2009年9月10日木曜日

10日 木曜日、仏滅

ウイルスバスター コーポレートエディション 7.3における修正プログラム公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1299

Trend Micro LeakProof Appliance/Virtual Appliance 5.0 公開とサポート開始のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1302

JVN#62211338 Microsoft Windows におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN62211338/index.html

JVNDB-2009-001991 IBM AIX の デバッグコンポーネントにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001991.html

JVNDB-2009-001990 Sun Java SE における任意のファイルを改ざんされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001990.html
JVNDB-2009-001989 Apache Xerces C++ におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001989.html

JVNDB-2009-001988 Sun JRE で使用している Apache Xerces2 Java におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001988.html

JVNDB-2009-001819 Adobe Reader および Acrobat の JPX データ処理における複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001819.html

JVNDB-2009-001818 Adobe Reader における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001818.html

JVNDB-2009-001817 Adobe Reader の JBIG2 フィルタにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001817.html

JVNDB-2009-001816 Adobe Reader におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001816.html

JVNDB-2009-001815 Adobe Reader における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001815.html

JVNDB-2009-001814 Adobe Reader の JBIG2 フィルタにおけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001814.html

JVNDB-2009-001813 Adobe Reader の JBIG2 フィルタにおけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001813.html

Healthcare Spam
http://isc.sans.org/diary.html?storyid=7111

Mozilla Firefox Bugs in JavaScript Engine and Browser Engine Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Sep/1022876.html

Mozilla Firefox Default WIndows Font May Let Remote Users Spoof the Location Bar Contents
http://securitytracker.com/alerts/2009/Sep/1022875.html

Mozilla Firefox XUL Tree Element Memory Free Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Sep/1022874.html

Mozilla Firefox feedWriter Bug Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Sep/1022873.html

Apple iPhone Heap Overflow in Processing AAC and MP3 Files Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Sep/1022869.html

Apple iPhone May Disclose Usersnames and Passwords via URLs to Remote Users
http://securitytracker.com/alerts/2009/Sep/1022868.html

Apple iPhone Lets Physically Local Users Bypass Security Restrictions
http://securitytracker.com/alerts/2009/Sep/1022868.html

Apple iPhone SMS Processing Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Sep/1022866.html

QuickTime H.264, MPEG-4, and FlashPix Processing Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Sep/1022865.html

Symantec Launches Norton 2010 Products, Introducing New Detection Technologies in the Fight against Cyber Crime
http://www.symantec.com/about/news/release/article.jsp?prid=20090909_01

Firefox 3.5.3, 3.0.14 released
http://mozilla.jp/firefox/3.5.3/releasenotes/
http://mozilla.jp/firefox/3.0.14/releasenotes/

About the security content of iPhone OS 3.1 and iPhone OS 3.1.1 for iPod touch
http://support.apple.com/kb/HT3860

QuickTime 7.6.4 のセキュリティコンテンツについて
http://support.apple.com/kb/HT3859?viewlocale=ja_JP

マイクロソフト セキュリティ アドバイザリ (975497): SMB の脆弱性により、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/975497.mspx

Mozilla Firefox Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/2585

Apple QuickTime File Handling Remote Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/2584

Apple iPhone / iPod touch Security Bypass and Code Execution Issues
http://www.vupen.com/english/advisories/2009/2583

SILC Toolkit HTTP Server Format String Vulnerability
http://www.securityfocus.com/bid/36194

Pidgin Libpurple Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/36277

Microsoft Windows TCP/IP Orphaned Connection Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36269

TCP/IP Protocol Stack Zero Window Size Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/31545

Microsoft Windows Wireless LAN AutoConfig Frame Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36223

Mozilla Firefox Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35803

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343




+ Linux kernel 2.6.27.33, 2.6.30.6, 2.6.31 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.33
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.6
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31

