Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by errors in...
Last Update Date: 24 Jun 2011 11:16 Release Date: 24 Jun 2011 9093 Views

RISK: High Risk

High Risk

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.Some unspecified errors can be exploited to corrupt memory.A use-after-free error in the...
Last Update Date: 22 Jun 2011 14:33 Release Date: 22 Jun 2011 8802 Views

RISK: High Risk

High Risk

Microsoft Word Insufficient Pointer Validation Vulnerability

A vulnerability has been identified in Microsoft Word, which can be exploited by malicious people to compromise a user's system.  It is caused due to a certain value in a document being used as a pointer, which can be exploited to corrupt memory via a...
Last Update Date: 20 Jun 2011 17:28 Release Date: 20 Jun 2011 8702 Views

RISK: High Risk

High Risk

IBM Lotus Notes KeyView File Processing Vulnerabilities

Multiple vulnerabilities have been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.An error when processing Windows Write (WRI) files can be exploited to cause a stack-based buffer overflow.Some errors when...
Last Update Date: 17 Jun 2011 10:21 Release Date: 17 Jun 2011 8564 Views

RISK: High Risk

High Risk

Adobe ColdFusion Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe ColdFusion, which can be exploited by malicious people to conduct cross-site request forgery attacks, cause a DoS (Denial of Service), and compromise a vulnerable system. The administrative interface allows users to perform certain actions via HTTP...
Last Update Date: 16 Jun 2011 15:48 Release Date: 16 Jun 2011 8474 Views

RISK: High Risk

High Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which can be exploited by malicious people to compromise a user's system.Unspecified errors in dirapi.dll and IML32.dll, an input validation error in dirapi.dll, an integer underflow error in...
Last Update Date: 16 Jun 2011 15:47 Release Date: 16 Jun 2011 8540 Views

RISK: Extremely High Risk

Extremely High Risk

Google Chrome Flash Player Unspecified Memory Corruption Vulnerability

A vulnerability has been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a bundled vulnerable version of Adobe Flash Player.   For more information, please refer to SA11061601. NOTE: ...
Last Update Date: 16 Jun 2011 15:43 Release Date: 16 Jun 2011 8504 Views

RISK: High Risk

High Risk

Adobe Reader / Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader / Acrobat, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system. An error in 3difr.x3d...
Last Update Date: 16 Jun 2011 15:42 Release Date: 16 Jun 2011 8995 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Unspecified Memory Corruption Vulnerability

A vulnerability has been identified in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error and can be exploited to corrupt memory. Successful exploitation allows execution of arbitrary code.   ...
Last Update Date: 16 Jun 2011 15:38 Release Date: 16 Jun 2011 8677 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Certificate Services Vulnerability

A reflected XSS vulnerability exists in Active Directory Certificate Services Web Enrollment that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user...
Last Update Date: 15 Jun 2011 14:19 Release Date: 15 Jun 2011 8687 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Editor XML External Entities Resolution Vulnerability

An information disclosure vulnerability exists in the way that Microsoft XML Editor handles specially crafted XML files.
Last Update Date: 15 Jun 2011 14:17 Release Date: 15 Jun 2011 8806 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Request Parsing Vulnerability

A denial of service vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB requests. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message...
Last Update Date: 15 Jun 2011 14:14 Release Date: 15 Jun 2011 8834 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Hyper-V VMBus Persistent DoS Vulnerability

A denial of service vulnerability exists in Hyper-V on Windows Server 2008 and Windows Server 2008 R2. The vulnerability is due to Hyper-V servers insufficiently validating specific sequences of machine instructions. An attacker who successfully exploited this vulnerability could cause the affected Hyper-...
Last Update Date: 15 Jun 2011 14:11 Release Date: 15 Jun 2011 8258 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists where the Ancillary Function Driver (afd.sys) improperly validates input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this vulnerability could execute...
Last Update Date: 15 Jun 2011 14:08 Release Date: 15 Jun 2011 8440 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilities

