2009年4月24日金曜日

金曜日、先勝

DBD-Pg 2.13.1 released
http://www.cpan.org/modules/by-module/DBD/DBD-Pg-2.13.1.readme

JVN#97248625 Movable Type におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN97248625/index.html

JVNDB-2009-000020 Movable Type におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000020.html

JVNDB-2009-001174 Openswan および Strongswan IPsec におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001174.html

JVNDB-2008-002308 Openswan の IPSEC livetest ツールにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002308.html

JVNDB-2009-001173 Mozilla Firefox/SeaMonkey における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001173.html

JVNDB-2009-001172 SystemTap における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001172.html

JVNDB-2009-001171 net-snmp の netsnmp_udp_fmtaddr 関数におけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001171.html

JVNDB-2006-000993 JRE、JDK および SDK におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-000993.html

JVNDB-2008-002285 PHP の imageRotate 関数における任意のメモリ内容を読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002285.html

JVNDB-2008-002260 PHP の ext/mbstring/libmbfl/filters/mbfilter_htmlent.c における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002260.html

JVNDB-2008-002168 PHP の FastCGI モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002168.html

JVNDB-2008-001733 PHP の imageloadfont 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001733.html

JVNDB-2008-000084 PHP におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000084.html








DBD-SQLite 1.25 released
http://www.cpan.org/modules/by-module/DBD/?M=D

[ curl-Bugs-2715307 ] VMS-Alpha abend using CURLOPT_HTTPHEADER
http://curl.haxx.se/mail/tracker-2009-04/0027.html

Licensing Lab Manager 3.0
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010191&sliceId=1&docTypeID=DT_KB_1_1

Licensing VMware View Manager
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010190&sliceId=1&docTypeID=DT_KB_1_1

+ Solution 248386 : Security vulnerability in Solaris Related to the Apache 1.3 mod_perl(3) Module Component "PerlRun.pm" may Lead to Denial of Service (DoS)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-248386-1

+ Solution 247406 : Security Vulnerability with IKE Packet Handling in Solaris libike Library may Lead to a Crash of in.iked(1M)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-247406-1

+ Solution 254569 : Security Vulnerabilities in the Java Runtime Environment (JRE) LDAP Implementation may Allow a Denial of Service (DoS) and Malicious Code to be Executed
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1

InterScan Messaging Hosted Security:Webポータルへのアクセス障害に関するご報告
http://www.trendmicro.co.jp/support/news.asp?id=1249

USN-764-1: Firefox and Xulrunner vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29082

チェック・ポイントがハイエンドUTM製品を発表
http://itpro.nikkeibp.co.jp/article/NEWS/20090423/329014/?ST=security

ゴールデンウィーク中も「ワンクリック詐欺」に気をつけて
IPAが長期休暇前に警告、対策ソフトが効かない新手口に注意
http://itpro.nikkeibp.co.jp/article/NEWS/20090423/329046/?ST=security

巨大ボットネット発見,190万台の感染マシンで構成
http://itpro.nikkeibp.co.jp/article/NEWS/20090423/329035/?ST=security

[USN-764-1] Firefox and Xulrunner vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00229.html

FOWLCMS 1.1--Multiple Remote Vulnerabilities-->
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00232.html

FreeBSD update for openssl
http://secunia.com/advisories/34896/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/34894/

webClassifieds Insecure Cookie Handling Vulnerability
http://secunia.com/advisories/34877/

Red Hat update for giflib
http://secunia.com/advisories/34872/

Debian update for mahara
http://secunia.com/advisories/34871/

Slackware update for mozilla-firefox
http://secunia.com/advisories/34867/

Citrix Presentation Server Access Gateway Filters Security Bypass
http://secunia.com/advisories/34865/

SAP Products Cfolders Engine Cross-Site Scripting and Script Insertion
http://secunia.com/advisories/34859/

Xitami Multiple Requests Denial of Service Vulnerability
http://secunia.com/advisories/34858/

SUSE update for cups
http://secunia.com/advisories/34852/

Joomla RS-Monials Component "comments" Script Insertion Vulnerability
http://secunia.com/advisories/34837/

New 5 Star Rating System "myusername" SQL Injection Vulnerability
http://secunia.com/advisories/34820/

Ubuntu update for firefox and xulrunner
http://secunia.com/advisories/34817/

FreeBSD libc "db" Interface Information Leak Weakness
http://secunia.com/advisories/34810/

Banner Student "question" Script Insertion Vulnerability
http://secunia.com/advisories/34806/

OCS Inventory NG Server Unspecified Vulnerabilities
http://secunia.com/advisories/34763/

Symantec Brightmail Appliance Brightmail Control Center Lets Remote Authenticated Users Gain Elevated Privileges
http://www.securitytracker.com/id?1022117

Symantec Brightmail Input Validation Flaw in Brightmail Control Center Permits Cross-Site Scripting Attacks
http://www.securitytracker.com/id?1022116

