Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to obtain sensitive information, bypass security restrictions or compromise a vulnerable system. These issues are caused by errors in ImageIO, libxml, and WebKit, which could allow attackers to execute...
Last Update Date: 11 Mar 2011 10:50 Release Date: 11 Mar 2011 9215 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote attackers or malicious users to manipulate or gain knowledge of sensitive information, bypass restrictions, cause a denial of service or compromise a vulnerable system. These issues are caused by errors...
Last Update Date: 10 Mar 2011 14:43 Release Date: 10 Mar 2011 8426 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, disclose sensitive information, cause a denial of service or execute arbitrary code. These issues are caused by access and input validation errors, use-after-free...
Last Update Date: 10 Mar 2011 12:27 Release Date: 10 Mar 2011 8553 Views

RISK: Medium Risk

Medium Risk

Joomla Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Joomla, which could be exploited by attackers or malicious users to gain unauthorized access, manipulate or gain knowledge of certain information and data, or cause a denial of service. These issues are caused by input validation errors that could allow...
Last Update Date: 10 Mar 2011 12:26 Release Date: 10 Mar 2011 8636 Views

RISK: Medium Risk

Medium Risk

Foxit Reader "createDataObject()" Arbitrary File Creation Vulnerability

A vulnerability has been identified in Foxit Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an input validation error when handling arguments supplied via the "createDataObject()" method, which could allow attackers to create a file...
Last Update Date: 9 Mar 2011 10:18 Release Date: 9 Mar 2011 8407 Views

RISK: High Risk

High Risk

Microsoft Office Groove Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Groove 2007 handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 9 Mar 2011 10:18 Release Date: 9 Mar 2011 8743 Views

RISK: High Risk

High Risk

Microsoft Windows Remote Desktop Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Windows Remote Desktop Client handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 9 Mar 2011 09:55 Release Date: 9 Mar 2011 8479 Views

RISK: High Risk

High Risk

Microsoft Windows Media Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft DirectShow handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 9 Mar 2011 09:54 Release Date: 9 Mar 2011 8364 Views

RISK: High Risk

High Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which could be exploited by remote attackers to obtain sensitive information, bypass security restrictions or compromise a vulnerable system. These issues are caused by errors in ImageIO, libxml and WebKit.
Last Update Date: 4 Mar 2011 10:52 Release Date: 4 Mar 2011 8580 Views

RISK: High Risk

High Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.Due to memory corruption errors in the browser engine when parsing malformed data, which...
Last Update Date: 3 Mar 2011 10:59 Release Date: 3 Mar 2011 8783 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to spoof the address bar, disclose sensitive information, cause a denial of service or execute arbitrary code. These issues are caused by input validation errors, stale pointers, out-...
Last Update Date: 2 Mar 2011 09:34 Release Date: 2 Mar 2011 8624 Views

RISK: High Risk

High Risk

Cisco Secure Desktop CSDWebInstaller ActiveX Multiple Vulnerabilities

Two vulnerabilities have been identified in Cisco Secure Desktop, which could be exploited by remote attackers to compromise a vulnerable system. An error in the "CSDWebInstallerCtrl" ActiveX control (CSDWebInstaller.ocx) when handling a Cisco-signed executable file named "inst.exe...
Last Update Date: 1 Mar 2011 17:04 Release Date: 1 Mar 2011 9042 Views

RISK: High Risk

High Risk

Citrix Secure Gateway Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in Citrix Secure Gateway, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error which could result in arbitrary code being executed on the server in the context of the Secure Gateway process...
Last Update Date: 1 Mar 2011 16:47 Release Date: 1 Mar 2011 8762 Views

RISK: High Risk

High Risk

Foxit Reader and Phantom ICC Parsing Integer Overflow Vulnerability

 A vulnerability has been identified in Foxit Reader and Phantom, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an integer overflow error when parsing certain ICC chunks, which could be exploited by attackers to crash an affected application...
Last Update Date: 28 Feb 2011 11:11 Release Date: 28 Feb 2011 8709 Views

