SANS @RISK
(1) CRITICAL: Microsoft Internet Explorer 'iepeers.dll' Remote Code Execution Vulnerability
Category: Widely Deployed Software
Affected:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2 and Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2
- Windows Vista x64 Edition , Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition and Service Pack 2
- Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
- Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
- Internet Explorer 6 for Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 6 for Windows Server 2003 Service Pack 2, Windows Server 2003 with SP2 for Itanium-based Systems, and Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 for Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Server 2003 Service Pack 2, Windows Server 2003 with SP2 for Itanium-based Systems, and Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 in Windows Vista, Windows Vista Service Pack 1, Windows Vista Service Pack 2, Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
- Internet Explorer 7 in Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
- Internet Explorer 7 in Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
- Description:
- A vulnerability has been identified in ipeers.dll, a library used by
- Microsoft Internet Explorer. By enticing the user to visit a specially
- crafted page, an attacker can execute arbitrary code with the
- permissions of the currently logged-in user. The vulnerability exists
- because it is possible for the vulnerable software to use a pointer
- reference after it is freed. Microsoft has reported targeted attacks
- attempting to exploit this vulnerability. Full technical details for
- this vulnerability via a public proof-of-concept.
(10) MODERATE: VLC Media Player Bookmark Handling Buffer Overflow Vulnerability
Category: Widely Deployed Software
Affected:
- VideoLAN VLC media player 1.0.5
- VideoLAN VLC media player 1.0.3
- VideoLAN VLC media player 1.0.2
- VideoLAN VLC media player 1.0.1
- VideoLAN VLC media player 1.0
SANS 2009
(2) HIGH: Microsoft Office Excel Multiple Vulnerabilities (MS10-017)
Category: Widely Deployed Software
Affected:
- Microsoft Office XP Service Pack 3
- Microsoft Office 2003 Service Pack 3
- 2007 Microsoft Office System Service Pack 1
- 2007 Microsoft Office System Service Pack 2
- Microsoft Office 2004 for Mac
- Microsoft Office 2008 for Mac
- Open XML File Format Converter for Mac
- Microsoft Office Excel Viewer Service Pack 1 and Microsoft Office Excel Viewer Service Pack 2
- Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
- Microsoft Office SharePoint Server 2007 Service Pack 1 (32-bit editions)[2]
- Microsoft Office SharePoint Server 2007 Service Pack 2 (32-bit editions)[2]
- Microsoft Office SharePoint Server 2007 Service Pack 1 (64-bit editions)[2]
- Microsoft Office SharePoint Server 2007 Service Pack 2 (64-bit editions)[2]
(3) HIGH: Microsoft Windows Movie Maker Buffer Overflow Vulnerability (MS10-016)
Category: Widely Deployed Software
Affected:
- Windows XP Service Pack 2 and Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2
- Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
- Windows 7 for 32-bit Systems
- Windows 7 for x64-based Systems
- Microsoft Producer 2003
- Movie Maker 2.1
- Movie Maker 2.6
- Movie Maker 6.0
(4) HIGH: Autonomy KeyView Module OLE Document Processing Integer Overflow Vulnerability
Category: Widely Deployed Software
Affected:
- Symantec Mail Security for SMTP 5.0.1
- Symantec Mail Security for SMTP 5.0
- Symantec Mail Security for Microsoft Exchange 6.0.9
- Symantec Mail Security for Microsoft Exchange 6.0.8
- Symantec Mail Security for Microsoft Exchange 6.0.7
- Symantec Mail Security for Microsoft Exchange 6.0.6
