2009年10月14日水曜日

14日 水曜日、先負

「SSL証明書を更新してください」、新たなウイルスメール出現
リンクのクリックでウイルスがダウンロード、更新プログラムに見せかける
http://itpro.nikkeibp.co.jp/article/NEWS/20091014/338752/?ST=security

2009年10月 Microsoft セキュリティ情報 (緊急 8件) に関する注意喚起
http://www.jpcert.or.jp/at/2009/at090020.txt

JVNDB-2009-002094 Windows SMB version 2 に脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002094.html

JVNDB-2009-002093 Microsoft Windows の DHTML Editing Component ActiveX コントロールにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002093.html

JVNDB-2009-002092 Microsoft Windows におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002092.html

JVNDB-2009-002091 Microsoft Windows の TCP/IP 実装における任意のコードを実行される脆弱性http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002091.html

JVNDB-2009-002090 複数の TCP の実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002090.html

JVNDB-2009-002089 Microsoft Windows の Wireless LAN AutoConfig Service における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002089.html

JVNDB-2009-002088 Microsoft Windows の JScript スクリプトエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002088.html

Adobe Reader および Acrobat の脆弱性(APSB09-15)について
http://www.ipa.go.jp/security/ciadr/vul/20091014-adobe.html

Microsoft IIS の FTP サービスの脆弱性(MS09-053)について
http://www.ipa.go.jp/security/ciadr/vul/20091014-ms09-053.html

Microsoft Windows における SMBv2 の脆弱性(MS09-050)について
http://www.ipa.go.jp/security/ciadr/vul/20091014-ms09-050.html

Cisco Unified Communications Manager Express Vulnerability
http://www.securiteam.com/securitynews/6Q00C0UPPC.html

Dnsmasq TFTP Service Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36121

Dnsmasq TFTP Service Remote NULL-Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36120

Dopewars Server 'REQUESTJET' Message Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36606




+ マイクロソフト 2009 年 10 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms09-oct.mspx

- MS09-050 SMBv2 の脆弱性により、リモートでコードが実行される (975517)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-050.mspx
http://www.securityfocus.com/bid/36595
http://www.securityfocus.com/bid/36299

+ MS09-051 Windows Media Runtime の脆弱性により、リモートでコードが実行される (975682)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-051.mspx
http://www.securityfocus.com/bid/36614
http://www.securityfocus.com/bid/36602

+ MS09-052 Windows Media Player の脆弱性により、リモートでコードが実行される (974112)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-052.mspx
http://www.securityfocus.com/bid/36644

+ MS09-053 インターネット インフォメーション サービスの FTP サービスの脆弱性により、リモートでコードが実行される (975254)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-053.mspx
http://www.securityfocus.com/bid/36273

+ MS09-054 Internet Explorer 用の累積的なセキュリティ更新プログラム (974455)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-054.mspx
http://www.securityfocus.com/bid/36616
http://www.securityfocus.com/bid/36620
http://www.securityfocus.com/bid/36622
http://www.securityfocus.com/bid/36621

+ MS09-055 ActiveX の Kill Bit の累積的なセキュリティ更新プログラム (973525)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-055.mspx
http://www.securityfocus.com/bid/35828

+ MS09-056 Windows CryptoAPI の脆弱性により、なりすましが行われる (974571)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-056.mspx
http://www.securityfocus.com/bid/36475
http://www.securityfocus.com/bid/36577

+ MS09-057 インデックス サービスの脆弱性により、リモートでコードが実行される (969059)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-057.mspx
http://www.securityfocus.com/bid/36629

+ MS09-058 Windows カーネルの脆弱性により、特権が昇格される (971486)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-058.mspx
http://www.securityfocus.com/bid/36625
http://www.securityfocus.com/bid/36624
http://www.securityfocus.com/bid/36623

+ MS09-059 Local Security Authority Subsystem Service (LSASS) の脆弱性により、サービス拒否が起こる (975467)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-059.mspx
http://www.securityfocus.com/bid/36593

+ MS09-060 Microsoft Office 用の Microsoft ATL (Active Template Library) の ActiveX コントロールの脆弱性により、リモートでコードが実行される (973965)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-060.mspx
http://www.securityfocus.com/bid/35830
http://www.securityfocus.com/bid/35828
http://www.securityfocus.com/bid/35832