RISK: Medium Risk

Medium Risk

Cisco TelePresence Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco TelePresence products, which could be exploited by attackers to bypass restrictions, gain knowledge of sensitive information or unauthorized access, upload arbitrary files, cause a denial of service or execute arbitrary code. These issues are caused by errors related...
Last Update Date: 25 Feb 2011 18:12 Release Date: 25 Feb 2011 8500 Views

RISK: High Risk

High Risk

CA Products HIPSEngine XMLSecDB ActiveX File Creation Vulnerability

A vulnerability has been identified in CA Host-Based Intrusion Prevention System (HIPS) and CA Internet Security Suite (ISS), which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a design error in the XMLSecDB ActiveX control...
Last Update Date: 25 Feb 2011 16:40 Release Date: 25 Feb 2011 8469 Views

RISK: High Risk

High Risk

Novell NetWare XNFS "xdrDecodeString()" Code Execution Vulnerability

A vulnerability has been identified in Novell NetWare, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an input validation error in the "xdrDecodeString()" function within the "XNFS.NLM" component when handling...
Last Update Date: 25 Feb 2011 16:38 Release Date: 25 Feb 2011 8539 Views

RISK: Medium Risk

Medium Risk

Novell ZENworks Configuration Management TFTP Remote Heap Overflow Vulnerability

A vulnerability has been identified in Novell ZENworks Configuration Management (ZCM), which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a heap overflow error in the "novell-tftp.exe" component when processing requests sent to...
Last Update Date: 25 Feb 2011 Release Date: 18 Feb 2011 8931 Views

RISK: Medium Risk

Medium Risk

Cisco Security Agent "st_upload" Remote File Creation Vulnerability

A vulnerability has been identified in Cisco Security Agent, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an input validation error in the "webagent.exe" component when processing "st_upload" POST requests...
Last Update Date: 25 Feb 2011 Release Date: 18 Feb 2011 8597 Views

RISK: High Risk

High Risk

Oracle Sun Java JDK, JRE and SDK Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Sun Java JDK, JRE and SDK, which could be exploited by remote attackers or malicious users to manipulate or gain knowledge of sensitive information, bypass restrictions, cause a denial of service or compromise a vulnerable system. These issues...
Last Update Date: 25 Feb 2011 Release Date: 18 Feb 2011 9394 Views

RISK: High Risk

High Risk

Asterisk UPDTL Buffer Overflow Vulnerabilities

 Multiple vulnerabilities have been identified in Asterisk, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. These issues are caused by stack and heap overflow errors in the UDPTL decoding routines, which could be exploited by remote attackers...
Last Update Date: 23 Feb 2011 15:24 Release Date: 23 Feb 2011 8544 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by input validation errors, memory corruptions, and integer overflow errors when processing malformed Flash content, which could...
Last Update Date: 16 Feb 2011 Release Date: 10 Feb 2011 8325 Views

RISK: High Risk

High Risk

Microsoft Windows SMB "mrxsmb.sys" Remote Heap Overflow Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to cause a denial of service or take complete control of a vulnerable system. This issue is caused by a heap overflow error in the "BowserWriteErrorLogEntry()" function within...
Last Update Date: 16 Feb 2011 17:01 Release Date: 16 Feb 2011 9487 Views

RISK: High Risk

High Risk

VMware Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by attackers or malicious users to bypass security restrictions, gain knowledge of certain information, cause a denial of service or execute arbitrary code. These issues are caused by errors in...
Last Update Date: 16 Feb 2011 Release Date: 14 Feb 2011 9003 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Server LPD Code Execution Vulnerability

A vulnerability has been identified in Novell iPrint for Linux Open Enterprise Server, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in LPD when processing malformed data, which could be exploited...
Last Update Date: 11 Feb 2011 17:46 Release Date: 11 Feb 2011 8648 Views

