Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Access Snapshot Viewer ActiveX Control Vulnerability

A vulnerability has been identified in the Snapshot Viewer for Microsoft Access, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a design error in the "snapview.ocx" ActiveX control that does not restrict...
Last Update Date: 28 Jan 2011 Release Date: 8 Jul 2008 7645 Views

RISK: Medium Risk

Medium Risk

Opera for Windows Unspecified Code Execution Vulnerability

A vulnerability has been reported in Opera, which can be exploited by malicious people to compromise a vulnerable system.The vulnerability is caused due to an unspecified error, which can be exploited to execute arbitrary code. No further information is currently available.The vulnerability is...
Last Update Date: 28 Jan 2011 Release Date: 3 Jul 2008 7682 Views

RISK: Medium Risk

Medium Risk

Mozilla Products Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. Due to memory corruption errors in...
Last Update Date: 28 Jan 2011 Release Date: 3 Jul 2008 7573 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to cause a denial of service, disclose sensitive information, bypass security restrictions or compromise an affected system. These issues are caused by implementation, data validation, ...
Last Update Date: 28 Jan 2011 Release Date: 2 Jul 2008 7683 Views

RISK: Medium Risk

Medium Risk

Apple Safari Remote Code Execution Vulnerability

A vulnerability has been identified in Apple Safari, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a memory corruption error in WebKit when handling malformed JavaScript arrays, which could be exploited to...
Last Update Date: 28 Jan 2011 Release Date: 2 Jul 2008 7500 Views

RISK: Medium Risk

Medium Risk

IBM AFP Viewer Plug-In "SRC" Property Buffer Overflow Vulnerability

A vulnerability has been identified in IBM AFP Viewer Plug-In, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when handling an overly long "...
Last Update Date: 28 Jan 2011 Release Date: 30 Jun 2008 7866 Views

RISK: Medium Risk

Medium Risk

Adobe Products JavaScript Method Code Execution Vulnerability

A vulnerability has been identified in Adobe Reader and Acrobat, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an unspecified input validation error in a JavaScript method, which could allow attackers to execute arbitrary code...
Last Update Date: 28 Jan 2011 Release Date: 25 Jun 2008 7617 Views

RISK: Medium Risk

Medium Risk

HP-UX CIFS Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in CIFS Server.
Last Update Date: 28 Jan 2011 Release Date: 25 Jun 2008 7665 Views

RISK: Medium Risk

Medium Risk

Apple Safari for Windows Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to disclose sensitive information or compromise a vulnerable system.1. Due to an error when handling BMP and GIF images, which could cause an out-of-bounds memory read...
Last Update Date: 28 Jan 2011 Release Date: 23 Jun 2008 7596 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing certain data, which could allow attackers to execute arbitrary code by tricking a user into visiting a...
Last Update Date: 28 Jan 2011 Release Date: 20 Jun 2008 7494 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service, or execute arbitrary commands and scripting code. These issues are caused by errors in Tomcat and JRE...
Last Update Date: 28 Jan 2011 Release Date: 18 Jun 2008 7554 Views

RISK: Medium Risk

Medium Risk

OpenOffice "rtl_allocateMemory()" Integer Overflow Vulnerability

A vulnerability has been identified in OpenOffice.org, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by an integer overflow error in the custom memory allocation function "rtl_allocateMemory()" when processing malformed data...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7709 Views

RISK: Medium Risk

Medium Risk

SNMPv3 Authentication Bypass Vulnerability

A vulnerability has been identified in the way implementations of SNMPv3 handle specially crafted packets may allow authentication bypass.The Simple Network Management Protocol (SNMP) is a widely deployed protocol that is commonly used to monitor and manage network devices. SNMPv3 (RFC 3410) supports...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 8879 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Pragmatic General Multicast (PGM) Multiple Vulnerabilities( 11 June 2008 )

1. PGM Invalid Length VulnerabilityA denial of service vulnerability exists in implementations of the Pragmatic General Multicast (PGM) protocol on Microsoft Windows XP and Windows Server 2003. The vulnerability is due to improper validation of specially crafted PGM packets. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7772 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows WINS Memory Overwrite Vulnerability( 11 June 2008 )

