Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Video ActiveX Control Vulnerability ( 15 July 2009 )

A remote code execution vulnerability exists in the Microsoft Video ActiveX Control, msvidctl.dll. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 4272 Views

RISK: Medium Risk

Medium Risk

Microsoft ISA Server 2006 Radius OTP Bypass Vulnerability ( 15 July 2009 )

An elevation of privilege vulnerability exists in ISA Server 2006 authentication when configured with Radius OTP. The vulnerability could allow an unauthenticated user access to any Web published resource. With knowledge of administrator account usernames, an attacker who successfully exploited this vulnerability could take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 4296 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Embedded OpenType Font Engine Multiple Vulnerabilities ( 15 July 2009 )

1. Embedded OpenType Font Heap Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Windows Embedded OpenType (EOT) font technology parses data records in specially crafted embedded fonts. If a user is logged on with administrative user rights, an attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 4259 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow Multiple Vulnerabilities ( 15 July 2009 )

1. DirectX NULL Byte Overwrite VulnerabilityA remote code execution vulnerability exists in the way that Microsoft DirectShow parses QuickTime media files. This vulnerability could allow code execution if a user opened a specially crafted QuickTime file. If a user is logged on with administrative user rights, ...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 4246 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Memory Corruption Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a memory corruption error when handling certain elements, which could be exploited by remote attackers to execute arbitrary code by tricking a...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 4450 Views

RISK: Medium Risk

Medium Risk

MicrosoftOffice Web Components Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft Office Web Components, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a memory corruption error in the "OWC10.DLL" and "OWC11.DLL" ActiveX controls, which...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2009 4554 Views

RISK: Medium Risk

Medium Risk

Apple Safari WebKit Memory Corruption and Cross Site Scripting Vulnerabilties

Two vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. An input validation error in WebKit when handling parent and top objects, which could be exploited by attackers to cause...
Last Update Date: 28 Jan 2011 Release Date: 10 Jul 2009 4413 Views

RISK: Medium Risk

Medium Risk

Nokia Phones RealPlayer and MMS Viewer Memory Corruption Vulnerability

Multiple vulnerabilities have been identified in various Nokia phones, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable device. These issues are caused by memory corruption errors in the "rarender.dll", "STH264HWDecHwDevice.dll", "clntcore.dll...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2009 4586 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectShow MSVidCtl Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Microsoft Windows DirectShow, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a buffer overflow error in the ActiveX control for streaming video "MSVidCtl.dll" when reading a file containing overly...
Last Update Date: 28 Jan 2011 Release Date: 7 Jul 2009 4261 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server krb5 Vulnerabilities

A vulnerability has been identified in VMware ESX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 2 Jul 2009 4404 Views