Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2010-04-14 CVE-2010-0193 Denial of Service vulnerability in Adobe Acrobat and Reader
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196.
network
adobe apple microsoft
critical
9.3
2010-04-14 CVE-2010-0192 Denial of Service vulnerability in Adobe Acrobat and Reader
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196.
network
adobe apple microsoft
critical
9.3
2010-04-14 CVE-2010-0191 Code Injection vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."
network
adobe apple microsoft CWE-94
critical
9.3
2010-04-12 CVE-2010-1349 Numeric Errors vulnerability in Opera Browser 10.10/10.50
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.
network
low complexity
opera microsoft CWE-189
critical
10.0
2010-04-12 CVE-2009-1565 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in VMWare products
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted HexTile-encoded video chunks that trigger heap-based buffer overflows, related to "integer truncation errors."
network
vmware microsoft CWE-119
critical
9.3
2010-04-12 CVE-2009-1564 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in VMWare products
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.
network
vmware microsoft CWE-119
critical
9.3
2010-04-05 CVE-2010-1241 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat Reader
Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
network
adobe apple microsoft CWE-119
critical
9.3
2010-04-05 CVE-2010-1240 Permissions, Privileges, and Access Controls vulnerability in Adobe Acrobat Reader 9.3.1
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.
network
adobe microsoft CWE-264
critical
9.3
2010-04-05 CVE-2009-4764 Code Injection vulnerability in Adobe Acrobat Reader
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
network
adobe microsoft CWE-94
critical
9.3
2010-04-01 CVE-2010-1225 Permissions, Privileges, and Access Controls vulnerability in Microsoft Virtual PC, Virtual Server and Windows Virtual PC
The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application.
network
microsoft CWE-264
critical
9.3