2009年6月25日木曜日

25日 木曜日、先勝

JVN#32788272: レッツPHP! 製 PHP-I-BOARD におけるディレクトリトラバーサルの脆弱性
http://jvn.jp/jp/JVN32788272/index.html

JVN#20219071: レッツPHP! 製 PHP-I-BOARD におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN20219071/index.html

JVN#93827000: レッツPHP! 製 Tree BBS におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN93827000/index.html

JVNDB-2009-001185: Microsoft Office PowerPoint に任意のコードが実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001185.html

JVNDB-2009-001129: PostgreSQL のエラーメッセージの変換処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001129.html

JVNDB-2008-000075: EC-CUBE における SQL インジェクションの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000075.html

JVNDB-2008-000009: Apache Tomcat において不正な Cookie を送信される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000009.html

JVNDB-2007-000217: Apache Tomcat の Apache HTTP Server との組合せによるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000217.html

JVNDB-2007-000185: Apache Tomcat JK Web Server Connector におけるスタックオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000185.html

JVNDB-2009-000046: レッツPHP! 製 PHP-I-BOARD におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000046.html

JVNDB-2009-000045: レッツPHP! 製 PHP-I-BOARD におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000045.html

JVNDB-2009-000044: レッツPHP! 製 Tree BBS におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000044.html

JVNDB-2009-001324: Apple Mac OS X のヘルプビューアにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001324.html

JVNDB-2009-001323: Apple Mac OS X のヘルプビューアにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001323.html

JVNDB-2009-001322: Apple Mac OS X におけるスパースディスクイメージの処理に関する権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001322.html

JVNDB-2009-001321: Apple Mac OS X におけるスパースディスクイメージの処理に関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001321.html

JVNDB-2009-001320: CUPS における DNS リバインド攻撃を誘導される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001320.html

JVNDB-2009-001319: Cscope におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001319.html

JVNDB-2009-001318: Xpdf の JBIG2 デコーダにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001318.html

JVNDB-2009-001317: Apple Mac OS X の CoreGraphics における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001317.html

JVNDB-2009-001316: Apple Mac OS X の CoreGraphics における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001316.html

JVNDB-2009-001315: Apple Mac OS X の CFNetwork におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001315.html

JVNDB-2009-001314: Apple Mac OS X の CFNetwork における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001314.html

JVNDB-2009-001313: Apple Mac OS X の Apple Type Services (ATS) における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001313.html

JVNDB-2008-002309: Apache HTTP Server の mod_negotiation モジュールにおける任意の HTTP ヘッダを注入される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002309.html

JVNDB-2009-001312: Perl の DBD::Pg モジュール dequote_bytea 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001312.html

JVNDB-2009-001311: Perl の DBD::Pg モジュールにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001311.html

ウイルスバスター月額版 2009
プログラムバージョン17.00 ビルド1697 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1276

Linux Kernel release: 2.6.31-rc1
http://www.linux.org/news/2009/06/24/0006.html
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc1

DBD-drizzle 0.200 released
http://www.cpan.org/modules/by-module/DBD/DBD-drizzle-0.200.readme

pgDay San Jose Schedule up, Registration open
http://www.postgresql.org/about/news.1105




+ Solution 262408: Security Vulnerability in the Solaris IP(7P) Multicast Reception May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-262408-1
http://osvdb.org/show/osvdb/55299
http://secunia.com/advisories/35552/
http://securitytracker.com/alerts/2009/Jun/1022443.html
http://www.vupen.com/english/advisories/2009/1667
http://www.securityfocus.com/bid/35474

[ANNOUNCE] Apache POI 3.5 Beta 6 Released
http://poi.apache.org/changes.html

[ANNOUNCE] PostgreSQL Conference West 2009 Call for Papers
http://www.postgresqlconference/talksubmission

Is Apple 'open enough' to rule the next decade of mobile?
http://www.linux.org/news/2009/06/24/0005.html

