2009年7月28日火曜日

28日 火曜日、赤口

JVNDB-2009-001819 Adobe Reader および Acrobat の JPX データ処理における複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001819.html

JVNDB-2009-001818 Adobe Reader における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001818.html

JVNDB-2009-001817 Adobe Reader の JBIG2 フィルタにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001817.html

JVNDB-2009-001816 Adobe Reader におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001816.html

JVNDB-2009-001815 Adobe Reader における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001815.html

JVNDB-2009-001814 Adobe Reader の JBIG2 フィルタにおけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001814.html

The latest snapshot for the stable Linux kernel tree is: 2.6.31-rc4-git1
http://git.kernel.org/?p=linux%2Fkernel%2Fgit%2Ftorvalds%2Flinux-2.6.git;a=summary

CommuniGate Pro Input Validation Flaw in WebUser Component Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2009/Jul/1022604.html

Mozilla Firefox Invalid Character URL Bug Lets Remote Users Spoof URLs
http://securitytracker.com/alerts/2009/Jul/1022603.html

Cisco Wireless LAN Controller Basic Authentication Processing Bug Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Jul/1022600.html

MPlayer and VLC Player Real Data Transport Remote Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35821

ISC DHCP 'dhclient' 'script_write_params()' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35668

MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/35609




+ RHSA-2009:1177-1: Moderate: python security update
http://rhn.redhat.com/errata/RHSA-2009-1177.html
+ RHSA-2009:1178-1: Moderate: python security update
http://rhn.redhat.com/errata/RHSA-2009-1178.html

+ ISC DHCP dhclient http://www.milw0rm.com/exploits/9265

+ Solution 264408: Solaris 10 Systems Using the hme(7D) Driver May Hang On Boot if the Install Image Contains Patch 140179-02
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264408-1

MySQL Workbench 5.2.2 alpha released
http://dev.mysql.com/downloads/workbench/5.2.html

Why aren't schools adopting open source?
http://www.linux.org/news/2009/07/27/0006.html

Edubuntu 9.04 Released
http://www.linux.org/news/2009/07/27/0005.html

Finding Linux Bugs Before they Become Exploits
http://www.linux.org/news/2009/07/27/0004.html

Timeline: 40 Years Of Unix
http://www.linux.org/news/2009/07/27/0003.html

Yes Linus, Microsoft hating is a disease. And it's a pandemic
http://www.linux.org/news/2009/07/27/0002.html

10 Ways Google Is Trying To Kill Microsoft
http://www.linux.org/news/2009/07/27/0001.html

Does Linux Have a 'Safe Mode'?
http://www.linux.org/news/2009/07/26/0002.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.cisco.com/warp/public/707/cisco-sa-20090727-wlc.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.cisco.com/warp/public/707/cisco-amb-20090727-wlc.shtml

cross site scripting the browser google "chrome"
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00201.html

NcFTPd <= 2.8.5 remote jail breakout
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00198.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00196.html

[DZC-2009-001] The Movie Player and VLC Media Player Real Data Transport parsing integer und
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00197.html

[ MDVSA-2009:159 ] mysql
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00195.html

Remote File Inclusion in aiocp
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00186.html

PHP filesystem attack vectors - Take Two
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00184.html

Cisco WLC 4402 Denial-of-Service vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00183.html

computer crime statistics
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00200.html

[Tool] sqlmap 0.7 released
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00192.html

DoS vulnerabilities in Internet Explorer
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00191.html

[SECURITY] [DSA 1841-1] New git-core packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00189.html

IXXO Cart! Standalone and Joomla Component SQL Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00188.html

rPSA-2009-0111-1 kernel
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00187.html

トレンドマイクロが企業向けウイルス製品を刷新,パターン配信を10KB未満に
http://itpro.nikkeibp.co.jp/article/NEWS/20090727/334516/?ST=security

JVN#36085487 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN36085487/index.html

JVN#19072922 EC-CUBE における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN19072922/index.html

