Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

FoxitReader JPEG2000/JBIG Decoder Memory Corruption Vulnerability

Two vulnerabilities have been identified in Foxit Reader JPEG2000/JBIG Decoder Add-on, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by memory corruption errors in the handling of JPX (JPEG2000) streams, which could allow attackers...
Last Update Date: 28 Jan 2011 Release Date: 23 Jun 2009 7954 Views

RISK: Medium Risk

Medium Risk

Apple iPhone and iPod touch Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple iPhone and iPod touch, which could be exploited by atatckers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflows, memory corruptions...
Last Update Date: 28 Jan 2011 Release Date: 19 Jun 2009 7578 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. A memory corruption errors in the JavaScript and browser...
Last Update Date: 28 Jan 2011 Release Date: 15 Jun 2009 7714 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by memory corruption errors, and integer and heap overflows in the JBIG2 filter and within the handling of PDF data, which...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2009 7590 Views

RISK: Medium Risk

Medium Risk

Google Chrome WebKit Memory Corruption and Information Disclosure Vulnerabilities

Two vulnerabilities have been reported in Google Chrome, which can be exploited by attackers to disclose sensitive information or compromise an affected system.1. An error in WebKit when handling recursion in certain DOM event handlers can be exploited to corrupt memory and potentially execute arbitrary code...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2009 7614 Views

RISK: Medium Risk

Medium Risk

Microsoft Works File Converters Buffer Overflow Vulnerability ( 10 June 2009 )

A remote code execution vulnerability exists in the way that the Works for Windows document converters handle specially crafted Works files. The vulnerability could allow remote code execution if a user opens a specially crafted .wps file. Users whose accounts are configured to have fewer user rights...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7447 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Vulnerabilities ( 10 June 2009 )

A remote code execution vulnerability exists in the way that Microsoft Office Word handles a specially crafted Word file that includes a malformed record. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7387 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Print Spooler Multiple Vulnerabilities ( 10 June 2009 )

1. Buffer Overflow in Print Spooler VulnerabilityA remote code execution vulnerability exists in the Windows Print Spooler that could allow a remote, unauthenticated attacker to execute arbitrary code on an affected system. An attacker who successfully exploited this vulnerability could take complete control of an affected system...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7547 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) WebDAV Authentication Bypass Vulnerabilities ( 10 June 2009 )

1. IIS 5. WebDAV Authentication Bypass VulnerabilityAn elevation of privilege vulnerability exists in the way that the WebDAV extension for IIS handles HTTP requests. An attacker could exploit this vulnerability by creating a specially crafted anonymous HTTP request to gain access to a location that should require...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7926 Views

RISK: Medium Risk

Medium Risk

Microsoft RPC Marshalling Engine Vulnerability ( 10 June 2009 )

An elevation of privilege vulnerability exists in the Windows remote procedure call (RPC) facility where the RPM Marshalling Engine does not update its internal state appropriately. The failure to update internal state could lead to a pointer being read from an incorrect location. An attacker who...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7412 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities ( 10 June 2009 )

1. Windows Kernel Desktop VulnerabilityAn elevation of privilege vulnerability exists in the way that the Windows kernel does not properly validate changes in certain kernel objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; ...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7480 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. Due to an error in CFNetwork when identifying the file type of certain...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7758 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Invalid Free and Memory Leak Vulnerabilities ( 10 June 2009 )

1. Active Directory Invalid Free VulnerabilityA remote code execution vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability is due to incorrect freeing of memory when processing specially crafted LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7599 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities ( 10 June 2009 )

1. Race Condition Cross-Domain Information Disclosure VulnerabilityAn information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to the content in another browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7402 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities ( 10 June 2009 )

A remote code execution vulnerability exists in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed record object. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 7412 Views