SCO vs. Linux: a new start with unXis?
http://www.linux.org/news/2009/06/24/0004.html

Cisco launches Linux powered Wireless-N router
http://www.linux.org/news/2009/06/24/0003.html

Kaspersky Lab releases beta of new Linux antivirus
http://www.linux.org/news/2009/06/24/0002.html

The little Linux school house
http://www.linux.org/news/2009/06/24/0001.html

Commercial support for OpenSSL is now available
http://www.openssl.org/support/funding/contract.html

Cisco Security Advisory: Vulnerabilities in Cisco Video Surveillance Products
http://www.cisco.com/warp/public/707/cisco-sa-20090624-video.shtml

Cisco Security Advisory: Cisco Physical Access Gateway Denial of Service Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090624-gateway.shtml

米MSが無料ウイルス対策ソフトのベータ版を限定公開、日本は対象外
上限は7万5000ダウンロード、米国・イスラエル・中国・ブラジルが対象
http://itpro.nikkeibp.co.jp/article/NEWS/20090625/332554/?ST=security

Symantec,エンドポイント保護技術の監視・管理サービスを発表
http://itpro.nikkeibp.co.jp/article/NEWS/20090624/332547/?ST=security

Cisco Security Advisory: Cisco Physical Access Gateway Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00218.html

Cisco Security Advisory: Vulnerabilities in Cisco Video Surveillance Products
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00216.html

Trustwaves SpiderLabs Security Advisory TWSL2009-002
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00214.html

[ MDVSA-2009:139 ] libtorrent-rasterbar
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00213.html

CHASE - 2009 Lahoe Pakistan Call for Papers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00217.html

Nagios 3.1.2 Released
http://www.nagios.org/news/77-news-announcements/205-nagios-312-released

Samba 3.3.6 Security Release Available
http://news.samba.org/releases/3.3.6/

Samba 3.2.13 Security Release Available
http://news.samba.org/releases/3.2.13/

Samba 3.0.35 Security Release Available
http://news.samba.org/releases/3.0.35/

Sun Solaris IP Multicast Reception Denial of Service
http://secunia.com/advisories/35552/

Zen Cart Administration Security Bypass Vulnerability
http://secunia.com/advisories/35550/

Shockwave Player Arbitrary Code Execution Vulnerability
http://secunia.com/advisories/35544/

URD Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35540/

Samba Security Bypass and Format String Vulnerabilities
http://secunia.com/advisories/35539/

Movable Type Security Bypass and Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35534/

Cisco Video Surveillance Services Platform xvcrman Process Bug Lets Remote Users Reboot the Target System
http://securitytracker.com/alerts/2009/Jun/1022446.html

Cisco Video Surveillance Camera Discloses Arbitrary Files to Remote Authenticated Users
http://securitytracker.com/alerts/2009/Jun/1022445.html

Cisco Physical Access Gateway Unspecified Bug Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Jun/1022444.html

Solaris Memory Leak in IP Multicast Reception Lets Local Users Deny Service
http://securitytracker.com/alerts/2009/Jun/1022443.html

Samba smbd Access Control Bug Lets Remote Authenticated Users Bypass Certain Access Controls
http://securitytracker.com/alerts/2009/Jun/1022442.html

Samba smbclient Format String Bug May Let Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022441.html

Adobe Shockwave Unspecified Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022440.html

Mozilla Thunderbird Multipart/Alternative Processing Bug May Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022433.html

Movable Type Cross Site Scripting and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/1668

Sun Solaris IP Multicast Reception Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/1667

XEmacs Image Processing Multiple Integer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2009/1666

Adobe Shockwave Player 11 Remote Code Execution Vulnerability
http://www.vupen.com/english/advisories/2009/1665

Samba smbclient Format String and smbd Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/1664

DirectAdmin "CMD_REDIRECT" Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1663

BASE <= 1.2.4 (Auth Bypass) Insecure Cookie Handling Vulnerability http://www.milw0rm.com/exploits/9009

ウイルス検索エンジン VSAPI 8.950 (ビルド1094) Windows NTKD版公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1273