+ PostgreSQL 8.4.1, 8.3.8, 8.2.14, 8.1.18, 8.0.22, 7.4.26 released
http://www.postgresql.org/about/news.1135
http://www.postgresql.org/docs/8.4/static/release-8-4-1.html
http://www.postgresql.org/docs/8.3/static/release-8-3-8.html
http://www.postgresql.org/docs/8.2/static/release-8-2-14.html
http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-18
http://www.postgresql.org/docs/8.0/static/release.html#RELEASE-8-0-22

+ IBM WebSphere MQ Multiple Vulnerabilities
http://secunia.com/advisories/36647/
http://www-01.ibm.com/support/docview.wss?uid=swg24024153
http://www.vupen.com/english/advisories/2009/2578
http://www.securityfocus.com/bid/36310

+ Solution 266228: Security Vulnerability in lx Branded Zones May Result in Denial of Service (DoS)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266228-1
http://www.vupen.com/english/advisories/2009/2581
http://www.securityfocus.com/bid/36340

+ PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314
http://www.postgresql.org/support/security

HPSBUX02181 SSRT061289 rev.5 - IPFilterを実行する HP-UX、リモートサービス拒否 (DoS)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=ja_JP&docId=emr_na-c01716013-2

HPSBUX02437 SSRT090038 rev.2 - XNTPを実行するHP-UX、任意コードのリモート実行
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=ja_JP&docId=emr_na-c01818501-2

linux-next: next-20090909
http://git.kernel.org/?p=linux/kernel/git/next/linux-next.git;a=summary

Linux kernel 2.6.31-rc9-git3
http://www.kernel.org/pub/linux/kernel//v2.6/snapshots/patch-2.6.31-rc9-git3.bz2

PostgreSQL Security Update
http://www.postgresql.org/about/news.1135

Choosing a network adapter for your virtual machine
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1001805&sliceId=1&docTypeID=DT_KB_1_1

Debian : New xapian-omega packages fix cross-site scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30327

Gentoo Linux : Apache Portable Runtime, APR Utility Library: Execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30333

Gentoo Linux : Clam AntiVirus: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30334

Gentoo Linux : Openswan: Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30335

Gentoo Linux : aMule: Parameter injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30336

Gentoo Linux : TkMan: Insecure temporary file usage
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30337

Gentoo Linux : C* music player: Insecure temporary file usage
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30338

Gentoo Linux : Screenie: Insecure temporary file usage
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30339

Gentoo Linux : LMBench: Insecure temporary file usage
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30340

Gentoo Linux : GCC-XML: Insecure temporary file usage
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30341

Cisco : TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30330

Independent Researcher : Novell eDirectory 8.8 SP5 Dhost Http Server DoS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30344

Independent Researcher : Regarding Microsoft srv2.sys SMB2.0 NEGOTIATE BSOD
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30345

「Microsoft Windows」におけるセキュリティ上の弱点(脆弱性)の注意喚起
http://www.ipa.go.jp/security/vuln/documents/2009/200909_windows.html

RHSA-2009:1430-1: Critical: firefox security update
http://rhn.redhat.com/errata/RHSA-2009-1430.html

RHSA-2009:1431-1: Critical: seamonkey security update
http://rhn.redhat.com/errata/RHSA-2009-1431.html

RHSA-2009:1432-1: Critical: seamonkey security update
http://rhn.redhat.com/errata/RHSA-2009-1432.html

VistaとServer 2008に新たな脆弱性、修正パッチは準備中
SMBの実装に問題、Windows 7やServer 2008 R2は影響を受けず
http://itpro.nikkeibp.co.jp/article/NEWS/20090910/336933/?ST=security

Windowsに危険な脆弱性が5件、Webアクセスやデータ受信で被害の恐れ
TCP/IP通信機能や無線LAN機能にも脆弱性、「早急にパッチ適用を」
http://itpro.nikkeibp.co.jp/article/NEWS/20090910/336932/?ST=security

[ MDVSA-2009:226 ] aria2
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00066.html

CORE-2009-0820 - Dnsmasq Heap Overflow and Null-pointer Dereference on TFTP Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00065.html

[SECURITY] [DSA 1882-1] New xapian-omega packages fix cross-site scripting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00064.html

TCP/IP Orphaned Connections Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00048.html

