Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities( 11 November 2009 )

1. Excel Cache Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7448 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory LSASS Recursive Stack Overflow Vulnerability( 11 November 2009 )

A denial of service vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008. The vulnerability also exists in implementations of Active Directory Application Mode (ADAM) when installed on Windows XP and Windows Server 2003, ...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7497 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities( 11 November 2009 )

1. Win32k NULL Pointer Dereferencing VulnerabilityAn elevation of privilege vulnerability exists because the Windows kernel does not properly validate an argument passed to a Windows kernel system call. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7569 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. Due to a heap overflow error in QuickDraw...
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 8207 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system. These issues are caused by errors in Java.
Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 7665 Views

RISK: Medium Risk

Medium Risk

HP Power Manager Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in HP Power Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing user-supplied requests, which could allow remote attackers to execute arbitrary code.
Last Update Date: 28 Jan 2011 Release Date: 6 Nov 2009 8262 Views

RISK: Medium Risk

Medium Risk

Sun Java Multiple Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system.1. An errors when decoding DER encoded data and parsing HTTP headers, ...
Last Update Date: 28 Jan 2011 Release Date: 5 Nov 2009 7763 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system.1. An invalid index when handling certain Shockwave content, which could be exploited to execute arbitrary code via a specially crafted web page.2...
Last Update Date: 28 Jan 2011 Release Date: 4 Nov 2009 7684 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system.1. An error within the form history, which could allow malicious web sites to trick a vulnerable...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2009 7773 Views

RISK: Medium Risk

Medium Risk

Mozilla SeaMonkey Code Execution and Spoofing Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla SeaMonkey, which could be exploited by attackers to spoof certain information, bypass security restrictions or compromise a vulnerable system.1. A memory corruption error when parsing certain regular expressions used in Proxy Auto-configuration (PAC) files...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2009 7540 Views

RISK: Medium Risk

Medium Risk

Opera Browser Remote Code Execution and Spoofing Vulnerabilities

Three vulnerabilities have been identified in Opera, which could be exploited by remote attackers to bypass security restrictions, spoof or gain knowledge of certaine information, or compromise a vulnerable system.1. A memory corruption error when processing malformed domain names, which could lead to...
Last Update Date: 28 Jan 2011 Release Date: 29 Oct 2009 7645 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory HTTP Request Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the "dhost" service when processing overly long HTTP requests, ...
Last Update Date: 28 Jan 2011 Release Date: 28 Oct 2009 7528 Views

RISK: Medium Risk

Medium Risk

SunJava System Web Server Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in Sun Java System Web Server, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable web server. This issue is caused by an unspecified buffer overflow error when processing user-supplied requests, which...
Last Update Date: 28 Jan 2011 Release Date: 27 Oct 2009 7582 Views

RISK: Medium Risk

Medium Risk

Oracle Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2009 8143 Views

RISK: Medium Risk

Medium Risk

VMwareESX Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in DHCP, Service Console kernel, and...
Last Update Date: 28 Jan 2011 Release Date: 20 Oct 2009 7856 Views

RISK: Medium Risk

Medium Risk

VMwareProducts DHCP and JRE Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in DHCP and JRE.
Last Update Date: 28 Jan 2011 Release Date: 20 Oct 2009 7748 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Firefox Plugin Memory Corruption Vulnerability

A vulnerability has been identified in Foxit Reader, which could be exploited by attackers to compromise a vulnerable system.The vulnerability is caused due to an error in the Foxit Reader plugin for Firefox (npFoxitReaderPlugin.dll). This can be exploited to trigger a memory corruption...
Last Update Date: 28 Jan 2011 Release Date: 16 Oct 2009 7639 Views

RISK: Medium Risk

Medium Risk

Xpdf Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Xpdf, which could be exploited by attackers to compromise a vulnerable system.1. Multiple integer overflows in "SplashBitmap::SplashBitmap()" can be exploited to cause heap-based buffer overflows.2. An integer overflow error in "...
Last Update Date: 28 Jan 2011 Release Date: 16 Oct 2009 7696 Views