Excel Insufficient Record Validation Vulnerability A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 15 Jun 2011 14:06 Release Date: 15 Jun 2011 8384 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MHTML Mime-Formatted Request Vulnerability

An information disclosure vulnerability exists in the way that MHTML interprets MIME-formatted requests for content that are embedded in an HTML document. Similar to server-side cross-site scripting (XSS) vulnerabilities, it is possible under certain conditions for this vulnerability to allow...
Last Update Date: 15 Jun 2011 14:02 Release Date: 15 Jun 2011 8524 Views

RISK: High Risk

High Risk

Microsoft Windows Vector Markup Language Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability...
Last Update Date: 15 Jun 2011 14:00 Release Date: 15 Jun 2011 8308 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

MIME Sniffing Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to force the browser to perform unexpected actions when a user downloads Web content, allowing an attacker to view content from a different domain or Internet Explorer zone other than...
Last Update Date: 15 Jun 2011 12:41 Release Date: 15 Jun 2011 8053 Views

RISK: High Risk

High Risk

Microsoft .NET Framework JIT Optimization Vulnerability

A remote code execution vulnerability exists in the way that Microsoft .NET Framework validates certain values within an object. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 15 Jun 2011 12:40 Release Date: 15 Jun 2011 8529 Views

RISK: High Risk

High Risk

Microsoft Windows SMB Response Parsing Vulnerability

An unauthenticated remote code execution vulnerability exists in the way that the Microsoft Server Message Block (SMB) client implementation handles specially crafted SMB responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted...
Last Update Date: 15 Jun 2011 12:38 Release Date: 15 Jun 2011 8859 Views

RISK: High Risk

High Risk

Microsoft Windows Distributed File System Memory Corruption Vulnerability

DFS Memory Corruption Vulnerability An unauthenticated remote code execution vulnerability exists in the way that the Distributed File System (DFS) client parses specially crafted DFS responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending...
Last Update Date: 15 Jun 2011 12:37 Release Date: 15 Jun 2011 8611 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Drivers Win32k OTF Validation Vulnerability

A remote code execution vulnerability exists due to the way that the Windows kernel-mode driver improperly parses specially crafted OpenType fonts on x64-based and Itanium-based systems. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker...
Last Update Date: 15 Jun 2011 12:35 Release Date: 15 Jun 2011 8446 Views

RISK: High Risk

High Risk

Microsoft Forefront Threat Management Gateway Firewall Client Memory Corruption Vulnerability

A remote code execution vulnerability exists in the TMG Firewall Client Winsock provider that could allow code execution in the security context of the client application.
Last Update Date: 15 Jun 2011 12:32 Release Date: 15 Jun 2011 8616 Views

RISK: High Risk

High Risk

Microsoft .NET Framework Array Offset Vulnerability

A remote code execution vulnerability exists in the Microsoft .NET Framework that can allow a specially crafted Microsoft .NET application to access memory in an unsafe manner. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on...
Last Update Date: 15 Jun 2011 12:29 Release Date: 15 Jun 2011 8373 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Automation Underflow Vulnerability

A remote code execution vulnerability exists in Object Linking and Embedding (OLE) Automation. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker could...
Last Update Date: 15 Jun 2011 12:28 Release Date: 15 Jun 2011 8386 Views

RISK: High Risk

High Risk

Symantec Mail Security KeyView File Processing Vulnerabilities

Multiple vulnerabilities have been reported in Symantec Mail Security, which can be exploited by malicious people to compromise a vulnerable system.An error when processing Windows Write (WRI) files can be exploited to cause a stack-based buffer overflow.Some errors when processing unspecified...
Last Update Date: 13 Jun 2011 14:34 Release Date: 13 Jun 2011 8447 Views

