2009年6月11日木曜日

11日 木曜日、大安

The latest snapshot for the stable Linux kernel tree is: 2.6.30-git1
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.30-git1.log

DBD-ODBC 1.22 released
http://www.cpan.org/modules/by-module/DBD/DBD-ODBC-1.22.readme

- Solution 261088: Multiple Security Vulnerabilities in Common UNIX Printing System (CUPS) May Allow a Remote User to Execute Arbitrary Code
http://sunsolve.sun.com/search/document.do?assetkey=1-66-261088-1

「Microsoft Works コンバーター」におけるセキュリティ上の弱点(脆弱性)の注意喚起
http://www.ipa.go.jp/security/vuln/documents/2009/200906_msworks.html

JVNTA09-161A: Adobe Reader および Acrobat における脆弱性
http://jvn.jp/cert/JVNTA09-161A/index.html

JVNVU#649212: libpng が適切にエレメントポインタを初期化しない脆弱性
http://jvn.jp/cert/JVNVU649212/index.html

JVNTA09-160A: Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-160A/index.html

JVN#70858401: Microsoft Works コンバーターにおけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN70858401/index.html

HP OpenView Network Node Manager SNMP and MIB Vulnerability
http://www.vupen.com/english/advisories/2009/1549

HP-UX Update Fixes OpenSSL Security Bypass and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2009/1548

Adobe Reader and Acrobat Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/1547

Microsoft PowerPoint Buffer Overflow in Freelance Translator Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022369.html

Solaris rpc.nisd Daemon Lets Remote Authenticated Users Deny Service
http://securitytracker.com/alerts/2009/Jun/1022368.html

FreeBSD SIOCSIFINFO_IN6 IOCTL Access Bug Lets Local Users Modify IPv6 Interface Properties
http://securitytracker.com/alerts/2009/Jun/1022367.html

FreeBSD Kernel Integer Overflow in Pipe Implementation Lets Local Users Read System Memory
http://securitytracker.com/alerts/2009/Jun/1022365.html




+ Linux Kernel release: 2.6.30
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30

+ FreeBSD-SA-09:08.openssl: Remotely exploitable crash in OpenSSL
http://security.freebsd.org/advisories/FreeBSD-SA-09:08.openssl.asc

+ FreeBSD-SA-09:07.libc: Information leak in db(3)
http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc

+ FreeBSD-SA-09:06.ktimer: Local privilege escalation
http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.asc

+ FreeBSD-SA-09:11.ntpd: ntpd stack-based buffer-overflow vulnerability
http://security.freebsd.org/advisories/FreeBSD-SA-09:11.ntpd.asc

+ FreeBSD-SA-09:10.ipv6: Missing permission check on SIOCSIFINFO_IN6 ioctl
http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc

+ FreeBSD-SA-09:09.pipe: Local information disclosure via direct pipe writes
http://security.freebsd.org/advisories/FreeBSD-SA-09:09.pipe.asc

+ Solution 256748: A Security Vulnerability in the Solaris rpc.nisd(1M) Daemon may Cause a Denial of Service (DoS) Condition to a NIS+ Server
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256748-1

+ Security threat with SSL certificates created with MD5 hash
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011704&sliceId=1&docTypeID=DT_KB_1_1

- Red Hat update for mod_jk
http://secunia.com/advisories/35384/
https://rhn.redhat.com/errata/RHSA-2009-1087.html

+ Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35281

First Linux USB 3.0 drivers emerge
http://www.linux.org/news/2009/06/10/0004.html

New Linux tool helps manage guest virtual machines
http://www.linux.org/news/2009/06/10/0003.html

QueryPerformanceCounter behaves improperly when /usepmtimer is used with some Windows HALs (1011714)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011714&sliceId=1&docTypeID=DT_KB_1_1

