A cross-site-scripting vulnerability has been reported in the Symantec Endpoint Protection Manager. The vulnerability is due to insufficient input validation on user-supplied input. A remote attacker could exploit this vulnerability by enticing authenticated users to click on a crafted link. Successful exploitation could allow the attacker to execute malicious script code in the context of the victim’s browser.
Category Archives: Checkpoint
Checkpoint
Weak Password Login Attempt Over Telnet
Telnet is an internet protocol that provides access to remote computers using a virtual terminal. A remote attacker may use an open Telnet service to run arbitrary code on the victim machine.
Rockwell Automation MicroLogix Remote Code Execution (CVE-2016-5645)
A vulnerability exists in the SNMP functionality on Rockwell Automation PLC systems. A remote attacker can leverage the vulnerability to execute arbitrary code on the affected system.
Fortinet Cookie Overflow Remote Code Execution (EGREGIOUSBLUNDER)
An overflow vulnerability exists in authentication cookie on Fortinet firewalls. A remote attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Command Injection Over Telnet
Telnet is an internet protocol that provides access to remote computers using a virtual terminal. A remote attacker may use an open Telnet service to run arbitrary code on the victim machine.
Cisco ASA Disable Password Remote Code Execution (Extrabacon; CVE-2016-6366)
A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software has been reported. A remote attacker could exploit the vulnerability to remotely execute arbitrary code on the affected system.
Adobe Acrobat and Reader Security Bypass (APSB16-14 : CVE-2016-1040; CVE-2016-1040)
A remote code execution vulnerability exists in Adobe Acrobat and Reader. The vulnerability is due to the way Adobe Reader handles certain API functions, that could lead to bypass restrictions. A remote attacker can exploit this issue by enticing a target user to open a specially crafted PDF file.
Drupal CODER Module Remote Code Execution
A code execution vulnerability exists in Drupal CODER Module. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
WECON LeviStudio Stack Buffer Overflow
The vulnerability is due to improper parsing of XML HmiSet Type attribute of LeviStudio project files. A remote attacker could exploit this vulnerability by enticing a user to open a crafted project file. Successful exploitation could allow the attacker to execute arbitrary code under the security context of the user process.
Adobe Acrobat and Reader Use After Free (APSB16-26: CVE-2016-4206; CVE-2016-4206)
A memory corruption vulnerability exists in Adobe Acrobat and Reader. The vulnerability is due to an error while handling a specially crafted PDF file that leads to out-of-bounds memory access. A remote attacker can exploit this vulnerability by enticing a target user to open a specially crafted PDF file.