RISK: Medium Risk

Medium Risk

HP-UX CDE Calendar Manager Buffer Overflow Vulnerability

A vulnerability has been identified in HP-UX, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the CMSD server (rpc.cmsd) within the CDE Calendar Manager when...
Last Update Date: 11 Feb 2011 17:41 Release Date: 11 Feb 2011 8861 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. Due to a stale pointer related to animation event handling, which could allow code execution.Due to a use...
Last Update Date: 11 Feb 2011 Release Date: 10 Feb 2011 8576 Views

RISK: High Risk

High Risk

RealPlayer Predictable Temporary File Cross Domain Scripting Vulnerability

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error within the temporary file naming scheme used by the application to store references to RM files, which could...
Last Update Date: 11 Feb 2011 Release Date: 10 Feb 2011 8431 Views

RISK: High Risk

High Risk

Adobe Acrobat and Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Acrobat and Reader, which could be exploited by malicious users to gain elevated privileges, or by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by insecure permissions...
Last Update Date: 11 Feb 2011 Release Date: 10 Feb 2011 8784 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LSASS Length Validation Vulnerability( 09 February 2011 )

An elevation of privilege vulnerability exists in the way that the Microsoft Windows Local Security Authority Subsystem Service (LSASS) processes specially crafted authentication requests. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 7821 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kerberos Multiple Vulnerabilities( 09 February 2011 )

Kerberos Unkeyed Checksum Vulnerability An elevation of privilege vulnerability exists in implementations of Kerberos. The vulnerability exists because the Microsoft Kerberos implementation supports a weak hashing mechanism, which can allow for certain aspects of a Kerberos service ticket to be forged. A malicious ...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 7957 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities( 09 February 2011 )

Win32k Improper User Input Validation Vulnerability An elevation of privilege vulnerability exists in the way that Windows kernel-mode drivers validate data supplied from user mode to kernel mode. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode and take...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 7773 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 09 February 2011 )

Driver Improper Interaction with Windows Kernel Vulnerability An elevation of privilege vulnerability exists due to the improper interaction of drivers with the Windows kernel. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode and take complete control of an affected system...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 7728 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows CSRSS Elevation of Privilege Vulnerability( 09 February 2011 )

An elevation of privilege vulnerability exists in the way that the Windows Client/Server Run-time Subsystem (CSRSS) terminates a process when a user logs off. An attacker who successfully exploited this vulnerability could run code designed to monitor the actions of...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 8052 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Scripting Engines Information Disclosure Vulnerability( 09 February 2011 )

An information disclosure vulnerability exists in the JScript and VBScript scripting engines due to a memory corruption error. An attacker who successfully exploited this vulnerability could read data not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 8242 Views

RISK: Medium Risk

Medium Risk

Microsoft Visio Multiple Vulnerabilities( 09 February 2011 )

Visio Object Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Microsoft Visio validates objects in memory when parsing specially crafted Visio files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 8144 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory SPN Validation Vulnerability( 09 February 2011 )

A denial of service vulnerability exists in implementations of Microsoft Windows Active Directory due to improper validation of service principal names (SPN), which could result in SPN collisions. When this occurs, services that use the SPN will downgrade to NT LAN Manager (...
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 8305 Views

RISK: Medium Risk

Medium Risk

Microsoft IIS FTP Service Heap Buffer Overrun Vulnerability( 09 February 2011 )

A vulnerability exists in the FTP Service in Microsoft Internet Information Services (IIS) 7. and Microsoft Internet Information Services (IIS) 7.5. The vulnerability could allow remote code execution.
Last Update Date: 11 Feb 2011 Release Date: 9 Feb 2011 9803 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Encoded Character Vulnerability( 09 February 2011 )

