Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft MPEG Layer-3 codecs handle AVI media files. This vulnerability could allow remote code execution if a user opened a specially crafted AVI file containing an MPEG Layer-3 audio stream. If a user is...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7379 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Publisher Could Allow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Publisher opens Publisher files. An attacker could exploit the vulnerability by creating a specially crafted Publisher file that could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7319 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Services Could Allow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows 2000 Server Service Pack 4 running the optional Windows Media Services component due to the way the Windows Media Unicast Service handles specially crafted transport information packets. On Microsoft Windows 2000 Server Service Pack 4, Windows Media Services is...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7331 Views

RISK: Medium Risk

Medium Risk

Microsoft Media Player Could Allow Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Windows Media Player ActiveX control. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs or view, change, or delete data with full user rights.
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7305 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflows, memory corruptions, ...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7509 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange and Windows SMTP Service Could Allow Denial of Service Vulnerabilities

1. SMTP Server MX Record VulnerabilityA denial of service vulnerability exists in the way that the Microsoft Windows Simple Mail Transfer Protocol (SMTP) component handles specially crafted DNS Mail Exchanger (MX) resource records. An attempt to exploit the vulnerability would not require authentication, ...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7857 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Could Allow Elevation of Privilege Vulnerabilities

1. Windows Kernel Null Pointer VulnerabilityA denial of service vulnerability exists in the Windows kernel due to the insufficient validation of registry keys passed to a Windows kernel system call. An attacker could exploit the vulnerability by running a specially crafted application, causing the system to become...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 7561 Views

RISK: Medium Risk

Medium Risk

Sun Java Deployment Toolkit Remote Argument Injection Vulnerability

A vulnerability has been identified in Sun Java JRE/JDK, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an input validation error in the Java Deployment Toolkit that does not properly validate arguments supplied via "javaw....
Last Update Date: 28 Jan 2011 Release Date: 13 Apr 2010 7606 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by attackers to disclose sensitive information, cause a denial of service, or compromise an affected system. 1.Two errors in the VMware Tools package for Windows can be exploited to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 12 Apr 2010 7711 Views

RISK: Medium Risk

Medium Risk

ClamAV Scanning Bypass and Memory Corruption Vulnerability

A vulnerability has been identified in ClamAV, which can be exploited by malicious people to bypass the scanning functionality or potentially compromise a vulnerable system.1. Due to an error when processing archives can be exploited to bypass the anti-virus scanning functionality via specially crafted...
Last Update Date: 28 Jan 2011 Release Date: 8 Apr 2010 8120 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Embedded Executable Code Injection Vulnerability

A vulnerability has been identified in Foxit Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused due to Foxit Reader automatically running executable programs embedded within a PDF document without asking for a user's permission, which could...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2010 7614 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Node Scope Confusion Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a use-after-free error when moving DOM nodes between documents, which could allow attackers to crash an affected browser...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2010 7530 Views

RISK: Medium Risk

Medium Risk

Sun Java JDK and JRE Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilitieshave been identified in Sun Java JDK, JRE and SDK, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by memory corruptions, ...
Last Update Date: 28 Jan 2011 Release Date: 1 Apr 2010 7775 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Code Execution and Privilege Escalation Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple iTunes, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system, or by local attackers to obtain elevated privileges.1. Due to various errors exist in ColorSync and ImageIO when processing malformed...
Last Update Date: 28 Jan 2011 Release Date: 1 Apr 2010 7773 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime File Handling Multiple Code Execution Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by memory corruptions, and integer and heap overflow errors when processing malformed PICT, QDM2, QDMC, H.263...
Last Update Date: 28 Jan 2011 Release Date: 1 Apr 2010 7794 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the browser engine when parsing malformed data, ...
Last Update Date: 28 Jan 2011 Release Date: 1 Apr 2010 7669 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. 1. A boundary error in AppKit within the feature...
Last Update Date: 28 Jan 2011 Release Date: 31 Mar 2010 8123 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities

1. Uninitialized Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the...
Last Update Date: 28 Jan 2011 Release Date: 31 Mar 2010 7369 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to a use-after-free error when handling "multipart/...
Last Update Date: 28 Jan 2011 Release Date: 25 Mar 2010 7547 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco IOS software, which could be exploited by attackers to cause denial of service or execute arbitrary code.1. Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability2. Cisco IOS Software Crafted TCP Packet Denial of Service Vulnerability3. Cisco IOS...
Last Update Date: 28 Jan 2011 Release Date: 25 Mar 2010 7948 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox WOFF Font Processing Integer Overflow Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a integer overflow error in a font decompression routine within the WOFF decoder, which could be exploited by attackers to crash an...
Last Update Date: 28 Jan 2011 Release Date: 24 Mar 2010 7664 Views

RISK: Medium Risk

Medium Risk

CA ARCserve Backup JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in CA ARCserve Backup, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system. These issues are caused by errors in the JRE version shipped with the...
Last Update Date: 28 Jan 2011 Release Date: 22 Mar 2010 7623 Views

RISK: Medium Risk

Medium Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, disclose sensitive information or compromise a vulnerable system.1. A race conditions and pointer errors in the sandbox.2. An errors related to persisted metadata such...
Last Update Date: 28 Jan 2011 Release Date: 19 Mar 2010 7747 Views

RISK: Medium Risk

Medium Risk

Mozilla SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. An error when handling scriptable plugin content (e.g. Flash objects) embedded in...
Last Update Date: 28 Jan 2011 Release Date: 19 Mar 2010 7752 Views

RISK: Medium Risk

Medium Risk

Drupal Email Input Filter Module Code Execution Vulnerability

A vulnerability has been reported in the Email Input Filter module for Drupal, which could be exploited by remote attackers to compromise a vulnerable system.Input passed to the Email Input Filter module is not properly sanitised before being used to create content. This can be exploited...
Last Update Date: 28 Jan 2011 Release Date: 19 Mar 2010 7613 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions or compromise an affected system.1. An integer overflow error exists in ColorSync when processing certain images with an embedded color profile, which could...
Last Update Date: 28 Jan 2011 Release Date: 15 Mar 2010 7638 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Use-after-free Code Execution Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a user-after-free error in the Internet Explorer Peer Objects module "iepeers.dll" when processing certain...
Last Update Date: 28 Jan 2011 Release Date: 10 Mar 2010 7641 Views

RISK: Medium Risk

Medium Risk

Microsoft Movie Maker and Producer Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that Windows Movie Maker and Microsoft Producer 2003 handle specially crafted project files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Mar 2010 7419 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities

1. Microsoft Office Excel Record Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 28 Jan 2011 Release Date: 10 Mar 2010 8160 Views

RISK: Medium Risk

Medium Risk

Yahoo! Player Playlist Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Yahoo! Player, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing playlists (e.g. ".m3u" or ".pls") containing overly long data, ...
Last Update Date: 28 Jan 2011 Release Date: 9 Mar 2010 7639 Views

RISK: Medium Risk

Medium Risk

Symantec Products OLE File Parsing Integer Overflow Vulnerability

A vulnerability has been identified in various Symantec products, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an integer overflow error in the Autonomy KeyView component, which could be exploited by attackers to execute arbitrary code via a...
Last Update Date: 28 Jan 2011 Release Date: 8 Mar 2010 7835 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes OLE File Parsing Integer Overflow Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an integer overflow error in the Autonomy KeyView component, which could be exploited by attackers to execute arbitrary code by tricking...
Last Update Date: 28 Jan 2011 Release Date: 8 Mar 2010 7605 Views

RISK: Medium Risk

Medium Risk

Apache HTTP Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by malicious people to gain access to potentially sensitive information, cause a DoS (Denial of Service) and potentially compromise a vulnerable system.1. Due to the "ap_proxy_ajp_request()" function in...
Last Update Date: 28 Jan 2011 Release Date: 5 Mar 2010 8155 Views

RISK: Medium Risk

Medium Risk

Opera Browser "Content-Length" Header Buffer Overflow Vulnerability

A vulnerability has been identified in Opera, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed HTTP "Content-Length:" headers, which could be exploited by remote attackers to crash...
Last Update Date: 28 Jan 2011 Release Date: 5 Mar 2010 7809 Views

