Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Opera Browser Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system.1. A buffer overflow error when handling certain text-area contents, which could...
Last Update Date: 28 Jan 2011 Release Date: 18 Dec 2008 7669 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player for Linux Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player for Linux, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when loading a specially crafted SWF file, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 18 Dec 2008 7567 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to execute arbitrary code, gain access to sensitive information, or cause a denial of service.
Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2008 7681 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Basic Multiple Remote Code Execution Vulnerabilities (10 December 2008)

1. DataGrid Control Memory Corruption VulnerabilityA remote code execution vulnerability exists in the DataGrid ActiveX Control for Visual Basic 6. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7777 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows GDI Two Remote Code Execution Vulnerabilities (10 December 2008)

1. GDI Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that GDI handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted WMF image file. An attacker who successfully exploited this vulnerability could take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7510 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows WordPad Converter Code Execution Vulnerability

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the WordPad Text Converter when processing a specially crafted Word 97 file (.doc, .wri, or...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7644 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Search Code Execution Vulnerabilities (10 December 2008)

1. Windows Saved Search VulnerabilityA remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.2. Windows Search Parsing VulnerabilityA remote code execution vulnerability exists in Windows Explorer...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7264 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Code Execution Vulnerabilities (10 December 2008)

1. File Format Parsing Vulnerability - CVE-2008-4265A remote code execution vulnerability exists in Microsoft Office Excel as a result of memory corruption when loading Excel records. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file that includes...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7271 Views

RISK: Medium Risk

Medium Risk

Microsoft Office SharePoint Server Security Bypass Vulnerability (10 December 2008)

An elevation of privilege vulnerability exists in Microsoft Office SharePoint Server 2007 and Microsoft Office SharePoint Server 2007 Service Pack 1. The vulnerability could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack leading to...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7296 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Code Execution Vulnerabilities (10 December 2008)

1. Word Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file with a malformed record. Users whose accounts are configured to have...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7405 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer XML Parsing Code Execution Vulnerability

A remote code execution vulnerability exists as an invalid pointer reference in the data binding function of Internet Explorer. When data binding is enabled (which is the default state), it is possible under certain conditions for an object to be released without updating the array length, ...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7387 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Products Code Execution Vulnerabilities (10 December 2008)

1. SPN VulnerabilityA credential reflection vulnerability exists in the Windows Media components that could allow an attacker to execute code with the same rights as the local user or with Windows Media Services distribution credentials. The vulnerability exists due to weaknesses in Service Principal Name (SPN) ...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7389 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Code Execution Vulnerabilities (10 December 2008)

1. Parameter Validation Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Internet Explorer handles certain navigation methods. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code...
Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 7326 Views

RISK: Medium Risk

Medium Risk

Sun Java JDK / JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or take complete control of an affected system.1. Due to JRE creating temporary files...
Last Update Date: 28 Jan 2011 Release Date: 5 Dec 2008 7668 Views

RISK: Medium Risk

Medium Risk

BitDefenderAntivirus PDF Processing Memory Corruption Vulnerability

It has discovered a vulnerability in BitDefender Antivirus, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.The vulnerability is caused due to a boundary error in the "pdf.xmd" module...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2008 7799 Views

RISK: Medium Risk

Medium Risk

AppleiPhone / iPod touch Multiple Vulnerabilities

Some weaknesses, security issues, and vulnerabilities have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people to bypass certain security restrictions, disclose potential sensitive information, conduct spoofing attacks, to cause a DoS (Denial of Service), or...
Last Update Date: 28 Jan 2011 Release Date: 24 Nov 2008 7838 Views

RISK: Medium Risk

Medium Risk

Adobe AIR Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe AIR, which can be exploited by malicious people to compromise a user's system.1. Due to multiple unspecified input validation errors in the parsing of SWF files which can be exploited to potentially execute arbitrary code.2...
Last Update Date: 28 Jan 2011 Release Date: 19 Nov 2008 7850 Views

RISK: Medium Risk

Medium Risk

Apple Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by buffer overflow, uninitialized memory access, memory corruption, ...
Last Update Date: 28 Jan 2011 Release Date: 17 Nov 2008 7863 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. An error when using the canvas...
Last Update Date: 28 Jan 2011 Release Date: 14 Nov 2008 7689 Views

