Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by local attackers to gain knowledge of sensitive information or by remote attackers to execute arbitrary code.1. Due to a heap overflow error when processing JP2 images, which could be exploited to compromise...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2010 8145 Views

RISK: Medium Risk

Medium Risk

Winamp MIDI File Processing Code Execution Vulnerability

A vulnerability has been identified in Winamp, which could be exploited by attackers to execute arbitrary code. This issue is caused by a memory corruption error in the "in_midi" module when processing malformed data within a MIDI file, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2010 8071 Views

RISK: Medium Risk

Medium Risk

Adobe Device Central & Pixel Bender Toolkit Insecure Library Loading Vulnerability

A vulnerability has been discovered in Adobe Device Central and Adobe Pixel Bender Toolkit, which can be exploited by malicious people to compromise a user's system.1. The vulnerability is caused due to the application loading libraries (e.g. ibfs32.dll...
Last Update Date: 28 Jan 2011 Release Date: 8 Dec 2010 8038 Views

RISK: Medium Risk

Medium Risk

VMware ESX Service Console Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by attackers to bypass security restrictions, disclose or manipulate information, cause a denial of service or execute arbitrary code. These issues are caused by errors in samba, bzip2 and OpenSSL.
Last Update Date: 28 Jan 2011 Release Date: 8 Dec 2010 7778 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware products, which could be exploited by remote attackers to execute arbitrary code, or by malicious users to gain elevated privileges on a host or guest system.1. Caused by a race condition within the "vmware-mount" ...
Last Update Date: 28 Jan 2011 Release Date: 6 Dec 2010 7836 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, cause a denial of service, or execute arbitrary code.1. Caused by an error which could allow a website to bypass the pop-up blocker....
Last Update Date: 28 Jan 2011 Release Date: 6 Dec 2010 7817 Views

RISK: Medium Risk

Medium Risk

ProFTPD HELP Command Injection Backdoor

A backdoor has been identified in ProFTPD, which could be exploited by remote unauthenticated attackers to take complete control of a vulnerable server. This issue results from the compromise of the main FTP server and sync mirrors of the project, and the inclusion of a backdoor into...
Last Update Date: 28 Jan 2011 Release Date: 3 Dec 2010 8472 Views

RISK: Medium Risk

Medium Risk

ClamAV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ClamAV, which could be exploited by attackers or malware to cause a denial of service or execute arbitrary code.1. The errors in the "libclamav/pdf.c" file, which could be exploited to crash an affected...
Last Update Date: 28 Jan 2011 Release Date: 3 Dec 2010 7797 Views

RISK: Medium Risk

Medium Risk

AWStats Remote Code Execution and Directory Traversal Vulnerabilities

Two vulnerabilities have been identified in AWStats, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable web server.1. An input validation error when specifying a configuration file directory on Windows, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 2 Dec 2010 8121 Views

RISK: Medium Risk

Medium Risk

Winamp Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which could be exploited by attackers to execute arbitrary code.1. A buffer and integer overflow errors in the "in_midi" module when processing malformed data, which could be exploited by attackers to compromise a vulnerable system....
Last Update Date: 28 Jan 2011 Release Date: 1 Dec 2010 8008 Views

RISK: Medium Risk

Medium Risk

McAfee VirusScan Enterprise Insecure Library Loading Vulnerability

A vulnerability has been identified in McAfee VirusScan Enterprise, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading libraries (e.g. traceapp.dll) in an insecure manner. This...
Last Update Date: 28 Jan 2011 Release Date: 30 Nov 2010 7833 Views

RISK: Medium Risk

Medium Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS for iPhone, iPod touch and iPad, which could be exploited by attackers to gain knowledge of sensitive information, bypass restrictions, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2010 8992 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions or execute arbitrary code. These issues are caused by design errors, invalid casts, memory corruptions, uninitialized pointers and memory, integer overflows and...
Last Update Date: 28 Jan 2011 Release Date: 22 Nov 2010 8093 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Client "GetDriverSettings()" Remote Stack Overflow Vulnerability

A vulnerability has been identified Novell iPrint Client, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the "ienipp.ocx" ActiveX component when processing data supplied via the "GetDriverSettings()" method, ...
Last Update Date: 28 Jan 2011 Release Date: 22 Nov 2010 7794 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader 9.4 (and earlier versions) for Windows, Macintosh and UNIX, and Adobe Acrobat 9.4 (and earlier 9.x versions) for Windows and Macintosh. These vulnerabilities could cause the application to crash...
Last Update Date: 28 Jan 2011 Release Date: 18 Nov 2010 7744 Views

