Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

VMwareProducts DHCP and JRE Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various VMware products, which could be exploited by remote attackers to bypass security restrictions, disclose sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in DHCP and JRE.
Last Update Date: 28 Jan 2011 Release Date: 20 Oct 2009 5436 Views

RISK: Medium Risk

Medium Risk

Foxit Reader Firefox Plugin Memory Corruption Vulnerability

A vulnerability has been identified in Foxit Reader, which could be exploited by attackers to compromise a vulnerable system.The vulnerability is caused due to an error in the Foxit Reader plugin for Firefox (npFoxitReaderPlugin.dll). This can be exploited to trigger a memory corruption...
Last Update Date: 28 Jan 2011 Release Date: 16 Oct 2009 5452 Views

RISK: Medium Risk

Medium Risk

Xpdf Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Xpdf, which could be exploited by attackers to compromise a vulnerable system.1. Multiple integer overflows in "SplashBitmap::SplashBitmap()" can be exploited to cause heap-based buffer overflows.2. An integer overflow error in "...
Last Update Date: 28 Jan 2011 Release Date: 16 Oct 2009 5499 Views

RISK: Medium Risk

Medium Risk

Sun Solaris and JES Network Security Services Buffer Overflow Vulnerability

A vulnerability has been identified in Sun Solaris and Sun Java Enterprise System, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an error in Network Security Services (NSS).
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2009 6244 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Local Security Authority Subsystem Service (LSASS) Integer Overflow Vulnerability( 14 October 2009 )

A denial of service vulnerability exists in the Microsoft Windows Local Security Authority Subsystem Service (LSASS) due to its improper handling of malformed packets during NTLM authentication. An attacker could create specially crafted anonymous NTLM authentication requests that would cause a crash in the LSASS service and...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5490 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player Heap Overflow Vulnerability( 14 October 2009 )

A remote code execution vulnerability exists in Windows Media Player 6.4. An attacker could exploit the vulnerability by constructing a specially crafted ASF file that could allow remote code execution when played using Windows Media Player 6.4. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5336 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMBv2 Multiple Vulnerabilities( 14 October 2009 )

1. SMBv2 Infinite Loop VulnerabilityA denial of service vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB version 2 (SMBv2) packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5370 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 14 October 2009 )

1. Windows Kernel Integer Underflow VulnerabilityAn elevation of privilege vulnerability exists in the Windows kernel due to the incorrect truncation of a 64-bit value to a 32-bit value. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5219 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Runtime Multiple Vulnerabilities( 14 October 2009 )

1. Windows Media Runtime Voice Sample Rate VulnerabilityA remote code execution vulnerability exists in Windows Media Player due to the improper processing of specially crafted Advanced Systems Format (ASF) files. An attacker could exploit the vulnerability by constructing a specially crafted audio file that could allow...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5398 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows GDI+ Multiple Vulnerabilities( 14 October 2009 )

1. GDI+ WMF Integer Overflow VulnerabilityA remote code execution vulnerability exists in the way that GDI+ allocates buffer size when handling WMF image files. The vulnerability could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web...
Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 5448 Views