2009年8月25日火曜日

25日 火曜日、赤口

+ Perl 5.10.1 released
http://use.perl.org/articles/09/08/25/0556226.shtml

JVNDB-2009-001929 Sun Solaris の NFSv4 モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001929.html

JVNDB-2009-001928 Sun Solaris の IP Filter サブシステムにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001928.html

JVNDB-2009-001927 Sun Solaris の SCTP 実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001927.html

JVNDB-2008-002418 MTR の isplit_redraw 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002418.html

JVNDB-2009-001926 libtiff の inter-color spaces conversion ツールにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001926.html

JVNDB-2009-001925 libtiff の LZWDecodeCompat 関数におけるバッファアンダーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001925.html

JVNDB-2008-000075 EC-CUBE における SQL インジェクションの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000075.html

JVNDB-2008-000065 EC-CUBE における SQL インジェクションの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000065.html

JVNDB-2008-000064 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000064.html

JVNDB-2008-000063 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000063.html

JVNDB-2008-000062 EC-CUBE におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000062.html

The Ubuntu Welfare Program
http://www.linux.org/news/2009/08/24/0007.html

The SCO zombie wins one
http://www.linux.org/news/2009/08/24/0006.html

Aug. 25, 1991: Kid From Helsinki Foments Linux Revolution
http://www.linux.org/news/2009/08/24/0005.html

First Ever PostgreSQL Alpha Release Now Available
http://www.postgresql.org/about/news.1125

Flash attack vectors (and worms)
http://isc.sans.org/diary.html?storyid=7015

Adobe Coldfusion 8 Multiple Linked XSS Vulnerabilies
http://www.securiteam.com/unixfocus/5YP0N15S0G.html

Insight Control Suite For Linux (ICE-LX) Multiple Vulnerabilities
http://www.securiteam.com/unixfocus/5WP0L15S0Q.html

Piwigo SQL Injection Vulnerability
http://www.securiteam.com/securitynews/5XP0M15S0I.html

IBM AFS Null Pointer Dereference Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022762.html

Linux Kernel Null Pointer Dereference in udp_sendmsg() Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Aug/1022761.html

NaviCOPA Web Server Remote Buffer Overflow and Source Code Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/33585

FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36119

FreeBSD 8.0-BETA3 Available
http://www.freebsd.org/news/newsflash.html#event20090824:01






+ RHSA-2009:1222-02: Important: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-1222.html
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30209

+ RHSA-2009:1223-02: Important: kernel security update
http://rhn.redhat.com/errata/RHSA-2009-1223.html
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30210

+ FreeBSD-SA-08/22/2009: FreeBSD <= 6.1 kqueue() NULL pointer dereference http://www.criticalwatch.com/support/security-advisories.aspx?AID=30211
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00195.html
http://www.milw0rm.com/exploits/9488
http://www.securityfocus.com/bid/36101

+ Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36108

+ FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36119

[ANNOUNCE] First Ever PostgreSQL Alpha Release Now Available
http://developer.postgresql.org/pgdocs/postgres/release-8.5.html

- HPSBTU02453 SSRT091037 rev.2 - HP Tru64 UNIX or HP Tru64 Internet Express Running BIND Server, Denial of Service (DoS)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01837667-2

Mandriva Linux 2010 Beta released
http://www.linux.org/news/2009/08/24/0004.html

Linux User-Friendliness
http://www.linux.org/news/2009/08/24/0003.html

All Linux needs is a good commercial
http://www.linux.org/news/2009/08/24/0002.html

The Joy of Linux Myth Debunking
http://www.linux.org/news/2009/08/24/0001.html

Chromium popularity rising on Ubuntu, gains 64-bit support
http://www.linux.org/news/2009/08/23/0002.html

Pidgin 2.6.1: The best Linux IM client gets better
http://www.linux.org/news/2009/08/23/0001.html

$9.99 Learning Perl and Mastering Perl e-books from O'Reilly
http://use.perl.org/articles/09/08/24/2012226.shtml

