Cisco Talos Blog

October 17, 2019 14:32

Vulnerability Spotlight: Multiple vulnerabilities in YouPHPTube

Yuri Kramarz of Security Advisory EMEAR discovered these vulnerabilities. YouPHPTube contains multiple vulnerabilities that could allow an attacker to carry out a variety of malicious activities. Specially crafted, attacker-created web requests can allow an attacker to inject SQ

October 15, 2019 15:34

Vulnerability Spotlight: Another fix for Adobe Acrobat Reader DC text field value remote code execution

Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Cisco Talos once again would like to bring attention to a remote code execution vulnerability in Adobe Acrobat Reader. Acrobat, which is one of the most popular PDF readers on the market, contains a bug when the s

October 9, 2019 10:10

Vulnerability Spotlight: Multiple remote code execution bugs in NitroPDF

Cory Duplantis and Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Cisco Talos recently discovered multiple remote code execution vulnerabilities in NitroPDF. Nitro PDF allows users to save, read, sign and edit PDF files on their machines. There are two versi

October 8, 2019 13:49

Vulnerability spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580

Jared Rittle and Patrick DeSantis of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw. There are several vulnerabilities in the Schneider Electric Modicon M580 that could lead to a variety of conditions, the majority of which can cause a denial of service. The Mo

September 17, 2019 10:58

Vulnerability Spotlight: Multiple vulnerabilities in Aspose PDF API

Marcin Noga of Cisco Talos discovered these vulnerabilities. Cisco Talos recently discovered multiple remote code execution vulnerabilities in the Aspose.PDF API. Aspose provides a series of APIs for manipulating or converting a large family of document formats. These vulnerabil

September 16, 2019 15:25

Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability

Piotr Bania of Cisco Talos discovered this vulnerability. Some AMD Radeon cards contain a remote code execution vulnerability in their ATIDXX64.DLL driver. AMD produces the Radeon line of hardware, which includes graphics cards and graphics processing units. This specific vulner

September 16, 2019 13:06

Vulnerability Spotlight: Multiple vulnerabilities in Atlassian Jira

Ben Taylor of Cisco ASIG discovered these vulnerabilities. Atlassian’s Jira software contains multiple vulnerabilities that could allow an attacker to carry out a variety of actions, including the disclosure of sensitive information and the remote execution of JavaScript code. J

September 9, 2019 09:48

Vulnerability Spotlight: Denial-of-service vulnerabilities in some NETGEAR routers

Dave McDaniel of Cisco Talos discovered these vulnerabilities. The NETGEAR N300 line of wireless routers contains two denial-of-service vulnerabilities. The N300 is a small and affordable wireless router that contains the basic features of a wireless router. An attacker could e

September 4, 2019 10:32

Vulnerability Spotlight: Information disclosure vulnerability in Blynk-Library

Lilith Wyatt of Cisco Talos discovered this vulnerability. Cisco Talos recently discovered an information disclosure vulnerability in Blynk-Library. Blynk-Library is a small library for connecting more than 400 different embedded device models into a private or enterprise Blynk-