Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

CiscoWorks Common Services Remote Code Execution Vulnerability

A vulnerability has been identified in CiscoWorks Common Services, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing user-supplied data, which could allow a remote attacker to execute arbitrary code on the...
Last Update Date: 28 Jan 2011 Release Date: 30 May 2008 5637 Views

RISK: Medium Risk

Medium Risk

Apple Mac OS XMultiple Vulnerabilities

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to cause a denial of service, disclose sensitive information, bypass security restrictions or compromise an affected system. These issues are caused by implementation, data validation, ...
Last Update Date: 28 Jan 2011 Release Date: 30 May 2008 5429 Views

RISK: Medium Risk

Medium Risk

Samba "receive_smb_raw()" Remote Buffer Overflow Vulnerability

A vulnerability has been identified in Samba, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the "receive_smb_raw()" [lib/util_sock.c] function when processing...
Last Update Date: 28 Jan 2011 Release Date: 29 May 2008 5426 Views

RISK: Medium Risk

Medium Risk

Adobe Flash Player Unspecified Remote Code Execution Vulnerability

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an unspecified memory corruption error when processing a malformed SWF file, which could be exploited by attackers to...
Last Update Date: 28 Jan 2011 Release Date: 28 May 2008 5371 Views

RISK: Medium Risk

Medium Risk

FileZilla GnuTLS Multiple Vulnerabilities

Multiple vulnerabilities have been identified in FileZilla, which could be exploited by remote attackers to cause a denial of service or compromise an affected system.1. Due to a NULL pointer dereference error when processing TLS packets containing multiple "Client Hello" messages, which could...
Last Update Date: 28 Jan 2011 Release Date: 22 May 2008 5498 Views

RISK: Medium Risk

Medium Risk

CA Products Code Execution and File Manipulation Vulnerabilities

Multiple vulnerabilities have been identified in various CA products, which could be exploited by remote attackers to take complete control of an affected system.1. Due to insufficient path verification by the logging service (caloggerd), which could allow a remote attacker to append data to...
Last Update Date: 28 Jan 2011 Release Date: 21 May 2008 5401 Views

RISK: Medium Risk

Medium Risk

Debian/Ubuntu OpenSSL Random Number Generator Vulnerability

A vulnerabiliity exists in the random number generator used by the OpenSSL package included with the Debian GNU/Linux, Ubuntu, and other Debian-based operating systems. This vulnerability causes the generated numbers to be predictable.The result of this error is that certain encryption...
Last Update Date: 28 Jan 2011 Release Date: 19 May 2008 6114 Views

RISK: Medium Risk

Medium Risk

Microsoft Word Two Vulnerabilities( 14 May 2008 )

1. Object Parsing VulnerabilityA remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted Rich Text Format (.rtf) files. The vulnerability could allow remote code execution if a user opens a specially crafted .rtf file with malformed strings in Word or...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 5177 Views

RISK: Medium Risk

Medium Risk

Yahoo! Assistant "ynotifier" ActiveX Control Code Execution Vulnerability

A vulnerability has been identified in Yahoo! Assistant, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a memory corruption error when instantiating the "ynotifier.dll" ActiveX control, which could be exploited...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 5350 Views

RISK: Medium Risk

Medium Risk

Microsoft Publisher Object Handler Validation Vulnerability( 14 May 2008 )

A remote code execution vulnerability exists in the way Microsoft Publisher validates object header data. An attacker could exploit the vulnerability by sending a specially crafted Publisher file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site...
Last Update Date: 28 Jan 2011 Release Date: 14 May 2008 5130 Views