[VulnWatch] 21 issues in Windows/Outlook Express

From: Chris Wysopal (weld_at_vulnwatch.org)
Date: 04/13/04

  • Next message: by way of NSFOCUS Security Team: "[VulnWatch] NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding"
    Date: Tue, 13 Apr 2004 15:04:29 -0500 (EST)
    To: vulnwatch@vulnwatch.org
    
    

    Microsoft Security Bulletin MS04-011
    Security Update for Microsoft Windows (835732)
    http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

    LSASS Vulnerability - CAN-2003-0533
    LDAP Vulnerability . CAN-2003-0663
    PCT Vulnerability - CAN-2003-0719
    Winlogon Vulnerability - CAN-2003-0806
    Metafile Vulnerability - CAN-2003-0906
    Help and Support Center Vulnerability - CAN-2003-0907
    Utility Manager Vulnerability - CAN-2003-0908
    Windows Management Vulnerability - CAN-2003-0909
    Local Descriptor Table Vulnerability - CAN-2003-0910
    H.323 Vulnerability* - CAN-2004-0117
    Virtual DOS Machine Vulnerability - CAN-2004-0118
    Negotiate SSP Vulnerability - CAN-2004-0119
    SSL Vulnerability - CAN-2004-0120
    ASN.1 .Double Free. Vulnerability - CAN-2004-0123

    Microsoft Security Bulletin MS04-012
    Cumulative Update for Microsoft RPC/DCOM (828741)
    http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx

    RPC Runtime Library Vulnerability - CAN-2003-0813
    RPCSS Service Vulnerability - CAN-2004-0116
    COM Internet Services (CIS) . RPC over HTTP Vulnerability - CAN-2003-0807
    Object Identity Vulnerability - CAN-2004-0124

    Microsoft Security Bulletin MS04-013
    Cumulative Security Update for Outlook Express (837009)
    http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx

    Microsoft Security Bulletin MS04-014
    Vulnerability in the Microsoft Jet Database Engine Could Allow Code
    Execution (837001)
    http://www.microsoft.com/technet/security/bulletin/MS04-014.mspx


  • Next message: by way of NSFOCUS Security Team: "[VulnWatch] NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding"

    Relevant Pages

    • Re: Microsoft Security Bulletin MS04-018 - Cumulative Security Update for Outlook Express (823353)
      ... | This update resolves a public vulnerability. ... | vulnerability exists in Outlook Express because of a lack of robust ... | to this security update section of this bulletin. ... | .Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack ...
      (microsoft.public.win2000.general)
    • Re: Microsoft Security Bulletin MS04-018 - Cumulative Security Update for Outlook Express (823353)
      ... | This update resolves a public vulnerability. ... | vulnerability exists in Outlook Express because of a lack of robust ... | to this security update section of this bulletin. ... | .Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: I am SICK of w32.spybot.worm
      ... * The DCOM RPC Vulnerability (described in Microsoft Security Bulletin ... * The Microsoft Windows Local Security Authority Service Remote Buffer ... Overflow (described in Microsoft Security Bulletin MS04-011). ... * The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft ...
      (alt.comp.anti-virus)
    • RE: W32.GAOBOT.AFJ Virus in Win32.exe file
      ... backdoors that the Beagle and Mydoom worms install, and several Windows ... --Workstation Service Buffer Overrun Vulnerability (described in Microsoft ... protected against this vulnerability if Microsoft Security Bulletin ...
      (microsoft.public.security.virus)
    • << Security Bulletins released today >>>
      ... Microsoft Security Bulletin MS04-041 ... Vulnerability in WordPad Could Allow Code Execution ... Severity: Important ...
      (microsoft.public.backoffice.smallbiz)