RISK: High Risk

High Risk

Sun Java JDK / JRE / SDK Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), compromise a user's system, and compromise a vulnerable system.Errors in...
Last Update Date: 9 Jun 2011 11:30 Release Date: 9 Jun 2011 8954 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct injection attacks, bypass certain security restrictions, and potentially compromise a user's system. A use-after-free error exists within the...
Last Update Date: 9 Jun 2011 10:49 Release Date: 9 Jun 2011 8761 Views

RISK: High Risk

High Risk

Novell iPrint Client Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell iPrint Client, which could be exploited by remote attackers to compromise a vulnerable system. A boundary error in nipplib.dll when handling the "uri" parameter via "printer-url" can be exploited to cause a heap...
Last Update Date: 8 Jun 2011 14:17 Release Date: 8 Jun 2011 8910 Views

RISK: High Risk

High Risk

ACDSee Products Insecure Library Loading Vulnerability

A vulnerability have been identified in various ACDSee products, which could be exploited by remote attackers to compromise a vulnerable system.  This issue is caused due to the application loading libraries (e.g. Wintab32.dll / CV11-DialogEditor.dll / ShellIntMgrPFMU....
Last Update Date: 8 Jun 2011 14:16 Release Date: 8 Jun 2011 8637 Views

RISK: High Risk

High Risk

VMware Products VI Client ActiveX Control Memory Corruption Vulnerability

A vulnerability has been reported in various VMware products, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an unspecified error within the VI Client ActiveX controls, which can be exploited to cause a memory corruption...
Last Update Date: 7 Jun 2011 14:36 Release Date: 7 Jun 2011 8685 Views

RISK: High Risk

High Risk

Adobe Flash Player cross-site scripting Vulnerability

A vulnerability have been identified in Adobe Flash Player, which could be exploited by remote attackers to conduct a cross-site scripting attack.   A universal cross-site scripting vulnerability could be used to take actions on a user's behalf on any website or webmail...
Last Update Date: 7 Jun 2011 14:28 Release Date: 7 Jun 2011 8612 Views

RISK: High Risk

High Risk

Cisco AnyConnect VPN Client Two Vulnerabilities

Two vulnerabilities have been reported in Cisco AnyConnect VPN Client, which can be exploited by malicious people with physical access to bypass certain security restrictions and by malicious people to compromise a user's system. An error in the graphical user interface when displayed on the Windows...
Last Update Date: 3 Jun 2011 11:28 Release Date: 3 Jun 2011 8848 Views

RISK: High Risk

High Risk

Symantec Products KeyView PRZ Processing Buffer Overflow Vulnerability

A vulnerability has been identified in various Symantec products, which can be exploited by malicious people to compromise a user's system. For more information, please refer to point 6 in the following security bulletin: /my_url/en/alert/11052602
Last Update Date: 2 Jun 2011 09:59 Release Date: 2 Jun 2011 8804 Views

RISK: High Risk

High Risk

IBM Lotus Notes File Viewers Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system. An error within xlssr.dll when parsing a Binary File Format (BIFF) record in an Excel spreadsheet can be exploited to cause...
Last Update Date: 26 May 2011 10:05 Release Date: 26 May 2011 9463 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. An unspecified error allows bypassing the pop-up blocker. An error when rendering floats may lead to a stale...
Last Update Date: 26 May 2011 09:58 Release Date: 26 May 2011 8735 Views

RISK: High Risk

High Risk

Opera Browser Frameset Constructs Memory Corruption Vulnerability

A vulnerability has been identified in Opera, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when handling certain frameset constructs while the page is unloaded, which could be exploited to crash an affected browser...
Last Update Date: 19 May 2011 10:18 Release Date: 19 May 2011 8912 Views

RISK: High Risk

High Risk

Nullsoft Winamp MIDI System Exclusive Message Processing Integer Underflow Vulnerability

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by  an integer underflow error when processing System Exclusive (SysEx) MIDI messages, which could be exploited by attackers to cause...
Last Update Date: 17 May 2011 10:41 Release Date: 17 May 2011 9009 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by integer overflows and memory corruptions in WebKit and Flash, which could be exploited by remote attackers to compromise a vulnerable system by...
Last Update Date: 16 May 2011 14:33 Release Date: 16 May 2011 8758 Views

