2009年5月1日金曜日

1日 金曜日、仏滅

Identifying Symmetrix devices using the esxcfg-mpath and symdev commands
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010402&sliceId=1&docTypeID=DT_KB_1_1

Live clone of a virtual machine with an independent disk fails
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010396&sliceId=1&docTypeID=DT_KB_1_1

Where to download the Converter 4.0 boot CD
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010367&sliceId=1&docTypeID=DT_KB_1_1

「豚インフルに注意!」に注意、国の研究機関をかたるウイルスメール
不安に付け込む悪質な手口、送信者名は「国立感染症研究所」
http://itpro.nikkeibp.co.jp/article/NEWS/20090501/329422/?ST=security

JVNDB-2008-002241 Mozilla Firefox におけるプライバシー制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002241.html

JVNDB-2008-002240 複数の Mozilla 製品の CSS パーサにおけるサニタイズ処理を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002240.html

JVNDB-2008-002239 複数の Mozilla 製品における誤った URL が表示される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002239.html

JVNDB-2008-002238 複数の Mozilla 製品の loadBindingDocument 関数におけるデータにアクセスされる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002238.html

JVNDB-2008-002237 複数の Mozilla 製品におけるデータの一部にアクセスされる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002237.html

JVNDB-2008-002236 複数の Mozilla 製品における別ドメインからコンテンツを読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002236.html

JVNDB-2008-002235 Mozilla Firefox におけるクローム特権で任意の JavaScript を実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002235.html

JVNDB-2008-002234 複数の Mozilla 製品におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002234.html

JVNDB-2008-002233 複数の Mozilla 製品におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002233.html

JVNDB-2008-002232 複数の Mozilla 製品におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002232.html

JVNDB-2008-002231 Mozilla Firefox のセッション復元機能におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002231.html

JVNDB-2008-002230 複数の Mozilla 製品における任意の JavaScript を実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002230.html

JVNDB-2008-002229 複数の Mozilla 製品における クロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002229.html

JVNDB-2008-001955 複数の Mozilla 製品における引用文字のエスケープ処理に関する XML を挿入される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001955.html

JVNDB-2008-001951 Mozilla Firefox/SeaMonkey におけるコードベースプリンシパルに対する防御機構を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001951.html

JVNDB-2008-001950 複数の Mozilla 製品の nsXMLHttpRequest::NotifyEventListeners メソッドにおける同一生成元ポリシーを回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001950.html

JVNDB-2008-001947 Mozilla Firefox/SeaMonkey の http-index-format MIME type parser におけるメモリ割り当てに関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001947.html

JVNDB-2008-001946 Mozilla Firefox における同一生成元ポリシー違反によるクロサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001946.html

JVNDB-2008-001945 複数の Mozilla 製品の nsFrameManager における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001945.html

JVNDB-2008-001944 複数の Mozilla 製品の JavaScript エンジンにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001944.html

JVNDB-2008-001943 複数の Mozilla 製品のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001943.html

JVNDB-2008-001942 複数の Mozilla 製品のレイアウトエンジンにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001942.html

Adobe Flash Media Server Bug Lets Remote Users Execute Remote Procedures
http://securitytracker.com/alerts/2009/Apr/1022148.html




+ Solution 258048 : A Security Vulnerability in the ASN.1 Handling in Solaris OpenSSL May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-258048-1

+ RHSA-2009:0459-1 Important: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-0459.html

Request for Comment: TPF to engage Richard Dice on 6 month contract for Perl community development
http://use.perl.org/articles/09/04/30/1650205.shtml

Microsoft Security Advisory (960715)
Update Rollup for ActiveX Kill Bits
http://www.microsoft.com/technet/security/advisory/960715.mspx

Making the Business Case for Software Assurance Published
http://www.cert.org/archive/pdf/09sr001.pdf

Backing up the ADAM database in VMware Virtual Desktop Manager
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010285&sliceId=1&docTypeID=DT_KB_1_1

ネットマークスが認証ソフトの新版、管理できるID数を増大
http://itpro.nikkeibp.co.jp/article/NEWS/20090430/329396/?ST=security

JVNVU#970180 Adobe Reader および Acrobat における customDictionaryOpen() と getAnnots() に脆弱性
http://jvn.jp/cert/JVNVU970180/index.html

Samba 3.3.4 リリース
http://us3.samba.org/samba/

MULTIPLE REMOTE VULNERABILITIES--Leap CMS 0.1.4-->
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00292.html

Security tools list: First Version
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-04/msg00290.html

Coppermine Photo Gallery "css" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/34961/

Sun Solaris OpenSSL "ASN1_STRING_print_ex()" Denial of Service
http://secunia.com/advisories/34960/

Drupal Fivestar Module Cross-Site Request Forgery
http://secunia.com/advisories/34956/

Drupal Node Access User Reference Module Security Bypass
http://secunia.com/advisories/34955/

Drupal News Page Module "keywords" SQL Injection
http://secunia.com/advisories/34954/

Drupal Exif Module Script Insertion Vulnerability
http://secunia.com/advisories/34953/

Ubuntu update for apport
http://secunia.com/advisories/34952/

SCO UnixWare IGMP Driver Denial of Service Vulnerability
http://secunia.com/advisories/34951/

Drupal Script Insertion and Information Disclosure
http://secunia.com/advisories/34950/

vbDrupal Script Insertion and Information Disclosure
http://secunia.com/advisories/34948/

Apport Cleanup Race Condition Security Issue
http://secunia.com/advisories/34947/

LimeSurvey Unspecified Vulnerability
http://secunia.com/advisories/34946/

S-CMS "page" Local File Inclusion Vulnerability
http://secunia.com/advisories/34940/