RISK: Medium Risk

Medium Risk

Sun Solaris and JES Network Security Services Buffer Overflow Vulnerability

A vulnerability has been identified in Sun Solaris and Sun Java Enterprise System, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error in Network Security Services (NSS).
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2009 8605 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Local Security Authority Subsystem Service (LSASS) Integer Overflow Vulnerability( 14 October 2009 )

A denial of service vulnerability exists in the Microsoft Windows Local Security Authority Subsystem Service (LSASS) due to its improper handling of malformed packets during NTLM authentication. An attacker could create specially crafted anonymous NTLM authentication requests that would cause a crash in the LSASS service and...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7823 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player Heap Overflow Vulnerability( 14 October 2009 )

A remote code execution vulnerability exists in Windows Media Player 6.4. An attacker could exploit the vulnerability by constructing a specially crafted ASF file that could allow remote code execution when played using Windows Media Player 6.4. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7621 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMBv2 Multiple Vulnerabilities( 14 October 2009 )

1. SMBv2 Infinite Loop VulnerabilityA denial of service vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB version 2 (SMBv2) packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 8416 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 14 October 2009 )

1. Windows Kernel Integer Underflow VulnerabilityAn elevation of privilege vulnerability exists in the Windows kernel due to the incorrect truncation of a 64-bit value to a 32-bit value. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7428 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Runtime Multiple Vulnerabilities( 14 October 2009 )

1. Windows Media Runtime Voice Sample Rate VulnerabilityA remote code execution vulnerability exists in Windows Media Player due to the improper processing of specially crafted Advanced Systems Format (ASF) files. An attacker could exploit the vulnerability by constructing a specially crafted audio file that could allow...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7672 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows GDI+ Multiple Vulnerabilities( 14 October 2009 )

1. GDI+ WMF Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that GDI+ allocates buffer size when handling WMF image files. The vulnerability could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7831 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IIS FTP Service Multiple Vulnerabilities( 14 October 2009 )

1. IIS FTP Service DoS VulnerabilityA vulnerability exists in the FTP Service in Microsoft Internet Information Services (IIS) 5., Microsoft Internet Information Services (IIS) 5.1, Microsoft Internet Information Services (IIS) 6., and Microsoft Internet Information Services...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7502 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Memory Corruption in Indexing Service Vulnerability( 14 October 2009 )

A remote code execution vulnerability exists in the Indexing Service on Windows systems. The vulnerability is due to an ActiveX control included with the service not properly handling specifically crafted Web content. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7410 Views

RISK: Medium Risk

Medium Risk

Microsoft Office ATL ActiveX Controls Multiple Vulnerabilities( 14 October 2009 )

1. ATL Uninitialized Object VulnerabilityA remote code execution vulnerability exists in the Microsoft Active Template Library (ATL) due to an issue in the ATL headers that could allow an attacker to force VariantClear to be called on a VARIANT that has not been correctly initialized. Because...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7594 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ATL COM Initialization Vulnerability( 14 October 2009 )

A remote code execution vulnerability exists in the Microsoft ActiveX controls listed in the FAQ section of this vulnerability, which were compiled using the vulnerable Microsoft Active Template Library described in Microsoft Security Bulletin MS09-035. An attacker could exploit the vulnerability in these controls by constructing...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7771 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows CryptoAPI Multiple Vulnerabilities( 14 October 2009 )

1. Null Truncation in X.509 Common Name VulnerabilityA spoofing vulnerability exists in the Microsoft Windows CryptoAPI component when parsing ASN.1 information from X.509 certificates. An attacker who successfully exploited this vulnerability could impersonate another user or system.2. Integer Overflow...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7596 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework Multiple Vulnerabilities( 14 October 2009 )

