MCAFEE FOUNDSTONE FSL UPDATE 2014-JUN-03 To better protect your environment McAfee has created this FSL check update for the Foundstone Product Suite. The following is a detailed summary of the new and updated checks included with this release. NEW CHECKS 16673 - Microsoft Internet Explorer WeakMap Integer Divide-by-Zero Denial of Service Description A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service. Observation A vulnerability in some versions of Microsoft Internet Explorer could lead to a denial of service. The flaw is due to an unspecified defect. Successful exploitation by a remote attacker could result in a denial of service condition. 16661 - Intel Indeo Video ir41_32.ax Crafted File Denial of Service CVE: CVE-2014-3735 Description A vulnerability in some versions of Intel Indeo Video could lead to a denial of service. Observation A vulnerability in some versions of Intel Indeo Video could lead to a denial of service. The flaw lies in ir41_32.ax. Successful exploitation by a remote attacker could result in a denial of service condition. 16671 - Apache Tomcat Multiple Vulnerabilities Prior To 6.0.41 CVE: CVE-2014-0075, CVE-2014-0096, CVE-2014-0099, CVE-2014-0119 Description Multiple vulnerabilities are present in some versions of Apache Tomcat. Observation Apache Tomcat is a Java application server. Multiple vulnerabilities are present in some versions of Apache Tomcat. The flaws lie in multiple components. Successful
exploitation could allow an attacker to obtain sensitive information or cause denial of service. ENHANCED CHECKS The following checks have been updated. Enhancements may include optimizations, changes that reflect new information on a vulnerability and anything else that improves upon an existing FSL check. 761 - PowerFTP Personal FTP Server Path Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Check Version: 1.2 CVE: CVE-2001-0934 780 - WebSitePro win-c-sample.exe Path Disclosure Check Version: 1.2 CVE: CVE-1999-0178 852 - Oracle9iAS XSQLServlet XSQLConfig.xml disclosure Check Version: 1.2 CVE: CVE-2002-0568, CVE-2002-0569 DISA IAVA: 2002-T-0006,2002-T-0005 856 - Lotus Domino $defaultnav Information Disclosure Check Version: 1.2 CVE: CVE-2001-0847
875 - Microsoft IIS Anonymous Write Permissions Enabled 884 - Oracle WebDB Admin Backdoor Unauthorized Access Check Version: 1.2 908 - Microsoft IIS 4.0 /IISADMPWD/achg.htr Proxied Password Attack Check Version: 1.524 CVE: CVE-1999-0407 934 - csmailto.cgi Command Execution Check Version: 1.2 CVE: CVE-2002-0749 956 - Compaq Web-Based Management default page CVE: CVE-2001-0374
1224 - Sun Chili!Soft ASP Administration Console Default Password Check Version: 1.2 CVE: CVE-2001-0632 1248 - Oracle Web Listener Batch File Command Execution Check Version: 1.2 CVE: CVE-2000-0169 1876 - Perl logbook.pl Command Execution Check Version: 1.2 3048 - Morpheus FastTrack Service Identity Spoofing Vulnerability Check Version: 1.2 CVE: CVE-2002-0314, CVE-2002-0315 3290 - Linksys WAP55AG Wireless Access Point User Access Vulnerability Category: Wireless Assessment -> NonIntrusive -> Wireless Check Version: 1.3383
CVE: CVE-2004-0312 3382 - Campas CGI Script Information Leakage Vulnerability Check Version: 1.3 CVE: CVE-1999-0146 3386 - AdCycle Build.cgi Web Script Allows Unauthorized Access Check Version: 1.2 CVE: CVE-2000-1161 3393 - CCBill Arbitrary Code Execution Vulnerability Check Version: 1.1 3767 - Upload Lite Arbitrary File Upload and Execution Vulnerability Check Version: 1.2 3823 - Alt-N MDaemon Local Privilege Escalation
Check Version: 1.935 CVE: CVE-2004-2504 3884 - w3who.dll ISAPI Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Web Server Check Version: 1.1 CVE: CVE-2004-1133, CVE-2004-1134 4098 - Microsoft HTML Help Workshop Buffer Overflow vulnerability Check Version: 1.95 CVE: CVE-2006-0564 4207 - BLNews Path Parameter Vulnerability Check Version: 1.328 CVE: CVE-2003-0394 4285 - Nph-maillist Email Address Code Execution Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Check Version: 1.2284 CVE: CVE-2001-0400
4306 - Kootenay Web Whois Command Execution Check Version: 1.338 CVE: CVE-2000-0941 4319 - GAMSoft TelSrv Long Username Denial of Service Category: General Vulnerability Assessment -> Intrusive -> UNIX Check Version: 1.340 CVE: CVE-1999-0230, CVE-2000-0166, CVE-2000-0480, CVE-2000-0665, CVE-2001-0348 4339 - MSN ActiveX Setup BBS Buffer Overflow Check Version: 1.340 CVE: CVE-1999-1484 4723 - Microsoft Internet Explorer Window Injection Vulnerability Check Version: 1.1630 CVE: CVE-2004-1155
4754 - NetGear Wireless Driver Long Beacon Stack Overflow Check Version: 1.1756 CVE: CVE-2006-5972 4835 - Oracle Portal HTTP Response Splitting Check Version: 1.1952 CVE: CVE-2006-6697, CVE-2006-6699, CVE-2006-6703 4899 - Microsoft Visual Studio.CNT Buffer Overflow Check Version: 1.2129 CVE: CVE-2007-0352, CVE-2007-0427 4902 - Microsoft Help Workshop.CNT Files Buffer Overflow Check Version: 1.2128 CVE: CVE-2007-0352, CVE-2007-0427 4905 - Microsoft Visual Studio.HPJ Buffer Overflow
Check Version: 1.2816 CVE: CVE-2007-0352, CVE-2007-0427 4984 - FactoSystem Weblog Multiple SQL Injection Vulnerabilities Check Version: 1.2542 CVE: CVE-2002-1499 4997 - Microsoft Windows Explorer DOC File Crash Check Version: 1.2601 CVE: CVE-2007-1347 5064 - Microsoft Word wwlib.dll Heap Buffer Overflow Check Version: 1.2891 CVE: CVE-2007-1910 5065 - Microsoft Windows HLP File Handling Heap Buffer Overflow Check Version: 1.2927 CVE: CVE-2007-1912
5182 - Microsoft Internet Information Services Remote DoS Check Version: 1.3580 CVE: CVE-2007-2897 5218 - Microsoft Windows XP GDI+.ICO Handling DoS Vulnerability Check Version: 1.3441 CVE: CVE-2007-2237 5242 - Microsoft Office MSODataSourceControl ActiveX Control Vulnerability Check Version: 1.3444 CVE: CVE-2007-3282 5431 - Microsoft Internet Explorer FTP Access Information Disclosure Check Version: 1.3909 CVE: CVE-2007-4356
5469 - VMware vstor-ws60.sys Vulnerability Check Version: 1.4077 CVE: CVE-2007-4591, CVE-2007-4593 5492 - Microsoft Windows Media Player HTML Backdooring Vulnerability Check Version: 1.4196 CVE: CVE-2007-5095 5495 - Sun JRE isinstalled.dnsresolve Overflow Check Version: 1.4196 CVE: CVE-2007-5019 5526 - Symantec Veritas Backup Exec For Windows Servers Unspecified Vulnerability Check Version: 1.4374 CVE: CVE-2007-5126 5656 - RealNetworks RealPlayer Unspecified Buffer Overflow
CVE: CVE-2008-0098 5671 - Microsoft Visual InterDev.sln Vulnerability CVE: CVE-2008-0250, CVE-2008-1709 5836 - Microsoft Works WkImgSrv.dll ActiveX Vulnerability CVE: CVE-2008-1898 5844 - Apple QuickTime Crafted MOV File Code Execution CVE: CVE-2008-2010 5867 - Microsoft Internet Explorer Cross-Zone Scripting Vulnerability CVE: CVE-2008-2281
5899 - Creative Software AutoUpdate Engine ActiveX Control Stack Overflow CVE: CVE-2008-0955 6007 - Microsoft Internet Explorer Cookie Session Fixation CVE: CVE-2008-3173 6139 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability CVE: CVE-2008-4116 7256 - HP LoadRunner XUpload.ocx ActiveX Control Arbitrary File Download CVE: CVE-2009-3693 7278 - Oracle Document Capture BlackIce DEVMODE ActiveX Control Remote Command Execution
