ENISA EUVD · EUVD-2016-6366Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-0180Dell Data Protection Advisor: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-116Juniper security bulletinsNumber: AV18-116
Date: 13 July 2018
Purpose
The purpose of this advisory is to bring attention to security bulletins released by Juniper.
Assessment
Juniper has released multiple security bulletins to address vulnerabilities in their products. Exploitation of these vulnerabilities allows code execution, elevation of privilege, denial of service conditions, circumvention of security measures, or access to sensitive information
Affected products:
cURL and libcurl
Junos Space
Junos OS
Junos OS, SRX series
CVE References: CVE-2017-3145, CVE-2017-3143, CVE-2017-3142, CVE-2017-3138, CVE-2000-0973, CVE-2016-5421, CVE-2016-7167, CVE-2016-9953, CVE-2017-8816, CVE-2017-8817, CVE-2017-8818, CVE-2018-1000120, CVE-2016-4802, CVE-2013-2174, CVE-2016-9586, CVE-2016-9952, CVE-2014-0138, CVE-2017-1000257, CVE-2018-1000005, CVE-2018-1000122, CVE-2014-0139, CVE-2013-1944, CVE-2014-3613, CVE-2015-3143, CVE-2015-3148, CVE-2015-3153, CVE-2016-0754, CVE-2016-0755, CVE-2016-5419, CVE-2016-5420, CVE-2016-7141, CVE-2017-1000254, CVE-2017-9502, CVE-2018-1000007, CVE-2018-1000121, CVE-2013-4545, CVE-2014-3707, CVE-2014-8150, CVE-2017-1000099, CVE-2017-1000100, CVE-2017-1000101, CVE-2013-6422, CVE-2014-0015, CVE-2016-3739, CVE-2017-7407, CVE-2016-8615, CVE-2016-8616, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-006SierraWireless ALEOS update 4.4.5 for AirLink devices-0702, CVE-2017-3732, CVE-2016-2182, CVE-2016-0705, CVE-2016-2105, CVE-2016-2183, CVE-2016-0797, CVE-2016-2106, CVE-2016-6302, CVE-2016-0798, CVE-2016-2107, CVE-2016-6303, CVE-2016-0799, CVE-2016-2109, CVE-2016-6304, CVE-2016-0800, CVE-2016-2176, CVE-2016-6306, CVE-2016-2842, CVE-2016-2177, CVE-2015-3195, CVE-2015-1794, CVE-2016-2178, CVE-2015-3197, CVE-2015-3193, CVE-2016-2179, CVE-2015-3194, CVE-2016-2180
Dropbear: CVE-2017-9078 and CVE-2017-9079
Tcpdump and Libpcap: CVE-2014-8769 and CVE-2014-8767
Linux kernel: CVE-2017-14106, CVE-2014-7822, CVE-2014-9888, CVE-2015-3288
OpenVPN: CVE-2017-7520 and CVE-2017-7479
SNMP: CVE-2015-5621
Libcurl: CVE-2016-5421
Dnsmasq: CVE-2017-14496, CVE-2017-14491, CVE-2017-14492, CVE-2017-14493, CVE-2017-14494, CVE-2017-14495
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.
CCIRC recommends confirming if your remote access, mobile or off-site solutions include this type of cellular gateway. Contact your integrator or service provider for more information on how to properly test and deploy the vendor released updates on affected platforms accordingly.
References:
Release Notes:
https://source.sierrawireless.com/resources/airlink/software_reference_docs/release-notes/aleos-
Official advisory ↗Canadian Centre for Cyber Security · English · AV17-048Oracle Critical Patch update Advisory – April 2017236, CVE-2015-3237, CVE-2015-4852, CVE-2015-5252, CVE-2015-5351, CVE-2015-7501, CVE-2015-7940, CVE-2016-0635, CVE-2016-0706, CVE-2016-0714, CVE-2016-0729, CVE-2016-0762, CVE-2016-0763, CVE-2016-1181, CVE-2016-1182, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2510, CVE-2016-3092, CVE-2016-3504, CVE-2016-3506, CVE-2016-3607, CVE-2016-3674, CVE-2016-3739, CVE-2016-4430, CVE-2016-4431, CVE-2016-4433, CVE-2016-4436, CVE-2016-4802, CVE-2016-5018, CVE-2016-5019, CVE-2016-5407, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-5551, CVE-2016-6288, CVE-2016-6289, CVE-2016-6290, CVE-2016-6291, CVE-2016-6292, CVE-2016-6294, CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6794, CVE-2016-6796, CVE-2016-6797, CVE-2016-6816, CVE-2016-6817, CVE-2016-7052, CVE-2016-7055, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625, CVE-2016-8735, CVE-2016-8743, CVE-2017-3230, CVE-2017-3232, CVE-2017-3233, CVE-2017-3234, CVE-2017-3237, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV16-204Multiple Apple security updatespurpose of this advisory is to bring attention to multiple Apple system security updates for iCloud, iTunes, macOS (Sierra, El Capitan, Yosemite) and Safari.
