Announcements

Drupal Core - Moderately Critical - Multiple Vulnerabilities

  • 20th March 2015
Advisory ID: DRUPAL-SA-CORE-2015-001 Project: Drupal core Version: 6.x, 7.x Date: 2015-March-18  Security risk: 14/25 (Moderately Critical) AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass, Open Redirect, Multiple vulnerabilities Description Access bypass (Password reset URLs - Drupal 6 and ...
Continue reading

Cumulative Security Update for Internet Explorer

  • 10th March 2015
The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less ...
Continue reading

Vulnerabilities in Adobe Font Driver Could Allow Remote Code Execution

  • 10th March 2015
The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted file or website. An attacker who successfully exploited the vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user ...
Continue reading

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution

  • 10th March 2015
The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less ...
Continue reading