JVN#81111541 EC-CUBE における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN81111541/index.html

JVN#99916563 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN99916563/index.html

JVN#26621646 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN26621646/index.html

RedHat : Moderate: python security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29886

RedHat : Moderate: python security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29887

RedHat : Moderate: python security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29888

SuSE : Mozilla Firefox 3.0.12
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29884

Independent Researcher : WLC 4402 Denial-of-Service vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29892

Independent Researcher : filesystem attack vectors - Take Two
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29893

Debian : New git-core packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29885

Independent Researcher : Standalone and Joomla Component SQL Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29890

Filemon and Regmon are dead, long life to Procmon!
http://isc.sans.org/diary.html?storyid=6868

New Hacker Challenge: Prison Break - Breaking, Entering & Decoding
http://isc.sans.org/diary.html?storyid=6865

RHSA-2009:1176-1: Moderate: python security update
http://rhn.redhat.com/errata/RHSA-2009-1176.html

RHEA-2008:0274-2: new package: para-virtualized drivers for fully-virtualized guests
http://rhn.redhat.com/errata/RHEA-2008-0274.html

RHBA-2009:1175-1: strace bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1175.html

Red Hat update for python
http://secunia.com/advisories/36014/

Red Hat update for python
http://secunia.com/advisories/36013/

Red Hat update for python
http://secunia.com/advisories/36011/

rPath update for kernel
http://secunia.com/advisories/36010/

nilfs-utils Privilege Escalation Vulnerability
http://secunia.com/advisories/36008/

Squid Multiple Denial of Service Vulnerabilities
http://secunia.com/advisories/36007/

SUSE update for MozillaFirefox
http://secunia.com/advisories/36005/

PG MatchMaking Script Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/36004/

AlmondSoft Products Multiple Vulnerabilities
http://secunia.com/advisories/36003/

Scripteen Free Image Hosting Script Insecure Cookie Handling
http://secunia.com/advisories/36002/

Mozilla Firefox URL Spoofing Security Issue
http://secunia.com/advisories/36001/

Flashden Guestbook "phpinfo.php" Information Disclosure
http://secunia.com/advisories/36000/

Almond Classifieds Pro Edition Multiple Vulnerabilities
http://secunia.com/advisories/35999/

Joomla Almond Classifieds Component SQL Injection and Cross-Site Scripting
http://secunia.com/advisories/35998/

SkaDate Cross-Site Scripting and Local File Inclusion
http://secunia.com/advisories/35997/

XZero Community Classifieds Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35996/

Hitachi Business Logic Container Unspecified Cross-Site Scripting
http://secunia.com/advisories/35994/

Debian update for git-core
http://secunia.com/advisories/35992/

KDE KHTML Numeric Character References Memory Corruption
http://secunia.com/advisories/35991/

TrackMania United/Nations Forever Multiple Vulnerabilities
http://secunia.com/advisories/35989/

Star Wars Battlefront II Player Handling Vulnerability
http://secunia.com/advisories/35988/

Scripteen Free Image Hosting Script "header.php" SQL Injection
http://secunia.com/advisories/35976/

CommuniGate Pro Script Insertion Vulnerability
http://secunia.com/advisories/35969/

SaphpLesson "cp_username" SQL Injection Vulnerability
http://secunia.com/advisories/35954/

PG Roommate Finder Solution "part" Cross-Site Scripting
http://secunia.com/advisories/35906/

Squid HTTP Data Processing Remote Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2013

Sun Solaris and OpenSolaris SASL Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2012

Hitachi Products Unspecified Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/2011

XZero Community Classifieds Two Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2009/2010

TrackMania Forever Remote Integer Overflow and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2009/2009

Star Wars Battlefront II Guests Handling Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2008

nilfs-utils mkfs.nilfs2 "disk_scan()" Local Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2009/2007

Mozilla Firefox URL Processing Address Bar Spoofing Vulnerability
http://www.vupen.com/english/advisories/2009/2006