RISK: Medium Risk

Medium Risk

ACDSee Products TIFF and Font Parsing Buffer Overflow Vulnerabilities

Two vulnerabilities have been identified in various ACDSee products, which could be exploited by attackers to compromise a vulnerable system.1. A buffer overflow error when parsing a specially crafted TIFF image, which could be exploited to crash an affected application or execute arbitrary code by...
Last Update Date: 28 Jan 2011 Release Date: 4 Jun 2009 7679 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime File Processing Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by memory corruption, heap overflow, sign extension, and uninitialized memory access errors when processing specially crafted Sorenson 3...
Last Update Date: 28 Jan 2011 Release Date: 3 Jun 2009 7750 Views

RISK: Medium Risk

Medium Risk

Apple iTunes "itms:" URI Handling Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Apple iTunes, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a stack overflow error when processing a specially crafted "itms:" URL, which could be...
Last Update Date: 28 Jan 2011 Release Date: 3 Jun 2009 7792 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow Remote Code Execution Vulnerability

A vulnerability in Microsoft DirectX that could allow remote code execution if user opened a specially crafted QuickTime media file.
Last Update Date: 28 Jan 2011 Release Date: 29 May 2009 7581 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Vulnerabilities

Multiple vulnerabilities have been identified in various BlackBerry products, which could be exploited by attackers to compromise a vulnerable device. These issues are caused by memory corruption errors in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF files, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 29 May 2009 7545 Views

RISK: Medium Risk

Medium Risk

HP-UX Java Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system. These issues are caused by errors in Java.
Last Update Date: 28 Jan 2011 Release Date: 29 May 2009 7735 Views

RISK: Medium Risk

Medium Risk

Novell GroupWise Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell GroupWise, which could be exploited by remote attackers to bypass security restrictions, conduct phishing attacks, cause a denial of service or compromise a vulnerable system.1. A buffer overflow error in the Novell GroupWise Internet Agent (GWIA...
Last Update Date: 28 Jan 2011 Release Date: 25 May 2009 7935 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Java Calendar Deserialisation Code Execution Vulnerability

A vulnerability has been identified in Apple Mac OS X, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in Java within the deserialization of Calendar objects, which could be exploited by attackers to bypass the Java...
Last Update Date: 28 Jan 2011 Release Date: 22 May 2009 7566 Views

RISK: Medium Risk

Medium Risk

Winamplibsndfile.dll VOC File Processing Heap Overflow Vulnerability

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system.This issue is caused by a buffer overflow error when processing a malformed VOC file.These issues are caused by buffer overflow errors in the "voc_read_header()" [...
Last Update Date: 28 Jan 2011 Release Date: 19 May 2009 7637 Views

RISK: Medium Risk

Medium Risk

Google Chrome WebKit SVGList Object Memory Corruption Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a memory corruption error in WebKit when processing a specially crafted SVGList object, which could be...
Last Update Date: 28 Jan 2011 Release Date: 18 May 2009 7733 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Security Update Fixes Multiple Vulnerabilities ( 14 May 2009 )

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by input validation errors, buffer...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2009 8414 Views

RISK: Medium Risk

Medium Risk

Apple Safari for Mac and Windows Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari for Mac and Windows, which could be exploited by attackers to compromise a vulnerable system.The first issue is caused by input validation errors within the handling of "feed:" URLs, which could allow attackers to inject arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2009 7577 Views

RISK: Medium Risk

Medium Risk

Microsoft Office PowerPoint Multiple Vulnerabilities( 13 May 2009 )

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker could exploit the vulnerability by creating a specially crafted PowerPoint file that could be included as an e-mail attachment, or hosted on a specially crafted or...
Last Update Date: 28 Jan 2011 Release Date: 13 May 2009 7764 Views

RISK: Medium Risk

Medium Risk

Google Chrome Mutliple Vulnerabilities

Two vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to compromise a vulnerable system.The first vulnerability is caused by an integer overflow error in the Skia 2D graphics engine when computing image sizes, which could allow attackers to crash an affected...
Last Update Date: 28 Jan 2011 Release Date: 8 May 2009 7743 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Remote Code Execution Vulnerability

A vulnerability has been identified in HP OpenView Network Node Manager (NNM), which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an unspecified error when processing specially crafted data, which could allow remote...
Last Update Date: 28 Jan 2011 Release Date: 6 May 2009 7840 Views