RISK: Medium Risk

Medium Risk

VMware ESX / ESXi Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX/ESXi, which could be exploited by attackers to cause a denial of service or execute arbitrary code. These issues are caused by errors in COS kernel, likewisekrb5, likewiseopenldap, likewiseopen, and pamkrb5.
Last Update Date: 28 Jan 2011 Release Date: 17 Nov 2010 7811 Views

RISK: Medium Risk

Medium Risk

RealPlayer RealMedia Image Map Parsing Vulnerabilities

A vulnerability has been identified in RealPlayer which could be exploited by remote attackers to compromise a vulnerable system. The vulnerabilities are caused due to integer truncation errors when parsing image maps in RealMedia (.rm) files. This can be exploited to cause heap-based buffer...
Last Update Date: 28 Jan 2011 Release Date: 16 Nov 2010 7851 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by errors in AFP Server, ...
Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2010 8017 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Sorenson Video 3 Array-Indexing Vulnerability

A vulnerability have been identified in Apple QuickTime, could be exploited by remote attackers to compromise an affected system. An array-indexing error when parsing Sorenson Video 3 content and can be exploited to corrupt memory during decompression via a specially crafted file.
Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2010 7829 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Media Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Media Server, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.1. Due to an unspecified memory corruption error that could lead to arbitrary code execution....
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2010 7820 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Multiple Vulnerabilities( 10 November 2010 )

1. RTF Stack Buffer Overflow VulnerabilityA remote code execution vulnerability exists in the way that affected Microsoft Office software parses specially crafted Rich Text Format (RTF) data. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 10 Nov 2010 7662 Views

RISK: Medium Risk

Medium Risk

Microsoft Office PowerPoint Multiple Vulnerabilities( 10 November 2010 )

1. PowerPoint Parsing Buffer Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft PowerPoint handles specially crafted PowerPoint 95 files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Nov 2010 7752 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X ATSServer CFF Font Parsing Vulnerability

A vulnerability has been identified in Apple Mac OS X, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the Apple Type Services (ATS) when processing embedded CFF fonts, which could allow attackers...
Last Update Date: 28 Jan 2011 Release Date: 10 Nov 2010 8104 Views

RISK: Medium Risk

Medium Risk

Microsoft Forefront Unified Access Gateway Multiple Vulnerabilities( 10 November 2010 )

1. UAG Redirection Spoofing VulnerabilityA spoofing vulnerability exists in Forefront Unified Access Gateway (UAG). The vulnerability could allow spoofing or redirecting of traffic intended for the UAG server if a UAG user clicks a specially crafted link. An attacker could send a specially crafted URL to...
Last Update Date: 28 Jan 2011 Release Date: 10 Nov 2010 7841 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Code Execution and Information Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash and Flex, which could be exploited by attackers to disclose sensitive information or compromise a vulnerable system.These issues are caused by input validation and memory corruption errors when processing malformed Flash content, which could be exploited by attackers...
Last Update Date: 28 Jan 2011 Release Date: 8 Nov 2010 7896 Views

RISK: Medium Risk

Medium Risk

Google Chrome Memory Corruption and Use-after-free Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to execute arbitrary code.1. A use-after-free related to text editing.2. A memory corruption error when handling an overly large text area.3. ...
Last Update Date: 28 Jan 2011 Release Date: 5 Nov 2010 7871 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader "printSeps()" Heap Corruption Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a heap corruption error in the "EScript.api" plugin when processing the "printSeps()" function within a PDF...
Last Update Date: 28 Jan 2011 Release Date: 5 Nov 2010 8049 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer CSS Tag Parsing Code Execution Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused due to an invalid flag reference within the "mshtml.dll" module when processing a Cascading Style Sheets...
Last Update Date: 28 Jan 2011 Release Date: 4 Nov 2010 7762 Views