+ MS09-061 Microsoft .NET 共通言語ランタイムの脆弱性により、リモートでコードが実行される (974378)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-061.mspx
http://www.securityfocus.com/bid/36611
http://www.securityfocus.com/bid/36617
http://www.securityfocus.com/bid/36618

+ MS09-062 GDI+ の脆弱性により、リモートでコードが実行される (957488)
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-062.mspx
http://www.securityfocus.com/bid/36650
http://www.securityfocus.com/bid/36651
http://www.securityfocus.com/bid/36646
http://www.securityfocus.com/bid/36647
http://www.securityfocus.com/bid/36649
http://www.securityfocus.com/bid/36648
http://www.securityfocus.com/bid/36645
http://www.securityfocus.com/bid/36619

+ Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36273

+ Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36189

[ANNOUNCE] Apache CouchDB 0.10. has been released
http://couchdb.apache.org/downloads.html

Hulu Labs launches Hulu Desktop for Linux
http://www.linux.org/news/2009/10/13/0002.html

Ubuntu Linux Adds Private Cloud Backing
http://www.linux.org/news/2009/10/13/0001.html

A review of the Dell Mini 10v, Ubuntu Moblin Remix edition
http://www.linux.org/news/2009/10/12/0004.html

Microsoft Security Advisory (975497): Vulnerabilities in SMB Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/975497.mspx

Microsoft Security Advisory (975191): Vulnerabilities in the FTP Service in Internet Information Services
http://www.microsoft.com/technet/security/advisory/975191.mspx

Microsoft Security Advisory (973882): Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/973882.mspx

You are not authorized to access this Document.
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1901&sliceId=1&docTypeID=DT_KB_1_1

Debian : New kvm packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30609

Mandriva : phpmyadmin
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30608

Microsoft : Vulnerabilities in SMBv2 Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30610

Microsoft : Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30611

Microsoft : Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30613

Microsoft : Cumulative Security Update for Internet Explorer
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30614

Microsoft : Vulnerabilities in Windows CryptoAPI Could Allow Spoofing
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30616

Microsoft : Vulnerability in Indexing Service Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30617

Microsoft : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30618

Microsoft : Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30619

Microsoft : Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Cou
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30620

Microsoft : Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30621

Microsoft : Vulnerabilities in GDI+ Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30622

Mandriva : mono
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30602

Mandriva : mono
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30603

Mandriva : wireshark
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30604

Mandriva : libnasl
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30605

Mandriva : libmikmod
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30606

Mandriva : strongswan
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30607

Microsoft : Vulnerability in Windows Media Player Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30612

Microsoft : Cumulative Security Update of ActiveX Kill Bits
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30615

iDefense Security Advisory 10.13.09: Microsoft Office Drawing Format Shape Properties Memory Corrupt
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00106.html

iDefense Security Advisory 10.13.09: Microsoft Windows GDI+ TIFF File Parsing Buffer Overflow Vulner
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00105.html

ZDI-09-073: Adobe Reader Compact Font Format Malformed Index Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00101.html

iDefense Security Advisory 10.13.09: Adobe Acrobat and Reader Firefox Plugin Use After Free Vulnerab
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00102.html

iDefense Security Advisory 10.13.09: Adobe Acrobat and Reader U3D File Invalid Array Index Vulnerabi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00100.html

ZDI-09-072: Microsoft Windows GDI+ TIFF Parsing Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00103.html

ZDI-09-071: Microsoft Internet Explorer writing-mode Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00098.html

ZDI-09-070: Microsoft Internet Explorer Event Object Type Double-Free Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00104.html

ZDI-09-069: Microsoft Windows Media Player Audio Voice Sample Rate Memory Corruption Vulnera
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00099.html

[ MDVSA-2009:276 ] python-django
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00097.html

[G-SEC 46-2009] Computer Associates multiple products arbritary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00075.html

[ MDVSA-2009:275 ] python-django
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00077.html

[BONSAI] XSS in Achievo - Customized XSS payload included
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00096.html

[BONSAI] SQL Injection in Achievo
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00095.html

