MS-ISAC Cyber Security Advisories
2009 | 2008 | 2007 | 2006 | 2005
2009 Cyber Advisories
January | February | March | April | May | June
June 2009
| Number |
Date Issued |
Subject |
| 2009-037 |
Thursday, June 25, 2009 |
Vulnerability in Adobe Shockwave Player Could Allow Remote Code Execution |
| 2009-036 |
Tuesday, June 16, 2009 |
Multiple Vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird could allow for Remote Code Execution |
| 2009-035 |
Wednesday, June 10, 2009 |
Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (MS09-027) |
| 2009-034 |
Tuesday, June 09, 2009 |
Vulnerabilities in Active Directory |
| 2009-033 |
Tuesday, June 09, 2009 |
Multiple Vulnerabilities in Internet Explorer |
| 2009-026 Update |
Tuesday, June 09, 2009 |
Multiple Authentication Bypass Vulnerabilities in Microsoft IIS Web Servers Could Allow for Privilege Escalation |
| 2009-009 Updated |
Tuesday, June 09, 2009 |
Vulnerability in Microsoft Excel |
| 2009-032 |
Wednesday, June 03, 2009 |
Multiple Vulnerabilities in Apple QuickTime Player Could Allow for Remote Code Execution |
May 2009
| Number |
Date Issued |
Subject |
| 2009-031 |
Friday, May 29, 2009 |
Vulnerability in Microsoft DirectX Could Allow Remote Code Execution |
| 2009-030 |
Thursday, May 28, 2009 |
Multiple Vulnerabilities in BlackBerry Attachment Service Could Allow Remote Code Execution |
| 2009-029 |
Friday, May 22, 2009 |
Multiple Vulnerabilities in Novell GroupWise WebAccess Could Lead to Unauthorized Account Access |
| 2009-028 |
Friday, May 22, 2009 |
Multiple Vulnerabilities in Novell GroupWise Internet Agent Could Lead to Remote Code Execution |
| 2009-027 |
Tuesday, May 19, 2009 |
Multiple Buffer Overflow Vulnerabilities reported in Oracle Outside In |
| 2009-026 |
Tuesday, May 19, 2009 |
Multiple Authentication Bypass Vulnerabilities in Microsoft IIS Web Servers Could Allow for Privilege Escalation |
| 2009-025 |
Thursday, May 14, 2009 |
Multiple Vulnerabilities in Sun Java Runtime Environment ActiveX Control Could Allow for Remote Code Execution |
| 2009-024 |
Wednesday, May 13, 2009 |
Vulnerabilities in Adobe Reader and Adobe Acrobat Could Allow For Remote Code Execution |
| 2009-016 Updated |
Tuesday, May 12, 2009 |
Vulnerability in Microsoft PowerPoint Could Allow for Remote Code Execution |
| 2009-023 Updated |
Friday, May 08, 2009 |
Multiple Vulnerabilities in Symantec Products Could Allow For Remote Code Execution |
April 2009
| Number |
Date Issued |
Subject |
| 2008-037 Updated |
Thursday, April 30, 2009 |
Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution |
| 2009-023 |
Wednesday, April 29, 2009 |
Multiple Vulnerabilities in Symantec Products Could Allow For Remote Code Execution |
| 2009-022 |
Wednesday, April 15, 2009 |
Multiple Vulnerabilities in Microsoft Windows Could Allow Privilege Escalation (MS09-012) |
| 2009-021 |
Tuesday, April 14, 2009 |
Multiple Vulnerabilities in Windows HTTP Services |
| 2009-020 |
Tuesday, April 14, 2009 |
Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution |
| 2009-019 |
Tuesday, April 14, 2009 |
Multiple Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
| 2009-009 Updated |
Tuesday, April 14, 2009 |
A Vulnerability in Microsoft Excel Could Allow Remote Code Execution |
| 2008-043 Updated |
Tuesday, April 14, 2009 |
Vulnerability in WordPad Text Converter Could Allow Remote Code Execution |
| 2009-018 |
Thursday, April 09, 2009 |
Multiple Vulnerabilities in VMware Products |
| 2009-018 |
Thursday, April 09, 2009 |
Multiple Vulnerabilities in Cisco PIX Firewalls and ASA Security Devices |
| 2009-016 |
Friday, April 03, 2009 |
Vulnerability in Microsoft PowerPoint Could Allow for Remote Code Execution |
March 2009
