2009年8月12日水曜日

12日 水曜日、先負

JVNDB-2009-001874 OpenSSL の dtls1_retrieve_buffered_fragment 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001874.html

JVNDB-2009-001873 OpenSSL の dtls1_process_out_of_seq_message 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001873.html

JVNDB-2009-001872 OpenSSL の dtls1_buffer_record 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001872.html

JVNDB-2009-001871 Cisco Adaptive Security Appliances (ASA) デバイスの WebVPN における WebVPN 証明書を送信させられやすくなる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001871.html

JVNDB-2009-001870 Cisco Adaptive Security Appliances (ASA) デバイスの WebVPN におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001870.html

JVNDB-2009-001869 Cisco Adaptive Security Appliances (ASA) デバイスの csco_wrap_js 関数におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001869.html

JVNDB-2009-001563 Microsoft DirectX の DirectShow における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001563.html

Penguin Computing Launches First Complete High Performance Computing (HPC) Solution in the Cloud
http://www.linux.org/news/2009/08/11/0010.html

Trend Micro InterScan WebManager Lite サポート開始のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1279

Microsoft Office Web コンポーネント の脆弱性(MS09-043)について
http://www.ipa.go.jp/security/ciadr/vul/20090812-ms09-043.html

Microsoft ATL の脆弱性(MS09-037)について
http://www.ipa.go.jp/security/ciadr/vul/20090812-ms09-037.html

Microsoft Video ActiveX コントロール の脆弱性(MS09-032)について
http://www.ipa.go.jp/security/ciadr/vul/20090707-ms-activex.html

2009年8月 Microsoft セキュリティ情報 (緊急 5件含) に関する注意喚起
http://www.jpcert.or.jp/at/2009/at090017.txt

JPCERT/CC WEEKLY REPORT 2009-08-12
http://www.jpcert.or.jp/wr/2009/wr093101.html

JVNTA09-223A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-223A/index.html

Apple Safari Unknown Plug-in Type Bug Lets Remote Users Obtain Potentially Sensitive Information
http://securitytracker.com/alerts/2009/Aug/1022720.html

Apple Safari IDN and Unicode Support Lets Remote Users Spoof URLs
http://securitytracker.com/alerts/2009/Aug/1022719.html

Apple Safari Top Sites View Can Be Modified By Remote Users
http://securitytracker.com/alerts/2009/Aug/1022718.html

Apple Safari Buffer Overflows Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022717.html






+ HPSBUX02437 SSRT090038 rev.2 - HP-UX Running XNTP, Remote Execution of Arbitrary Code
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01763606-2

+ Linux Kernel "mm_for_maps()" Information Disclosure
http://secunia.com/advisories/36265/
http://www.securityfocus.com/bid/36019

+ Microsoft Windows Embedded OpenType Font Engine Unspecified Denial of Service Vulnerability
http://www.securityfocus.com/bid/36029

+ マイクロソフト セキュリティ情報 2009 年 8 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms09-aug.mspx

+ MS09-037 - 緊急: Microsoft ATL (Active Template Library) の脆弱性により、リモートでコードが実行される (973908)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-037.mspx

+ MS09-038 - 緊急: Windows Media ファイル処理における脆弱性により、リモートでコードが実行される (971557)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-038.mspx
http://www.securityfocus.com/bid/35967

+ MS09-039 - 緊急: WINS の脆弱性により、リモートでコードが実行される (969883)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-039.mspx

+ MS09-040 - 重要: メッセージ キューの脆弱性により、特権が昇格される (971032)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-040.mspx
http://www.securityfocus.com/bid/35969

+ MS09-041 - 重要: ワークステーション サービスの脆弱性により、特権が昇格される (971657)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-041.mspx

+ MS09-042 - 重要: Telnet の脆弱性により、リモートでコードが実行される (960859)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-042.mspx

+ MS09-043 - 緊急: Microsoft Office Web コンポーネントの脆弱性により、リモートでコードが実行される (957638)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-043.mspx
http://www.securityfocus.com/bid/35990
http://www.securityfocus.com/bid/35642
http://www.securityfocus.com/bid/35992
http://www.securityfocus.com/bid/35991
+ MS09-044 - 緊急: リモート デスクトップ接続の脆弱性により、リモートでコードが実行される (970927)
http://www.microsoft.com/japan/technet/security/bulletin/ms09-044.mspx

[ANNOUNCE] Apache Jackrabbit 1.6.0 released
http://jackrabbit.apache.org/downloads.html

[ANN] Maven Repository Plugin 2.2 Released
http://maven.apache.org/plugins/maven-repository-plugin/

