2009年6月15日月曜日

15日 月曜日、先負

+ Microsoft Internet Explorer Cached Content Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35200

+ Multiple Symantec Products RAR/TAR/ZIP File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/35354

- Microsoft Windows Media Player ScriptCommand Multiple Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35335

MySQL Workbench 5.1.13 RC availabe
http://dev.mysql.com/workbench/?page_id=49

[ANNOUNCE] Apache Harmony 5.0M10 available
http://harmony.apache.org/download.cgi

PSN-2009-05-366: End of Life Announcement – SBR Enterprise and Global Enterprise Appliances
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2009-05-366&viewMode=view

PHP 5.2.10RC2 and PHP 5.3.0RC3 Release Announcements
http://www.php.net/archive/2009.php#id2009-06-12-1

Navicat PostgreSQL GUI for Windows ver. 8.1.11 is now available
http://www.postgresql.org/about/news.1096

Firefox-SA-06/12/2009: Mozilla Firefox Java Applet Loading Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29564

USN-787-1: Apache vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29555

Adobe-SA-06/11/2009: Adobe Reader/Acrobat TrueType Font Processing Memory Corruption Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29563

iDefense Security Advisory 06.11.09: Multiple Vendor WebKit Error Handling Use After Free Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29558

iDefense Security Advisory 06.11.09: Microsoft Active Directory Hexdecimal DN AttributeValue Invalid Free Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29559

iDefense Security Advisory 06.11.09: Microsoft Excel SST Record Integer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29560

iDefense Security Advisory 06.11.09: Microsoft Windows 2000 Print Spooler Remote Stack Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29561

iDefense Security Advisory 06.11.09: Adobe Reader and Acrobat FlateDecode Integer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29562

FirePass-SA-06/11/2009: F5 FirePass Cross-Site Scripting vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29565

ModSecurity-SA-06/11/2009: ModSecurity (Core Rules) HTTP Parameter Pollution Filter Bypass Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29568

Serena Dimensions CM has insufficient default privileges
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00136.html

Secunia Research: Mozilla Firefox Java Applet Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00137.html

[USN-787-1] Apache vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00135.html

「Web改ざんの被害連鎖が発生している」――セキュアブレインが自社サイトの検査を呼びかけ
http://itpro.nikkeibp.co.jp/article/NEWS/20090612/331813/?ST=security

Mozilla Thunderbird Multiple Vulnerabilities
http://secunia.com/advisories/35440/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/35439/

Google Chrome WebKit Use-After-Free Vulnerability
http://secunia.com/advisories/35438/

Git git-daemon Parameter Parsing Infinite Loop Denial of Service
http://secunia.com/advisories/35437/

Teiid LDAP Anonymous Bind Security Bypass
http://secunia.com/advisories/35432/

Red Hat update for firefox
http://secunia.com/advisories/35431/

Red Hat update for seamonkey
http://secunia.com/advisories/35428/

Sniggabo CMS "id" SQL Injection Vulnerability
http://secunia.com/advisories/35420/

phpWebThings "module" Local File Inclusion Vulnerability
http://secunia.com/advisories/35396/

Ubuntu update for apache2
http://secunia.com/advisories/35395/

Grestul "admin/options.php" Security Bypass Vulnerability
http://secunia.com/advisories/35367/

Kloxo / HyperVM Multiple Vulnerabilities
http://secunia.com/advisories/35337/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/35331/

PDshopPro "search" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/34200/

Mozilla Thunderbird Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022397.html

Mozilla Thunderbird Proxy Response Processing Bug Lets Remote Users Execute Arbitrary Code in the Context of an SSL-Protected Domain
http://securitytracker.com/alerts/2009/Jun/1022396.html

F5 FirePass Input Validation Flaw in Unspecified Password Fields Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2009/Jun/1022387.html

Mozilla Firefox Race Condition in Accessing an NPObject May Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022386.html

Mozilla Firefox Event Listener Null Document Owner Bug Lets Remote Users Execute Arbitrary Code with Chrome Privileges
http://securitytracker.com/alerts/2009/Jun/1022385.html

Mozilla Firefox Lets Remote Users Execute Arbitrary Scripting Code with Chrome Privileges
http://securitytracker.com/alerts/2009/Jun/1022384.html

Mozilla Firefox Proxy Response Processing Bug Lets Remote Users Execute Arbitrary Code in the Context of an SSL-Protected Domain
http://securitytracker.com/alerts/2009/Jun/1022383.html

Mozilla Firefox 'file:' Protocol Lets Remote Users Access Stored Cookies
http://securitytracker.com/alerts/2009/Jun/1022382.html

Mozilla Firefox 'file:' Resources May Let Remote Users Access Certain Documents
http://securitytracker.com/alerts/2009/Jun/1022381.html