| Number |
Date Issued |
Subject |
| 2009-015 |
Friday, March 27, 2009 |
Vulnerability in Mozilla Firefox Could Allow for Remote Code Execution |
| 2009-014 |
Thursday, March 26, 2009 |
Multiple vulnerabilities in Java JDK, SDK, and JRE Could Allow Remote Code Execution |
| 2009-013 |
Thursday, March 26, 2009 |
Vulnerabilities in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2009-008 Updated |
Wednesday, March 25, 2009 |
Vulnerability in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2009-008 Updated |
Wednesday, March 18, 2009 |
Vulnerability in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2009-012 |
Wednesday, March 11, 2009 |
Multiple Vulnerabilities in DNS and WINS Server (MS09-008) |
| 2009-008 Updated |
Wednesday, March 11, 2009 |
Vulnerability in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2009-011 |
Tuesday, March 10, 2009 |
Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (MS09-006) |
February 2009
| Number |
Date Issued |
Subject |
| 2009-010 |
Wednesday, February 25, 2009 |
Multiple Vulnerabilities Discovered in Adobe Flash Player |
| 2009-009 |
Tuesday, February 24, 2009 |
A Vulnerability in Microsoft Excel Could Allow Remote Code Execution |
| 2009-008 |
Friday, February 20, 2009 |
Vulnerability in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2009-005 Updated |
Tuesday, February 17, 2009 |
Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
| 2009-007 |
Wednesday, February 11, 2009 |
Security Update of ActiveX Kill Bits |
| 2009-006 |
Tuesday, February 10, 2009 |
Vulnerabilities in Microsoft Exchange Server |
| 2009-005 |
Tuesday, February 10, 2009 |
Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
| 2008-045 Updated |
Tuesday, February 10, 2009 |
Microsoft SQL Server Remote Memory Corruption Vulnerability |
Back To Top
2008 Cyber Advisories
January | February | March | April | May | June | July | August | September | October | November | December
December 2008
| Number |
Date Issued |
Subject |
| 2008-046 Updated |
Tuesday, December 30, 2008 |
Microsoft Windows Media Player WAV/MID/MIDI/SND File Parsing Integer Overflow Vulnerability |
| 2008-046 |
Monday, December 29, 2008 |
Microsoft Windows Media Player WAV/MID/MIDI/SND File Parsing Integer Overflow Vulnerability |
| 2008-045 Updated |
Friday, December 26, 2008 |
Microsoft SQL Server Remote Memory Corruption Vulnerability |
| 2008-044 Updated |
Wednesday, December 17, 2008 |
Vulnerability in Microsoft Internet Explorer |
| 2008-044 Updated |
Friday, December 12, 2008 |
Vulnerability in Microsoft Internet Explorer |
| 2008-045 |
Wednesday, December 10, 2008 |
Microsoft SQL Server Remote Memory Corruption Vulnerability |
| 2008-044 |
Wednesday, December 10, 2008 |
Vulnerability in Microsoft Internet Explorer 7 |
| 2008-043 |
Wednesday, December 10, 2008 |
Vulnerability in WordPad Text Converter Could Allow Remote Code Execution |
| 2008-042 |
Wednesday, December 10, 2008 |
Multiple Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution |
| 2008-041 |
Tuesday, December 09, 2008 |
Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution |
| 2008-040 |
Tuesday, December 09, 2008 |
Vulnerabilities in Microsoft GDI Could Allow Remote Code Execution |
| 2008-039 |
Tuesday, December 09, 2008 |
Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
| 2008-038 |
Thursday, December 04, 2008 |
Multiple Vulnerabilities in Sun Java Web Start and Java Plug-in |
October 2008
| Number |
Date Issued |
Subject |
| 2008-034 Updated |
Friday, October 24, 2008 |
Vulnerability in Server Services Could Allow Remote Code Execution |
| 2008-034 |
Thursday, October 23, 2008 |
Vulnerability in Server Services Could Allow Remote Code Execution |