RISK: High Risk

High Risk

Adobe Audition Session Files Processing Memory Corruption Vulnerabilities

Two vulnerabilities have been identified in Adobe Audition, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by buffer overflow and memory corruption errors when processing Session (.ses) files, which could be exploited by attackers to execute arbitrary code...
Last Update Date: 16 May 2011 14:31 Release Date: 16 May 2011 9174 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Media Server Two Vulnerabilities

Two vulnerabilities have been identified in Adobe Flash Media Server, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. A memory corruption error which can lead to arbitrary code execution. An XML data corruption, leading to a denial...
Last Update Date: 16 May 2011 14:24 Release Date: 16 May 2011 9043 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by integer overflows and memory corruption errors when processing malformed Flash content, which could be exploited by attackers to compromise a vulnerable...
Last Update Date: 16 May 2011 14:22 Release Date: 16 May 2011 9085 Views

RISK: High Risk

High Risk

HP/Palm webOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP/Palm webOS, which could be exploited by attackers to compromise a vulnerable system. An input validation errors in the Email application when processing JavaScript and HTML code, which could allow execution of arbitrary code. An error related to...
Last Update Date: 13 May 2011 10:33 Release Date: 13 May 2011 8824 Views

RISK: High Risk

High Risk

HP Intelligent Management Center (IMC) Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Intelligent Management Center (IMC), which could be exploited by remote attackers to take complete control of a vulnerable system. These issues are caused by buffer overflows, memory corruptions, use-after-free and input validation errors in...
Last Update Date: 13 May 2011 10:32 Release Date: 13 May 2011 9155 Views

RISK: High Risk

High Risk

Skype for Mac Message Handling Remote Code Execution Vulnerability

A vulnerability has been identified in Skype for Mac, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing malformed messages, which could be exploited by an attacker who is in Skype's Contact...
Last Update Date: 11 May 2011 11:18 Release Date: 11 May 2011 8697 Views

RISK: Medium Risk

Medium Risk

Microsoft PowerPoint Multiple Remote Code Execution Vulnerabilities

Presentation Memory Corruption RCE Vulnerability A remote code execution vulnerability exists in the way that Microsoft PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 11 May 2011 10:18 Release Date: 11 May 2011 8990 Views

RISK: High Risk

High Risk

Microsoft Windows WINS Service Failed Response Vulnerability

A remote code execution vulnerability exists in the Windows Internet Name Service (WINS) due to insufficient validations for the data structures within specially crafted WINS network packets sent to the WINS service.
Last Update Date: 11 May 2011 10:18 Release Date: 11 May 2011 8744 Views

RISK: High Risk

High Risk

Adobe Photoshop File Processing Unspecified Security Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Photoshop, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by unspecified errors related to file processing, which could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted...
Last Update Date: 5 May 2011 09:41 Release Date: 5 May 2011 8771 Views

RISK: High Risk

High Risk

VLC Media Player libmodplug Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in VLC Media Player, which could be exploited by malicious people to compromise a user's system.  The vulnerabilities are caused due to the application using a vulnerable version of the libmodplug library.  This issues are caused by the boundary errors...
Last Update Date: 4 May 2011 12:18 Release Date: 4 May 2011 8769 Views

RISK: High Risk

High Risk

Check Point SSL VPN On-Demand Applications Remote Code Execution Vulnerability

A vulnerability has been identified in Check Point products, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the SSL Network Extender (SNX), SecureWorkSpace and Endpoint Security On-Demand application when deployed through a...
Last Update Date: 4 May 2011 12:18 Release Date: 4 May 2011 9142 Views

RISK: Medium Risk

Medium Risk

HP OpenView Storage Data Protector Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Storage Data Protector, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by buffer overflows and directory traversal errors in the Backup Client Service (OmniInet....
Last Update Date: 3 May 2011 17:51 Release Date: 3 May 2011 10089 Views