RISK: Medium Risk

Medium Risk

IBM Lotus iNotes ActiveX Control and UltraLite Vulnerabilities

Multiple vulnerabilitieshave been identified in IBM Lotus iNotes (Domino Web Access), which could be exploited by remote attackers to manipulate data or compromise an affected system.1. Due to a buffer overflow error in the iNotes ActiveX control.2. Due to unspecified errors related...
Last Update Date: 28 Jan 2011 Release Date: 2 Mar 2010 7613 Views

RISK: Medium Risk

Medium Risk

IBM Lotus iNotes ActiveX Control Remote Buffer Overflow Vulnerability

A vulnerability has been identified in IBM Lotus iNotes (Domino Web Access) ActiveX control, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a buffer overflow error when processing malformed data, which could be exploited by remote...
Last Update Date: 28 Jan 2011 Release Date: 2 Mar 2010 7578 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer VBScript Remote Code Execution Vulnerability

A vulnerability has been identified in VBScript, which could be exploited by remote attackers to compromise a vulnerable system. The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer. If a malicious Web site displayed a specially crafted dialog box...
Last Update Date: 28 Jan 2011 Release Date: 2 Mar 2010 7388 Views

RISK: Medium Risk

Medium Risk

Adobe Download Manager File Download and Execute Vulnerability

A vulnerability has been identified in Adobe Download Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error when processing URLs, which could be exploited by attackers to download and install unauthorized software onto a vulnerable system...
Last Update Date: 28 Jan 2011 Release Date: 26 Feb 2010 7867 Views

RISK: Medium Risk

Medium Risk

Symantec Products Client Proxy Remote Buffer Overflow Vulnerability

A vulnerability has been identified in various Symantec products, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a buffer overflow error in the Client Proxy "CLIproxy.dll" ActiveX control when processing user-supplied data, ...
Last Update Date: 28 Jan 2011 Release Date: 19 Feb 2010 7494 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an unspecified error and can be exploited to cause a stack-based buffer overflow.Successful exploitation allows...
Last Update Date: 28 Jan 2011 Release Date: 19 Feb 2010 7482 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilitieshave been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. Due to memory corruption errors in the JavaScript and browser engines when parsing malformed...
Last Update Date: 28 Jan 2011 Release Date: 19 Feb 2010 7567 Views

RISK: Medium Risk

Medium Risk

Novell Products Kerberos AES / RC4 Integer Underflow Vulnerabilities

Multiple vulnerabilitieshave been identified in Novell products, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in Kerberos. These issues are caused by integer underflow errors in the AES and RC4 decryption...
Last Update Date: 28 Jan 2011 Release Date: 19 Feb 2010 7557 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader PDF Handling Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the "authplay.dll" module when processing malformed Flash data within a PDF document...
Last Update Date: 28 Jan 2011 Release Date: 18 Feb 2010 7635 Views

RISK: Medium Risk

Medium Risk

Google Chrome Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, disclose sensitive information or compromise a vulnerable system.1. Due to an unspecified DNS and fall-back behavior of proxies, which could disclose sensitive information....
Last Update Date: 28 Jan 2011 Release Date: 12 Feb 2010 7534 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Java JDK / JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in in HP OpenView Network Node Manager, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.The vulnerabilities are caused due to...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2010 7771 Views

RISK: Medium Risk

Medium Risk

Panda Security ActiveScan "as2stubie.dll" File Download Vulnerability

A vulnerability has been identified in Panda Security ActiveScan, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "as2stubie.dll" component that fails to validate the digital signature of the "as2guiie....
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2010 7610 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Arbitrary Command Execution Vulnerability

A vulnerability has been identified in HP Network Node Manager, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to an unspecified error, which can be exploited to execute arbitrary commands.
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2010 7535 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Multiple Vulnerabilities

1. ICMPv6 Router Advertisement VulnerabilityA remote code execution vulnerability exists in the Windows TCP/IP stack due to insufficient bounds checking when processing specially crafted ICMPv6 Router Advertisement packets. An anonymous attacker could exploit the vulnerability by sending specially crafted ICMPv6 Router Advertisement packets to a computer...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7753 Views

RISK: Medium Risk

Medium Risk

Microsoft Office MSO.DLL Buffer Overflow Vulnerabilities

A remote code execution vulnerability exists in the way Microsoft Office handles specially crafted Office files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7680 Views