Installing VMware Products on Unsupported Linux Distributions
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1623&sliceId=1&docTypeID=DT_KB_1_1

Independent Researcher : Radvision's Scopia Cross Site Scripting Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30216

Independent Researcher : D-Link 500G Authentication Bypass
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30219

RedHat : Important: kernel security and bug fix update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30209

RedHat : Important: kernel security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30210

Security-Assessment.com : WizzRSS Firefox Extension - Privileged Code Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30213

Security-Assessment.com : ScribeFire Firefox Extension - Privileged Code Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30214

Security-Assessment.com : Feed Sidebar Firefox Extension - Privileged Code Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30215

Security-Assessment.com : CoolPreviews - Firefox Extension - Chrome Privileged Code Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30217

Security-Assessment.com : Update Scanner - Firefox Extension - Chrome Privileged Code Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30218

Debian : New wordpress packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30208

Mandriva : expat
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30200

Mandriva : python
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30201

Mandriva : wxgtk
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30202

Mandriva : python-celementtree
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30203

Mandriva : audacity
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30205

Mandriva : mozilla-thunderbird
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30206

Mandriva : mozilla-thunderbird
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30207

Independent Researcher : FreeBSD <= 6.1 kqueue() NULL pointer dereference http://www.criticalwatch.com/support/security-advisories.aspx?AID=30211

Independent Researcher : CS-MARS Clear Text Password Storage - v6.0.4 and Earlier
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30212

Independent Researcher : Clear Text Storage of Password in CS-MARS v6.0.4 and Earlier
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30220

Independent Researcher : Cuteflow Version 2.10.3 "edituser.php" Security Bypass Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30222

Independent Researcher : DoS vulnerabilities in Mozilla Firefox, Internet Explorer and Chrome
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30223

rPSA-2009-0124-1 curl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00224.html

rPSA-2009-0123-1 apr-util
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00220.html

rPSA-2009-0122-1 idle python
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00221.html

[ MDVSA-2009:220 ] davfs
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00222.html

[USN-825-1] libvorbis vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00227.html

[USN-824-1] PHP vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00226.html

[USN-823-1] KDE-Graphics vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00225.html

[USN-822-1] KDE-Libs vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00223.html

[SECURITY] [DSA 1872-1] New Linux 2.6.18 packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00219.html

[ MDVSA-2009:219 ] kompozer
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00218.html

[ MDVSA-2009:218 ] w3c-libwww
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00217.html

Update Scanner - Firefox Extension - Chrome Privileged Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00213.html

CoolPreviews - Firefox Extension - Chrome Privileged Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00197.html

Local Kernel Buffer Overflow vulnerability in Avast!
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00196.html

Radvisions Scopia Cross Site Scripting Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00200.html

WizzRSS Firefox Extension - Privileged Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00212.html

ScribeFire Firefox Extension - Privileged Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00211.html

Feed Sidebar Firefox Extension - Privileged Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00210.html

[ MDVSA-2009:217 ] mozilla-thunderbird
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00209.html

[ MDVSA-2009:216 ] mozilla-thunderbird
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00208.html

[ MDVSA-2009:215 ] audacity
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00207.html

[ MDVSA-2009:214 ] python-celementtree
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00206.html

[ MDVSA-2009:213 ] wxgtk
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00205.html

WM Downloader (.Smi/ .Ram/ .pls/ .smil/ .wax/ .wpl File) Local Buffer Overflow Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00204.html

[ MDVSA-2009:213 ] wxgtk
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00203.html
[ MDVSA-2009:212 ] python
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00202.html

[ MDVSA-2009:212 ] python
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00201.html

[ MDVSA-2009:211 ] expat
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00199.html

DoS vulnerability in Google Chrome
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00214.html

[SECURITY] [DSA 1871-1] New wordpress packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00198.html

FreeBSD <= 6.1 kqueue() NULL pointer dereference http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00195.html

Packet Storm is back online.
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00215.html

相次ぐ「Delphiウイルス」の感染事例、正規のオンラインソフトにも
トレンドマイクロが警告、「検出されたら作者に報告を」
http://itpro.nikkeibp.co.jp/article/NEWS/20090824/335890/?ST=security

