| OSVDB ID | Disclosure Date | Title |
|
93291
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1306)
|
|
93289
Description:
Microsoft IE contains an unspecified flaw that may allow a context-dependent attacker to gain access to potentially sensitive information stored in JSON data files. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified JSON Data File Information Disclosure
|
|
93290
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-0811)
|
|
93292
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1307)
|
|
93293
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1308)
|
|
93294
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1309)
|
|
93295
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1310)
|
|
93296
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1311)
|
|
93297
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1312)
|
|
93298
Description:
Microsoft IE contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1313)
|
|
93306
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of a corrupt interface pointer in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Corrupt Interface Pointer Handling Arbitrary Code Execution
|
|
93307
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of a return value in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Return Value Handling Arbitrary Code Execution
|
|
93308
Description:
Microsoft Office Publisher contains an overflow condition that is triggered as user-supplied input is not properly validated during the handling of a specially crafted PUB file. This may allow a context-dependent attacker to cause a buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Handling Buffer Overflow
|
|
93309
Description:
Microsoft Office Publisher contains a flaw that is triggered during the validation of a return value in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Return Value Validation Arbitrary Code Execution
|
|
93310
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of an invalid range check in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Invalid Range Check Handling Arbitrary Code Execution
|
|
93311
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of an incorrect NULL value in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Incorrect NULL Value Handling Arbitrary Code Execution
|
|
93312
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of a signed integer in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Signed Integer Handling Arbitrary Code Execution
|
|
93313
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of a pointer in a specially crafted PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Pointer Handling Arbitrary Code Execution
|
|
93314
Description:
Microsoft Office Publisher contains an underflow condition that is triggered as user-supplied input is not properly validated during the handling of a specially crafted PUB file. This may allow a context-dependent attacker to cause a buffer underflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Handling Buffer Underflow
|
|
93317
Description:
Microsoft Windows Essentials contains a flaw in Windows Writer that is triggered during the handling of a specially crafted URL. This may allow a context-dependent attacker to gain access to potentially sensitive information or overwrite arbitrary files.
|
2013-05-14
|
Microsoft Windows Essentials Windows Writer Crafted URL Handling Arbitrary File Overwrite
|
|
93320
Description:
Microsoft Windows contains a flaw in win32k.sys that leads to unauthorized privileges being gained. The issue is triggered during the handling of a memory object. This may allow a local attacker to gain elevated privileges.
|
2013-05-14
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation
|
|
93318
Description:
Microsoft Windows contains a flaw in the DirectX Graphics Kernel Subsystem (dxgkrnl.sys) that leads to unauthorized privileges being gained. The issue is triggered during the handling of a memory object. This may allow a local attacker to gain elevated privileges.
|
2013-05-14
|
Microsoft Windows DirectX Graphics Kernel Subsystem (dxgkrnl.sys) Memory Object Handling Local Privilege Escalation
|
|
93300
Description:
Microsoft Windows contains a flaw in the HTTP Protocol Stack (HTTP.sys) that may allow a remote denial of service. The issue is triggered during the handling of a specially crafted HTTP header, which may allow a remote attacker to cause an infinite loop and crash the process.
|
2013-05-14
|
Microsoft Windows HTTP Protocol Stack (HTTP.sys) Crafted HTTP Header Handling Infinite Loop Remote DoS
|
|
93301
Description:
Microsoft .NET Framework contains a spoofing weakness that is due to the program failing to properly validate XML file signatures. This may allow a remote attacker to change the contents of an XML file without invalidating the signature.
|
2013-05-14
|
Microsoft .NET Framework XML File Signature Validation Spoofing Weakness
|
|
93302
Description:
Microsoft .NET Framework contains a flaw that is due to program improperly creating authentication policy requirements during custom WCF endpoint authentication setup. This may allow a remote attacker to bypass authentication and gain access to certain endpoint functions, which will allow the attacker to more easily gain access to sensitive information or perform actions as an authenticated user.