Basilic "idAuthor" Processing Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2005

UIajaxIM for Joomla Data Processing Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/2004

Million Dollar Pixel Ads Platinum SQL Injection and Cross Site Scripting
http://www.vupen.com/english/advisories/2009/2003

NcFTPd <= 2.8.5 Remote Jail Breakout Vulnerability
http://www.milw0rm.com/exploits/9278

Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit (py)
http://www.milw0rm.com/exploits/9272

nilfs-utils Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35796

NOS getPlus Download Manager Insecure File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35740

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

SERWeb Multiple Remote and Local File Include Vulnerabilities
http://www.securityfocus.com/bid/26747

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

Akamai Download Manager ActiveX Control Redswoosh Download Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35778

Pango 'pango_glyph_string_set_size()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34870

WebKit Numeric Character References Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35607

Cyrus SASL 'sasl_encode64()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34961

Apple Safari Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35829

WordPress 'wp-comments-post.php' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35797

Git Parameter Processing Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35338

OSI Codes PHP Live! 'knowledge_searchm.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/27807

Ekiga GetHostAddress Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/25642

OpenH323 Opal SIP Protocol Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/25955

Joomla! UIajaxIM Component Arbitrary Script Injection Vulnerability
http://www.securityfocus.com/bid/35798

Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
http://www.securityfocus.com/bid/35780

PHPLive! 'message_box.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35791

Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
http://www.securityfocus.com/bid/35818

Cisco Wireless LAN Controller Unspecified Remote Security Vulnerability
http://www.securityfocus.com/bid/35819

Cisco Wireless LAN Controller SSH Connections Denial of Service Vulnerability
http://www.securityfocus.com/bid/35817

Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
http://www.securityfocus.com/bid/35805

Python 'Imageop' Module Argument Validation Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31932

Python 'expandtabs' Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/33187

Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/28749

Python Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/30491

Python Imageop Module 'imageop.crop()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31976

Python zlib Module Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/28715

Python ImageOP Module Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/25696

Python PyLocale_strxfrm Function Remote Information Leak Vulnerability
http://www.securityfocus.com/bid/23887

Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35185

Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34934

Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35281

Linux Kernel 'PER_CLEAR_ON_SETID' Incomplete Personality List Access Validation Weakness
http://www.securityfocus.com/bid/35647

Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34612

Mozilla Firefox and Thunderbird RDF File Handling Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35775

Mozilla Firefox 'XPCCrossOriginWrapper' Multiple Cross Domain Scripting Vulnerabilities
http://www.securityfocus.com/bid/35773

Mozilla Firefox/Thunderbird JavaScript Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35776

Mozilla Firefox/Thunderbird Double Frame Construction Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35770

Mozilla Firefox 'watch()' and ' __defineSetter__ ()' Functions Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35772

Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35767

Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35769

Mozilla Firefox 'setTimeout()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35766

Mozilla Firefox and Thunderbird Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35765

Mozilla Firefox Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35803

ISC DHCP 'dhclient' 'script_write_params()' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35668

MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/35609

Multiple Drupal Modules Date Wizard HTML Injection Vulnerability
http://www.securityfocus.com/bid/35790

Microsoft Visual Studio Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35804

Automatic Image Upload with Thumbnails for PunBB 'uploadimg.php' Arbitrary File Delete Vulnerability
http://www.securityfocus.com/bid/35825

Automatic Image Upload with Thumbnails 'uploadimg_view.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35823

NcFTPD Symbolic Link Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35822

MPlayer and VLC Player Real Data Transport Remote Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35821

CELEPAR Xoops Celepar Module Multiple SQL Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/35820

AlmondSoft Almond Classifieds SQL Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/35816

Almond Classifieds Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
http://www.securityfocus.com/bid/35815

PG Roommate Finder Solution 'part' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35814

SkaDate Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/35813

Squid Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35812

AIOCP 'cp_html2txt.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/35811

IXXO Cart! 'parent' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35810

TrackMania Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35807

0 件のコメント:

コメントを投稿