Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Opera Multiple Vulnerabilities

Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, disclose potentially sensitive information, or potentially compromise a user's system.1. An unspecified error exists...
Last Update Date: 28 Jan 2011 Release Date: 21 Aug 2008 5562 Views

RISK: Medium Risk

Medium Risk

Microsoft Visual Studio Masked Edit Control "Mask" Code Execution Vulnerability

A vulnerability has been identified in Microsoft Visual Studio, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "Msmask32.ocx" ActiveX control...
Last Update Date: 28 Jan 2011 Release Date: 15 Aug 2008 5579 Views

RISK: Medium Risk

Medium Risk

VMware ESX Server Multiple Vulnerabilities

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by attackers or malicious users to bypass security restrictions, disclose sensitive information, cause a denial of service, or execute arbitrary code. These issues are caused by errors in OpenSSL, net-snmp...
Last Update Date: 28 Jan 2011 Release Date: 14 Aug 2008 5468 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Image Color Management System Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Color Management System (MSCMS) module of the Microsoft ICM component handles memory allocation. The vulnerability could allow remote code execution if a user opens a specially crafted image file. An attacker who successfully exploited this...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5323 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows IPsec Policy Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in the manner in which IPsec policies are imported to Windows Server 2008 domains from Windows Server 2003 domains. This vulnerability could cause systems to ignore IPsec policies and transmit network traffic in clear text. This, in turn, would potentially disclose...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5207 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Record Parsing Vulnerability( 13 August 2008 )

A remote code execution vulnerability exists in the way that Microsoft Word handles specially crafted Word files. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed record value. An attacker who successfully exploited this vulnerability could take...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5187 Views

RISK: Medium Risk

Medium Risk

Microsoft PowerPoint Multiple Vulnerabilities( 13 August 2008 )

1. Memory Allocation VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office PowerPoint Viewer 2003 handles specially crafted PowerPoint files. An attacker could exploit the vulnerability by creating a specially crafted PowerPoint file that could be included as an e-mail attachment, or...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5247 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Event System Vulnerability( 13 August 2008 )

1. Event System VulnerabilityA remote code execution vulnerability exists because the Microsoft Windows Event System does not correctly validate user subscriptions requests when created. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. ...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5230 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Filters Multiple Vulnerabilities( 13 August 2008 )

1. Microsoft Malformed EPS Filter VulnerabilityA remote code execution vulnerability exists in the way that a Microsoft Office filter handles a malformed graphics image. An attacker could exploit the vulnerability by constructing a specially crafted Encapsulated PostScript (EPS) file that could allow remote code execution if...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5277 Views

RISK: Medium Risk

Medium Risk

Microsoft Outlook Express and Windows Mail URL Parsing Cross-Domain Information Disclosure Vulnerability( 13 August 2008 )

An information disclosure vulnerability exists in Outlook Express and Windows Mail because the MHTML protocol handler incorrectly interprets MHTML URL redirections that could potentially bypass Internet Explorer domain restrictions when returning MHTML content. An attacker could exploit the vulnerability by constructing a specially crafted Web page. If the...
Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5254 Views