Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft OLE Heap Overrun Vulnerability( 13 February 2008 )

A remote code execution vulnerability exists in Object Linking and Embedding (OLE) Automation that could allow an attacker who successfully exploited this vulnerability to make changes to the system with the permissions of the logged-on user. If a user is logged on with administrative user...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7705 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) File Change Notification Vulnerability ( 13 February 2008 )

A local elevation of privilege vulnerability exists in the way that the Internet Information Service handles file change notifications in the FTPRoot, NNTPFile\Root, and WWWRoot folders. An attacker who successfully exploited this vulnerability could execute arbitrary code in the context of local system. An...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7783 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Execution Jump Vulnerability( 13 February 2008 )

The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office document with a malformed object inserted into the document. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7720 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to cause a denial of service, disclose sensitive information, bypass security restrictions or compromise an affected system.1. Due to a memory corruption error in Safari...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7829 Views

RISK: Medium Risk

Medium Risk

ClamAV Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Clam AntiVirus (ClamAV), which could be exploited by remote attackers or malware to cause a denial of service or take complete control of an affected system.1. Due to a heap corruption error in the "libclamav/mew....
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7984 Views

RISK: Medium Risk

Medium Risk

Microsoft Active Directory Vulnerability( 13 February 2008 )

A denial of service vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 and Windows Server 2003. The vulnerability also exists in implementations of Active Directory Application Mode (ADAM) when installed on Windows XP and Windows Server 2003. The vulnerability is due to improper...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7614 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Information Services (IIS) ASP Vulnerability( 13 February 2008 )

A remote code execution vulnerability exists in the way that Internet Information Services handles input to ASP Web pages. An attacker could exploit the vulnerability by passing malicious input to a Web site's ASP page. An attacker who successfully exploited this vulnerability could then perform any...
Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 7719 Views

RISK: Medium Risk

Medium Risk

Sun Java Runtime Environment Remote Code Execution Vulnerabilities

Two vulnerabilities have been identified in Sun Java Runtime Environment, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by unspecified errors when handling certain untrusted applications or applets, which could be exploited by a malicious web...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2008 7890 Views

RISK: Medium Risk

Medium Risk

Adobe Reader/Acrobat Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions or take complete control of an affected system. These issues are caused by input validation and buffer overflow errors when handling malformed data, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2008 8312 Views

RISK: Medium Risk

Medium Risk

Mozilla Firefox and SeaMonkey Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Firefox and SeaMonkey, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. A memory corruption errors in the browser and...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2008 7908 Views

RISK: Medium Risk

Medium Risk

Mozilla Thunderbird Multiple Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Mozilla Thunderbird, which could be exploited by attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or take complete control of an affected system.1. A memory corruption errors in the browser and JavaScript engines...
Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2008 7930 Views

RISK: Medium Risk

Medium Risk

Nero Media Player M3U File Processing Buffer Overflow Vulnerability

A vulnerability has been identified in Nero Media Player, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when processing a M3U file containing overly long data, ...
Last Update Date: 28 Jan 2011 Release Date: 6 Feb 2008 8494 Views

RISK: Medium Risk

Medium Risk

UltraVNC Multiple Buffer Overflow Vulnerabilities

A vulnerability has been identified in UltraVNC, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. A buffer overflow error in the [vncviewer/ClientConnection.cpp] function and multiple boundary errors within the [...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2008 8141 Views

RISK: Medium Risk

Medium Risk

Yahoo! Music Jukebox ActiveX Multiple Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Yahoo! Music Jukebox, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "datagrid.dll" and "...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2008 7752 Views

RISK: Medium Risk

Medium Risk

Facebook Photo Uploader Control Remote Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Facebook Photo Uploader, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "ImageUploader4.ocx" ActiveX control when...
Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2008 7931 Views

RISK: Medium Risk

Medium Risk

Cisco Wireless Control System Apache Tomcat JK Web Server Connector Buffer Overflow Vulnerability

A vulnerability has been identified in Cisco Wireless Control System (WCS), which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. This issue is due to a buffer overflow error in the mod_jk library when processing overly long URLs via...
Last Update Date: 28 Jan 2011 Release Date: 1 Feb 2008 8147 Views

RISK: Medium Risk

Medium Risk

Winamp Ultravox Streaming Metadata Parsing Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Winamp, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in "in_mp3.dll" when constructing stream titles while parsing...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2008 7995 Views

