Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Multiple Vulnerabilities

CSRSS Local EOP AllocConsole Vulnerability An elevation of privilege vulnerability exists in Windows CSRSS due to the way that the CSRSS subsystem assigns memory for specific user transactions. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 13 Jul 2011 11:23 Release Date: 13 Jul 2011 5447 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Win32k Use After Free Vulnerability An elevation of privilege vulnerability exists due to the way that Windows kernel-mode drivers manage kernel-mode driver objects. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs...
Last Update Date: 13 Jul 2011 11:22 Release Date: 13 Jul 2011 5338 Views

RISK: High Risk

High Risk

Microsoft Windows Bluetooth Stack Vulnerability

A remote code execution vulnerability exists in the Windows Bluetooth 2.1 Stack due to the way an object in memory is accessed when it has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a series of specially crafted Bluetooth...
Last Update Date: 13 Jul 2011 11:21 Release Date: 13 Jul 2011 5470 Views

RISK: High Risk

High Risk

Sun Java JRE Insecure Executable Loading Vulnerability

A vulnerability has identified in Sun Java, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading an executable file in an insecure manner when an out of memory condition occurs. This can be...
Last Update Date: 12 Jul 2011 12:21 Release Date: 12 Jul 2011 5886 Views

RISK: High Risk

High Risk

Microsoft Visio Insecure Library Loading Vulnerability

A vulnerability has been identified in Microsoft Visio, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the application loading libraries (e.g. mfc71enu.dll and mfc71loc.dll) in an insecure manner. ...
Last Update Date: 11 Jul 2011 10:41 Release Date: 11 Jul 2011 5667 Views

RISK: Medium Risk

Medium Risk

ISC BIND Multiple Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an error when handling UPDATE requests and can be exploited to terminate the named process by sending specially crafted...
Last Update Date: 6 Jul 2011 11:22 Release Date: 6 Jul 2011 5813 Views

RISK: High Risk

High Risk

vsftpd Compromised Source Packages Backdoor Vulnerability

A vulnerability has been identified in vsftpd, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the distribution of backdoored vsftpd version 2.3.4 source code packages (vsftpd-2.3.4....
Last Update Date: 5 Jul 2011 10:58 Release Date: 5 Jul 2011 8759 Views

RISK: High Risk

High Risk

Apple Mac OS X Java Vulnerability

Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.   For more...
Last Update Date: 30 Jun 2011 10:14 Release Date: 30 Jun 2011 5822 Views

RISK: High Risk

High Risk

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to compromise a user's system. An error when handling a NPAPI string can be exploited to cause an out-of-bounds read. A use-after-free...
Last Update Date: 30 Jun 2011 10:10 Release Date: 30 Jun 2011 5824 Views

RISK: High Risk

High Risk

Winamp Multiple Vulnerabilities

Multiple vulnerabilities have identified in Winamp, which can be exploited by malicious people to potentially compromise a user's system. An error in vp6.w5s when parsing media files encoded with the On2 TrueMotion VP6 codec where the "version" field value is greater than...
Last Update Date: 28 Jun 2011 14:42 Release Date: 28 Jun 2011 5980 Views