RISK: Medium Risk

Medium Risk

Symantec Products Alert Management System 2 Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Symantec products, which could be exploited by remote attackers to compromise a vulnerable system.1. An error in the Intel LANDesk Common Base Agent (CBA) using data sent to port 12174 as an argument to "CreateProcessA()", ...
Last Update Date: 28 Jan 2011 Release Date: 30 Apr 2009 7794 Views

RISK: Medium Risk

Medium Risk

HP OpenView NNM "ovalarmsrv" Remote Integer Overflow Vulnerability

A vulnerability has been identified in HP OpenView Network Node Manager (NNM), which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an integer overflow error in "ovalarmsrv.exe" when processing a...
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2009 7601 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox "nsTextFrame::ClearTextRun()" Memory Corruption Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a memory corruption error in "nsTextFrame::ClearTextRun()" when processing certain data, which could be...
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2009 7574 Views

RISK: Medium Risk

Medium Risk

Adobe Reader and Acrobat JavaScript Memory Corruption Vulnerabilities

Two vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to compromise a vulnerable system.1. Due to a memory corruption error when processing specially crafted data passed to the "getAnnots()" JavaScript method, which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2009 8438 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox, SeaMonkey and Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. Due to memory corruption errors in the...
Last Update Date: 28 Jan 2011 Release Date: 22 Apr 2009 7790 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Unspecified Vulnerabilities

Some vulnerabilities have been identified in in BlackBerry Enterprise Server and BlackBerry Professional Software, which could be exploited by remote attackers to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.The vulnerabilities are caused due to unspecified errors within the PDF distiller...
Last Update Date: 28 Jan 2011 Release Date: 20 Apr 2009 7539 Views

RISK: Medium Risk

Medium Risk

Micosoft Whale IAG ActiveX Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Whale Communications Intelligent Application Gateway (IAG) 2007, which could be exploited by remote attackers to comrpromise an affected system. These issues are caused by buffer overflow errors in the "WhlMgr.dll" ActiveX control when processing a...
Last Update Date: 28 Jan 2011 Release Date: 17 Apr 2009 7512 Views

RISK: Medium Risk

Medium Risk

Novell Kerberos KDC Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell Kerberos KDC, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in Kerberos.1. A NULL pointer dereference error in the "spnego_gss_accept_sec_context()" [...
Last Update Date: 28 Jan 2011 Release Date: 17 Apr 2009 7599 Views

RISK: Medium Risk

Medium Risk

DivX Web Player Stream Format Chunk Buffer Overflow Vulnerability

A vulnerability has been identified in DivX Web Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a signedness error in the processing of "STRF" (Stream Format) chunks within a DivX file, which could be...
Last Update Date: 28 Jan 2011 Release Date: 16 Apr 2009 7777 Views

RISK: Medium Risk

Medium Risk

Oracle and BEA Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 16 Apr 2009 7700 Views

RISK: Medium Risk

Medium Risk

Sun Solaris Adobe Reader Multiple Vulnerabilities

Multiple vulnerability have been identified in Sun Solaris, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by errors in Adobe Reader.
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 8011 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 15 April 2009 )

1. Blended Threat Remote Code Execution VulnerabilityA blended threat remote code execution vulnerability exists in the way that Internet Explorer locates and opens files on the system. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7512 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Multiple Privilege Escalation Vulnerabilities( 15 April 2009 )

1. Windows MSDTC Service Isolation VulnerabilityAn elevation of privilege vulnerability exists in the Microsoft Distributed Transaction Coordinator (MSDTC) transaction facility in Microsoft Windows platforms. MSDTC leaves a NetworkService token that can be impersonated by any process that calls into it. The vulnerability allows a process...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7920 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows HTTP Services Multiple Vulnerabilities( 15 April 2009 )

1. Windows HTTP Services Integer Underflow VulnerabilityA remote code execution vulnerability exists in the way that Windows HTTP Services handle specific values that are returned by a remote Web server. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7553 Views