7638 - Oracle Document Capture EasyMail ActiveX Control Buffer Overflow Vulnerability CVE: CVE-2007-4607 7930 - Oracle Times-Ten In-Memory Database Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Web Server 8139 - PHP 4 Userland ZVAL Reference Counter Integer Overflow Vulnerability CVE: CVE-2007-1383 8198 - Microsoft IIS ASP.NET Cookie Header Information Disclosure Vulnerability 8300 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1118) CVE: CVE-2010-1118
8716 - XAMPP Insecure Default Password Disclosure Vulnerability CVE: CVE-2005-1078 8724 - Unix Finger Service User Account Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX CVE: CVE-1999-0198 8725 - Unix Finger User Account Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX CVE: CVE-1999-0197 8764 - Perforce Server Multiple Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2010-0929, CVE-2010-0930, CVE-2010-0931, CVE-2010-0932, CVE-2010-0933, CVE-2010-0934, CVE-2010-0935 8800 - Open Flash Chart PHP Library Arbitrary File Creation Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-2009-4140
8872 - Callisto PhotoParade Player PhPInfo ActiveX Control Buffer Overflow Vulnerability CVE: CVE-2007-1688 8919 - Macrovision InstallFromTheWeb Multiple Buffer Overflow Vulnerabilities CVE: CVE-2007-0320 8942 - Nginx HTTP Server File Path Parse Vulnerability 9155 - IBM Access Support ActiveX Control GetXMLValue Method Buffer Overflow Vulnerability CVE: CVE-2009-0215 9270 - Microsoft Visual FoxPro FPOLE.OCX ActiveX Control Remote Command Execution Vulnerability CVE: CVE-2007-5322
9340 - Microsoft SQL Server SQLExecutiveCmdExec Weak Password Encryption Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Windows CVE: CVE-1999-1556 9390 - IBM DB2 Shared Libraries Privilege Escalation Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2003-1052 9603 - Oracle Application Server Arbitrary File Access Vulnerability CVE: CVE-2001-0326 9635 - Oracle Application Server dbsnmp And nmo Programs Privilege Escalation Vulnerability CVE: CVE-2004-1707 9667 - Allied Telesyn TFTP Server Long Filename Remote Buffer Overflow Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2006-6184
9670 - Wind River Systems VxWorks WDB Target Agent Debug Service Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2010-2965 DISA IAVA: 2010-B-0075 9743 - FutureSoft TFTP Server 2000 Remote Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous 9805 - Microsoft Windows 'win32k!grestretchbltinternal()' Local Denial Of Service Vulnerability 9815 - SMTP Server Too Long Line Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous 9831 - TFTPUtil GUI Long Transport Mode Buffer Overflow Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2010-2028
9835 - ProSysInfo TFTP Server TFTPDWIN Long File Name Buffer Overflow Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2006-4948 9945 - glftpd Default Credentials Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> UNIX CVE: CVE-1999-0502 10061 - Atrium Mercur Messaging IMAP Service Remote Buffer Overflow Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2006-1255 10088 - GuildFTPd LIST and CWD Commands Heap Overflow Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2008-4572 10129 - Open&Compact FTP Server Authentication Bypass Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2010-2620 10145 - Open&Compact FTP Server Multiple Buffer Overflow Vulnerabilities
Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous 10610 - Microsoft Internet Explorer 'window.onerror' Information Disclosure 10672 - GIGABYTE Dldrv2 ActiveX Control Multiple Vulnerabilities CVE: CVE-2010-1517, CVE-2010-1518 10694 - WordPress Plugin fgallery SQL Injection Vulnerability CVE: CVE-2008-0491 11008 - Microsoft Windows Ipv6 Router Advertisement Denial Of Service CVE: CVE-2010-4669 11610 - WordPress Rating-Widget Plugin Multiple Cross-Site Scripting Vulnerabilities
11873 - Microsoft HTML Help Stack Overflow Remote Code Execution 11890 - Microsoft Reader Integer Overflow 11898 - Microsoft Reader Heap Overflow Denial of Service 11902 - Microsoft Reader NULL Byte Write Denial of Service 12012 - WordPress SocialGrid Plugin "default_services" Cross-Site Scripting Vulnerability
12097 - Quest Software Big Brother Arbitrary File Deletion Remote Code Execution Category: General Vulnerability Assessment -> Intrusive -> Web Server 12135 - WordPress Magazeen Theme Multiple Vulnerabilities 12188 - HP 3COM/H3C Intelligent Management Center Img Recv Remote Code Execution CVE: CVE-2011-2331 12577 - HP SiteScope Default Credentials Weaknesses Category: General Vulnerability Assessment -> Intrusive -> Web Server 12703 - Microsoft Windows wab32res.dll Insecure Library Loading Remote Code Execution CVE: CVE-2010-3143
12708 - Sunway ForceControl YRWXls.ocx ActiveX Control Buffer Overflow Vulnerability Category: Windows Host Assessment -> SCADA 12709 - Sunway ForceControl SCADA SNMP NetDBServer Integer Signedness Buffer Overflow Remote Code Execution Category: Windows Host Assessment -> SCADA 12798 - Sunway ForceControl SNMP NetDBServer Stack Buffer Overflow Remote Code Execution Category: General Vulnerability Assessment -> Intrusive -> SCADA 12821 - OPC Systems.NET OPCSystemsService Denial Of Service Vulnerability Category: Windows Host Assessment -> SCADA 12842 - Snort Report target Multiple Remote Command Execution Vulnerabilities Category: General Vulnerability Assessment -> Intrusive -> Web Server 12852 - A-Blog Sources Search.php SQL Injection Remote Code Execution
CVE: CVE-2010-4917 12875 - Oracle AutoVue AutoVueX ActiveX Control Remote Code Execution 12876 - Oracle AutoVue AutoVueX ActiveX Control ExportEdaBom Remote Code Execution 12877 - Oracle AutoVue AutoVueX ActiveX Control Export3DBom Remote Code Execution 12887 - IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities Category: Windows Host Assessment -> SCADA 12897 - Microsoft Excel VBScript Validation Use After Free Vulnerability
12924 - Oracle DataDirect Multiple Native Wire Protocol ODBC Driver Buffer Overflow Remote Code Execution 12929 - HP Data Protector Media Operations Directory Traversal Remote Code Execution 12930 - HP Data Protector Media Operations Heap Buffer Overflow Remote Code Execution 12951 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution II Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2008-7303 12952 - Apple OS X Sandbox Predefined Profiles Bypass Remote Code Execution Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2011-1516
12962 - Microsoft Excel Window2 Record Use After Free Remote Code Execution 13053 - Adobe Flash Player VulnDisco Step Ahead Remote Code Execution CVE: CVE-2011-4693, CVE-2011-4694 13091 - Ipswitch WS TFTP Server Directory Traversal Information Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous 13144 - Microsoft Windows Media Player Null Pointer Remote Denial Of Service 13182 - CoCSoft Stream Down Response Buffer Overflow Remote Code Execution CVE: CVE-2011-5052
