Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Palm Pre webOS vCard Processing Code Execution Vulnerability

A vulnerability has been identified in Palm Pre webOS, which could be exploited by remote attackers to take complete control of a vulnerable device. This issue is caused by an error when processing messages including a specially crafted electronic business card (vCard), which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 16 Aug 2010 7619 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by attackers to bypass security restrictions or compromise a vulnerable system.1. A heap overflow error when performing some painting operations on a HTML5 canvas while certain transformations are being applied, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2010 7574 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player and AIR Multiple Code Execution Vulnerabilities

Multiple vulnerabilitieshave been identified in Adobe Flash and AIR, which could be exploited by attackers to disclose sensitive information or compromise a vulnerable system.1. Due to a memory corruption error in the ActionScript Virtual Machine 1 (AVM1) when processing the "ActionPush" command...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2010 7511 Views

RISK: Medium Risk

Medium Risk

Google Chrome Flash Plugin Vulnerabilities

Multiple vulnerabilitieshave been identified in Google Chrome, which could be exploited by attackers to disclose sensitive information or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2010 7667 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Media Server Multiple Code Execution and DoS Vulnerabilities

Multiple vulnerabilitieshave been identified in Adobe Flash Media Server, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. Due to an unspecified error related to a JS method, which could allow denial of service attacks.2...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2010 7544 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Tracing Feature for Services Multiple Vulnerabilities ( 11 August 2010 )

1. Tracing Registry Key ACL VulnerabilityAn elevation of privilege vulnerability exists when Windows places incorrect access control lists (ACLs) on the registry keys for the Tracing Feature for Services. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7372 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities ( 11 August 2010 )

1. Windows Kernel Data Initialization VulnerabilityAn elevation of privilege vulnerability exists in the Windows Kernel due to the way the kernel deals with specific thread creation attempts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7287 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities ( 11 August 2010 )

1. Win32k Bounds Checking VulnerabilityA denial of service vulnerability exists in the Windows kernel-mode drivers due to the improper validation of an argument passed to a system call. An attacker could exploit the vulnerability by running a specially crafted application causing the system to become unresponsive...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7355 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Networking Multiple Vulnerabilities ( 11 August 2010 )

1. IPv6 Memory Corruption VulnerabilityA denial of service vulnerability exists in TCP/IP processing in Microsoft Windows due to an error in the processing of specially crafted IPv6 packets with a malformed extension header. An attacker could exploit the vulnerability by sending the target system a small...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7256 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Server Multiple Vulnerabilities ( 11 August 2010 )

1. SMB Pool Overflow VulnerabilityAn unauthenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7753 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Secure Channel (SChannel) Multiple Vulnerabilities ( 11 August 2010 )

1. TLS/SSL Renegotiation VulnerabilityA spoofing vulnerability exists in the TLS/SSL protocol, implemented in the Microsoft Windows SChannel authentication component. An attacker who successfully exploited this vulnerability would be able to introduce information on a TLS/SSL protected connection, effectively sending traffic...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7460 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Shell Shortcut Icon Loading Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in affected versions of Microsoft Windows. The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7468 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Vulnerabilities ( 11 August 2010 )

1. Word Record Parsing VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office Word handles malformed records inside a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7408 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in the way that Microsoft DirectShow MP3 filter handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted audio file. If a user is logged on with administrative user rights, an attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7375 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in the way that Microsoft XML Core Services handles HTTP responses. The vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7570 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 11 August 2010 )

1. Event Handler Cross-Domain VulnerabilityAn information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7319 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Memory Corruption Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7310 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Movie Maker Memory Corruption Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in the way that Windows Movie Maker handles specially crafted project files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7362 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Common Language Runtime and Silverlight Multiple Vulnerabilities ( 11 August 2010 )

1. Microsoft Silverlight Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Silverlight handles pointers. The vulnerability could allow remote code execution if a user visit a specially crafted Web site that contains Silverlight content.2. Microsoft Silverlight and Microsoft .NET...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7449 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Cinepak Codec Decompression Vulnerability ( 11 August 2010 )

A remote code execution vulnerability exists in the way the Cinepak codec handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 7601 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Compact Font Format Memory Corruption Vulnerability