Determining if Intel Virtualization Technology or AMD Virtualization is enabled in the BIOS without rebooting (1011712)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011712&sliceId=1&docTypeID=DT_KB_1_1

VMotion fails with a CPU error in the Resource Map (1011711)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011711&sliceId=1&docTypeID=DT_KB_1_1

Control+Alt key combinations in the vCenter Service Console (1011705)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011705&sliceId=1&docTypeID=DT_KB_1_1

Security threat with SSL certificates created with MD5 hash (1011704)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011704&sliceId=1&docTypeID=DT_KB_1_1

In specific situations, the results of the cat command might return truncated results
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011666&sliceId=1&docTypeID=DT_KB_1_1

Blue Moon : Cross Site Request Forgery in Yahoo! 360plus
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29534

ECHO : Firefox (GNU/Linux version) <= 3.0.10 Denial Of Services http://www.criticalwatch.com/support/security-advisories.aspx?AID=29544

Fortinet : Microsoft Internet Explorer DHTML Handling Remote Memory Corruption Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29537

Fortinet : Apple Safari Remote Memory Corruption Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29538

FreeBSD : ntpd
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29514

FreeBSD : ipv6
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29515

FreeBSD : pipe
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29516

Hewlett-Packard : HP-UX Running OpenSSL, Remote Denial of Service (DoS), Bypass Security Restrictions
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29543

Independent Researcher : UPDATED RequestDispatcher directory traversal vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29542

Independent Researcher : XM Easy Personal FTP Server HELP and TYPE command Remote Denial of Service exploit
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29545

Secunia : Microsoft PowerPoint Freelance Layout Parsing Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29535

Secunia : Adobe Reader JBIG2 Text Region Segment Buffer Overflow
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29536

Ubuntu Security Notice : Quagga regression
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29527

US-CERT : Adobe Acrobat and Reader Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29518

ZDI : Adobe Reader U3D RHAdobeMeta Stack Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29526

Core Security Technologies : DX Studio Player Firefox plug-in command injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29530

Core Security Technologies : Internet Explorer Security Zone restrictions bypass
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29531

Hewlett-Packard : HP OpenView Network Node Manager, Remote Execution of Arbitrary Code, DoS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29541

Adobe,最初の定例アップデートは重要度「緊急」含む13件の脆弱性を修正
http://itpro.nikkeibp.co.jp/article/NEWS/20090611/331685/?ST=security

[RSA Conference 2009]ネットを危険地帯にしているのは教育者---和歌山大の豊田准教授が指摘
http://itpro.nikkeibp.co.jp/article/NEWS/20090611/331724/?ST=security

[RSA Conference 2009](ISC)2 Japanがセキュリティ人材のキャリアモデルを作成へ
http://itpro.nikkeibp.co.jp/article/NEWS/20090610/331723/?ST=security

マイクロソフトの6月定例アップデートは「緊急」6件,「重要」3件,「警告」1件
http://itpro.nikkeibp.co.jp/article/NEWS/20090610/331717/?ST=security

[RSA Conference 2009]中小オフィス向けの小型侵入防御システム,TippingPointが参考出展
http://itpro.nikkeibp.co.jp/article/NEWS/20090610/331681/?ST=security

JVNTA09-160A: Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-160A/index.html

JVNVU#568153: Adobe Reader および Acrobat の JPX データ処理における複数の脆弱性
http://jvn.jp/cert/JVNVU568153/index.html

US-CERT Technical Cyber Security Alert TA09-161A -- Adobe Acrobat and Reader Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/Cert/2009-06/msg00001.html

[security bulletin] HPSBUX02435 SSRT090059 rev.1 - HP-UX Running OpenSSL, Remote Denial of S
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00107.html

[SECURITY] UPDATED CVE-2008-5515 RequestDispatcher directory traversal vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00106.html

FreeBSD Security Advisory FreeBSD-SA-09:09.pipe
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00105.html