RISK: Medium Risk

Medium Risk

Trend Micro ServerProtect Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Trend Micro ServerProtect, which could be exploited by remote attackers to take complete control of an affected system.An access control error within an unspecified RPC interface could allow remote unauthenticated attackers to gain administrative access to a vulnerable server.Various...
Last Update Date: 28 Jan 2011 Release Date: 13 Nov 2008 7764 Views

RISK: Medium Risk

Medium Risk

Apple iLife and Aperture Image Handling Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple iLife and Aperture, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by uninitialized memory access and memory corruption errors in ImageIO when processing malformed LZW-encoded TIFF images or embedded ICC profiles...
Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2008 7605 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Credential Reflection Vulnerability( 12 November 2008 )

A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles NTLM credentials when a user connects to an attacker's SMB server. This vulnerability allows an attacker to replay the user's credentials back to them and execute...
Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2008 7714 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Multiple Vulnerabilities( 12 November 2008 )

1. MSXML Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that Microsoft XML Core Services parses XML content. The vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail...
Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2008 7403 Views

RISK: Medium Risk

Medium Risk

Adobe Reader/Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in in Adobe Reader/Acrobat, which can be exploited by malicious people to compromise a user's system.1. A memory corruption error when passing an overly long argument to an AcroJS function, which could be exploited to crash...
Last Update Date: 28 Jan 2011 Release Date: 5 Nov 2008 7831 Views

RISK: Medium Risk

Medium Risk

Opera Command Execution and Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to conduct cross-site scripting attacks or compromise a user's system.1. Certain parameters passed to the "History Search" functionality are not properly sanitised before being used. ...
Last Update Date: 28 Jan 2011 Release Date: 31 Oct 2008 7651 Views

RISK: Medium Risk

Medium Risk

OpenOffice WMF and EMF Handling Heap Overflow Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice, which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a heap overflow error when processing malformed WMF files, which could be exploited by attackers to execute arbitrary code by tricking a user into...
Last Update Date: 28 Jan 2011 Release Date: 30 Oct 2008 7860 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Server Service Vulnerability ( 24October 2008 )

A remote code execution vulnerability exists in the Server service on Windows systems. The vulnerability is due to the service not properly handling specially crafted RPC requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 24 Oct 2008 7783 Views

RISK: Medium Risk

Medium Risk

F-Secure Products RPM File Handling Integer Overflow Vulnerability

A vulnerability has been identified in various F-Secure products, which could be exploited by attackers or malware to compromise a vulnerable system. This issue is caused by an integer overflow error when processing malformed RPM files, which could be exploited to crash an affected application...
Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2008 7634 Views

RISK: Medium Risk

Medium Risk

Adobe Flash CS3 SWF File Handling Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash CS3, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by heap overflow errors when processing overly long control parameters within an SWF file, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 17 Oct 2008 7766 Views

RISK: Medium Risk

Medium Risk

Oracle and BEA Products Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 8057 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Message Queuing Service Remote Code Execution Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the Message Queuing Service due to a specific flaw in the parsing of an RPC request to the Message Queuing service.An attacker could exploit the vulnerability by sending a specially crafted RPC request. A heap request can be controlled and...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7393 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Buffer Underflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles specially crafted file names. An attempt to exploit the vulnerability would require authentication because the vulnerable function is only reachable when the share type is a disk, and by...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7621 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Virtual Address Descriptor Elevation of Privilege Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the way that Memory Manager handles memory allocation and Virtual Address Descriptors (VADs). The vulnerability could allow elevation of privilege if an authenticated attacker runs a specially crafted program on an affected system. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7353 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Internet Printing Service Integer Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists on Windows systems running IIS with the internet printing service enabled. This issue could allow a remote, authenticated attacker to execute arbitrary code on an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7352 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 15 October 2008 )

1. Windows Kernel Window Creation VulnerabilityAn elevation of privilege vulnerability exists because the Windows kernel does not properly validate properties of a window passed during the new window creation process. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7280 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 15 October 2008 )