A remote code execution vulnerability exists in the way that the Windows OpenType Compact Font Format (CFF) driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then...
Last Update Date: 9 Feb 2011 15:59 Release Date: 9 Feb 2011 8158 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Graphics Processing Overrun Vulnerability( 09 February 2011 )

A remote code execution vulnerability exists in the way that the Windows Shell graphics processor handles specially crafted thumbnail images. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on user. An attacker could...
Last Update Date: 9 Feb 2011 15:43 Release Date: 9 Feb 2011 8360 Views

RISK: Extremely High Risk

Extremely High Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 09 February 2011 )

CSS Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that Internet Explorer accesses memory while importing a Cascading Style Sheet that refers to itself recursively. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user...
Last Update Date: 9 Feb 2011 15:34 Release Date: 9 Feb 2011 8252 Views

RISK: High Risk

High Risk

IBM Lotus Notes "cai" URI and iCal Remote Code Execution Vulnerabilities

Two vulnerabilities have been identified in IBM Lotus Notes, which could be exploited by remote attackers to compromise a vulnerable system. 1. An input validation error when processing "cai" URIs, which could allow attackers to execute arbitrary code. 2. A buffer overflow...
Last Update Date: 8 Feb 2011 15:27 Release Date: 8 Feb 2011 8487 Views

RISK: High Risk

High Risk

IBM Lotus Domino Multiple Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in IBM Lotus Domino, which could be exploited by remote attackers to compromise a vulnerable server. 1. A stack overflow error related to MIME handling, which could be exploited by remote unauthenticated attackers to execute arbitrary code. 2. An...
Last Update Date: 8 Feb 2011 15:25 Release Date: 8 Feb 2011 8582 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, gain knowledge of sensitive information, cause a denial of service or execute arbitrary code. 1. A race condition within audio handling, which could...
Last Update Date: 7 Feb 2011 16:55 Release Date: 7 Feb 2011 8366 Views

RISK: High Risk

High Risk

HP OpenView Performance Insight Server Hiden Account Vulnerability

A vulnerability has been identified in HP OpenView Performance Insight Server, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused due to a hidden account present within the "com.trinagy.security....
Last Update Date: 2 Feb 2011 15:42 Release Date: 2 Feb 2011 8417 Views

RISK: High Risk

High Risk

Oracle Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Solaris, which could be exploited by attackers or malicious users to cause a denial of service, gain knowledge of sensitive information or take complete control of a vulnerable system. These issues are caused by errors in the...
Last Update Date: 1 Feb 2011 Release Date: 20 Jan 2011 10113 Views

RISK: High Risk

High Risk

Oracle Open Office and StarOffice/StarSuite Code Execution Vulnerabilities

Two vulnerabilities have been identified in Oracle Open Office and StarOffice/StarSuite, which could be exploited by attackers to compromise a vulnerable system.
Last Update Date: 1 Feb 2011 Release Date: 20 Jan 2011 9912 Views

RISK: High Risk

High Risk

Oracle Database Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Database, which could be exploited by attackers or malicious users to cause a denial of service, gain knowledge of sensitive information or execute arbitrary code. These issues are caused by errors in the Client System Analyzer, ...
Last Update Date: 1 Feb 2011 Release Date: 20 Jan 2011 9985 Views

RISK: Medium Risk

Medium Risk

HP OpenView Storage Data Protector Remote Code Execution Vulnerability

A vulnerability has been identified in HP OpenView Storage Data Protector, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an error when processing user-supplied data, which could allow remote unauthenticated attackers...
Last Update Date: 1 Feb 2011 Release Date: 21 Jan 2011 10039 Views

RISK: Medium Risk

Medium Risk

Trend Micro Control Manager "mrf.exe" Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Trend Micro Control Manager, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "mrf.exe" TMI service module when displaying...
Last Update Date: 1 Feb 2011 Release Date: 21 Jan 2011 10682 Views