A vulnerability has been identified in Foxit Reader, which could be exploited by attackers to potentially compromise a vulnerable system. This issue is caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 9 Aug 2010 7656 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Font Parsing Integer Overflow Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by attackers to potentially compromise a vulnerable system. This issue is caused by an integer overflow error in the "CoolType.dll" module when processing a PDF document containing a TrueType Font...
Last Update Date: 28 Jan 2011 Release Date: 5 Aug 2010 8033 Views

RISK: Medium Risk

Medium Risk

OpenOffice.org Impress File Processing Buffer Overflow Vulnerabilities

Two vulnerabilitieshave been identified in OpenOffice.org, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by buffer overflow errors in Impress when processing malformed documents, which could be exploited by attackers to crash an affected application or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 5 Aug 2010 7501 Views

RISK: Medium Risk

Medium Risk

Apple iOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iOS for iPhone, iPad and iPod, which could be exploited by remote attackers to take complete control of a vulnerable device.1. Caused by a memory corruption error when processing Compact Font Format (CFF) data within a...
Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2010 8374 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Client Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell iPrint Client, which could be exploited by remote attackers to manipulate certain data or compromise a vulnerable system.1. An unspecified error exists in the browser plugin when parsing parameter names.2. A boundary error in the ActiveX...
Last Update Date: 28 Jan 2011 Release Date: 2 Aug 2010 7418 Views

RISK: Medium Risk

Medium Risk

IBM Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IBM Java, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 30 Jul 2010 7606 Views

RISK: Medium Risk

Medium Risk

Apple Safari Code Execution and Information Disclosure Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by memory corruptions, use-after-free and information disclosure errors related to RSS feeds, AutoFill...
Last Update Date: 28 Jan 2011 Release Date: 30 Jul 2010 7856 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes File Parsing Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in IBM Lotus Notes, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by errors in the Autonomy Keyview.
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2010 7556 Views

RISK: Medium Risk

Medium Risk

Symantec Products File Parsing Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in various Symantec products, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in the Autonomy Keyview Filter.
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2010 7702 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. An unspecified error in the layout code can be exploited to disclose memory content....
Last Update Date: 28 Jan 2011 Release Date: 28 Jul 2010 7521 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Streaming Debug Error Logging Buffer Overflow Vulnerability

A vulnerability has been identified in Apple QuickTime, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a boundary error in QuickTimeStreaming.qtx when constructing a string to write to a debug log file. and cause a stack-...
Last Update Date: 28 Jan 2011 Release Date: 27 Jul 2010 7491 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser engine when parsing malformed data, ...
Last Update Date: 28 Jan 2011 Release Date: 22 Jul 2010 7521 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Buffer Overflow Vulnerabilities

Two vulnerabilitieshave been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a buffer overflow error in the "nnmrptconfig.exe" CGI executable when processing an overly long parameter...
Last Update Date: 28 Jan 2011 Release Date: 22 Jul 2010 7747 Views

RISK: Medium Risk

Medium Risk

Apple iTunes "itpc:" URL Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Apple iTunes, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed "itpc:" URLs, which could be exploited by attackers to crash an affected application...
Last Update Date: 28 Jan 2011 Release Date: 21 Jul 2010 7501 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Shell Shortcut Handling Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers or malware to compromise an affected system. This issue is caused by an error in the Windows Shell component when parsing shortcuts (*.LNK files), which could allow attackers to automatically execute a...
Last Update Date: 28 Jan 2011 Release Date: 19 Jul 2010 7449 Views

RISK: Medium Risk

Medium Risk

Sun Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Sun products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, bypass security restrictions, or execute arbitrary code.These issues are caused by...
Last Update Date: 28 Jan 2011 Release Date: 16 Jul 2010 7890 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to cause a denial of service, disclose sensitive information or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7571 Views

RISK: Medium Risk

Medium Risk

Winamp Player FLV Data Processing Integer Overflow Vulnerabilities

Multiple vulnerabilitieshave been identified in Winamp, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by integer and buffer overflow errors within the "vp6.w5s" component when parsing malformed Flash Video data, which could allow attackers to execute...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7538 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Canonical Display Driver Integer Overflow Vulnerability ( 14 July 2010 )

