Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2011-04-13 CVE-2011-0103 Buffer Errors vulnerability in Microsoft Excel, Office and Open XML File Format Converter
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
network
microsoft CWE-119
critical
9.3
2011-04-13 CVE-2011-0101 Buffer Errors vulnerability in Microsoft Excel 2002
Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, double-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
network
microsoft CWE-119
critical
9.3
2011-04-13 CVE-2011-0098 Numeric Errors vulnerability in Microsoft products
Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via an XLS file with a large record size, aka "Excel Heap Overflow Vulnerability."
network
microsoft CWE-189
critical
9.3
2011-04-13 CVE-2011-0097 Numeric Errors vulnerability in Microsoft products
Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which triggers a stack-based buffer overflow, aka "Excel Integer Overrun Vulnerability."
network
microsoft CWE-189
critical
9.3
2011-04-13 CVE-2011-0028 Code Injection vulnerability in Microsoft Windows Server 2003 and Windows XP
WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
network
microsoft CWE-94
critical
9.3
2011-04-10 CVE-2011-0994 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell File Reporter
Stack-based buffer overflow in NFRAgent.exe in Novell File Reporter (NFR) before 1.0.2 allows remote attackers to execute arbitrary code via unspecified XML data.
network
low complexity
novell CWE-119
critical
10.0
2011-04-08 CVE-2011-0465 Improper Input Validation vulnerability in multiple products
xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.
network
matthias-hopf x CWE-20
critical
9.3
2011-04-06 CVE-2011-1525 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks Realplayer
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file.
network
realnetworks CWE-119
critical
9.3
2011-04-05 CVE-2011-1568 USE of Externally-Controlled Format String vulnerability in 7T Igss
Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated using the RMS Reports Delete command, related to the logging of messages to GSST.LOG.
network
low complexity
7t CWE-134
critical
10.0
2011-04-05 CVE-2011-1567 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in 7T Igss
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report templates (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.
network
low complexity
7t CWE-119
critical
10.0