2009年7月3日金曜日

3日 金曜日、先負

Microsoft VM の問題により、システムが侵害される (816093) (MS03-011)
http://www.microsoft.com/japan/technet/security/bulletin/MS03-011.mspx

Microsoft VM の問題により、システムが侵害される (810030) (MS02-069)
http://www.microsoft.com/japan/technet/security/bulletin/MS02-069.mspx

Microsoft VM JDBC クラスの問題により、コードが実行される (329077) (MS02-052)
http://www.microsoft.com/japan/technet/security/bulletin/MS02-052.mspx

2002 年 3 月 4 日 VM 用の累積的な修正プログラム (MS02-013)
http://www.microsoft.com/japan/technet/security/bulletin/MS02-013.mspx

「VM のファイルの読み取り」 の脆弱性に対する対策 (MS00-081)
http://www.microsoft.com/japan/technet/security/bulletin/MS00-081.mspx

「Microsoft VM による ActiveX コンポーネントの制御」 の脆弱性に対する対策 (MS00-075)
http://www.microsoft.com/japan/technet/security/bulletin/MS00-075.mspx

「Java VM アプレット」 の脆弱性に対する対策 (MS00-059)
http://www.microsoft.com/japan/technet/security/bulletin/MS00-059.mspx

「VM ファイル参照 問題」 の脆弱性に対する対策 (MS00-011)
http://www.microsoft.com/japan/technet/security/bulletin/MS00-011.mspx

「仮想マシン ベリファイア」 の脆弱性に対する対策 (MS99-045)
http://www.microsoft.com/japan/technet/security/bulletin/MS99-045.mspx

「仮想マシン サンドボックス」 の脆弱性に対する対策 (MS99-031)
http://www.microsoft.com/japan/technet/security/bulletin/MS99-031.mspx

JVNDB-2009-001561: Cisco IOS の UDP パケットの処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001561.html

JVNDB-2009-001560: Cisco IOS の TCP パケットの処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001560.html

JVNDB-2009-001559: Cisco IOS の IP ソケットの処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001559.html

JVNDB-2009-001558: Cisco IOS の SSLVPN 機能 におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001558.html

JVNDB-2009-001557: Cisco IOS の SSLVPN 機能 におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001557.html

JVNDB-2009-001269: JBIG2 デコーダにおける SplashBitmap に関連する整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001269.html

JVNDB-2009-001268: JBIG2 デコーダにおける CairoOutputDev に関連する整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001268.html

JVNDB-2009-001267: JBIG2 MMR デコーダにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001267.html

JVNDB-2009-001266: JBIG2 MMR デコーダにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001266.html

JVNDB-2009-001265: JBIG2 デコーダにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001265.html

JVNDB-2009-001264: JBIG2 デコーダにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001264.html

JVNDB-2009-001263: JBIG2 デコーダにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001263.html

JVNDB-2009-001262: JBIG2 デコーダにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001262.html

JVNDB-2009-001261: JBIG2 デコーダにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001261.html

JVNDB-2009-001260: Xpdf および CUPS の JBIG2 デコーダーにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001260.html

JVNDB-2009-001259: Xpdf および CUPS の JBIG2 デコーダーにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001259.html

JVNDB-2009-001258: Xpdf および CUPS の JBIG2 デコーダーにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001258.html

JVNDB-2008-002148: Java Runtime Environment (JRE) における RSA 公開鍵に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002148.html

コンピュータウイルス・不正アクセスの届出状況[6月分および上半期]について
http://www.ipa.go.jp/security/txt/2009/07outline.html

誇大広告のスパム送信者に罰金370万ドル
http://itpro.nikkeibp.co.jp/article/NEWS/20090703/333178/?ST=security

ボットネット「Waledac」が米独立記念日に向けスパム準備中
http://itpro.nikkeibp.co.jp/article/Research/20090703/333148/?ST=security

BOM: 複数のPing監視を設定している環境で、存在しない監視対象へのPing監視に成功することがある
http://www.say-tech.co.jp/support/bom-for-windows/pingping/index.shtml

BOM: プロセス監視で、カウンターオブジェクトの出力値を正しく取得できないことがある
http://www.say-tech.co.jp/support/bom-for-windows/post-42/index.shtml

BOM: 監視項目の削除ができず、同一IDの項目が2つできる
http://www.say-tech.co.jp/support/faq/id2/index.shtml

BOM5.0の監視で使用するアカウントについて
http://www.say-tech.co.jp/support/bom-for-windows/bom50-2/index.shtml




+ Solution 262908: Security Vulnerability in the SNMP daemon (snmpd(1M)) May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-262908-1
http://secunia.com/advisories/35679/

+ RHSA-2009:1140-2: Moderate: ruby security update
http://rhn.redhat.com/errata/RHSA-2009-1140.html

+ Linux Kernel 'ptrace_start()' And 'do_coredump()' Deadlock Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35559

+ Net-SNMP GETBULK Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32020/info

+ Solution 256728: Multiple Security Vulnerabilities in the Solaris Kerberos 'Mech' Libraries May Lead To Execution of Arbitrary Code, Unauthorized Access to Data or a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256728-1

+ Linux Kernel 2.6.27.26, 2.6.29.6, 2.6.30.1 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.26
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.6
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.1