An elevation of privilege vulnerability exists in the Windows Internet Name Service (WINS) in the way that WINS does not sufficiently validate the data structures within specially crafted WINS network packets. The vulnerability could allow a local attacker to run code with elevated privileges. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7628 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 11 June 2008 )

1. HTML Objects Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Internet Explorer displays a Web page that contains certain unexpected method calls to HTML objects. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7399 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Bluetooth Vulnerability( 11 June 2008 )

A remote code execution vulnerability exists in the Bluetooth stack in Microsoft Windows because the Bluetooth stack does not correctly handle a large number of service description requests. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7335 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows DirectX MJPEG/SAMI File Processing Vulnerabilities( 11 June 2008 )

1. MJPEG Decoder VulnerabilityA remote code execution vulnerability exists in the way that the Windows MJPEG Codec handles MJPEG streams in AVI or ASF files. A user would have to preview or play a specially crafted MJPEG file for the vulnerability to be exploited.2. SAMI...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7665 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by memory corruption and implementation errors when processing specially crafted PICT images, AAC-encoded or Indeo video codec media...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7716 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Vulnerability( 11 June 2008 )

A denial of service vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008. The vulnerability also exists in implementations of Active Directory Application Mode (ADAM) when installed on Windows XP and Windows Server 2003 and...
Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 7387 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by local or remote attackers to bypass security restrictions, cause a denial of service or compromise a vulnerable system.1. Due to an input validation error in the "HGFS.sys" ...
Last Update Date: 28 Jan 2011 Release Date: 6 Jun 2008 8309 Views

RISK: Medium Risk

Medium Risk

Sun Java System Active Server Pages Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java System Active Server Pages, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to disclose sensitive information, manipulate certain data, bypass certain security restrictions, or to compromise a vulnerable system...
Last Update Date: 28 Jan 2011 Release Date: 5 Jun 2008 7781 Views

RISK: Medium Risk

Medium Risk

CA Secure Content Manager Multiple Vulnerabilities

Multiple vulnerabilities have been identified in CA Secure Content Manager (CA eTrust Secure Content Manager), which could be exploited by attackers to cause a denial of service or compromise an affected system. These issues are caused by unspecified input validation and buffer overflow errors when processing certain...
Last Update Date: 28 Jan 2011 Release Date: 5 Jun 2008 7746 Views

RISK: Medium Risk

Medium Risk

HP Instant Support ActiveX Control Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Instant Support, which could be exploited by remote attackers to manipulate data or take complete control of an affected system.1. Due to buffer overflow errors in the "HPISDataManager.dll" ActiveX control when processing malformed data passed...
Last Update Date: 28 Jan 2011 Release Date: 5 Jun 2008 7679 Views

RISK: Medium Risk

Medium Risk

Apple Safari for Windows Remote Code Execution Vulnerability

A vulnerability has been identified in Apple Safari for Windows, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by errors within the combination of the default download location in Safari and how the Windows desktop handles executables...
Last Update Date: 28 Jan 2011 Release Date: 3 Jun 2008 7581 Views

RISK: Medium Risk

Medium Risk

CiscoWorks Common Services Remote Code Execution Vulnerability

A vulnerability has been identified in CiscoWorks Common Services, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing user-supplied data, which could allow a remote attacker to execute arbitrary code on the...
Last Update Date: 28 Jan 2011 Release Date: 30 May 2008 7897 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS XMultiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to cause a denial of service, disclose sensitive information, bypass security restrictions or compromise an affected system. These issues are caused by implementation, data validation, ...
Last Update Date: 28 Jan 2011 Release Date: 30 May 2008 7725 Views

RISK: Medium Risk

Medium Risk

Samba "receive_smb_raw()" Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Samba, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the "receive_smb_raw()" [lib/util_sock.c] function when processing...
Last Update Date: 28 Jan 2011 Release Date: 29 May 2008 7783 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an unspecified memory corruption error when processing a malformed SWF file, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 28 May 2008 7600 Views

RISK: Medium Risk

Medium Risk

FileZilla GnuTLS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FileZilla, which could be exploited by remote attackers to cause a denial of service or compromise an affected system.1. Due to a NULL pointer dereference error when processing TLS packets containing multiple "Client Hello" messages, which could...
Last Update Date: 28 Jan 2011 Release Date: 22 May 2008 7853 Views

