Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Common Control Library Heap Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows common control library renders specially crafted Web sites when using a third-party scalable vector graphics (SVG) viewer. This vulnerability could allow code execution if a user visited a specially crafted Web page. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4340 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities ( 13 October 2010 )

1. Excel Record Parsing Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4334 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Vulnerabilities ( 13 October 2010 )

1. Word Uninitialized Pointer VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Word handles an uninitialized pointer when parsing a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4501 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework x64 JIT Compiler Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the Microsoft .NET Framework that can allow a specially crafted Microsoft .NET application to access memory in an unsafe manner, leading to arbitrary unmanaged code execution. This vulnerability only affects the x64 and Itanium architectures.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4473 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 13 October 2010 )

1. AutoComplete Information Disclosure VulnerabilityAn information disclosure vulnerability exists that potentially allows form data within Internet Explorer to be captured via the AutoComplete feature. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4510 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Title Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error when attempting to set the window title text and can be exploited to cause a stack-...
Last Update Date: 28 Jan 2011 Release Date: 7 Oct 2010 4662 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system, or by local attackers to gain elevated privileges. These issues are caused by memory corruptions, array-indexing...
Last Update Date: 28 Jan 2011 Release Date: 6 Oct 2010 4609 Views

RISK: Medium Risk

Medium Risk

Novell iManager Tomcat Remote File Upload Vulnerability

A vulnerability has been identified in Novell iManager, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by access and input validation errors in the "nps.jar" web application when handling uploaded files via the...
Last Update Date: 28 Jan 2011 Release Date: 4 Oct 2010 4581 Views

RISK: Medium Risk

Medium Risk

Sun Solaris XServer FreeType CFF Font Parsing Vulnerability

A vulnerability has been identified in Sun Solaris and OpenSolaris, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error in the FreeType library used by Xserver.
Last Update Date: 28 Jan 2011 Release Date: 30 Sep 2010 4528 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ASP.NET Padding Oracle Vulnerability ( 29 September 2010 )

An information disclosure vulnerability exists in ASP.NET due to improper error handling during encryption padding verification. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for...
Last Update Date: 28 Jan 2011 Release Date: 29 Sep 2010 4629 Views