2009年7月9日木曜日

9日 木曜日、先負

JVNDB-2009-001735 CUPS の directory-services 機能におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001735.html

JVNDB-2009-001734 CUPS の pdftops フィルタにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001734.html

JVNDB-2009-001733 CUPS の ippReadIO 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001733.html

JVNDB-2009-001732 IBM WebSphere Application Server (WAS) の Administrative Console コンポーネントにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001732.html

JVNDB-2009-001731 IBM WebSphere Application Server (WAS) の System Management/Repository コンポーネントにおける wsadmin のセキュリティ問題に関連した脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001731.html

JVNDB-2009-001730 IBM WebSphere Application Server (WAS) の Administrative Console コンポーネントにおける WAS セッションの内容を読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001730.html

JVNDB-2009-001729 IBM WebSphere Application Server (WAS) の セキュリティコンポーネントにおける標準でない http メソッドを許可する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001729.html

Windowsの脆弱性を突くゼロデイ攻撃、日本のユーザーからも報告
国別では中国からの報告が最多、「1日で180種類を超える新種ウイルス」
http://itpro.nikkeibp.co.jp/article/NEWS/20090709/333519/?ST=security

韓国と米国のWebサイトに大規模なDDoS攻撃,FTCなどがアクセス不能に
http://itpro.nikkeibp.co.jp/article/NEWS/20090709/333470/?ST=security

JVNTA09-187A Microsoft Video ActiveX コントロールにおけるバッファオーバーフローの脆弱性
http://jvn.jp/cert/JVNTA09-187A/index.html

JVN#63832775 Apache Tomcat における情報漏えいの脆弱性
http://jvn.jp/jp/JVN63832775/index.html

JVN#80057925 Apache HTTP Server の mod_imap および mod_imagemap におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN80057925/index.html

RFI: DDoS Against Government and Civilian Web Sites
http://isc.sans.org/diary.html?storyid=6748

eBay Enhanced Picture Uploader ActiveX Code Execution Vulnerability
http://www.vupen.com/english/advisories/2009/1828

Apple Safari WebKit Memory Corruption and Cross Site Scripting Issues
http://www.vupen.com/english/advisories/2009/1827

Adobe ColdFusion FCKeditor File Upload and Security Bypass Issues
http://www.vupen.com/english/advisories/2009/1826

Zope.html FCKeditor File Upload and Information Disclosure Issues
http://www.vupen.com/english/advisories/2009/1825

IBM WebSphere Application Server JAX-RPC WS-Security Vulnerability
http://www.vupen.com/english/advisories/2009/1824




+ WebSphere MQ V6.0 Fix Pack 6.0.2.7
http://www-01.ibm.com/support/docview.wss?rs=171&uid=swg24022718

[ANNOUNCEMENT] Apache James MPT 0.1 Released
http://james.apache.org/mpt/0.1/release-notes.html

[ANNOUNCE] Apache Click 2.1.0-RC1-incubating released
http://incubator.apache.org/click/

[ANNOUNCE] Apache ZooKeeper 3.2.0
http://hadoop.apache.org/zookeeper/releases.html

Richard Stallman Fights Latest Linux Threat
http://www.linux.org/news/2009/07/08/0005.html

Virtualization: Pushing Linux into Small Business
http://www.linux.org/news/2009/07/08/0004.html

Linux patch sidesteps Microsoft's TomTom patent
http://www.linux.org/news/2009/07/08/0003.html

Linux Distros Upbeat, Wary of Google's New Chrome OS
http://www.linux.org/news/2009/07/08/0002.html

Google's Chrome OS Threatens Linux, Is Good For Microsoft
http://www.linux.org/news/2009/07/08/0001.html

Hospitals respond well to Linux treatment
http://www.linux.org/news/2009/07/07/0003.html

Enhanced VMotion Compatibility (EVC) processor support
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1003212&sliceId=1&docTypeID=DT_KB_1_1

MDVSA-2009:124-1: apache
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29758

DSA 1828-1: New ocsinventory-agent packages fix arbitrary code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29760

CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00043.html

[ MDVSA-2009:124-1 ] apache
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00042.html

ネットユーザーの9割が知人からの情報を信頼、企業サイトの信頼度も高い
http://itpro.nikkeibp.co.jp/article/Research/20090708/333461/?ST=security

Safari 4.0.2 update published
http://isc.sans.org/diary.html?storyid=6754
http://www.apple.com/downloads/macosx/apple/application_updates/safari.html

Dokeos FCKeditor "CurrentFolder" Information Disclosure and Arbitrary File Upload
http://secunia.com/advisories/35765/

Siteframe "phpinfo.php" Information Disclosure
http://secunia.com/advisories/35761/

ClanSphere FCKeditor "CurrentFolder" Information Disclosure and Arbitrary File Upload
http://secunia.com/advisories/35731/

NetBSD update for openssl
http://secunia.com/advisories/35729/

Tausch Ticket Script Two SQL Injection Vulnerabilities
http://secunia.com/advisories/35725/

Jobbr "emp_id" SQL Injection Vulnerability
http://secunia.com/advisories/35722/

Nokia N96 RealMedia Processing Memory Corruption Vulnerability
http://secunia.com/advisories/35719/

Ebay Clone SQL Injection and Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35713/

NEC WebOTX Products "RemoteFilterValve" Security Bypass Security Issue
http://secunia.com/advisories/35684/

Tausch Ticket Script Multiple Parameter SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2009/1823

Siteframe Remote SQL Injection and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/1822

