2009年11月11日水曜日

11日 火曜日、先負

JVNDB-2009-002206 IBM AIX の libcsa.a におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002206.html

JVNDB-2009-002205 Wireshark の erf ファイル処理に脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002205.html

JVNDB-2009-002204 APR ライブラリの Solaris pollset 機能におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002204.html

JVNDB-2009-002203 ZODB の ZEO ストレージサーバ機能における任意のファイルを閲覧/削除される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002203.html

JVNDB-2009-002202 Xen の pyGrub ブートローダにおけるゲストの Kernel ブートパラメータを改ざん可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002202.html

JVNDB-2009-001892 Apache httpd の mod_deflate モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001892.html

JVNDB-2009-001884 Apache HTTP Server の mod_proxy におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001884.html

JVNDB-2009-001170 JDK および JRE の Java プラグインにおけるセキュリティ警告文を非表示にされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001170.html

JVNDB-2009-001169 JDK および JRE の Java プラグインにおける crossdomain.xml ファイル の処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001169.html

JVNDB-2009-001168 JDK および JRE の Java プラグインにおける古い JRE バージョンで動作可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001168.html

JVNDB-2009-001167 JDK および JRE の Java プラグインにおけるアクセス制限を回避可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001167.html

JVNDB-2009-001166 JDK および JRE の Java プラグインにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001166.html

JVNDB-2009-001163 JDK および JRE における一時フォントファイルの処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001163.html

JVNDB-2009-001162 JDK および JRE の lightweight HTTP サーバ実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001162.html

JVNDB-2009-001161 JDK および JRE の仮想マシンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001161.html

Postfix 2.7 Snapshot 20091110
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.7-20091110.HISTORY

Rdbhost provides SQL databases (PostgreSQL) via Web Service
http://www.postgresql.org/about/news.1155

Tryton 1.4 is available
http://www.postgresql.org/about/news.1154

PostgreSQL Native OLEDB Provider (PGNP) 1.3.0 32/64-bit released!
http://www.postgresql.org/about/news.1153

CTX123359: Transport Layer Security Renegotiation Vulnerability
http://support.citrix.com/article/CTX123359

CTX123248: Vulnerability in Citrix Online Plug-ins and ICA Clients Could Result in SSL/TLS Certificate Spoofing
http://support.citrix.com/article/CTX123248

Restarting the Management agents on an ESX or ESXi Server
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1003490&sliceId=1&docTypeID=DT_KB_1_1

偽造カードで900万ドル,コンピュータ不正侵入の国際グループを起訴
http://itpro.nikkeibp.co.jp/article/NEWS/20091111/340364/?ST=security

JVNTA09-314A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-314A/index.html

Layer 2 Network Protections against Man in the Middle Attacks
http://isc.sans.org/diary.html?storyid=7567

HP NonStop Server Unspecified Flaw in OSS Name Server Lets Remote Authenticated Users Access Data
http://securitytracker.com/alerts/2009/Nov/1023159.html

Microsoft Word Memory Corruption Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Nov/1023158.html

Free Download Manager Torrent File Parsing Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/33555




+ Dovecot 1.1.20, 1.2.7 released
http://www.dovecot.org/list/dovecot-news/2009-November/000141.html
http://www.dovecot.org/list/dovecot-news/2009-November/000142.html

+ Linux kernel 2.6.27.39, 2.6.31.6 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.39
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.6

+ マイクロソフト2009 年 11 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms09-nov.mspx

+ MS09-064 - 緊急:ライセンス ログ サーバーの脆弱性により、リモートでコードが実行される (974783)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-064.mspx
http://www.securityfocus.com/bid/36921

+ MS09-065 - 緊急:Windows カーネル モード ドライバーの脆弱性により、リモートでコードが実行される (969947)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-065.mspx
http://www.securityfocus.com/bid/36029
http://www.securityfocus.com/bid/36939
http://www.securityfocus.com/bid/36941

+ MS09-066 - 重要:Active Directory の脆弱性により、サービス拒否が起こる (973309)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-066.mspx
http://www.securityfocus.com/bid/36918