13370 - Novell GroupWise Messenger nmma.exe Login Memory Corruption Remote Code Execution 13371 - Novell GroupWise Messenger nmma.exe Arbitrary Memory Corruption Remote Code Execution 13383 - Beckhoff TwinCAT TCatScopeView SVW And SCP File Processing Remote Code Execution Category: Windows Host Assessment -> SCADA 13423 - IBM Tivoli Provisioning Manager Express ActiveX Control Remote Code Execution CVE: CVE-2012-0198 13424 - IBM Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Remote Code Execution CVE: CVE-2012-0199
13435 - Apple Safari Plug-in Unloading Remote Code Execution CVE: CVE-2011-3845 13579 - Microsoft Visual Studio Incremental Linker Integer Overflow Remote Code Execution 13733 - Tftpd32 DNS Server Denial Of Service Vulnerability 13735 - Microsoft Wordpad Doc File Null Pointer Denial of Service 13749 - Apple ios Safari match() Buffer Denial of Service 13790 - Microsoft IIS 7.5 Classic ASP Authentication Bypass Remote Code Execution
13791 - Microsoft IIS 6.0 PHP Authentication Bypass Remote Code Execution 13792 - Microsoft IIS 7.5.NET Authentication Bypass Remote Code Execution 13831 - PHP com_print_typeinfo Function Buffer Overflow Remote Code Execution CVE: CVE-2012-2376 13986 - Apple ios Safari match() Buffer Denial of Service Category: Wireless Assessment -> NonIntrusive -> ios 14076 - Windows Explorer BMP File Handling Vulnerability
CVE: CVE-2007-1946 14084 - Microsoft Index Service Ixsso.dll Denial of Service 14085 - KASKAD SCADA DAServer.exe Remote Code Execution Category: Windows Host Assessment -> SCADA 14095 - Oracle Business Transaction Management Server FlashTunnelService Denial of Service 14125 - HP Intelligent Management Center uam.exe Stack Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2012-3274 14154 - EMC AutoStart Remote Code Execution
14158 - EMC AlphaStor Remote Code Execution Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous 14181 - Oracle Business Transaction Management SOAP Web Service Directory Traversal Vulnerability 14250 - QNX FTPD Denial of Service Category: General Vulnerability Assessment -> NonIntrusive -> SCADA 14260 - CYME Power Engineering ChartFX Client Server ActiveX Control Array Indexing Remote Code Execution 14294 - Microsoft Office Picture Manager Memory Corruption Remote Code Execution
14324 - RealNetworks RealPlayer 3GP File Handling Remote Code Execution 14352 - Microsoft Office Excel WriteAV Remote Code Execution 14452 - Sunsolve sscd_suncourier.pl Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2002-0436 14455 - WordPress AdWizz Plugin "link" Cross-Site Scripting Vulnerability 14515 - VideoLAN VLC Media Player SWF File Remote Code Execution 14527 - Adobe Flash Player FLV File Remote Code Execution
14539 - Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities CVE: CVE-2012-6270, CVE-2012-6271 14540 - Microsoft Internet Explorer Remote Stack Overflow Vulnerability 14789 - Oracle Java SE Reflection API Remote Code Execution I 14790 - Oracle Java SE Reflection API Remote Code Execution II 14806 - HMS Netbiter Config Utility Denial of Service Category: Windows Host Assessment -> SCADA
14865 - Kaspersky Internet Security Kaspersky Anti-Virus NDIS 6 Filter Denial of Service Vulnerability Category: Windows Host Assessment -> Anti-Virus Software 14922 - PostgreSQL Command-Line Switch Error Messages Data Directory Denial of Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2013-1899 15010 - Schneider Electric Vijeo Web Gate Server Denial Of Service Category: Windows Host Assessment -> SCADA 15105 - MOXA Mass Configuration Tool Denial of Service Category: Windows Host Assessment -> SCADA 15303 - MOXA AWK Search Utility Denial of Service Category: Windows Host Assessment -> SCADA
15423 - DotNetNuke DNNArticle Module "categoryid" SQL Injection Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-2013-5117 15542 - (MS13-067) Microsoft SharePoint MAC Disabled Remote Code Execution (2834052) CVE: CVE-2013-1330 DISA IAVA: 2013-A-0174 Microsoft ID: MS13-067 Microsoft KB: 2834052 15780 - EATON VURemote Denial of Service Category: Windows Host Assessment -> SCADA 15782 - Moore Industries NCS Configuration Denial of Service Category: Windows Host Assessment -> SCADA 15794 - McAfee Web Reporter Tomcat EJBInvokerServlet Marshalled Object Remote Code Execution
CVE: CVE-2012-0874 15845 - NETGEAR WNDR3700v4 ping6 Diagnostic Page Command Injection Vulnerability Category: Wireless Assessment -> NonIntrusive -> Wireless 15905 - FirebirdSQL Firebird Null Pointer Denial of Service I 15960 - Symantec Workspace Streaming EJBInvokerServlet / JMXInvokerServlet Marshalled Object Vulnerability 15975 - Microsoft Word Embedded Image Fork Bomb Denial of Service CVE: CVE-2013-6801 16164 - McAfee Email Gateway Multiple SQL Injection and Remote Command Execution Vulnerabilities CVE: CVE-2013-7092, CVE-2013-7103, CVE-2013-7104
16205 - HP 2620 Switches /html/json.html Admin Account Manipulation Cross-Site Request Forgery Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2013-6852 16258 - Eaton Network Shutdown Module Pi3Web WebServer Denial of Service Category: General Vulnerability Assessment -> NonIntrusive -> SCADA 16262 - Inductive Automation Ignition Gateway OPC-UA Server Denial of Service Category: Windows Host Assessment -> SCADA 16426 - Linksys Multiple E-Series Routers Security Bypass Vulnerability Category: Wireless Assessment -> NonIntrusive -> Wireless CVE: CVE-2013-5122 16445 - Delta Electronics WPLSoft DVPSimulator.exe Buffer Overflow Remote Code Execution Category: General Vulnerability Assessment -> Intrusive -> SCADA
16463 - Adobe Reader Multiple Remote Code Execution Vulnerabilities CVE: CVE-2014-0511, CVE-2014-0512 DISA IAVA: 2014-A-0070 16558 - Microsoft Windows Unspecified Flaw Kernel Local Privilege Escalation CVE: CVE-2014-1766 16559 - Microsoft Internet Explorer Multiple Sandbox Bypass and Use-After-Free Vulnerabilities CVE: CVE-2014-1762, CVE-2014-1763, CVE-2014-1764, CVE-2014-1765 16584 - McAfee Email And Web Security Appliance Multiple Unspecified Vulnerabilities 16620 - Paessler PRTG Network Monitor Server.exe Denial of Service Category: Windows Host Assessment -> SCADA
16628 - FrameFlow Server Monitor Unspecified Defect Denial Of Service Category: Windows Host Assessment -> SCADA 16632 - VideoLAN VLC Media Player libpng_plugin.dll Denial of Service CVE: CVE-2014-3441 16641 - Nullsoft Winamp Malformed.FLV File Remote Code Execution CVE: CVE-2014-3442 16648 - RealNetworks RealPlayer GetGUID Function Remote Code Execution CVE: CVE-2014-3444 16651 - IceWarp Mail Server Preauth Buffer Overflow Remote Code Execution Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous
38132 - Apple QuickTime Crafted MOV File Code Execution Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2008-2010 38159 - Apple Quicktime Stack_Cookie Stack Overflow Vulnerability Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2008-4116 38208 - Apple Mac OS X AppleTalk 'zip-notify' Buffer Overflow Vulnerability Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2009-1236 87313 - Fedora Linux 16 FEDORA-2013-1130 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2013-1348, CVE-2013-1397 Risk is updated. 87368 - Fedora Linux 18 FEDORA-2013-1167 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2013-1397 Risk is updated.
