TO SUBSCRIBE, UNSUBSCRIBE, OR CHANGE YOUR SUBSCRIPTION, go to:

http://www.dragonsoft.com/english/epaper/

 

DragonSoft Vulnerability and Threat Knowledge Base:

http://vdb.dragonsoft.com/

 

Contents:

* 37 Reported Vulnerabilities

* Sort by Risk

-------------------------------------------------

 

Date Reported: 2008/02/13

Name: MS08-008:Microsoft OLE Stream Automation SubstringData Remote Code Execution Vulnerability-2003

Risk: High

CVSS Base Score: 10

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3184

 

Date Reported: 2008/02/13

Name: MS08-008:Microsoft OLE Stream Automation SubstringData Remote Code Execution Vulnerability-XP

Risk: High

CVSS Base Score: 10

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3183

 

Date Reported: 2008/02/13

Name: MS08-008:Microsoft OLE Stream Automation SubstringData Remote Code Execution Vulnerability-2000

Risk: High

CVSS Base Score: 10

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3182

 

Date Reported: 2008/02/13

Name: MS08-006:MS IIS ASP Remote Code Execution Vulnerability-2003

Risk: High

CVSS Base Score: 10

Category: Web Servers

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3179

 

Date Reported: 2008/02/13

Name: MS08-006:MS IIS ASP Remote Code Execution Vulnerability-XP

Risk: High

CVSS Base Score: 10

Category: Web Servers

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3178

 

Date Reported: 2008/02/10

Name: Adobe Acrobat and Reader Multiple Arbitrary Code Execution Vulnerabilities

Risk: High

CVSS Base Score: 10

Category: Others

Affect OS: Windows NT4, 2000, XP, 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3171

 

Date Reported: 2007/08/06

Name: MS07-039:Windows Active Directory LDAP Request Validation Remote Code Execution Vulnerability-2003

Risk: High

CVSS Base Score: 10

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3031

 

Date Reported: 2007/08/06

Name: MS07-039:Windows Active Directory LDAP Request Validation Remote Code Execution Vulnerability-2000

Risk: High

CVSS Base Score: 10

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3030

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Argument Handling Remote Memory Corruption Vulnerability-2003

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3197

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Argument Handling Remote Memory Corruption Vulnerability-XP

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3196

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Argument Handling Remote Memory Corruption Vulnerability-2000

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3195

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Property Method Remote Memory Corruption Vulnerability-2003

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3194

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Property Method Remote Memory Corruption Vulnerability-XP

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3193

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE Property Method Remote Memory Corruption Vulnerability-2000

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3192

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE HTML Rendering Remote Memory Corruption Vulnerability-2003

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3191

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE HTML Rendering Remote Memory Corruption Vulnerability-XP

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3190

 

Date Reported: 2008/02/13

Name: MS08-010:MS IE HTML Rendering Remote Memory Corruption Vulnerability-2000

Risk: High

CVSS Base Score: 9.3

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3189

 

Date Reported: 2008/02/13

Name: MS08-010:MS Visual FoxPro FPOLE.OCX ActiveX Control Buffer Overflow Vulnerability-2003

Risk: High

CVSS Base Score: 7.5

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3188

 

Date Reported: 2008/02/13

Name: MS08-010:MS Visual FoxPro FPOLE.OCX ActiveX Control Buffer Overflow Vulnerability-XP

Risk: High

CVSS Base Score: 7.5

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3187

 

Date Reported: 2008/02/13

Name: MS08-010:MS Visual FoxPro FPOLE.OCX ActiveX Control Buffer Overflow Vulnerability-2000

Risk: High

CVSS Base Score: 7.5

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3186

 

Date Reported: 2008/02/13

Name: MS08-005:MS IIS File Change Notification Local Privilege Escalation Vulnerability-2003

Risk: High

CVSS Base Score: 7.2

Category: Web Servers

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3177

 

Date Reported: 2008/02/13

Name: MS08-005:MS IIS File Change Notification Local Privilege Escalation Vulnerability-XP

Risk: High

CVSS Base Score: 7.2

Category: Web Servers

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3176

 

Date Reported: 2008/02/13

Name: MS08-005:MS IIS File Change Notification Local Privilege Escalation Vulnerability-2000

Risk: High

CVSS Base Score: 7.2

Category: Web Servers

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3175

 

Date Reported: 2008/02/13

Name: MS08-009:MS Word Malformed String Remote Code Execution Vulnerability

Risk: High

CVSS Base Score: 8

Category: MS HotFix

Affect OS: NT

Description: http://vdb.dragonsoft.com/detail.php?id=3185

 

Date Reported: 2008/02/13

Name: MS08-007:Windows WebDAV Mini-Redirector Heap Overflow Vulnerability-2003

Risk: High

CVSS Base Score: 6.2

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3181

 