RISK: Medium Risk

Medium Risk

CA Products Code Execution and File Manipulation Vulnerabilities

Multiple vulnerabilities have been identified in various CA products, which could be exploited by remote attackers to take complete control of an affected system.1. Due to insufficient path verification by the logging service (caloggerd), which could allow a remote attacker to append data to...
Last Update Date: 28 Jan 2011 Release Date: 21 May 2008 7636 Views

RISK: Medium Risk

Medium Risk

Debian/Ubuntu OpenSSL Random Number Generator Vulnerability

A vulnerabiliity exists in the random number generator used by the OpenSSL package included with the Debian GNU/Linux, Ubuntu, and other Debian-based operating systems. This vulnerability causes the generated numbers to be predictable.The result of this error is that certain encryption...
Last Update Date: 28 Jan 2011 Release Date: 19 May 2008 11677 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Two Vulnerabilities( 14 May 2008 )

1. Object Parsing VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted Rich Text Format (.rtf) files. The vulnerability could allow remote code execution if a user opens a specially crafted .rtf file with malformed strings in Word or...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 7356 Views

RISK: Medium Risk

Medium Risk

Yahoo! Assistant "ynotifier" ActiveX Control Code Execution Vulnerability

A vulnerability has been identified in Yahoo! Assistant, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a memory corruption error when instantiating the "ynotifier.dll" ActiveX control, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 7528 Views

RISK: Medium Risk

Medium Risk

Microsoft Publisher Object Handler Validation Vulnerability( 14 May 2008 )

A remote code execution vulnerability exists in the way Microsoft Publisher validates object header data. An attacker could exploit the vulnerability by sending a specially crafted Publisher file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 7375 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows CE Image Processing Vulnerabilities

Multiple vulnerabilities have been identified in Microsoft Windows CE, which could be exploited by attackers to take complete control of an affected device. These issues are caused by unspecified errors when processing malformed JPEG (GDI+) and GIF images, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 7500 Views

RISK: Medium Risk

Medium Risk

Microsoft Jet Engine MDB File Parsing Stack Overflow Vulnerability( 14 May 2008 )

A buffer overrun vulnerability exists in the Microsoft Jet Database Engine (Jet) that could allow remote code execution on an affected system. An attacker could exploit the vulnerability by creating a specially crafted database query and sending it through an application that is using Jet on an...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 7422 Views

RISK: Medium Risk

Medium Risk

Novell GroupWise "mailto:" URI Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Novell GroupWise, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when processing overly long "mailto:" URIs, which...
Last Update Date: 28 Jan 2011 Release Date: 2 May 2008 7527 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Expeditor "cai:" URI Handler Command Injection Vulnerability

A vulnerability has been identified in IBM Lotus Expeditor, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an input validation error when handling "cai" URIs and passing the "-launcher" argument to the...
Last Update Date: 28 Jan 2011 Release Date: 2 May 2008 7622 Views

RISK: Medium Risk

Medium Risk

WordPress Cookie Integrity Protection Privilege Escalation Vulnerability

A vulnerability has been identified in WordPress, which could be exploited by attackers to compromise an affected web site. This issue is caused by an error in the MAC calculation procedure when handling the "USERNAME" and "EXPIRY_TIME" parameters contained in the authentication cookie, ...
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2008 7627 Views

RISK: Medium Risk

Medium Risk

StarOffice/StarSuite Multiple Vulnerabilities

Multiple vulnerabilities have been identified in StarOffice/StarSuite, which could be exploited by attackers to cause a denial of service or compromise an affected system. These issues are caused by heap overflow and corruption errors when processing specially crafted ODF text documents with XForms, or when...
Last Update Date: 28 Jan 2011 Release Date: 29 Apr 2008 7691 Views

RISK: Medium Risk

Medium Risk

HP Software Update HPeDiag ActiveX Control Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Software Update, which could be exploited by remote attackers to gain knowledge of sensitive information or take complete control of an affected system.1. Due to a buffer overflow error in the HPeDiag ActiveX control when handling malformed data passed...
Last Update Date: 28 Jan 2011 Release Date: 28 Apr 2008 7702 Views

RISK: Medium Risk

Medium Risk

Cisco Network Admission Control Shared Secret Vulnerability

A vulnerability has been identified in the Cisco Network Admission Control (NAC) Appliance, which could allow an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM).
Last Update Date: 28 Jan 2011 Release Date: 25 Apr 2008 7675 Views