87383 - Fedora Linux 17 FEDORA-2013-0985 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2013-1397 Risk is updated. 187491 - Fedora Linux 19 FEDORA-2013-23720 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2013-2298 Risk is updated. 187493 - Fedora Linux 20 FEDORA-2013-23734 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2013-2298 Risk is updated. 642 - Microsoft IIS ExAir Denial-of-Service CVE: CVE-1999-0449 762 - PowerFTP Personal FTP Server Directory Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Check Version: 1.3 CVE: CVE-2002-1544
763 - PowerFTP Personal FTP Server Tilde Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Check Version: 1.2 826 - D-Link DWL-1000AP Wireless Access Point SNMP Public Community String Category: Wireless Assessment -> NonIntrusive -> Wireless Check Version: 1.2 CVE: CVE-2001-1221 845 - Apache Win32 PHP.EXE Remote File Disclosure CVE: CVE-2002-2029 859 - Compaq Survey Utility Anonymous Login CVE: CVE-1999-0771 872 - Lotus Domino Web Server statrep.nsf Anonymous Access Check Version: 1.2
935 - FormMail.pl Detected Check Version: 1.3 CVE: CVE-2001-0357 937 - Apple Airport Base Station WEP Key Disclosure Category: Wireless Assessment -> NonIntrusive -> Wireless Check Version: 1.4598 1014 - Microsoft ASP.NET Application Trace Enabled 1039 - Omnicron OmniHTTPd Long Request Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-2001-0613 1041 - MyWebServer Buffer Overflow Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-2002-1003
1056 - Multiple Vendor Access Point Information Leakage Category: Wireless Assessment -> NonIntrusive -> Wireless Check Version: 1.2 1212 - RedHat Linux Apache Remote Username Enumeration Check Version: 1.941 CVE: CVE-2001-1013 1408 - Novell NetWare Webservers Denial-of-Service Check Version: 1.3 CVE: CVE-1999-0929 1413 - Sun JavaServer Default Admin Password Check Version: 1.3 1956 - Intel Express 8100 Router Fragmented ICMP Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network Check Version: 1.3383 CVE: CVE-2000-0451
1958 - Efficient Networks 5861 Router NMap Denial-of-Service Category: General Vulnerability Assessment -> NonIntrusive -> Network Check Version: 1.4598 CVE: CVE-2003-1250 1965 - Lucent Router UDP Information Disclosure Category: General Vulnerability Assessment -> NonIntrusive -> Network Check Version: 1.3383 CVE: CVE-2002-2148 2367 - Sun Java App Server PE 8.0 Path Disclosure 3012-3com 3CDaemon FTP Remote Format String Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous Check Version: 1.2 CVE: CVE-2005-0276 3052 - Grokster FastTrack P2P Supernode Packet Handler Buffer Overrun Check Version: 1.2 CVE: CVE-2003-0397
3053 - IMesh FastTrack P2P Supernode Packet Handler Buffer Overrun Check Version: 1.1 CVE: CVE-2003-0397 3054 - Morpheus FastTrack P2P Supernode Packet Handler Buffer Overrun Check Version: 1.2 CVE: CVE-2003-0397 3055 - Kazaa FastTrack P2P Supernode Packet Handler Buffer Overrun Check Version: 1.2 CVE: CVE-2003-0397 3180 - RealPlayer RealMedia ".rm" Security Bypass Vulnerability Check Version: 1.3193
3372 - Abe Zimmerman xml.cgi Remote File Disclosure Vulnerability Check Version: 1.2 CVE: CVE-2001-1209 3861 - Home FTP Information Disclosure Check Version: 1.935 CVE: CVE-2005-2726, CVE-2005-2727, CVE-2006-0355, CVE-2006-0356 4173 - Visual Studio 6.0 Project Name Buffer Overflow Vulnerability Check Version: 1.226 CVE: CVE-2006-1043 4227 - AlienForm2 Directory Traversal Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX Check Version: 1.328 CVE: CVE-2002-0934 4295 - Way-BOARD CGI Information Disclosure
Check Version: 1.2161 CVE: CVE-2001-0214 4299 - BroadVision One-To-One Enterprise Information Disclosure Check Version: 1.338 CVE: CVE-2001-0031 4307 - Armada Master Index search.cgi Directory Traversal Check Version: 1.2161 CVE: CVE-2000-0924 4329 - WindMail Metacharacter Vulnerability Check Version: 1.2280 CVE: CVE-2000-0242 4330 - Caldera OpenLinux rpm_query Vulnerability Check Version: 1.2161 CVE: CVE-2000-0192
4335 - PowerScripts PlusMail CGI password file Vulnerability Check Version: 1.2167 CVE: CVE-2000-0074 4345 - OmniHTTPD visadmin.exe Denial of Service Check Version: 1.338 CVE: CVE-1999-0970 4348 - Alibaba web server CGI Vulnerability Check Version: 1.2273 CVE: CVE-1999-0885 4721 - Microsoft Internet Explorer Popup Address Bar Spoofing Vulnerability Check Version: 1.1621 CVE: CVE-2006-5544 4973 - Microsoft Internet Explorer HTML Tag Information Disclosure
Check Version: 1.2437 CVE: CVE-2007-3406 4986 - Microsoft Windows Vista Local Privilege Escalation Vulnerability Check Version: 1.2513 5433 - Microsoft DXMedia SDK ActiveX Remote Code Execution Check Version: 1.3926 CVE: CVE-2007-4336 5457 - Microsoft Internet Saved Web Page Cross-Site Scripting Check Version: 1.4019 CVE: CVE-2007-4478 5458 - Sony MicroVault USB Fingerprint Hidden Folder Vulnerability Category: Windows Host Assessment -> Trojans, Backdoors, Viruses, and Malware Check Version: 1.4063 CVE: CVE-2007-4785
5488 - Microsoft Visual Studio PDWizard Remote Code Execution Check Version: 1.4153 CVE: CVE-2007-4891 5511 - Microsoft Internet Explorer OnKeyDown Focus Information Disclosure Check Version: 1.4361 CVE: CVE-2007-5158 5540 - Xunlei Web Thunder DPClient.Vod.1 ActiveX Vulnerability Check Version: 1.4469 CVE: CVE-2007-5064 5563 - Mozilla Firefox Data URL Scheme Design Flaw Check Version: 1.4594 5579 - Viewpoint Media Player AxMetaStream ActiveX Stack Overflow
Check Version: 1.4653 CVE: CVE-2007-5911 5601 - Microsoft Windows Pseudo-Random Number Generator Design Flaw Check Version: 1.4818 CVE: CVE-2007-6043 5888 - Mozilla Firefox JSFrame Vulnerability CVE: CVE-2008-2419 6006 - Yahoo Messenger VBscript Remote Denial of Service 6242 - Microsoft Windows Vista TCP/IP Buffer Overflow Vulnerability CVE: CVE-2008-5229
6558 - Mozilla Firefox XUL/XML Parser Corruption Vulnerability CVE: CVE-2009-1232 6567 - Mozilla Firefox location.hash Denial-of-Service Vulnerability CVE: CVE-2008-5715 6626 - Safari For Windows XML Tag Denial Of Service Vulnerability CVE: CVE-2009-1233 6980 - Apache HTTPD suexec Multiple Local Privilege Escalation Vulnerabilities CVE: CVE-2007-1741, CVE-2007-1742, CVE-2007-1743 6982 - Microsoft Internet Explorer findtext Parsing Denial-of-Service Vulnerability CVE: CVE-2009-2655
7129 - Microsoft Wordpad Memory Exhaustion Vulnerability 7139 - Microsoft Internet Explorer URL Spoofing Vulnerability CVE: CVE-2009-3003 7750 - Oracle Reports Server Multiple Cross Site Scripting Vulnerabilities CVE: CVE-2005-2379 8095 - IBM Lotus Domino Server nserver.exe Crash Denial Of Service Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2009-3087 8126 - Apache mod_perl File Descriptor Leakage Vulnerability
