Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Stack Overflow Vulnerability

A remote code execution vulnerability exists in the way that the OpenType Font (OTF) driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, ...
Last Update Date: 13 Apr 2011 17:03 Release Date: 13 Apr 2011 5118 Views

RISK: High Risk

High Risk

Microsoft Windows Scripting Memory Reallocation Vulnerability

A remote code execution vulnerability exists in the JScript and VBScript scripting engines due to a memory corruption error. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the logged-on user. An attacker could then install programs; view, ...
Last Update Date: 13 Apr 2011 16:53 Release Date: 13 Apr 2011 5097 Views

RISK: High Risk

High Risk

Microsoft Windows DNS Query Vulnerability

A remote code execution vulnerability exists in the way that the DNS client service handles specially crafted LLMNR queries. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the NetworkService account. An attacker could then install programs; view, change, ...
Last Update Date: 13 Apr 2011 16:43 Release Date: 13 Apr 2011 5195 Views

RISK: High Risk

High Risk

Microsoft Windows GDI+ Integer Overflow Vulnerability

A remote code execution vulnerability exists in the way that GDI+ handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted EMF image file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. ...
Last Update Date: 13 Apr 2011 16:35 Release Date: 13 Apr 2011 5226 Views

RISK: High Risk

High Risk

Microsoft Windows .NET Framework Stack Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft .NET Framework handles certain function calls. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 13 Apr 2011 16:25 Release Date: 13 Apr 2011 5171 Views

RISK: High Risk

High Risk

Microsoft Windows ActiveX Control Multiple Vulnerabilities

Microsoft Internet Explorer 8 Developer Tools Vulnerability A remote code execution vulnerability exists in the ActiveX control, Microsoft Internet Explorer 8 Developer Tools. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could...
Last Update Date: 13 Apr 2011 16:18 Release Date: 13 Apr 2011 5171 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Layouts Handling Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views...
Last Update Date: 13 Apr 2011 16:15 Release Date: 13 Apr 2011 5086 Views

RISK: High Risk

High Risk

McAfee Firewall Reporter Remote Authentication Bypass Vulnerability

A vulnerability has been identified in McAfee Firewall Reporter, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a design error within the "GernalUtilities.pm" script that checks for the existence of a particular file without verifying...
Last Update Date: 13 Apr 2011 15:51 Release Date: 13 Apr 2011 5158 Views

RISK: Medium Risk

Medium Risk

Novell ZENworks Configuration Management File Overwrite Vulnerability

A vulnerability has been identified in Novell ZENworks Configuration Management, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error related to specific transversal file modifications, which could allow attackers to execute arbitrary code via an inventory service...
Last Update Date: 12 Apr 2011 12:11 Release Date: 12 Apr 2011 5270 Views

RISK: High Risk

High Risk

VLC Media Player Libmodplug "CSoundFile::ReadS3M()" Stack Overflow Vulnerability

A vulnerability has been identified in VLC Media Player, which could be exploited by attackers to take complete control of a vulnerable system. This issue is caused by a stack overflow error in the "CSoundFile::ReadS3M()" [load_s3m.cpp] function of Libmodplug when handling...
Last Update Date: 8 Apr 2011 10:33 Release Date: 8 Apr 2011 5511 Views