RISK: Medium Risk

Medium Risk

Microsoft WordPad and Office Text Converters Multiple Vulnerabilities( 15 April 2009 )

1. WordPad and Office Text Converter Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that text converters in WordPad and Microsoft Office process memory when a user opens a specially crafted Word 6 file that includes malformed data.2. WordPad Word 97 Text Converter...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7449 Views

RISK: Medium Risk

Medium Risk

Microsoft DirectShow MJPEG Decompression Vulnerability( 15 April 2009 )

A remote code execution vulnerability exists in the way Microsoft DirectShow handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted MJPEG file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7452 Views

RISK: Medium Risk

Medium Risk

Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Multiple Vulnerabilities( 15 April 2009 )

1. Web Proxy TCP State Limited Denial of Service VulnerabilityA denial of service vulnerability exists in the way the firewall engine handles TCP state for Web proxy or Web publishing listeners. The vulnerability could allow a remote user to cause a Web listener to stop responding to new...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7494 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Memory Corruption Vulnerabilities( 15 April 2009 )

1. Memory Corruption VulnerabilityA remote code execution vulnerability exists in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed object. An attacker who successfully exploited this vulnerability could take complete control of an affected system...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2009 7370 Views

RISK: Medium Risk

Medium Risk

ClamAVcli_url_canon()" Buffer Overflow and UPack DoS Vulnerabilities

Multiple vulnerabilities have been identified in ClamAV, which could be exploited by attackers or malware to cause a denial of service or compromise a vulnerable system.1. A buffer overflow error in the "cli_url_canon()" [libclamav/phishcheck.c] function when processing specially crafted...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2009 7665 Views

RISK: Medium Risk

Medium Risk

HPOpenView Performance Agent DynaZip Buffer Overflow Vulnerability

A vulnerability has been identified in HP OpenView Performance Agent and HP Performance Agent, which could be exploited by remote attackers to compromise a vulnerable system.Buffer overflow errors in the "dzip32.dll" and "dzips32.dll" libraries when repairing, adding, ...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2009 7896 Views

RISK: Medium Risk

Medium Risk

SunSolaris and SEAM Kerberos Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Solaris and SEAM (Sun Enterprise Authentication Mechanism), which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in Kerberos.1. A NULL pointer dereference...
Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2009 7579 Views

RISK: Medium Risk

Medium Risk

Novell NetIdentity Client Agent Remote Code Execution Vulnerability

A vulnerability has been identified in Novell NetIdentity Client, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an input validation error within "xtagent.exe" when handling RPC messages over the "XTIERRPCPIPE" named pipe, which...
Last Update Date: 28 Jan 2011 Release Date: 8 Apr 2009 7682 Views

RISK: Medium Risk

Medium Risk

VMwareProducts Code Execution and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by attackers or malicious users to cause a denial of service, gain elevated privileges, or execute arbitrary code.1. An unspecified error in a guest virtual device driver, which could allow...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2009 8343 Views

RISK: Medium Risk

Medium Risk

Microsoft Office PowerPoint Remote Code Execution Vulnerability

A vulnerability in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file.
Last Update Date: 28 Jan 2011 Release Date: 3 Apr 2009 7484 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox and Seamonkey Multiple Vulnerabilities

Two vulnerability has been identified in Mozilla Firefox and Seamonkey, which could be exploited by remote attackers to cause a denial of service or potentially compromise a vulnerable system. 1. A memory corruption error within the "txMozillaXSLTProcessor::TransformToDoc()" function when processing specially crafted XSLT...
Last Update Date: 28 Jan 2011 Release Date: 27 Mar 2009 7631 Views

RISK: Medium Risk

Medium Risk

Sun Java JDK / JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or compromise an affected system.1. An unspecified error in the HTTP server implementation, which could allow...
Last Update Date: 28 Jan 2011 Release Date: 27 Mar 2009 7740 Views

