Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft FAST Search Server 2010 for SharePoint Multiple Vulnerabilities

Remote code execution vulnerabilities exist in FAST Search Server 2010 for SharePoint with the Advanced Filter Pack enabled. An attacker who succesfully exploited these vulnerabilities could run arbitrary code in the context of a user account with a restricted token. By default, Advanced Filter Pack in FAST...
Last Update Date: 14 Feb 2013 17:30 Release Date: 14 Feb 2013 3834 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Multiple Vulnerabilities

Shift JIS Character Encoding Vulnerability An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a...
Last Update Date: 14 Feb 2013 17:25 Release Date: 14 Feb 2013 3608 Views

RISK: High Risk

High Risk

Microsoft Windows Media Decompression Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles media content. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a ....
Last Update Date: 14 Feb 2013 17:21 Release Date: 14 Feb 2013 3965 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Multiple Vulnerabilities

Two vulnerabilities exist in Microsoft Exchange Server through the WebReady Document Viewing feature. The more severe vulnerability, CVE-2013-0418, could allow remote code execution as the LocalService account if a user views a specially crafted file through Outlook Web Access in a browser. ...
Last Update Date: 14 Feb 2013 17:18 Release Date: 14 Feb 2013 3906 Views

RISK: High Risk

High Risk

Microsoft Windows OLE Automation Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Object Linking and Embedding (OLE) Automation allocates memory. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete...
Last Update Date: 14 Feb 2013 17:16 Release Date: 14 Feb 2013 3524 Views

RISK: High Risk

High Risk

Microsoft Windows NFS Server NULL Dereference Vulnerability

A denial of service vulnerability exists when the Windows NFS server fails to properly handle a file operation on a read-only share. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding and restart.
Last Update Date: 14 Feb 2013 17:08 Release Date: 14 Feb 2013 3739 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Multiple Vulnerabilities

Elevation of privilege vulnerabilities exist when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges and read arbitrary amounts of kernel memory.
Last Update Date: 14 Feb 2013 17:06 Release Date: 14 Feb 2013 3712 Views

RISK: High Risk

High Risk

Microsoft .NET Framework WinForms Allow Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that the .NET Framework elevates the permissions of a callback function when a particular Windows Forms object is created. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 14 Feb 2013 17:00 Release Date: 14 Feb 2013 3616 Views

RISK: High Risk

High Risk

PostgreSQL Array Index Error Vulerability

A vulnerability has been identified in PostgreSQL, which can be exploited by remote authenticated user to cause denial of service and disclose portions of system memory by sending a specially crafted SQL command to trigger an array index error.
Last Update Date: 14 Feb 2013 Release Date: 8 Feb 2013 4561 Views

RISK: Medium Risk

Medium Risk

Ruby on Rails Multiple Vulnerabilities

Two vulnerabilities have been discovered in Ruby on Rails, a Ruby framework for web application development.The blacklist provided by the attr_protected method could be bypassed with crafted requests, having an application-specific impact.In some applications, the +serialize+ helper...
Last Update Date: 14 Feb 2013 15:13 Release Date: 14 Feb 2013 3811 Views