8129 - Apache HTTP Server mod_rewrite Security Bypass Vulnerability CVE: CVE-2001-1072 8205 - Sendmail Long IDENT Logging Circumvention Weakness Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX CVE: CVE-2002-2423 8213 - Microsoft Virtual PC Hypervisor Memory Protection Security Bypass Vulnerability 8233 - Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability CVE: CVE-2002-1745 8299 - Microsoft Internet Explorer Unspecified Heap Overflow Vulnerability (CVE-2010-1117) CVE: CVE-2010-1117
8380 - Microsoft IIS Sample Application Cross Site Scripting Vulnerability 8499 - Sun Java System Directory Server LDAP Search Request Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2010-0313 8502 - Microsoft Office Communicator (Beta) SIP Denial Of Service Vulnerability 8634 - Sun Java System Web Server WebDAV LOCK Request File Disclosure 8666 - Cisco IOS HTTP Server Cross Site Scripting Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2009-0470
8671 - Cisco IOS HTTP Server Cross Site Request Forgery Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2009-0471 8688 - Microsoft Windows "SfnLOGONNOTIFY()" And "SfnINSTRING()" Denial Of Service Vulnerability 8691 - Internet Explorer XSS Filter Cross-Site Scripting Vulnerability CVE: CVE-2010-1489 8701 - ROBS-PROJECTS Digital Sales IPN Information Disclosure Vulnerability CVE: CVE-2009-0328 8726 - Nuked-Klan phpinfo Information Disclosure Vulnerability CVE: CVE-2003-1371
8757 - Perforce P4Web Client Two Vulnerabilities 8937 - Microsoft Internet Explorer UTF-7 Charset Inheritance Cross Site Scripting Vulnerability CVE: CVE-2007-1114 8945 - WeOnlyDo! SFTP ActiveX Control Remote Arbitrary File Access Vulnerability CVE: CVE-2006-1175 9048 - Microsoft Windows Remote Desktop Protocol mstlsapi.dll Private Key Spoofing Vulnerability CVE: CVE-2005-1794 9107 - IBM DB2 Universal Database Default Credentials Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2001-0051
9134 - Learn2 Corporation STRunner iestm32.dll ActiveX Control Multiple Buffer Overflow Vulnerabilities CVE: CVE-2007-6252 9153 - Apache HTTP Server mod_alias URL Validation Canonicalization CGI Script Source Code Disclosure Vulnerability CVE: CVE-2006-4110 9160 - Microsoft IIS Denial Of Service Vulnerability (CVE-1999-0229) Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-1999-0229 9212 - Oracle Application Server Portal Security Bypass Vulnerability CVE: CVE-2008-2138 9295 - Oracle Database Alter Session Set Events Code Execution Vulnerability CVE: CVE-2006-7067
9308 - Microsoft IIS HTR Files Password Policy Security Bypass Vulnerability CVE: CVE-2002-0421 DISA IAVA: 2003-T-0014,2003-A-0005(v2),2003-A-0005(v1),2003-A-0005,2002-A- 9331 - Microsoft SQL Server Login Weak Password Encryption Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Windows CVE: CVE-2002-1872 9332 - Microsoft ASP.NET Framework _VIEWSTATE Denial Of Service Vulnerability CVE: CVE-2005-1665 9336 - Microsoft ASP.NET VIEWSTATE Parameter Cross Site Scripting Vulnerability CVE: CVE-2010-2088 9338 - Mircosoft IIS ASP.NET NULL Character Cross Site Scripting Vulnerability CVE: CVE-2003-0768
9341 - Microsoft ASP.NET Framework _VIEWSTATE Insecure Crypto Validation Vulnerability CVE: CVE-2005-1664 9343 - Microsoft ASP.NET aspnet_wp.exe RPC Encoded Method Denial Of Service Vulnerability CVE: CVE-2005-2224 9346 - Microsoft ASP.NET Unicode Character Conversion Multiple Cross-Site Scripting Vulnerabilities CVE: CVE-2005-0452 9347 - Microsoft ASP.NET InnerHtml Property Cross Site Scripting Vulnerability CVE: CVE-2010-2084 9406 - IBM WebSphere Application Server JSP Root Password Disclosure Vulnerability CVE: CVE-2001-1189
9408 - IBM WebSphere Application Server HTTP Request Smuggling Vulnerability CVE: CVE-2005-2091 9485 - Microsoft DirectX DirectPlay Denial Of Service Vulnerabilities 9503 - Oracle Database Server CREATE ANY DIRECTORY Privilege Escalation Vulnerability CVE: CVE-2008-6065 9525 - Cisco IOS Virtual LAN 802.1q Frame Injection Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-1999-1129 9534 - Cisco IOS Large TCP Scan Denial Of Service Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2002-2052 9561 - Cisco IOS Regular Expression Engine Denial Of Service Vulnerability
Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2007-4430 9563 - Cisco IOS Firewall/IPS Functionality HTTP Unicode Encoding Detection Security Bypass Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2007-2688 9597 - Oracle Application Server query.xsql Sample Page SQL Injection Vulnerability CVE: CVE-2002-1631 9600 - Oracle Application Server Apache Configuration File Information Disclosure Vulnerability CVE: CVE-2002-1635 9608 - Oracle Application Server PL/SQL Module Format String Vulnerability CVE: CVE-2002-2153 9611 - Oracle Application Server TopLink Mapping Workbench Weak Password Encryption Vulnerability
CVE: CVE-2004-2134 9626 - Oracle Application Server DMS Cross Site Scripting Vulnerability CVE: CVE-2007-1609 9631 - Oracle Application Server Multiple Components Default Credentials Privilege Escalation Vulnerability CVE: CVE-2002-1637 9632 - Oracle Application Server HTTP Request Smuggling Vulnerability CVE: CVE-2005-2093 9669 - Unix Account Default Password Information Disclosure Vulnerability Category: General Vulnerability Assessment -> Intrusive -> UNIX CVE: CVE-1999-0502 9671 - Microsoft Internet Explorer Frame Border Property Denial Of Service Vulnerability
9810 - RealVNC ClientCutText Message Remote Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous 9824 - SolarWinds TFTP Server Option Acknowledgement Request Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2009-3115 9841 - Microsoft Windows Ipv4SetEchoRequestCreate Interruption Denial Of Service Vulnerability 9858 - SquirrelMail Multiple Remote Vulnerabilities 9859 - Network Associates WebShield SMTP GET_CONFIG Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2000-0448
9911 - Cisco IOS TACACS+ Body Length Buffer Overflow Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2000-0486 9922 - University Of Washington pop2d Remote File Read Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous 9948 - glftpd ZIP Plugins Multiple Directory Traversal Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> UNIX CVE: CVE-2005-0483 10031 - Xerver Administration Interface currentpath Directory Traversal Vulnerability CVE: CVE-2009-3561 10058 - Xerver Administration Interface portnr Denial Of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Web Server CVE: CVE-2009-4658