RISK: Medium Risk

Medium Risk

phpMyAdmin HTTP Response Splitting and File Inclusion Vulnerabilities

Two vulnerabilities have been identified in phpMyAdmin, which could be exploited by attackers to disclose sensitive information or bypass security restrictions. These issues are caused by input validation errors in the BLOB streaming feature, which could allow arbitrary file inclusion and HTTP header inject attacks.
Last Update Date: 28 Jan 2011 Release Date: 26 Mar 2009 7702 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a stack overflow error in the "OvCgi/Toolbar.exe" CGI when processing an overly...
Last Update Date: 28 Jan 2011 Release Date: 25 Mar 2009 7801 Views

RISK: Medium Risk

Medium Risk

Sun Java System Identity Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java System Identity Manager, which could be exploited by attackers to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a vulnerable system.1. An unspecified error can lead to...
Last Update Date: 28 Jan 2011 Release Date: 23 Mar 2009 7624 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader JavaScript Method Code Execution Vulnerability

A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error whithin the processing of an unspecified JavaScript method, which could allow attackers to cause a vulnerable application to crash...
Last Update Date: 28 Jan 2011 Release Date: 20 Mar 2009 7569 Views

RISK: Medium Risk

Medium Risk

Lotus Notes File Viewer "wp6sr.dll" Buffer Overflow Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the File Viewer for WordPerfect module when processing a specially crafted file attachment, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 19 Mar 2009 7693 Views

RISK: Medium Risk

Medium Risk

Sun Solaris Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Solaris, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by errors in Flash.
Last Update Date: 28 Jan 2011 Release Date: 18 Mar 2009 7644 Views

RISK: Medium Risk

Medium Risk

Symantec Products KeyView Module Buffer Overflow Vulnerability

A vulnerability has been identified in various Symantec products, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the Autonomy KeyView module, which could be exploited by attackers to crash an affected server or application...
Last Update Date: 28 Jan 2011 Release Date: 18 Mar 2009 7588 Views

RISK: Medium Risk

Medium Risk

Adobe Reader/Acrobat Remote Code Execution Vulnerability

A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system.
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2009 7832 Views

RISK: Medium Risk

Medium Risk

HP-UXJava Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or take complete control of an affected system. These issues are caused by errors in...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2009 7562 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SChannel Could Allow Spoofing Vulnerability ( 11 March 2009 )

A spoofing vulnerability exists in the Microsoft Windows SChannel authentication component when using certificate based authentication. An attacker who successfully exploited this vulnerability would be able to authenticate to a server using only an authorized user¡¦s digital certificate and without the associated private key.
Last Update Date: 28 Jan 2011 Release Date: 11 Mar 2009 7423 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DNS and WINS Server Could Allow Spoofing Vulnerabilities ( 11 March 2009 )

1. DNS Server Query Validation VulnerabilityA spoofing vulnerability exists in Windows DNS server. This vulnerability could allow a remote unauthenticated attacker to quickly and reliably spoof responses and insert records into the DNS server's cache, thereby redirecting Internet traffic.2. DNS Server Response...
Last Update Date: 28 Jan 2011 Release Date: 11 Mar 2009 7680 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Could Allow Remote Code Execution Vulnerabilities ( 11 March 2009 )

1. Windows Kernel Input Validation VulnerabilityA remote code execution vulnerability exists in the Windows kernel due to improper validation of input passed from user mode through the kernel component of GDI. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 11 Mar 2009 7387 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Foxit Reader, which could be exploited by attackers to compromise a vulnerable system.1. A stack overflow error when processing a PDF containing an action (e.g. Open/Execute a file) with an overly long filename...
Last Update Date: 28 Jan 2011 Release Date: 10 Mar 2009 7828 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. A memory corruption errors in the JavaScript and layout engines when parsing malformed...
Last Update Date: 28 Jan 2011 Release Date: 6 Mar 2009 7698 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. Due to a memory corruption error when processing a malformed JPEG image, which...
Last Update Date: 28 Jan 2011 Release Date: 4 Mar 2009 7599 Views