Assessment
Apple has released the following support articles:
HT207421 – Safari 10.0.2
HT207423 – macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite
HT207424 – iCloud for Windows 6.1
HT207427 – iTunes 12.5.4 for Windows
This update addresses multiple vulnerabilities on the systems listed above.
CVE Reference: CVE-2016-1777, CVE-2016-1823, CVE-2016-4688, CVE-2016-4691, CVE-2016-4692, CVE-2016-4693, CVE-2016-4743, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-6303, CVE-2016-6304, CVE-2016-7141, CVE-2016-7167, CVE-2016-7411, CVE-2016-7412, CVE-2016-7413, CVE-2016-7414, CVE-2016-7416, CVE-2016-7417, CVE-2016-7418, CVE-2016-7636, CVE-2016-7586, CVE-2016-7587, CVE-2016-7588, CVE-2016-7589, CVE-2016-7591, CVE-2016-7592, CVE-2016-7594, CVE-2016-7595, CVE-2016-7596, CVE-2016-7598, CVE-2016-7599, CVE-2016-7600, CVE-2016-7602, CVE-2016-7603, CVE-2016-7604, CVE-2016-7605, CVE-2016-7606, CVE-2016-7607, CVE-2016-7608, CVE-2016-7609, CVE-2016-7610, CVE-2016-7611, CVE-2016-7612, CVE-2016-7615, CVE-2016-7616, CVE-2016-7617, CVE-2016-7618, CVE-2016-7619, CVE-2016-7620, CVE-2016-7621, CVE-2016-7622, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV16-196Android security bulletin – December 2016Number: AV16-196
Date: 5 December 2016
Purpose
The purpose of this advisory is to bring attention to the Android Security Bulletin for December.
Assessment
The Android Security Bulletin addresses security updates for 74 vulnerabilities (11 Critical, 43 High, and 20 Moderate). The 11 vulnerabilities tagged as critical have the possibility of remote code execution, privilege escalation and/or permanent device compromise.
CVE References: CVE-2016-4794, CVE-2016-5195, CVE-2016-6775, CVE-2016-6776, CVE-2016-6777, CVE-2015-8966, CVE-2016-6915, CVE-2016-6916, CVE-2016-6917, CVE-2016-9120, CVE-2016-8411, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-6762 CVE-2016-6763, CVE-2016-6766, CVE-2016-6765, CVE-2016-6764, CVE-2016-6767, CVE-2016-6768, CVE-2014-4014, CVE-2015-8967, CVE-2016-6778, CVE-2016-6779, CVE-2016-6780, CVE-2016-6492, CVE-2016-6781, CVE-2016-6782, CVE-2016-6783, CVE-2016-6784, CVE-2016-6785, CVE-2016-6761, CVE-2016-6760, CVE-2016-6759, CVE-2016-6758, CVE-2016-6755, CVE-2016-6786, CVE-2016-6787, CVE-2016-6788, CVE-2016-6789, CVE-2016-6790, CVE-2016-6791, CVE-2016-8391, CVE-2016-8392, CVE-2015-7872, CVE-2016-8393, CVE-2016-8394, CVE-2014-9909, CVE-2014-9910, CVE-2016-8396, CVE-2016-8397, CVE-2016-5341, CVE-2016-8395, CVE-2016-6769, CVE-2016-6770, CVE-2016-6771, CVE-
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-339Multiples vulnérabilités dans les produits Juniper.cve.org/CVERecord?id=CVE-2015-3148
Référence CVE CVE-2015-3153
https://www.cve.org/CVERecord?id=CVE-2015-3153
Référence CVE CVE-2015-7236
https://www.cve.org/CVERecord?id=CVE-2015-7236
Référence CVE CVE-2016-0754
https://www.cve.org/CVERecord?id=CVE-2016-0754
Référence CVE CVE-2016-0755
https://www.cve.org/CVERecord?id=CVE-2016-0755
Référence CVE CVE-2016-3739
https://www.cve.org/CVERecord?id=CVE-2016-3739
Référence CVE CVE-2016-4802
https://www.cve.org/CVERecord?id=CVE-2016-4802
Référence CVE CVE-2016-5419
https://www.cve.org/CVERecord?id=CVE-2016-5419
Référence CVE CVE-2016-5420
https://www.cve.org/CVERecord?id=CVE-2016-5420
Référence CVE CVE-2016-5421
https://www.cve.org/CVERecord?id=CVE-2016-5421
Référence CVE CVE-2016-7141
https://www.cve.org/CVERecord?id=CVE-2016-7141
Référence CVE CVE-2016-7167
https://www.cve.org/CVERecord?id=CVE-2016-7167
Référence CVE CVE-2016-8615
https://www.cve.org/CVERecord?id=CVE-2016-8615