RISK: Medium Risk

Medium Risk

Microsoft SMB Client Multiple Vulnerabilities

1. SMB Client Pool Corruption VulnerabilityAn unauthenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7550 Views

RISK: Medium Risk

Medium Risk

Microsoft SMB Server Multiple Vulnerabilities

1. SMB Pathname Overflow VulnerabilityAn authenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB packets. An attacker could exploit the vulnerability by sending a specially crafted network message to a system running the Server...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 8094 Views

RISK: Medium Risk

Medium Risk

Microsoft URL Validation Vulnerability

A remote code execution vulnerability exists in affected versions of Microsoft Windows. The vulnerability results from the incorrect validation of input sent to the ShellExecute API function. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7371 Views

RISK: Medium Risk

Medium Risk

Microsoft Office PowerPoint Multiple Vulnerabilities

1. PowerPoint File Path Handling Buffer Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; ...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7436 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities

1. Windows Kernel Exception Handler VulnerabilityAn elevation of privilege vulnerability exists in the Windows Kernel due to the way the kernel handles certain exceptions. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7345 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow Heap Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft DirectShow parses AVI media files. This vulnerability could allow remote code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, an attacker who successfully exploited...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7441 Views

RISK: Medium Risk

Medium Risk

Microsoft Hyper-V Instruction Set Validation Vulnerability

A denial of service vulnerability exists in Hyper-V on Windows Server 2008 and Windows Server 2008 R2. The vulnerability is due to insufficient validation of specific sequences of machine instructions by Hyper-V. An attacker who successfully exploited this vulnerability could cause the affected Hyper...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7376 Views

RISK: Medium Risk

Medium Risk

Microsoft Kerberos Null Pointer Dereference Vulnerability

A denial of service vulnerability exists in implementations of Kerberos. The vulnerability is due to improper handling of Ticket-Granting-Ticket renewal requests by a client on a remote, non-Windows realm in a mixed-mode Kerberos implementation. An attacker who successfully exploited...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7437 Views

RISK: Medium Risk

Medium Risk

Microsoft Data Analyzer ActiveX Control Vulnerability

A remote code execution vulnerability exists in the Microsoft Data Analyzer ActiveX Control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7426 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Local Privilege Elevation Vulnerability

An elevation of privilege vulnerability exists because the Windows Client/Server Run-time Subsystem (CSRSS) does not properly terminate user processes when a user logs out. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 7433 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Information Disclosure Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to access files with an already known filename and location.The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed...
Last Update Date: 28 Jan 2011 Release Date: 4 Feb 2010 7583 Views

RISK: Medium Risk

Medium Risk

Apple iPhone and iPod Touch Multiple Vulnerabilities

Multiple vulnerabilitieshave been identified in Apple iPhone and iPod touch, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. Due to a buffer overflow error when processing malformed...
Last Update Date: 28 Jan 2011 Release Date: 4 Feb 2010 7620 Views

RISK: Medium Risk

Medium Risk

VMware Products Java JRE Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system. These issues are caused by errors in Java JRE.
Last Update Date: 28 Jan 2011 Release Date: 2 Feb 2010 7529 Views

RISK: Medium Risk

Medium Risk

Apache mod_proxy "ap_proxy_send_fb()" Integer Overflow Vulnerability

A vulnerability has been identified in Apache, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable web server. This issue is caused by an integer overflow error in the "ap_proxy_send_fb()" [modules/proxy/proxy_util.c] ...
Last Update Date: 28 Jan 2011 Release Date: 29 Jan 2010 8059 Views

RISK: Medium Risk

Medium Risk

Google Chrome Memory Corruption and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to bypass restrictions, gain knowledge of sensitive information, cause a denial of service or potentially compromise a vulnerable system.1. Due to an unspecified error which could allow web sites...
Last Update Date: 28 Jan 2011 Release Date: 27 Jan 2010 7582 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 22 January 2010 )

1. XSS Filter Script Handling Vulnerability An XSS filter bypass vulnerability exists in the way that Internet Explorer 8 disables an HTML attribute in otherwise appropriately filtered HTTP response data. The vulnerability could allow initially disabled scripts to run in the wrong security context, leading to information...
Last Update Date: 28 Jan 2011 Release Date: 22 Jan 2010 7710 Views