RISK: Medium Risk

Medium Risk

HP Oracle for OpenView Multiple Vulnerabilities

Multiple vulnerabilities have been identified in HP Oracle for OpenView (OfO), which could be exploited by remote or local attackers to cause a denial of service, execute arbitrary commands, read and overwrite arbitrary data, disclose sensitive information, conduct SQL injection and cross site scripting...
Last Update Date: 28 Jan 2011 Release Date: 21 Jan 2008 7933 Views

RISK: Medium Risk

Medium Risk

Cisco Products CTL Provider Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Cisco Unified CallManager and Unified Communications Manager, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a heap overflow error in the CTL (Certificate...
Last Update Date: 28 Jan 2011 Release Date: 18 Jan 2008 7978 Views

RISK: Medium Risk

Medium Risk

Oracle Products Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle products, which could be exploited by remote or local attackers to cause a denial of service, execute arbitrary commands, read and overwrite arbitrary data, disclose sensitive information, conduct SQL injection and cross site scripting attacks, or...
Last Update Date: 28 Jan 2011 Release Date: 17 Jan 2008 8613 Views

RISK: Medium Risk

Medium Risk

Apple iPhone / iPod touch Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple iPhone and iPod touch, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, or take complete control of an affected device.The first issue is caused by a memory corruption error in Safari when...
Last Update Date: 28 Jan 2011 Release Date: 17 Jan 2008 8245 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Remote Code Execution Vulnerability

A vulnerability has been identified in Microsoft Excel, which could be exploited by remote attackers to take complete control of an affected system or gain the same user rights as the local user by tricking a user into opening a specially crafted Excel file.
Last Update Date: 28 Jan 2011 Release Date: 16 Jan 2008 7834 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.1. Due to a memory corruption issue in QuickTime's handling of Sorenson 3 video files, ...
Last Update Date: 28 Jan 2011 Release Date: 16 Jan 2008 8020 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime RTSP Response "Reason-Phrase" Buffer Overflow

A vulnerability has been identified in Apple QuickTime, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when processing RTSP response messages and displaing the "Reason...
Last Update Date: 28 Jan 2011 Release Date: 14 Jan 2008 7994 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server and VirtualCenter Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server and VirtualCenter, which could be exploited by attackers to bypass security restrictions, disclose sensitive information or execute arbitrary commands and scripting code. These issues are caused by errors in Tomcat, JRE, OpenPegasus, Samba, util...
Last Update Date: 28 Jan 2011 Release Date: 9 Jan 2008 8005 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX Server, which could be exploited by attackers to bypass security restrictions or execute arbitrary code.These issues are caused by errors in OpenPegasus, Samba, util-linux, Perl, and OpenSSL.
Last Update Date: 28 Jan 2011 Release Date: 9 Jan 2008 8199 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LSASS Bypass Vulnerability( 09 January 2008 )

An elevation of privilege vulnerability exists in the Microsoft Windows Local Security Authority Subsystem Service (LSASS) due to its improper handling of local procedure call (LPC) requests. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited...
Last Update Date: 28 Jan 2011 Release Date: 9 Jan 2008 7947 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows TCP/IP Multiple Vulnerabilities( 09 January 2008 )

1. Windows Kernel TCP/IP/IGMPv3 and MLDv2 VulnerabilityA remote code execution vulnerability exists in the Windows kernel due to the way that the Windows kernel handles TCP/IP structures storing the state of IGMPv3 and MLDv2 queries. Supported editions of Microsoft Windows XP, ...
Last Update Date: 28 Jan 2011 Release Date: 9 Jan 2008 7987 Views

RISK: Medium Risk

Medium Risk

PHP Multiple Vulnerabilities

Some vulnerabilities have been reported in PHP, where some have unknown impact and others can be exploited by malicious users to bypass certain security restrictions.1) An integer overflow error exists in the "chunk_split()" function.2) Integer overflow errors exists in the "...
Last Update Date: 28 Jan 2011 Release Date: 4 Jan 2008 8457 Views

RISK: Medium Risk

Medium Risk

RealPlayer Data Processing Buffer Overflow Vulnerability

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by an unspecified buffer overflow error when processing malformed data, which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 4 Jan 2008 8281 Views

RISK: High Risk

High Risk

Novell GroupWise VCALENDAR Multiple Vulnerabilities

A vulnerability has been identified in Novell GroupWise, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "gwwww1.dll" module when processing the "TZID" ...
Last Update Date: 27 Jan 2011 16:05 Release Date: 27 Jan 2011 9690 Views