2009年4月1日水曜日

水曜日、友引

How to rename a Volume Manager Disk Group (VMDg) with Storage Foundation for Windows (SFW) 5.0 RP1a in a Microsoft Cluster (MSCS).
http://seer.entsupport.symantec.com/docs/321252.htm

Solution 253588 : Security Vulnerability in the Solaris NFS Server Security Modes (nfssec(5)) may Lead to Unauthorized Access to Shared Resources
http://sunsolve.sun.com/search/document.do?assetkey=1-66-253588-1

+ Solution 253468 : A Security Vulnerability in the Solaris dircmp(1) Shell Script may Allow Overwriting of Arbitrary Files
http://sunsolve.sun.com/search/document.do?assetkey=1-66-253468-1

Positive Technologies SA 2009-09: Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28825

Cisco-SA-03/31/2009: Cisco ASA5520 Web VPN Host Header XSS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28824

ZDI-09-015: Mozilla Firefox XUL _moveToEdgeShift() Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00271.html

Zabbix Multiple Frontend CSRF (Password reset & command execution)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00273.html

[ECHO_ADV_108$2009] JobHut <= 1.2 (pk) Remote Sql Injection Vulnerability http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00272.html

[USN-750-1] OpenSSL vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00274.html

[SECURITY] [DSA 1759-1] New strongswan packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00275.html

[SECURITY] [DSA 1760-1] New openswan packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00276.html

aspWebCalendar Free Edition bug
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00278.html

Cisco ASA5520 Web VPN Host Header XSS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00280.html

[Positive Technologies SA 2009-09] Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00281.html

webEdition 6.0.0.4 Local File Inclusion
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00282.html

[DSECRG-09-013] IBM WebSphere Application Server 7.0 Multiple XSS Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00283.html

[security bulletin] HPSBMA02416 SSRT090008 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00284.html

[DSECRG-09-016] SAP SAPDB Multiple XSS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00285.html

[DSECRG-09-030] PrecisionID Datamatrix ActiveX control - Arbitrary File overwriting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00286.html

CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-03/msg00287.html

53001 : JobHut library/process.php pk Parameter SQL Injection
http://osvdb.org/show/osvdb/53001

53002 : Amaya Script Tags defer Attribute Handling Overflow
http://osvdb.org/show/osvdb/53002

Vulnerability Note VU#985449 SAP AG SAPgui EAI WebViewer3D ActiveX control stack buffer overflow
http://www.kb.cert.org/vuls/id/985449

Openswan ISAKMP R_U_THERE/R_U_THERE_ACK Null Pointer Dereference Lets Remote Users Service
http://securitytracker.com/alerts/2009/Mar/1021949.html

strongSwan ISAKMP R_U_THERE/R_U_THERE_ACK Null Pointer Dereference Lets Remote Users Service
http://securitytracker.com/alerts/2009/Mar/1021950.html

MapServer Buffer Overflows and Other Bugs Let Remote Users Execute Arbitrary Code and Create Files on the Target System
http://securitytracker.com/alerts/2009/Mar/1021952.html

Positive Technologies SA 2009-09: Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28825

Cisco-SA-03/31/2009: Cisco ASA5520 Web VPN Host Header XSS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28824

Taifajobs 'jobdetails.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/33864

libsndfile CAF Processing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33963

Mozilla Firefox '_moveToEdgeShift' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34181

SystemTap Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34260

IBM WebSphere Application Server Administrative Console Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34001

Sun Java System Calendar Server 'command.shtml' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34153

Sun Java System Calendar Server Duplicate URI Request Denial of Service Vulnerability
http://www.securityfocus.com/bid/34150

Sun Java System Calendar Server 'login.wcap' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34152

Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34169

Apple Safari XML Parser Nested XML Tag Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34318

+ Sun Solaris 'dircmp(1)' Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/34316

Free Arcade Script 'play.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/33869