RISK: Medium Risk

Medium Risk

Sun Java System Web Server Two Vulnerabilities

Some vulnerabilities have been reported in Sun Java System Web Server, which can be exploited by malicious people to disclose sensitive information and potentially compromise a vulnerable system.1. Due to a boundary error when processing the "OPTIONS" requests which can be exploited to cause...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2010 7523 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in RealNetworks RealPlayer, which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a heap overflow error when processing a malformed ASM Rulebook, which could be exploited to execute arbitrary code.2. Due to...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2010 7568 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Buffer and Integer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by buffer and integer overflow errors when processing Shockwave files or 3D models, which could be exploited to execute arbitrary code by...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2010 7568 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. Due to a boundary error in CoreAudio which...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2010 7763 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Invalid Pointer Reference Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. The vulnerability exists as an invalid pointer reference within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object...
Last Update Date: 28 Jan 2011 Release Date: 15 Jan 2010 7462 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. Due to an integer overflow error in the U3D...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2010 7837 Views

RISK: Medium Risk

Medium Risk

Kerberos AES and RC4 Decryption Integer Underflow Vulnerabilities

Multiple vulnerabilities have been identified in Kerberos, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by integer underflow errors in the AES and RC4 decryption operations when processing an invalid ciphertext, which could...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2010 7677 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities

A vulnerability has been identified in various Oracle products and components, which could be exploited by attackers to cause a denial of service, disclose sensitive information or compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2010 8008 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Embedded OpenType Font Engine Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Windows Embedded OpenType (EOT) Font Engine decompresses specially crafted EOT fonts. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an...
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2010 7358 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Flash Player Multiple Vulnerabilities

A vulnerability has been identified in Flash Player, which could be exploited by attackers to compromise a vulnerable system.The vulnerability is caused due to a use-after-free error in the bundled version of Flash Player when unloading Flash objects while these are still being...
Last Update Date: 28 Jan 2011 Release Date: 13 Jan 2010 7400 Views

RISK: Medium Risk

Medium Risk

Novell iManager eDirectory Plugin Schema Buffer Overflow Vulnerability

A vulnerability has been identified in Novell iManager, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the eDirectory plugin when importing or exporting data from the schema, which could be exploited to crash an...
Last Update Date: 28 Jan 2011 Release Date: 11 Jan 2010 7529 Views

RISK: Medium Risk

Medium Risk

VMware ESX and vMA Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX and vMA, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system. These issues are caused by errors in NSS and NSPR.
Last Update Date: 28 Jan 2011 Release Date: 8 Jan 2010 7664 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Media Server Directory Traversal and DoS Vulnerabilities

Two vulnerabilities have been identified in Adobe Flash Media Server, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.1. An unspecified directory traversal error which could lead to FMS loading arbitrary DLLs present on the server....
Last Update Date: 28 Jan 2011 Release Date: 22 Dec 2009 7624 Views

RISK: Medium Risk

Medium Risk

Winamp Module Decoder Plug-in Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by buffer and integer overflow errors in the Module Decoder Plug-in (IN_MOD.DLL) when processing malformed Impulse Tracker, Ultratracker or...
Last Update Date: 28 Jan 2011 Release Date: 18 Dec 2009 7543 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. A memory corruption errors in the JavaScript and browser engines when parsing malformed data...
Last Update Date: 28 Jan 2011 Release Date: 17 Dec 2009 7610 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat Unspecified Code Execution Vulnerability

A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified memory corruption error, which could be exploited by attackers to execute arbitrary code by tricking a user into...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2009 7661 Views

RISK: Medium Risk

Medium Risk

Sun Solaris Gnome PDF Viewer Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Solaris, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in the Solaris GNOME PDF rendering libraries.1. Multiple integer overflows in "SplashBitmap::...
Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2009 7760 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player and AIR Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and AIR, which could be exploited by remote attackers to disclose sensitive information or compromise a vulnerable system.1. Due to a memory corruption error when parsing JPEG data, which could be exploited by attackers to execute...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2009 7582 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Client Remote Buffer Overflow Vulnerabilities

Two vulnerabilities have been identified in Novell iPrint Client, which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a buffer overflow error in "ienipp.ocx" when processing an overly long "target-frame" parameter, which...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7481 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Federation Services (ADFS) Multiple Vulnerabilities( 09 December 2009 )