1. Window Location Property Cross-Domain VulnerabilityA remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7339 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability is due to incorrect memory allocation when receiving specially crafted LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7338 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Kernel Overwrite Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the Ancillary Function Driver (afd.sys) due to Windows improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7352 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilities( 15 October 2008 )

1. Calendar Object Validation VulnerabilityA remote code execution vulnerability exists in the way Excel processes a VBA Performance Cache. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file in a VBA Performance Cache. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7391 Views

RISK: Medium Risk

Medium Risk

Microsoft Host Integration Server Command Execution Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the SNA Remote Procedure Call (RPC) service for Host Integration Server. An attacker could exploit the vulnerability by constructing a specially crafted RPC request. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 7315 Views

RISK: Medium Risk

Medium Risk

SunJava System Web Proxy Server FTP Heap Overflow Vulnerability

A vulnerability has been identified in Sun Java System Web Proxy Server, which could be exploited by remote or local attackers to compromise a vulnerable system. This issue is caused by a heap overflow error in the FTP subsytem when processing malformed data, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2008 7611 Views

RISK: Medium Risk

Medium Risk

MacOS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X,which could be exploited by remote or local attackers to disclose sensitive information,bypass security restrictions, cause a denial of service or compromise an affected system.These issues are caused by buffer overflow, range checking...
Last Update Date: 28 Jan 2011 Release Date: 10 Oct 2008 7720 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. Due to an error when processing page redirects to a specially crafted address (URL), which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 9 Oct 2008 7599 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server and VMware VirtualCenter Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various VMWare products, which could be exploited by remote attackers to bypass security restrictions or compromise a vulnerable system, or by local attackers to disclose sensitive information or gain elevated privileges, cause a denial of service or take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 8 Oct 2008 7692 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory Heap Overflow and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Novell eDirectory, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. Due to heap overflow errors when processing update replica verbs (Opcode 0x23 and 0x24), which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 8 Oct 2008 7539 Views

RISK: Medium Risk

Medium Risk

AppleTV Multiple Vulnerabilities

Some vulnerabilities have been reported in Apple TV, which can be exploited by malicious people to compromise a vulnerable system.1) An error in the processing of movie atoms can be exploited to cause a stack-based buffer overflow.2) An error in the...
Last Update Date: 28 Jan 2011 Release Date: 6 Oct 2008 7775 Views

RISK: Medium Risk

Medium Risk

Trend Micro OfficeScan Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Trend Micro OfficeScan, which could be exploited by remote attackers to gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system.1. Due to an unspecified buffer overflow error in certain CGI modules, which...
Last Update Date: 28 Jan 2011 Release Date: 3 Oct 2008 7666 Views

RISK: Medium Risk

Medium Risk

WinZipGDI+ Library Multiple Vulnerabilities

Multiple vulnerabilities have been identified in WinZip, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused due to the application placing a vulnerable "gdiplus.dll" library in the program folder and using it on Windows...
Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2008 7893 Views

RISK: Medium Risk

Medium Risk

Mac OS X Java Multiple Vulnerabilities

Some vulnerabilities have been identified in Java for Mac OS X, which can be exploited by malicious people to cause a Denial of Service, to bypass certain security restrictions, disclose system information or potentially sensitive information, or to compromise a vulnerable system.1) An...
Last Update Date: 28 Jan 2011 Release Date: 26 Sep 2008 7630 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. A stack overflow error when processing...
Last Update Date: 28 Jan 2011 Release Date: 25 Sep 2008 7519 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Linecard Redundancy Unauthorized Access Vulnerability

Cisco IOS software contains a vulnerability when running on uBR10012 series devices that could allow an unauthenticated, remote attacker to gain privileged access to the device.The vulnerability exists when the device is configured for linecard redundancy, which is the default setting. The device automatically enables...
Last Update Date: 28 Jan 2011 Release Date: 25 Sep 2008 7757 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey and Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. A stack overflow error when processing...
Last Update Date: 28 Jan 2011 Release Date: 25 Sep 2008 7632 Views

RISK: Medium Risk

Medium Risk

Adobe Illustrator Unspecified Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Illustrator CS2 for Mac, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by unspecified errors when processing AI files, which could be exploited to execute arbitrary code by tricking a user into opening...
Last Update Date: 28 Jan 2011 Release Date: 18 Sep 2008 7759 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by buffer overflow, insecure file...
Last Update Date: 28 Jan 2011 Release Date: 17 Sep 2008 7925 Views