|
2013-05-14
|
Microsoft .NET Framework WCF Endpoint Authentication Unspecified Policy Requirement Weakness Authentication Bypass
|
|
93303
Description:
Microsoft Lync contains an unspecified use-after-free error that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-05-14
|
Microsoft Lync Unspecified Use-after-free Arbitrary Code Execution
|
|
93304
Description:
Microsoft Office Publisher contains a flaw that is triggered during the handling of negative value allocation in a PUB file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Negative Value Allocation Handling Arbitrary Code Execution
|
|
93305
Description:
Microsoft Office Publisher contains an integer overflow condition that is triggered as user-supplied input is not properly validated during the handling of a specially craft PUB file. This may allow a context-dependent attacker to cause a buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2013-05-14
|
Microsoft Office Publisher PUB File Handling Integer Overflow
|
|
93315
Description:
Microsoft Office Word contains a flaw that is triggered during the handling of shape data within a specially crafted DOC file. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-05-14
|
Microsoft Office Word DOC File Shape Data Handling Arbitrary Code Execution
|
|
93316
Description:
Microsoft Visio contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data in a Visio file, a context-dependent attacker can gain access to arbitrary files.
|
2013-05-14
|
Microsoft Visio File Handling External Entity (XXE) Data Parsing Arbitrary File Access
|
|
93319
Description:
Microsoft Windows contains an overflow condition in win32k.sys. The issue is triggered as user-supplied input is not properly validated during the handling of a memory object. This may allow a local attacker to cause a buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-05-14
|
Microsoft Windows win32k.sys Memory Object Handling Local Buffer Overflow
|
|
92993
Description:
Microsoft Internet Explorer (IE) contains a use-after-free error. The issue is triggered when handling CGenericElement objects. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code.
|
2013-05-03
|
Microsoft IE CGenericElement Object Handling Use-after-free Arbitrary Code Execution
|
|
92913
Description:
Microsoft IE contains an unspecified use-after-free error. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-24
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1338)
|
|
92128
Description:
Microsoft Antimalware Client contains a flaw that leads to unauthorized privileges being gained. The issue is triggered during the handling of improper pathnames. This may allow a local attacker to gain elevated privileges.
|
2013-04-09
|
Microsoft Antimalware Client Improper Pathname Handling Local Privilege Escalation Weakness
|
|
92124
Description:
Microsoft Windows Kernel contains an unspecified flaw that leads to unauthorized privileges being gained. The issue is due to a race condition that occurs during the handling of memory objects. This may allow a local attacker to gain access to elevated privileges. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft Windows Kernel Unspecified Memory Object Handling Race Condition Local Privilege Escalation (2013-1284)
|
|
92125
Description:
Microsoft Windows Kernel contains an unspecified flaw that leads to unauthorized privileges being gained. The issue is due to a race condition that occurs during the handling of memory objects. This may allow a local attacker to gain access to elevated privileges. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft Windows Kernel Unspecified Memory Object Handling Race Condition Local Privilege Escalation (2013-1294)
|
|
92129
Description:
Microsoft Office contains a flaw that allows a reflected cross-site scripting (XSS) attack in the HTML sanitization component. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-09
|
Microsoft Office HTML Sanitization Component Unspecified XSS
|
|
92123
Description:
Microsoft SharePoint Server contains a flaw that may lead to unauthorized disclosure of sensitive information. The issue is due to the program failing to properly enforce access controls on unspecified SharePoint lists. This may allow a remote authenticated attacker to gain access to potentially sensitive information.
|
2013-04-09
|
Microsoft SharePoint Server SharePoint Lists Access Control Handling Unspecified Information Disclosure
|
|
92126
Description:
Microsoft Windows contains a flaw in Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services that may allow a remote denial of service. The issue is due to the LDAP service failing to properly handle a specially crafted query. This may allow an authenticated remote attacker to cause a consumption of memory resources, which will cause the service to stop responding.
|
2013-04-09
|
Microsoft Windows Multiple Active Directory Components LDAP Crafted Query Handling Memory Consumption Remote DoS
|
|
92127
Description:
Microsoft Windows contains an unspecified memory corruption flaw in the Client/Server Run-time Subsystem (CSRSS). The issue is triggered as user-supplied input is not properly sanitized when handling memory objects. This may allow a local attacker to corrupt memory and gain elevated privileges.
|
2013-04-09
|
Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Unspecified Local Memory Corruption
|