Zubrag Smart File Download File Extension Security Bypass
http://secunia.com/advisories/34929/

Precidia Ether232 Web Server Denial of Service Vulnerability
http://secunia.com/advisories/34929/

Symantec WinFax Pro Fax Viewer ActiveX Control Buffer Overflow
http://secunia.com/advisories/34925/

Debian update for libdbd-pg-perl
http://secunia.com/advisories/34909/

Debian update for mysql-dfsg
http://secunia.com/advisories/34907/

TWiki Cross-Site Request Forgery Vulnerabilities
http://secunia.com/advisories/34880/

Foswiki Cross-Site Request Forgery Vulnerabilities
http://secunia.com/advisories/34863/

GnuTLS Multiple Vulnerabilities
http://secunia.com/advisories/34842/

Tiger DMS "username" and "password" SQL Injection
http://secunia.com/advisories/34784/

Symantec WinFax Buffer Overflow Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Apr/1022147.html

TWiki Image Tag Processing Bug Permits Cross-Site Request Forgery Attacks
http://securitytracker.com/alerts/2009/Apr/1022146.html

RHBA-2009:0456-1 file bug fix update
http://rhn.redhat.com/errata/RHBA-2009-0456.html

RHSA-2009:0457-1 Moderate: libwmf security update
http://rhn.redhat.com/errata/RHSA-2009-0457.html

Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34740

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
http://www.securityfocus.com/bid/7254

Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/11182

Multiple China-on-site.com Products Username and Password SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/32810

Joomla HBS Multiple Components 'showhoteldetails' SQL Injection Vulnerability
http://www.securityfocus.com/bid/32952

Symantec Brightmail Gateway Control Center Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34641

Symantec Brightmail Gateway Control Center Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34639

Gowon Designs Leap Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/34787

LimeSurvey '/admin/remotecontrol' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34785

Tiger DMS Login SQL Injection Vulnerability
http://www.securityfocus.com/bid/34775

GnuTLS Prior to 2.6.6 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34783

Coppermine Photo Gallery 'css' Parameter Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/34782

Zubrag Smart File Download 'download.php' File Download Security Bypass Vulnerability
http://www.securityfocus.com/bid/34773

Baby Web Server URL File Disclosure Vulnerability
http://www.securityfocus.com/bid/34772

S-CMS 'plugin.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/34771

Google Chrome 'throw()' function Null Pointer Dereference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34786

Mpegable Player '.YUV' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34770

Drupal Node Access User Reference Module Security Bypass Vulnerability
http://www.securityfocus.com/bid/34778

News Page Drupal Module Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/34777

Sun Solaris DTrace Handler IOCTL Request Multiple Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34753

Microsoft XML Core Services Transfer Encoding Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32204

Microsoft XML Core Services DTD Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32155

Drupal HTML Injection and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/34779

Exif Drupal Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/34774

udev Netlink Message Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34536

Microsoft Windows SeImpersonatePrivilege Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/28833

Symantec WinFax Pro 'DCCFAXVW.DLL' Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34766

Microsoft Windows Media Components ISATAP URL Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32654

Microsoft Windows Media Components 'Service Principle Name' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/32653

eLitius 'banner-details.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34769

GNU Tar Invalid Headers Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/16764

Ubuntu Apport Local Arbitrary File Deletion Vulnerability
http://www.securityfocus.com/bid/34776

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

McAfee Products RAR/ZIP Files Scan Evasion Vulnerability
http://www.securityfocus.com/bid/34780

SCO UnixWare IGMP Driver Unspecified Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34781

JBC Explorer Auth.Inc.PHP Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/26332

IBM Tivoli Continuous Data Protection for Files Insecure Default Permissions Vulnerability
http://www.securityfocus.com/bid/26293

Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34790

BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34789

Mercury Audio Player '.m3u' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34788

Symantec WinFax Pro ActiveX Control Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1221

Sun Solaris OpenSSL Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/1220

LimeSurvey Remote Code Execution and Information Disclosure Issues
http://www.vupen.com/english/advisories/2009/1219

GnuTLS Key and Certificate Handling Double Free and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2009/1218

TWiki URL Processing Cross Site Request Forgery Vulnerabilities
http://www.vupen.com/english/advisories/2009/1217

vbDrupal Cross Site Scripting and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/1216

Drupal Fivestar Module Cross Site Request Forgery Vulnerability
http://www.vupen.com/english/advisories/2009/1215

Drupal News Page Keywords Processing SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/1214

Drupal Exif Module Data Handling Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1213

Drupal Node Access User Reference Access Bypass Vulnerability
http://www.vupen.com/english/advisories/2009/1212

Drupal Cross Site Scripting and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/1211

RHSA-2009:0457 Moderate: libwmf security update
http://rhn.redhat.com/errata/RHSA-2009-0457.html

RHSA-2009:0458 Important: gpdf security update
http://rhn.redhat.com/errata/RHSA-2009-0458.html

RHSA-2009:0459 Important: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-0459.html

マイクロソフト セキュリティ情報 MS09-012 - 重要
Windows の脆弱性により、特権が昇格される (959454) 【更新】http://www.microsoft.com/japan/technet/security/bulletin/ms09-012.mspx

マイクロソフト セキュリティ情報 MS08-076 - 重要
Windows Media コンポーネントの脆弱性により、リモートでコードが実行される (959807) 【更新】http://www.microsoft.com/japan/technet/security/bulletin/ms08-076.mspx

マイクロソフト セキュリティ情報 MS08-069 - 緊急
Microsoft XML コア サービスの脆弱性により、リモートでコードが実行される (955218) 【更新】http://www.microsoft.com/japan/technet/security/bulletin/ms08-069.mspx

0 件のコメント:

コメントを投稿