RISK: Medium Risk

Medium Risk

Apple iPhone Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iPhone, which could be exploited by attackers to bypass security restrictions, poison DNS cache, cause a denial of service or compromise a vulnerable system.1. An error in the Application Sandbox that does not properly enforce access restrictions...
Last Update Date: 28 Jan 2011 Release Date: 16 Sep 2008 8011 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system.1. Due to an uninitialized memory access in the third-party Indeo v5 codec (not shipped with QuickTime), which could be...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2008 7517 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Uniform Resource Locator Validation Error Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted URLs using the OneNote protocol handler (onenote://). The vulnerability could allow remote code execution if a user clicks a specially crafted OneNote URL. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 7506 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player Sampling Rate Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in Windows Media Player 11. An attacker could exploit the vulnerability by constructing a specially crafted audio file that could allow remote code execution when streamed from a Windows Media server using Windows Media Player 11. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 7344 Views

RISK: Medium Risk

Medium Risk

Microsoft Products GDI+ Multiple Vulnerabilities( 10 September 2008 )

1. GDI+ VML Buffer Overrun VulnerabilityA remote code execution vulnerability exists in the way that GDI+ handles gradient sizes. The vulnerability could allow remote code execution if a user browses to a Web site that contains specially crafted content. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 7764 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Encoder Buffer Overrun Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in the WMEX.DLL ActiveX control installed by Windows Media Encoder 9 Series. The vulnerability could allow remote code execution if a user views a specially crafted Web page. If a user is logged on with administrative user rights, an...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 7764 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system.1. Due to an uninitialized memory access in the third-party Indeo v5 codec (not shipped with QuickTime), which could be...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2008 7651 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

VMware Server 1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.2. An unspecified error when processing malformed requests exists within...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2008 7653 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory Multiple Vulnerabilities

Multiple vulnerabilites have been identified in Novell eDirectory, which could be exploited by attackers to execute arbitrary scripting code, cause a denial of service or compromise a vulnerable system.1. An unspecified heap overflow error, which could allow attackers to execute arbitrary code.2...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2008 7671 Views

RISK: Medium Risk

Medium Risk

Novell Forum TCL Command Injection Vulnerability

A vulnerability has been reported in Novell Forum, which can be exploited by malicious people to to compromise a vulnerable system.The vulnerability is caused due to an unspecified error when handling certain requests, which can be exploited to inject and execute TCL commands by modifying the...
Last Update Date: 28 Jan 2011 Release Date: 1 Sep 2008 7622 Views

RISK: Medium Risk

Medium Risk

AWStats Totals Code Execution and Cross Ste Scripting Vulnerabilities

Multiple vulnerabilities have been identified in AWStats Totals, which could be exploited by remote attackers to execute arbitrary commands or scripting code.1. An input validation errors when processing the "month" and "year" parameters, which could be exploited by attackers to cause...
Last Update Date: 28 Jan 2011 Release Date: 28 Aug 2008 7816 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, disclose potentially sensitive information, or potentially compromise a user's system.1. An unspecified error exists...
Last Update Date: 28 Jan 2011 Release Date: 21 Aug 2008 7762 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Studio Masked Edit Control "Mask" Code Execution Vulnerability

A vulnerability has been identified in Microsoft Visual Studio, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "Msmask32.ocx" ActiveX control...
Last Update Date: 28 Jan 2011 Release Date: 15 Aug 2008 7832 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or execute arbitrary code. These issues are caused by errors in OpenSSL, net-snmp...
Last Update Date: 28 Jan 2011 Release Date: 14 Aug 2008 7638 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Image Color Management System Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Color Management System (MSCMS) module of the Microsoft ICM component handles memory allocation. The vulnerability could allow remote code execution if a user opens a specially crafted image file. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7484 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IPsec Policy Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in the manner in which IPsec policies are imported to Windows Server 2008 domains from Windows Server 2003 domains. This vulnerability could cause systems to ignore IPsec policies and transmit network traffic in clear text. This, in turn, would potentially disclose...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7357 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Record Parsing Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed record value. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7383 Views