BSD Security Advisory FreeBSD-SA-09:10.ipv6
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00104.html

FreeBSD Security Advisory FreeBSD-SA-09:11.ntpd
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00103.html

Secunia Research: Adobe Reader JBIG2 Text Region Segment Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00119.html

Secunia Research: Microsoft PowerPoint Freelance Layout Parsing Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00117.html

[ECHO_ADV_110$2009] Firefox (GNU/Linux version) <= 3.0.10 Denial Of Services http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00116.html

XM Easy Personal FTP Server HELP and TYPE command Remote Denial of Service exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00114.html

FortiGuard Advisory: Apple Safari Remote Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00111.html

FortiGuard Advisory: Microsoft Internet Explorer DHTML Handling Remote Memory Corruption Vulnerabili
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00109.html

[USN-775-2] Quagga regression
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00109.html

catching up on several recently fixed bugs of note
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00101.html

CORE-2008-0826 - Internet Explorer Security Zone restrictions bypass
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00100.html

CORE-2009-0521 - DX Studio Player Firefox plug-in command injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00099.html

Apple Safari cross-domain XML theft vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00120.html

SUSE Update for Multiple Packages
http://secunia.com/advisories/35416/

Avaya CMS Solaris Kerberos Unauthorised Access Vulnerability
http://secunia.com/advisories/35414/

eBay Enhanced Picture Services ActiveX Control Command Execution Vulnerability
http://secunia.com/advisories/35412/

Google Chrome WebKit Memory Corruption and Information Disclosure
http://secunia.com/advisories/35411/

FreeBSD "SIOCSIFINFO_IN6" IOCTL Security Issue
http://secunia.com/advisories/35410/

HP OpenView Network Node Manager SNMP and MIB Code Execution Vulnerability
http://secunia.com/advisories/35408/

MoinMoin Hierarchical ACL Security Bypass Security Issue
http://secunia.com/advisories/35407/

Sun Solaris rpc.nisd NIS+ Server Denial of Service
http://secunia.com/advisories/35406/

Ubuntu update for ipsec-tools
http://secunia.com/advisories/35404/

DX Studio Player Firefox Plugin Command Execution Vulnerability
http://secunia.com/advisories/35402/

Ruby BigDecimal Denial of Service Vulnerability
http://secunia.com/advisories/35399/

FreeBSD Direct Pipe Writes Information Disclosure Vulnerability
http://secunia.com/advisories/35398/

FreeBSD update for ntpd
http://secunia.com/advisories/35388/

SUSE update for kernel
http://secunia.com/advisories/35387/

Avaya CMS Solaris libpng Multiple Vulnerabilities
http://secunia.com/advisories/35386/

Red Hat update for mod_jk
http://secunia.com/advisories/35384/

HP-UX update for OpenSSL
http://secunia.com/advisories/35380/

Microsoft PowerPoint Freelance Layout Parsing Vulnerability
http://secunia.com/advisories/35184/

Adobe Reader/Acrobat Multiple Vulnerabilities
http://secunia.com/advisories/34580/

DX Studio Player http://www.milw0rm.com/exploits/8922

Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35274

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Mozilla Firefox Large GIF File Background Denial of Service Vulnerability
http://www.securityfocus.com/bid/35280

Microsoft Internet Explorer Malformed Row Property Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35235

Microsoft Excel QSIR Record Pointer Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35246

Microsoft Internet Explorer Cached Content Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35200

Microsoft Internet Explorer 'onreadystatechange' Corrupt Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35234

Microsoft Windows Search Script Injection Vulnerability
http://www.securityfocus.com/bid/35220

Microsoft Internet Explorer Event Handler Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35224

Microgaming FlashXControl Object ActiveX Control Unspecified Security Vulnerability
http://www.securityfocus.com/bid/35247

Microsoft PowerPoint Freelance Layout Parsing Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35275

Microsoft Internet Explorer XMLHttpRequest Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35222

