Vulnerabilities / Threats

5/6/2016
11:00 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail

The 10 Worst Vulnerabilities of The Last 10 Years

From the thousands of vulns that software vendors disclosed over the past 10 years, a few stand out for being a lot scarier than the rest.
1 of 11

Image Source: Software Bug

Image Source: Software Bug

1 of 11
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
nathanwburke
50%
50%
nathanwburke,
User Rank: Author
5/9/2016 | 12:05:52 PM
Re: OS vulnerabilities
It's a good point you raise about Mac vulnerabilities. Macs are certainly increasing in the enterprise, yet security products have been largely windows-centric. With attackers looking for a way in to gain access to other data on the network, a macbook without the same protection as the windows machines would be an attractive target. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/9/2016 | 9:14:01 AM
Re: OS vulnerabilities
@Ryan: Plus, only in the past few years have people even started to pay much attention to Apple platform security.  For years, as Apple's market share was relatively tiny, people -- including attackers -- didn't care much.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/9/2016 | 7:45:29 AM
Shellshock and Heartbleed
As they were not too long ago I know all to well the scramblings behind trying to remediate these two major vulnerabilities. They were so well publicized that non-security sides of the organization were inquiring about the patching efforts.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/9/2016 | 7:41:56 AM
Re: OS vulnerabilities
Yes, I think you will start to see this as more of a commonality with the increasing Mac footprint in the market. It hasn't quite extended over to the corporate side as fast as it has from a personal perspective but regardless Mac is definitely becoming more prevalent then before. With that comes more code for the OS and more opportunities for open holes.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/8/2016 | 12:03:07 PM
OS vulnerabilities
It's one thing to look at the past ten years in a single lump, but it's also worth noting that many more vulnerabilities are being found for Apple OS's than Microsoft OS's these days.

Case in point: informationweek.com/ios-security-reports-say-no-iphone-is-safe/a/d-id/1319750
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
5 Reasons Why Threat Intelligence Doesn't Work
Jonathan Zhang, CEO/Founder of WhoisXML API and TIP,  11/7/2018
Why the CISSP Remains Relevant to Cybersecurity After 28 Years
Steven Paul Romero, SANS Instructor and Sr. SCADA Network Engineer, Chevron,  11/6/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19205
PUBLISHED: 2018-11-12
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
CVE-2018-19206
PUBLISHED: 2018-11-12
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVE-2018-19207
PUBLISHED: 2018-11-12
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.
CVE-2018-1786
PUBLISHED: 2018-11-12
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
CVE-2018-1798
PUBLISHED: 2018-11-12
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force...