An unauthenticated remote code execution vulnerability exists in the way that the Microsoft Canonical Display Driver (cdd.dll) parses information copied from user mode to kernel mode. Although it is possible that the vulnerability could allow code execution, successful code execution is unlikely due to...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7573 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Help Center URL Validation Vulnerability ( 14 July 2010 )

An unauthenticated remote code execution vulnerability exists in the way that the Microsoft Help and Support Center validates specially crafted URLs. This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser or clicks a specially crafted link in an...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7354 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Access ActiveX Controls Multiple Vulnerabilities ( 14 July 2010 )

1. Access ActiveX Control VulnerabilityA remote code execution vulnerability exists in Access ActiveX controls due to the way that multiple ActiveX controls are loaded by Internet Explorer. An attacker who successfully exploited this vulnerability could run arbitrary code as the logged-on user. If a user...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7433 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook SMB Attachment Vulnerability( 14 July 2010 )

A remote code execution vulnerability exists in the way that Microsoft Office Outlook verifies attachments in a specially crafted e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2010 7336 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Google Chrome, which could be exploited by attackers to gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. An unspecified error related to WebGL can be exploited to trigger an OOB read.2...
Last Update Date: 28 Jan 2011 Release Date: 6 Jul 2010 7564 Views

RISK: Medium Risk

Medium Risk

Kingsoft Office 2010 Document Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Kingsoft Office 2010, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed Writer documents, which could be exploited by attackers to execute arbitrary commands by tricking a...
Last Update Date: 28 Jan 2011 Release Date: 30 Jun 2010 7613 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by memory corruptions, invalid pointers, uninitialized memory, array-indexing and use-after...
Last Update Date: 28 Jan 2011 Release Date: 30 Jun 2010 7906 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. An input validation error related to "application/json" responses, which could allow cross site scripting attacks....
Last Update Date: 28 Jan 2011 Release Date: 28 Jun 2010 7497 Views

RISK: Medium Risk

Medium Risk

HP-UX Kerberos Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in Kerberos. .
Last Update Date: 28 Jan 2011 Release Date: 25 Jun 2010 7615 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser and JavaScript engines when parsing malformed...
Last Update Date: 28 Jan 2011 Release Date: 24 Jun 2010 7607 Views

RISK: Medium Risk

Medium Risk

Apple iPhone and iPod touch iOS Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple iPhone and iPod touch iOS, which could be exploited by attackers to disclose sensitive information, bypass security restrictions or compromise an affected system.1. An security issue is caused due to the Application Sandbox not properly restricting access to the...
Last Update Date: 28 Jan 2011 Release Date: 23 Jun 2010 7799 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Opera, which could be exploited by attackers to bypass security restrictions or compromise a vulnerable system. These issues are caused by unspecified errors, which could allow attackers to bypass certain restrictions, disclose sensitive information or execute arbitrary code.
Last Update Date: 28 Jan 2011 Release Date: 22 Jun 2010 7497 Views

RISK: Medium Risk

Medium Risk

Novell Access Manager Administration Console File Upload Vulnerability

A vulnerability has been identified in Novell Access Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by access and input validation errors in the "PortalModuleInstallManager" component within the Admin Console on Windows when handling uploaded files, ...
Last Update Date: 28 Jan 2011 Release Date: 18 Jun 2010 7506 Views

RISK: Medium Risk

Medium Risk

Novell NetWare "CIFS.NLM" SMB Request Buffer Overflow Vulnerability

A vulnerability has been identified in Novell NetWare, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "CIFS.NLM" driver when processing SMB "Sessions Setup AndX" packets containing an...
Last Update Date: 28 Jan 2011 Release Date: 18 Jun 2010 7582 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iTunes, which could be exploited by remote attackers to obtain sensitive information, bypass security restrictions or compromise a vulnerable system.1. A heap overflow error within the handling of images with an embedded ColorSync profile, which could be...
Last Update Date: 28 Jan 2011 Release Date: 18 Jun 2010 7563 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to conduct cross-site scripting attacks, bypass certain security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnrable system.1. The CUPS web...
Last Update Date: 28 Jan 2011 Release Date: 17 Jun 2010 7702 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to conduct cross-site scripting attacks, bypass certain security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnrable system.1. The CUPS web...
Last Update Date: 28 Jan 2011 Release Date: 17 Jun 2010 7609 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Buffer Overflow Vulnerabilities