RISK: Medium Risk

Medium Risk

Microsoft PowerPoint Multiple Vulnerabilities( 13 August 2008 )

1. Memory Allocation VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office PowerPoint Viewer 2003 handles specially crafted PowerPoint files. An attacker could exploit the vulnerability by creating a specially crafted PowerPoint file that could be included as an e-mail attachment, or...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7504 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Event System Vulnerability( 13 August 2008 )

1. Event System VulnerabilityA remote code execution vulnerability exists because the Microsoft Windows Event System does not correctly validate user subscriptions requests when created. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7429 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Filters Multiple Vulnerabilities( 13 August 2008 )

1. Microsoft Malformed EPS Filter VulnerabilityA remote code execution vulnerability exists in the way that a Microsoft Office filter handles a malformed graphics image. An attacker could exploit the vulnerability by constructing a specially crafted Encapsulated PostScript (EPS) file that could allow remote code execution if...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7617 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook Express and Windows Mail URL Parsing Cross-Domain Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in Outlook Express and Windows Mail because the MHTML protocol handler incorrectly interprets MHTML URL redirections that could potentially bypass Internet Explorer domain restrictions when returning MHTML content. An attacker could exploit the vulnerability by constructing a specially crafted Web page. If the...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7465 Views

RISK: Medium Risk

Medium Risk

Microsoft Access Snapshot Viewer Arbitrary File Download Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the ActiveX control for the Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7633 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilities( 13 August 2008 )

1. Excel Indexing Validation VulnerabilityA remote code execution vulnerability exists in the way Excel processes index values when loading Excel files into memory. An attacker could exploit the vulnerability by opening a specially crafted file which could be hosted on a Web site, or included as an...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7515 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 13 August 2008 )

1. HTML Objects Memory Corruption VulnerabilityA remote code execution vulnerability exists in Internet Explorer due to attempts to access uninitialized memory in certain situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7491 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Messenger Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in supported versions of Windows Messenger. Scripting of a particular ActiveX control, Messenger.UIAutomation.1, could allow information disclosure from these programs in the context of the logged-on user. An attacker could change state, get contact...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 7570 Views

RISK: Medium Risk

Medium Risk

Sun Solaris "snoop" Utility Remote Command Execution Vulnerability

A vulnerability has been identified in Sun Solaris, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by unspecified errors in the "snoop" network utility when displaying SMB traffic, which may allow a remote attacker to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 7 Aug 2008 7828 Views

RISK: Medium Risk

Medium Risk

CA ARCserve Backup LGServer Service Vulnerability

A vulnerability has been identified in CA ARCserve Backup for Laptops and Desktops, CA Desktop Management Suite and CA Protection Suites, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an integer underflow error...
Last Update Date: 28 Jan 2011 Release Date: 5 Aug 2008 7740 Views

RISK: Medium Risk

Medium Risk

Sun Solaris Adobe Reader Multiple Vulnerabilities

A vulnerability and a security issue in Adobe Reader in Sun Solaris, which can be exploited by malicious, local users to perform certain actions with escalated privileges and potentially by malicious people to compromise a user's system.NOTE: Solaris 8, Solaris 9, ...
Last Update Date: 28 Jan 2011 Release Date: 5 Aug 2008 7790 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.1. Due to a stack buffer overflow error in...
Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2008 7637 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or execute arbitrary code.
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2008 7639 Views

RISK: Medium Risk

Medium Risk

Trend Micro OfficeScan ObjRemoveCtrl Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Trend Micro OfficeScan, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the Web-Deployment ObjRemoveCtrl Class ActiveX control (...
Last Update Date: 28 Jan 2011 Release Date: 29 Jul 2008 7590 Views

RISK: Medium Risk

Medium Risk

RealNetworks RealPlayer SWF Frame Handling Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which potentially can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a design error within the handling of frames in Shockwave Flash (SWF) files and can be exploited to...
Last Update Date: 28 Jan 2011 Release Date: 28 Jul 2008 7652 Views