[ MDVSA-2009:274 ] phpmyadmin
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00094.html

[SECURITY] [DSA 1907-1] New kvm packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00093.html

Palm Pre WebOS version <= 1.1 Floating Point Exception http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00092.html

Quick Heal Local Privilege Escalation Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00091.html

[ MDVSA-2009:273 ] strongswan
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00090.html

[ MDVSA-2009:272 ] libmikmod
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00089.html

[ MDVSA-2009:271 ] libnasl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00087.html

[ MDVSA-2009:270 ] wireshark
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00088.html

[ MDVSA-2009:269 ] mono
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00086.html

[ MDVSA-2009:268 ] mono
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00085.html

DEDECMS v5.1 Sql Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00084.html

[SECURITY] [DSA 1906-1] End-of-life announcement for clamav in stable and oldstable
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00083.html

[SECURITY] [DSA 1905-1] New python-django packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00082.html

[ MDVSA-2009:267 ] xmlsec1
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00080.html

[ MDVSA-2009:266 ] awstats
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00079.html

[SECURITY] [DSA 1895-2] New opensaml2 and shibboleth-sp2 packages fix regression
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00078.html

[ MDVSA-2009:264 ] gd
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00076.html

[ MDVSA-2009:265 ] egroupware
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00074.html

[ MDVSA-2009:263 ] sympa
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00073.html

PUBLIC ADVISORY: 10.13.09: Adobe Acrobat and Reader Firefox Plugin Use After Free Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=826

PUBLIC ADVISORY: 10.13.09: Microsoft Windows GDI+ TIFF File Parsing Buffer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=828

PUBLIC ADVISORY: 10.13.09: Adobe Acrobat and Reader U3D File Invalid Array Index Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=827

PUBLIC ADVISORY: 10.13.09: Microsoft Office Drawing Format Shape Properties Memory Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=829

Microsoft Products GDI+ Multiple Vulnerabilities
http://secunia.com/advisories/37007/

Microsoft Local Security Authority Subsystem Denial of Service
http://secunia.com/advisories/37002/

Microsoft Windows Privilege Escalation and Denial of Service
http://secunia.com/advisories/37001/

Docebo Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/37019/

Debian update for kvm
http://secunia.com/advisories/37018/

httpdx Source Code Disclosure Vulnerability
http://secunia.com/advisories/37013/

Skype Extras Manager Unspecified Vulnerability
http://secunia.com/advisories/37012/

Sun Solaris Thunderbird Network Security Services Vulnerabilities
http://secunia.com/advisories/37009/

Microsoft Silverlight Common Language Runtime Vulnerability
http://secunia.com/advisories/37008/

Microsoft .NET Framework Multiple Vulnerabilities
http://secunia.com/advisories/37006/

Microsoft Office ActiveX Controls Multiple Vulnerabilities
http://secunia.com/advisories/37005/

VooDoo cIRCle XTelnet GnuTLS Unspecified Vulnerabilities
http://secunia.com/advisories/37004/

VooDoo cIRCle OpenSSL DTLS Denial of Service Vulnerabilities
http://secunia.com/advisories/37003/

Microsoft Indexing Service ActiveX Control Memory Corruption
http://secunia.com/advisories/37000/

Microsoft Windows CryptoAPI Two Spoofing Vulnerabilities
http://secunia.com/advisories/36999/

Microsoft Windows ActiveX Controls ATL "OleLoadFromStream()" Vulnerability
http://secunia.com/advisories/36997/

Dream Poll Cross-Site Scripting and SQL Injection Vulnerabilities
http://secunia.com/advisories/36990/

Microsoft Internet Explorer Multiple Vulnerabilities
http://secunia.com/advisories/36979/

RioRey RIOS Undocumented SSH Account Security Issue
http://secunia.com/advisories/36971/

Microsoft Windows Media Player ASF Processing Vulnerability
http://secunia.com/advisories/36944/

Microsoft Windows Media Runtime Code Execution Vulnerability
http://secunia.com/advisories/36938/

Adobe RoboHelp Server Arbitrary File Upload and Execute Vulnerability
http://www.securiteam.com/unixfocus/6P00B0UPPK.html

