ENISA EUVD · EUVD-2015-3264Official EUVD mapping0 linked advisory records.
Official EUVD record ↗Canadian Centre for Cyber Security · English · AV18-006SierraWireless ALEOS update 4.4.5 for AirLink devicesEnabled” is set to “Automatic”; and a user space monitor has been added to the flash memory file system.
Affected Products:
AirLink GX400, GX440, ES440, and LS300 running software prior to 4.4.5.
CVE References:
User input validation: CVE-2017-15043
OpenSSL: CVE-2016-0701, CVE-2017-3731, CVE-2016-2181, CVE-2016-0702, CVE-2017-3732, CVE-2016-2182, CVE-2016-0705, CVE-2016-2105, CVE-2016-2183, CVE-2016-0797, CVE-2016-2106, CVE-2016-6302, CVE-2016-0798, CVE-2016-2107, CVE-2016-6303, CVE-2016-0799, CVE-2016-2109, CVE-2016-6304, CVE-2016-0800, CVE-2016-2176, CVE-2016-6306, CVE-2016-2842, CVE-2016-2177, CVE-2015-3195, CVE-2015-1794, CVE-2016-2178, CVE-2015-3197, CVE-2015-3193, CVE-2016-2179, CVE-2015-3194, CVE-2016-2180
Dropbear: CVE-2017-9078 and CVE-2017-9079
Tcpdump and Libpcap: CVE-2014-8769 and CVE-2014-8767
Linux kernel: CVE-2017-14106, CVE-2014-7822, CVE-2014-9888, CVE-2015-3288
OpenVPN: CVE-2017-7520 and CVE-2017-7479
SNMP: CVE-2015-5621
Libcurl: CVE-2016-5421
Dnsmasq: CVE-2017-14496, CVE-2017-14491, CVE-2017-14492, CVE-2017-14493, CVE-2017-14494, CVE-2017-14495
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.
CCIRC recommends confirming if your remote access, mobile or off-site solutions include this
Official advisory ↗Canadian Centre for Cyber Security · English · AV17-105Oracle Critical Patch update Advisory – July 2017rise PRTL Interaction Hub, version 9.1.0
Primavera Gateway, versions 1.0, 1.1, 14.2, 15.1, 15.2, 16.1, 16.2
Primavera P6 Enterprise Project Portfolio Management, versions 8.3, 8.4, 15.1, 15.2, 16.1, 16.2
Primavera Unifier, versions 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1, 16.2
Siebel Applications, versions 16.0, 17.0
Solaris Cluster, version 4
Solaris, versions 10, 11
Sun ZFS Storage Appliance Kit (AK), version AK 2013
CVE References:
CVE-2013-2027, CVE-2014-0224, CVE-2014-1912, CVE-2014-3566, CVE-2014-3571, CVE-2015-0235, CVE-2015-0254, CVE-2015-0286, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-3195, CVE-2015-3197, CVE-2015-3253, CVE-2015-5254, CVE-2015-7501, CVE-2015-7940, CVE-2015-8607, CVE-2015-8608, CVE-2016-0635, CVE-2016-1181, CVE-2016-1950, CVE-2016-1979, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2381, CVE-2016-2834, CVE-2016-3092, CVE-2016-3506, CVE-2016-4430, CVE-2016-4431, CVE-2016-4433, CVE-2016-4436, CVE-2016-4438, CVE-2016-4465, CVE-2016-5019, CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV16-037Cisco Multiple Security AdvisoriesCisco released multiple security updates to address critical vulnerabilities in the following software/hardware:
Critical
Insecure Default Credential Vulnerability in Cisco Nexus 3000 Series and 3500 Platform Switches.
High
Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability.
Cisco NX-OS Software SNMP Packet Denial of Service Vulnerability.
Cisco NX-OS Software TCP Netstack Denial of Service Vulnerability.
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products.
Medium
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016.
Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability.
Cisco FireSIGHT System Software Device Management UI Cross-Site Scripting Vulnerability.
Cisco FireSIGHT System Software Convert Timing Channel Vulnerability.
CVE-2016-1288, CVE-2015-6260, CVE-2016-1329, CVE-2015-0718, CVE-2015-3197, CVE-2015-7973, CVE-2016-1354, CVE-2016-1355, CVE-2016-1356.
Official advisory ↗Canadian Centre for Cyber Security · English · AV16-036OpenSSL Advisory – Multiple VulnerabilitiesCCIRC is aware of eight recently disclosed vulnerabilities in OpenSSL, two of which are rated as high.
Affected versions: OpenSSL 0.9.8, 1.0.0, 1.0.1, 1.0.2
CVE References: CVE-2015-0293, CVE-2015-3197, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0800
Official advisory ↗Canadian Centre for Cyber Security · English · AV16-017OpenSSL Advisory – Multiple VulnerabilitiesCCIRC is aware of five disclosed vulnerabilities in OpenSSL.