RISK: Medium Risk

Medium Risk

ProFTPD Remote Buffer Overflow and Directory Traversal Vulnerabilities

Two vulnerabilities have been identified in ProFTPD, which could be exploited by remote attackers to take complete control of an affected system.The first issue is caused by a stack overflow error in the "pr_netio_telnet_gets()" [src/netio.c] function when processing input containing...
Last Update Date: 28 Jan 2011 Release Date: 3 Nov 2010 7978 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions and buffer overflow errors in the "DIRAPI.dll" and "IML32.dll" modules when processing...
Last Update Date: 28 Jan 2011 Release Date: 1 Nov 2010 7932 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DAO 3.6 Object Library Insecure Library Loading Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system. The vulnerability is caused due to the Data Access Objects library (dao360.dll) loading libraries (e.g. msjet49.dll) in...
Last Update Date: 28 Jan 2011 Release Date: 1 Nov 2010 8619 Views

RISK: Medium Risk

Medium Risk

SonicWALL SSL-VPN Buffer Overflow Vulnerability

A vulnerability has been identified in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX Control, which could be exploited by remote attackers to compromise a vulnerable system. The vulnerability is caused due to a boundary error in the "Aventail.EPInstaller" ActiveX control...
Last Update Date: 28 Jan 2011 Release Date: 1 Nov 2010 7977 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Content Processing Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by an unspecified error when processing malformed Flash content, which could be exploited by attackers to compromise a vulnerable system by tricking a...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2010 7782 Views

RISK: Medium Risk

Medium Risk

Cisco Products Multiple Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which could be exploited by remote attackers to take complete control of a vulnerable system. These issues are caused by buffer overflow errors in the Cisco developed authentication code in the web server module of CiscoWorks Common Services when...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2010 7836 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader "authplay.dll" Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error in the "authplay.dll" module when processing malformed Flash content within a PDF document, ...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2010 7938 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox DOM Insertion Remote Code Execution Vulnerability

A vulnerability has been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by malicious web sites to execute arbitrary code. This issue is caused by a memory corruption error when handling "document.write()" methods and DOM insertion, which could allow...
Last Update Date: 28 Jan 2011 Release Date: 28 Oct 2010 8001 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player rcsL Chunk Memory Corruption Vulnerability

A vulnerability has been identified in Adobe Shockwave Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error in the Director (dirapi.dll) module when processing and calculating offsets while parsing "rcsL" ...
Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2010 7740 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Java Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote attackers or malicious users to execute arbitrary code.1. Amemory corruption error in Java's handling of applet window bounds, which could allow remote attackers to compromise a vulnerable...
Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2010 7884 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser engine when parsing malformed data...
Last Update Date: 28 Jan 2011 Release Date: 21 Oct 2010 7786 Views

RISK: Medium Risk

Medium Risk

Google Chrome Memory Corruption and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to bypass security restrictions, manipulate certain information or compromise a vulnerable system.1. Due to an unknown error related to autofill / autocomplete profile spamming.2. Due to a memory...
Last Update Date: 28 Jan 2011 Release Date: 21 Oct 2010 8005 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealNetworks RealPlayer, which could be exploited by remote attackers to compromise a vulnerable system.1. an invalid index when processing RealMedia .IVR file with malformed sample data, which could allow attackers to execute arbitrary code by tricking a user...
Last Update Date: 28 Jan 2011 Release Date: 19 Oct 2010 7809 Views

RISK: Medium Risk

Medium Risk

BlackBerry Enterprise Server and Professional Software Vulnerability

A vulnerability has been identified in BlackBerry Enterprise Server and BlackBerry Professional Software, which could be exploited by remote attackers to compromise a vulnerable server. This issue is caused by a buffer overflow error in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2010 7798 Views

RISK: Medium Risk

Medium Risk

Winamp File Processing Buffer and Integer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which could be exploited by attackers to cause a denial of service or execute arbitrary code.1. Due to an integer overflow error in the Matroska Demuxer (in_mkv.dll) when processing a malformed MKV files, which...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2010 7825 Views

RISK: Medium Risk

Medium Risk

Oracle Sun Java JDK / JRE / SDK Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which can be exploited by malicious users to cause a DoS (Denial of Service) and by malicious people to disclose potentially sensitive information, manipulate certain data, and compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2010 8313 Views

RISK: Medium Risk

Medium Risk

Oracle Sun Solaris Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Solaris, which can be exploited by malicious users to manipulate certain data or cause a DoS (Denial of Service) and by malicious people to disclose sensitive information, manipulate certain data, cause a DoS (Denial of Service), ...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2010 7903 Views