SAP MaxDB 'webdbm' Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34319

SAP AG SAPgui EAI WebViewer3D ActiveX Control Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34310

HP OpenView Network Node Manager 'OvAcceptLang' Parameter Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34134

IBM Access Support ActiveX Control 'GetXMLValue()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34228

IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34077

Cisco IOS Multiple Features UDP Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/34245

HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34135

HP OpenView Network Node Manager 'OvOSLocale' Cookie Parameter Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34294

Hitachi JP1/Cm2/Network Node Manager Shared Trace Service Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34313

Cisco IOS Multiple Features IP Sockets Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34242

Haudenschilt Family Connections Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/29722

Family Connections Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34297

VirtueMart Prior to 1.1.3 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/33480

Symantec Backup Exec for Windows Server Remote Agent Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/32347

Trend Micro Internet Security 2008/9 IOCTL Request Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34304

Cisco ASA Appliance WebVPN Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34307

Frog CMS Multiple Remote Vulnerabilities and Weaknesses
http://www.securityfocus.com/bid/34293

Openswan IPsec Livetest Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/31243

Openswan and strongSwan DPD Packet Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34296

MapServer Multiple Remote Security Vulnerabilities
http://www.securityfocus.com/bid/34306

gedit 'PySys_SetArgv' Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/33445

Auth2DB Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/34287

Net-SNMP Remote Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/29623

OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerability
http://www.securityfocus.com/bid/33150

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/33990

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -01 to -06 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/33598

Mozilla Firefox XSL Parsing 'root' XML Tag Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34235

Bugzilla 'attachment.cgi' Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/34308

webEdition CMS 'WE_LANGUAGE' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/34323

JobHut 'manageUser.php' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34321

Podcast Generator 'core/admin/delete.php' Arbitrary File Deletion Vulnerability
http://www.securityfocus.com/bid/34317


+ Security-announce] VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim
http://lists.vmware.com/pipermail/security-announce/2009/000053.html

トレンドマイクロ、セキュリティ情報サイトに新社会人向けコーナー開設
http://itpro.nikkeibp.co.jp/article/NEWS/20090401/327485/?ST=security

4月1日に活動を開始するワーム「Downadup」,トレンドマイクロが警戒を呼びかけ
http://itpro.nikkeibp.co.jp/article/NEWS/20090401/327557/?ST=security

IPA、セキュリティ意識調査を発表
http://itpro.nikkeibp.co.jp/article/NEWS/20090331/327495/?ST=security

JVNDB-2008-002303 Wireshark の WLCCP 解析部におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002303.html

JVNDB-2008-002302 Wireshark におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002302.html

JVNDB-2009-001114 Mozilla Firefox におけるロケーションバーを偽装可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001114.html

JVNDB-2009-001113 複数の Mozilla 製品における XML データを読み取り可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001113.html

JVNDB-2008-001801 IPv6 NDP 実装における Neighbor Discovery メッセージの送信元検証処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001801.html

53005 : Diskos CMS side.asp kat Parameter SQL Injection
http://osvdb.org/show/osvdb/53005

53006 : Diskos CMS Administration Section Multiple Parameter SQL Injection
http://osvdb.org/show/osvdb/53006

53007 : Diskos CMS medlemmer.mdb Direct Request Information Disclosure
http://osvdb.org/show/osvdb/53007

Bugzilla Input Validation Flaw in Attachment Editing Permits Cross-Site Request Forgery Attacks
http://securitytracker.com/alerts/2009/Mar/1021953.html

Solaris dircmp Script Lets Local Users Overwrite Arbitrary Files to Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Mar/1021954.html


Host Power Management Causes Problems with Guest Timekeeping (Windows Hosts)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1227&sliceId=1&docTypeID=DT_KB_1_1

Positive Technologies SA 2009-09: Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28825

2009年Q1のスパム・メール,McColo遮断前の流通量に戻る
http://itpro.nikkeibp.co.jp/article/NEWS/20090401/327588/?ST=security

0 件のコメント:

コメントを投稿