Rapidsendit Clone Cookie Handling Authentication Bypass Vulnerability
http://www.vupen.com/english/advisories/2009/1821

WebAsyst Shop-Script SQL Injection and Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1820

MyPHPDating "page_id" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/1819

NEC WebOTX "RemoteFilterValve" Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2009/1818

NullLogic Groupware Buffer Overflow and SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2009/1817

TekRADIUS SQL Injection and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/1816

Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues
http://www.vupen.com/english/advisories/2009/1815

Citrix XenCenterWeb Multiple Command and SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2009/1814

ClanSphere FCKeditor File Upload and Information Disclosure Issues
http://www.vupen.com/english/advisories/2009/1813

Ocsinventory-Agent Perl Module Insecure Search Path Vulnerability
http://www.vupen.com/english/advisories/2009/1809

Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/35530

Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulnerability
http://www.securityfocus.com/bid/35380

Nullsoft Winamp 'gen_ff.dll' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35052

Campsite Multiple Remote Input Validation Vulnerabilities
http://www.securityfocus.com/bid/35456

LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/35451

MyPHPDating 'page.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35603

phpDatingClub 'search.php' Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35454

Citrix XenCenterWeb Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/35592

Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
http://www.securityfocus.com/bid/31698

Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/30560

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

Linux Kernel 'splice(2)' Double Lock Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35143

Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34934

Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35185

Sun Java Web Console Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35513

phpMyAdmin SQL bookmark HTML Injection Vulnerability
http://www.securityfocus.com/bid/35543

cPanel 'lastvisit.html' Arbitrary File Disclosure Vulnerability
http://www.securityfocus.com/bid/35518

Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35281

Sun Java System Access Manager Cross-Domain Controller (CDC) Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35527

NetGear DG632 Router Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35376

PHP Address Book Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35511

Adobe Shockwave Player Director File Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35469

Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34612

Linux Kernel 'kvm_arch_vcpu_ioctl_set_sregs()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35529

WebKit 'parent/top' Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/35441

RSMonials Joomla! Component Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/34684

F5 Networks FirePass SSL VPN 'password' Field Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35312

XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35574

FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/31812

IPplan 'grp' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35037

ClanSphere Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35576

Cisco VPN 3000 Concentrator FTP Arbitrary File Access Vulnerability
http://www.securityfocus.com/bid/19680

Eggdrop 'ctcpbuf' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34985

Horde 'Passwd' Module Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35573

Hitachi Multiple Products Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/35589

Mozilla Firefox/Thunderbird/SeaMonkey Multiple JavaScript Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35372

Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Construction Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35371

Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/35383

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35373

Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35370

Mozilla Firefox/Thunderbird/SeaMonkey XUL Scripts Content-Policy Check Security Bypass Vulnerability
http://www.securityfocus.com/bid/35377

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35417

'Compress::Raw::Zlib' Perl Module Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35307

Irssi 'WALLOPS' Message Off By One Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35399

LibTIFF 'tif_lzw.c' Remote Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/30832

strongSwan IKE Request Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35178

CUPS 'cups/ipp.c' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35169

ImageMagick TIFF File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35111

CUPS PDF File Multiple Heap Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35195

Pango 'pango_glyph_string_set_size()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34870

PHP 5.2.8 and Prior Versions Multiple Vulnerabilities
http://www.securityfocus.com/bid/33927

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

Quagga Autonomous System Number Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34817

IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34765

DBD::Pg 'pg_getline()' and 'getline()' Heap Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34755

DBD::Pg BYTEA Values Memory Leak Denial of Service Vulnerability
http://www.securityfocus.com/bid/34757

libmodplug 's3m' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30801

Drupal Cross-Site Scripting, Code Injection and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35548

OptiPNG GIF Image Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/33873

Net-SNMP 'snmpUDPDomain.c' Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33755

Poppler Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/33749

Zoph Unspecified Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35567

Axesstel MV 410R Multiple Remote Vulnerabilites and Weakness
http://www.securityfocus.com/bid/35563

Opial 'albumdetail.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35562

Symbian S60 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35590

SubmitterScript and PHP Dir Submit Admin Login SQL Injection Vulnerability
http://www.securityfocus.com/bid/34970

Acajoom Component for Mambo/Joomla! Backdoor Vulnerability
http://www.securityfocus.com/bid/35459

RETIRED: PHP Dir Submit Admin Login SQL Injection Vulnerability
http://www.securityfocus.com/bid/35003

ConPresso CMS 'detail.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35561

FreeBSD 'mount(2)' and 'nmount(2)' Multiple Stack Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/31002

ModSecurity Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34096

libwmf WMF Image File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34792

Zoph Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/30116

Opial 'admin/index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35560

CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35556

Radware AppWall Source Code Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35551

wxWidgets 'wxImage::Create()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35552

OpenSSL DTLS Packets Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35001

OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35174

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35138

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

OpenSSL 'zlib' Compression Memory Leak Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/31692

WebKit Numeric Character References Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35607

NullLogic Groupware Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/35606

ClanSphere 'text' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35605

Bugzilla Bug Status Modification Security Bypass Vulnerability
http://www.securityfocus.com/bid/35604

Drupal Nodequeue Module Node Title Security Bypass Vulnerability
http://www.securityfocus.com/bid/35602

Siteframe 'phpinfo.php' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35598

Siteframe 'document.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/35597

Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
http://www.securityfocus.com/bid/35595

WordPress 'wp-admin/admin.php' Module Configuration Security Bypass Vulnerability
http://www.securityfocus.com/bid/35584

WordPress Multiple Existing/Non-Existing Username Enumeration Weaknesses
http://www.securityfocus.com/bid/35581

0 件のコメント:

コメントを投稿