Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system.1. Due to an uninitialized memory access in the third-party Indeo v5 codec (not shipped with QuickTime), which could be...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2008 5335 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Uniform Resource Locator Validation Error Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted URLs using the OneNote protocol handler (onenote://). The vulnerability could allow remote code execution if a user clicks a specially crafted OneNote URL. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 5317 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Player Sampling Rate Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in Windows Media Player 11. An attacker could exploit the vulnerability by constructing a specially crafted audio file that could allow remote code execution when streamed from a Windows Media server using Windows Media Player 11. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 5189 Views

RISK: Medium Risk

Medium Risk

Microsoft Products GDI+ Multiple Vulnerabilities( 10 September 2008 )

1. GDI+ VML Buffer Overrun VulnerabilityA remote code execution vulnerability exists in the way that GDI+ handles gradient sizes. The vulnerability could allow remote code execution if a user browses to a Web site that contains specially crafted content. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 5278 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Encoder Buffer Overrun Vulnerability( 10 September 2008 )

A remote code execution vulnerability exists in the WMEX.DLL ActiveX control installed by Windows Media Encoder 9 Series. The vulnerability could allow remote code execution if a user views a specially crafted Web page. If a user is logged on with administrative user rights, an...
Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 5523 Views

RISK: Medium Risk

Medium Risk

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system.1. Due to an uninitialized memory access in the third-party Indeo v5 codec (not shipped with QuickTime), which could be...
Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2008 5463 Views

RISK: Medium Risk

Medium Risk

VMware Products Multiple Vulnerabilities

VMware Server 1. Various vulnerabilities are caused due to unspecified errors within certain ActiveX controls. These can be exploited to e.g. execute arbitrary code by tricking a user into visiting a malicious website.2. An unspecified error when processing malformed requests exists within...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2008 5439 Views

RISK: Medium Risk

Medium Risk

Novell eDirectory Multiple Vulnerabilities

Multiple vulnerabilites have been identified in Novell eDirectory, which could be exploited by attackers to execute arbitrary scripting code, cause a denial of service or compromise a vulnerable system.1. An unspecified heap overflow error, which could allow attackers to execute arbitrary code.2...
Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2008 5475 Views

RISK: Medium Risk

Medium Risk

Novell Forum TCL Command Injection Vulnerability

A vulnerability has been reported in Novell Forum, which can be exploited by malicious people to to compromise a vulnerable system.The vulnerability is caused due to an unspecified error when handling certain requests, which can be exploited to inject and execute TCL commands by modifying the...
Last Update Date: 28 Jan 2011 Release Date: 1 Sep 2008 5451 Views

RISK: Medium Risk

Medium Risk

AWStats Totals Code Execution and Cross Ste Scripting Vulnerabilities

Multiple vulnerabilities have been identified in AWStats Totals, which could be exploited by remote attackers to execute arbitrary commands or scripting code.1. An input validation errors when processing the "month" and "year" parameters, which could be exploited by attackers to cause...
Last Update Date: 28 Jan 2011 Release Date: 28 Aug 2008 5635 Views