RISK: High Risk

High Risk

Mozilla Products Mulitple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system. These issues are caused by memory corruptions, dangling pointers, input validation errors, ...
Last Update Date: 3 May 2011 17:49 Release Date: 3 May 2011 9214 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilites

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, conduct spoofing attacks, and compromise a vulnerable system. An unspecified error related to a stale pointer exists within the handling of floating objects...
Last Update Date: 29 Apr 2011 11:43 Release Date: 29 Apr 2011 9465 Views

RISK: High Risk

High Risk

Oracle Products Multiple Vulnerabilies

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to cause a denial of service, disclose sensitive information or compromise a vulnerable system.
Last Update Date: 21 Apr 2011 12:23 Release Date: 21 Apr 2011 8989 Views

RISK: High Risk

High Risk

Apple iTunes WebKit Multiple Vulnerabilities

Two vulnerabilities have been identified in Apple iTunes, which could be exploited by remote attackers to compromise a vulnerable system. Due to a use-after-free error in WebKit when handling text nodes, which could be exploited to execute arbitrary code via a malicious web...
Last Update Date: 21 Apr 2011 12:22 Release Date: 21 Apr 2011 8803 Views

RISK: High Risk

High Risk

Wireshark Multiple Code Execution and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Wireshark, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. A buffer overflow error in the DECT dissector when processing malformed data, which could allow code execution via malformed packets or a malicious...
Last Update Date: 20 Apr 2011 10:27 Release Date: 20 Apr 2011 8863 Views

RISK: High Risk

High Risk

Google Chrome GPU Process Vulnerability

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system. An off-by-three error in the GPU process, which could be exploited by remote attackers to execute arbitrary code via a malicious web page...
Last Update Date: 19 Apr 2011 11:31 Release Date: 19 Apr 2011 9133 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS for iPhone, iPod and iPad, which could be exploited by remote attackers to bypass restrictions, gain knowledge of sensitive information, or compromise a vulnerable device. 1. A use-after-free error in WebKit when...
Last Update Date: 19 Apr 2011 Release Date: 15 Apr 2011 9060 Views

RISK: Medium Risk

Medium Risk

VLC Media Player "MP4_ReadBox_skcr()" Heap Corruption Vulnerability

A vulnerability has been identified in VLC Media Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a heap corruption error in the "MP4_ReadBox_skcr()" [modules/demux/mp4/libmp4.c] function when processing...
Last Update Date: 19 Apr 2011 Release Date: 12 Apr 2011 8443 Views

RISK: High Risk

High Risk

Apple Safari WebKit Multiple Vulnerabilities

Two vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to compromise a vulnerable system.A use-after-free error in WebKit when handling text nodes, which could be exploited to execute arbitrary code via a malicious web page...
Last Update Date: 19 Apr 2011 Release Date: 15 Apr 2011 8696 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer "OpenURLInDefaultBrowser()" Vulnerability

A vulnerability has been identified in RealNetworks RealPlayer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error within the "OpenURLInDefaultBrowser()" method when processing user-supplied parameters, which could allow an attacker to execute arbitrary...
Last Update Date: 19 Apr 2011 Release Date: 15 Apr 2011 8759 Views

RISK: Extremely High Risk

Extremely High Risk

Google Chrome Flash Content Processing Code Execution Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by an error in Flash.    This vulnerability is exploited in the wild.   For additional information, please refer to Adobe Flash Player Content...
Last Update Date: 18 Apr 2011 Release Date: 13 Apr 2011 8415 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Acrobat and Reader "authplay.dll" Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error in the "authplay.dll" module when processing malformed Flash content within a PDF document, ...
Last Update Date: 18 Apr 2011 Release Date: 13 Apr 2011 8659 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Content Processing Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error when processing malformed Flash content, which could be exploited by attackers to compromise a vulnerable system by tricking...
Last Update Date: 18 Apr 2011 Release Date: 13 Apr 2011 8472 Views

