Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Adobe Flash Player Cross Site Scripting and Other Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which can be exploited to cause a crash and potentially allow an attacker to take control of the affected system.   This update also resolves cross-site scripting vulnerability that could be used to take actions on a...
Last Update Date: 16 Feb 2012 10:21 Release Date: 16 Feb 2012 7782 Views

RISK: High Risk

High Risk

Microsoft Windows Indeo Codec Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Indeo Codec handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 15 Feb 2012 12:50 Release Date: 15 Feb 2012 7512 Views

RISK: High Risk

High Risk

Microsoft Visio Viewer Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Visio Viewer validates attributes when handling specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 15 Feb 2012 12:49 Release Date: 15 Feb 2012 7585 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Copy and Paste Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted web page that could allow information...
Last Update Date: 15 Feb 2012 12:06 Release Date: 15 Feb 2012 7590 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

GDI Access Violation Vulnerability A remote code execution vulnerability exists in the Windows kernel due to improper validation of input passed from user mode through the kernel component of GDI. The vulnerability could allow an attacker to run code in kernel-mode and then install programs; ...
Last Update Date: 15 Feb 2012 12:05 Release Date: 15 Feb 2012 7581 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Color Control Panel Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Color Control Panel handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 15 Feb 2012 12:04 Release Date: 15 Feb 2012 7503 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities

XSS in inplview.aspx Vulnerability A cross-site scripting vulnerability exists in Microsoft SharePoint 2010 that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL containing malicious JavaScript elements. Due to the vulnerability, when the malicious JavaScript...
Last Update Date: 15 Feb 2012 12:02 Release Date: 15 Feb 2012 7562 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Multiple Vulnerabilities

AfdPoll Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists where the Ancillary Function Driver (afd.sys) improperly validates input passed from user mode to the Windows kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker...
Last Update Date: 15 Feb 2012 12:01 Release Date: 15 Feb 2012 7706 Views

RISK: High Risk

High Risk

Microsoft .NET Framework and Microsoft Silverlight Multiple Vulnerabilities

.NET Framework Unmanaged Objects Vulnerability A remote code execution vulnerability exists in Microsoft .NET Framework and Silverlight that can allow a specially crafted Microsoft .NET Framework application to access memory in an unsafe manner. An attacker who successfully exploited this vulnerability could run arbitrary code...
Last Update Date: 15 Feb 2012 11:45 Release Date: 15 Feb 2012 7440 Views

RISK: High Risk

High Risk

Microsoft Windows C Run-Time Library Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that the msvcrt DLL calculates the size of a buffer in memory, allowing data to be copied into memory that has not been properly allocated. This vulnerability could allow remote code execution if a user opens a specially crafted...
Last Update Date: 15 Feb 2012 11:44 Release Date: 15 Feb 2012 7826 Views