+ MS09-067 - 重要:Microsoft Office Excel の脆弱性により、リモートでコードが実行される (972652)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-067.mspx
http://www.securityfocus.com/bid/36945
http://www.securityfocus.com/bid/36943
http://www.securityfocus.com/bid/36911
http://www.securityfocus.com/bid/36909
http://www.securityfocus.com/bid/36908
http://www.securityfocus.com/bid/36946
http://www.securityfocus.com/bid/36944
http://www.securityfocus.com/bid/36912

+ MS09-068 - 重要:Microsoft Office Word の脆弱性により、リモートでコードが実行される (976307)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-068.mspx
http://www.securityfocus.com/bid/36950

+ RHSA-2009:1572-1: Moderate: 4Suite security update
http://rhn.redhat.com/errata/RHSA-2009-1572.html

OpenSSL 1.0.0 beta4 release
http://www.openssl.org/

[ANN] Solr 1.4.0 Released
http://www.apache.org/dyn/closer.cgi/lucene/solr/

[ANNOUNCE] Apache PyLucene 2.9.1
http://svn.apache.org/repos/asf/lucene/pylucene/tags/pylucene_2_9_1/CHANGES

SUN ALERT WEEKLY SUMMARY REPORT - Week of 01-Nov-2009 to 07-Nov-2009
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272469-1

MS09-063 - 緊急:Web Services on Devices API の脆弱性により、リモートでコードが実行される (973565)
http://www.microsoft.com/japan/technet/security/bulletin/MS09-063.mspx

HPSBNS02443 SSRT090109: rev.1 - HP NonStop Server Running OSS Name Server, Unauthorized Access to Data
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01845977-1&docLocale=en&admit=109447627+1257903110312+28353475

個人のお客様向け「チャットサポート」
サーバメンテナンスにともなうサービス停止のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1318

Debian : New cups packages fix cross-site scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30846

Microsoft : Vulnerability in Web Services on Devices API Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30856

Microsoft : Vulnerability in License Logging Server Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30857

Microsoft : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30858

Microsoft : Vulnerability in Active Directory Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30859

Microsoft : Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30860

Microsoft : Vulnerability in Microsoft Office Word Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30861

Apple : Security Update 2009-006 / Mac OS X v10.6.2
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30845

Cisco : Transport Layer Security Renegotiation Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30852

Independent Researcher : Apache Tomcat Windows Installer insecure default administrative password
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30854

Red Hat : Low: Red Hat Enterprise Linux 3 - 1-Year End Of Life Notice
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30847

Red Hat : Critical: java-1.6.0-sun security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30848

Red Hat : Important: libvorbis security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30849

Red Hat : Important: tomcat security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30850

Red Hat : Important: tomcat security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30851

US-CERT Technical Cyber Security Alert TA09-314A -- Microsoft Updates for Multiple V
http://www.derkeiler.com/Mailing-Lists/Cert/2009-11/msg00001.html

iDefense Security Advisory 11.10.09: Microsoft Excel FEATHEADER Record Memory Corruption Vulnerabili
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00080.html

iDefense Security Advisory 11.10.09: Microsoft Word FIB Processing Stack Buffer Overflow Vulnerabili
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00081.html

ZDI-09-083: Microsoft Excel Shared Feature Header Pointer Offset Memory Corruption Vulnerabi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00079.html

ZDI-09-082: Microsoft Office Excel PivotTable Cache Record Parsing Memory Corruption Vulnera
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00078.html

TPTI-09-07: Microsoft Windows License Logging Service Heap Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00077.html

[security bulletin] HPSBUX02476 SSRT090250 rev.1 - HP-UX Running Java, Remote Increase in Pr
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00074.html

[USN-857-1] Qt vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00070.html

[USN-856-1] CUPS vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00071.html

Atheros Driver Reserved Frame Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00069.html

Marvell Driver Multiple Information Element Overflows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00073.html

[MORNINGSTAR-2009-02] Multiple security issues in Cute News and UTF-8 Cute News
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00072.html

XM Easy Personal FTP Server LIST Command Remote DoS Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00076.html

[SECURITY] [DSA 1933-1] New cups packages fix cross-site scripting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00075.html

PUBLIC ADVISORY: 11.10.09: Microsoft Word FIB Processing Stack Buffer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=831

