2009年12月10日木曜日

10日 木曜日、先負

トレンドマイクロURLフィルタリングエンジンにおける脆弱性および脆弱性に対する修正プログラムの提供について
http://www.trendmicro.co.jp/support/news.asp?id=1330

ウェブサイトで利用されているDNSサーバの既知の脆弱性への注意喚起
http://www.ipa.go.jp/security/vuln/documents/2009/200912_dns.html

JVNTA09-343A Adobe Flash に複数の脆弱性
http://jvn.jp/cert/JVNTA09-343A/

JVNTA09-342A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-342A/

JVN#79762947 EC-CUBE における情報漏えいの脆弱性
http://jvn.jp/jp/JVN79762947/

JVNVU#568372 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/cert/JVNVU568372/

Veritas Cluster Server Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023313.html

Symantec Veritas NetBackup Manager Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023312.html

Symantec Backup Exec Continuous Protection Server Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023311.html

Symantec Veritas Storage Foundation Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023309.html

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

VLC Media Player RTSP Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37236

Achievo Scheduler Category HTML Injection Vulnerability
http://www.securityfocus.com/bid/37220

Achievo Document Types Section Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/37219

Adobe Flash Player ActiveX Control Information Disclosure Vulnerability
http://www.securityfocus.com/bid/37272

Adobe Flash Player and AIR (CVE-2009-3797) Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37273

Adobe Flash Player and AIR Multiple Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/37269

Adobe Flash Player and AIR JPEG File Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37266

Adobe Flash Player and AIR (CVE-2009-3798) Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37275

JBoss Enterprise Application Platform Multiple Vulnerabilities
http://www.securityfocus.com/bid/37276




+ HPSBUX02480 SSRT090253 rev.1 - HP-UX Running VRTSweb, Remote Execution of Arbitrary Code, Increase of Privilege
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01943614

+ iptables 1.4.6 released
http://www.iptables.org/news.html#
http://www.iptables.org/projects/iptables/files/changes-iptables-1.4.6.txt

+ Security Advisories Relating to Symantec Products - Symantec Veritas VRTSweb remote code execution, escalation of privilege
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091209_00

- Linux Kernel 'ip_frag_reasm() ' Null Pointer Deference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37231

Thunderbird 3.0 released
http://mozilla.jp/thunderbird/3.0/releasenotes/

[ntp:announce] NTP 4.2.6-RC Released
http://support.ntp.org/

HPSBMA02477 SSRT090177 rev.3 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01926980

HPSBMA02483 SSRT090257 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01950877

Document ID: 338335: New disks are not available to use with SFW on Windows 2008
http://support.veritas.com/docs/338335

Fortinet : Fortinet Advisory: Fortinet Discovers Adobe Flash Player Multiple Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31173

Mandriva : ntp
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31154

SektionEins GmbH : Advisory 02/2009: PHPIDS Unserialize() Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31174

SektionEins GmbH : Advisory 03/2009: Piwik Cookie unserialize() Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31175

Ubuntu Security Notice : GRUB 2 vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31156

Computer Associates : Security Notice for CA Service Desk
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31170

Debian : New ntp packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31158

Fortinet : Fortinet Advisory: Fortinet Discovers Microsoft Office Project Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31171

Fortinet : Fortinet Advisory: Fortinet Discovers Vulnerability in Indeo Codec
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31172

「Flash Player」に新たな脆弱性が発覚、攻撃に悪用される危険性大
ファイルを開くだけで被害の恐れ、最新版へのアップデートを
http://itpro.nikkeibp.co.jp/article/NEWS/20091210/341876/?ST=security

WindowsやIEなどの「緊急」パッチが3件、ゼロデイ脆弱性にも対応
「重要」のセキュリティ情報も3件、「できるだけ早期に適用を」
http://itpro.nikkeibp.co.jp/article/NEWS/20091210/341875/?ST=security

JVNVU#568372 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/cert/JVNVU568372/index.html

JVNTA09-342A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA09-342A/index.html

JVNVU#261869 複数の SSL VPN (Web VPN) 製品においてウェブブラウザのセキュリティが迂回される
http://jvn.jp/cert/JVNVU261869/index.html

JVNDB-2009-002307 Mozilla Firefox におけるフォーム履歴を読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002307.html

JVNDB-2009-002306 Mozilla Firefox における Web ページ上で選択された文字列を読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002306.html

JVNDB-2009-002305 Mozilla Firefox/SeaMonkey における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002305.html