RISK: High Risk

High Risk

Microsoft Reader LIT File Processing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Reader, which could be exploited by attackers to execute arbitrary code. These issues are caused by buffer and integer overflows, memory corruptions and array indexing errors when processing malformed LIT files, which could be exploited by attackers to compromise...
Last Update Date: 15 Apr 2011 14:45 Release Date: 15 Apr 2011 9221 Views

RISK: High Risk

High Risk

Microsoft Windows SMB Transaction Parsing Vulnerability

An unauthenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted SMB...
Last Update Date: 13 Apr 2011 18:48 Release Date: 13 Apr 2011 8887 Views

RISK: High Risk

High Risk

Microsoft Windows SMB Client Multiple Vulnerabilities

Browser Pool Corruption Vulnerability An unauthenticated remote code execution vulnerability exists in the way that the Common Internet File System (CIFS) Browser Protocol implementation parses malformed browser messages. An attempt to exploit the vulnerability would not require authentication. An attacker who successfully exploited this vulnerability...
Last Update Date: 13 Apr 2011 18:46 Release Date: 13 Apr 2011 8406 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MHTML Mime-Formatted Request Vulnerability

An information disclosure vulnerability exists in the way MHTML interprets MIME-formatted requests for content blocks within a document. It is possible under certain conditions for this vulnerability to allow an attacker to run a client-side script in the wrong security context. Similar...
Last Update Date: 13 Apr 2011 18:30 Release Date: 13 Apr 2011 8807 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows WordPad Converter Parsing Vulnerability

A remote code execution vulnerability exists in the way that Microsoft WordPad parses specially crafted Word documents. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed structure. An attacker could then install programs...
Last Update Date: 13 Apr 2011 18:18 Release Date: 13 Apr 2011 8456 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Win32k Use After Free Vulnerability An elevation of privilege vulnerability exists due to the way that Windows Kernel-mode drivers manage kernel-mode driver objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 13 Apr 2011 18:14 Release Date: 13 Apr 2011 8528 Views

RISK: Medium Risk

Medium Risk

Microsoft Office PowerPoint Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft PowerPoint handles specially crafted PowerPoint files. An attacker could exploit the vulnerability by creating a specially crafted PowerPoint file that could be included as an e-mail attachment, or hosted on a specially crafted or compromised...
Last Update Date: 13 Apr 2011 18:11 Release Date: 13 Apr 2011 8527 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 13 Apr 2011 18:03 Release Date: 13 Apr 2011 8552 Views

RISK: Medium Risk

Medium Risk

Microsoft MFC Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that certain applications built Microsoft Foundation Classes (MFC) handle the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 13 Apr 2011 17:59 Release Date: 13 Apr 2011 8920 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Fax Cover Page Editor Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that the Windows Fax Cover Page Editor improperly parses specially crafted fax cover pages. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts...
Last Update Date: 13 Apr 2011 17:51 Release Date: 13 Apr 2011 8643 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Multiple Vulnerabilities

Office Component Insecure Library Loading Vulnerability A remote code execution vulnerability exists in the way that Microsoft Office handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 13 Apr 2011 17:45 Release Date: 13 Apr 2011 8554 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Stack Overflow Vulnerability

A remote code execution vulnerability exists in the way that the OpenType Font (OTF) driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, ...
Last Update Date: 13 Apr 2011 17:03 Release Date: 13 Apr 2011 8284 Views

RISK: High Risk

High Risk

Microsoft Windows Scripting Memory Reallocation Vulnerability

A remote code execution vulnerability exists in the JScript and VBScript scripting engines due to a memory corruption error. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the logged-on user. An attacker could then install programs; view, ...
Last Update Date: 13 Apr 2011 16:53 Release Date: 13 Apr 2011 8304 Views