[ GLSA 200909-11 ] GCC-XML: Insecure temporary file usage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00062.html

[ GLSA 200909-10 ] LMBench: Insecure temporary file usage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00061.html

[ GLSA 200909-09 ] Screenie: Insecure temporary file usage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00060.html

[ GLSA 200909-08 ] C* music player: Insecure temporary file usage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00059.html

[ GLSA 200909-07 ] TkMan: Insecure temporary file usage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00057.html

[ GLSA 200909-06 ] aMule: Parameter injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00056.html

[ GLSA 200909-05 ] Openswan: Denial of Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00055.html

[ GLSA 200909-04 ] Clam AntiVirus: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00053.html

[ GLSA 200909-03 ] Apache Portable Runtime, APR Utility Library: Execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00052.html

SeacureIT Preview Conference 2009
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00051.html

[Advisory] ChartDirector Critical File Access
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00049.html

Open Beta - New Free AV Software
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00047.html

4f: The File Format Fuzzing Framework
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00054.html

SMB SRV2.SYS Denial of Service PoC
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00063.html

[USN-828-1] PAM vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00045.html

JPCERT/CC WEEKLY REPORT
http://www.jpcert.or.jp/wr/2009/wr093501.html

JVNVU#943657 複数の TCP の実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/cert/JVNVU943657/index.html

JVNTA09-251A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-251A/index.html

JVN#62211338 Microsoft Windows におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN62211338/index.html

Vulnerability Note VU#336053: Cyrus IMAPd buffer overflow vulnerability
http://www.kb.cert.org/vuls/id/336053

Mozilla Firefox Temporary File Download Manipulation Security Issue
http://secunia.com/advisories/36649/

IBM WebSphere MQ Multiple Vulnerabilities
http://secunia.com/advisories/36647/

Hitachi Products GIF Processing Denial of Service Vulnerability
http://secunia.com/advisories/36646/

Hitachi JP1/File Transmission Server/FTP Unspecified Vulnerabilities
http://secunia.com/advisories/36645/

ChartDirector for .NET "cacheid" File Disclosure Vulnerability
http://secunia.com/advisories/36644/

Fedora update for kdelibs3
http://secunia.com/advisories/36642/

Hitachi Products GIF Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/36622/

Ubuntu update for pam
http://secunia.com/advisories/36620/

IBM HTTP Server Multiple Vulnerabilities
http://secunia.com/advisories/36619/

Cisco Products TCP Implementation Denial of Service Vulnerabilities
http://secunia.com/advisories/36618/

Red Hat update for xmlsec1
http://secunia.com/advisories/36615/

Red Hat update for fetchmail
http://secunia.com/advisories/36612/

Fedora update for cyrus-imapd
http://secunia.com/advisories/36609/

Orion Application Server Input Validation Holes in Example Scripts Permit Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2009/Sep/1022864.html

Cyrus IMAP Server Buffer Overflow in Sieve Component Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Sep/1022863.html

IBM WebSphere Application Server doGet/doTrace Method Flaw Lets Remote Users Bypass Security Restrictions
http://securitytracker.com/alerts/2009/Sep/1022862.html

IBM Lotus Notes RSS Widget Input Validation Flaw May Let Remote Users Gain Privileges
http://securitytracker.com/alerts/2009/Sep/1022861.html

Linux Kernel tc_fill_tclass() Discloses Uninitialized Kernel Memory to Local Users
http://securitytracker.com/alerts/2009/Sep/1022860.html

XML Security Library (xmlsec) XML Digital Signature Flaw May Let Remote Users Bypass Authentication
http://securitytracker.com/alerts/2009/Sep/1022852.html

Microsoft Windows XP/Vista TCP/IP Orphaned Connections Vulnerability
http://www.securiteam.com/windowsntfocus/5KP022KSAO.html

Microsoft Internet Explorer JScript arguments Invocation Memory Corruption
http://www.securiteam.com/windowsntfocus/5JP012KSAC.html

