Communication with SSL servers using weak, legacy “export-grade” cipher suites might be prone to attacks trying to intercept secure communications.
Category Archives: Checkpoint
Checkpoint
Samba smbd ServerPasswordSet RPC Memory Corruption (CVE-2015-0240)
This protection will detect and block attempts to exploit this vulnerability.
Adobe Acrobat and Reader Stack Buffer Overflow (APSB13-02; CVE-2013-0610)
A stack overflow vulnerability has been reported in Adobe Acrobat and Reader. The vulnerability is due to an error in Adobe Acrobat and Reader while parsing a specially crafted file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted file.
Web Clients Suspicious Image File Download
A remote attacker can hide a malicious code within an image file, in an attempt to avoid detection. Successful exploitation could result in the execution of arbitrary code in the security context of the web server.
WordPress Redirection Page Plugin Cross Site Request Forgery (CVE-2015-1580)
A cross-site request forgery (CSRF) vulnerability has been reported in WordPress Redirection Page Plugin. An attacker could exploit this vulnerability by convincing the user to follow a malicious link or visit an attacker controlled website.
WordPress Holding Pattern Theme Arbitrary File Upload (CVE-2015-1172)
An unauthorized file upload vulnerability has been reported in WordPress Holding Pattern Theme. A remote attacker could exploit this vulnerability by uploading a file to a server running the vulnerable application. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
WordPress Slimstat Plugin SQL Injection
An SQL injection vulnerability has been reported in WordPress Slimstat Plugin. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Adobe Flash Player Memory Corruption (APSB15-04; CVE-2015-0318)
A memory corruption vulnerability has been reported in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Microsoft Group Policy Remote Code Execution (MS15-011; CVE-2015-0008)
A remote code execution vulnerability exists in Microsoft Windows. The vulnerability is due to the way Group Policy receives and applies policy data when a domain-joined system connects to a domain controller. An attacker can exploit this vulnerability by convincing a victim with a domain-configured system to connect to an attacker-controlled network.
Adobe Flash Player Type Confusion Code Execution (APSB15-04; CVE-2015-0317)
A remote code execution vulnerability has been reported in Adobe Flash Player. The vulnerability is due to a type confusion condition while handling a malformed SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file. Successful exploitation would allow an attacker to execute arbitrary code on the target.