RISK: Medium Risk

Medium Risk

Winamp "libsndfile.dll" CAF Processing Integer Overflow Vulnerability

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system.This issue is caused by an integer overflow error in libsndfile.dll when processing CAF description chunks, which could be exploited by attackers to crash an affected...
Last Update Date: 28 Jan 2011 Release Date: 4 Mar 2009 7691 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory iMonitor Buffer Overflow Vulnerability

A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in iMonitor when handling a malformed "Accept-Language" header, ...
Last Update Date: 28 Jan 2011 Release Date: 2 Mar 2009 7639 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Code Execution and Clickjacking Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by attackers to gain knowledge of sensitive information, manipulate certain data, cause a denial of service or compromise a vulnerable system.1. A vulnerability is caused by an invalid object references when...
Last Update Date: 28 Jan 2011 Release Date: 26 Feb 2009 7788 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Invalid Object Reference Vulnerability

A vulnerability has been reported in Microsoft Excel, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an error that may cause an invalid object to be referenced when opening an Excel document.Successful exploitation allows...
Last Update Date: 28 Jan 2011 Release Date: 25 Feb 2009 7501 Views

RISK: Medium Risk

Medium Risk

Adobe Acrobat and Reader Image Stream Code Execution Vulnerability

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing a malformed image stream within a PDF document, which could allow attackers to cause a...
Last Update Date: 28 Jan 2011 Release Date: 23 Feb 2009 7777 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. A race condition error in the AFP Server...
Last Update Date: 28 Jan 2011 Release Date: 16 Feb 2009 7709 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer Internet Video Recording Multiple Vulnerabilities

Two vulnerabilities have been identified in RealNetworks RealPlayer, which could be exploited by attackers to compromise a vulnerable system.1. Due to a heap corruption error when processing Internet Video Recording (IVR) files containing a malformed field that determines the length of a structure, ...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7560 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 11 February 2009 )

1. Uninitialized Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Internet Explorer accesses an object that has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7307 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Visio Multiple Vulnerabilities( 11 February 2009 )

1. Memory Validation VulnerabilityA remote code execution vulnerability exists in the way Microsoft Office Visio validates object data when opening up Visio files. An attacker could exploit the vulnerability by sending a specially crafted file which could be included as an e-mail attachment, or hosted...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7373 Views

RISK: Medium Risk

Medium Risk

BlackBerry Application Web Loader ActiveX Control Buffer Overflow Vulnerability

A vulnerability has been identified in BlackBerry Application Web Loader, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a buffer overflow error in the RIM AxLoader ActiveX control (AxLoader.ocx or AxLoader.dll) when processing...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7611 Views

RISK: Medium Risk

Medium Risk

Microsoft Exchange Server Multiple Vulnerabilities( 11 February 2009 )

1. Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Microsoft Exchange Server decodes the Transport Neutral Encapsulation Format (TNEF) data for a message.2. Literal Processing VulnerabilityA denial of service vulnerability exists in the EMSMDB2 (Electronic Messaging System Microsoft Data Base...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7492 Views

RISK: Medium Risk

Medium Risk

Microsoft SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability( 11 February 2009 )

A remote code execution vulnerability exists in the way that SQL Server checks parameters in the "sp_replwritetovarbin" extended stored procedure. The vulnerability could allow remote code execution if untrusted users have access to an affected system or if a SQL injection vulnerability exists on an affected system...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 7724 Views

RISK: Medium Risk

Medium Risk

Google Chrome URI Handler Registration Vulnerability

A vulnerability has been identified in Google Chrome, which could be exploited by attackers to compromise an affected system. This issue is caused due to certain URI handlers being registered in an insecure manner by the browser, which could be exploited by remote attackers to pass malicious...
Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2009 7768 Views

RISK: Medium Risk

Medium Risk

HPOpenView NNM Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in HP OpenView Network Node Manager (OV NNM), which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error which could allow an attacker to remotely execute arbitrary code. No further details...
Last Update Date: 28 Jan 2011 Release Date: 9 Feb 2009 7642 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. A memory corruption errors in the JavaScript and layout...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2009 7669 Views