Apache MPT 1.0 released
http://james.apache.org/mpt/1.0/release-notes.html

Linux devs strike back at Microsoft patent claims
http://www.linux.org/news/2009/07/02/0002.html

Legalized drugs, now open source. Those crazy Dutch!
http://www.linux.org/news/2009/07/02/0001.html

TweetMeme Migrates to Sun's MySQL Enterprise Database Subscription Service
http://uk.sun.com/sunnews/press/2009/2009-06-30.jsp

定期サーバメンテナンスのお知らせ(2009年7月17日)
http://www.trendmicro.co.jp/support/news.asp?id=1277

CERT Resiliency Management Model
http://www.cert.org/resiliency/rmm.html

USN-793-1: Linux kernel vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29718

RHBA-2009:1137-1: bind bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1137.html

RHSA-2009:1138-1: Important: openswan security update
http://rhn.redhat.com/errata/RHSA-2009-1138.html

RHSA-2009:1139-1: Moderate: pidgin security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-1139.html

Multiple Flaws in Axesstel MV 410R
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00016.html

[ GLSA 200907-02 ] ModSecurity: Denial of Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00015.html

[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00013.html

[USN-795-1] Nagios vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00014.html

[USN-794-1] Perl vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00012.html

[ISecAuditors Security Advisories] Joomla! http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00011.html

[oCERT-2009-009] CamlImages integer overflows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00010.html

eAccelerator encoder files backup Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00009.html

Sourcefire 3D Sensor and DC, privilege escalation vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00008.html

[security bulletin] HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00007.html

[security bulletin] HPSBUX02440 SSRT090106 rev.1 - HP-UX Running NFS/ONCplus, Local Denial of Service (DoS)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00006.html

HP-UX NFS/ONCplus Unspecified Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/1755

Drupal Advanced Forum Module Cross-Site Scripting
http://secunia.com/advisories/35682/

Drupal Multiple Vulnerabilities
http://secunia.com/advisories/35681/

Sun Solaris SNMP Daemon Denial of Service Vulnerability
http://secunia.com/advisories/35679/

Drupal Advanced Forum Module Multiple Vulnerabilities
http://secunia.com/advisories/35678/

Fedora update for xorg-x11-xfs
http://secunia.com/advisories/35674/

AudioPLUS Playlist Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/35673/

ARD-9808 DVR Card Software Web Server Two Vulnerabilities
http://secunia.com/advisories/35671/

CMS Chaynik "id" Local File Disclosure Vulnerability
http://secunia.com/advisories/35669/

Green Dam System Time Modification Security Issue
http://secunia.com/advisories/35664/

PEamp Playlist Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/35663/

Drupal URL Information Disclosure Security Issue
http://secunia.com/advisories/35657/

Ubuntu update for linux and linux-source-2.6.15
http://secunia.com/advisories/35656/

SUSE update for acroread
http://secunia.com/advisories/35655/

HP-UX NFS/ONCplus Denial of Service Vulnerability
http://secunia.com/advisories/35644/

wxWidgets "wxImage::Create()" Integer Overflow Vulnerability
http://secunia.com/advisories/35351/

Oracle 10g SYS.LT.COMPRESSWORKSPACETREE SQL Injection Exploit
http://www.milw0rm.com/exploits/9072

Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35464

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34240

ModSecurity Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34096

libwmf WMF Image File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34792

Zoph Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/30116

'Compress::Raw::Zlib' Perl Module Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35307

APOP Protocol Insecure MD5 Hash Weakness
http://www.securityfocus.com/bid/23257

Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vulnerability
http://www.securityfocus.com/bid/33769

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

Radware AppWall Source Code Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35551

Adobe Reader and Acrobat TrueType Font Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35296

Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35295

Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35300

Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35303

Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35289

Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35282

Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35293

Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35301

Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35299

Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow Vulnerability
http://www.securityfocus.com/bid/35302

Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35291

Adobe Reader and Acrobat FlateDecode Filter Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35294

Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35298

Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35544

Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/35530

Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35274

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

VLC Media Player 'smb://' URI Handling Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35500

Net-SNMP GETBULK Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32020

X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/24888

Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34654

Linux Kernel 'inet6_hashtables.c' NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/34602

Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34405

Linux Kernel CIFS Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34453

Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34934

Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34612

Linux Kernel '/proc/iomem' Sparc64 Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35415

Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35185

Linux Kernel 'drivers/char/agp/generic.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34673

Linux Kernel 'kill_something_info()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34558

Linux Kernel 'NFS filename' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34390

Linux Kernel 'splice(2)' Double Lock Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35143

Linux Kernel 'EFER_LME' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34331

Linux Kernel nfsd 'CAP_MKNOD' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34205

Axesstel MV 410R Multiple Remote Vulnerabilites and Weakness
http://www.securityfocus.com/bid/35563

Opial 'albumdetail.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35562

ConPresso CMS 'detail.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35561

Opial 'admin/index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35560

Linux Kernel 'ptrace_start()' And 'do_coredump()' Deadlock Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35559

CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35556

Apple Safari 'reload()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35555

Sourcefire 3D Sensor and Defense Center 'user.cgi' Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/35553

wxWidgets 'wxImage::Create()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35552

0 件のコメント:

コメントを投稿