PUBLIC ADVISORY: 11.10.09: Microsoft Excel FEATHEADER Record Memory Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=832

Googleの「セサミストリート」ロゴに便乗、偽ソフトの新手口
SEOを駆使して配布サイトが上位に、検索結果は“地雷原”?
http://itpro.nikkeibp.co.jp/article/NEWS/20091111/340380/?ST=security

TippingPoint,スループットが低下しにくいIPSアプライアンスを発売
http://itpro.nikkeibp.co.jp/article/NEWS/20091110/340360/?ST=security

Microsoft November Black Tuesday Overview
http://isc.sans.org/diary.html?storyid=7564

Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities
http://secunia.com/advisories/37318/

Windows Web Services on Devices API Memory Corruption Vulnerability
http://secunia.com/advisories/37314/

Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
http://secunia.com/advisories/37313/

Microsoft Windows License Logging Server Buffer Overflow
http://secunia.com/advisories/37311/

Debian update for cups
http://secunia.com/advisories/37310/

Microsoft Windows Win32k Kernel-Mode Driver Privilege Escalation
http://secunia.com/advisories/37309/

CUPS "kerberos" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37308/

SUSE Update for Multiple Packages
http://secunia.com/advisories/37307/

Red Hat update for libvorbis
http://secunia.com/advisories/37306/

Red Hat update for java-1.6.0-sun
http://secunia.com/advisories/37305/

Microsoft Windows Active Directory Denial of Service
http://secunia.com/advisories/37304/

HP-UX update for JRE / JDK
http://secunia.com/advisories/37300/

Microsoft Excel Multiple Vulnerabilities
http://secunia.com/advisories/37299/

Red Hat update for tomcat
http://secunia.com/advisories/37281/

Spam Inspector EasyMail SMTP Object ActiveX Control Vulnerability
http://secunia.com/advisories/37278/

Microsoft Office Word File Information Memory Corruption Vulnerability
http://secunia.com/advisories/37277/

Oracle Document Capture EasyMail ActiveX Control Vulnerabilities
http://secunia.com/advisories/37269/

Microsoft Excel Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Nov/1023157.html

Microsoft Active Directory Stack Memory Consumption Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Nov/1023156.html

Windows Kernel 'Win32k.sys' Bugs Let Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Nov/1023155.html

Microsoft License Logging Service Buffer Overflow Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Nov/1023154.html

Microsoft Web Services on Devices API (WSDAPI) Validation Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Nov/1023153.html

Mac OS X Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Nov/1023149.html

Cisco Products Protocol Flaw in SSL Renegotiation May Let Remote Users Conduct Man-in-the-Middle Attacks
http://securitytracker.com/alerts/2009/Nov/1023148.html

EXCLUSIVE VIDEO: Zaki Qureshey boasting having helped Kuwait US Embassy to hack Iraqi networks
http://www.zone-h.org/news/id/4729

Microsoft Office Word File Information Memory Corruption (MS09-068)
http://www.vupen.com/english/advisories/2009/3194

Microsoft Office Excel Multiple Code Execution Vulnerabilities (MS09-067)
http://www.vupen.com/english/advisories/2009/3193

Microsoft Windows Active Directory Denial of Service Vulnerability (MS09-066)
http://www.vupen.com/english/advisories/2009/3192

Microsoft Windows Kernel-Mode Drivers Code Execution (MS09-065)
http://www.vupen.com/english/advisories/2009/3191

Microsoft Windows License Logging Heap Overflow (MS09-064)
http://www.vupen.com/english/advisories/2009/3190

Microsoft Windows WSDAPI Memory Corruption Vulnerabiliy (MS09-063)
http://www.vupen.com/english/advisories/2009/3189

IBM BladeCenter Advanced Management Module Vulnerabilities
http://www.vupen.com/english/advisories/2009/3188

HP-UX Security Update Fixes Java Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/3186

Apache Tomcat Windows Installer Default Password Weakness
http://www.vupen.com/english/advisories/2009/3185

Microsoft Windows WSDAPI code execution
http://www.iss.net/threats/353.html

Microsoft Windows kernel font code execution
http://www.iss.net/threats/354.html

Apple Mac OS X IOKit Keyboard Firmware Local Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/36979