RISK: Medium Risk

Medium Risk

Nokia PC Suite Multimedia Player Playlist Buffer Overflow Vulnerability

A vulnerability has been identified in Nokia PC Suite, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the Multimedia Player when processing playlists (e.g. ".m3u") with overly long data...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2009 7795 Views

RISK: Medium Risk

Medium Risk

Sun Solaris Libxml2 Data Processing Integer Overflow Vulnerabilities

Two vulnerabilities have been identified in Sun Solaris, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. An integer overflow error in the "xmlSAX2Characters()" function when processing an overly large XML file, which could cause...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2009 7610 Views

RISK: Medium Risk

Medium Risk

NovellGroupWise Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell GroupWise, which can be exploited by malicious people to conduct cross-site scripting, cross-site request forgery, and script insertion attacks, bypass certain security restrictions, or compromise a vulnerable system.1. Input passed to...
Last Update Date: 28 Jan 2011 Release Date: 3 Feb 2009 7771 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.1. A heap overflow error when handling malformed RTSP URLs, which could be exploited to crash an affected application or...
Last Update Date: 28 Jan 2011 Release Date: 23 Jan 2009 7561 Views

RISK: Medium Risk

Medium Risk

SymantecAppStream Client ActiveX Insecure Method Vulnerability

A vulnerability has been identified in Symantec AppStream Client, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by errors in the LaunchObj ActiveX control (launcher.dll) that contains unsafe methods e.g. "installAppMgr()", which...
Last Update Date: 28 Jan 2011 Release Date: 19 Jan 2009 7631 Views

RISK: Medium Risk

Medium Risk

Oracle and BEA Products Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2009 7775 Views

RISK: Medium Risk

Medium Risk

Winamp AIFF File Header Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Winamp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when parsing a AIFF file with a malformed header, which could allow attackers to crash an affected application or...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2009 7626 Views

RISK: Medium Risk

Medium Risk

BlackBerry Products PDF Distiller Memory Corruption Vulnerabilities

Multiple vulnerabilities have been identified in various BlackBerry products, which could be exploited by attackers to compromise a vulnerable device. These issues are caused by heap overflow and uninitialized memory errors in the PDF distiller of the BlackBerry Attachment Service component when processing malformed PDF files, which...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2009 7625 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Multiple Vulnerabilities( 14 January 2009 )

Multiple vulnerabilities have been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system.1. SMB Buffer Overflow Remote Code Execution VulnerabilityAn unauthenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2009 7847 Views

RISK: Medium Risk

Medium Risk

HP OpenView Network Node Manager Multiple Remote Vulnerabilities

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager (NNM), which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflow errors in the "OpenView5.exe", "getcvdata....
Last Update Date: 28 Jan 2011 Release Date: 8 Jan 2009 7602 Views

RISK: Medium Risk

Medium Risk

RealNetworks Helix Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in RealNetworks Helix Server, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. A heap overflow error when processing malformed RTSP DESCRIBE requests, which could be exploited to crash an affected server...
Last Update Date: 28 Jan 2011 Release Date: 2 Jan 2009 7694 Views

RISK: Medium Risk

Medium Risk

Trend MicroHouseCall ActiveX Control "notifyOnLoadNative()" Vulnerability

A vulnerability has been identified in Trend Micro HouseCall, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a use-after-free error in the HouseCall ActiveX control (Housecall_ActiveX.dll). This can...
Last Update Date: 28 Jan 2011 Release Date: 22 Dec 2008 7569 Views

RISK: Medium Risk

Medium Risk

BitDefenderfor Linux PE File Handling Memory Corruption Vulnerability

A vulnerability has been identified in BitDefender for Linux, which could be exploited by attackers or malware to cause a denial of service or potentially compromise a vulnerable system. This issue is caused by a memory corruption error in the scanning engine when processing malformed PE binaries packed...
Last Update Date: 28 Jan 2011 Release Date: 22 Dec 2008 7600 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. A memory corruption errors in the...
Last Update Date: 28 Jan 2011 Release Date: 18 Dec 2008 8223 Views