Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/6/2016
11:00 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

The 10 Worst Vulnerabilities of The Last 10 Years

From the thousands of vulns that software vendors disclosed over the past 10 years, a few stand out for being a lot scarier than the rest.
Previous
1 of 11
Next

Looks like you've hit your article limit. Please log in or register for a free account to get unlimited access to articles, discussions, and newsletters on Darkreading.

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
nathanwburke
50%
50%
nathanwburke,
User Rank: Author
5/9/2016 | 12:05:52 PM
Re: OS vulnerabilities
It's a good point you raise about Mac vulnerabilities. Macs are certainly increasing in the enterprise, yet security products have been largely windows-centric. With attackers looking for a way in to gain access to other data on the network, a macbook without the same protection as the windows machines would be an attractive target. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/9/2016 | 9:14:01 AM
Re: OS vulnerabilities
@Ryan: Plus, only in the past few years have people even started to pay much attention to Apple platform security.  For years, as Apple's market share was relatively tiny, people -- including attackers -- didn't care much.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/9/2016 | 7:45:29 AM
Shellshock and Heartbleed
As they were not too long ago I know all to well the scramblings behind trying to remediate these two major vulnerabilities. They were so well publicized that non-security sides of the organization were inquiring about the patching efforts.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/9/2016 | 7:41:56 AM
Re: OS vulnerabilities
Yes, I think you will start to see this as more of a commonality with the increasing Mac footprint in the market. It hasn't quite extended over to the corporate side as fast as it has from a personal perspective but regardless Mac is definitely becoming more prevalent then before. With that comes more code for the OS and more opportunities for open holes.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/8/2016 | 12:03:07 PM
OS vulnerabilities
It's one thing to look at the past ten years in a single lump, but it's also worth noting that many more vulnerabilities are being found for Apple OS's than Microsoft OS's these days.

Case in point: informationweek.com/ios-security-reports-say-no-iphone-is-safe/a/d-id/1319750
WannaCry Remains No. 1 Ransomware Weapon
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/27/2019
Cryptography & the Hype Over Quantum Computing
Yehuda Lindell, Chief Scientist at Unbound Tech and Professor of Computer Science at Bar-Ilan University,  8/26/2019
Imperva Customer Database Exposed
Dark Reading Staff 8/27/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Here’s some insight on what's working – and what isn't – in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13608
PUBLISHED: 2019-08-29
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
CVE-2019-14533
PUBLISHED: 2019-08-29
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
CVE-2019-14534
PUBLISHED: 2019-08-29
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
CVE-2019-14776
PUBLISHED: 2019-08-29
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
CVE-2019-14777
PUBLISHED: 2019-08-29
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.