VMWare VMnc Codec Mismatched Dimensions Buffer Overflow
http://www.securiteam.com/unixfocus/5NP052KSAC.html

Orion Application Server Example Pages XSS Vulnerability
http://www.securiteam.com/unixfocus/5MP042KSAQ.html

ChartDirector for .NET File Access Vulnerability
http://www.securiteam.com/securitynews/5LP032KSAW.html

Pidgin MSN <= 2.5.8 Remote Code Execution Exploit http://www.milw0rm.com/exploits/9615

Linux Kernel 2.4/2.6 sock_sendpage() Local Root Exploit [2]
http://www.milw0rm.com/exploits/9598

Windows Vista/7 SMB2.0 Negotiate Protocol Request Remote BSOD Vuln
http://www.milw0rm.com/exploits/9594

FTPShell Client 4.1 RC2 Remote Buffer Overflow Exploit (univ)
http://www.milw0rm.com/exploits/9613

SIDVault 2.0e Windows Universal Buffer Overflow Exploit (SEH)
http://www.milw0rm.com/exploits/9596

jetAudio 7.1.9.4030 plus vx(asx/wax/wvx) Universal Local BOF (SEH)
http://www.milw0rm.com/exploits/9619

Millenium MP3 Studio (pls/mpf/m3u) Local Universal BOF Exploits (SEH)
http://www.milw0rm.com/exploits/9618

Audio Lib Player (m3u File) Buffer Overflow Exploit (SEH)
http://www.milw0rm.com/exploits/9610

GemStone/S 6.3.1 (stoned) Local Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9608

HTMLDOC 1.8.27 (html File Handling) Stack Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9595

Adobe RoboHelp Server Upload and Code Execution Vulnerability
http://www.vupen.com/english/advisories/2009/2582

Sun Solaris lx Branded Zones Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2581

Check Point Products TCP State Table Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2580

IBM HTTP Server Multiple Overflow and Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2579

IBM WebSphere MQ Memory Overwrite and Denial of Service Issues
http://www.vupen.com/english/advisories/2009/2578

Cisco Products TCP State Remote Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2577

Hitachi Products GIF Image Processing Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2576

Hitachi JP1/File Transmission Server/FTP Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/2575

Hitachi Products Java Applications GIF Handling Buffer Overflow Issue
http://www.vupen.com/english/advisories/2009/2574

Apple iPhone and iPod touch Safari Referer Header Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36339

Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
http://www.securityfocus.com/bid/36342

Qt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36203

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

RETIRED: Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36326

RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/36239

RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/35974

Symantec Altiris Deployment Solution File Transfer Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36113

Symantec Altiris Deployment Solution 'DBManager' Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36110

Autonomy KeyView Module Excel Document Processing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36042

Symantec Altiris Deployment Solution 'Aclient' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36111

Symantec Altiris Deployment Solution Authentication Handshake Race Condition Security Vulnerability
http://www.securityfocus.com/bid/36112

COWON America jetAudio ASX File Processing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/27698

ytnef Buffer Overflow and Directory Traversal Vulnerabilities
http://www.securityfocus.com/bid/36294

Worldweaver DX Studio Player Browser Plugin Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35273

GlobalSCAPE Secure FTP Server and Enhanced File Transfer Server Unspecified Security Vulnerability
http://www.securityfocus.com/bid/36302

The Rat CMS 'admin/add_album.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/36295

Pidgin 'msn_slplink_process_msg()' NULL Pointer Dereference Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36071

Pidgin Libpurple Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/36277

libvorbis OGG Vorbis Processing Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36018

CoolPlayer M3U File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30418

Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36296

Joomla! Joomlub Component 'aid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36287

libxml2 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36010

AgoraGroups Joomla! Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35118

JNLPAppletLauncher Arbitrary File Creation Vulnerability
http://www.securityfocus.com/bid/35946

Mambo Zoom Component 'catid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36281

Asterisk IAX2 Call Number Space Exhaustion Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36275

DvBBS 'boardrule.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/36282

DotNetNuke Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/36274

WebKit International Domain Name URI Spoofing Vulnerability
http://www.securityfocus.com/bid/36026