RISK: High Risk

High Risk

Linksys WRT54GC Web Management Interface Buffer Overflow Vulnerability

A vulnerability has been identified in Linksys WRT54GC, which could be exploited by malicious people to take complete control of a vulnerable system. This issue is caused by a boundary error when handling HTTP POST requests sent to the web-based management interface. ...
Last Update Date: 1 Feb 2011 Release Date: 24 Jan 2011 9399 Views

RISK: High Risk

High Risk

Opera Browser "select" Element Children Integer Truncation Vulnerability

A vulnerability has been identified in Opera, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an integer truncation error within the Opera Internet Browser module "opera.dll" when handling a HTML...
Last Update Date: 1 Feb 2011 Release Date: 24 Jan 2011 9254 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to gain knowledge of sensitive information, perfom unauthorized actions, or compromise a vulnerable system. An integer truncation error when handling large form inputs, which could be exploited to execute...
Last Update Date: 1 Feb 2011 Release Date: 28 Jan 2011 8648 Views

RISK: Medium Risk

Medium Risk

OpenOffice.org Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by remote attackers to compromise a vulnerable system. A buffer overflow error when processing malformed TGA files, which could be exploited by attackers to execute arbitrary code by convincing a user...
Last Update Date: 1 Feb 2011 Release Date: 28 Jan 2011 8624 Views

RISK: Medium Risk

Medium Risk

Symantec Products Intel Alert Management System Vulnerabilities

Multiple vulnerabilities have been identified in various Symantec products, which could be exploited by remote attackers or malicious users to cause a denial of service or take complete control of a vulnerable system. These issues are caused by buffer overflow and input validation errors...
Last Update Date: 1 Feb 2011 Release Date: 28 Jan 2011 8765 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MHTML Information Disclosure Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an error in the way MHTML (MIME Encapsulation of Aggregate HTML) interprets MIME-formatted requests for content blocks within a...
Last Update Date: 1 Feb 2011 Release Date: 31 Jan 2011 8253 Views

RISK: High Risk

High Risk

RealPlayer AVI Header Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the "vidplin.dll" module when processing malformed header data, which could be exploited ...
Last Update Date: 31 Jan 2011 16:43 Release Date: 31 Jan 2011 8668 Views

RISK: Medium Risk

Medium Risk

Google Chrome and Chrome OS Multiple Memory Corruption Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome and Chrome OS, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. These issues are caused by input validation errors, invalid and dangling pointers, and memory corruptions related to extensions...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2011 8014 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Remote Code Execution Vulnerability

A vulnerability has been identified in BlackBerry Enterprise Server and BlackBerry Professional Software, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF files...
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2011 8005 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a format string error in the "nnmrptconfig.exe" CGI executable when parsing an invalid template...
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2011 8958 Views

RISK: Medium Risk

Medium Risk

Nokia Multimedia Player Playlist Handling Buffer Overflow Vulnerability

A vulnerability has been identified in Nokia Multimedia Player, which could be exploited by attackers to execute arbitrary code. This issue is caused by a buffer overflow error when processing playlists (e.g. ".npl") containing overly long data, which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2011 8053 Views

RISK: Medium Risk

Medium Risk

Microsoft Data Access Components Multiple Vulnerabilities

1. DSN Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Data Access Components validates third-party API usage. This vulnerability could allow code execution if a user visited a specially crafted Web page. If a user is logged on with administrative user...
Last Update Date: 28 Jan 2011 Release Date: 12 Jan 2011 7784 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Backup Manager Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Windows Backup Manager handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or...
Last Update Date: 28 Jan 2011 Release Date: 12 Jan 2011 7725 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Circular Memory References Use-after-free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a use-after-free error within the "mshtml.dll" library when handling circular references...
Last Update Date: 28 Jan 2011 Release Date: 6 Jan 2011 7990 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Rendering Engine Buffer Overflow Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to take complete control of a vulnerable system. This issue is caused by a stack overflow error in the "CreateSizedDIBSECTION()" function within the "shimgvw.dll" module when parsing a...
Last Update Date: 28 Jan 2011 Release Date: 5 Jan 2011 7825 Views

