|
|
Unchecked Buffer in Microsoft Data Access Components
New
An unchecked buffer in Microsoft Data Access Components 2.5, 2.6 and 2.7 could allows an attacker to run the code of their choice with the same level of permissions as the MDAC application.
An unchecked buffer in Microsoft Data Access Components 2.5, 2.6 and 2.7 could allows an attacker to run the code of their choice with the same level of permissions as the MDAC application.
Unchecked Buffer in DirectX
New
A security vulnerability exists in all versions of DirectX prior to v8.1b that due to an unchecked buffer could allow an attacker to execute code on a user's system.
A security vulnerability exists in all versions of DirectX prior to v8.1b that due to an unchecked buffer could allow an attacker to execute code on a user's system.
Flaw In Windows Media Player
New
A security vulnerability exists in an ActiveX control shipped with Windows Media Player 9 that when exploited could allow a remote attacker to view and manipulate metadata contained in the media library on the user's computer.
A security vulnerability exists in an ActiveX control shipped with Windows Media Player 9 that when exploited could allow a remote attacker to view and manipulate metadata contained in the media library on the user's computer.
Flaw in Windows Media Player Skins
New
A flaw exists in the way Windows Media Player 7.1 and Windows Media Player for Windows XP handle the download of skin files. The flaw means that an attacker could force a file masquerading as a skin file into a known location on a user's machine. This could allow an attacker to place a malicious executable on the system.
A flaw exists in the way Windows Media Player 7.1 and Windows Media Player for Windows XP handle the download of skin files. The flaw means that an attacker could force a file masquerading as a skin file into a known location on a user's machine. This could allow an attacker to place a malicious executable on the system.
Cumulative Patch for Outlook Express
New
Microsoft has released a cumulative patch for Outlook Express 5.5 and 6.0 which resolves a new critical MHTML security flaw and previous security vulnerabilities.
Microsoft has released a cumulative patch for Outlook Express 5.5 and 6.0 which resolves a new critical MHTML security flaw and previous security vulnerabilities.
Flaw in Windows Script Engine
New
A security vulnerability exists in the Windows Script Engine (WSH) on most versions of Windows that could allow a malicious web page operator to execute the code of their choice on the local machine.
A security vulnerability exists in the Windows Script Engine (WSH) on most versions of Windows that could allow a malicious web page operator to execute the code of their choice on the local machine.
Unchecked Buffer in Outlook Express
New
A security vulnerability in Outlook Express S/MIME parsing could allow a remote attacker to compromise the system by running the code of their choice.
A security vulnerability in Outlook Express S/MIME parsing could allow a remote attacker to compromise the system by running the code of their choice.
Flaw Could Enable Web Page to Launch Visual FoxPro 6.0
New
A flaw in the installation routine for Microsoft Visual FoxPro 6.0 means that a web page could cause FoxPro to launch and load a remotely or locally hosted application.
A flaw in the installation routine for Microsoft Visual FoxPro 6.0 means that a web page could cause FoxPro to launch and load a remotely or locally hosted application.
Multiple Vulnerabilities in Yahoo! Messenger
New
Multiple security vulnerabilities exist in the Yahoo! Messenger IM client that may allow an attacker to execute arbitrary code with the privileges of the victim user.
Multiple security vulnerabilities exist in the Yahoo! Messenger IM client that may allow an attacker to execute arbitrary code with the privileges of the victim user.
AOL Instant Messenger Overflow
New
A security vulnerability exists in AOL Instant Messenger (AIM) which could allow a malicious user to remotely penetrate a victim's system without any indication as to who performed the attack.
A security vulnerability exists in AOL Instant Messenger (AIM) which could allow a malicious user to remotely penetrate a victim's system without any indication as to who performed the attack.
Unchecked Buffer in Windows Media Player
New
A security vulnerability exists in the Windows Media Player .ASF Processor which could allow a malicious user to exploit an unchecked buffer to run code of their choice on the target computer through a malformed media stream.
A security vulnerability exists in the Windows Media Player .ASF Processor which could allow a malicious user to exploit an unchecked buffer to run code of their choice on the target computer through a malformed media stream.
Windows Media Player Contains Unchecked Buffer
New
An unchecked buffer vulnerability exists in the media player .NSC Processor which could allow a malicious user to run code of their choice on a vulnerable machine.
An unchecked buffer vulnerability exists in the media player .NSC Processor which could allow a malicious user to run code of their choice on a vulnerable machine.
Windows Media Player .ASX Processor Contains Unchecked Buffer
New
A security vulnerability exists in the Media Players ASX codec processor which could allow a user to run the code of their choice on a machine by ustilizing a buffer overrun.
A security vulnerability exists in the Media Players ASX codec processor which could allow a user to run the code of their choice on a machine by ustilizing a buffer overrun.