1. Microsoft .NET Framework Pointer Verification VulnerabilityA remote code execution vulnerability exists in the Microsoft .NET Framework that could allow a malicious Microsoft .NET application to obtain a managed pointer to stack memory that is no longer used. The malicious Microsoft .NET application could...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7918 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 14 October 2009 )

1. Data Stream Header Corruption VulnerabilityA remote code execution vulnerability exists in the way that Internet Explorer processes data stream headers in specific situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 7484 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat Multiple Code Execution Vulnerability

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by memory corruptions, integer and heap...
Last Update Date: 28 Jan 2011 Release Date: 12 Oct 2009 7734 Views

RISK: Medium Risk

Medium Risk

CA Anti-Virus Engine RAR Heap Corruption and DoS Vulnerabilities

Two vulnerabilities have been identified in various CA products, which could be exploited by attackers or malware to cause a denial of service or compromise a vulnerable system.1. A heap corruption error in the Anti-Virus engine arclib component when processing malformed RAR archives, ...
Last Update Date: 28 Jan 2011 Release Date: 12 Oct 2009 7875 Views

RISK: Medium Risk

Medium Risk

IBM Informix Client and Connect ".nfx" File Buffer Overflow Vulnerability

A vulnerability has been identified in IBM Informix Client and Informix Connect, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the SetNet32 utility when processing a ".nfx" file containing a malformed field (...
Last Update Date: 28 Jan 2011 Release Date: 6 Oct 2009 7855 Views

RISK: Medium Risk

Medium Risk

GoogleApps "googleapps.url.mailto:" Argument Injection Vulnerability

A vulnerability has been identified in Google Apps, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "googleapps.exe"application when processing parameters passed to the "---renderer-path" argument via...
Last Update Date: 28 Jan 2011 Release Date: 5 Oct 2009 7620 Views

RISK: Medium Risk

Medium Risk

Novell NetWare RPC CALLIT Buffer Overflow Vulnerability

A vulnerability has been identified in Novell NetWare, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a stack overflow error in the NFS Portmapper (PKERNEL.NLM) when processing malformed RPC CALLIT requests, which could be...
Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2009 7828 Views

RISK: Medium Risk

Medium Risk

Google Chrome v8 Engine Floating Point Memory Corruption Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the v8 engine when parsing strings into floating point numbers via the "dtoa()" implementation, which could...
Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2009 7782 Views

RISK: Medium Risk

Medium Risk

IBM Installation Manager "iim:" URI Remote Library Injection Vulnerability

A vulnerability has been identified in IBM Installation Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "IBMIM.exe" file when processing parameters passed to the "-vm" argument via the...
Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2009 7861 Views

RISK: Medium Risk

Medium Risk

Cisco IOS for Unified Communications Manager Express Vulnerability

A vulnerability has been identified in Cisco IOS for Unified Communications Manager Express, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the login section of the Extension Mobility feature...
Last Update Date: 28 Jan 2011 Release Date: 25 Sep 2009 7627 Views

RISK: Medium Risk

Medium Risk

Apple iTunes Playlist Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Apple iTunes, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing playlist ".pls" files containing malformed data, which could be exploited by attackers to crash an...
Last Update Date: 28 Jan 2011 Release Date: 23 Sep 2009 7795 Views

RISK: Medium Risk

Medium Risk

Sun StarOffice / StarSuite XML Parsing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun StarOffice/StarSuite, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. User-after-free errors when processing an XML document with specially-crafted Notation or Enumeration attribute...
Last Update Date: 28 Jan 2011 Release Date: 22 Sep 2009 7724 Views

RISK: Medium Risk

Medium Risk

Sun StarOffice / StarSuite Word Document Table Parsing Vulnerabilities

Two vulnerabilities have been identified in StarOffice and StarSuite, may allow a remote unprivileged user to execute arbitrary code on the system with the privileges of a local user running StarOffice/StarSuite, if the local user opens a crafted Microsoft Word document provided by the remote user...
Last Update Date: 28 Jan 2011 Release Date: 17 Sep 2009 7849 Views