Référence CVE CVE-2016-8616
https://www.cve.org/CVERecord?id=CVE-2016-8616
Référence CVE CVE-2016-8617
https://www.cve.org/CVERecord?id=CVE-2016-8617
Référence CVE CVE-2016-8618
https://www.cve.org/CVERecord?id=CVE-2016-8618
Référence CVE CVE-2016-8619
https://www.cve.org/CVERecord?id=CVE-2016-8619
Référence CVE CVE-2016-8620
https://www.cve.org/CVERecord?id=CVE-2016-8620
Ré
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-411Multiples vulnérabilités dans les produits Apple.cve.org/CVERecord?id=CVE-2016-1777
Référence CVE CVE-2016-1823
https://www.cve.org/CVERecord?id=CVE-2016-1823
Référence CVE CVE-2016-4688
https://www.cve.org/CVERecord?id=CVE-2016-4688
Référence CVE CVE-2016-4691
https://www.cve.org/CVERecord?id=CVE-2016-4691
Référence CVE CVE-2016-4692
https://www.cve.org/CVERecord?id=CVE-2016-4692
Référence CVE CVE-2016-4693
https://www.cve.org/CVERecord?id=CVE-2016-4693
Référence CVE CVE-2016-4743
https://www.cve.org/CVERecord?id=CVE-2016-4743
Référence CVE CVE-2016-5419
https://www.cve.org/CVERecord?id=CVE-2016-5419
Référence CVE CVE-2016-5420
https://www.cve.org/CVERecord?id=CVE-2016-5420
Référence CVE CVE-2016-5421
https://www.cve.org/CVERecord?id=CVE-2016-5421
Référence CVE CVE-2016-6303
https://www.cve.org/CVERecord?id=CVE-2016-6303
Référence CVE CVE-2016-6304
https://www.cve.org/CVERecord?id=CVE-2016-6304
Référence CVE CVE-2016-7141
https://www.cve.org/CVERecord?id=CVE-2016-7141
Référence CVE CVE-2016-7167
https://www.cve.org/CVERecord?id=CVE-2016-7167
Référence CVE CVE-2016-7411
https://www.cve.org/CVERecord?id=CVE-2016-7411
Référence CVE CVE-2016-7412
https://www.cve.org/CVERecord?id=CVE-2016-7412
Référence CVE CVE-2016-7413
https://www.cve.org/CVERecord?id=CVE-2016-7413
Référence CVE CVE-2016-7414
https://www.cve.org/CVERecord?id=CVE-2016-7414
Ré
Official advisory ↗CERT-FR · French · CERTFR-2016-AVI-396Multiples vulnérabilités dans Google Android (Nexus).cve.org/CVERecord?id=CVE-2014-9910
Référence CVE CVE-2015-7872
https://www.cve.org/CVERecord?id=CVE-2015-7872
Référence CVE CVE-2015-8966
https://www.cve.org/CVERecord?id=CVE-2015-8966
Référence CVE CVE-2015-8967
https://www.cve.org/CVERecord?id=CVE-2015-8967
Référence CVE CVE-2016-4794
https://www.cve.org/CVERecord?id=CVE-2016-4794
Référence CVE CVE-2016-5195
https://www.cve.org/CVERecord?id=CVE-2016-5195
Référence CVE CVE-2016-5341
https://www.cve.org/CVERecord?id=CVE-2016-5341
Référence CVE CVE-2016-5419
https://www.cve.org/CVERecord?id=CVE-2016-5419
Référence CVE CVE-2016-5420
https://www.cve.org/CVERecord?id=CVE-2016-5420
Référence CVE CVE-2016-5421
https://www.cve.org/CVERecord?id=CVE-2016-5421
Référence CVE CVE-2016-6492
https://www.cve.org/CVERecord?id=CVE-2016-6492
Référence CVE CVE-2016-6704
https://www.cve.org/CVERecord?id=CVE-2016-6704
Référence CVE CVE-2016-6755
https://www.cve.org/CVERecord?id=CVE-2016-6755
Référence CVE CVE-2016-6756
https://www.cve.org/CVERecord?id=CVE-2016-6756
Référence CVE CVE-2016-6757
https://www.cve.org/CVERecord?id=CVE-2016-6757
Référence CVE CVE-2016-6758
https://www.cve.org/CVERecord?id=CVE-2016-6758
Référence CVE CVE-2016-6759
https://www.cve.org/CVERecord?id=CVE-2016-6759
Référence CVE CVE-2016-6760
https://www.cve.org/CVERecord?id=CVE-2016-6760
Ré
Official advisory ↗JVN iPedia · Japanese · JVNDB-2016-004391libcurl における使用される接続を制御される脆弱性libcurl には、解放済みメモリの使用 (Use-after-free) により、使用される接続を制御されるなど、不特定の影響を受ける脆弱性が存在します。 補足情報 : CWE による脆弱性タイプは、CWE-416: Use After Free (解放済みメモリの使用) と識別されています。 http://cwe.mitre.org/data/definitions/416.html
Official advisory ↗