1. Single Sign On Spoofing in ADFS Vulnerabilityspoofing vulnerability in Active Directory Federation Services could allow an attacker to impersonate an authenticated user if the attacker has access to a workstation and Web browser recently used by the targeted user to access a Web site that offers single sign...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7351 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Internet Authentication Service Multiple Vulnerabilities( 09 December 2009 )

1. Internet Authentication Service Memory Corruption VulnerabilityA remote code execution vulnerability exists in implementations of Protected Extensible Authentication Protocol (PEAP) on the Internet Authentication Service. The vulnerability is due to incorrect copying into memory of messages received by the server when handling PEAP authentication attempts. ...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7501 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Local Security Authority Subsystem Service (LSASS) Resource Exhaustion Vulnerability( 09 December 2009 )

A denial of service vulnerability exists in Microsoft Windows due to the way that the Local Security Authority Subsystem Service (LSASS) improperly handles specially crafted ISAKMP messages communicated through IPsec.
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7585 Views

RISK: Medium Risk

Medium Risk

Microsoft WordPad and Office Text converter Memory Corruption Vulnerability( 09 December 2009 )

A remote code execution vulnerability exists in the way that text converters in Microsoft WordPad and Microsoft Office Word process memory when a user opens a specially crafted Word 97 file.
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7488 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 09 December 2009 )

1. ATL COM Initialization VulnerabilityA remote code execution vulnerability exists in an ActiveX control built with vulnerable Microsoft Active Template Library (ATL) headers. This vulnerability only directly affects systems with components and controls installed that were built using Visual Studio ATL. Components and controls built...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7303 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Project Memory Validation Vulnerability( 09 December 2009 )

A remote code execution vulnerability exists in the way that Microsoft Office Project handles specially crafted Project files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; ...
Last Update Date: 28 Jan 2011 Release Date: 9 Dec 2009 7400 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in BlackBerry Enterprise Server and BlackBerry Professional Software, which could be exploited by attackers to compromise a vulnerable device. These issues are caused by memory corruption errors in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF files, ...
Last Update Date: 28 Jan 2011 Release Date: 4 Dec 2009 7373 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in JRE, Tomcat, ntp, ...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2009 7657 Views

RISK: Medium Risk

Medium Risk

HPOpenView Operations Default Account Code Execution Vulnerability

A vulnerability has been identified in HP OpenView Operations, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused due to a hidden account being present within the Tomcat users XML file, which could allow remote attackers to gain unauthorized access...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2009 7686 Views

RISK: Medium Risk

Medium Risk

MicrosoftInternet Explorer CSS Handling Code Execution Vulnerability

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the "...
Last Update Date: 28 Jan 2011 Release Date: 23 Nov 2009 7542 Views

RISK: Medium Risk

Medium Risk

OperaFloating Point Number Handling Memory Corruption Vulnerability

A vulnerability has been identified in Opera, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing floating point numbers, which could allow remote attackers to crash an affected browser or execute arbitrary code by...
Last Update Date: 28 Jan 2011 Release Date: 23 Nov 2009 7571 Views

RISK: Medium Risk

Medium Risk

KDEkdelibs Floating Point Numbers Memory Corruption Vulnerability

A vulnerability has been identified in KDE kdelibs, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing floating point numbers, which could allow remote attackers to crash an affected browser or execute arbitrary code...
Last Update Date: 28 Jan 2011 Release Date: 23 Nov 2009 7584 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. An integer overflow error in ColorSync when processing images with a malformed color...
Last Update Date: 28 Jan 2011 Release Date: 13 Nov 2009 7598 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word File Information Memory Corruption Vulnerability( 11 November 2009 )

A remote code execution vulnerability exists in the way that Microsoft Office Word handles a specially crafted Word file that includes a malformed record. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7500 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows License Logging Server Heap Overflow Vulnerability( 11 November 2009 )

An unauthenticated remote code execution vulnerability exists in the way that the Microsoft License Logging Server software handles specially crafted RPC packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7418 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Web Services on Devices API Memory Corruption Vulnerability( 11 November 2009 )

A remote code execution vulnerability exists in the Web Services on Devices API (WSDAPI) on Windows systems. The vulnerability is due to the service not properly handling a WSDAPI message with a specially crafted header. An attacker who successfully exploited this vulnerability could take complete control...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7377 Views