CyberNoggin.com Security Blogs

Sober.X from 11-23-05 - Virus Still Lurking

Sober.X - Secunia issued a HIGH RISK virus alert at 2005-11-23 11:46 GMT+1, the first anti-virus vendor reported the virus at 2005-11-19 18:34 GMT+1. Currently, this virus has been confirmed by 6 anti-virus vendors. [Secunia Virus Alerts]

Submitted by cybernoggin on Sun, 02/26/2006 - 7:15pm. categories [ | ] read more | cybernoggin's blog | login or register to post comments

MS06-005 Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)

MS06-005
Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)
http://www.microsoft.com/technet/security/bulletin/MS06-005.mspx

Submitted by cybernoggin on Thu, 02/16/2006 - 8:05am. categories [ | ] read more | cybernoggin's blog | 1 comment

MS06-004 Cumulative Security Update for Internet Explorer (910620)

Bulletin Summary - February 15, 2006

MS06-004
Cumulative Security Update for Internet Explorer (910620)
http://www.microsoft.com/technet/security/bulletin/MS06-004.mspx

Submitted by cybernoggin on Thu, 02/16/2006 - 7:37am. categories [ | ] read more | cybernoggin's blog | login or register to post comments

Microsoft Internet Explorer Drag and Drop Events Timing Vulnerability


Technical Description

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to an error in the Drag and Drop functionality that fails to properly validate certain Dynamic HTML (DHTML) events and methods provided by the DHTML Object Model, which could be exploited by malicious web sites to bypass security restrictions and place arbitrary executables on a vulnerable system by tricking a user into clicking and dragging an object from a specially crafted browser window to another window pointing to local resources.

Submitted by cybernoggin on Tue, 02/14/2006 - 7:41am. categories [ | ] read more | cybernoggin's blog | login or register to post comments
Syndicate content