10401 - IBM DB2 Default User db2admin Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2001-0051 10403 - IBM DB2 Default User db2inst1 Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2001-0051 10404 - IBM DB2 Default User db2as Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2001-0051 10406 - IBM DB2 Default User db2fenc1 Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2001-0051 10489 - Microsoft ASP.NET Application Tracing trace.axd Information Disclosure Vulnerability
10515 - Nuked-Klan Cross Site Scripting Vulnerability CVE: CVE-2003-1238 10703 - WordPress Vodpod Video Gallery Plugin "gid" Cross Site Scripting Vulnerability CVE: CVE-2010-4875 10918 - Microsoft Remote Access Phonebook Insecure Executable Loading Vulnerability 10925 - WordPress Safe Search Plugin 'v1' Parameter Cross Site Scripting Vulnerability CVE: CVE-2010-4518 10973 - VMware Server Web Access Interface Directory Traversal Vulnerability 11139 - WordPress RSS Feed Reader For WordPress Plugin "rss url" Cross-Site Scripting Vulnerability
11229 - Microsoft FrontPage Server Extensions.pwd File Information Disclosure Vulnerability 11352 - WordPress Featured Content Plugin "param" Cross-Site Scripting Vulnerability 11368 - WordPress x7host's Videox7 UGC Plugin "listid" Cross-Site Scripting Vulnerability 11371 - OraMon oramon.ini Information Disclosure Vulnerability CVE: CVE-2008-6869 11376 - WordPress Conduit Banner Plugin "banner-index-field-id" Cross-Site Scripting Vulnerability
11397 - Xerver HTTP Response Splitting Vulnerability CVE: CVE-2009-4086 11407 - HP Power Manager Server Cross Site Request Forgery Vulnerability CVE: CVE-2011-0277 11415 - WordPress WP Featured Post With Thumbnail Plugin "src" Cross-Site Scripting Vulnerability 11464 - WordPress TagNinja Plugin 'id' Parameter Cross Site Scripting Vulnerability 11468 - WordPress YT-Audio Plugin "v" Parameter Cross Site Scripting Vulnerability 11536 - WordPress PHP Speedy Plugin "page" Parameter Local File Inclusion Vulnerability
11538 - Novell Netware SSH Remote Buffer Overflow Category: SSH Module -> NonIntrusive -> SSH Miscellaneous 11608 - Unix ypserv Domainname passwd.bynames Map Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> UNIX 11672 - RSA ClearTrust Login Page Cross Site Scripting Vulnerability 11722 - Citrix MetaFrame Client Specified Published Applications Enumeration Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous 11829 - WordPress Placester Plugin "ajax_action" Parameter Cross Site Scripting Vulnerability
11843 - HP LaserJet JetDirect Card Security Bypass Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Printers and Print Servers CVE: CVE-1999-1062 11871 - WordPress WP Forum Multiple SQL Injection Vulnerabilities 11913 - Microsoft Word 2003 MSO.dll Null Pointer Dereference Vulnerability CVE: CVE-2010-3200 11914 - Microsoft Windows Live Safety Scanner One Care Local Download And Execute Vulnerability 11999 - TCP/IP SYN-FIN Packet Filtering Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Raw Socket 12068 - WordPress WP-StarsRateBox Plugin Cross Site Scripting And SQL Injection Vulnerabilities
12110 - RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Remote Code Execution 12123 - IBM Lotus Domino ReadDesign Request Design Element Disclosure Vulnerability 12142 - Apache mod_info /server-info Information Disclosure Vulnerability 12319 - Microsoft Windows SMB Response Denial Of Service Vulnerability Category: Windows Host Assessment -> No Credentials Required CVE: CVE-2000-1227 12356 - Sybase Advantage Database Server Memory Corruption Vulnerability
12359 - Oracle Java Runtime Environment Insecure File Loading 12531 - Microsoft Internet Explorer 'Iedvtool.dll' Malformed HTML Denial Of Service Vulnerability 12532 - Microsoft Windows DHCPv6 Packets Remote Denial Of Service 12574 - WordPress WP CSS Plugin f Local File Inclusion Vulnerability 12608 - Microsoft Windows Server 2008 R1 Local Denial Of Service 12635 - WordPress Donation Plugin did Parameter SQL Injection Vulnerability
12669 - Carel Industries PlantVisor Enhanced Directory Traversal Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> SCADA CVE: CVE-2011-3487 12896 - Oracle Hyperion Financial Management TList6 ActiveX Control Remote Code Execution 12904 - NexusPHP thanks php SQL Injection Denial Of Service CVE: CVE-2011-4026 12935 - Oracle Hyperion Strategic Finance Client TTF16 ActiveX SetDevNames Remote Code Execution 12963 - Adobe ColdFusion Multiple Vulnerabilities
13008 - WordPress Bonus Theme s Parameter Cross Site Scripting Vulnerability 13009 - WordPress Simple Balance Theme s Parameter Cross Site Scripting Vulnerability 13106 - Microsoft Internet Explorer Cache Objects History Enumeration Weakness Information Disclosure CVE: CVE-2011-4689 13133 - Microsoft Windows NetBIOS NULL Name Denial Of Service Vulnerability Category: Windows Host Assessment -> No Credentials Required CVE: CVE-2000-0347 13235 - Rockwell Automation FactoryTalk Diagnostics Receiver Service Denial of Service Vulnerabilities Category: Windows Host Assessment -> SCADA
13368 - WordPress ucan Post Plugin Multiple Parameters Cross Site Scripting Vulnerability 13392 - Microsoft Internet Explorer ASLR/DEP Bypass Denial of Service CVE: CVE-2012-1545 13636 - Microsoft Windows Remote Desktop Protocol mstlsapi.dll Private Key Spoofing Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Windows CVE: CVE-2005-1794 13839 - Samsung AllShare HTTP Header Processing Denial of Service Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Web Server 13968 - Honeywell PowerNet Twin Client RFSync.exe Denial of Service 14179 - Trend Micro InterScan Messaging Security Suite Cross-Site Scripting and Request Forgery
Vulnerabilities CVE: CVE-2012-2995, CVE-2012-2996 14241 - Microsoft Office Excel ReadAV Remote Code Execution CVE: CVE-2012-5672 14323 - Microsoft Windows NTFS.SYS via USB Local Code Execution 14390 - RealNetworks RealPlayer Watch Folders Remote Code Execution CVE: CVE-2012-4987 14424 - VideoLAN VLC Media Player SHAddToRecentDocs() Function Denial of Service
14464 - Oracle Java SE OpenJDK Hash Table Denial of Service II CVE: CVE-2012-5373 14508 - Apache Tomcat Slowloris HTTP Denial of Service CVE: CVE-2012-5568 14582 - MODx Login User Enumeration Weakness 14655 - Microsoft Internet Explorer Proxy Settings TCP Sessions Information Disclosure CVE: CVE-2013-1450 14656 - Microsoft Internet Explorer Proxy Settings SSL Lock Icon Denial of Service CVE: CVE-2013-1451