| 2008-033 |
Wednesday, October 15, 2008 |
Vulnerability in Microsoft Server Message Block (SMB) Protocol Could Allow Remote Code Execution |
| 2008-032 |
Wednesday, October 15, 2008 |
Vulnerability in Active Directory Could Allow Remote Code Execution |
| 2008-031 |
Tuesday, October 14, 2008 |
Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
April 2008
| Number |
Date Issued |
Subject |
| 2008-017 |
Wednesday, April 30, 2008 |
Novell GroupWise Buffer Overflow Vulnerability |
| 2008-016 Updated |
Thursday, April 10, 2008 |
Vulnerability in Microsoft Graphics Device Interface (GDI) Could Allow for Remote Code Execution |
| 2008-016 |
Wednesday, April 09, 2008 |
Vulnerability in Microsoft Graphics Device Interface (GDI) Could Allow for Remote Code Execution |
| 2008-015 |
Wednesday, April 09, 2008 |
Security Update of ActiveX Kill Bits |
| 2008-014 |
Wednesday, April 09, 2008 |
A Vulnerability in Adobe Flash Player Allows for Remote Code Execution |
| 2008-013 |
Tuesday, April 08, 2008 |
Cumulative Internet Explorer Update Addresses Critical Data Stream Handling Vulnerability |
| 2008-012 |
Tuesday, April 08, 2008 |
Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution |
March 2008
| Number |
Date Issued |
Subject |
| 2008-010 Updated |
Wednesday, March 19, 2008 |
Multiple Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution |
| 2008-011 |
Tuesday, March 11, 2008 |
Microsoft Office Web Components Remote Code Execution Vulnerability |
| 2008-010 |
Tuesday, March 11, 2008 |
Multiple Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution |
| 2008-009 |
Tuesday, March 11, 2008 |
Multiple Vulnerabilities in Microsoft Office Could Allow Remote Code Execution |
| 2008-008 |
Friday, March 07, 2008 |
Sun Java Runtime Environment Image Parsing Vulnerability |
February 2008
| Number |
Date Issued |
Subject |
| 2008-007 |
Wednesday, February 13, 2008 |
Multiple Vulnerabilities in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution |
| 2008-006 |
Wednesday, February 13, 2008 |
Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution |
| 2008-005 |
Tuesday, February 12, 2008 |
Multiple Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
| 2008-004 |
Tuesday, February 12, 2008 |
Vulnerability in Microsoft OLE Automation Could Allow Remote Code Execution |
| 2008-003 |
Tuesday, February 12, 2008 |
Novell Netware Client 4.91 Service Pack 1 through Service Pack 4 |
Back To Top
2007 Cyber Advisories
January | February | March | April | May | June | July | August | October | November | December
December 2007
| Number |
Date Issued |
Subject |
| 2007-028 |
Wednesday, December 19, 2007 |
Multiple Vulnerabilities in Adobe Flash Player Could Allow for Remote Code Execution |
| 2007-023 |
Friday, December 14, 2007 |
Apple QuickTime RTSP Response Header Remote Stack Based Buffer Overflow |
| 2007-027 Updated |
Tuesday, December 11, 2007 |
Vulnerabilities in Microsoft DirectX Could Allow Remote Code Execution |
| 2007-026 Updated |
Tuesday, December 11, 2007 |
Vulnerability in Windows Media File Format Could Allow for Remote Code Execution |
| 2007-025 |
Tuesday, December 11, 2007 |
Multiple Vulnerabilities in Internet Explorer Could Allow Remote Code Execution |
October 2007
| Number |
Date Issued |
Subject |
| 2007-022 |
Wednesday, October 24, 2007 |
IBM Lotus Notes Attachment Viewer Multiple Buffer Overflow Vulnerabilities |
| 2007-020 |
Tuesday, October 23, 2007 |
New Vulnerability in Windows URI Handler Could Allow for Remote Code Execution |
| 2007-021 |
Monday, October 22, 2007 |
Unpatched RealPlayer ActiveX Component Exploitation |
| 2007-021 |
Friday, October 19, 2007 |
Unpatched RealPlayer ActiveX Component Exploitation |