Microsoft Crypto API NULL Character Flaw in Common Name Field and ASN.1 Integer Overflow Lets Remote Users Spoof Certficiates
http://securitytracker.com/alerts/2009/Oct/1023013.html

Windows Media Player Heap Overflow in Processing ASF Files Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023012.html

Microsoft Indexing Service ActiveX Control Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023011.html

Microsoft Local Security Authority Subsystem Service (LSASS) Integer Underflow Lets Local Users Deny Service
http://securitytracker.com/alerts/2009/Oct/1023010.html

Microsoft Silverlight Memory Modification Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023009.html

Microsoft .NET Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023008.html

Adobe Acrobat and Adobe Reader Flaws Lets Remote Users Execute Arbitrary Code and Deny Service
http://securitytracker.com/alerts/2009/Oct/1023007.html

Microsoft GDI+ Overflows Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023006.html

Windows Media Format Runtime Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023005.html

Windows Server Message Block Validation Errors Let Remote Users Deny Service and Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023004.html

Windows Kernel Lets Local Users Gain Elevated Privileges or Deny Service
http://securitytracker.com/alerts/2009/Oct/1023003.html

Microsoft Internet Explorer Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1023002.html

Vulnerability Note VU#654545 Wyse Device Manager (WDM) HServer and HAgent contain multiple vulnerabilities
http://www.kb.cert.org/vuls/id/654545

Vulnerability Note VU#257117 Adobe Acrobat and Reader contain vulnerabilities in multiple Document Object JavaScript methods
http://www.kb.cert.org/vuls/id/257117

Cyber Security Awareness Month - Day 13 Proxies (TCP 3128, 8080 & ......)
http://isc.sans.org/diary.html?storyid=7339

Microsoft October 2009 Black Tuesday Overview
http://isc.sans.org/diary.html?storyid=7345

Adobe Reader and Acrobat - Black Tuesday continues
http://isc.sans.org/diary.html?storyid=7348

Adobe Reader and Acrobat Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/2898

Microsoft Products GDI Plus Code Execution Vulnerabilities (MS09-062)
http://www.vupen.com/english/advisories/2009/2897

Microsoft Windows .NET Framework Code Execution Vulnerabilities (MS09-061)
http://www.vupen.com/english/advisories/2009/2896

Microsoft Office Active Template Library Vulnerabilities (MS09-060)
http://www.vupen.com/english/advisories/2009/2895

Microsoft Windows LSASS Denial of Service Vulnerability (MS09-059)
http://www.vupen.com/english/advisories/2009/2894

Microsoft Windows Kernel Privilege Escalation Vulnerabilities (MS09-058)
http://www.vupen.com/english/advisories/2009/2893

Microsoft Windows Indexing Service ActiveX Vulnerability (MS09-057)
http://www.vupen.com/english/advisories/2009/2892

Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (MS09-056)
http://www.vupen.com/english/advisories/2009/2891

Microsoft Windows ATL COM Initialization Code Execution Vulnerability (MS09-055)
http://www.vupen.com/english/advisories/2009/2890

Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (MS09-054)
http://www.vupen.com/english/advisories/2009/2889

Microsoft Windows Media Player ASF Heap Overflow Vulnerability (MS09-052)
http://www.vupen.com/english/advisories/2009/2888

Microsoft Windows Media Runtime Code Execution Vulnerabilities (MS09-051)
http://www.vupen.com/english/advisories/2009/2887

Microsoft Windows SMBv2 Code Execution and DoS Vulnerabilities (MS09-050)
http://www.vupen.com/english/advisories/2009/2886

Skype Extras Manager Component Unspecified Vulnerability
http://www.vupen.com/english/advisories/2009/2885

VooDoo cIRCle XTelnet GnuTLS Unspecified Vulnerabilities
http://www.vupen.com/english/advisories/2009/2884

VooDoo cIRCle OpenSSL DTLS Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/2883

Sun Solaris Thunderbird SSL Code Execution and Spoofing Issues
http://www.vupen.com/english/advisories/2009/2882

RHBA-2009:1494-1: tcsh bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1494.html

RHBA-2009:1495-1: selinux-policy bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1495.html