RISK: Medium Risk

Medium Risk

VMware Workstation 5 VMnc Codec Multiple Vulnerabilities

A vulnerabilities have been identified in VMware Workstation, which could be exploited by attackers to compromisean affected system.The vulnerabilities are caused due to multiple errors in vmnc.dll when processing specially crafted AVI files and can be exploited to cause heap-based buffer overflows.
Last Update Date: 28 Jan 2011 Release Date: 17 Sep 2009 7643 Views

RISK: Medium Risk

Medium Risk

AppleMac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X,which could be exploited by remote or local attackers to disclosesensitive information, bypass security restrictions, cause a denialof service or compromise an affected system. These vulnerabilitiesare caused by buffer overflows, integer overflows, uninitialized pointers...
Last Update Date: 28 Jan 2011 Release Date: 14 Sep 2009 7655 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to manipulate certain data, bypass security restrictions or compromise a vulnerable system.1. Memory corruption errors in the JavaScript and browser engines when parsing malformed data, which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2009 7577 Views

RISK: Medium Risk

Medium Risk

Apple iPhone / iPod touch Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iPhone and iPod touch, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. A heap overflow error in CoreAudio when processing...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2009 7680 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by memory corruption and heap overflow errors when processing malformed H.264 movies, MPEG-4 videos, or...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2009 7517 Views

RISK: Medium Risk

Medium Risk

Cisco Products TCP State Remote Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in various Cisco products, which could be exploited by remote attackers to cause a denial of service.1. An errors in TCP protocol when handling the states of large numbers of established TCP connections, which could be exploited to exhaust all...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2009 7672 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Multiple Vulnerabilities( 09 September 2009 )

1. TCP/IP Zero Window Size VulnerabilityA denial of service vulnerability exists in TCP/IP processing in Microsoft Windows due to the way that Windows handles an excessive number of established TCP connections. The effect of this vulnerability can be amplified by the requirement to process...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2009 7664 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Wireless LAN AutoConfig Service Remote Code Execution Vulnerability( 09 September 2009 )

A remote code execution vulnerability exists in the way that the Wireless LAN AutoConfig Service (wlansvc) parses specific frames received on the wireless network. This vulnerability could allow remote code execution if a client or server with a wireless network interface enabled receives specially crafted wireless frames...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2009 7594 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows JScript Scripting Engine Remote Code Execution Vulnerability( 09 September 2009 )

A remote code execution vulnerability exists in the way that the JScript scripting engine processes scripts in Web pages. The vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running a specially crafted script. If a...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2009 7357 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Multiple Vulnerabilities( 09 September 2009 )

1. Windows Media Header Parsing Invalid Free VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Windows handles specially crafted ASF format files. This vulnerability could allow remote code execution if a user opened a specially crafted file. If a user is logged on with...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2009 7637 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DHTML Editing Component ActiveX Control Vulnerability( 09 September 2009 )

A remote code execution vulnerability exists in the DHTML Editing Component ActiveX Control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2009 7769 Views

RISK: Medium Risk

Medium Risk

VMware Workstation Movie Decoder VMnc Codec Vulnerabilities

Two vulnerabilities have been identified in VMware Workstation Movie Decoder, which could be exploited by attackers to potentially compromise a vulnerable system.1. A heap overflow error in the VMnc codec (vmnc.dll) when processing a video file with mismatched dimensions, which could...
Last Update Date: 28 Jan 2011 Release Date: 8 Sep 2009 7767 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system.A stack overflow error in Java Web Start command launcher when handling...
Last Update Date: 28 Jan 2011 Release Date: 7 Sep 2009 7568 Views

RISK: Medium Risk

Medium Risk

Novell iPrint Client Unspecified Buffer Overflow Vulnerability

A vulnerability has been identified in Novell iPrint Client, which could be exploited by attackers to compromisean affected system.The vulnerability is caused due to an unspecified error and can be exploited to cause a buffer overflow.
Last Update Date: 28 Jan 2011 Release Date: 7 Sep 2009 7582 Views

