
CVE-2015-4218 (jabber)
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
CVE-2015-4219 (identity_services_engine_software, secure_access_control_system)
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
Tablet AntiVirus Security FREE scoops award
We are happy to announce that AVG’s Tablet AntiVirus Security FREE has been voted as the best tablet security app in a Czech and Slovak app award.
The awards, organized by Czech company Tuesday Business Network, are designed to celebrate the very best of Czech and Slovak app development industry.
A shortlist of products was drawn up by public nominations and an expert panel selected the winners.
AVG Tablet AntiVirus Security FREE has many powerful protection and anti-theft features that can help you keep your device safe as well as protecting the data stored on it.
These include:
- App scanning
- Remote locating/locking/wiping if it gets lost or stolen.
- Task killer to help you improve the speed of your device
- Secure web browser to protect you from malicious links and phishing attacks
- Battery, storage and data package usage monitors
- And many more
Download AVG Tablet AntiVirus Security FREE from Google Play today.
![]()
![]()