Two Remote Code Execution Vulnerabilities in Internet Explorer

2011-10-13 Thread Ivan Fratric
### Vulnerability 1: Internet Explorer Select Element Remote Code Execution ### Original advisory:

VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console

2011-10-13 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2011-0012 Synopsis: VMware ESXi and ESX updates to third party libraries and ESX

SEC Consult SA-20111012-0 :: Client-side remote file upload command execution in Microsoft Forefront UAG Remote Access Agent (CVE-2011-1969)

2011-10-13 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20111012-0 === title: Client-side remote file upload command execution product: Microsoft Forefront Unified Access Gateway Remote

Security-Assessment.com Advisory: Destination Search Admin Console Access Control Bypass

2011-10-13 Thread Drew Calcott
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/\/.-. \/\/:wq

Multiple G-WAN vulnerabilities

2011-10-13 Thread Fredrik Widlund
Title: Multiple G-WAN vulnerabilities Product: G-WAN (http://gwan.com/) Author: Fredrik Widlund E-mail: fredrik.widlund (at) gmail (dot) com Date: 2011-10-12

iDefense Security Advisory 10.12.11: Apple MobileSafari Attachment Viewing Cross Site Scripting Vulnerability

2011-10-13 Thread labs-no-reply
iDefense Security Advisory 10.12.11 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 12, 2011 I. BACKGROUND MobileSafari is Apple's mobile we browser for iOS devices. For more information about MobileSafari, please the visit following website:

iDefense Security Advisory 10.12.11: Apple Mobile OfficeImport Framework Word Document Parsing Memory Corruption Vulnerability

2011-10-13 Thread labs-no-reply
iDefense Security Advisory 10.12.11 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 12, 2011 I. BACKGROUND The OfficeImport framework is an API used by Apple's mobile devices, including the iPod Touch, iPhone, and iPad. The framework is used to parse and display Microsoft Office file