2009年4月13日月曜日

月曜日、友引

Trend Micro Control Manager 5.0 Patch 3 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1236

弊社ホームページ サーバメンテナンスのお知らせ(2009年4月14日)
http://www.trendmicro.co.jp/support/news.asp?id=1242

「Confickerに感染してますよ。すぐに駆除を」MSをかたる悪質メール
偽のウイルスチェックサイトに誘導、ウイルスをダウンロードさせる
http://itpro.nikkeibp.co.jp/article/NEWS/20090413/328299/?ST=security

「画像スパム」が再び急増、迷惑メールの7%以上に
バイアグラなどの宣伝が主流、価格の通貨単位だけが異なるメールも
http://itpro.nikkeibp.co.jp/article/NEWS/20090413/328278/?ST=security

「偽ソフトをインストール、5月3日に消滅」凶悪ウイルスに新しい亜種
セキュリティ企業各社が警告、ボット感染で迷惑メールの踏み台にも
http://itpro.nikkeibp.co.jp/article/NEWS/20090413/328242/?ST=security

ライフボートがUSBメモリーからの情報漏えいを抑制するソフトを販売http://itpro.nikkeibp.co.jp/article/NEWS/20090413/328270/?ST=security

JVNDB-2009-001134 LittleCMS におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001134.html

JVNDB-2009-001133 LittleCMS における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001133.html

JVNDB-2009-001132 LittleCMS におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001132.html

JVNDB-2009-001131 Adobe Reader および Adobe Acrobat における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001131.html


NTP Release Candidate 4.2.4p7-RC2
http://archive.ntp.org/ntp4/ChangeLog-stable-rc

NTP Development 4.2.5p163
http://archive.ntp.org/ntp4/ChangeLog-dev

+ [Security-announce] VMSA-2009-0006 VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
http://www.vmware.com/security/advisories/VMSA-2009-0006.html

GLSA 200904-12: Wicd: Information disclosure
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28934

MDVSA-2009:089: opensc
http://www.criticalwatch.com/support/security-advisories.aspx?AID=28931

ftpdmin v. 0.96 RNFR remote buffer overflow exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00115.html

HP Deskjet 6800 XSS in Web Interface
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00114.html

[SECURITY] [DSA 1769-1] New openjdk-6 packages fix arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00111.html

In Response to Bid 34130 Invalid
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00113.html

[BMSA 2009-04] Remote DoS in Internet Explorer
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00112.html

Bid 34130 Invalid
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00097.html

+ VMSA-2009-0006 VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00109.html

[ MDVSA-2009:090 ] php
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00105.html

[SECURITY] [DSA 1768-1] New openafs packages potential code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00103.html

Loggix Project 9.4.5 Blind SQL Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00099.html

[ GLSA 200904-12 ] Wicd: Information disclosure
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00106.html

PHP-agenda <= 2.2.5 Remote File Overwriting http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00098.html

+ PHP 5.2.9 curl safe_mode & open_basedir bypass
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00100.html

[DSECRG-09-036] Chance-i Techno Vision Security System - Directory Traversal File Do
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00104.html

[DSECRG-09-035] Chance-i DiViS DVR ActiveX - Heap Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00095.html

[ MDVSA-2009:089 ] opensc
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00096.html

Dynamic Flash Forum 1.0 Beta Multiple Remote Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00107.html

[SECURITY] [DSA 1754-1] New roundup packages fix privilege escalation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00102.html

+ 53571 : Linux Kernel sys/net/af_rose.c Length Value Handling Overflow
http://osvdb.org/show/osvdb/53571

MapServer Multiple Vulnerabilities
http://www.securiteam.com/unixfocus/5RP0C0KQUQ.html

+ VMware Flaw in Virtual Machine Display Function Lets Local Users on a Guest Operating System Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Apr/1022031.html

Cisco Subscriber Edge Services Manager (SESM) Input Validation Hole Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2009/Apr/1022030.html

Ghostscript Heap Overflow in jbig2dec Library Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Apr/1022029.html

Clam AntiVirus UPack File and URL Processing Bugs Let Remote Users Deny Service
http://www.securitytracker.com/id?1022028

Wireshark LDAP/CPHAP/Tektronix Bugs Let Remote Users Deny Service
http://www.securitytracker.com/id?1022027

MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34409

MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34408

Wireshark PN-DCP Data Format String Vulnerability
http://www.securityfocus.com/bid/34291

Wireshark Prior to 1.0.7 Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34457

Little CMS Monochrome Profiles Null Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/34411

Avahi 'avahi-core/server.c' Multicast DNS Denial Of Service Vulnerability
http://www.securityfocus.com/bid/33946

Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34383

+ NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

RETIRED: Maian Music Joomla! Component 'category' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/34432

Google Chrome Single Thread Alert Out of Bounds Memory Access Vulnerability
http://www.securityfocus.com/bid/34130

Little CMS Memory Leak and Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/34185

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34240

Sun Java Applet Font.createFont Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/17981

HP Deskjet 6840 'refresh_rate.htm' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34480

FTPDMIN 'RNFR' Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34479

Microsoft Internet Explorer File Download Denial of Service Vulnerability
http://www.securityfocus.com/bid/34478

Cisco PIX and ASA Multiple Denial of Service, ACL Bypass, and Authentication Bypass Vulnerabilities
http://www.securityfocus.com/bid/34429

VMware Multiple Hosted Products Display Function Code Execution Vulnerability
http://www.securityfocus.com/bid/34471

Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33658

PHP 5.2.8 and Prior Versions Multiple Vulnerabilities
http://www.securityfocus.com/bid/33927

OpenAFS Error Codes Remote Denial of Service Vulnerabiliy
http://www.securityfocus.com/bid/34404

OpenAFS Unix Cache Manager Heap-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34407

OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/33922

w3bcms Guestbook Module 'index.inc.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34477

Redaxscript 'language' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/34476

+ PHP cURL 'safe_mode' and 'open_basedir' Restriction-Bypass Vulnerability
http://www.securityfocus.com/bid/34475

MoziloCMS Local File Include and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34474

Chance-i DiViS DVR System Web Server Directory Traversal Vulnerability
http://www.securityfocus.com/bid/34473

Xilisoft Video Converter Wizard '.CUE' File Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34472

Chance-i DiViS-Web DVR System ActiveX Control 'AddSiteEx()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34468

Loggix Project 'post.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34467

JVNDB-2007-000217 Apache Tomcat の Apache HTTP Server との組合せによるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000217.html

0 件のコメント:

コメントを投稿