14676 - Apple QuickTime Out of Bound Read Denial of Service 14971 - Cisco Linksys EA2700 Multiple Vulnerabilities Category: Wireless Assessment -> NonIntrusive -> Wireless 15134 - D-Link DIR-635 "data" Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities Category: Wireless Assessment -> NonIntrusive -> Wireless 15141 - Siemens Solid Edge ST5 ActiveX Controls Vulnerabilities Category: Windows Host Assessment -> SCADA 15205 - WordPress Content Slide Plugin Cross-Site Request Forgery Vulnerability CVE: CVE-2013-2708 15214 - WordPress Stream Video Player Plugin Cross-Site Request Forgery Vulnerability
CVE: CVE-2013-2706 15230 - Cisco Video Surveillance Operations Manager Help Page Redirection Vulnerability CVE: CVE-2013-3376 15237 - RealNetworks RealPlayer Crafted HTML File Denial of Service CVE: CVE-2013-3299 15290 - WordPress Dropdown Menu Widget Plugin Cross Site Request Forgery Vulnerability CVE: CVE-2013-2704 15296 - WordPress Sharebar Plugin Cross-Site Request Forgery Vulnerability CVE: CVE-2013-3491 15529 - WordPress Mingle Forum Plugin Cross-Site Request Forgery Vulnerability
CVE: CVE-2013-0736 15600 - TP-LINK TD-W8951ND Router Cross-Site Scripting and Request Forgery Vulnerabilities Category: Wireless Assessment -> NonIntrusive -> Wireless 15619 - Cisco Prime Network Control System (NCS) Health Monitor Login Page Cross-Site Scripting Vulnerability CVE: CVE-2012-5990 15758 - WordPress WP Ultimate Email Marketer Plugin Multiple Vulnerabilities CVE: CVE-2013-3263, CVE-2013-3264 15962 - Cisco Adaptive Security Appliance Software Phone Proxy Denial of Service Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2013-6682 15963 - Cisco Adaptive Security Appliance Software Auto-Update Denial of Service Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2013-5568
15994 - Wordpress dhtmlxspreadsheet Plugin Cross-Site Scripting Vulnerability CVE: CVE-2013-6281 16177 - Microsoft Windows Movie Maker wav File Handling Denial of Service Vulnerability CVE: CVE-2013-4858 16244 - (VMSA-2014-0001) VMware Workstation Invalid Ports Denial of Service Vulnerability CVE: CVE-2014-1208 DISA IAVA: 2014-B-0010,2014-B-0009,2014-B-0008,2014-A-0019 Observation is updated. 16270 - Cisco NX-OS Software Label Distribution Protocol Message Denial of Service Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-0677 16271 - Cisco NX-OS Software TACACS+ Command Authorization Local Security Bypass Category: SSH Module -> NonIntrusive -> SSH Miscellaneous
CVE: CVE-2014-0676 16351 - Multiple Routers RomPager Embedded Web Server ROM-0 Information Disclosure Vulnerability 16384 - Cisco Adaptive Security Appliance Phone Proxy CTL Security Bypass Vulnerability Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-0738 16386 - Cisco Adaptive Security Appliance Phone Proxy sec_db Race Condition Security Bypass Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-0739 16457 - Cisco Adaptive Security Appliance WebVPN Login Page Cross-Site Scripting Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-2120 16465 - Kaspersky Internet Security Regular Expression Patterns Processing Denial of Service Vulnerability Category: Windows Host Assessment -> Anti-Virus Software
16473 - Microsoft Windows Media Player Crafted WAV File Denial of Service CVE: CVE-2014-2671 16475 - McAfee Asset Manager downloadreport Directory Traversal Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-2588 16476 - McAfee Asset Manager ReportsAudit.jsp SQL Injection Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-2587 16499 - Microsoft Office XML Parser Nested Entity References Denial of Service CVE: CVE-2014-2730 16502 - McAfee Cloud Single Sign On Login Audit Form Cross-Site Scripting
CVE: CVE-2014-2586 16527 - BlackBerry Link OpenSSL TLS/DTLS Heartbeat Information Disclosure Vulnerabilities CVE: CVE-2014-0160 DISA IAVA: 2014-B-0041,2014-A-0063,2014-A-0053 16528 - BlackBerry Link OpenSSL TLS/DTLS Heartbeat Information Disclosure Vulnerabilities Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2014-0160 DISA IAVA: 2014-B-0041,2014-A-0063,2014-A-0053 38204 - Mozilla Firefox XUL/XML Parser Corruption Vulnerability Category: SSH Module -> NonIntrusive -> SSH Miscellaneous CVE: CVE-2009-1232 38209 - Apple Mac OS X XNU Kernel Memory Denial-of-Service Vulnerability Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2009-1237 38210 - Apple Mac OS X Local Kernel Memory Information Disclosure Vulnerability
Category: SSH Module -> NonIntrusive -> Mac OS X Patches and Hotfixes CVE: CVE-2009-1238 44005 - Microsoft Windows spoolss Remote Denial of Service Category: Windows Host Assessment -> No Credentials Required Check Version: 1.1818 CVE: CVE-2006-6296 87429 - Fedora Linux 18 FEDORA-2013-2090 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5391 Risk is updated. 87528 - Fedora Linux 17 FEDORA-2013-3227 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5391 Risk is updated. 87529 - Fedora Linux 18 FEDORA-2013-3265 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5391 Risk is updated. 87794 - Fedora Linux 19 FEDORA-2013-9918 Update Is Not Installed
Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5572 Risk is updated. 87827 - Fedora Linux 18 FEDORA-2013-9950 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5572 Risk is updated. 87834 - Fedora Linux 17 FEDORA-2013-9961 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5572 Risk is updated. 647 - Netscape Enterprise Server INDEX Directory Disclosure Check Version: 1.2 CVE: CVE-2001-0250 806 - ActiveState ActivePerl Path Disclosure 821 - Microsoft IIS 4.0 bdir.htr Directory Disclosure
Check Version: 1.1795 839 - Microsoft IIS htimage.exe Path Disclosure CVE: CVE-2000-0122 840 - Microsoft IIS / RPC Guest Username Disclosure CVE: CVE-2000-0114 851 - Oracle9iAS Web Server globals.jsa disclosure Check Version: 1.2 CVE: CVE-2002-0562 DISA IAVA: 2003-T-0004,2002-T-0006,2002-T-0005 860 - Netscape Enterprise Server Internal IP Address Disclosure Check Version: 1.2 873 - Novell GroupWise Web Root Disclosure
Check Version: 1.2 CVE: CVE-1999-1006, CVE-2002-0341 883 - Microsoft IIS Blank Host Auth Internal IP Disclosure Check Version: 1.648 CVE: CVE-2002-0422 DISA IAVA: 2003-T-0014,2003-A-0005(v2),2003-A-0005(v1),2003-A-0005,2002-A- 886 - SilverStream Application Server Database Structure Disclosure Check Version: 1.2 896 - SilverStream Application Server Directory Listing Disclosure Check Version: 1.2 897 - SilverStream Application Server Configuration Disclosure Check Version: 1.2
904 - AnalogX Simple Server Cross-Site Scripting 909 - (KB272079) Microsoft IIS 5.0 WebDAV Directory Disclosure CVE: CVE-2000-0951 Microsoft KB: KB272079 912 - WebStar ssi_demo.ssi Information Disclosure Check Version: 1.2 948 - Apache Tomcat 4.1 Path Disclosure Check Version: 1.3630 CVE: CVE-2001-0917 964 - Redhat Stronghold Secure Webserver Sample Script Path Disclosure Check Version: 1.2 CVE: CVE-2001-0868