Xitami Web Server HEAD Request Processing Flaw Lets Remote Users Deny Service
http://www.securitytracker.com/id?1022115

Citrix XenApp Bug Lets Remote Users Bypass Access Policy
http://www.securitytracker.com/id?1022114

Symantec Brightmail Gateway Privilege Elevation and XSS Vulnerabilities
http://www.vupen.com/english/advisories/2009/1155

Citrix XenApp Access Gateway Filters Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2009/1154

SAP Products cFolders Multiple Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2009/1153

OCS Inventory NG Security Update Fixes Unspecified Vulnerabilities
http://www.vupen.com/english/advisories/2009/1152

RS-Monials component for Joomla Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1151

New 5 Star Rating "myusername" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/1150

ElkaGroup Image Gallery Arbitrary File Upload Vulnerability
http://www.vupen.com/english/advisories/2009/1149

Dokeos LMS "include" Parameter Local File Inclusion Vulnerability
http://www.vupen.com/english/advisories/2009/1148

Apache "mod_proxy_ajp" Module Information Disclosure Vulnerability
http://www.vupen.com/english/advisories/2009/1147

Trend Micro OfficeScan Client Folder Name Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/1146

TYPO3 Diocese of Portsmouth Calendar Today Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29819

TYPO3 Diocese of Portsmouth Training Courses Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29822

TYPO3 Download system Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29825

TYPO3 Random Prayer Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29827

TYPO3 TIMTAB Social Bookmark Icons Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29823

TYPO3 Fussballtippspiel Extension SQL Injection Vulnerability
http://www.securityfocus.com/bid/29824

TYPO3 TARGET-E WorldCup Bets Extension Multiple Unspecified Input Validation Vulnerabilities
http://www.securityfocus.com/bid/29826

TYPO3 Resource Library Extension Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/29832

CoolPlayer Skin File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/32947

CUPS Insufficient 'Host' Header Validation Weakness
http://www.securityfocus.com/bid/34665

CUPS '_cupsImageReadTIFF()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34571

CoolPlayer M3U File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30418

Libungif Colormap Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/15299

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

Libungif Null Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/15304

mpg123 'store_id3_text()' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34381

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/32620

Sun Java Web Start and Java Plug-in JAR File Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/32892

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/32608

SLURM 'sbcast' and 'strigger' Group Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34638

eLitius 'database-backup.php' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34659

CRE Loaded 'product_info.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34640

Quick.CMS.Lite 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/34647

MixedCMS 1.0 Beta Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34649

Microsoft Internet Explorer Marquee Tag Handling Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34426

DirectAdmin '/CMD_DB' Restore Action Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34678

DirectAdmin '/CMD_DB' Backup Action Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/34676

Dokeos 'user_portal.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/30150

Symantec Norton Ghost 'EasySetupInt.dll' ActiveX Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34696

Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34412

Dokeos 'whoisonline.php' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34633

Linux Kernel nfsd 'CAP_MKNOD' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34205

Linux Kernel 'CAP_FS_SET' Incomplete Capabilities List Access Validation Vulnerability
http://www.securityfocus.com/bid/34695

VS Panel 'showcat.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34648

Mozilla Firefox International Domain Name Subdomain URI Spoofing Vulnerability
http://www.securityfocus.com/bid/33837

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Epona IP Address Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34651

Zervit HTTP Server Malformed URI Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34637

Adam Patterson Addess Book Multiple Script Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/34652

SunGard Banner Student 'twbkwbis.P_SecurityQuestion' HTML Injection Vulnerability
http://www.securityfocus.com/bid/34620

NotFTP 'config.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/34636

Mod_Perl Path_Info Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/23192

Download Center Lite Unspecified Security Vulnerability
http://www.securityfocus.com/bid/34653

Microsoft DirectX DirectShow MJPEG Video Decompression Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34460

Symantec Brightmail Gateway Control Center Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34641

Symantec Brightmail Gateway Control Center Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34639

OAuth Session-Fixation Vulnerability
http://www.securityfocus.com/bid/34682

PastelCMS Local File Include and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34635

Oracle April 2009 Critical Patch Update Multiple Vulnerabilities
http://www.securityfocus.com/bid/34461

Dojo 'dijit.Editor' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34661

Dojo Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34660

AbleSpace Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/34512

I-RATER Photo Rating Script Pro 'admin/login.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34646

I-RATER Platinum 'platinumadmin.html' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34645

Avaya Communication Manager Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/29939

xine-lib STTS QuickTime Atom Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34384

Citrix XenApp Unspecified Security Bypass Vulnerability
http://www.securityfocus.com/bid/34691

Novell Access Manager Local Browser Security Bypass Vulnerability
http://www.securityfocus.com/bid/32121

Popcorn POP3 Response Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34699

Home Web Server Graphical User Interface Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34698

OCS Inventory NG Server Prior to 1.02 Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/34694

Recover Data for Novell Netware '.SAV' File Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34693

FOWLCMS Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34690

0 件のコメント:

コメントを投稿