Thinking OPEN

Archives for the ‘Security Notifications’ Category

Blender 2.49b and prior [High]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA….

CVE Identifier: CVE-2009-3850
Vulnerability Type(s):
Severity: High



E-courirer Cms [Medium]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors….

CVE Identifier: CVE-2009-3901
Vulnerability Type(s):
Severity: Medium



E-courirer Cms [Medium]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors…

CVE Identifier: CVE-2009-3905
Vulnerability Type(s):
Severity: Medium



Jre 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694….

CVE Identifier: CVE-2009-3864
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752….

CVE Identifier: CVE-2009-3865
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824….

CVE Identifier: CVE-2009-3866
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303….

CVE Identifier: CVE-2009-3867
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970….

CVE Identifier: CVE-2009-3868
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357….

CVE Identifier: CVE-2009-3869
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358….

CVE Identifier: CVE-2009-3871
Vulnerability Type(s):
Severity: High