RISK: High Risk

High Risk

Microsoft Windows DNS Query Vulnerability

A remote code execution vulnerability exists in the way that the DNS client service handles specially crafted LLMNR queries. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the NetworkService account. An attacker could then install programs; view, change, ...
Last Update Date: 13 Apr 2011 16:43 Release Date: 13 Apr 2011 8563 Views

RISK: High Risk

High Risk

Microsoft Windows GDI+ Integer Overflow Vulnerability

A remote code execution vulnerability exists in the way that GDI+ handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted EMF image file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. ...
Last Update Date: 13 Apr 2011 16:35 Release Date: 13 Apr 2011 8737 Views

RISK: High Risk

High Risk

Microsoft Windows .NET Framework Stack Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft .NET Framework handles certain function calls. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 13 Apr 2011 16:25 Release Date: 13 Apr 2011 8378 Views

RISK: High Risk

High Risk

Microsoft Windows ActiveX Control Multiple Vulnerabilities

Microsoft Internet Explorer 8 Developer Tools Vulnerability A remote code execution vulnerability exists in the ActiveX control, Microsoft Internet Explorer 8 Developer Tools. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could...
Last Update Date: 13 Apr 2011 16:18 Release Date: 13 Apr 2011 8382 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Layouts Handling Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views...
Last Update Date: 13 Apr 2011 16:15 Release Date: 13 Apr 2011 8233 Views

RISK: High Risk

High Risk

McAfee Firewall Reporter Remote Authentication Bypass Vulnerability

A vulnerability has been identified in McAfee Firewall Reporter, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a design error within the "GernalUtilities.pm" script that checks for the existence of a particular file without verifying...
Last Update Date: 13 Apr 2011 15:51 Release Date: 13 Apr 2011 8339 Views

RISK: Medium Risk

Medium Risk

Novell ZENworks Configuration Management File Overwrite Vulnerability

A vulnerability has been identified in Novell ZENworks Configuration Management, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error related to specific transversal file modifications, which could allow attackers to execute arbitrary code via an inventory service...
Last Update Date: 12 Apr 2011 12:11 Release Date: 12 Apr 2011 8446 Views

RISK: High Risk

High Risk

VLC Media Player Libmodplug "CSoundFile::ReadS3M()" Stack Overflow Vulnerability

A vulnerability has been identified in VLC Media Player, which could be exploited by attackers to take complete control of a vulnerable system. This issue is caused by a stack overflow error in the "CSoundFile::ReadS3M()" [load_s3m.cpp] function of Libmodplug when handling...
Last Update Date: 8 Apr 2011 10:33 Release Date: 8 Apr 2011 8789 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

 Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system. 1. A buffer error related to base string handling, which could allow arbitrary code execution. 2. A use-after-free in...
Last Update Date: 28 Mar 2011 11:51 Release Date: 28 Mar 2011 8742 Views

RISK: High Risk

High Risk

Google Picasa Insecure Library Loading Vulnerability

 A vulnerability has been identified in Google Picasa, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error when loading executable and library files while using the "Locate on Disk" feature, which could allow attackers...
Last Update Date: 28 Mar 2011 11:50 Release Date: 28 Mar 2011 8653 Views

RISK: Medium Risk

Medium Risk

Comodo Fraudulent Digital Certificates Spoofing Vulnerabiliity

It is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Other products (including all web browsers) using digital certificates may also be affected.  Comodo advised that...
Last Update Date: 25 Mar 2011 Release Date: 24 Mar 2011 9150 Views

RISK: High Risk

High Risk

Citrix Presentation Server and XenApp ActiveSync Remote Code Execution Vulnerability

A vulnerability has been identified in Citrix Presentation Server and Citrix XenApp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the ActiveSync feature when processing malformed packets while synchronizing PDA devices, which could be exploited...
Last Update Date: 25 Mar 2011 12:18 Release Date: 25 Mar 2011 9065 Views