RISK: Medium Risk

Medium Risk

Adobe Products BMP Handling Buffer Overflow Vulnerability

A vulnerability has been identified in multiple Adobe products, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when parsing malformed BMP images, which could be...
Last Update Date: 28 Jan 2011 Release Date: 23 Apr 2008 7660 Views

RISK: Medium Risk

Medium Risk

ICQ Personal Status Manager Vulnerability

A vulnerability has been identified in ICQ, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by a buffer overflow error in the Personal Status Manager feature when processing a specially crafted status message, which...
Last Update Date: 28 Jan 2011 Release Date: 22 Apr 2008 7631 Views

RISK: Medium Risk

Medium Risk

Mozilla JavaScript Garbage Collector Vulnerability

A vulnerability has been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by memory corruption errors in the JavaScript Garbage Collector when processing malformed data, ...
Last Update Date: 28 Jan 2011 Release Date: 18 Apr 2008 7655 Views

RISK: Medium Risk

Medium Risk

OpenOffice Multiple Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to cause a denial of service or compromise an affected system. These issues are caused by heap overflow and corruption errors when processing specially crafted ODF text documents with XForms, or when...
Last Update Date: 28 Jan 2011 Release Date: 18 Apr 2008 7886 Views

RISK: Medium Risk

Medium Risk

CA Products DSM "gui_cm_ctrls" ActiveX Vulnerability

A vulnerability has been identified in various CA products, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by input validation errors in the DSM "gui_cm_ctrls" ActiveX control when handling...
Last Update Date: 28 Jan 2011 Release Date: 18 Apr 2008 7742 Views

RISK: Medium Risk

Medium Risk

Safari Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to disclose sensitive information, cause a denial of service or execute arbitrary code.1. An error in WebKit when handling URLs containing a colon character in the host name, which...
Last Update Date: 28 Jan 2011 Release Date: 18 Apr 2008 7615 Views

RISK: Medium Risk

Medium Risk

DivX Player Subtitle Parsing Client-Side Buffer Overflow Vulnerability

A vulnerability has been identified in DivX Player, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when parsing overly long subtitles, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 17 Apr 2008 7677 Views

RISK: Medium Risk

Medium Risk

ClamAV PeSpin and Archives Processing Multiple Vulnerabilities

Multiple vulnerabilities have been identified in ClamAV (Clam AntiVirus), which could be exploited by attackers or malware to cause a denial of service or compromise a vulnerable system.1. Due to a heap overflow error in "libclamav/spin.c" when processing malformed...
Last Update Date: 28 Jan 2011 Release Date: 16 Apr 2008 7587 Views

RISK: Medium Risk

Medium Risk

ClamAV Upack Executable Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Clam AntiVirus (ClamAV), which could be exploited by remote attackers or malware to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "cli_scanpe()" [libclamav...
Last Update Date: 28 Jan 2011 Release Date: 15 Apr 2008 7603 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information or take complete control of an affected system.1. Due to a buffer overflow error in the processing of "Declare...
Last Update Date: 28 Jan 2011 Release Date: 10 Apr 2008 7683 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Data Stream Handling Memory Corruption Vulnerability( 09 April 2008 )

A remote code execution vulnerability exists in Internet Explorer because of the way that it processes data streams. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7533 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows VBScript/JScript Remote Code Execution Vulnerability( 09 April 2008 )

A remote code execution vulnerability exists in the way that the VBScript and JScript scripting engines decode script in Web pages. This vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running specially crafted script. If...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7414 Views

RISK: Medium Risk

Medium Risk

Symantec Mail Security Attachment Parsing Vulnerabilities

Multiple vulnerabilities have been identifed in Symantec Mail Security for SMTP, Symantec Mail Security for Domino and Symantec Mail Security for Exchange, which can be exploited by malicious people to compromise a vulnerable system.The vulnerabilities are caused due to various errors within the third-party...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7599 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows GDI Overflow Vulnerability( 09 April 2008 )

1. GDI Heap Overflow VulnerabilityA remote code execution vulnerability exists in the way that GDI handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted EMF or WMF image file. An attacker who successfully exploited this vulnerability could take complete...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7437 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Vulnerability( 09 April 2008 )

