The security update for October 2005 includes fixes for Microsoft Windows and Internet Explorer.
|
Bulletin Description
|
Impact
|
Bulletin Rating
|
|
Vulnerability in DirectShow Could Allow Remote Code Execution (904706)
Affected Software:
- Microsoft DirectX 7.0 on Microsoft Windows 2000 with Service Pack 4
- Microsoft DirectX 8.1 on Microsoft Windows XP Service Pack 1 and Microsoft DirectX 9.0c on Microsoft Windows XP with Service Pack 2
- Microsoft DirectX 9.0c on Microsoft Windows XP Professional x64 Edition
- Microsoft DirectX 8.1 on Microsoft Windows Server 2003 and Microsoft DirectX 9.0c on Microsoft Windows Server 2003 with Service Pack 1
- Microsoft DirectX 8.1 on Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft DirectX 9.0c on Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft DirectX 9.0c on Microsoft Windows Server 2003 x64 Edition
- Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME)
Affected Components:
- Microsoft DirectX 8.0, 8.0a, 8.1, 8.1a, 8.1b, and 8.2 when installed on Windows 2000 Service Pack 4
- Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c when installed on Windows 2000 Service Pack 4
- Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c when installed on Windows XP Service Pack 1
- Microsoft DirectX 9.0, 9.0a, 9.0b, and 9.0c when installed on Windows Server 2003
|
Remote Code Execution
|
Critical
|
|
Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution (902400)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
|
Remote Code Execution
|
Critical
|
|
Cumulative Security Update for Internet Explorer (896688)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
- Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME)
|
Remote Code Execution
|
Critical
|
|
Vulnerability in the Client Services for Netware Could Allow Remote Code Execution (899589)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
|
Remote Code Execution
|
Important
|
|
Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege (905749)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Service Pack 2
|
Remote Code Execution and Local Elevation of Privilege
|
Important
|
|
Vulnerability in the Microsoft Collaboration Data Objects Could Allow Remote Code Execution (907245)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
- Microsoft Exchange 2000 Server Service Pack 3 with the Exchange 2000 Post-Service Pack 3 Update Rollup of August 2004
|
Remote Code Execution
|
Important
|
|
Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
|
Remote Code Execution
|
Important
|
|
Vulnerability in the Windows FTP Client Could Allow File Transfer Location and Tampering (905495)
Affected Software:
- Microsoft Windows XP Service Pack 1
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based Systems
|
Tampering
|
Moderate
|
|
Vulnerability in Network Connection Manager Could Allow Denial of Service (905414)
Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1
|
Denial of Service
|
Moderate
|