Date Reported: 2008/02/13

Name: MS08-007:Windows WebDAV Mini-Redirector Heap Overflow Vulnerability-XP

Risk: High

CVSS Base Score: 6.2

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3180

 

Date Reported: 2008/02/01

Name: Apple QuickTime Sorenson 3 Video Files Remote Buffer Overflow Vulnerability

Risk: High

CVSS Base Score: 5.8

Category: Others

Affect OS: Windows NT4, 2000, XP, 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3170

 

Date Reported: 2008/02/01

Name: Apple QuickTime Compressed PICT Remote Buffer Overflow Vulnerability

Risk: High

CVSS Base Score: 6.8

Category: Others

Affect OS: Windows NT4, 2000, XP, 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3169

 

Date Reported: 2007/08/15

Name: MS07-043:Microsoft OLE Automation SubstringData Remote Code Execution Vulnerability-2003

Risk: High

CVSS Base Score: 6.3

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3041

 

Date Reported: 2007/08/15

Name: MS07-043:Microsoft OLE Automation SubstringData Remote Code Execution Vulnerability-XP

Risk: High

CVSS Base Score: 6.3

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3040

 

Date Reported: 2007/08/15

Name: MS07-043:Microsoft OLE Automation SubstringData Remote Code Execution Vulnerability-2000

Risk: High

CVSS Base Score: 6.3

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3039

 

Date Reported: 2006/07/12

Name: MS06-034:MS IIS ASP Remote Code Execution Vulnerability-2003

Risk: High

CVSS Base Score: 4.2

Category: Web Servers

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=2630

 

Date Reported: 2006/07/12

Name: MS06-034:MS IIS ASP Remote Code Execution Vulnerability-XP

Risk: High

CVSS Base Score: 4.2

Category: Web Servers

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=2629

 

Date Reported: 2006/07/12

Name: MS06-034:MS IIS ASP Remote Code Execution Vulnerability-2000

Risk: High

CVSS Base Score: 4.2

Category: Web Servers

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=2628

 

Date Reported: 2008/02/13

Name: MS08-003:Windows Active Directory LDAP Request Validation Remote DoS Vulnerability-2003

Risk: Low

CVSS Base Score: 6.8

Category: MS HotFix

Affect OS: Windows 2003

Description: http://vdb.dragonsoft.com/detail.php?id=3174

 

Date Reported: 2008/02/13

Name: MS08-003:Windows Active Directory LDAP Request Validation Remote DoS Vulnerability-XP

Risk: Low

CVSS Base Score: 6.8

Category: MS HotFix

Affect OS: Windows XP

Description: http://vdb.dragonsoft.com/detail.php?id=3173

 

Date Reported: 2008/02/13

Name: MS08-003:Windows Active Directory LDAP Request Validation Remote DoS Vulnerability-2000

Risk: Low

CVSS Base Score: 6.8

Category: MS HotFix

Affect OS: Windows 2000

Description: http://vdb.dragonsoft.com/detail.php?id=3172

 

 

-------------------------------------------------

 

Risk:

  High: Allow immediate remote, or local access or immediate execution of code or commands,

          with unauthorized privileges, and bypassing security on firewalls.

  Medium: Potential of granting access or allowing code execution by means of complex or

          lengthy exploit procedures. Examples are cross-site scripting, man-in-the-middle

          attacks, SQL injection, denial of service, information disclosure.

  Low: deny service or provide non-system information that could be used to formulate

         structured attacks on a target, but not directly gain unauthorized access.

-------------------------------------------------

Copyright (c) DragonSoft Security Associates, Inc. All rights reserved

 

Permission is hereby granted for the electronic redistribution of this document.

It is not to be edited or altered in any way without the express written consent of the DragonSoft Security Associates. If you wish to reprint the whole or any part of this document in any other medium excluding electronic media, please email alert@dragonsoft.com for permission.

 

Disclaimer: The information in the database may change without notice.

Use of this information constitutes acceptance for use in an AS IS condition.

There are NO warranties with regard to this information, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

 

Please send suggestions, updates, and comments to: DragonSoft vdb_adm@dragonsoft.com of DragonSoft Security Associates, Inc.

 

About DragonSoft Security Associates:

DragonSoft Security Associates is a leading developer in Taiwan for network security software and an active contributor to network security education.

Founded in 2002, DragonSoft offers vulnerability management solutions, including vulnerability assessment, System Security Management and intrusion prevention.

 

DragonSoft Security Associates, Inc. http://www.dragonsoft.com/

Taipei: 4F-8, No 351, Sec.2, Chun-Sun Road, Chun-Ho City, Taiwan 235 R.O.C

 Tel. +886-2-8221-5408   Fax. +886-2-8221-5476

 Hsinchu: 6F, No. 30, Lane 607, Sec. 1, Guangfu Rd., Hsinchu, Taiwan 300 R.O.C

Tel. +886-3-5630989    Fax. +886-3-5797758

arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()