|
Cumulative Patch for Internet Explorer New Microsoft has released a cumulative patch that includes the functionality of all previously released patches for Internet Explorer 5.01, 5.5 and 6.0, in addition, it eliminates two newly discovered vulnerabilities. Updated: October 3, 2003
Buffer Overrun In RPCSS Service New Three critical security vulnerabilities exist in the Remote Procedure Call (RPC) service that could allow an attacker to take any action on the system by sending a malformed RPC message to a vulnerable system. Updated: September 10, 2003
Unchecked buffer in Microsoft Access Snapshot Viewer New A security vulnerability exists in the Microsoft Access 97, 2000 and 2002 Snapshot Viewer which could allow an attacker to execute code of their choice by persuading a user to open an affected document Updated: September 4, 2003
Flaw in Visual Basic for Applications New A buffer overrun exists in the Microsoft Visual Basic for Applications SDK which is included with a large number of Microsoft products. If exploited successfully it could allow an attacker to execute code of their choice in the context of the logged on user. Updated: September 3, 2003
Buffer Overrun in WordPerfect Converter New A security flaw exists in the WordPerfect converter included with the Microsoft Office and Works suites that could allow an attacker to run the code of their choice by persuading a user to open a malicious WordPerfect document. Updated: September 3, 2003
Flaw in Microsoft Word Could Enable Macros New A flaw in Microsoft Word 97, 98, 2000, 2002 and Microsoft Works 2001, 2002, 2003 could allow documents to run macros automatically bypassing the normal security restrictions. Updated: September 3, 2003
Flaw in NetBIOS Could Lead to Information Disclosure New A security vulnerability exists in the NetBIOS Name Service on Windows NT, 2000 and XP which could possibly allow a remote user to view random segments of memory on a user's computer. Updated: September 3, 2003
Unchecked Buffer in Microsoft Data Access Components New An unchecked buffer in Microsoft Data Access Components 2.5, 2.6 and 2.7 could allows an attacker to run the code of their choice with the same level of permissions as the MDAC application. Updated: August 20, 2003
Cumulative Patch for Internet Explorer New Microsoft has released a cumulative patch that includes all previously released patches for Internet Explorer 5.01, 5.5 and 6.0. In addition, it eliminates two new vulnerabilities, the most serious of which could enable an attacker to run arbitrary code on a user's system. Updated: August 20, 2003
What You Should Know About the Windows Blaster Worm New A new worm known as W32.Blaster.Worm (also known as MBlaster, W32/Lovsan.worm, MSBlast, W32.blaster.worm, Win32.posa.worm, Win32.poza.worm) has been identified that is seeking to exploit the vulnerability that was addressed by a recent Microsoft Security Bulletin. Blaster is designed to launch a denial of service attack against Microsoft's Windows Update Web site. Updated: August 15, 2003
|