| OSVDB ID | Disclosure Date | Title |
|
92130
Description:
Microsoft Windows contains an unspecified flaw in win32k.sys that leads to unauthorized privileges being gained. The issue is due to a race condition that is triggered during the handling of memory objects. This may allow a local attacker to gain elevated privileges. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft Windows win32k.sys Unspecified Memory Object Handling Race Condition Local Privilege Escalation (2013-1283)
|
|
92131
Description:
Microsoft Windows contains a flaw in win32k.sys that may allow a denial of service. The issue is triggered during the handling of a specially crafted font file. This may allow a context-dependent attacker to crash the system.
|
2013-04-09
|
Microsoft Windows win32k.sys Crafted Font File Handling DoS
|
|
92132
Description:
Microsoft Windows contains an unspecified flaw in win32k.sys that leads to unauthorized privileges being gained. The issue is due to a race condition that is triggered during the handling of memory objects. This may allow a local attacker to gain elevated privileges. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft Windows win32k.sys Unspecified Memory Object Handling Race Condition Local Privilege Escalation (2013-1292)
|
|
92133
Description:
Microsoft Windows contains a flaw that leads to unauthorized privileges being gained. The issue is due to the NTFS kernel-mode driver failing to properly handle objects in memory. This may allow a physically present attacker to cause a NULL pointer dereference, which will allow them to gain elevated privileges.
|
2013-04-09
|
Microsoft Windows NTFS NULL Pointer Dereference Local Privilege Escalation
|
|
92120
Description:
Microsoft IE contains an unspecified use-after-free error. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1303)
|
|
92121
Description:
Microsoft IE contains an unspecified use-after-free error. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-09
|
Microsoft IE Unspecified Use-after-free Arbitrary Code Execution (2013-1304)
|
|
92122
Description:
Microsoft Windows Remote Desktop Client contains a use-after-free error in the mstscax.dll ActiveX component, when manipulating TransportSettings or AdvancedSettings. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code.
|
2013-04-09
|
Microsoft Windows Remote Desktop Client ActiveX (mstscax.dll) Use-after-free Arbitrary Code Execution
|
|
91155
Description:
Microsoft Windows contains a flaw that leads to unauthorized privileges being gained. The issue is triggered when an error occurs in the USB RNDIS driver during the handling of unspecified memory objects supplied by a USB device. This may allow a physically present attacker to gain elevated privileges.
|
2013-03-12
|
Microsoft Windows USB RNDIS Driver Memory Object Handling Unspecified Local Privilege Escalation (2013-1285)
|
|
91156
Description:
Microsoft Windows contains a flaw that leads to unauthorized privileges being gained. The issue is triggered when an error occurs in the USB RNDIS driver during the handling of unspecified memory objects supplied by a USB device. This may allow a physically present attacker to gain elevated privileges.
|
2013-03-12
|
Microsoft Windows USB RNDIS Driver Memory Object Handling Unspecified Local Privilege Escalation (2013-1286)
|
|
91157
Description:
Microsoft Windows contains a flaw that leads to unauthorized privileges being gained. The issue is triggered when an error occurs in the USB RNDIS driver during the handling of unspecified memory objects supplied by a USB device. This may allow a physically present attacker to gain elevated privileges.
|
2013-03-12
|
Microsoft Windows USB RNDIS Driver Memory Object Handling Unspecified Local Privilege Escalation (2013-1287)
|
|
91152
Description:
Microsoft SharePoint contains an unspecified overflow condition that is triggered as user-supplied input is not properly validated. This may allow a remote attacker to cause a buffer overflow, resulting in a denial of service. No further details have been released by the vendor.
|
2013-03-12
|
Microsoft SharePoint Unspecified Remote Buffer Overflow DoS
|
|
91138
Description:
Microsoft IE contains a use-after-free error related to OnResize and OnMove, in the CElement::EnsureRecalcNotify() function, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft IE OnResize / OnMove CElement::EnsureRecalcNotify() Function Use-after-free Arbitrary Code Execution
|
|
91139
Description:
Microsoft IE contains a use-after-free error related to the handling of elements related to saveHistory and the onload event handler, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code.
|
2013-03-12
|
Microsoft IE saveHistory Onload Event Handler Event Handling Use-after-free Arbitrary Code Execution
|
|
91140
Description:
Microsoft IE contains a use-after-free error related to the handling of elements in CMarkupBehaviorContext objects, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code.