RISK: Medium Risk

Medium Risk

Oracle Sun StarOffice / StarSuite Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle Sun StarOffice and StarSuite, which could be exploited by remote attackers to compromise a vulnerable system, manipulate certain information or bypass restrictions.
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2010 7754 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could allow attackers to gain knowledge of certain information, manipulate data or execute arbitrary code.1. An error when handling CSS files, which could allow cross domain scripting attacks.2. An error when manipulating the...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7901 Views

RISK: Medium Risk

Medium Risk

Oracle Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle, which could allow attackers to execute arbitrary code.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7844 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType Font Multiple Vulnerabilities ( 13 October 2010 )

1. OpenType Font Parsing VulnerabilityAn elevation of privilege vulnerability exists in the way that the Windows OpenType Font (OTF) format driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7622 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Server 2008 R2 Permissions on New Cluster Disks Vulnerability ( 13 October 2010 )

A tampering vulnerability exists in the way the Failover Cluster Manager user interface handles permissions on shared cluster disks. This vulnerability exists because the Failover Cluster Manager uses unsecured default permissions when adding disks to a cluster. When an administrator adds a disk to a shared cluster, ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7584 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TLSv1 Denial of Service Vulnerability ( 13 October 2010 )

A denial of service vulnerability exists in the way that SChannel processes client certificates in implementations of Internet Information Services (IIS) 7. on Windows Server 2008 and Windows Vista, and in IIS 7.5 on Windows Server 2008 R2 and Windows 7. A remote...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7596 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LPC Message Buffer Overrun Vulnerability ( 13 October 2010 )

An elevation of privilege vulnerability exists in the Remote Procedure Call Subsystem (RPCSS) running in the context of the NetworkService account, where a local application can use LPC to request that the LPC server connect back to the client using LRPC. This request could contain specially...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7645 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player Memory Corruption Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows Media Player deallocates objects during a reload operation via a Web browser. This vulnerability could allow code execution if a user visits a specially crafted Web page. If a user is logged on with administrative user...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7650 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player RTSP Use After Free Vulnerability ( 13 October 2010 )

A vulnerability exists in Microsoft Windows Media Player Network Sharing Service that could allow a remote user to send a specially crafted network packet to an instance of the application's network streaming service and cause remote code execution in the context of the current application.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7815 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MFC Document Title Updating Buffer Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that window titles are managed in applications written using the Microsoft Foundation Class (MFC) Library. While the vulnerability is located in MFC and is present on affected operating systems, it can only be exploited if a remote...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7696 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Embedded OpenType Font Integer Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that Microsoft Windows Embedded OpenType (EOT) font technology parses certain tables in specially crafted embedded fonts. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7602 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Mode Drivers Multiple Vulnerabilities ( 13 October 2010 )

1. Win32k Reference Count VulnerabilityAn elevation of privilege vulnerability exists due to the way that the Windows kernel-mode drivers maintain the reference count for an object. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7744 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities ( 13 October 2010 )

1. HTML Sanitization VulnerabilityAn information disclosure vulnerability exists in the way that HTML is filtered that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user.2. HTML Sanitization VulnerabilityAn information disclosure vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7552 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows COM Validation Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows Shell and WordPad validate COM object instantiation. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7514 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Common Control Library Heap Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows common control library renders specially crafted Web sites when using a third-party scalable vector graphics (SVG) viewer. This vulnerability could allow code execution if a user visited a specially crafted Web page. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7547 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities ( 13 October 2010 )

1. Excel Record Parsing Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7531 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Vulnerabilities ( 13 October 2010 )

1. Word Uninitialized Pointer VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Word handles an uninitialized pointer when parsing a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7971 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework x64 JIT Compiler Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the Microsoft .NET Framework that can allow a specially crafted Microsoft .NET application to access memory in an unsafe manner, leading to arbitrary unmanaged code execution. This vulnerability only affects the x64 and Itanium architectures.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7719 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 13 October 2010 )

1. AutoComplete Information Disclosure VulnerabilityAn information disclosure vulnerability exists that potentially allows form data within Internet Explorer to be captured via the AutoComplete feature. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 7625 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Title Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Foxit Reader, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error when attempting to set the window title text and can be exploited to cause a stack-...
Last Update Date: 28 Jan 2011 Release Date: 7 Oct 2010 7975 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system, or by local attackers to gain elevated privileges. These issues are caused by memory corruptions, array-indexing...
Last Update Date: 28 Jan 2011 Release Date: 6 Oct 2010 8034 Views