RISK: Medium Risk

Medium Risk

OpenOffice.org Documents Parsing Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to compromise a vulnerable system.1. Due to an integer underflow error when parsing certain records in a Word document table, which could allow attackers to crash an affected application or...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2009 7601 Views

RISK: Medium Risk

Medium Risk

Google Chrome V8 Javascript Engine Memory Read Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error in the V8 Javascript engine, which may allow a specially crafted web page to read unauthorized memory, bypassing security checks...
Last Update Date: 28 Jan 2011 Release Date: 27 Aug 2009 7856 Views

RISK: Medium Risk

Medium Risk

Symantec Products KeyView XLS Handling Integer Overflow Vulnerability

A vulnerability has been identified in various Symantec products, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an integer overflow error in the Autonomy KeyView Viewer for Excel (xlssr.dll) when processing XLS documents containing a malformed...
Last Update Date: 28 Jan 2011 Release Date: 27 Aug 2009 8085 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes File Viewer for Excel Code Execution Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the File Viewer for Excel (xlssr.dll) when processing a malformed XLS document, which...
Last Update Date: 28 Jan 2011 Release Date: 26 Aug 2009 7725 Views

RISK: Medium Risk

Medium Risk

Apple Safari Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. A heap overflow error in CoreGraphics in the drawing of long text strings...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2009 7798 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows WINS Multiple Vulnerabilities( 12 August 2009 )

1. WINS Heap Overflow VulnerabilityA remote code execution vulnerability exists in the Windows Internet Name Service (WINS) due to a buffer overflow caused by incorrect calculation of buffer length when processing specially crafted WINS network packets. An attacker who successfully exploited this vulnerability could take complete...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7497 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Message Queuing service (MSMQ) Null Pointer Vulnerability( 12 August 2009 )

An elevation of privilege vulnerability exists in the Windows Message Queuing service (MSMQ) due to a specific flaw in the parsing of an IOCTL request to the Message Queuing service. The MSMQ service improperly checks input data before passing them to the buffer. An attacker who...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7446 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Telnet Credential Reflection Vulnerability( 12 August 2009 )

A remote code execution vulnerability exists in the Microsoft Telnet service. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7694 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Workstation Service Memory Corruption Vulnerability( 12 August 2009 )

An elevation of privilege vulnerability exists in the Windows Workstation Service due to a possible "Double Free" condition occurring in the service. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated privileges. An attacker could then install programs; view, change...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7529 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Template Library (ATL) Multiple Vulnerabilities( 12 August 2009 )

1. Microsoft Video ActiveX Control VulnerabilityA remote code execution vulnerability exists in the Microsoft Active Template Library (ATL) due to the function CComVariant::ReadFromStream used in the ATL header. This function does not properly restrict untrusted data read from a stream. This issue leads...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 8016 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media File Processing Vulnerabilities( 12 August 2009 )

1. Malformed AVI Header VulnerabilityA remote code execution vulnerability exists in the way Microsoft Windows handles specially crafted AVI format files. This vulnerability could allow code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, ...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7474 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Web Components Multiple Vulnerabilities( 12 August 2009 )

1. Office Web Components Memory Allocation VulnerabilityA remote code execution vulnerability exists in the Office Web Components ActiveX Control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7547 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Desktop Connection Heap Overflow Vulnerabilities( 12 August 2009 )

1. Remote Desktop Connection Heap Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Remote Desktop Connection (formerly known as Terminal Services Client) processes specific parameters returned by the RDP server. An attacker who successfully exploited this vulnerability could take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7798 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Remote Unauthenticated Denial of Service in ASP.NET Vulnerability( 12 August 2009 )

