2009年11月26日木曜日

26日 木曜日、先勝

JVNVU#515749 Microsoft Internet Explorer に脆弱性
http://jvn.jp/cert/JVNVU515749/index.html

JVNDB-2009-002268 Oracle Database の Oracle Spatial コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002268.html

JVNDB-2009-002267 Oracle Database の Data Mining コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002267.html

JVNDB-2009-002266 Oracle Database の Network Authentication コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002266.html

JVNDB-2009-002265 Oracle Database の Network Authentication コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002265.html

JVNDB-2009-002264 Oracle Database の Core RDBMS コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002264.html

Solaris ldap_cachemgr() Flaws Let Local Users Deny Service
http://securitytracker.com/alerts/2009/Nov/1023239.html

Sun Solaris ldap_cachemgr Local Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/3336

Sun Solaris BIND DNSSEC Validation DNS Cache Poisoning
http://www.vupen.com/english/advisories/2009/3335

Sun OpenSolaris Security Update Fixes Firefox Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2009/3334

Sun Solaris Timeout Mechanism Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3333

Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37085

Mozilla Firefox 'document.getSelect' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36858

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Mozilla Firefox CVE-2009-3382 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36866

Mozilla Firefox CVE-2009-3377 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36872

Mozilla Firefox CVE-2009-3378 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36873




+ Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273169-1

+ Denial of Service Vulnerabilities in ldap_cachemgr(1M) Daemon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-231402-1
http://www.securityfocus.com/bid/37129

+ HPSBUX02482 SSRT090249 rev.1 - HP-UX Running OpenSSL, Remote Unauthorized Data Injection, Denial of Service (DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01945686-1

+ Internet Explorer PDF Export Information Disclosure
http://secunia.com/advisories/37362/

+ Linux Kernel KVM Large SMP Instruction Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/37130

[ANNOUNCE] MyJSQLView Version 3.05 Released
http://dandymadeproductions.com/projects/MyJSQLView/index.html

[ANNOUNCE] Apache Jackrabbit 2.0 beta3 released
http://jackrabbit.apache.org/downloads.html

[ANNOUNCE] PostgreSQL RPM packages for Fedora-12 released
http://yum.pgsqlrpms.org/howtoyum.php

Multiple Security Vulnerabilities in Firefox Versions Before 3.5.5 May Allow Execution of Arbitrary Code or Unauthorized Access to Certain Data
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272909-1

A Solaris Kernel Change Stops Sun Cluster Using "zpool.cachefiles" to Import zpools Resulting in ZFS pool Import Performance Degradation or Failure to Import the zpools
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272669-1

Gentoo Linux : UW IMAP toolkit: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30983

Gentoo Linux : dstat: Untrusted search path
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30984

Red Hat : Critical: kdelibs security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30978

Debian : New libvorbis packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30977

[ GLSA 200911-05 ] Wireshark: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00176.html

[resent] [ GLSA 200911-04 ] dstat: Untrusted search path
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00175.html

[ GLSA 200911-03 ] UW IMAP toolkit: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00174.html

rPSA-2009-0156-1 sun-jdk sun-jre
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00172.html

rPSA-2009-0155-1 httpd mod_ssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00170.html

rPSA-2009-0154-1 httpd mod_ssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00171.html

[SECURITY] [DSA 1939-1] New libvorbis packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00169.html

Vulnerabilities in WP-Cumulus for WordPress
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00168.html

[security bulletin] HPSBMA02417 SSRT090031 rev.2 - HP Data Protector Express and HP Data Protect
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00167.html

Microsoft Updates requiring reboot
http://isc.sans.org/diary.html?storyid=7645

Updates to my GREM Gold scripts and a new script
http://isc.sans.org/diary.html?storyid=7648

libtool libltdl Library Search Path Privilege Escalation Security Issue
http://secunia.com/advisories/37489/