Mozilla Firefox Unicode Character Processing Bug Lets Remote Users Spoof URLs
http://securitytracker.com/alerts/2009/Jun/1022380.html

Mozilla Firefox XUL Script Policy Can By Bypassed By Remote Users
http://securitytracker.com/alerts/2009/Jun/1022379.html

Microsoft Windows Print Spooler Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35209

Microsoft Internet Explorer Event Handler Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35224

Microsoft Internet Explorer 'onreadystatechange' Corrupt Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35234

Microsoft Internet Explorer 'setCapture()' Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35223

Microsoft Internet Explorer XMLHttpRequest Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35222

Microsoft Internet Explorer Malformed Row Property Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35235

Microsoft Internet Explorer (CVE-2009-1141) Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35198

Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35226

RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35260

Microsoft Windows Print Spooler Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35208

Microsoft Active Directory Memory Leak Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35225

Microsoft Windows Print Spooler 'EnumeratePrintShares()' Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35206

XM Easy Personal FTP Server Multiple Command Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35239

Worldweaver DX Studio Player Browser Plugin Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35273

WebKit Web Inspector Page Privilege Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/35349

Safari X.509 Extended Validation Certificate Revocation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35353

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

Yogurt Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35324

Apple Safari 'open-help-anchor' URI Handler Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35351

SHA-0/SHA-1 Reduced Operation Digest Collision Weakness
http://www.securityfocus.com/bid/12577

GnuTLS X.509 Certificate Chain Security Bypass Vulnerability
http://www.securityfocus.com/bid/32232

Opera Web Browser 9.26 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/28585

Apple Safari for Windows Reset Password Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35352

Microgaming FlashXControl Object ActiveX Control Unspecified Security Vulnerability
http://www.securityfocus.com/bid/35247

MoinMoin Hierarchical ACL Security Bypass Vulnerability
http://www.securityfocus.com/bid/35277

PDFlib Lite PNG Image Size Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35266

WebKit Java Applet Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35350

Kerio MailServer WebMail Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35264

Joomla! AkoBook Component 'Itemid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35268

Multiple OrdaSoft Joomla! Components 'mosConfig_absolute_path' Remote File Include Vulnerability
http://www.securityfocus.com/bid/35269

Ideal MooFAQ Joomla! Component 'file_includer.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/35259

Apple Safari CFNetwork Downloaded Files Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35347

WebKit Web Inspector Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35348

Automated Link Exchange Portal Insecure Cookie Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35261

Apple Safari for Windows Private Browsing Cookie Data Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35346

Apple Safari Windows Installer Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35339

Rasterbar Software libtorrent Arbitrary File Overwrite Vulnerability
http://www.securityfocus.com/bid/35262

LightNEasy Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/28801

Apple Safari CFNetwork Script Injection Weakness
http://www.securityfocus.com/bid/35344

NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35017

phpMyAdmin 'setup.php' PHP Code Injection Vulnerability
http://www.securityfocus.com/bid/34236

Ganglia gmetad 'process_path()' Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33299

Cyrus SASL 'sasl_encode64()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34961

Hot Links SQL-PHP 'report.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/31078

WebKit Custom Cursor and Adjusting CSS3 Hotspot Properties Browser UI Element Spoofing Vulnerability
http://www.securityfocus.com/bid/35340

CUPS 'HP-GL/2' Filter Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/31688

CUPS Multiple Heap Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/31690

libwmf WMF Image File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34792

Libpng Library ICC Profile Chunk Off-By-One Denial of Service Vulnerability
http://www.securityfocus.com/bid/25957

Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/33827

Luottokunta Payment Security Bypass Vulnerability
http://www.securityfocus.com/bid/35191

ImageMagick TIFF File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35111

WebKit JavaScript DOM User After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35325

WebKit SVG Animation Elements User After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35334

WebKit XML External Entity Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35321

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35326

Microsoft Word Record Parsing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35190

Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35303

Apple iTunes Multiple URI Handler Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35157

Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34663

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

WebKit File Enumeration Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35333

WebKit 'about:blank' Security Bypass Vulnerability
http://www.securityfocus.com/bid/35332

WebKit JavaScript Prototypes Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35330

WebKit 'Canvas' SVG Image Capture Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35331

WebKit 'Location' and 'History' Objects Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35327

WebKit Frame Transition Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/35328

Microsoft Windows Pointer Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35238

Microsoft Windows 'win32k.sys' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35121

Microsoft RPC Marshalling Engine Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35219

Microsoft Windows Argument Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35240

Microsoft Windows Desktop Wall Paper System Parameter Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35120

Microsoft Internet Explorer Cached Content Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35200

Microsoft Internet Explorer JavaScript Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/24283

Microsoft Windows Media Player ScriptCommand Multiple Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35335

0 件のコメント:

コメントを投稿