Affected versions: OpenSSL 1.0.2f and prior
CVE References: CVE-2016-0701, CVE-2015-3197
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-1094Multiples vulnérabilités dans les produits Siemens.cve.org/CVERecord?id=CVE-2015-1789
Référence CVE CVE-2015-1790
https://www.cve.org/CVERecord?id=CVE-2015-1790
Référence CVE CVE-2015-1791
https://www.cve.org/CVERecord?id=CVE-2015-1791
Référence CVE CVE-2015-1792
https://www.cve.org/CVERecord?id=CVE-2015-1792
Référence CVE CVE-2015-1794
https://www.cve.org/CVERecord?id=CVE-2015-1794
Référence CVE CVE-2015-3193
https://www.cve.org/CVERecord?id=CVE-2015-3193
Référence CVE CVE-2015-3194
https://www.cve.org/CVERecord?id=CVE-2015-3194
Référence CVE CVE-2015-3195
https://www.cve.org/CVERecord?id=CVE-2015-3195
Référence CVE CVE-2015-3196
https://www.cve.org/CVERecord?id=CVE-2015-3196
Référence CVE CVE-2015-3197
https://www.cve.org/CVERecord?id=CVE-2015-3197
Référence CVE CVE-2015-4000
https://www.cve.org/CVERecord?id=CVE-2015-4000
Référence CVE CVE-2015-5352
https://www.cve.org/CVERecord?id=CVE-2015-5352
Référence CVE CVE-2015-5600
https://www.cve.org/CVERecord?id=CVE-2015-5600
Référence CVE CVE-2015-6563
https://www.cve.org/CVERecord?id=CVE-2015-6563
Référence CVE CVE-2015-6564
https://www.cve.org/CVERecord?id=CVE-2015-6564
Référence CVE CVE-2015-6565
https://www.cve.org/CVERecord?id=CVE-2015-6565
Référence CVE CVE-2015-6574
https://www.cve.org/CVERecord?id=CVE-2015-6574
Référence CVE CVE-2015-8325
https://www.cve.org/CVERecord?id=CVE-2015-8325
Ré
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-244Multiples vulnérabilités dans Oracle Sun Systems Products Suite721 du 19 juillet 2016
http://www.oracle.com/technetwork/security-advisory/cpujul2016verbose-2881721.html#SUNS
Référence CVE CVE-2012-3410
https://www.cve.org/CVERecord?id=CVE-2012-3410
Référence CVE CVE-2013-2566
https://www.cve.org/CVERecord?id=CVE-2013-2566
Référence CVE CVE-2014-3566
https://www.cve.org/CVERecord?id=CVE-2014-3566
Référence CVE CVE-2015-0235
https://www.cve.org/CVERecord?id=CVE-2015-0235
Référence CVE CVE-2015-1793
https://www.cve.org/CVERecord?id=CVE-2015-1793
Référence CVE CVE-2015-2808
https://www.cve.org/CVERecord?id=CVE-2015-2808
Référence CVE CVE-2015-3183
https://www.cve.org/CVERecord?id=CVE-2015-3183
Référence CVE CVE-2015-3197
https://www.cve.org/CVERecord?id=CVE-2015-3197
Référence CVE CVE-2015-5600
https://www.cve.org/CVERecord?id=CVE-2015-5600
Référence CVE CVE-2015-8104
https://www.cve.org/CVERecord?id=CVE-2015-8104
Référence CVE CVE-2016-0800
https://www.cve.org/CVERecord?id=CVE-2016-0800
Référence CVE CVE-2016-3451
https://www.cve.org/CVERecord?id=CVE-2016-3451
Référence CVE CVE-2016-3453
https://www.cve.org/CVERecord?id=CVE-2016-3453
Référence CVE CVE-2016-3480
https://www.cve.org/CVERecord?id=CVE-2016-3480
Référence CVE CVE-2016-3481
https://www.cve.org/CVERecord?id=CVE-2016-3481
Référence CVE CVE-2016-3497
https://www.cve.org/CVERecord?id=CVE-2016-3497
Ré
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-137Multiples vulnérabilités dans Oracle Linux and VirtualizationDe multiples vulnérabilités ont été corrigées dans Oracle Linux and Virtualization . Certaines d'entre
elles permettent à un attaquant de provoquer un déni de service à
distance, un contournement de la politique de sécurité et une atteinte à
l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-076Multiples vulnérabilités dans OpenSSLDe multiples vulnérabilités ont été corrigées dans OpenSSL . Elles permettent à un attaquant de
provoquer un déni de service à distance et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-041Multiples vulnérabilités dans OpenSSLDe multiples vulnérabilités ont été corrigées dans OpenSSL . Elles permettent à un attaquant de
provoquer un contournement de la politique de sécurité, une atteinte à
l'intégrité des données et une atteinte à la confidentialité des
données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2015-006985OpenSSL の ssl/s2_srvr.c における暗号保護メカニズムを破られる脆弱性OpenSSL の ssl/s2_srvr.c は、無効にされた暗号の使用を制限しないため、暗号保護メカニズムを破られる脆弱性が存在します。 なお、JVNVU#95668716 では、CWE-757 として公開されています。 CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') https://cwe.mitre.org/data/definitions/757.html
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4592OpenSSL 취약점 보안업데이트 권고SSLv2을 사용할 경우 조작된 핸드셰이크 전송을 통한 MITM(man-in-the-middle)공격이 가능한 취약점(CVE-2015-3197)
Official advisory ↗