Visual Studio VB T-SQL Object Contains Unchecked Buffer
A security vulnerability exists in Microsoft Visual Basic 6.0 which could allow a malicious user to exploit a buffer overrun to run code of the attacker's choice on the hosting machine.
A security vulnerability exists in Microsoft Visual Basic 6.0 which could allow a malicious user to exploit a buffer overrun to run code of the attacker's choice on the hosting machine.
Windows Media Player Skins File Download Vulnerability
New
A security vulnerability exists in Microsoft® Windows Media™ Player 7 which could potentially enable a malicious user to cause a program of his choice to run on another user’s computer.
A security vulnerability exists in Microsoft® Windows Media™ Player 7 which could potentially enable a malicious user to cause a program of his choice to run on another user’s computer.
ASX Buffer Overrun and WMS Script Execution Vulnerabilities
Two security vulnerabilities exist in Microsoft® Windows Media™ Player which could potentially enable a malicious user to cause a program of their choice to run on another user’s computer.
Two security vulnerabilities exist in Microsoft® Windows Media™ Player which could potentially enable a malicious user to cause a program of their choice to run on another user’s computer.
NetMeeting Desktop Sharing Vulnerability
A security vulnerability exists in NetMeeting which could allow a malicious user to temporarily prevent an affected machine from providing any NetMeeting services and possibly consume 100% CPU utilization during an attack.
A security vulnerability exists in NetMeeting which could allow a malicious user to temporarily prevent an affected machine from providing any NetMeeting services and possibly consume 100% CPU utilization during an attack.
OCX Attachment Vulnerability
A security vulnerability exists in a OCX control, associated with Windows Media Player, that could cause certain email applications to fail, requiring the user to restart the e-mail client to resume normal operation.
A security vulnerability exists in a OCX control, associated with Windows Media Player, that could cause certain email applications to fail, requiring the user to restart the e-mail client to resume normal operation.
Money Password Vulnerability
A security vulnerability exists in Microsoft® Money which could allow a malicious user to obtain the password of a Money data file.
A security vulnerability exists in Microsoft® Money which could allow a malicious user to obtain the password of a Money data file.
Clip Art Buffer Overrun Vulnerability
The buffer overrun could cause Clip Gallery 5.0 to stop responding (crash), or allow arbitrary code to run on your computer. A malicious user could embed this arbitrary code in a file that Clip Gallery 5.0 downloads to your computer. This code could be harmful, damaging information stored on the computer.
The buffer overrun could cause Clip Gallery 5.0 to stop responding (crash), or allow arbitrary code to run on your computer. A malicious user could embed this arbitrary code in a file that Clip Gallery 5.0 downloads to your computer. This code could be harmful, damaging information stored on the computer.
Malformed RTF Control Word Vulnerability
When you are using a program that calls the default viewer for a Rich Text Format (RTF) file that contains a specially malformed control word in the file header, the program may not work properly or may generate a general protection (GP) fault.
When you are using a program that calls the default viewer for a Rich Text Format (RTF) file that contains a specially malformed control word in the file header, the program may not work properly or may generate a general protection (GP) fault.
Malformed Help File Vulnerability
A vulnerability exists in the Microsoft® Windows NT® help utility which could allow arbitrary code to be run on a Windows NT machine.
A vulnerability exists in the Microsoft® Windows NT® help utility which could allow arbitrary code to be run on a Windows NT machine.
Taskpads Scripting Vulnerability
A vulnerability exists in the Taskpads feature which could allow a malicious web site operator to run executables on the computer of a visiting user.
A vulnerability exists in the Taskpads feature which could allow a malicious web site operator to run executables on the computer of a visiting user.
Clipboard Exposure Vulnerability in Forms 2.0 TextBox Control
A vulnerability exists in the Forms 2.0 ActiveX control which is distributed in any application that includes Visual Basic for Applications 5.0. A malicious hacker could use the Forms 2.0 Control to read or export text on a user's Clipboard when that user visits a web site set up by the malicious hacker or opens a HTML email created by the malicious hacker.
A vulnerability exists in the Forms 2.0 ActiveX control which is distributed in any application that includes Visual Basic for Applications 5.0. A malicious hacker could use the Forms 2.0 Control to read or export text on a user's Clipboard when that user visits a web site set up by the malicious hacker or opens a HTML email created by the malicious hacker.
Security Vulnerabilities in Microsoft PPTP
Customers using Microsoft's Point-to-Point Tunneling Protocol (PPTP) to secure communcations over a public network (i.e. the Internet) may be affected by several security issues in the encryption and authentication functions.
Customers using Microsoft's Point-to-Point Tunneling Protocol (PPTP) to secure communcations over a public network (i.e. the Internet) may be affected by several security issues in the encryption and authentication functions.

