Twitter Issues
http://isc.sans.org/diary.html?storyid=7012

Solaris Recursive mutex_enter() in pollwakeup() Lets Local Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022759.html

Python expat Module UTF-8 Denial of Service Vulnerability
http://secunia.com/advisories/36433/

Python expat Module UTF-8 Denial of Service Vulnerability
http://secunia.com/advisories/36432/

Fedora update for pidgin
http://secunia.com/advisories/36431/

Red Hat update for kernel
http://secunia.com/advisories/36430/

Wizz RSS News Reader Extension for Firefox Code Execution Vulnerability
http://secunia.com/advisories/36428/

ScribeFire Firefox Extension Code Execution Vulnerability
http://secunia.com/advisories/36427/

Feed Sidebar Firefox Extension Code Execution Vulnerability
http://secunia.com/advisories/36426/

Expat XML Parser UTF-8 Denial of Service Vulnerability
http://secunia.com/advisories/36425/

SugarCRM Unspecified SQL Injection Vulnerability
http://secunia.com/advisories/36423/

Sun Solaris "pollwakeup()" Denial of Service Vulnerability
http://secunia.com/advisories/36419/

Fedora update for buildbot
http://secunia.com/advisories/36418/

Fedora update for perl-Compress-Raw-Bzip2
http://secunia.com/advisories/36415/

CA Internet Security Suite Local Denial of Service
http://secunia.com/advisories/36397/

Buildbot Web Status Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/36352/

fotoshow pro "category" SQL Injection Vulnerability
http://secunia.com/advisories/36350/

CuteFlow "edituser.php" Security Bypass Vulnerability
http://secunia.com/advisories/36349/

CoolPreviews Extension for Firefox Code Execution Vulnerability
http://secunia.com/advisories/36341/

Update Scanner Extension for Firefox Code Execution Vulnerability
http://secunia.com/advisories/36321/

Debian update for wordpress
http://secunia.com/advisories/36316/

IBM AFS Linux Client Denial of Service
http://secunia.com/advisories/36310/

Live for Speed S2 Join Packets Processing Denial of Service
http://secunia.com/advisories/36198/

Wizz RSS News Reader for Firefox Remote Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2369

ScribeFire Add-on for Firefox Remote Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2368

Feed Sidebar Add-on for Firefox Remote Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2367

CoolPreviews Add-on for Firefox Remote Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2366

Update Scanner Add-on for Firefox Remote Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2365

Cisco CS-MARS Logs Files Information Disclosure Vulnerability
http://www.vupen.com/english/advisories/2009/2364

Infinity Remote File Disclosure and Remote SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2009/2363

CuteFlow "edituser.php" Script Unauthorized Access Vulnerability
http://www.vupen.com/english/advisories/2009/2362

Photodex ProShow Gold "psh" File Handling Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2360

CMS Aspect Web Design "ProductID" Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2359

IBM AFS Client for Linux Unspecified Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2358

Sun Solaris Security Update Fixes Flash Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/2357

Sun Solaris "pollwakeup" Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2356

Sun OpenSolaris Security Update Fixes Firefox Code Execution Issues
http://www.vupen.com/english/advisories/2009/2355

VMware Security Update Fixes Libpng and Apache Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2009/2354

Avast! 4.8.1335 Professional Local Kernel Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9492

FreeBSD <= 6.1 kqueue() NULL pointer Dereference Local Root Exploit http://www.milw0rm.com/exploits/9488

Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)
http://www.milw0rm.com/exploits/9479

Radix Antirootkit
http://www.milw0rm.com/exploits/9478

Huawei SmartAX MT880 Multiple XSRF Vulnerabilities
http://www.milw0rm.com/exploits/9503

NaviCopa Web Server 3.01 Remote Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9500

Netgear WNR2000 FW 1.2.0.8 Information Disclsoure Vulnerabilities
http://www.milw0rm.com/exploits/9498

Audacity <= 1.2 (.gro File) Universal BOF Exploit (egg hunter) http://www.milw0rm.com/exploits/9501