An elevation of privilege vulnerability exists due to the Windows kernel improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7355 Views

RISK: Medium Risk

Medium Risk

Microsoft Project Memory Validation Vulnerability( 09 April 2008 )

A remote code execution vulnerability exists in the way Microsoft Project handles specially crafted Project files. An attacker could exploit the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site.
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7368 Views

RISK: Medium Risk

Medium Risk

Microsoft Visio Multiple Vulnerabilities( 09 April 2008 )

1. Visio Object Header VulnerabilityA remote code execution vulnerability exists in the way Microsoft Visio validates object header data in specially crafted files. An attacker could exploit the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7594 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows ActiveX Object Memory Corruption Vulnerability( 09 April 2008 )

A remote code execution vulnerability exists in the ActiveX control hxvz.dll. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7410 Views

RISK: Medium Risk

Medium Risk

Lotus Notes Multiple Keyview Parsing Vulnerabilities

Multiple vulnerabilities have been identified in Lotus Notes, which can be exploited by malicious people to compromise a user's system.The vulnerabilities are caused due to various errors within certain third-party file viewers and can be exploited to cause buffer overflows when a specially...
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7608 Views

RISK: Medium Risk

Medium Risk

Microsoft DNS Client DNS Spoofing Attack Vulnerability( 09 April 2008 )

A spoofing vulnerability exists in Windows DNS clients. The vulnerability could allow an unauthenticated attacker to send malicious responses to DNS requests made by vulnerable clients, thereby spoofing or redirecting Internet traffic from legitimate locations.
Last Update Date: 28 Jan 2011 Release Date: 9 Apr 2008 7427 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.1. Due to an invalid memory access when handling newsfeed prompts, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2008 7579 Views

RISK: Medium Risk

Medium Risk

Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability

A vulnerability has been identified in various Cisco products, which could be exploited by remote attackers to cause a denial of service, disclose sensitive information, or take complete control of an affected system. This issue is caused by a design error in the Disaster Recovery Framework...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2008 7743 Views

RISK: Medium Risk

Medium Risk

Novell Kerberos KDC Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Novell Kerberos KDC, which could be exploited by attackers to gain knowledge of sensitive information, cause a denial of service or take complete control of an affected system.1. Due to errors in KDC when handling krb4 messages, which...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2008 7563 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to disclose sensitive information or take complete control of an affected system. These issues are caused by memory corruption and implementation errors when processing specially crafted Java applets, data reference atoms, ...
Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2008 7617 Views

RISK: Medium Risk

Medium Risk

Cisco IOS Multiple Vulnerabilities

Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service).1) A memory leak exists in the handling of completed PPTP sessions, which...
Last Update Date: 28 Jan 2011 Release Date: 28 Mar 2008 7914 Views

RISK: Medium Risk

Medium Risk

Mozilla Thunderbird Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Thunderbird, which could be exploited by attackers to bypass security restrictions, execute arbitrary scripting code, cause a denial of service or take complete control of an affected system.1. Due to an error in the handling of "...
Last Update Date: 28 Jan 2011 Release Date: 27 Mar 2008 7689 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox and SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and SeaMonkey, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. Due to an error in the handling of...
Last Update Date: 28 Jan 2011 Release Date: 27 Mar 2008 7553 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory LDAP Extended Request Buffer Overflow Vulnerability

A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error when processing overly large LDAP Extended Request messages, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 26 Mar 2008 7775 Views

RISK: Medium Risk

Medium Risk

Apple Safari Memory Corruption and Address Bar Spoofing Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari for Windows, which could be exploited by remote attackers to spoof arbitrary web sites, cause a denial of service or compromise a vulnerable system.1. Due to a memory corruption error when handling overly long filenames, which...
Last Update Date: 28 Jan 2011 Release Date: 26 Mar 2008 7611 Views

RISK: Medium Risk

Medium Risk

Mac OS X Multiple Vulnerabilities

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.1. Multiple boundary errors in AFP client when processing "afp://" URLs can be exploited to cause stack-based buffer overflows when a user connects to a malicious AFP server....
Last Update Date: 28 Jan 2011 Release Date: 20 Mar 2008 7777 Views