WebKit 'parent/top' Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/35441

FreeRADIUS Unspecified Denial of Service Vulnerability
http://www.securityfocus.com/bid/36263

WebKit Numeric Character References Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35607

Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36262

LiteSpeed Web Server Multiple Unspecified Remote Security Vulnerabilities
http://www.securityfocus.com/bid/36268

XEmacs Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35473

Mutt SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36251

Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36249

MailSite 'LDAP3A.exe' Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/36240

freeSSHd Pre Authentication Error Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36235

68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/36208

Novell eDirectory HTTP GET Request Unicode Strings Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36301

RETIRED: HAURI ViRobot Desktop Unspecified Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36241

Microsoft Windows RDP Connection Denial of Service Vulnerability
http://www.securityfocus.com/bid/36315

PPStream 'MList.ocx' ActiveX Control Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36234

FreeRADIUS Tag Field Heap Corruption Vulnerability
http://www.securityfocus.com/bid/9079

HTMLDOC 'html' File Handling Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35727

Adobe RoboHelp Server Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36245

ASUS WL-500W Wireless Router Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/36236

Microsoft Windows TCP/IP Orphaned Connection Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36269

Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36299

Hitachi Multiple Products GIF File Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36311

Net-SNMP GETBULK Divide By Zero Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35492

Net-SNMP GETBULK Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32020

Hitachi Multiple Products GIF File Parsing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36309

Hitachi JP1/File Transmission Server/FTP Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36307

LMbench Insecure Temporary File Creation Vulnerabilities
http://www.securityfocus.com/bid/30913

IBM WebSphere MQ Multiple Vulnerabilities
http://www.securityfocus.com/bid/36310

SIDVault 'simple_bind()' Function Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/25460

Microsoft JScript Scripting Engine Keyword Arguments Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36224

Microsoft Windows Wireless LAN AutoConfig Frame Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36223

Microsoft Windows Media Format MP3 Metadata Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36228

Microsoft Windows Media Format ASF Header Invalid Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36225

Microsoft DHTML Editing Component ActiveX Control Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36280

Microsoft Windows TCP/IP TimeStamps Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36265

Screenie Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/32737

CMus Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/32741

TkMan Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/32407

aMule 'wxExecute()' Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/34683

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

Openswan and strongSwan DPD Packet Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34296

ClamAV Prior to 0.95.1 Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34446

ClamAV Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/34357

Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35949

Apache 'mod_proxy' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35565

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

KDE KSSL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36229

Fetchmail Failed Warning Message Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/25495

Fetchmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35951

Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/29705

SAP AG SAPgui EAI WebViewer3D ActiveX Control Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34310

Dnsmasq TFTP Service Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36121

Dnsmasq TFTP Service Remote NULL-Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36120

SILC Toolkit 'command.c' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/36193

SILC Client Format String Vulnerability
http://www.securityfocus.com/bid/35940

SILC Toolkit HTTP Server Format String Vulnerability
http://www.securityfocus.com/bid/36194

SILC Toolkit Encoded OID Format String Vulnerability
http://www.securityfocus.com/bid/36192

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Apple iPhone and iPod Touch Recovery Mode Command Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36341

Sun Solaris lx Branded Zones Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36340

Apple iPhone and iPod Touch MP3 and AAC File Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36338

Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
http://www.securityfocus.com/bid/36337

Apple iPhone prior to 3.1 SMS Message NULL-Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36336

Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36335

Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36334

Media Player Classic '.mid' File Processing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36333

Drupal REST API Module Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36331

Drupal Quota by Role Module Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36330

Drupal Subdomain Manager Module Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36329

Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities
http://www.securityfocus.com/bid/36328

FTPShell Client 'CWD' Command Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36327

Drupal Node Browser Module Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36325

Mambo Hestar Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36324

Drupal Node2Node Module Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36323

Joomla! Joomloc Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36322

Joomla! TPDugg Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36321

Drupal BUEditor Live Preview Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36320

Xapian Omega Search Query Exception Handling Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36317

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314

GNOME glib Symbolic Link Arbitrary File Access Vulnerability
http://www.securityfocus.com/bid/36313

0 件のコメント:

コメントを投稿