A vulnerability exists in IKEv1 packet processing code in Cisco IOS, Cisco IOS XE and Cisco IOS XR Software. The vulnerability , known as Pix Pocket, is due to insufficient condition checks in the IKEv1 security negotiation requests. A successful could cause disclosure of confidential information.
Category Archives: Checkpoint
Checkpoint
OpenSSL OCSP Extension Unbounded Memory Denial of Service (CVE-2016-6304)
A denial-of-service vulnerability exists in OpenSSL. A remote, unauthenticated attacker can send an excessively large OCSP Status Request extension and create a denial of service condition.
Adobe Flash Player Memory Corruption (APSB16-29: CVE-2016-4282; CVE-2016-4282)
A memory corruption vulnerability has been reported in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Adobe Flash Player Memory Corruption (APSB16-29: CVE-2016-4283; CVE-2016-4283)
A memory corruption vulnerability has been reported in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Adobe Flash Player Memory Corruption (APSB16-29: CVE-2016-4285; CVE-2016-4285)
A memory corruption vulnerability has been reported in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Adobe Flash Player Memory Corruption (APSB16-29: CVE-2016-4274; CVE-2016-4274)
A memory corruption vulnerability has been reported in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Adobe Flash Player Type Confusion (APSB16-29: CVE-2016-4280; CVE-2016-4280)
A remote code execution vulnerability has been reported in Adobe Flash Player. The vulnerability is due to a type confusion condition while handling a malformed SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file. Successful exploitation would allow an attacker to execute arbitrary code on the target.
Suspicious Metadata Mail Phishing Containing Attachment
Mail attachment containing a malicious downloader was observed as part of ransomware campaigns. A remote attacker could send spam e-mails including those downloaders and convince users to manually enable them. This would allow the malicious code to run and infect the target system.
IBM WebSphere Application Server SIP Processing Denial of Service (CVE-2016-2960)
A denial-of-service vulnerability has been reported in IBM WebSphere Application Server. The vulnerability is due to improper validation of SIP messages. A remote, unauthenticated attacker can exploit this vulnerability by sending crafted SIP messages to the target server. Successful exploitation results in a denial-of-service condition.
Adobe Flash Player Memory Corruption (APSB16-29: CVE-2016-4284; CVE-2016-4284)
A memory corruption vulnerability exist in Adobe Flash Player. The vulnerability is caused by a crafted SWF file which causes an out of bounds memory access. A remote attacker can exploit this issue in order to trigger an access violation exception.