Two vulnerabilities have been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system.1. A buffer overflow error within the "ovwebsnmpsrv.exe" process (invoked via the "jovgraph.exe...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2010 7503 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Help and Support Center Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system.1. An error in the "MPC::HTML::UrlUnescapeW()" function within the Help and Support Center application (helpctr.exe) that does...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2010 7377 Views

RISK: Medium Risk

Medium Risk

CA PSFormX and WebScan ActiveX Controls Multiple Vulnerabilities

Multiple vulnerabilities have been identified in CA PSFormX and WebScan ActiveX controls, which could be exploited by remote attackers to comrpromise an affected system. These issues are caused by input validation errors when processing user-supplied parameters, which could be exploited to execute arbitrary code by...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2010 7627 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, disclose potentially sensitive information, or potentially compromise a vulnerable system.1. An unspecified error exists related to cross...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2010 7560 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows OpenType CFF Font Driver Memory Corruption Vulnerability ( 09 June 2010 )

An elevation of privilege vulnerability exists in the Windows OpenType Compact Font Format (CFF) driver due to improper validation of certain data passed from user mode to kernel mode. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7354 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities ( 09 June 2010 )

1. Win32k Improper Data Validation VulnerabilityAn elevation of privilege vulnerability exists because the Windows kernel-mode drivers do not properly validate changes in certain kernel objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7442 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Decompression Multiple Vulnerabilities ( 09 June 2010 )

1. Media Decompression VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Windows handles media files. This vulnerability could allow remote code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 8106 Views

RISK: Medium Risk

Medium Risk

Microsoft Office COM Validation Vulnerability ( 09 June 2010 )

A remote code execution vulnerability exists in the way that affected Microsoft Office software validates COM object instantiation. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7353 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities( 09 June 2010 )

1. Excel Record Parsing Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7319 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities( 09 June 2010 )

1. Help.aspx XSS VulnerabilityA cross-site scripting and spoofing vulnerability exists in Microsoft Windows SharePoint Services 3. and Microsoft Office SharePoint Server 2007 that could allow an attacker to convince a user to run a malicious script. An attacker who successfully exploited the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7452 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ActiveX Multiple Vulnerabilities ( 09 June 2010 )

1. Microsoft Data Analyzer ActiveX Control Vulnerability A remote code execution vulnerability exists in the Microsoft Data Analyzer ActiveX Control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7264 Views

RISK: Medium Risk

Medium Risk

Microsoft IIS Authentication Memory Corruption Vulnerability( 09 June 2010 )

A remote code execution vulnerability exists in Internet Information Services (IIS). The vulnerability is due to improper parsing of authentication information. An attacker who successfully exploited this vulnerability could execute code in the context of the Worker Process Identity (WPI).
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7722 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 09 June 2010 )

1. Cross-Domain Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that Internet Explorer caches data and incorrectly allows the cached content to be called, potentially bypassing Internet Explorer domain restriction. An attacker could exploit the vulnerability by constructing a specially crafted Web...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7429 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions or compromise an affected system. These issues are caused by use-after-free, double free, integer truncation, heap overflow, memory corruption...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7920 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework XML Signature HMAC Truncation Authentication Bypass Vulnerability( 09 June 2010 )

A data tampering vulnerability exists in the Microsoft .NET Framework that could allow an attacker to tamper with signed XML content without being detected. In custom applications, the security impact depends on the specific usage scenario. Scenarios in which signed XML messages are transmitted over a...
Last Update Date: 28 Jan 2011 Release Date: 9 Jun 2010 7676 Views

RISK: Medium Risk

Medium Risk

OpenOffice.org Code Execution and Security Bypass Vulnerabilities

Two vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to bypass security restrictions or compromise a vulnerable system.1. An error when using the built-in scripting IDE to explore python code, which could allow attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 8 Jun 2010 7600 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player SWF Data Processing Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing malformed data within a SWF file, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 7 Jun 2010 7736 Views