InterScan VirusWall スタンダードエディション 6.02 Windows版 Patch 2 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1271

【重要なお知らせ】ウイルス検索エンジンアップデートのお願い
http://www.trendmicro.co.jp/support/news.asp?id=1269

Adobe Shockwave Player Director File Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35469

Moodle 'Login As' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/33617

Moodle HotPot Module 'report.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/33878

chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/32799

Moodle Calendar Export Unspecified Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33612

Moodle Wiki Page Name Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/32714

Moodle Forum Unspecified Cross-Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/33615

Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/32402

Moodle Log Table HTML Injection Vulnerability
http://www.securityfocus.com/bid/33610

Smarty Template Engine 'Smarty_Compiler.class.php' Security Bypass Vulnerability
http://www.securityfocus.com/bid/31862

Smarty Template Engine 'function.math.php' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34918

Snoopy '_httpsrequest()' Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/31887

Moodle TeX Filter Remote File Disclosure Vulnerability
http://www.securityfocus.com/bid/34278

PHPMailer Remote Shell Command Execution Vulnerability
http://www.securityfocus.com/bid/24417

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Linux Kernel i915 Driver 'drivers/char/drm/i915_dma.c' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/31792

Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33113

Linux Kernel 'net/atm/proc.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32676

Linux Kernel 'pppol2tp_recvmsg()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/29747

Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35185

Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35281

Cyrus SASL 'sasl_encode64()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34961

Basic Analysis And Security Engine 'readRoleCookie()' Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35470

Rasterbar Software libtorrent Arbitrary File Overwrite Vulnerability
http://www.securityfocus.com/bid/35262

Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35282

MyBB 'birthdayprivacy' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35458

Mozilla Firefox/SeaMonkey 'file://' URI Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35391

Mozilla Firefox/Thunderbird/SeaMonkey 'file://' URI Security Bypass Vulnerability
http://www.securityfocus.com/bid/35386

Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulnerability
http://www.securityfocus.com/bid/35380

Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/35383

Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Construction Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35371

Mozilla Firefox/Thunderbird/SeaMonkey Multiple JavaScript Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35372

Mozilla Firefox/Thunderbird/SeaMonkey XUL Scripts Content-Policy Check Security Bypass Vulnerability
http://www.securityfocus.com/bid/35377

Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35373

Mozilla Firefox and SeaMonkey Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35388

Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35370

Mozilla Firefox 'NPObject' Access Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35360

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

Sun Solaris 'IP(7P)' Multicast Reception Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35474

Git Parameter Processing Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35338

GStreamer gst-plugins-good 'gstpngdec.c' PNG Output Buffer Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35172

ImageMagick TIFF File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35111

Office OCX WordViewer.OCX Word Viewer ActiveX Multiple Vulnerabilities
http://www.securityfocus.com/bid/23784

Samba Format String And Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/35472

Zen Cart 'admin/sqlpatch.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35468

Zen Cart 'record_company.php' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35467

PHPEcho CMS SQL Injection and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/35488

RT 'ShowConfigTab' Security Bypass Vulnerability
http://www.securityfocus.com/bid/35487

AN Guestbook 'flags.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/35486

PinME! Joomla! Component Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/35485

Tribiq CMS Multiple Local File Include and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/35484

Glossword 'index.php Local File Include Vulnerability
http://www.securityfocus.com/bid/35483

Cisco ASA Appliance HTML Rewriting Security Bypass Vulnerability
http://www.securityfocus.com/bid/35480

Cisco Video Surveillance Stream Manager Firmware Denial of Service Vulnerability
http://www.securityfocus.com/bid/35479

Cisco Video Surveillance 2500 Series IP Cameras Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35478

Cisco Physical Access Gateway Malformed Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35477

Cisco ASA Appliance WebVPN DOM Wrapper Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35476

Cisco Adaptive Security Appliance Web VPN FTP or CIFS Authentication Form Phishing Vulnerability
http://www.securityfocus.com/bid/35475

XEmacs Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35473

0 件のコメント:

コメントを投稿