Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the way that the Microsoft Windows SSL/TLS (Secure Socket Layer and Transport Layer Security) handle the SSL version 3 (SSLv3) and TLS protocols. The vulnerability could allow security feature bypass if an attacker injects specially crafted...
Last Update Date: 9 Jan 2013 15:10 Release Date: 9 Jan 2013 7757 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities

System Drawing Information Disclosure Vulnerability An information disclosure vulnerability exists in the way the Windows Forms in .NET Framework handles pointers to unmanaged memory locations. WinForms Buffer Overflow Vulnerability An elevation of privilege vulnerability exists in the way that a Windows Forms method included in the .NET...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7595 Views

RISK: Medium Risk

Medium Risk

Microsoft System Center Operations Manager Web Console Multiple XSS Vulnerabilities

Two cross-site scripting (XSS) vulnerabilities exist in System Center Operations Manager that could allow specially crafted script code to run under the guise of the server. These are non-persistent cross-site scripting vulnerabilities that could allow an attacker to issue commands to...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7586 Views

RISK: High Risk

High Risk

Microsoft XML Core Services Multiple Vulnerabilities

MSXML Integer Truncation Vulnerability A remote code execution vulnerability exists in the way that Microsoft Windows parses XML content. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the logged-on user. MSXML XSLT Vulnerability...
Last Update Date: 9 Jan 2013 15:09 Release Date: 9 Jan 2013 7913 Views

RISK: High Risk

High Risk

Microsoft Windows Print Spooler Components Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows Print Spooler handles specially crafted print jobs. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code.
Last Update Date: 9 Jan 2013 15:08 Release Date: 9 Jan 2013 7870 Views

RISK: High Risk

High Risk

Adobe Acrobat/Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system. A local user can obtain elevated privileges on the target system. A user can bypass security restrictions. A remote...
Last Update Date: 9 Jan 2013 14:19 Release Date: 9 Jan 2013 7189 Views

RISK: High Risk

High Risk

Adobe Flash Player / AIR Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to cause a buffer overflow. Successful exploitation may...
Last Update Date: 9 Jan 2013 14:17 Release Date: 9 Jan 2013 7280 Views

RISK: High Risk

High Risk

Symantec PGP Desktop Elevated Privileges Vulnerability

A vulnerability has been identified in Symantec PGP Desktop. A local user can obtain elevated privileges on the target system.   A local user can issue a specially crafted IOCTL 0x80022058 request to execute arbitrary code on the target system with system level privileges.  Note: Vendor patch...
Last Update Date: 8 Jan 2013 10:34 Release Date: 8 Jan 2013 7783 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Method Parameters SQL Injection Vulnerability

Multiple vulnerabilities have been identified in Ruby on Rails, which can be exploited by malicious people to conduct SQL injection attacks.   Input passed to the Active Record interface via method parameters is not properly sanitised before being used in SQL queries. This can be exploited to manipulate...
Last Update Date: 4 Jan 2013 15:41 Release Date: 4 Jan 2013 6951 Views

RISK: High Risk

High Risk

VLC Media Player HTML Subtitle Parsing Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in  VLC Media Player, which can be exploited by malicious people to compromise a user's system.   The vulnerabilities are caused due to errors when parsing HTML subtitles in modules/codec/subsdec.c and can be exploited to...
Last Update Date: 2 Jan 2013 Release Date: 31 Dec 2012 7394 Views