RISK: Medium Risk

Medium Risk

Bea Weblogic Apache Connector Buffer Overflow Vulnerability

A vulnerability in Bea Weblogic, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.The vulnerability is caused due to a boundary error within the Apache connector and can be exploited to cause a stack...
Last Update Date: 28 Jan 2011 Release Date: 21 Jul 2008 7682 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox for Mac OS X GIF Rendering Code Execution Vulnerability

A vulnerability has been identified in Mozilla Firefox for Mac OS X, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the Mozilla graphics code when handling malformed GIF data, which could be exploited by attackers...
Last Update Date: 28 Jan 2011 Release Date: 18 Jul 2008 7790 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 17 Jul 2008 7962 Views

RISK: Medium Risk

Medium Risk

HP Oracle for OpenView Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Oracle for OpenView (OfO) , which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute...
Last Update Date: 28 Jan 2011 Release Date: 17 Jul 2008 8609 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox URI Launching and XUL Error Page Vulnerabilities

Multiple vulnerabilities have been identified in Firefox, which can be exploited by malicious people to bypass certain security restrictions, potentially conduct spoofing attacks, or compromise a user's system.1. A vulnerability can be exploited to launch e.g. "file" or...
Last Update Date: 28 Jan 2011 Release Date: 17 Jul 2008 7587 Views

RISK: Medium Risk

Medium Risk

Apple iPhone / iPod touch Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iPhone and iPod touch, which could be exploited by remote attackers to disclose sensitive information, spoof certain data, cause a denial of service or compromise a vulnerable device.1. An error in CFNetwork when processing 502 Bad Gateway...
Last Update Date: 28 Jan 2011 Release Date: 15 Jul 2008 7543 Views

RISK: Medium Risk

Medium Risk

Apple TV Data Processing Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple TV, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by buffer overflow and input validation errors when processing specially crafted movie files, QuickTime content or PICT images, which...
Last Update Date: 28 Jan 2011 Release Date: 14 Jul 2008 7553 Views

RISK: Medium Risk

Medium Risk

Sun Java JDK / JRE Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.1. An error in the...
Last Update Date: 28 Jan 2011 Release Date: 10 Jul 2008 7858 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Document Handling Code Execution Vulnerability

A vulnerability has been identified in Microsoft Office, which could be exploited by attackers to take complete control of an affected system. This issue is caused by a memory corruption error when handling malformed Word documents, which could be exploited by attackers to crash a vulnerable application...
Last Update Date: 28 Jan 2011 Release Date: 10 Jul 2008 7384 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Multiple DNS Spoofing Vulnerabilities( 09 July 2008 )

1. DNS Insufficient Socket Entropy VulnerabilityA spoofing vulnerability exists in Windows DNS client and Windows DNS server. This vulnerability could allow a remote unauthenticated attacker to quickly and reliably spoof responses and insert records into the DNS server or client cache, thereby redirecting Internet traffic.2...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 7414 Views

RISK: Medium Risk

Medium Risk

Multiple DNS Implementations Cache Poisoning Vulnerabilities

Deficiencies in the DNS protocol and common DNS implementations facilitate DNS cache poisoning attacks. DNS cache poisoning (sometimes referred to as cache pollution) is an attack technique that allows an attacker to introduce forged DNS information into the cache of a caching nameserver. The general concept...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 9482 Views

RISK: Medium Risk

Medium Risk

Microsoft SQL Server Multiple Vulnerabilities( 09 July 2008 )

1. Memory Page Reuse VulnerabilityAn information disclosure vulnerability exists in the way that SQL Server manages memory page reuse. An attacker with database operator access who successfully exploited this vulnerability could access customer data.2. Convert Buffer OverrunA vulnerability exists in the convert function in SQL...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 7702 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Explorer Saved Search Vulnerability( 09 July 2008 )

A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 7388 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook Web Access for Exchange Server Multiple Cross-Site Scripting Vulnerabilities( 09 July 2008 )

1. Outlook Web Access for Exchange Server Data Validation Cross-Site Scripting VulnerabilityThis is a cross-site scripting vulnerability in the affected versions of Outlook Web Access (OWA) for Exchange Server. Exploitation of the vulnerability could lead to elevation of privilege on individual OWA...
Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 7451 Views