Skip to content

WindowsTechs.com

Collaborate Disseminate

Menu

Primary menu

  • Home

Author Archives: CERT

VU#742632: Sage XRT Treasury database fails to properly restrict access to authorized users

Posted on February 28, 2017 by CERT

Sage XRT Treasury,version 3,fails to properly restrict database access to authorized users,which may enable any authenticated user to gain full access to privileged database functions. Continue reading VU#742632: Sage XRT Treasury database fails to properly restrict access to authorized users→

Posted in authorization bypass, sage, treasury

VU#742632: Sage XRT Treasury database fails to properly restrict access to authorized users

Posted on February 28, 2017 by CERT

Sage XRT Treasury,version 3,fails to properly restrict database access to authorized users,which may enable any authenticated user to gain full access to privileged database functions. Continue reading VU#742632: Sage XRT Treasury database fails to properly restrict access to authorized users→

Posted in authorization bypass, sage, treasury

VU#614751: Hughes satellite modems contain multiple vulnerabilities

Posted on February 15, 2017 by CERT

Several models of Hughes high-performance broadband satellite modems are potentially vulnerable to several issues if not appropriately configured. Continue reading VU#614751: Hughes satellite modems contain multiple vulnerabilities→

Posted in authentication, credentials, dos, hard-coded, validation

VU#745607: Accellion FTP server contains information exposure and cross-site scripting vulnerabilities

Posted on February 8, 2017 by CERT

The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting and information exposure. Continue reading VU#745607: Accellion FTP server contains information exposure and cross-site scripting vulnerabilities→

Posted in disclosure, xss

VU#867968: Microsoft Windows SMB Tree Connect Response denial of service vulnerability

Posted on February 2, 2017 by CERT

Microsoft Windows contains a memory corruption bug in the handling of SMB traffic,which may allow a remote,unauthenticated attacker to cause a denial of service on a vulnerable system. Continue reading VU#867968: Microsoft Windows SMB Tree Connect Response denial of service vulnerability→

Posted in mrxsmb20.sys, SMB

VU#167623: SHDesigns Resident Download Manager does not authenticate firmware downloads

Posted on January 31, 2017 by CERT

SHDesigns’ Resident Download Manager(as well as the Ethernet Download Manager)does not authenticate firmware downloads before executing code and deploying them to devices. Continue reading VU#167623: SHDesigns Resident Download Manager does not authenticate firmware downloads→

Posted in CWE-494, integrity, verification

VU#909240: Cisco WebEx web browser extension allows arbitrary code execution

Posted on January 27, 2017 by CERT

The Cisco WebEx extensions for Chrome,Firefox,and Internet Explorer allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable Windows system. Continue reading VU#909240: Cisco WebEx web browser extension allows arbitrary code execution→

Posted in ActiveTouch, GpcContainer, ieatgpc.dll, npatgpc.dll

VU#865216: CodeLathe FileCloud is vulnerable to cross-site request forgery

Posted on January 13, 2017 by CERT

CodeLathe FileCloud,version 13.0.0.32841 and earlier,is vulnerable to cross-site request forgery(CSRF). Continue reading VU#865216: CodeLathe FileCloud is vulnerable to cross-site request forgery→

Posted in codelathe, CSRF, filecloud

VU#767208: ThreatMetrix SDK for iOS fails to validate SSL certificates

Posted on January 10, 2017 by CERT

On the iOS platform,the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections,which may allow an attacker to perform a man-in-the-middle(MITM)attack. Continue reading VU#767208: ThreatMetrix SDK for iOS fails to validate SSL certificates→

Posted in iPad, iPhone, mitm, mitm proxy, SSL

VU#475907: ShoreTel Mobility Client mobile application does not verify SSL certificates

Posted on January 3, 2017 by CERT

ShoreTel Mobility Client for iOS and Android,version 9.1.3.109 and earlier,fails to properly validate SSL certificates provided by HTTPS connections,which may enable an attacker to conduct man-in-the-middle(MITM)attacks. Continue reading VU#475907: ShoreTel Mobility Client mobile application does not verify SSL certificates→

Posted in CWE-295, man-in-the-middle, mitm, SSL

Post navigation

← Older posts
Newer posts →

Primary Sidebar Widget Area

Infocon Status

Internet Storm Center Infocon Status

Recent Posts

  • MA: Springfield Public Schools will be closed Tuesday after a cyber incident September 7, 2026
  • Instead of Fighting AI, Some Teachers Work It Into Their Lessons September 7, 2026
  • A Vacuum Tube Computer For The Home September 7, 2026
  • PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution September 7, 2026
  • A Man Charged His EV at a Dealership – and Was Billed $418 September 7, 2026

Tag Cloud

Agriculture Alzheimer's Disease Art Audio Automation Bluetooth Building and Construction Campervan Camping Cancer Coronavirus (COVID-19) Cycling Dementia Diabetes DNA Electric Vehicles Food Home House Huawei Indiegogo MIT Mobility Moon New Atlas Audio NVIDIA Off-grid Off-road Pedal-assisted Photography Physics Radio Repair RV Samsung Satellite Sony SpaceX spoofing sustainable design The Immune System Tiny Footprint Training Water Zoom

Archives

  • Facebook
  • Twitter
  • Linkedin
  • Email
Copyright © 2026 WindowsTechs.com. All Rights Reserved.
Theme: Catch Box by Catch Themes
Scroll Up