[ANN] Apache Maven 2.2.1 Released
http://maven.apache.org/

Solution 265668: SUN ALERT WEEKLY SUMMARY REPORT - Week of 02-Aug-2009 to 08-Aug-2009
http://sunsolve.sun.com/search/document.do?assetkey=1-66-265668-1

HPSBTU02454 SSRT080172 rev.1 - HP Internet Express for Tru64 UNIX Running Samba, Remote Information Disclosure
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01839839-1

Obama, open source & healthcare
http://www.linux.org/news/2009/08/11/0009.html

The nitty gritty
http://www.linux.org/news/2009/08/11/0008.html

New open source LiMo phones introduced
http://www.linux.org/news/2009/08/11/0007.html

Arch Linux 2009.08 Released
http://www.linux.org/news/2009/08/11/0006.html

SAM Linux 2009, the Last Release Based on PCLinuxOS
http://www.linux.org/news/2009/08/11/0005.html

When choice is bad: The OpenOffice ribbon
http://www.linux.org/news/2009/08/11/0004.html

Poll: Which area of Linux could use the most improvement?
http://www.linux.org/news/2009/08/11/0003.html

Suse Studio Review - DIY Linux
http://www.linux.org/news/2009/08/11/0002.html

Microsoft vs. Linux: If You Can't Beat 'Em, Join 'Em?
http://www.linux.org/news/2009/08/11/0001.html

Joyent Launches Virtual Appliance for MySQL -- Sets New Speed Benchmark for Database in the Cloud
http://www.mysql.com/news-and-events/generate-article.php?id=1625

Microsoft Security Advisory (973882): Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/973882.mspx

Microsoft Security Advisory (973811): Extended Protection for Authentication
http://www.microsoft.com/technet/security/advisory/973811.mspx

Microsoft Security Advisory (973472): Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/973472.mspx

Asterisk : Remote Crash Vulnerability in SIP channel driver
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30077

laurent gaffie : WordPress <= 2.8.3 Remote admin reset password http://www.criticalwatch.com/support/security-advisories.aspx?AID=30075

laurent gaffie : WordPress <= 2.8.3 Remote admin reset password http://www.criticalwatch.com/support/security-advisories.aspx?AID=30076

Microsoft : Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30079

Microsoft : Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30080

Microsoft : Vulnerabilities in WINS Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30081

Microsoft : Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30082

Microsoft : Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30083

Microsoft : Vulnerability in Workstation Service Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30084

Microsoft : Vulnerability in Message Queuing Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30085

Microsoft : Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30086

Microsoft : Vulnerability in Telnet Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30087

SuSE : security-announce SUSE Security Summary Report
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30068

Ubuntu Security Notice : openjdk-6 vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30067

[security bulletin] HPSBTU02454 SSRT080172 rev.1 - HP Internet Express for Tru64 UNIX Running Samba, Remote Information Disclosure
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00092.html

ZDI-09-057: Microsoft Remote Desktop Client Arbitrary Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00088.html

ZDI-09-056: Microsoft Office OWC10.Spreadsheet ActiveX BorderAround() Heap Corruption Vulner
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00091.html

ZDI-09-055: Microsoft Office OWC10 ActiveX Control Loading and Unloading Heap Corruption Vul
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00087.html

ZDI-09-054: Microsoft Office OWC10.Spreadsheet ActiveX msDataSourceObject() Heap Corruption
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00089.html

ZDI-09-053: Microsoft Windows WINS Service Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00090.html

US-CERT Technical Cyber Security Alert TA09-223A -- Microsoft Updates for Multiple V
http://www.derkeiler.com/Mailing-Lists/Cert/2009-08/msg00001.html

[USN-815-1] libxml2 vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00086.html

Sql injection in OCS Inventory NG Server 1.2.1
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00085.html

TPTI-09-06: Microsoft Windows Workstation Service NetrGetJoinInformation Heap Corruption Vul
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00084.html

IE7 Script
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00083.html

AST-2009-005: Remote Crash Vulnerability in SIP channel driver
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00082.html

[security bulletin] HPSBUX02450 SSRT090141 rev1 - HP-UX ttrace(2), Local Denial of Service (DoS)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00081.html

[USN-814-1] openjdk-6 vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00080.html

DNSキャッシュポイズニング対策
http://www.ipa.go.jp/security/vuln/DNS_security.html

Wordpress unauthenticated administrator password reset
http://isc.sans.org/diary.html?storyid=6934

Microsoft August 2009 Black Tuesday Overview
http://isc.sans.org/diary.html?storyid=6937

Safari 4.0.3 released
http://isc.sans.org/diary.html?storyid=6943

Microsoft Telnet NTLM Credential Reflection Flaw Lets Remote Users Gain Access
http://securitytracker.com/alerts/2009/Aug/1022716.html