RISK: Medium Risk

Medium Risk

MIT Kerberos Updates for Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Kerberos, which could be exploited by attackers to gain knowledge of sensitive information, cause a denial of service or take complete control of an affected system.1. Due to an errors in KDC when handling krb4 messages, which could...
Last Update Date: 28 Jan 2011 Release Date: 20 Mar 2008 7783 Views

RISK: Medium Risk

Medium Risk

Apple Safari Command Execution and Cross Site Scripting Vulnerabilities

Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to bypass security restrictions, cause a denial of service, disclose sensitive information, or execute arbitrary code.1. Due to an error in the validation of certificates, which could...
Last Update Date: 28 Jan 2011 Release Date: 19 Mar 2008 7777 Views

RISK: Medium Risk

Medium Risk

CA BrightStor ARCserve Backup List Control Code Execution Vulnerability

A vulnerability has been identified in CA BrightStor ARCserve Backup, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "ListCtrl.ocx" ActiveX...
Last Update Date: 28 Jan 2011 Release Date: 18 Mar 2008 7919 Views

RISK: Medium Risk

Medium Risk

F-Secure Products Archive Handling Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various F-Secure products, which could be exploited by attackers or malware to cause a denial of service or take complete control of an affected system. These issues are caused by memory corruption errors when processing malformed archives, which could...
Last Update Date: 28 Jan 2011 Release Date: 18 Mar 2008 7729 Views

RISK: Medium Risk

Medium Risk

Cisco User-Changeable Password Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Cisco User-Changeable Password (UCP), which could be exploited by remote attackers to execute arbitrary scripting code, cause a denial of service or take complete control of an affected system.1. Due to a buffer overflow errors in...
Last Update Date: 28 Jan 2011 Release Date: 14 Mar 2008 7851 Views

RISK: Medium Risk

Medium Risk

McAfee ePolicy Orchestrator "logDetail()" Format String Vulnerability

A vulnerability has been identified in McAfee ePolicy Orchestrator, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a format string error in the "logDetail()" [applib.dll] ...
Last Update Date: 28 Jan 2011 Release Date: 14 Mar 2008 7889 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Web Components Two Vulnerabilites( 12 March 2008 )

1. Office Web Components URL Parsing VulnerabilityA remote code execution vulnerability exists in the way Microsoft Office Web Components manages memory resources when parsing specially crafted URLs. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 7947 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook URI Vulnerability( 12 March 2008 )

A remote code execution exists in Outlook. The vulnerability could allow remote code execution if Outlook is passed a specially crafted mailto URI. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 7638 Views

RISK: Medium Risk

Medium Risk

RealPlayer ActiveX Control "Console" Memory Corruption Vulnerability

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a memory corruption error in the "rmoc3260.dll" ActiveX control when handling...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 7865 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilites( 12 March 2008 )

1. Excel Data Validation Record VulnerabilityA remote code execution vulnerability exists in the way Excel processes data validation records when loading Excel files into memory. An attacker could exploit the vulnerability by sending a malformed file which could be hosted on a specially crafted or compromised Web site...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 7635 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Multiple Memory Corruption Vulnerabilities( 12 March 2008 )

1. Microsoft Office Cell Parsing Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Microsoft Office handles specially crafted Excel files. An attacker could exploit the vulnerability by creating a malformed file which could be included as an e-mail attachment, or hosted on...
Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 7633 Views

RISK: Medium Risk

Medium Risk

Sun Java Multiple Code Execution and Security Bypass Vulnerabilities

Multiple vulnerabilities have been identified in Sun Java, which could be exploited by remote attackers to bypass security restrictions or take complete control of an affected system. These issues are caused by unspecified errors when handling certain data or applets, which could be exploited by malicious web...
Last Update Date: 28 Jan 2011 Release Date: 6 Mar 2008 7919 Views

RISK: Medium Risk

Medium Risk

ICQ Message Handling and Conversion Remote Format String Vulnerability

A vulnerability has been identified in ICQ, which could be exploited by remote attackers to cause a denial of service or potentially take complete control of an affected system. This issue is caused by a format string error when processing and converting received HTML messages, which could...
Last Update Date: 28 Jan 2011 Release Date: 29 Feb 2008 8093 Views