|
2013-03-12
|
Microsoft IE CMarkupBehaviorContext Object Handling Use-after-free Arbitrary Code Execution
|
|
91141
Description:
Microsoft IE contains an unspecified use-after-free error related to CCaret, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft IE CCaret Unspecified Use-after-free Arbitrary Code Execution
|
|
91142
Description:
Microsoft IE contains an unspecified use-after-free error related to CElement, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft IE CElement Unspecified Use-after-free Arbitrary Code Execution
|
|
91143
Description:
Microsoft IE contains an unspecified use-after-free error related to GetMarkupPtr and the execCommand Print event, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor or researcher.
|
2013-03-12
|
Microsoft IE GetMarkupPtr execCommand Print Event Handling Use-after-free Arbitrary Code Execution
|
|
91144
Description:
Microsoft IE contains a use-after-free error related to onBeforeCopy and execCommand selectAll event handling, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code.
|
2013-03-12
|
Microsoft IE onBeforeCopy execCommand selectAll Event Handling Use-after-free Arbitrary Code Execution
|
|
91145
Description:
Microsoft IE contains an unspecified use-after-free error related to removeChild and the handling of CHtmlComponentProperty objects, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft IE removeChild CHtmlComponentProperty Object Handling Use-after-free Arbitrary Code Execution
|
|
91146
Description:
Microsoft IE contains an unspecified use-after-free error related to CTreeNode, which may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft IE CTreeNode Unspecified Use-after-free Arbitrary Code Execution
|
|
91147
Description:
Microsoft Silverlight contains an unspecified flaw that is triggered during the handling of a specially crafted Silverlight application, which will result in a "double dereference" error. This may allow a context-dependent attacker to execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft Silverlight Application Handling Unspecified Double Dereference Arbitrary Code Execution
|
|
91148
Description:
Microsoft Visio Viewer contains an an unspecified flaw related to "tree object type confusion" that is triggered during the handling of a specially crafted Visio file. This may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-03-12
|
Microsoft Visio Viewer Unspecified Tree Object Type Confusion Visio File Handling Arbitrary Code Execution
|
|
91149
Description:
Microsoft SharePoint contains an unspecified flaw in the Callback function that leads to unauthorized privileges being gained. The issue is triggered when handling a specially crafted URL and may allow a context-dependent attacker to gain elevated privileges after obtaining unauthorized access to potentially sensitive information.
|
2013-03-12
|
Microsoft SharePoint Callback Function Unspecified URL Handling Privilege Escalation
|
|
91153
Description:
Microsoft OneNote contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when allocating memory when validating buffer sizes during the handling of a specially crafted ONE file. This may allow a context-dependent attacker to gain access to potentially sensitive information.
|
2013-03-12
|
Microsoft OneNote Buffer Size Validation ONE File Handling Information Disclosure
|
|
91150
Description:
Microsoft SharePoint contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-03-12
|
Microsoft SharePoint Unspecified XSS
|
|
91151
Description:
Microsoft SharePoint contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow a remote attacker to escalate their privileges after obtaining sensitive information.
|
2013-03-12
|
Microsoft SharePoint Unspecified Traversal Privilege Escalation
|
|
91154
Description:
Microsoft Office for Mac contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when loading unspecified content tags in an HTML5 email message. This may allow a context-dependent attacker to learn that "the targeted email account is valid and that the specially crafted email has been read".
|
2013-03-12
|
Microsoft Office for Mac HTML5 Email Message Unspecified Content Tag Loading Information Disclosure
|
|
91197
Description:
Microsoft Internet Explroer contains an unspecified flaw that may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided by the researcher.
|
2013-03-06
|
Microsoft IE Unspecified Remote Code Execution (pwn2own)
|
|
90133
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-13
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1250)
|
|
90137
Description:
Microsoft Windows contains a TOCTOU (Time-Of-Check, Time-Of-Use) race condition in the 'SfnINOUTSTYLECHANGE' function in the Windows kernel-mode driver, win32k.sys, as it fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-13
|
Microsoft Windows win32k.sys SfnINOUTSTYLECHANGE Function Memory Object Handling Local Privilege Escalation
|
|
90132
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1249)
|
|
90134
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1251)
|
|
90135
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1252)
|
|
90136
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1253)
|
|
90138
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1255)
|
|
90139
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1256)
|
|
90140
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1257)
|
|
90141
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1258)
|
|
90142
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1259)
|
|
90143
Description:
Microsoft Windows contains a race condition that leads to unauthorized privileges being gained. The issue is triggered when the Windows kernel-mode driver, win32k.sys, fails to properly handle objects in memory. This may allow a local attacker to gain elevated privileges.
|
2013-02-12
|
Microsoft Windows win32k.sys Memory Object Handling Local Privilege Escalation (2013-1260)
|