| 2007-020 |
Tuesday, October 16, 2007 |
New Vulnerability in Windows URI Handler Could Allow for Remote Code Execution |
| 2007-019 |
Tuesday, October 09, 2007 |
Multiple Remote Code Execution and Spoofing Vulnerabilities in Internet Explorer |
January 2007
| Number |
Date Issued |
Subject |
| 2007-004 |
Thursday, January 25, 2007 |
Multiple Vulnerabilities in Cisco IOS |
| 2007-003 |
Tuesday, January 23, 2007 |
Wide-Spread Trojan Horse Infection |
| 2007-001 Updated |
Thursday, January 11, 2007 |
Adobe Acrobat Reader Plugin is Prone to Cross-Site Scripting Attacks |
| 2007-002 Updated |
Tuesday, January 09, 2007 |
Vulnerability in Vector Markup Language Affecting Microsoft Window Platforms |
| 2006-002 Updated |
Tuesday, January 09, 2007 |
Vulnerability in Microsoft Outlook and Microsoft Exchange Could Allow Remote Control of System |
| 2007-001 |
Friday, January 05, 2007 |
Adobe Acrobat Reader Plugin is Prone to Cross-Site Scripting Attacks |
Back To Top
2006 Cyber Advisories
January | February | April | May | June | July | August | September | October | November | December
November 2006
| Number |
Date Issued |
Subject |
| 2006-014 Updated |
Friday, November 17, 2006 |
New Vulnerability in Microsoft Server Service Could Allow Remote Code Execution |
| 2006-018 |
Thursday, November 16, 2006 |
Vulnerabilities in Broadcom Wireless Driver and D-Link DWL-G132 Wireless Adapters |
| 2006-017 |
Tuesday, November 14, 2006 |
Vulnerabilities in ActiveX Controls Could Allow Remote Control of Systems |
| 2006-014 Updated |
Tuesday, November 14, 2006 |
New Vulnerability in Microsoft Server Service Could Allow Remote Code Execution |
| 2006-010 Updated |
Tuesday, November 14, 2006 |
Multiple Vulnerabilities in the Macromedia Flash Player from Adobe |
January 2006
| Number |
Date Issued |
Subject |
| 2006-004 |
Tuesday, January 24, 2006 |
Blackmal Email Worm destroys files on the third day of each month |
| 2006-003 |
Tuesday, January 10, 2006 |
Vulnerability in Windows Web Font Processing Could Allow Remote Control of System |
| 2006-002 |
Tuesday, January 10, 2006 |
Vulnerability in Microsoft Outlook and Microsoft Exchange Could Allow Remote Control of System |
| 2006-001 |
Monday, January 09, 2006 |
New Unpatched WMF Vulnerability in Microsoft Windows |
| 2005-022 Updated |
Thursday, January 05, 2006 |
Public Exploitation of Unpatched WMF Vulnerability in Microsoft Windows |
Back To Top
2005 Cyber Advisories
January | February | March | April | May | June | July | August | October | November | December
August 2005
| Number |
Date Issued |
Subject |
| 2005-016 |
Tuesday, August 16, 2005 |
Update on the Microsoft Windows Plug and Play Buffer Overflow Vulnerability |
| 2005-013 Updated |
Friday, August 12, 2005 |
New Vulnerability in Microsoft Plug and Play |
| 2005-014 Updated |
Wednesday, August 10, 2005 |
Cumulative Security Update for Internet Explorer |
| 2005-015 |
Tuesday, August 09, 2005 |
Vulnerability in Print Spooler Service Could Allow Remote Code Execution |
| 2005-014 |
Tuesday, August 09, 2005 |
Cumulative Security Update for Internet Explorer |
| 2005-013 |
Tuesday, August 09, 2005 |
New Vulnerability in Microsoft Plug and Play |
July 2005
| Number |
Date Issued |
Subject |
| 2005-012 |
Friday, July 29, 2005 |
Cisco IOS IPv6 Vulnerability |
| 2005-011 |
Friday, July 22, 2005 |
Two States Report Similar Virus Infections |
| 2005-010 |
Tuesday, July 12, 2005 |
New Vulnerability in Microsoft Color Management Module |
| 2005-009 Updated |
Tuesday, July 12, 2005 |
New vulnerability in a component of Microsoft Internet Explorer |
| 2005-009 |
Sunday, July 03, 2005 |
New vulnerability in a component of Microsoft Internet Explorer |
Back To Top