RISK: Medium Risk

Medium Risk

Trend Micro OfficeScan Multiple Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Trend Micro OfficeScan, which could be exploited by remote attackers to cause a denial of service or take complete contol of an affected system. These issues are caused by NULL pointer dereference and buffer overflow errors in the "cgiChkMasterPwd.exe...
Last Update Date: 28 Jan 2011 Release Date: 29 Feb 2008 7904 Views

RISK: Medium Risk

Medium Risk

Symantec Products Decomposer Buffer Overflow and DoS Vulnerabilities

Multiple vulnerabilities have been identified in various Symantec products, which could be exploited by attackers or malware to cause a denial of service or take complete contol of an affected system. These issues are caused by infinite loop and buffer overflow errors in the Decomposer engine when processing...
Last Update Date: 28 Jan 2011 Release Date: 28 Feb 2008 8083 Views

RISK: Medium Risk

Medium Risk

Netscape Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Netscape Navigator, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system. For additional information, see : Mozilla Firefox and SeaMonkey Multiple Vulnerabilities
Last Update Date: 28 Jan 2011 Release Date: 22 Feb 2008 8239 Views

RISK: Medium Risk

Medium Risk

IBM Lotus Notes Java Plugin Sandbox Security Bypass Vulnerability

A vulnerability has been identified in IBM Lotus Notes, which could be exploited by remote attackers to bypass security restrictions and execute arbitrary code. This issue is caused by an error in the Java Plug-in when processing specially crafted JavaScript code, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 21 Feb 2008 7993 Views

RISK: Medium Risk

Medium Risk

Apache mod_jk2 Host Header Multiple Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in mod_jk2 for Apache, which could be exploited by remote attackers to cause a denial of service or compromise an affected web server. These issues are caused by buffer overflow errors when processing requests containing a malformed or overly long "Host" ...
Last Update Date: 28 Jan 2011 Release Date: 18 Feb 2008 7875 Views

RISK: Medium Risk

Medium Risk

MySQL Multiple Vulnerabilities

Multiple vulnerabilities have been identified in MySQL, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise an affected system.1. Missing permission checks when handling BINLOG statements, which could be...
Last Update Date: 28 Jan 2011 Release Date: 15 Feb 2008 8050 Views

RISK: Medium Risk

Medium Risk

Cisco Unified IP Phone Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Cisco Unified IP Phones, which could be exploited by attackers to cause a denial of service or take complete control of an affected device.1. A buffer overflow error when parsing DNS responses, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 15 Feb 2008 8304 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 13 February 2008 )

1. HTML Rendering Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way Internet Explorer interprets HTML with certain layout combinations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7814 Views

RISK: Medium Risk

Medium Risk

Microsoft Works File Converter Multiple Vulnerabilities( 13 February 2008 )

1. Microsoft Works File Converter Input Validation VulnerabilityA remote code execution vulnerability exists in Microsoft Works File Converter due to the way that it improperly validates section length headers with the .wps format. An attacker who successfully exploited this vulnerability could take complete control of an affected...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7699 Views

RISK: Medium Risk

Medium Risk

Novell Client "EnumPrinters" Function Remote Stack Overflow Vulnerability

A vulnerability has been identified in Novell Client for Windows, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a logical error in the "EnumPrinters" (nwspool.dll) ...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7942 Views

RISK: Medium Risk

Medium Risk

Microsoft WebDAV Mini-Redirector Heap Overflow Vulnerability( 13 February 2008 )

A remote code execution vulnerability exists in the way that the WebDAV Mini-Redirector handles responses. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7831 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Vista TCP/IP Vulnerability( 13 February 2008 )

A denial of service vulnerability exists in TCP/IP processing in Windows Vista. An attacker could exploit the vulnerability by creating a specially crafted DHCP server that returns a specially crafted packet to a host, corrupting TCP/IP structures and causing the affected system to stop...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7638 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Memory Corruption Vulnerability( 13 February 2008 )

A remote code execution vulnerability exists in the way that Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed value. An attacker who successfully exploited this vulnerability could take complete control...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7708 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Publisher Multiple Vulnerabilities( 13 February 2008 )

1. Publisher Invalid Memory Reference VulnerabilityA remote code execution vulnerability exists in the way Microsoft Office Publisher validates application data when loading Publisher files to memory. An attacker could exploit the vulnerability by constructing a specially crafted Publisher (.pub) file. When a user views the...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7775 Views