Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Internet Explorer Multiple Vulnerabilities( 15 October 2008 )

1. Window Location Property Cross-Domain VulnerabilityA remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5189 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Active Directory Overflow Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability is due to incorrect memory allocation when receiving specially crafted LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5188 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Ancillary Function Driver Kernel Overwrite Vulnerability( 15 October 2008 )

An elevation of privilege vulnerability exists in the Ancillary Function Driver (afd.sys) due to Windows improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5233 Views

RISK: Medium Risk

Medium Risk

Microsoft Excel Multiple Vulnerabilities( 15 October 2008 )

1. Calendar Object Validation VulnerabilityA remote code execution vulnerability exists in the way Excel processes a VBA Performance Cache. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file in a VBA Performance Cache. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5235 Views

RISK: Medium Risk

Medium Risk

Microsoft Host Integration Server Command Execution Vulnerability( 15 October 2008 )

A remote code execution vulnerability exists in the SNA Remote Procedure Call (RPC) service for Host Integration Server. An attacker could exploit the vulnerability by constructing a specially crafted RPC request. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability...
Last Update Date: 28 Jan 2011 Release Date: 15 Oct 2008 5172 Views

RISK: Medium Risk

Medium Risk

SunJava System Web Proxy Server FTP Heap Overflow Vulnerability

A vulnerability has been identified in Sun Java System Web Proxy Server, which could be exploited by remote or local attackers to compromise a vulnerable system. This issue is caused by a heap overflow error in the FTP subsytem when processing malformed data, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 13 Oct 2008 5427 Views

RISK: Medium Risk

Medium Risk

MacOS X Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X,which could be exploited by remote or local attackers to disclose sensitive information,bypass security restrictions, cause a denial of service or compromise an affected system.These issues are caused by buffer overflow, range checking...
Last Update Date: 28 Jan 2011 Release Date: 10 Oct 2008 5477 Views

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system.1. Due to an error when processing page redirects to a specially crafted address (URL), which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 9 Oct 2008 5391 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server and VMware VirtualCenter Multiple Vulnerabilities

Multiple vulnerabilities have been identified in various VMWare products, which could be exploited by remote attackers to bypass security restrictions or compromise a vulnerable system, or by local attackers to disclose sensitive information or gain elevated privileges, cause a denial of service or take complete control of...
Last Update Date: 28 Jan 2011 Release Date: 8 Oct 2008 5510 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory Heap Overflow and Denial of Service Vulnerabilities

Multiple vulnerabilities have been identified in Novell eDirectory, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.1. Due to heap overflow errors when processing update replica verbs (Opcode 0x23 and 0x24), which could be exploited by...
Last Update Date: 28 Jan 2011 Release Date: 8 Oct 2008 5399 Views