Adobe Reader and Acrobat Compact Font Format Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36667

Adobe Reader and Acrobat October 2009 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/36638

Adobe Acrobat Stack Exhaustion Denial of Service Vulnerability
http://www.securityfocus.com/bid/35148

Adobe Reader and Acrobat COM Objects Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36668

Adobe Reader and Acrobat Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/36664

Adobe Reader and Acrobat U3D File Invalid Array Index Remote Vulnerability
http://www.securityfocus.com/bid/36665

Microsoft GDI+ Malformed Office Object Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36650

Adobe Reader Plugin Open Parameters Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/21858

Adobe Acrobat Reader Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36600

Microsoft Windows Kernel Exception Handler Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36625

Microsoft Indexing Service ActiveX Control Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36629

Microsoft Windows SMB2 Field Validation Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36595

Microsoft Windows SMB2 Command Value Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36594

Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36644

Microsoft Internet Explorer NULL Byte CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36475

Microsoft Internet Explorer 'writing-mode' Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36616

Microsoft GDI+ Malformed Office BMP File Integer Overflow Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36651

Microsoft XML Core Services DTD Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32155

Microsoft GDI+ TIFF File Processing Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36647

Microsoft Internet Explorer 'Event' Object Copy Constructor Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36620

Microsoft XML Core Services Transfer Encoding Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32204

Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36273

Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36189

Microsoft Visual Studio Active Template Library NULL String Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35830

Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35828

Microsoft Windows Media Runtime Speech Codec Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36614

Microsoft Internet Explorer 'deflate' HTTP Content Encoding Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36622

Microsoft Windows LSASS NTLM Implementation Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36593

Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35832

Microsoft GDI+ TIFF File Processing 'BitsPerSample' Tag Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36646

Django URL Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35859

Django 'EmailField' and 'URLField' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36655

NOS getPlus Download Manager Insecure File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35740

Microsoft Internet Explorer HTML Component Handling Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36621

Internet Explorer X.509 Certificate Common Name Encoding Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36577

Microsoft .NET Framework Pointer Verification Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36611

Microsoft .NET Framework Type Verification Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36617

Microsoft Silverlight and .NET Framework CLR Interface Handling Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36618

Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36299

ProFTPD Controls Module Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/21587

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

libmikmod Multiple Sound Channel Media Playback Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/33235

libmikmod '.XM' File Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/33240

Palm WebOS 'LunaSysMgr' Service Denial of Service Vulnerability
http://www.securityfocus.com/bid/36659

Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verification Vulnerability
http://www.securityfocus.com/bid/33151

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

Mono Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/30471

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314

Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36296

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/32608

Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36377

Wireshark 1.2.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36408

Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36249

FreeRADIUS Zero-length Tunnel-Password Attributes Denial of Service Vulnerability
http://www.securityfocus.com/bid/36263

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

SILC Toolkit 'command.c' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/36193

SILC Toolkit HTTP Server Format String Vulnerability
http://www.securityfocus.com/bid/36194

SILC Toolkit Encoded OID Format String Vulnerability
http://www.securityfocus.com/bid/36192

SILC Client Format String Vulnerability
http://www.securityfocus.com/bid/35940

SILC Client Format String Vulnerability
http://www.securityfocus.com/bid/35940

Sun Java SE Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35922

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35943

Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35942

Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35939

Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35944

Computer Associates Anti-Virus Engine 'arclib' Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36653

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36596

Sun VirtualBox VBoxNetAdpCtl Configuration Tool Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36604

QEMU VNC 'monitor.c' Insecure Password Vulnerability
http://www.securityfocus.com/bid/33020

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35417

OpenSSL DTLS Packets Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35001

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35138

Dream Poll Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/36663

Quick Heal AntiVirus Insecure Program File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36662

Achievo Multiple Cross Site Scripting and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/36661

Achievo 'dispatch.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/36660

Microsoft GDI+ PNG File Integer Overflow Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36649

Microsoft GDI+ .NET Framework Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36648

Microsoft GDI+ PNG File Processing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36645

Microsoft Windows Kernel NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36624

Microsoft Windows Kernel Integer Underflow Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36623

Microsoft GDI+ WMF File Processing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36619

Microsoft Windows Media Runtime File Compression Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36602

0 件のコメント:

コメントを投稿