Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player RTSP Use After Free Vulnerability ( 13 October 2010 )

A vulnerability exists in Microsoft Windows Media Player Network Sharing Service that could allow a remote user to send a specially crafted network packet to an instance of the application's network streaming service and cause remote code execution in the context of the current application.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4794 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows MFC Document Title Updating Buffer Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that window titles are managed in applications written using the Microsoft Foundation Class (MFC) Library. While the vulnerability is located in MFC and is present on affected operating systems, it can only be exploited if a remote...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4723 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Embedded OpenType Font Integer Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that Microsoft Windows Embedded OpenType (EOT) font technology parses certain tables in specially crafted embedded fonts. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4704 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Mode Drivers Multiple Vulnerabilities ( 13 October 2010 )

1. Win32k Reference Count VulnerabilityAn elevation of privilege vulnerability exists due to the way that the Windows kernel-mode drivers maintain the reference count for an object. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4707 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Multiple Vulnerabilities ( 13 October 2010 )

1. HTML Sanitization VulnerabilityAn information disclosure vulnerability exists in the way that HTML is filtered that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user.2. HTML Sanitization VulnerabilityAn information disclosure vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4726 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows COM Validation Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows Shell and WordPad validate COM object instantiation. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4682 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Common Control Library Heap Overflow Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the way that the Windows common control library renders specially crafted Web sites when using a third-party scalable vector graphics (SVG) viewer. This vulnerability could allow code execution if a user visited a specially crafted Web page. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4672 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Excel Multiple Vulnerabilities ( 13 October 2010 )

1. Excel Record Parsing Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, ...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4671 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Word Multiple Vulnerabilities ( 13 October 2010 )

1. Word Uninitialized Pointer VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Word handles an uninitialized pointer when parsing a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4839 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework x64 JIT Compiler Vulnerability ( 13 October 2010 )

A remote code execution vulnerability exists in the Microsoft .NET Framework that can allow a specially crafted Microsoft .NET application to access memory in an unsafe manner, leading to arbitrary unmanaged code execution. This vulnerability only affects the x64 and Itanium architectures.
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2010 4816 Views