Gentoo update for uw-imap and c-client
http://secunia.com/advisories/37487/

rPath update for httpd and mod_ssl
http://secunia.com/advisories/37486/

rPath update for sun-jdk and sun-jre
http://secunia.com/advisories/37485/

OpenX Arbitrary File Upload Vulnerability
http://secunia.com/advisories/37475/

Firefox Yoono Extension Cross-Context Scripting Vulnerability
http://secunia.com/advisories/37468/

Debian update for libvorbis
http://secunia.com/advisories/37463/

Symantec Altiris ConsoleUtilities ActiveX Control "RunCmd()" Buffer Overflow
http://secunia.com/advisories/37462/

Red Hat update for kdelibs
http://secunia.com/advisories/37461/

ISC BIND DNSSEC Cache Poisoning Vulnerability
http://secunia.com/advisories/37426/

Sun Solaris sshd Timeout Mechanism Denial of Service
http://secunia.com/advisories/37424/

Quick.CMS "admin.php" Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/37421/

libtool libltdl Library Search Path Privilege Escalation Security Issue
http://secunia.com/advisories/37414/

Ubuntu update for libvorbis
http://secunia.com/advisories/37411/

Internet Explorer PDF Export Information Disclosure
http://secunia.com/advisories/37362/

HP Operations Manager for Windows Unauthorized Access
http://www.securiteam.com/unixfocus/6G00L1FQ0E.html

PHP Multipart/Form-data Denial of Service Attack
http://www.securiteam.com/unixfocus/6H00M1FQ0G.html

KDE KDELibs Remote Array Overrun with Arbitrary Code Execution
http://www.securiteam.com/securitynews/6I00N1FQ0S.html

HP Color LaserJet Printers Unauthorized Access to Data and DoS
http://www.securiteam.com/securitynews/6J00O1FQ0G.html

Mozilla Firefox CVE-2009-3381 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36870

Mozilla Firefox CVE-2009-3383 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36869

Wireshark 1.2.2 and 1.0.9 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36846

Wireshark ERF File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36591

Wireshark 1.2.0 Multiple Vulnerabilities
http://www.securityfocus.com/bid/35748

Home FTP Server 'MKD' Command Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37041

PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/37079

Wireshark 1.2.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36408

University of Washington IMAP c-client Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/32958

University of Washington IMAP 'smtp.c' Null Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/32280

University of Washington IMAP 'tmail' and 'dmail' Local Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/32072

PEAR Net_Ping 'ping()' Function Arbitrary Argument Injection Vulnerability
http://www.securityfocus.com/bid/37093

PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
http://www.securityfocus.com/bid/37094

Python 'Imageop' Module Argument Validation Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31932

RETIRED: Python Imageop Module 'imageop.crop()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31976

HP Data Protector Express 'dpwinsup.dll' Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34955

Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35927

libvorbis OGG Vorbis Processing Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36018

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache 'mod_deflate' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35623

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35510

Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36850

Quick.Cart and Quick.CMS Delete Function Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/37115

TYPSoft FTP Server 'APPE' and 'DELE' Commands Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37114

Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37131

XM Easy Personal FTP Server File/Folder Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37112

Subscribe to Comments Prior to 2.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/37111

klinza professional cms 'menulast.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/37127

WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/37100

ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/37118

Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/37129

Linux Kernel KVM Large SMP Instruction Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/37130

Mozilla Firefox Form History Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36853

Mozilla Firefox Download Manager World Writable File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36852

Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37092

Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36856

Mozilla Firefox and SeaMonkey 'libpr0n' GIF Parser Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36855

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Mozilla Firefox JavaScript Web-Workers Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36854

Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37085

Mozilla Firefox XPCOM Utility Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36857

Mozilla Firefox 'document.getSelect' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36858

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Mozilla Firefox CVE-2009-3377 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36872

Mozilla Firefox CVE-2009-3382 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36866

Mozilla Firefox CVE-2009-3378 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36873

GNU Libtool 'libltdl' Library Search Path Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37128

Microsoft Windows Media Components ISATAP URL Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/32654

Microsoft Windows Media Components 'Service Principle Name' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/32653

0 件のコメント:

コメントを投稿