RISK: High Risk

High Risk

HP OpenView Storage Data Protector Media Operations Memory Corruption Vulnerability

A vulnerability has been identified in HP OpenView Storage Data Protector Media Operations, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a memory corruption error in the "DBServer.exe" component when processing user...
Last Update Date: 25 Mar 2011 11:58 Release Date: 25 Mar 2011 8903 Views

RISK: High Risk

High Risk

IBM Lotus Domino Cookie File Authentication Bypass and Code Execution Vulnerability

A vulnerability has been identified in IBM Lotus Domino, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a design error in the remote console functionality that relies on a user-supplied COOKIEFILE path to retrieve...
Last Update Date: 25 Mar 2011 11:57 Release Date: 25 Mar 2011 9126 Views

RISK: High Risk

High Risk

VLC Media Player AMV and NSV Data Processing Vulnerability

Two vulnerabilities have been identified in VLC, which could be exploited by remote attackers to compromise a vulnerable system.  Due to a memory corruption error in the "libdirectx" plugin when processing malformed NSV or AMV data, which could be exploited by remote attackers to execute...
Last Update Date: 25 Mar 2011 11:43 Release Date: 25 Mar 2011 8843 Views

RISK: High Risk

High Risk

Apple iPhone iOS "OfficeArtMetafileHeader" Parsing Vulnerability

A vulnerability has been reported in Apple iPhone iOS, which can be exploited by malicious people to compromise a vulnerable device.  A boundary error exists in QuickLook when parsing an OfficeArtMetafileHeader record in certain Microsoft Office files. This can be exploited to cause a...
Last Update Date: 25 Mar 2011 10:04 Release Date: 25 Mar 2011 8718 Views

RISK: Extremely High Risk

Extremely High Risk

Adobe Flash Player Vulnerability

A vulnerability has been identified in Adobe flash player, which could be exploited by attackers to compromise a vulnerable system. This vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered...
Last Update Date: 23 Mar 2011 Release Date: 15 Mar 2011 8816 Views

RISK: High Risk

High Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by errors in AirPort, Apache...
Last Update Date: 23 Mar 2011 09:46 Release Date: 23 Mar 2011 9125 Views

RISK: High Risk

High Risk

RealPlayer RealVideo Renderer Plugin Remote Heap Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a heap overflow error in the RealVideo Renderer plugin for RealMedia (rvrender.dll) when processing a malformed IVR...
Last Update Date: 23 Mar 2011 09:45 Release Date: 23 Mar 2011 8644 Views

RISK: High Risk

High Risk

MIT Kerberos krb5 Key Distribution Center PKINIT Double-free Vulnerability

A vulnerability has been identified in MIT Kerberos, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a double-free error in the "perpare_error_as()" [do_as_req.c] function within the...
Last Update Date: 17 Mar 2011 09:39 Release Date: 17 Mar 2011 8844 Views

RISK: High Risk

High Risk

BlackBerry Smartphones Browser WebKit Style Handling Vulnerability

A vulnerability has been identified in various BlackBerry smartphones, which could be exploited by attackers to compromise a vulnerable smartphone. This issue is caused by a memory corruption error in WebKit when handling certain style data, which could be exploited by remote attackers to execute arbitrary code...
Last Update Date: 16 Mar 2011 09:36 Release Date: 16 Mar 2011 8931 Views

RISK: High Risk

High Risk

Google Chrome Style Handling Memory Corruption Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in WebKit when handling certain style data, which could be exploited by remote attackers to execute arbitrary code by...
Last Update Date: 15 Mar 2011 14:22 Release Date: 15 Mar 2011 8583 Views

RISK: High Risk

High Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS, which could be exploited by remote attackers to obtain sensitive information, bypass security restrictions or compromise a vulnerable system. These issues are caused by errors in CoreGraphics, ImageIO, libxml, Networking, Safari, WebKit, and...
Last Update Date: 11 Mar 2011 10:50 Release Date: 11 Mar 2011 8723 Views