Microsoft Word Record Parsing Length Field Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35188

Microsoft Internet Explorer 'setCapture()' Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35223

Apple Safari Prior to 4.0 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35260

Microsoft Internet Explorer (CVE-2009-1141) Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35198

Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35281

Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35263

Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35282

XM Easy Personal FTP Server Multiple Command Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35239

libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32331

libxml2 Denial of Service Vulnerability
http://www.securityfocus.com/bid/31555

Libpng Library Unknown Chunk Handler Vulnerability
http://www.securityfocus.com/bid/28770

libxml2 Recursive Entity Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/30783

LightNEasy Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/28801

Libpng Library 'png_push_read_zTXt()' Off-By-One Denial of Service Vulnerability
http://www.securityfocus.com/bid/31049

Libpng Library Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/25956

libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/32326

libxml XML Entity Name Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31126

Linux Kernel Cloned Process 'CLONE_PARENT' Local Origin Validation Weakness
http://www.securityfocus.com/bid/33906

Linux Kernel 'do_splice_from()' Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/31903

Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33113

Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/33003

Linux Kernel 'dell_rbu' Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/33428

Linux Kernel '/ipc/shm.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34020

Linux Kernel Audit System 'audit_syscall_entry()' System Call Security Bypass Vulnerability
http://www.securityfocus.com/bid/33951

Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34934

Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34654

Linux Kernel 'seccomp' System Call Security Bypass Vulnerability
http://www.securityfocus.com/bid/33948

Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34405

Linux Kernel CIFS Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34453

Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33846

Linux Kernel nfsd 'CAP_MKNOD' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34205

Linux Kernel 'splice(2)' Double Lock Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35143

Linux Kernel 'EFER_LME' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34331

Linux Kernel 'inet6_hashtables.c' NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/34602

Linux Kernel 'readlink' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/33412

Linux Kernel 'drivers/char/agp/generic.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34673

Apple iPhone and iPod touch Prior to Version 2.2 Multiple Vulnerabilities
http://www.securityfocus.com/bid/32394

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

Sun Solaris Kerberos Credential Management Security Bypass Vulnerability
http://www.securityfocus.com/bid/35205

Sun Solaris 'rpc.nisd(1M)' Daemon NIS+ Server Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35276

NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35017

Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/33827

Libpng Library ICC Profile Chunk Off-By-One Denial of Service Vulnerability
http://www.securityfocus.com/bid/25957

NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

Ghostscript 'gdevpdtb.c' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34340

Ghostscript 'jbig2dec' JBIG2 Processing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34445

Ghostscript Multiple Input Validation and Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34184

CUPS 'cups/ipp.c' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35169

Ghostscript 'CCITTFax' Decoding Filter Denial of Service Vulnerability
http://www.securityfocus.com/bid/34337

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

Multiple Browser JavaScript Engine 'Math.Random()' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33276

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34240

RealNetworks RealPlayer SWF File Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30370

IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34765

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35138

OpenSSL 'zlib' Compression Memory Leak Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/31692

OpenSSL DTLS Packets Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35001

Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/18228

WebKit DOM Event Handler Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35271

WebKit 'XMLHttpRequest' HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/35270

Apple Safari 'feed:' URI Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/34925

Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/30494

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34412

Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/35304

Drupal Services Module Key Based Access Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/35292

Mutt 'mutt_ssl.c' X.509 Certificate Chain Security Bypass Vulnerability
http://www.securityfocus.com/bid/35288

Drupal Booktree Module Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/35287

Drupal Taxonomy Manager Administrative Page HTML Injection Vulnerability
http://www.securityfocus.com/bid/35286

FreeBSD IPv6 'SIOCSIFINFO_IN6' Permission Check Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/35285

FreeBSD Direct Pipe Write Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35279

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

MoinMoin Hierarchical ACL Security Bypass Vulnerability
http://www.securityfocus.com/bid/35277

0 件のコメント:

コメントを投稿