Andrew Berges

Configuration Manager, Security, and other musings from a self-confessed IT geek.

Browse by Tags

All Tags » Vulnerability (RSS)
McAfee Agent Information Disclosure Vulnerability
A paper has been published by SySS GmbH illustrating that under certain circumstances this vulnerability can be exploited to escalate the privileges of...
Adobe PSIRT: Clipboard attack update
Here's a quick update to note that we will be changing the way Flash Player interacts with the clipboard to help prevent the potential clipboard attacks...
Posted: Sep 26 2008, 02:09 PM by aberges | with no comments
Filed under: ,
Adobe PSIRT: Flash Player "Clipboard Attack"
http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html We are aware of recent press reports about a potential “Clipboard attack” issue that involves...
CVE-2008-3648: Remote Code Execution Exploit with Windows XP nslookup.exe
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3648 Overview nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary...
BlackBerry Updates Attachment Service PDF Security Advisory
RIM has released version 4.1 Service Pack 6 (4.1.6) to address the vulnerability, giving an alternative to their prior suggested workaround of blocking...
Cisco Security Advisory: Vulnerability in Cisco WebEx Meeting Manager ActiveX Control
Summary A buffer overflow vulnerability exists in an ActiveX control used by the WebEx Meeting Manager. Exploitation of this vulnerability could allow...
Anti-Malware Blog: SAP Internet Graphics Service (IGS) Remote Buffer Overflow
SAP is the largest business application and Enterprise Resource Planning (ERP) solution software provider in terms of revenue. CYBSEC Security Systems...
Secunia: Microsoft Help Workshop Two Buffer Overflow Vulnerabilities
porkythepig has discovered two vulnerabilities in Microsoft Help Workshop, which can be exploited by malicious people to compromise a user's system. Microsoft...
F-Secure Antivirus Research Weblog: Further Information on the Pocket PC MMS Exploit
We have done further study on the MMS exploit discovered by Collin Mulliner. The exploit affects most Pocket PC phone edition and Windows Mobile devices...
Am I the only one that finds this a bit comical?
As reported on Donna's SecurityFlash weblog , Agnitum (maker of Outpost Firewall) is rather critical of the firewall included with Windows Vista. Donna...
Chris Mosby (myITforum): National Vulnerability Database (CVE-2007-0264) - Buffer overflow in Winzip32.exe in WinZip 9.0 SR-1
Vulnerability Summary CVE-2007-0264 Original release date: 1/16/2007 Last revised: 1/17/2007 Source: US-CERT/NIST Overview Buffer overflow in Winzip32...
Chris Mosby (myITforum): Sun Java GIF Image Processing Buffer Overflow Vulnerability
Fellow blogger Harry Waldron posted this info to in an e-mail list, so I hope he won’t mind me using it. Sun Java GIF Image Processing Buffer Overflow...
Donna's SecurityFlash: RealPlayer MID File Handling Remote Denial of Service Vulnerability
Vulnerable: Real Networks RealPlayer 10.5 RealNetwork RealPlayer is prone to a remote denial-of-service vulnerability because the application fails to...
Trend Micro: MS07-004 code in the WILD
It’s only been a few days since Microsoft released its first update for 2007 and already, the code for MS07-004 exploit has been introduced to the malicious...
Acer's Vulnerability Hotfix
There's an update for the Acer ActiveX component vulnerability we posted on last week. Details can be found via US-CERT . The patch is named "Acer Preload...
More Posts Next page »