Security Bulletins

[logo] Microsoft Security Bulletins   more  xml  hide  
last updated: Thu, 28 Aug 2008 04:47:45 GMT

 Tue, 12 Aug 2008 08:00:00 GMT MS08-051 – Critical: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)
Bulletin Severity Rating:Critical - This security update resolves three privately reported vulnerabilities in Microsoft Office PowerPoint and Microsoft Office PowerPoint Viewer that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
 Tue, 12 Aug 2008 08:00:00 GMT MS08-050 – Important: Vulnerability in Windows Messenger Could Allow Information Disclosure (955702)
Bulletin Severity Rating:Important - This security update resolves a publicly reported vulnerability in supported versions of Windows Messenger. As a result of this vulnerability, scripting of an ActiveX control could allow information disclosure in the context of the logged-on user. An attacker could change state, get contact information, and initiate audio and video chat sessions without the knowledge of the logged-on user. An attacker could also capture the user’s logon ID and remotely log on to the user’s Messenger client impersonating that user.
 Tue, 12 Aug 2008 08:00:00 GMT MS08-049 – Important: Vulnerabilities in Event System Could Allow Remote Code Execution (950974)
Bulletin Severity Rating:Important - This update resolves two privately reported vulnerabilities in Microsoft Windows Event System that could allow remote code execution. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.
 Tue, 12 Aug 2008 08:00:00 GMT MS08-048 - Important: Security Update for Outlook Express and Windows Mail (951066)
Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Outlook Express and Windows Mail. The vulnerability could allow information disclosure if a user visits a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
 Tue, 12 Aug 2008 08:00:00 GMT MS08-047 – Important: Vulnerability in IPsec Policy Processing Could Allow Information Disclosure (953733)
Bulletin Severity Rating:Important - This update resolves a privately reported vulnerability in the way certain Windows Internet Protocol Security (IPsec) rules are applied. This vulnerability could cause systems to ignore IPsec policies and transmit network traffic in clear text. This, in turn, would disclose information intended to be encrypted on the network. An attacker viewing the traffic on the network would be able to view and possibly modify the contents of the traffic. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly. It could be used to collect useful information to try to further compromise the affected system or network.

US-CERT Technical Alerts and Bulletins   more  xml  hide  
last updated: Thu, 28 Aug 2008 01:36:53 GMT

  SB08-238: Vulnerability Summary for the Week of August 18, 2008
Vulnerability Summary for the Week of August 18, 2008
  SB08-231: Vulnerability Summary for the Week of August 11, 2008
Vulnerability Summary for the Week of August 11, 2008
  TA08-225A: Microsoft Updates for Multiple Vulnerabilities
Microsoft Updates for Multiple Vulnerabilities
  SB08-224: Vulnerability Summary for the Week of August 4, 2008
Vulnerability Summary for the Week of August 4, 2008
  SB08-217: Vulnerability Summary for the Week of July 28, 2008
Vulnerability Summary for the Week of July 28, 2008

[logo] SecurityFocus Vulnerabilities   more  xml  hide  
last updated: Thu, 28 Aug 2008 04:47:46 GMT

 2008-08-28 Vuln: Opera Web Browser 9.51 Multiple Security Vulnerabilities
Opera Web Browser 9.51 Multiple Security Vulnerabilities
 2008-08-28 Vuln: Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness
Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness
 2008-08-28 Vuln: GE Fanuc Proficy Information Portal HTTP Basic Authentication Information Disclosure Vulnerability
GE Fanuc Proficy Information Portal HTTP Basic Authentication Information Disclosure Vulnerability
 2008-08-28 Vuln: Papoo 'suchanzahl' Parameter SQL Injection Vulnerability
Papoo 'suchanzahl' Parameter SQL Injection Vulnerability
  Bugtraq: [security bulletin] HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges
[security bulletin] HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges

[logo] Yahoo! News: Security News   more  xml  hide  
last updated: Thu, 28 Aug 2008 04:47:47 GMT

 Wed, 27 Aug 2008 22:22:57 GMT Computer virus goes into orbit (AFP)

The International Space Station in June 2008 as seen from the US space shuttle Discovery as it moved away from the station after completing nine days of joint operations. NASA confirmed on Wednesday that a computer virus sneaked aboard the International Space Station only to be tossed into quarantine on July 25 by security software.(AFP/HO NASA/File/null)AFP - NASA confirmed on Wednesday that a computer virus sneaked aboard the International Space Station only to be tossed into quarantine on July 25 by security software.