RISK: Medium Risk

Medium Risk

Adobe InDesign CS3 INDD File Handling Buffer Overflow Vulnerability

A vulnerability has been identified in Adobe InDesign CS3, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed INDD files, which could be exploited by attackers to execute arbitrary code by tricking a...
Last Update Date: 28 Jan 2011 Release Date: 7 Jun 2010 7751 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat "authplay.dll" Code Execution Vulnerability

A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the "authplay.dll" library when processing a PDF document including malformed Flash content...
Last Update Date: 28 Jan 2011 Release Date: 7 Jun 2010 7943 Views

RISK: Medium Risk

Medium Risk

F5 BIG-IP Kerberos and OpenSSL Vulnerabilities

Multiple vulnerabilities have been identified in F5 BIG-IP, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in Kerberos and OpenSSL.
Last Update Date: 28 Jan 2011 Release Date: 4 Jun 2010 7791 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory Buffer Overflow and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.1. An error in NDSD when processing a bad verb, which could be exploited to crash an affected daemon....
Last Update Date: 28 Jan 2011 Release Date: 4 Jun 2010 7713 Views

RISK: Medium Risk

Medium Risk

VMware vMA and ESX Products krb5 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware vMA and various ESX products krb5, which could be exploited by attackers to disclose sensitive information, cause a denial of service, or compromise an affected system.1. Some vulnerabilities are caused due to integer underflows within the AES...
Last Update Date: 28 Jan 2011 Release Date: 31 May 2010 7677 Views

RISK: Medium Risk

Medium Risk

Adobe Photoshop CS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Photoshop CS, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by errors when processing malformed ".ASL", ".ABR", or ".GRD" files, which could be exploited by attackers to execute...
Last Update Date: 28 Jan 2011 Release Date: 28 May 2010 7566 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to bypass security restrictions, spoof the URL, or compromise a vulnerable system.1. An error related to URL canonicalization.2. An unspecified error which could allow attackers to spoof...
Last Update Date: 28 Jan 2011 Release Date: 28 May 2010 7566 Views

RISK: Medium Risk

Medium Risk

rpc.pcnfsd Syslog Format String Vulnerability

A vulnerability has been identified in HP-UX, SGI IRIX, IBM AIX and VIOS which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an integer overflow error in the "rpc.pcnfsd...
Last Update Date: 28 Jan 2011 Release Date: 25 May 2010 7720 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Java Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple Mac OS X, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system. These issues are caused by errors in Java.
Last Update Date: 28 Jan 2011 Release Date: 20 May 2010 7541 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by memory corruptions, integer and buffer overflows, array indexing, and signedness errors when processing malformed Shockwave or Director files, ...
Last Update Date: 28 Jan 2011 Release Date: 13 May 2010 7481 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system.1. A format string error within the "ovet_demandpoll.exe" process (invoked via the "webappmon.exe...
Last Update Date: 28 Jan 2011 Release Date: 13 May 2010 7881 Views

RISK: Medium Risk

Medium Risk

IrfanView PSD Image Parsing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in IrfanView, which could be exploited by attackers to compromise a vulnerable system.1. A sign-extension error when parsing certain PSD images can be exploited to cause a heap-based buffer overflow by tricking a user into opening a...
Last Update Date: 28 Jan 2011 Release Date: 13 May 2010 7510 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook Express and Windows Mail Integer Overflow Vulnerability( 12 May 2010 )

An unauthenticated remote code execution vulnerability exists in the way that Windows Mail Client handles specially crafted mail responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted response to a client initiating a connection...
Last Update Date: 28 Jan 2011 Release Date: 12 May 2010 7844 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Basic for Applications VBE6.DLL Stack Memory Corruption Vulnerability( 12 May 2010 )

A remote code execution vulnerability exists in the way that Microsoft Visual Basic for Applications searches for ActiveX controls. This vulnerability could allow remote code execution if a host application opens and passes a specially crafted file to the Visual Basic for Applications runtime. If a user is...
Last Update Date: 28 Jan 2011 Release Date: 12 May 2010 7563 Views

