Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Image Color Management System Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Color Management System (MSCMS) module of the Microsoft ICM component handles memory allocation. The vulnerability could allow remote code execution if a user opens a specially crafted image file. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4596 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IPsec Policy Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in the manner in which IPsec policies are imported to Windows Server 2008 domains from Windows Server 2003 domains. This vulnerability could cause systems to ignore IPsec policies and transmit network traffic in clear text. This, in turn, would potentially disclose...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4542 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Record Parsing Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed record value. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4493 Views

RISK: Medium Risk

Medium Risk

Microsoft PowerPoint Multiple Vulnerabilities( 13 August 2008 )

1. Memory Allocation VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office PowerPoint Viewer 2003 handles specially crafted PowerPoint files. An attacker could exploit the vulnerability by creating a specially crafted PowerPoint file that could be included as an e-mail attachment, or...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4581 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Event System Vulnerability( 13 August 2008 )

1. Event System VulnerabilityA remote code execution vulnerability exists because the Microsoft Windows Event System does not correctly validate user subscriptions requests when created. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4556 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Filters Multiple Vulnerabilities( 13 August 2008 )

1. Microsoft Malformed EPS Filter VulnerabilityA remote code execution vulnerability exists in the way that a Microsoft Office filter handles a malformed graphics image. An attacker could exploit the vulnerability by constructing a specially crafted Encapsulated PostScript (EPS) file that could allow remote code execution if...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4592 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook Express and Windows Mail URL Parsing Cross-Domain Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in Outlook Express and Windows Mail because the MHTML protocol handler incorrectly interprets MHTML URL redirections that could potentially bypass Internet Explorer domain restrictions when returning MHTML content. An attacker could exploit the vulnerability by constructing a specially crafted Web page. If the...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4603 Views

RISK: Medium Risk

Medium Risk

Microsoft Access Snapshot Viewer Arbitrary File Download Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the ActiveX control for the Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4732 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilities( 13 August 2008 )

1. Excel Indexing Validation VulnerabilityA remote code execution vulnerability exists in the way Excel processes index values when loading Excel files into memory. An attacker could exploit the vulnerability by opening a specially crafted file which could be hosted on a Web site, or included as an...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4648 Views

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 13 August 2008 )

1. HTML Objects Memory Corruption VulnerabilityA remote code execution vulnerability exists in Internet Explorer due to attempts to access uninitialized memory in certain situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4594 Views