RISK: Medium Risk

Medium Risk

Novell iManager Tomcat Remote File Upload Vulnerability

A vulnerability has been identified in Novell iManager, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by access and input validation errors in the "nps.jar" web application when handling uploaded files via the...
Last Update Date: 28 Jan 2011 Release Date: 4 Oct 2010 7758 Views

RISK: Medium Risk

Medium Risk

Sun Solaris XServer FreeType CFF Font Parsing Vulnerability

A vulnerability has been identified in Sun Solaris and OpenSolaris, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error in the FreeType library used by Xserver.
Last Update Date: 28 Jan 2011 Release Date: 30 Sep 2010 7691 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ASP.NET Padding Oracle Vulnerability ( 29 September 2010 )

An information disclosure vulnerability exists in ASP.NET due to improper error handling during encryption padding verification. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for...
Last Update Date: 28 Jan 2011 Release Date: 29 Sep 2010 8114 Views

RISK: Medium Risk

Medium Risk

Nero Products Insecure Library Loading Vulnerabilities

Multiple vulnerabilities have been identified in Nero, which could be exploited by malicious people to compromise a user's system.1. Due to certain bundled applications loading various libraries in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user...
Last Update Date: 28 Jan 2011 Release Date: 29 Sep 2010 8043 Views

RISK: Medium Risk

Medium Risk

VMware ACE Management Server Two Vulnerabilities

Two vulnerabilities have been identified in VMware ACE Management Server (AMS), which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 27 Sep 2010 7710 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system.1. An error in Flash. 2. A bad cast with malformed SVGs.3. A buffer mismanagement error in the SPDY protocol.4...
Last Update Date: 28 Jan 2011 Release Date: 21 Sep 2010 7421 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Google Chrome, which could be exploited by attackers to bypass restrictions, crash an affected browser or compromise a vulnerable system. These issues are caused by use-after-free and input validation errors, and race conditions related to document APIs...
Last Update Date: 28 Jan 2011 Release Date: 16 Sep 2010 7460 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Uniscribe Font Parsing Engine Memory Corruption Vulnerability ( 15 September 2010 )

A remote code execution vulnerability exists in affected versions of Microsoft Windows and Microsoft Office. The vulnerability exists because Windows and Office incorrectly parse specific font types in such a way that could allow remote code execution. An attacker who successfully exploited this vulnerability could run arbitrary code...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7286 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows WordPad Word 97 Text Converter Memory Corruption Vulnerability ( 15 September 2010 )

A remote code execution vulnerability exists in the way that Microsoft WordPad processes memory when parsing a specially crafted Word 97 document. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed structure.
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7234 Views

RISK: Medium Risk

Medium Risk

Samba SID Parsing Buffer Overflow Vulnerability

A vulnerability has been identified in Samba, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "sid_parse()" function and the related "dom_sid_parse()" function in the source4 code when reading a...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7507 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MPEG-4 Codec Vulnerability ( 15 September 2010 )

A remote code execution vulnerability exists in the way that the MPEG-4 codec handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker who...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7407 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows RPC Memory Corruption Vulnerability ( 15 September 2010 )

An unauthenticated remote code execution vulnerability exists in the way that the Remote Procedure Call (RPC) client implementation allocates memory when parsing specially crafted RPC responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7451 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows CSRSS Local Elevation of Privilege Vulnerability ( 15 September 2010 )

An elevation of privilege vulnerability exists in the Windows CSRSS due to the way that the CSRSS assigns memory for specific user transactions. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7473 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IIS Multiple Vulnerabilities ( 15 September 2010 )

1. IIS Repeated Parameter Request Denial of Service VulnerabilityA denial of service vulnerability exists in Internet Information Services (IIS) that could allow an attacker who successfully exploited this vulnerability to interrupt service, causing the server to become un-responsive. An attacker could exploit the...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 8437 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LSASS Heap Overflow Vulnerability ( 15 September 2010 )

An authenticated elevation of privilege vulnerability exists in Microsoft Windows due to the way that the Local Security Authority Subsystem Service (LSASS) improperly handles certain Lightweight Directory Access Protocol (LDAP) messages. The vulnerability exists in implementations of Active Directory, Active Directory Application Mode (...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7406 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Heap Based Buffer Overflow in Outlook Vulnerability ( 15 September 2010 )

