Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Adobe Flash CS3 SWF File Handling Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash CS3, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by heap overflow errors when processing overly long control parameters within an SWF file, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 17 Oct 2008 4773 Views

RISK: Medium Risk

Medium Risk

Oracle and BEA Products Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4876 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Message Queuing Service Remote Code Execution Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the Message Queuing Service due to a specific flaw in the parsing of an RPC request to the Message Queuing service.An attacker could exploit the vulnerability by sending a specially crafted RPC request. A heap request can be controlled and...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4529 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Buffer Underflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles specially crafted file names. An attempt to exploit the vulnerability would require authentication because the vulnerable function is only reachable when the share type is a disk, and by...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4614 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Virtual Address Descriptor Elevation of Privilege Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the way that Memory Manager handles memory allocation and Virtual Address Descriptors (VADs). The vulnerability could allow elevation of privilege if an authenticated attacker runs a specially crafted program on an affected system. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4555 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Internet Printing Service Integer Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists on Windows systems running IIS with the internet printing service enabled. This issue could allow a remote, authenticated attacker to execute arbitrary code on an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4487 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 15 October 2008 )

1. Windows Kernel Window Creation VulnerabilityAn elevation of privilege vulnerability exists because the Windows kernel does not properly validate properties of a window passed during the new window creation process. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4439 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 15 October 2008 )

1. Window Location Property Cross-Domain VulnerabilityA remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4519 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability is due to incorrect memory allocation when receiving specially crafted LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4515 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Kernel Overwrite Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the Ancillary Function Driver (afd.sys) due to Windows improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 4576 Views