Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2010-02-11 CVE-2010-0445 Unspecified vulnerability in HP Network Node Manager
Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.
network
low complexity
hp
critical
10.0
2010-02-11 CVE-2010-0145 Unspecified vulnerability in Cisco Ironport Encryption Appliance and Ironport Postx
Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka IronPort Bug 65923.
network
low complexity
cisco
critical
10.0
2010-02-11 CVE-2010-0144 Unspecified vulnerability in Cisco Ironport Encryption Appliance and Ironport Postx
Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65922.
network
low complexity
cisco
7.8
2010-02-11 CVE-2010-0143 Unspecified vulnerability in Cisco Ironport Encryption Appliance and Ironport Postx
Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65921.
network
low complexity
cisco
7.8
2010-02-11 CVE-2009-3735 Code Injection vulnerability in Panda Activescan 2.0
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
network
panda CWE-94
critical
9.3
2010-02-10 CVE-2010-0243 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Office 2004/Xp
Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
network
microsoft CWE-119
critical
9.3
2010-02-10 CVE-2010-0233 Unspecified vulnerability in Microsoft products
Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability." Per: http://cwe.mitre.org/data/slices/2000.html#d "CWE-415 Double Free" vulnerability
local
low complexity
microsoft
7.2
2010-02-10 CVE-2010-0035 Unspecified vulnerability in Microsoft products
The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability." Per: http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx "This vulnerability only affects domain controllers.
network
microsoft
6.3
2010-02-10 CVE-2010-0034 Buffer Errors vulnerability in Microsoft Powerpoint 2003
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
network
microsoft CWE-119
critical
9.3
2010-02-10 CVE-2010-0033 Buffer Errors vulnerability in Microsoft Powerpoint 2003
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
network
microsoft CWE-119
critical
9.3