|
66993
|
Blogs: 10
Description:
(Description Provided by CVE) : The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
Comments: 0, Blogs: 10, References: 14
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Microsoft .NET Framework / Silverlight CLR Virtual Delegate Handling Remote Code Execution
|
|
66859
|
Blogs: 8
Description:
(Description Provided by CVE) : Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
Comments: 0, Blogs: 8, References: 12
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Local / Remote
- Context Dependent
| | | | | | |
|
Adobe Reader / Acrobat CoolType.dll maxp Table maxComponentPoints Field Font Handling Overflow
|
|
66387
|
Blogs: 3
Description:
Windows contains a flaw that may allow an attacker to execute arbitrary code. The issue is triggered by a specially crafted LNK which contains an icon resource that points to a malicious DLL file.
Comments: 0, Blogs: 4, References: 22
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Local / Remote
- Context Dependent
| | | | - Exploit Private
- Exploit Public
- Exploit Commercial
| - Discovered in the Wild
- Vendor Verified
- Uncoordinated Disclosure
| |
|
Microsoft Windows Shell LNK File Parsing Arbitrary Command Execution
|
|
66987
|
Blogs: 3
Description:
(Description Provided by CVE) : The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
Comments: 0, Blogs: 3, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Cryptographic
- Input Manipulation
| | | | | |
|
Microsoft Windows SChannel Malformed Certificate Request Remote Code Execution
|
|
67002
|
Blogs: 3
Description:
(Description Provided by CVE) : Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2010-0245, and CVE-2010-0246.
Comments: 0, Blogs: 3, References: 10
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Remote / Network Access
- Context Dependent
| | | | | | |
|
Microsoft IE Object Handling Unspecified Memory Corruption (2010-2559)
|
|
67237
|
Blogs: 2
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Comments: 0, Blogs: 2, References: 22
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | - Loss of Integrity
- Loss of Availability
| | | | |
|
Linux Kernel Userspace Stack Growth Memory Corruption
|
|
66974
|
Blogs: 2
Description:
(Description Provided by CVE) : The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
Comments: 0, Blogs: 2, References: 9
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Microsoft Windows SMB Server SMB_COM_TRANSACTION2 Request Handling Remote Code Execution
|
|
67331
|
Blogs: 1
Description:
(Description Provided by CVE) : The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.
Comments: 0, Blogs: 1, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
VLC Media Player TagLib Plugin taglib.cpp ReadMetaFromId3v2 Function DoS
|
|
67736
|
Blogs: 1
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Comments: 0, Blogs: 1, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
RealPlayer Multiple Products QCP File Handling Overflow
|
|
65224
|
Blogs: 1
Description:
(Description Provided by CVE) : The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
Comments: 0, Blogs: 2, References: 12
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Microsoft Windows Kernel-Mode Driver Win32k.sys GetDCEx() Function Device Contexts (DC) Handling Local Privilege Escalation
|