968 - New Atlanta ServletExec 4.x ISAPI Physical Path Disclosure Check Version: 1.2 CVE: CVE-2002-0892 996-3Com AirConnect Wireless Access Point WEP Key Disclosure Category: Wireless Assessment -> NonIntrusive -> Wireless Check Version: 1.4598 CVE: CVE-2001-0352 1171 - test-cgi Program Detected Check Version: 1.4 CVE: CVE-1999-0070 1238 - SuSE Apache CGI Source Code Disclosure CVE: CVE-2000-0868 1357 - Novell Groupwise Web Access Directory Traversal Check Version: 1.3
1432 - SunONE Starter Kit v2.0 SearchDisk File Disclosure CVE: CVE-2002-1525 2449 - IBM Net.Data db2www Error Message Cross-Site Scripting CVE: CVE-2004-1442 4205 - LedNews Cross Site Scripting Check Version: 1.328 CVE: CVE-2003-0495 4208 - One or Zero Helpdesk SQL Injection Check Version: 1.734 CVE: CVE-2003-0303 4242 - MSN Messenger Service Message Spoof
Check Version: 1.340 CVE: CVE-2002-0472 4294 - Muscat Empower CGI Path Disclosure Check Version: 1.340 CVE: CVE-2001-0224 4314 - Stalkerlab Mailers File Disclosure Check Version: 1.2284 CVE: CVE-2000-0726 4347 - ichat ROOMS Webserver File Disclosure Check Version: 1.2161 CVE: CVE-1999-0897 4685 - Microsoft PowerPoint 2003 Zero-Day Vulnerability Check Version: 1.1521 CVE: CVE-2006-5296
4993 - Google Desktop Anti-DNS Pinning vulnerability Check Version: 1.2586 5000 - Perl anacondaclip.pl Directory Traversal Check Version: 1.2620 CVE: CVE-2001-0593 5007 - Microsoft Windows Sticky Keys Vulnerability Check Version: 1.2681 6033 - Kyocera 3830 Printer Unauthorized Access Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Miscellaneous CVE: CVE-2006-0788 6245 - Microsoft Windows LDAP Bind Request Information Disclosure Vulnerability Category: General Vulnerability Assessment -> Intrusive -> BruteForce CVE: CVE-2008-5112
6936 - Microsoft Internet Explorer AddFavorite Method DoS Vulnerability CVE: CVE-2009-2433 7752 - Apache Default Foreign Language File Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network 8083 - Apache HTTP Server OS Fingerprinting Vulnerability 9410 - Microsoft Internet Explorer CSS 'expression' Remote Denial of Service Vulnerability 9527 - Cisco Spoofed HSRP Loopback Denial Of Service Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2002-2053
9583 - Cisco IOS Online Help Information Disclosure Vulnerability Category: General Vulnerability Assessment -> NonIntrusive -> Network CVE: CVE-2000-0345 9588 - Yahoo! Toolbar Internet Explorer Security Bypass Vulnerability 9630 - Oracle Application Server Single Sign-On Login Page Spoofing Vulnerability CVE: CVE-2004-1877 9822 - Microsoft Windows Kerberos "Pass The Ticket" Replay Vulnerability 10030 - Xerver Administration Interface currentpath Cross Site Scripting Vulnerability CVE: CVE-2009-3562
10065 - Home FTP Server 'MKD' Command Multiple Directory Traversal Vulnerabilities Category: General Vulnerability Assessment -> NonIntrusive -> Miscellaneous CVE: CVE-2009-4053 10132 - ICMP Netmask Request Information Disclosure Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Raw Socket CVE: CVE-1999-0524 11865 - HP Web Jetadmin setinfo.hts Script Directory Traversal Vulnerability CVE: CVE-2004-1857 12006 - ICMP Timestamp Request Information Disclosure Vulnerability Category: General Vulnerability Assessment -> Intrusive -> Raw Socket CVE: CVE-1999-0524 12437 - Microsoft Windows CSRSS SrvGetConsoleTitle Type Casting Weakness Information Disclosure
12840 - Microsoft Windows Local DNS Poisoning Vulnerabilities 13043 - Microsoft Internet Explorer Cache Objects History Enumeration Weakness CVE: CVE-2002-2435 13143 - Microsoft Windows Explorer Local Denial Of Service Vulnerability 13595 - Microsoft Windows Kernel Win32k.sys Local Denial Of Service 14271 - Microsoft Internet Explorer XSS Filter Bypass 14354 - Microsoft Windows Phone 7 SSL Certificate 'Common Name' Validation Security Bypass Vulnerability
Category: Wireless Assessment -> NonIntrusive -> WinMobile CVE: CVE-2012-2993 87121 - Fedora Linux 18 FEDORA-2012-18977 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5560 Risk is updated. 87201 - Fedora Linux 17 FEDORA-2012-19726 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5560 Risk is updated. 87473 - Fedora Linux 17 FEDORA-2013-2766 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5560 Risk is updated. 87487 - Fedora Linux 18 FEDORA-2013-2784 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes CVE: CVE-2012-5560 Risk is updated. 87967 - Fedora Linux 19 FEDORA-2013-13258 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Fedora Patches and Hotfixes
CVE: CVE-2013-4143 Risk is updated. 177724 - Gentoo Linux GLSA-201309-03 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Gentoo Linux Patches and HotFixes CVE: CVE-2012-4524, CVE-2013-4143 Risk is updated. 7405 - Microsoft Internet Explorer 'DC:TITLE' PDF Information Disclosure Vulnerability Risk Level: Informational CVE: CVE-2009-4073 7735 - SSL Certificate Short Public Key Risk Level: Informational ADDITIONAL NOTES 1 - Recommendations for scripts without vendor-supplied patch or update were normalized. HOW TO UPDATE FS1000 APPLIANCE customers should follow the instructions for Enterprise/Professional customers, below. In addition, we strongly urge all appliance customers to authorize and install any Windows Update critical patches. The appliance will auto-download any critical updates but will wait for your explicit authorization before installing. FOUNDSTONE ENTERPRISE and PROFESSIONAL customers may obtain these new scripts using the FSUpdate Utility by selecting "FoundScan Update" on the help menu. Make sure that you have a valid FSUpdate username and password. The new vulnerability scripts will be automatically included in your scans if you have selected that option by right-clicking the selected vulnerability category and checking the "Run New Checks" checkbox.
MANAGED SERVICE CUSTOMERS already have the newest update applied to their environment. The new vulnerability scripts will be automatically included when your scans are next scheduled, provided the Run New Scripts option has been turned on. MCAFEE TECHNICAL SUPPORT ServicePortal: https://mysupport.mcafee.com/ Multi-National Phone Support available here: http://www.mcafee.com/us/about/contact/index.html Non-US customers - Select your country from the list of Worldwide Offices. This email may contain confidential and privileged material for the sole use of the intended recipient. Any review or distribution by others is strictly prohibited. If you are not the intended recipient please contact the sender and delete all copies. Copyright 2012 McAfee, Inc. McAfee is a registered trademark of McAfee, Inc. and/or its affiliates