RISK: Medium Risk

Medium Risk

GIMP Multiple Vulnerabilities

Multiple vulnerabilities have been identified in GIMP, which could be exploited by attackers to execute arbitrary code. These issues are caused by buffer overflow errors in the Lighting Effects, Sphere Designer, GFIG, and PSP (Paint Shop Pro) file plugins when processing malformed files...
Last Update Date: 28 Jan 2011 Release Date: 5 Jan 2011 8303 Views

RISK: Medium Risk

Medium Risk

ImgBurn Insecure Library Loading Vulnerability

A vulnerability has been discovered in ImgBurn, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading libraries (e.g. dwmapi.dll) in an insecure manner. This can be...
Last Update Date: 28 Jan 2011 Release Date: 5 Jan 2011 7957 Views

RISK: Medium Risk

Medium Risk

VLC Media Player Real Demuxer File Handling Array Indexing Vulnerability

A vulnerability has been identified in VLC Media Player, which could be exploited by attackers to execute arbitrary code. This issue is caused by an array indexing error in the "Close()" and "DemuxAudioMethod1()" [modules/demux/real.c] functions within the...
Last Update Date: 28 Jan 2011 Release Date: 4 Jan 2011 8239 Views

RISK: Medium Risk

Medium Risk

Wireshark "dissect_enttec_dmx_data()" Buffer Overflow Vulnerability

A vulnerability has been identified in Wireshark, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error in the "dissect_enttec_dmx_data()" [epan/dissectors/packet-enttec.c] function...
Last Update Date: 28 Jan 2011 Release Date: 4 Jan 2011 8212 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the Fax Cover Page Editor (fxscover.exe) utility when processing a cover file ".cov" containing...
Last Update Date: 28 Jan 2011 Release Date: 28 Dec 2010 8152 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Remote Code Execution vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by the creation of uninitialized memory during a CSS function within Internet Explorer. It is possible under certain conditions for the memory to...
Last Update Date: 28 Jan 2011 Release Date: 24 Dec 2010 7854 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) FTP Buffer Overflow Vulnerability

A vulnerability has been identified in Microsoft Internet Information Services (IIS), which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "TELNET_STREAM_CONTEXT::OnSendData()" function within the protocol handler...
Last Update Date: 28 Jan 2011 Release Date: 23 Dec 2010 8246 Views

RISK: Medium Risk

Medium Risk

Microsoft WMI Administrative Tools Trusted Value Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft WMI Administrative Tools, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory trust error in the "WBEMSingleView.ocx" ActiveX control when using the parameter supplied via the "...
Last Update Date: 28 Jan 2011 Release Date: 23 Dec 2010 7999 Views

RISK: Medium Risk

Medium Risk

Opera Browser Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to manipulate or gain knowledge of certain information, or execute arbitrary code.1. An error when displaying security information or download dialogs, which could allow malicious web sites to display misleading...
Last Update Date: 28 Jan 2011 Release Date: 17 Dec 2010 8017 Views

RISK: Medium Risk

Medium Risk

Novell ZENworks Desktop Management Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Novell ZENworks Desktop Management, which could be exploited by remote attackers to take complete control of a vulnerable system.1. An uninitialized pointer in the "ZenRem32.exe" process when handling incoming connections to port 1761, which could...
Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2010 8275 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Remote Code Execution Vulnerability

A vulnerability has been identified in BlackBerry Enterprise Server and BlackBerry Professional Software, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF files...
Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2010 7882 Views

RISK: Medium Risk

Medium Risk

Citrix Access Gateway Legacy Authentication Command Injection Vulnerability

A vulnerability has been identified in Citrix Access Gateway, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an error in the NT4 and NTLM authentication components, which could allow an attacker to subvert the authentication...
Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2010 8162 Views