- Symantec Mail Security for Microsoft Exchange 5.0.13
- Symantec Mail Security for Microsoft Exchange 5.0.12
- Symantec Mail Security for Microsoft Exchange 5.0.11
- Symantec Mail Security for Microsoft Exchange 5.0.10 .382
- Symantec Mail Security for Microsoft Exchange 5.0.10
- Symantec Mail Security for Domino 8.0.2
- Symantec Mail Security for Domino 8.0.1
- Symantec Mail Security for Domino 7.5.8
- Symantec Mail Security for Domino 7.5.7
- Symantec Mail Security for Domino 7.5.6
- Symantec Mail Security for Domino 7.5.3 25
- Symantec Mail Security for Domino 8.0
- Symantec Mail Security for Domino 7.5.5.32
- Symantec Mail Security for Domino 7.5.4.29
- Symantec Mail Security for Domino 7.5.3.25
- Symantec IM Manager 8.4
- Symantec IM Manager 8.3
- Symantec Data Loss Prevention Endpoint Agents 9.0.2
- Symantec Data Loss Prevention Endpoint Agents 8.1
- Symantec Data Loss Prevention Endpoint Agents 10.0
- Symantec Data Loss Prevention Detection Servers for Windows 9.0.2
- Symantec Data Loss Prevention Detection Servers for Windows 8.1.1
- Symantec Data Loss Prevention Detection Servers for Windows 10.0
- Symantec Data Loss Prevention Detection Servers for Linux 9.0.2
- Symantec Data Loss Prevention Detection Servers for Linux 8.1.1
- Symantec Data Loss Prevention Detection Servers for Linux 10.0
- Symantec Data Loss Prevention Detection Servers 7.2 37
- Symantec Data Loss Prevention Detection Servers 7.2
- Symantec Brightmail Gateway 8.0.2
- Symantec Brightmail Gateway 8.0.1
- Symantec Brightmail Gateway 8.0
- IBM Lotus Notes 8.5
(5) HIGH: Opera Web Browser "Content-Length" Header Buffer Overflow Vulnerability
Category: Widely Deployed Software
Affected:
- Opera versions 10.50 and prior
(6) HIGH: Authentium Command On Demand ActiveX Control Multiple Vulnerabilities
Category: Widely Deployed Software
Affected:
- Authentium CSS Web Installer 1.4.9508 .605
- Authentium Command On Demand Online Scan 0
(7) HIGH: Hewlett-Packard Performance Insight Remote Command Execution Vulnerability
Category: Widely Deployed Software
Affected:
- HP OpenView Performance Insight 5.1.2
- HP OpenView Performance Insight 5.1.1
- HP OpenView Performance Insight 5.4
- HP OpenView Performance Insight 5.2
- HP OpenView Performance Insight 5.1
- HP OpenView Performance Insight 5.0
- HP HP Performance Insight 5.4
- HP HP Performance Insight 5.3
(8) MODERATE: Apache HTTP Server Memory Corruption Vulnerability
Category: Widely Deployed Software
Affected:
- Apache Versions prior to 2.2.15
(9) MODERATE: Yahoo! Player Playlist Processing Buffer Overflow Vulnerability
Category: Widely Deployed Software
Affected:
- Yahoo! Player 1.5.01.409
- Yahoo! Player 1.0
10.11.14 SpamAssassin Milter Plugin "mlfi_envrcpt()" Remote Arbitrary Command Injection
CVEs: CVE: Not Available
Platform: Cross Platform
10.11.15 Apache Subrequest Handling Information Disclosure
CVEs: CVE: CVE-2010-0434
Platform: Cross Platform
10.11.16 Perforce Server User Workspace Directory Traversal
CVEs: CVE: Not Available
Platform: Cross Platform
10.11.17 Perforce Server Journal and Log File Information Disclosure
CVEs: CVE: Not Available2009.2 is affected.
Platform: Cross Platform
10.11.18 Perforce Server Unauthorized Password Change Security Bypass
CVEs: CVE: Not Available
Platform: Cross Platform
10.11.19 Perforce Socket Hijacking
CVEs: CVE: Not Available
Platform: Cross Platform
10.11.20 QuickZip ZIP File Remote Buffer Overflow
CVEs: CVE: Not Available
Platform: Cross Platform
10.11.21 Samba "CAP_DAC_OVERRIDE" File Permissions Security Bypass
CVEs: CVE: CVE-2010-0728
Platform: Cross Platform
10.11.22 HP Performance Insight Remote Command Execution
CVEs: CVE: CVE-2010-0447
Platform: Cross Platform