A Denial of Service vulnerability exists in the way ASP.NET manages request scheduling. An attacker could exploit this vulnerability by creating specially crafted anonymous HTTP requests that would cause the affected Web server to become non-responsive until the associated application pool is restarted.
Last Update Date: 28 Jan 2011 Release Date: 12 Aug 2009 7739 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by out-of-bounds...
Last Update Date: 28 Jan 2011 Release Date: 7 Aug 2009 7957 Views

RISK: Medium Risk

Medium Risk

Sun Java Multiple Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system.1. An error in the SOCKS proxy implementation, which may allow an...
Last Update Date: 28 Jan 2011 Release Date: 6 Aug 2009 7601 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to manipulate certain data, disclose sensitive information or compromise a vulnerable system.1. Due to an error when handling a SOCKS5 proxy reply containing an overly long DNS name, which could...
Last Update Date: 28 Jan 2011 Release Date: 5 Aug 2009 7788 Views

RISK: Medium Risk

Medium Risk

Apple iPhone SMS Processing Memory Corruption Vulnerability

A vulnerability has been identified in Apple iPhone, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a memory corruption error when processing a malformed SMS message, which could be exploited to cause...
Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2009 7990 Views

RISK: Medium Risk

Medium Risk

Mozilla Products NSS Code Execution and Security Bypass Vulnerabilities

Two vulnerabilities have been identified in Mozilla Firefox, Thunderbird and Seamonkey, which could be exploited by remote attackers to bypass security restrictions or compromise a vulnerable system. These issues are caused by errors in NSS. 1. A heap overflow in a regular expression parser when...
Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2009 7617 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player and AIR Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player and AIR, which could be exploited by attackers to bypass security restrictions, disclose sensitive information or compromise a vulnerable system. These issues are caused by memory corruption, buffer overflow, privilege escalation, null pointer, sandbox...
Last Update Date: 28 Jan 2011 Release Date: 3 Aug 2009 7949 Views

RISK: Medium Risk

Medium Risk

Adobe Flash/Shockwave Player Active Template Library Vulnerability

A vulnerability has been identified in Adobe Flash/Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused due to the player using vulnerable MS Active Template Libraries (ATL) and headers, which could lead to code...
Last Update Date: 28 Jan 2011 Release Date: 30 Jul 2009 7794 Views

RISK: Medium Risk

Medium Risk

BIND 9 DNS Dynamic Update Denial of Service Vulnerability

Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. dns_db_findrdataset() fails when the prerequisite section of the dynamic update message contains a record of type "ANY" and where at...
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2009 7763 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities (29 July 2009)

1. Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Internet Explorer handles a memory object. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution...
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2009 7401 Views

RISK: Medium Risk

Medium Risk

KDE KHTML Numeric Character References Memory Corruption Vulnerability

A vulnerability has been identified in KDE, which could be exploited by malicious people to potentially compromise a user's system.The vulnerability is caused due to an error in KHTML when processing numeric character references and can be exploited to corrupt memory.
Last Update Date: 28 Jan 2011 Release Date: 28 Jul 2009 7685 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat/Reader and Flash Player Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat, Reader and Flash Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "flash9f.dll" and "authplay.dll" modules when processing...
Last Update Date: 28 Jan 2011 Release Date: 23 Jul 2009 7803 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Memory Corruption and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. Memory corruption errors in the JavaScript and browser engines when parsing...
Last Update Date: 28 Jan 2011 Release Date: 23 Jul 2009 7814 Views

RISK: Medium Risk

Medium Risk

Google Chrome Javascript Memory Corruption Vulnerabilities

Two vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system.1. A heap overflow error when evaluating a specially crafted regular expression in Javascript, which could be exploited to crash an affected browser and execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 20 Jul 2009 7681 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities ( 16 July 2009 )

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 16 Jul 2009 7683 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities ( 16 July 2009 )

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 16 Jul 2009 7536 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Publisher Pointer Dereference Vulnerability ( 15 July 2009 )