A remote code execution vulnerability exists in the way that Microsoft Outlook parses content in a specially crafted e-mail message. This vulnerability exists only in configurations where Outlook connects to an Exchange Server in Online Mode. Configurations where Outlook connects to an Exchange Server in the...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7453 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Print Spooler Service Impersonation Vulnerability ( 15 September 2010 )

A remote code execution vulnerability exists in the Windows Print Spooler service that could allow a remote, unauthenticated attacker to execute arbitrary code on an affected Windows XP system. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 7716 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by attackers to compromise a vulnerable system. This vulnerability is exploited in the wild.
Last Update Date: 28 Jan 2011 Release Date: 14 Sep 2010 7729 Views

RISK: Medium Risk

Medium Risk

Apple iOS for iPhone and iPod touch Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS for iPhone and iPod touch, which could be exploited by attackers to disclose sensitive information, bypass security restrictions or compromise an affected system. These issues are caused by errors in VoiceOver, FaceTime, ImageIO, and WebKit, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2010 7744 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to compromise a vulnerable system.1. Due to an input validation error in WebKit's handling of floating point data types, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2010 7410 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser engine when parsing malformed data, ...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2010 7396 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat / Reader SING Font Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "CoolType.dll" module when processing a PDF document containing malformed SING (Smart...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2010 7678 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to bypass security restrictions, manipulate certain information or compromise a vulnerable system.1. A memory corruption error related to focus handling, which could be exploited to execute arbitrary code.2...
Last Update Date: 28 Jan 2011 Release Date: 6 Sep 2010 7498 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which could be exploited by attackers to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by errors in WebKit.
Last Update Date: 28 Jan 2011 Release Date: 3 Sep 2010 7453 Views

RISK: Medium Risk

Medium Risk

VMware ESX Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in VMware ESX, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in cpio, tar, samba, krb5 and...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2010 7482 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime "QTPlugin.ocx" Trusted Parameter Value Vulnerability

A vulnerability has been identified in Apple QuickTime, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory trust error in the "QTPlugin.ocx" plugin when using the "_Marshaled_pUnk" parameter value as a pUnknown...
Last Update Date: 28 Jan 2011 Release Date: 1 Sep 2010 7453 Views

RISK: Medium Risk

Medium Risk

RealPlayer Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in RealPlayer, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. A memory corruption error when processing IVR files containing a malformed data header, which could allow attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 30 Aug 2010 7493 Views

RISK: Medium Risk

Medium Risk

Trend Micro Internet Security Pro 2010 "UfPBCtrl.dll" ActiveX Control Vulnerability

A vulnerability has been identified in Trend Micro Internet Security Pro, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "extSetOwner()" function within the "UfPBCtrl.dll" ActiveX control when processing user...
Last Update Date: 28 Jan 2011 Release Date: 27 Aug 2010 7563 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by errors in ATS, CFNetwork, ...
Last Update Date: 28 Jan 2011 Release Date: 26 Aug 2010 7475 Views

RISK: Medium Risk

Medium Risk

Insecure Library Loading Vulnerabilities

A remote attack vector for a class of vulnerabilities that affects how applications load external libraries has been identified in various applications, which could be exploited by attackers to remotely execute arbitrary code in the context of the user running the vulnerable application when the user opens a file...
Last Update Date: 28 Jan 2011 Release Date: 26 Aug 2010 7717 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions and integer overflow errors when processing malformed Shockwave or Director files, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 26 Aug 2010 7519 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Memory Corruption and Spoofing Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to manipulate certain information or compromise a vulnerable system. These issues are caused by memory corruptions and input validation errors related to file dialog, SVGs, text editing, history, MIME type...
Last Update Date: 28 Jan 2011 Release Date: 23 Aug 2010 7520 Views

RISK: Medium Risk

Medium Risk

SonicWALL E-Class SSL-VPN ActiveX Control Format String Vulnerability

A vulnerability has been identified in SonicWALL E-Class SSL-VPN, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a format string error in the Endpoint Interrogator/Installer ActiveX control (epi.dll) when...
Last Update Date: 28 Jan 2011 Release Date: 23 Aug 2010 7719 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Error Logging Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Apple QuickTime, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a stack overflow error within QuickTime's error logging feature when processing a malformed movie file, which could be exploited by attackers...
Last Update Date: 28 Jan 2011 Release Date: 16 Aug 2010 7529 Views