Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Windows Kernel Multiple Vulnerabilities

Kernel Race Condition Vulnerability An elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data...
Last Update Date: 14 Feb 2013 17:33 Release Date: 14 Feb 2013 6437 Views

RISK: Medium Risk

Medium Risk

Microsoft FAST Search Server 2010 for SharePoint Multiple Vulnerabilities

Remote code execution vulnerabilities exist in FAST Search Server 2010 for SharePoint with the Advanced Filter Pack enabled. An attacker who succesfully exploited these vulnerabilities could run arbitrary code in the context of a user account with a restricted token. By default, Advanced Filter Pack in FAST...
Last Update Date: 14 Feb 2013 17:30 Release Date: 14 Feb 2013 6698 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Shift JIS Character Encoding Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a...
Last Update Date: 14 Feb 2013 17:25 Release Date: 14 Feb 2013 6494 Views

RISK: High Risk

High Risk

Microsoft Windows Media Decompression Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles media content. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a ....
Last Update Date: 14 Feb 2013 17:21 Release Date: 14 Feb 2013 6842 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Multiple Vulnerabilities

Two vulnerabilities exist in Microsoft Exchange Server through the WebReady Document Viewing feature. The more severe vulnerability, CVE-2013-0418, could allow remote code execution as the LocalService account if a user views a specially crafted file through Outlook Web Access in a browser. ...
Last Update Date: 14 Feb 2013 17:18 Release Date: 14 Feb 2013 6806 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Automation Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Object Linking and Embedding (OLE) Automation allocates memory. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 14 Feb 2013 17:16 Release Date: 14 Feb 2013 6413 Views

RISK: High Risk

High Risk

Microsoft Windows NFS Server NULL Dereference Vulnerability

A denial of service vulnerability exists when the Windows NFS server fails to properly handle a file operation on a read-only share. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding and restart.
Last Update Date: 14 Feb 2013 17:08 Release Date: 14 Feb 2013 6673 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Multiple Vulnerabilities

Elevation of privilege vulnerabilities exist when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges and read arbitrary amounts of kernel memory.
Last Update Date: 14 Feb 2013 17:06 Release Date: 14 Feb 2013 6714 Views

RISK: High Risk

High Risk

Microsoft .NET Framework WinForms Allow Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that the .NET Framework elevates the permissions of a callback function when a particular Windows Forms object is created. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 14 Feb 2013 17:00 Release Date: 14 Feb 2013 6593 Views

RISK: High Risk

High Risk

PostgreSQL Array Index Error Vulerability

A vulnerability has been identified in PostgreSQL, which can be exploited by remote authenticated user to cause denial of service and disclose portions of system memory by sending a specially crafted SQL command to trigger an array index error.
Last Update Date: 14 Feb 2013 Release Date: 8 Feb 2013 7441 Views