Microsoft ASP.NET Request Scheduling Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022715.html

Windows Message Queuing Service (MSMQ) NULL Pointer Flaw Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Aug/1022714.html

Windows Workstation Service Double Free Memory Error Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Aug/1022713.html

Microsoft Active Template Library (ATL) Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022712.html

Windows Media File Processing Flaw in Handling AVI Files Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022711.html

Microsoft Windows Internet Name Service (WINS) Buffer Overflows Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022710.html

Windows Remote Desktop Connection Heap Overflows Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022709.html

Microsoft Office Web Components Buffer Overflows in ActiveX Control Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022708.html

WordPress Input Validation Bug Lets Remote Users Reset the Administrative Password
http://securitytracker.com/alerts/2009/Aug/1022707.html

HP-UX Flaw in ttrace(2) Lets Local Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022706.html

Asterisk Bug in Processing SIP Packets Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022705.html

EMC Replication Manager Client 'irccd.exe' Process Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022704.html

SUSE Update for Multiple Packages
http://secunia.com/advisories/36268/

GnuTLS X.509 CN and SAN Fields NUL Character Spoofing Vulnerability
http://secunia.com/advisories/36266/

Linux Kernel "mm_for_maps()" Information Disclosure
http://secunia.com/advisories/36265/

Red Hat update for libxml and libxml2
http://secunia.com/advisories/36264/

Fedora update for libvorbis
http://secunia.com/advisories/36263/

Fedora update for subversion
http://secunia.com/advisories/36262/

HP-UX "ttrace()" Local Denial of Service
http://secunia.com/advisories/36261/

Debian update for imagemagick
http://secunia.com/advisories/36260/

Ubuntu update for openjdk-6
http://secunia.com/advisories/36259/

Red Hat update for subversion
http://secunia.com/advisories/36257/

Red Hat update for apr and apr-util
http://secunia.com/advisories/36256/

Kayako SupportSuite Ticket Subject Script Insertion
http://secunia.com/advisories/36253/

Kunena "func" SQL Injection Vulnerability
http://secunia.com/advisories/36245/

libvorbis OGG Processing Multiple Vulnerabilities
http://secunia.com/advisories/36230/

Microsoft Remote Desktop Connection Two Vulnerabilities
http://secunia.com/advisories/36229/

Asterisk SIP Channel Driver Denial of Service
http://secunia.com/advisories/36227/

Microsoft Windows Telnet NTLM Credential Reflection Vulnerability
http://secunia.com/advisories/36222/

Microsoft Windows Workstation Service Memory Corruption
http://secunia.com/advisories/36220/

Alwasel "id" SQL Injection Vulnerabilities
http://secunia.com/advisories/36219/

Spiceworks "query" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/36216/

Microsoft Windows Message Queuing Service Privilege Escalation
http://secunia.com/advisories/36214/

Microsoft Windows WINS Service Two Vulnerabilities
http://secunia.com/advisories/36213/

Debian update for libxml2
http://secunia.com/advisories/36211/

libxml2 DTD Parsing Denial of Service Vulnerabilities
http://secunia.com/advisories/36207/

Microsoft Windows AVI Media File Parsing Vulnerabilities
http://secunia.com/advisories/36206/

Spiceworks Denial of Service and Cross-Site Request Forgery
http://secunia.com/advisories/36195/

Microsoft Windows Various Components ATL Vulnerabilities
http://secunia.com/advisories/36187/

Red Hat update for httpd
http://secunia.com/advisories/36186/

Python XML Processing Denial of Service Vulnerabilities
http://secunia.com/advisories/36174/

Microsoft .NET Framework Denial of Service Vulnerability
http://secunia.com/advisories/36127/

MAXcms Multiple Vulnerabilities
http://secunia.com/advisories/36105/

Microsoft Windows RDP Code Execution Vulnerabilities (MS09-044)
http://www.vupen.com/english/advisories/2009/2238

Microsoft Windows Telnet Credential Reflection Vulnerability (MS09-042)
http://www.vupen.com/english/advisories/2009/2237

Microsoft Workstation Service Queuing Privilege Escalation (MS09-041)
http://www.vupen.com/english/advisories/2009/2236

Microsoft Windows Message Queuing Privilege Escalation (MS09-040)
http://www.vupen.com/english/advisories/2009/2235

Microsoft Windows WINS Code Execution Vulnerabilities (MS09-039)
http://www.vupen.com/english/advisories/2009/2234

Microsoft Windows Media File Handling Code Execution (MS09-038)
http://www.vupen.com/english/advisories/2009/2233

Microsoft Active Template Library Code Execution Issues (MS09-037)
http://www.vupen.com/english/advisories/2009/2232