 Wed, 27 Aug 2008 21:16:51 GMT Researchers offer new way to avoid bogus Web sites (AP)
AP - Intercepting Internet traffic, and spying on the communication between two computers, is a gold mine for hackers. Now Carnegie Mellon University researchers hope software they've built will make it harder for criminals to hit that jackpot.
 Wed, 27 Aug 2008 20:51:43 GMT Computer Virus Hitches Ride on Space Station (NewsFactor)
NewsFactor - Perhaps you've seen this movie: A virus infects a human-piloted spacecraft, and within days the mission is compromised and Earth is lost to the alien attackers. There's now a report that the first part of that storyline has come true -- only it's a computer virus on the International Space Station.
 Wed, 27 Aug 2008 18:53:00 GMT Space -- the final frontier for computer viruses (CNET)
CNET - The first ever reported computer virus has infected at least two laptops on board the International Space Station more than 200 miles above earth.
 Wed, 27 Aug 2008 18:53:00 GMT Space: The final frontier for computer viruses (CNET)
CNET - The first ever reported computer virus has infected at least two laptops onboard the International Space Station more than 200 miles above Earth.

[logo] Cisco Security Notices   more  xml  hide  
last updated: Thu, 28 Aug 2008 01:36:55 GMT

 Thu, 09 Nov 2006 07:00:00 PST Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability
This Cisco Security Notice is being released in response to the Cisco VPN Concentrator Group Name Enumeration Vulnerability advisory published on June 20, 2005 by NTA Monitor at http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm.
 Fri, 21 Apr 2006 13:40:00 PST Crafted DNS Packet Can Cause Denial Of Service
 Thu, 26 Jan 2006 14:30:00 PST Cisco IPsec VPN Implementation Group Password Usage Vulnerability
 Mon, 07 Nov 2005 10:00:00 PST Response to BugTraq - Cisco Clean Access Agent (Perfigo) Bypass
This document is provided to simplify access to Cisco responses to possible product security vulnerability issues posted in public forums for Cisco customers. This does not imply that Cisco perceives each of these issues as an actual product security vulnerability. This notice is provided on an "as is" basis and does not imply any kind of guarantee or warranty. Your use of the information on the page or materials linked from this page are at your own risk. Cisco reserves the right to change or update this page without notice at any time.
 Thu, 08 Sep 2005 07:00:00 PST CSS SSL Authentication Bypass
The Cisco CSS 11500 Series Content Services Switches (CSS) running Secure Socket Layer (SSL) has a vulnerability that may allow a user to bypass SSL authentication and access protected content. Cisco has made free software available to address this vulnerability.

[logo] Cisco Security Advisories   more  xml  hide  
last updated: Thu, 28 Aug 2008 05:07:20 GMT

 Mon, 18 Aug 2008 08:30:00 PST Vulnerability in Cisco WebEx Meeting Manager ActiveX Control
An ActiveX control (atucfobj.dll) that is used by the Cisco WebEx Meeting Manager contains a buffer overflow vulnerability that may result in a denial of service or remote code execution. The WebEx Meeting Manager is a client-side program that is provided by the Cisco WebEx meeting service. The Cisco WebEx meeting service automatically downloads, installs, and configures Meeting Manager the first time a user begins or joins a meeting.
 Tue, 29 Jul 2008 08:00:00 PST Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
 Thu, 03 Jul 2008 05:30:00 PST Multiple Vulnerabilities in Cisco IOS While Processing SSL Packets
Cisco IOS devices may crash while processing malformed Secure Sockets Layer (SSL) packets. In order to trigger these vulnerabilities, a malicious client must send malformed packets during the SSL protocol exchange with the vulnerable device.
 Thu, 03 Jul 2008 05:30:00 PST Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
A device running Cisco IOS software that has Internet Protocol version 6 (IPv6) enabled may be subject to a denial of service (DoS) attack. For the device to be affected by this vulnerability the device also has to have certain Internet Protocol version 4 (IPv4) User Datagram Protocol (UDP) services enabled. To exploit this vulnerability an offending IPv6 packet must be targeted to the device. Packets that are routed throughout the router can not trigger this vulnerability. Successful exploitation will prevent the interface from receiving any additional traffic. The only exception is Resource Reservation Protocol (RSVP) service, which if exploited, will cause the device to crash. Only the interface on which the vulnerability was exploited will be affected.
 Thu, 03 Jul 2008 05:30:00 PST Cisco IOS Virtual Private Dial-up Network Denial of Service Vulnerability
Two vulnerabilities exist in the virtual private dial-up network (VPDN) solution when Point-to-Point Tunneling Protocol (PPTP) is used in certain Cisco IOS releases prior to 12.3. PPTP is only one of the supported tunneling protocols used to tunnel PPP frames within the VPDN solution.

powered by zFeeder

Reload this page to check for the most recent news updates.

Please read our legal disclaimer for the use of this information.

Stay Secure
Axiom understands how vital the security of your data is to your organization. Please don't hesitate to contact us if you would like a professional assessment of your network infrastructure.
Home » Axiom Advisor » Security Bulletins