Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

OpenOffice WMF and EMF Handling Heap Overflow Vulnerabilities

Multiple vulnerabilities have been identified in OpenOffice, which could be exploited by remote attackers to compromise a vulnerable system.1. Due to a heap overflow error when processing malformed WMF files, which could be exploited by attackers to execute arbitrary code by tricking a user into...
Last Update Date: 28 Jan 2011 Release Date: 30 Oct 2008 5669 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Server Service Vulnerability ( 24October 2008 )

A remote code execution vulnerability exists in the Server service on Windows systems. The vulnerability is due to the service not properly handling specially crafted RPC requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 24 Oct 2008 5330 Views

RISK: Medium Risk

Medium Risk

F-Secure Products RPM File Handling Integer Overflow Vulnerability

A vulnerability has been identified in various F-Secure products, which could be exploited by attackers or malware to compromise a vulnerable system. This issue is caused by an integer overflow error when processing malformed RPM files, which could be exploited to crash an affected application...
Last Update Date: 28 Jan 2011 Release Date: 22 Oct 2008 5450 Views

RISK: Medium Risk

Medium Risk

Adobe Flash CS3 SWF File Handling Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been identified in Adobe Flash CS3, which could be exploited by attackers to compromise a vulnerable system. These issues are caused by heap overflow errors when processing overly long control parameters within an SWF file, which could be exploited by attackers to execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 17 Oct 2008 5436 Views

RISK: Medium Risk

Medium Risk

Oracle and BEA Products Multiple Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5649 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Message Queuing Service Remote Code Execution Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the Message Queuing Service due to a specific flaw in the parsing of an RPC request to the Message Queuing service.An attacker could exploit the vulnerability by sending a specially crafted RPC request. A heap request can be controlled and...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5199 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows SMB Buffer Underflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles specially crafted file names. An attempt to exploit the vulnerability would require authentication because the vulnerable function is only reachable when the share type is a disk, and by...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5299 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Virtual Address Descriptor Elevation of Privilege Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the way that Memory Manager handles memory allocation and Virtual Address Descriptors (VADs). The vulnerability could allow elevation of privilege if an authenticated attacker runs a specially crafted program on an affected system. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5218 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Internet Printing Service Integer Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists on Windows systems running IIS with the internet printing service enabled. This issue could allow a remote, authenticated attacker to execute arbitrary code on an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5159 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Multiple Vulnerabilities( 15 October 2008 )

1. Windows Kernel Window Creation VulnerabilityAn elevation of privilege vulnerability exists because the Windows kernel does not properly validate properties of a window passed during the new window creation process. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5103 Views