RISK: Medium Risk

Medium Risk

F-Secure Products Binary Loading Vulnerability

A vulnerability has been identified in F-Secure products, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error when loading binaries from the current working directory, which could allow attackers to execute arbitrary code by tricking...
Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2010 7930 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that the OpenType Font (OTF) driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, ...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7801 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Task Scheduler Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Task Scheduler improperly validates whether scheduled tasks run within the intended security context. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 8297 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Encoder Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7742 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Movie Maker Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Windows Movie Maker handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7828 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Netlogon RPC Null dereference DOS Vulnerability

A remote authenticated denial of service vulnerability exists in implementations of the Netlogon RPC Service on affected versions of Windows Server. An attacker who successfully exploited this vulnerability could cause affected versions of the Windows Server to restart.
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7963 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Internet Connection Signup Wizard Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that the Internet Connection Signup Wizard, a component of Microsoft Windows, handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7588 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel NDProxy Buffer Overflow Vulnerability

An elevation of privilege vulnerability exists in the Routing and Remote Access NDProxy component of the Windows kernel due to improper validation of input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7793 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerability

1. Win32k Buffer Overflow Vulnerability2. Win32k PFE Pointer Double Free Vulnerability3. Win32k Double Free Vulnerability4. Win32k Cursor Linking VulnerabilityAn elevation of privilege vulnerability exists due to the way that the Windows kernel-mode drivers free objects that are no longer in use. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7766 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Consent UI Impersonation Vulnerability

An elevation of privilege vulnerability exists in the way that the Consent User Interface (UI) improperly processes special values read from the registry. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7693 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Hyper-V VMBus Vulnerability

A vulnerability exists in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V that could allow denial of service if a specifically crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 8054 Views

RISK: Medium Risk

Medium Risk

Microsoft Office SharePoint Malformed Request Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Document Conversions Launcher Service validates SOAP requests before processing on a SharePoint server. An attacker who successfully exploited this vulnerability could run arbitrary code on an affected SharePoint server under the security context of a guest account.
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7639 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Address Book Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Windows Address Book handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7599 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows BranchCache Insecure Library Loading Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows opens specific files on platforms that do not support the BranchCache functionality. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7825 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities

1. HTML Object/Element Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7566 Views

RISK: Medium Risk

Medium Risk

Microsoft Microsoft Office Graphics Filters Multiple Vulnerabilities

1. CGM Image Converter Buffer Overrun VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office allocates buffer size when handling CGM image files. The vulnerability could allow remote code execution if a user opens an Office document containing a specially crafted CGM image. An...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7799 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Publisher Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Publisher parses Publisher files. An attacker could exploit the vulnerability by creating a specially crafted Publisher file that could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7692 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code.1. A bad validation for message deserialization on 64-bit builds.2. An error when handling a bad extension...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7779 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Infinite Loop Vulnerability

A denial of service vulnerability exists in the way that the Microsoft Exchange store processes specially crafted RPC calls. The vulnerable code path is only accessible to authenticated users. An authenticated attacker could exploit the vulnerability by sending a specially crafted network message to a computer running the...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 7796 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser engine when parsing malformed data...
Last Update Date: 28 Jan 2011 Release Date: 13 Dec 2010 8024 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which could be exploited by remote attackers to take complete control of a vulnerable system. These issues are caused by buffer and integer overflows, array indexing, memory corruptions, invalid memory access and zone validation errors related to RealMedia...
Last Update Date: 28 Jan 2011 Release Date: 13 Dec 2010 7932 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Client Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Novell iPrint Client, which could be exploited by remote attackers to execute arbitrary code. These issues are caused by buffer overflow errors related to Netscape/ActiveX "printer-state-reasons", "nipplib.dll", "call-back-...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2010 7795 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer CSS Import Rule Use-after-free Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a use-after-free error within the "mshtml.dll" library when processing a web...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2010 8187 Views