Microsoft Security Bulletin MS04-016: Vulnerability in DirectPlay Could Allow Denial of Service (839643)
Microsoft Security Bulletin MS04-016: Vulnerability in DirectPlay Could Allow Denial of Service (839643)07/13/2004 12:00 PM This update resolves a newly-discovered, privately reported
vulnerability. A denial of service vulnerability exists in the
implementation of the IDirectPlay4 application programming interface
(API) of Microsoft DirectPlay because of a lack of robust packet
validation. The vulnerability is documented in the Vulnerability
Details section of this bulletin.
If a user is running a networked DirectPlay application, an attacker
who successfully exploited this vulnerability could cause the
DirectPlay application to fail. The user would have to restart the
application to resume functionality.
Microsoft recommends that customers should consider applying the
security update.
Microsoft Security Bulletin MS04-017: Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service (842689)
Microsoft Security Bulletin MS04-017: Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service (842689)07/13/2004 12:00 PM This update resolves a newly-discovered vulnerability in Crystal
Reports and Crystal Enterprise from Business Objects. Microsoft Visual
Studio .NET 2003 (all versions) and Outlook 2003 with Business Contact
Manager redistribute Crystal Reports and are therefore affected by the
vulnerability. Microsoft Business Solutions CRM 1.2 redistributes
Crystal Enterprise, which is affected in the same way. The
vulnerability is documented in the Vulnerability Details section of
this bulletin.
An attacker who successfully exploited the vulnerability could
retrieve and delete files through the Crystal Reports and Crystal
Enterprise Web viewers on an affected system. The number of files of
files that are impacted by this vulnerability would depend on the
security context of the affected component that is used by the Crystal
Web viewer.
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability
Another reason to switch. “Critical: Highly critical Impact:
System access Where: From remote Software: Microsoft Internet Explorer
5.01, Microsoft Internet Explorer 5.5, Microsoft Internet Explorer 6.
http-equiv has discovered a vulnerability in Microsoft Internet
Explorer, which can be exploited by malicious people to compromise a
user’s system….http-equiv has posted a PoC (Proof of
Concept), which plants a program in the startup directory when a user
drags a program masqueraded as an image. NOTE: Even though…
BugTraq: Microsoft Internet Explorer 6 Protocol Handler Vulnerability