Drupal Cross-Site Scripting, Code Injection and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35548

Apple Mac OS X Help Viewer Spoofed HTTP Response Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36977

Apple Mac OS X FTP Server CWD Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36975

Apple Mac OS X Disk Images FAT Filesystem Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36973

Apple Mac OS X CDF File Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36974

Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36921

Microsoft Excel 'FEATHEADER' Record Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36945

Apple Mac OS X DirectoryService Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36972

XOOPS Versions Prior to 2.4.0 Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/36955

Microsoft Excel 'PivotTable' Cache Record Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36943

Microsoft Windows Embedded OpenType Font Engine Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36029

Microsoft Excel Document Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36911

Microsoft Word Record Parsing Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36950

Microsoft Excel Index Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36909

Microsoft Excel Formula Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36908

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

Microsoft Excel Malformed BIFF Record Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36946

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36097

ISC DHCP Server Host Definition Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35669

ISC DHCP 'dhclient' 'script_write_params()' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35668

Microsoft Excel 'SxView' Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36944

Microsoft Excel Field Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36912

WordPress MU 'wp-includes/wpmu-functions.php' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/34075

WordPress 'wp-admin/admin.php' Module Configuration Security Bypass Vulnerability
http://www.securityfocus.com/bid/35584

Microsoft JScript Scripting Engine Keyword Arguments Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36224

Microsoft Active Directory LDAP Request Stack Exhaustion Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36918

Microsoft Windows Web Services on Devices API Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36919

CamlImages JPEG Handling Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36713

libvorbis OGG Vorbis Processing Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36018

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Microsoft Windows Kernel NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36939

Microsoft Windows Kernel GDI Data Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36941

Apple Mac OS X 2009-006 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36956

Apple Mac OS X AFP Client Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/36961

Apple Mac OS X Event Monitor Log Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36966

Apple Mac OS X Spotlight Insecure Temporary File Handling Vulnerability
http://www.securityfocus.com/bid/36967

Apple Mac OS X Screen Sharing Client Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/36964

Apple Mac OS X Adaptive Firewall Security Bypass Vulnerability
http://www.securityfocus.com/bid/36963

WebKit 'Document()' Function Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35284

WebKit DOM Event Handler Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35271

WebKit 'Attr' DOM Objects Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35310

WebKit Java Applet Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35350

WebKit Numeric Character References Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35607

WebKit SVGList Objects Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34924

WebKit CSS 'Attr' Function Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35318

WebKit JavaScript Garbage Collector Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35309

WebKit XML External Entity Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35321

Apple Mac OS X CoreGraphics Multiple Heap-Overflow Vulnerabilities
http://www.securityfocus.com/bid/36962

HP Power Manager Management Web Server Login Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36933

CUPS 'kerberos' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36958

JForJoomla JReservation Joomla! Component 'pid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36446

Apple Mac OS X Apple Type Services Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36959

Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities
http://www.securityfocus.com/bid/36328

Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36377

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

FreeRADIUS Zero-length Tunnel-Password Attributes Denial of Service Vulnerability
http://www.securityfocus.com/bid/36263

Xpdf Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36703

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34412

strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35452

Neon 'ne_xml*' expat XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36080

EasyMail Objects EMSMTP.DLL ActiveX Control Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/25467

Poppler 'create_surface_from_thumbnail_data()' Integer Overflow Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36718

Wireshark ERF File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36591

Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35943

Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35939

Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35944

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35942

JNLPAppletLauncher Arbitrary File Creation Vulnerability
http://www.securityfocus.com/bid/35946

Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35769

Mozilla Firefox CVE-2009-3378 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36873

Mozilla Firefox CVE-2009-3377 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36872

Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36856

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox XPCOM Utility Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36857

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Mozilla Firefox and SeaMonkey 'libpr0n' GIF Parser Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36855

Poppler 'ABWOutputDev.cc' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36976

CuteNews and UTF-8 CuteNews Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36971

IBM BladeCenter Advanced Management Module Multiple Unspecified Security Vulnerabilities
http://www.securityfocus.com/bid/36970

XM Easy Personal FTP Server 'LIST' Command Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36969

0 件のコメント:

コメントを投稿