Microsoft ASP.NET Remote Denial of Service Vulnerability (MS09-036)
http://www.vupen.com/english/advisories/2009/2231

HP-UX "ttrace()" System Call Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2230

Asterisk SIP Channel Driver Remote Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2229

Libvorbis OGG Processing Memory Corruption and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2009/2223

Libxml2 XML Data Processing Multiple Memory Corruption Vulnerabilities
http://www.vupen.com/english/advisories/2009/2220

Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH) #2
http://www.milw0rm.com/exploits/9418

Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)
http://www.milw0rm.com/exploits/9412

Microsoft Internet Explorer Memory Corruption Vulnerability
http://www.securiteam.com/windowsntfocus/5XP0B0AS0G.html

CS-Cart SQL Injection Vulnerability
http://www.securiteam.com/unixfocus/5AP0E0AS0K.html

SlideShowPro Director File Disclosure Vulnerability
http://www.securiteam.com/securitynews/5ZP0D0AS0A.html

Sun Java Pack200 Decoding Overflow Vulnerability
http://www.securiteam.com/securitynews/5YP0C0AS0Q.html

Sun OpenSSO Enterprise XML Document Processing Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35977

IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
http://www.securityfocus.com/bid/35934

Sun Java SE Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35922

libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32331

libxml2 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36010

libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/32326

Microsoft Windows Malformed AVI File Parsing Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35970

WordPress 'wp-login.php' Admin Password Reset Security Bypass Vulnerability
http://www.securityfocus.com/bid/36014

Microsoft Windows Malformed AVI File Header Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35967

PulseAudio setuid Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35721

Motorola Timbuktu Pro 'PlughNTCommand' Named Pipe Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35496

Microsoft Active Template Library Object Type Mismatch Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35982

FreeBSD 'mount(2)' and 'nmount(2)' Multiple Stack Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/31002

SafeNet SoftRemote IKE Service Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35154

Unisys Business Information Server Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35494

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35828

Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35832

Microsoft Active Template Library 'IPersistStreamInit' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35585

Microsoft Active Template Library Header Data Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35558

Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35981

Sun Solaris XScreenSaver Popup Windows Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35964

Microsoft OWC ActiveX Control 'BorderAround()' Heap Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35991

Microsoft Remote Desktop Connection Client Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35971

Samba Arbitrary Memory Contents Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32494

Microsoft Office Web Components ActiveX Control 'msDataSourceObject()' Code Execution Vulnerability
http://www.securityfocus.com/bid/35642

Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35980

Microsoft Office Web Components ActiveX Control Memory Allocation Code Execution Vulnerability
http://www.securityfocus.com/bid/35990

Apple Mac OS X 2009-003 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35954

CoreGraphics Font Glyph Rendering Library Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35774

Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35985

Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35187

Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnerability
http://www.securityfocus.com/bid/35186

Microsoft Visual Studio Active Template Library NULL String Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35830

libxml XML Entity Name Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31126

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35900

Adobe Flash Player and AIR (CVE-2009-1866) Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35901

Adobe Flash Player and AIR NULL Pointer Exception Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35906

TGS Content Management HTML-Injection and Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/30157

Adobe Flash Player and AIR Sandbox Bypass Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35908

Novell Privileged User Manager Remote Library Injection Vulnerability
http://www.securityfocus.com/bid/35752

Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35464

Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/35530

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/35451

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Pidgin Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35067

libsndfile VOC and AIFF Processing Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34978

Apache Geronimo Application Server Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34562

Memcached and MemcacheDB ASLR Information Disclosure Weakness
http://www.securityfocus.com/bid/34756

Memcached Multiple Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35989

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Adobe Flash Player and AIR URI Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35902

Adobe Flash Player and AIR 'intf_count' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35907

Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35939

Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35927

Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35942

Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35943

JNLPAppletLauncher Arbitrary File Creation Vulnerability
http://www.securityfocus.com/bid/35946

Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35944

Microsoft Windows Embedded OpenType Font Engine Unspecified Denial of Service Vulnerability
http://www.securityfocus.com/bid/36029

WebKit International Domain Name URI Spoofing Vulnerability
http://www.securityfocus.com/bid/36026

WebKit 'pluginspace' URI Scheme Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36024

WebKit Floating Point Number Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36023

Apple Safari Top Site Feature Website Promotion Security Vulnerability
http://www.securityfocus.com/bid/36022

Linux Kernel 'fs/proc/base.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36019

Microsoft Windows Telnet NTLM Credential Reflection Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35993

Microsoft Office Web Components ActiveX Control Buffer Overflow Code Execution Vulnerability
http://www.securityfocus.com/bid/35992

Microsoft Remote Desktop Connection ActiveX Control Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35973

Microsoft Windows Workstation Service Double Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35972

Microsoft Message Queuing Service NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35969

0 件のコメント:

コメントを投稿