Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows WordPad Converter Code Execution Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the WordPad Text Converter when processing a specially crafted Word 97 file (.doc, .wri, or...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4818 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Search Code Execution Vulnerabilities (10 December 2008)

1. Windows Saved Search VulnerabilityA remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.2. Windows Search Parsing VulnerabilityA remote code execution vulnerability exists in Windows Explorer...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4465 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Code Execution Vulnerabilities (10 December 2008)

1. File Format Parsing Vulnerability - CVE-2008-4265A remote code execution vulnerability exists in Microsoft Office Excel as a result of memory corruption when loading Excel records. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file that includes...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4470 Views

RISK: Medium Risk

Medium Risk

Microsoft Office SharePoint Server Security Bypass Vulnerability (10 December 2008)

An elevation of privilege vulnerability exists in Microsoft Office SharePoint Server 2007 and Microsoft Office SharePoint Server 2007 Service Pack 1. The vulnerability could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack leading to...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4536 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Code Execution Vulnerabilities (10 December 2008)

1. Word Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file with a malformed record. Users whose accounts are configured to have...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4612 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer XML Parsing Code Execution Vulnerability

A remote code execution vulnerability exists as an invalid pointer reference in the data binding function of Internet Explorer. When data binding is enabled (which is the default state), it is possible under certain conditions for an object to be released without updating the array length, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4596 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Products Code Execution Vulnerabilities (10 December 2008)

1. SPN VulnerabilityA credential reflection vulnerability exists in the Windows Media components that could allow an attacker to execute code with the same rights as the local user or with Windows Media Services distribution credentials. The vulnerability exists due to weaknesses in Service Principal Name (SPN) ...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4530 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Code Execution Vulnerabilities (10 December 2008)

1. Parameter Validation Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Internet Explorer handles certain navigation methods. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4549 Views

RISK: Medium Risk

Medium Risk

Sun Java JDK / JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or take complete control of an affected system.1. Due to JRE creating temporary files...
Last Update Date: 28 Jan 2011 Release Date: 5 Dec 2008 4838 Views

RISK: Medium Risk

Medium Risk

BitDefenderAntivirus PDF Processing Memory Corruption Vulnerability

It has discovered a vulnerability in BitDefender Antivirus, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.The vulnerability is caused due to a boundary error in the "pdf.xmd" module...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2008 4911 Views