Fat Player 0.6b (.wav File) Universal Local Buffer Exploit
http://www.milw0rm.com/exploits/9495

BlazeDVD 5.1 Professional (.PLF File) Local BOF Exploit (SEH) (xp/vista)
http://www.milw0rm.com/exploits/9491

Multiple BSD Operating Systems setusercontext() Vulnerabilities
http://www.milw0rm.com/exploits/9489

NaviCOPA Web Server Remote Buffer Overflow and Source Code Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/33585

Python Expat Wrapper Library Unspecified XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35988

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/28749

SugarCRM Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/36118

Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35929

Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35930

Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36108

Adobe Flash Player and AIR Sandbox Bypass Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35908

Linux Kernel PA-RISC EEPROM Driver Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36004

Adobe Flash Player and AIR NULL Pointer Exception Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35906

Adobe Flash Player and AIR URI Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35902

Adobe Flash Player and AIR (CVE-2009-1866) Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35901

Adobe Flash Player and AIR 'intf_count' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35907

Adobe Flash Player and AIR Unspecified Clickjacking Vulnerability
http://www.securityfocus.com/bid/35905

Adobe Flash Player and AIR Loader Object Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35904

Adobe Acrobat, Reader, and Flash Player Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35759

Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35900

Subdreamer CMS Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/36117

libvorbis OGG Vorbis Processing Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36018

libvorbis Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/29206

CoolPreviews Stack Preview Feature HTML Injection Vulnerability
http://www.securityfocus.com/bid/36116

Avast! Antivirus Professional File System Filter Driver Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36115

WebKit SVGList Objects Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34924

WebKit CSS 'Attr' Function Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35318

Live For Speed S2 Duplicate Join Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36114

WebKit DOM Event Handler Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35271

WebKit JavaScript Garbage Collector Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35309

Update Scanner 'onerror' HTML Injection Vulnerability
http://www.securityfocus.com/bid/36109

WebKit SVG Animation Elements User After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35334

Wizz RSS 'description' tag HTML Injection Vulnerability
http://www.securityfocus.com/bid/36107

Feed Sidebar RSS Feed HTML Injection Vulnerability
http://www.securityfocus.com/bid/36104

ScribeFire 'img' tag HTML Injection Vulnerability
http://www.securityfocus.com/bid/36105

cURL / libcURL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36032

Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36038

PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35440

Pidgin 'msn_slplink_process_msg()' NULL Pointer Dereference Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36071

SugarCRM Email Attachment Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/35361

Snoopy '_httpsrequest()' Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/31887

WordPress 'cat' Parameter Directory Traversal Vulnerability
http://www.securityfocus.com/bid/28845

kses Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/28599

Buildbot Multiple Unspecified Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/36100

Neon NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36079

Neon 'ne_xml*' expat XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36080

WordPress Comment Author URI Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35755

WordPress Prior to Version 2.8.3 'wp-admin' Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/35935

WordPress 'wp-admin/admin.php' Module Configuration Security Bypass Vulnerability
http://www.securityfocus.com/bid/35584

WordPress Lost Password SQL Column Truncation Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/31068

Multiple Vendor BSD 'kevent()' Race Condition Vulnerability
http://www.securityfocus.com/bid/36101

Sun Solaris pollwakeup(9F) Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36106

IBM AFS Client Denial of Service Vulnerability
http://www.securityfocus.com/bid/36102

Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35767

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

Mozilla Firefox Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35803

Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35660

Mozilla Firefox SOCKS5 Proxy Response Denial of Service Vulnerability
http://www.securityfocus.com/bid/35925

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

WebKit Numeric Character References Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35607

Cisco IOS XR Long Length Border Gateway Protocol (BGP) Update Denial of Service Vulnerability
http://www.securityfocus.com/bid/36092

Cisco IOS XR Border Gateway Protocol (BGP) Update AS Prepend Denial of Service Vulnerability
http://www.securityfocus.com/bid/36093

Cisco IOS XR Invalid Border Gateway Protocol (BGP) Update Denial of Service Vulnerability
http://www.securityfocus.com/bid/36063

FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36119

0 件のコメント:

コメントを投稿