弱點週報 - 2011/6/24

  • 1280
  • 0
  • 2011-06-28

本週更新弱點
平台 數量
Windows 6
Microsoft Office 2
其他 Microsoft 產品 3
第三方 Windows 應用程式 3
跨平台 8
Web 應用程式 - Cross Site Scripting 2
Web 應用程式 1
硬體 2

本週更新弱點

平台 數量
Windows 6
Microsoft Office 2
其他 Microsoft 產品 3
第三方 Windows 應用程式 3
跨平台 8
Web 應用程式 - Cross Site Scripting 2
Web 應用程式 1
硬體 2

Windows

  1. Microsoft Windows "win32k.sys" OpenType Font Parsing Remote Code Execution Vulnerability
  2. Microsoft Windows Distributed File System Remote Code Execution Vulnerability
  3. Microsoft Windows Server Message Block Client Remote Code Execution Vulnerability
  4. Microsoft Windows "AFD.sys" Driver Local Privilege Escalation Vulnerability
  5. Microsoft Object Linking and Embedding (OLE) Automation WMF File Remote Code Execution Vulnerability
  6. Microsoft Windows SMB Server Remote Denial of Service

Microsoft Office

  1. Microsoft Word "wdGetApplicationObject()" Remote Code Execution Vulnerability
  2. Microsoft Excel Multiple Remote Code Execution Vulnerabilities

其他 Microsoft 產品

  1. Microsoft Forefront Threat Management Gateway (TMG) Firewall Client Memory Corruption Vulnerability
  2. Microsoft XML External Entities Resolution Information Disclosure Vulnerability
  3. Microsoft Internet Explorer Multiple Vulnerabilities

第三方 Windows 應用程式

  1. Gogago YouTube Video Converter ActiveX control "Download()" Method Buffer Overflow
  2. Trend Micro Control Manager "ApHost" Parameter Cross-Site Scripting Vulnerability
  3. Sunway ForceControl Multiple Heap-Based Buffer Overflow

跨平台

  1. DJabberd XML Parsing Denial of Service
  2. WebGL Unspecified Information Disclosure and Denial of Service Vulnerabilities
  3. Wing FTP Server "ssh public key" Authentication Security Bypass Vulnerability
  4. Mozilla Firefox Firebug Extension "chrome:" Cross-Domain Scripting Vulnerability
  5. SAP Netweaver Multiple Vulnerabilities
  6. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Vulnerabilities
  7. IBM Rational Team Concert Multiple Unspecified Cross-Site Scripting Vulnerabilities
  8. Google SketchUp ".SKP" File Invalid Edge Geometry Remote Code Execution

Web 應用程式 - Cross Site Scripting

  1. WeblyGo Unspecified Cross-Site Scripting
  2. CIDWeb Multiple Cross-Site Scripting Vulnerabilities

Web 應用程式

  1. WeBid "adsearch.php" HTML Injection Vulnerability

硬體

  1. Polycom SoundPoint IP "reg_1.html" Information Disclosure
  2. Multiple IP Cameras "productmaker" Account Unauthorized Access Vulnerability