A remote code execution vulnerability exists in the way that Microsoft Office Publisher opens, imports, and converts files created in versions older than Microsoft Office Publisher 2007. An attacker could exploit the vulnerability by creating a specially crafted Publisher file that could be included as an e...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7404 Views

RISK: Medium Risk

Medium Risk

Microsoft Video ActiveX Control Vulnerability ( 15 July 2009 )

A remote code execution vulnerability exists in the Microsoft Video ActiveX Control, msvidctl.dll. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7645 Views

RISK: Medium Risk

Medium Risk

Microsoft ISA Server 2006 Radius OTP Bypass Vulnerability ( 15 July 2009 )

An elevation of privilege vulnerability exists in ISA Server 2006 authentication when configured with Radius OTP. The vulnerability could allow an unauthenticated user access to any Web published resource. With knowledge of administrator account usernames, an attacker who successfully exploited this vulnerability could take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7566 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Embedded OpenType Font Engine Multiple Vulnerabilities ( 15 July 2009 )

1. Embedded OpenType Font Heap Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Windows Embedded OpenType (EOT) font technology parses data records in specially crafted embedded fonts. If a user is logged on with administrative user rights, an attacker who successfully...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7510 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow Multiple Vulnerabilities ( 15 July 2009 )

1. DirectX NULL Byte Overwrite VulnerabilityA remote code execution vulnerability exists in the way that Microsoft DirectShow parses QuickTime media files. This vulnerability could allow code execution if a user opened a specially crafted QuickTime file. If a user is logged on with administrative user rights, ...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7579 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Memory Corruption Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a memory corruption error when handling certain elements, which could be exploited by remote attackers to execute arbitrary code by tricking a...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2009 7755 Views

RISK: Medium Risk

Medium Risk

MicrosoftOffice Web Components Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft Office Web Components, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a memory corruption error in the "OWC10.DLL" and "OWC11.DLL" ActiveX controls, which...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2009 7924 Views

RISK: Medium Risk

Medium Risk

Apple Safari WebKit Memory Corruption and Cross Site Scripting Vulnerabilties

Two vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. An input validation error in WebKit when handling parent and top objects, which could be exploited by attackers to cause...
Last Update Date: 28 Jan 2011 Release Date: 10 Jul 2009 7619 Views

RISK: Medium Risk

Medium Risk

Nokia Phones RealPlayer and MMS Viewer Memory Corruption Vulnerability

Multiple vulnerabilities have been identified in various Nokia phones, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable device. These issues are caused by memory corruption errors in the "rarender.dll", "STH264HWDecHwDevice.dll", "clntcore.dll...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2009 7845 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectShow MSVidCtl Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Microsoft Windows DirectShow, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a buffer overflow error in the ActiveX control for streaming video "MSVidCtl.dll" when reading a file containing overly...
Last Update Date: 28 Jan 2011 Release Date: 7 Jul 2009 7821 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server krb5 Vulnerabilities

A vulnerability has been identified in VMware ESX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Last Update Date: 28 Jan 2011 Release Date: 2 Jul 2009 7604 Views

RISK: Medium Risk

Medium Risk

KDEMultiple Vulnerabilities

Some vulnerabilities have been identified in KDE, which can be exploited by malicious people to compromise a user's system.1. A vulnerability is caused due to a boundary error when processing SVGList objects. This can be exploited to trigger a memory corruption when visiting...
Last Update Date: 28 Jan 2011 Release Date: 29 Jun 2009 7540 Views

RISK: Medium Risk

Medium Risk

Adobe Shockwave Player 11 Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Shockwave Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing Shockwave Player 10 content, which could allow attackers to execute arbitrary code by tricking a user...
Last Update Date: 28 Jan 2011 Release Date: 25 Jun 2009 7588 Views

RISK: Medium Risk

Medium Risk

Google Chrome HTTP Response Handling Buffer Overflow Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed HTTP responses, which could allow remote attackers to crash an affected browser or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 24 Jun 2009 7960 Views