Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2012-06-20 CVE-2012-2493 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.
network
cisco microsoft apple linux CWE-20
critical
9.3
2012-06-05 CVE-2012-1943 Local Privilege Escalation vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.
6.9
2012-06-05 CVE-2012-1942 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.
local
low complexity
mozilla microsoft CWE-264
7.2
2012-05-21 CVE-2012-2376 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in PHP
Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.
network
low complexity
php microsoft CWE-119
critical
10.0
2012-05-16 CVE-2012-0669 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
network
apple microsoft CWE-119
critical
9.3
2012-05-16 CVE-2012-0667 Numeric Errors vulnerability in Apple Quicktime
Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTVR movie file.
network
apple microsoft CWE-189
critical
9.3
2012-05-16 CVE-2012-0666 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTMovie object.
network
apple microsoft CWE-119
critical
9.3
2012-05-16 CVE-2012-0664 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text track in a movie file.
network
apple microsoft CWE-119
critical
9.3
2012-05-16 CVE-2012-0663 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.
network
apple microsoft CWE-119
critical
9.3
2012-05-16 CVE-2012-0265 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.
network
apple microsoft CWE-119
critical
9.3