VU#304725: Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange

Bluetooth firmware or operating system software drivers may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange,which may allow a remote attacker to obtain the encryption key used by the device. Continue reading VU#304725: Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange

VU#631579: Hardware debug exception documentation may result in unexpected behavior

In some circumstances,some operating systems or hypervisors may not expect or properly handle an Intel architecture hardware debug exception. The error appears to be due to developer interpretation of existing documentation for certain Intel architecture interrupt/exception instructions,namely MOV SS and POP SS. Continue reading VU#631579: Hardware debug exception documentation may result in unexpected behavior

VU#283803: Integrated GPUs may allow side-channel and rowhammer attacks using WebGL ("Glitch")

Some platforms with integrated GPUs,such as smartphones,may allow both side-channel and rowhammer attacks via WebGL,which may allow a remote attacker to compromise the browser on an affected platform. An attack technique that leverages these vulnerabilities is called"GLitch." Continue reading VU#283803: Integrated GPUs may allow side-channel and rowhammer attacks using WebGL ("Glitch")

VU#974272: Microsoft Outlook retrieves remote OLE content without prompting

When a Rich Text(RTF)email is previewed in Microsoft Outlook,remotely-hosted OLE content is retrieved without requiring any additional user interaction. This can leak private information including the user’s password hash,which may be cracked by an attacker. Continue reading VU#974272: Microsoft Outlook retrieves remote OLE content without prompting

VU#277400: Windows 7 and Windows Server 2008 R2 x64 fail to protect kernel memory when the Microsoft update for meltdown is installed

When the Microsoft update for meltdown is installed on a Windows 7 x64 or Windows Server 2008 R2 x64 system,an unprivileged process may be able to read and write the entire memory space available to the Windows kernel. Continue reading VU#277400: Windows 7 and Windows Server 2008 R2 x64 fail to protect kernel memory when the Microsoft update for meltdown is installed