2009年9月8日火曜日

8日 火曜日、友引

JVNDB-2009-001981 Mozilla Firefox におけるアドレスバーを偽装される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001981.html

JVNDB-2009-001980 Mozilla Firefox の JavaScript エンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001980.html

JVNDB-2009-001979 Mozilla Firefox などの製品で利用される libvorbis における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001979.html

JVNDB-2009-001978 Mozilla Firefox のブラウザエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001978.html

JVNDB-2009-001977 Mozilla Firefox におけるクローム特権で任意の JavaScript を実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001977.html

JVNDB-2008-002137 Samba の smbd におけるリクエスト処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002137.html

「OpenSSL」の古いバージョンを利用しているウェブサイトへの注意喚起
http://www.ipa.go.jp/security/vuln/documents/2009/200909_openssl.html

Anybody recognize these packets?
http://isc.sans.org/diary.html?storyid=7090




FreeBSD 8.0-BETA4 Available
http://www.freebsd.org/news/newsflash.html#event20090907:01

「偽ウイルスを生成して検出」――自作自演の偽ソフト現る
英ソフォスが警告、GUIを備えて「本物」を装う
http://itpro.nikkeibp.co.jp/article/NEWS/20090907/336683/?ST=security

Seclists.org is finally back
http://isc.sans.org/diary.html?storyid=7087

Request for packets
http://isc.sans.org/diary.html?storyid=7084

Zope Object Database ZEO Server Information Disclosure and File Deletion
http://secunia.com/advisories/36637/

Sun libxml2 DTD Parsing Denial of Service Vulnerabilities
http://secunia.com/advisories/36631/

IBM Lotus Domino Web Access Cross-Site Scripting Vulnerability
http://secunia.com/advisories/36626/

ytnef Buffer Overflow and Arbitrary File Overwrite Vulnerabilities
http://secunia.com/advisories/36624/

Sun Solaris TCP/IP Networking Stack Denial of Service
http://secunia.com/advisories/36616/

Debian update for openoffice.org
http://secunia.com/advisories/36613/

FluxBB Cross-Site Scripting Vulnerability
http://secunia.com/advisories/36611/

Gentoo update for libvorbis
http://secunia.com/advisories/36610/

Joomla Component Joomlub "aid" SQL Injection Vulnerability
http://secunia.com/advisories/36607/

Ticket Support Script Multiple Vulnerabilities
http://secunia.com/advisories/36606/

IBM Tivoli Identity Manager Script Insertion Vulnerability
http://secunia.com/advisories/36511/

VMware Workstation Movie Decoder VMnc Codec Two Vulnerabilities
http://secunia.com/advisories/34938/

IBM Lotus Domino Web Access Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/2557

Sun Solaris IPv6 Networking Stack Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2556

Sun Solaris IPv4 Networking Stack Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2555

Sun Solaris Libxml2 Data Parsing Memory Corruption Vulnerabilities
http://www.vupen.com/english/advisories/2009/2554

VMware Workstation Movie Decoder VMnc Codec Vulnerabilities
http://www.vupen.com/english/advisories/2009/2553

Asterisk IAX2 Call Number Remote Resource Exhaustion Vulnerability
http://www.vupen.com/english/advisories/2009/2552

Pidgin Multiple Protocol Remote Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2551

Apache mod_proxy_ftp EPSV Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2550

Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36038

Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35981

VMware Movie Decoder VMnc Codec Multiple Heap Overflow Vulnerabilities
http://www.securityfocus.com/bid/36290

Google SketchUp '.skp' File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35911

Pidgin Libpurple Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/36277

Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36189

Dnsmasq TFTP Service Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36121

Dnsmasq TFTP Service Remote NULL-Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36120

libvorbis OGG Vorbis Processing Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36018

OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36200

Linux-PAM Configuration File Non-ASCII User Name Handling Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34010

CoolPlayer M3U File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30418

Apple Safari JavaScript 'eval()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/36298

Ipswitch WS_FTP Professional HTTP Server Response Format String Vulnerability
http://www.securityfocus.com/bid/36297

Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36296

The Rat CMS 'admin/add_album.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/36295

ytnef Buffer Overflow and Directory Traversal Vulnerabilities
http://www.securityfocus.com/bid/36294

0 件のコメント:

コメントを投稿