RISK: Medium Risk

Medium Risk

Apple Safari "parent.close()" Code Execution Vulnerability

A vulnerability has been identified in Apple Safari, which could be exploited by attackers to compromise a vulnerable system.The vulnerability is caused due to an error in the handling of parent windows and can result in a function call using an invalid pointer. This can be...
Last Update Date: 28 Jan 2011 Release Date: 10 May 2010 7436 Views

RISK: Medium Risk

Medium Risk

Adobe Photoshop CS4 TIFF Handling Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Photoshop CS4, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by buffer overflow errors when processing malformed ".TIFF" files, which could be exploited by attackers to crash an affected application or...
Last Update Date: 28 Jan 2011 Release Date: 4 May 2010 7653 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to bypass security restrictions or compromise a vulnerable system.1. Due to a memory corruption error within HTML5 Media handling.2. Due to a memory corruption error within font handling....
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2010 7533 Views

RISK: Medium Risk

Medium Risk

Opera Browser "document.write()" Uninitialized Memory Vulnerability

A vulnerability has been identified in Opera, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused due to an uninitialized memory when writing a large amount of data to a web page e.g. using the "document....
Last Update Date: 28 Jan 2011 Release Date: 28 Apr 2010 7576 Views

RISK: Medium Risk

Medium Risk

Google Chrome mutliple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, disclose sensitive information or compromise a vulnerable system.1. An unspecified type confusion error with forms.2. A HTTP request errors, which could allow cross...
Last Update Date: 28 Jan 2011 Release Date: 22 Apr 2010 7543 Views

RISK: Medium Risk

Medium Risk

MIT Kerberos KDC "process_tgs_req()" Double Free Vulnerability

A vulnerability has been identified in MIT Kerberos, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a double free error within the "process_tgs_req()" function when handling renewal or validation of existing tickets, which could allow attackers...
Last Update Date: 28 Jan 2011 Release Date: 22 Apr 2010 7568 Views

RISK: Medium Risk

Medium Risk

HP Operations Manager ActiveX Remote Buffer Overflow Vulnerability

A vulnerability has been identified in HP Operations Manager for Windows, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "srcvw4.dll" and "srcvw32.dll" ActiveX controls when...
Last Update Date: 28 Jan 2011 Release Date: 21 Apr 2010 7579 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X ATS Font Processing Invalid Index Vulnerability

A vulnerability has been identified in Apple Mac OS X, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an invalid index within the Apple Type Services (ATS) when processing embedded fonts via the "TType1ParsingContext::SpecialEncoding()" ...
Last Update Date: 28 Jan 2011 Release Date: 16 Apr 2010 7590 Views

RISK: Medium Risk

Medium Risk

Cisco Secure Desktop ActiveX Control File Download Vulnerability

A vulnerability has been identified in Cisco Secure Desktop, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the CSDWebInstaller ActiveX control that fails to properly verify the integrity of an executable file that is used by...
Last Update Date: 28 Jan 2011 Release Date: 16 Apr 2010 7729 Views

RISK: Medium Risk

Medium Risk

Oracle Products and Components Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Oracle product and components, which could be exploited by attackers to gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7528 Views

RISK: Medium Risk

Medium Risk

Microsoft SMB Client Could Allow Remote Code Execution Vulnerabilities

1. SMB Client Incomplete Response VulnerabilityA denial of service vulnerability exists in the way that the Microsoft Server Message Block (SMB) client implementation handles specially crafted SMB responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7615 Views

RISK: Medium Risk

Medium Risk

Microsoft VBScript Scripting Engine Could Allow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer. If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, the Windows Help System would be started with a Windows...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7431 Views

RISK: Medium Risk

Medium Risk

Microsoft Visio Could Allow Remote Code Execution Vulnerabilities

1. Visio Attribute Validation Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office Visio validates attributes when handling specially crafted Visio files.An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7332 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Could Allow Remote Code Execution Vulnerabilities

1. WinVerifyTrust Signature Validation VulnerabilityA remote code execution vulnerability exists in the Windows Authenticode Signature Verification function used for portable executable (PE) and cabinet file formats. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to manipulate unverified portions of the...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7430 Views