JVNDB-2009-002304 Mozilla Firefox におけるダウンロードファイルを置き換えられる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002304.html

JVNDB-2009-002303 Mozilla Firefox/SeaMonkey における意図しないファイルをダウンロードさせられる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002303.html

JVNDB-2009-002302 複数の VMware 製品におけるページフォールトの例外処理における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002302.html

JVNDB-2009-002301 複数の VMware 製品におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002301.html

JVNDB-2009-002300 Sun Solaris の Solaris Trusted Extensions Policy 設定における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002300.html

PUBLIC ADVISORY: 12.08.09: Microsoft Internet Explorer HTML Layout Engine Uninitialized Memory Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=833

PUBLIC ADVISORY: 12.08.09: Microsoft WordPad Word97 Converter Integer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=834

PUBLIC ADVISORY: 12.08.09: Microsoft Windows Indeo32 Codec Parsing Heap Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=835

ZDI-09-098: Symantec Multiple Products VRTSweb.exe Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00173.html

TPTI-09-14: HP OpenView NNM ovwebsnmpsrv.exe OVwSelection Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00171.html

TPTI-09-13: HP OpenView NNM snmpviewer.exe CGI Host Header Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00170.html

TPTI-09-12: HP OpenView NNM ovalarm.exe CGI Accept-Language Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00169.html

TPTI-09-11: HP OpenView NNM OvWebHelp.exe CGI Topic Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00168.html

TPTI-09-10: HP OpenView NNM webappmon.exe CGI Host Header Buffer Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00167.html

TPTI-09-09: HP OpenView NNM ovsessionmgr.exe userid/passwd Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00166.html

TPTI-09-08: HP OpenView NNM ovlogin.exe CGI userid/passwd Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00165.html

ZDI-09-096: Hewlett-Packard OpenView NNM nnmRptConfig.exe Template Variable vsprintf Ove
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00159.html

ZDI-09-095: Hewlett-Packard OpenView NNM Snmp.exe Oid Variable Buffer Overflow Vulnerabi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00164.html

ZDI-09-097: Hewlett-Packard OpenView NNM nnmRptConfig.exe Template Variable strcat Overf
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00162.html

ZDI-09-094: Hewlett-Packard OpenView NNM Multiple Command Injection Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00158.html

ZDI-09-093: Adobe Flash Player ActionScript Exception Handler Integer Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00146.html

ZDI-09-092: Adobe Flash Player JPEG Parsing Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00148.html

[security bulletin] HPSBUX02495 SSRT090151 rev.1 - HP-UX Running sendmail, Remote Denial of
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00140.html

Zen Cart local file disclosure vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00154.html

Advisory 03/2009: Piwik Cookie unserialize() Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00152.html

Advisory 02/2009: PHPIDS Unserialize() Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00157.html

IPB v2.x up to 3.0.4 XSS vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00150.html

UPDATE: DISA Unix SRR root compromise / CVE-2009-4211 / VU#433821
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00151.html

[ MDVSA-2009:328 ] ntp
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00161.html

[USN-868-1] GRUB 2 vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00160.html

ZDI-09-091: Hewlett-Packard Application Recovery Manager MSG_PROTOCOL Stack Overflow Vul
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00143.html

[USN-867-1] Ntp vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00153.html

Fortinet Advisory: Fortinet Discovers Vulnerability in Indeo Codec
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00145.html

[ MDVSA-2009:276-1 ] python-django
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00155.html

Fortinet Advisory: Fortinet Discovers Microsoft Office Project Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00149.html

[ MDVSA-2009:030-1 ] amarok
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00172.html

[ MDVSA-2009:038-1 ] blender
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00139.html

[ MDVSA-2009:046-1 ] dia
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00142.html

Notepad++ buffer overflow issue
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00144.html

[ MDVSA-2009:059-1 ] xchat
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00156.html

[ MDVSA-2009:091-1 ] mod_perl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00137.html

ZDI-09-090: Microsoft Windows Intel Indeo Codec Parsing Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00147.html

ZDI-09-089: Microsoft Windows Intel Indeo Codec Parsing Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00135.html

ZDI-09-088: Microsoft Internet Explorer IFrame Attributes Circular Reference Dangling Pointe
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00163.html

ZDI-09-087: Microsoft Internet Explorer CSS Race Condition Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00141.html

ZDI-09-086: Microsoft Internet Explorer XHTML DOM Manipulation Memory Corruption Vulnerabili
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00136.html

[ MDVSA-2009:093-1 ] mpg123
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00138.html

ntpd upgrade to prevent spoofed looping
http://isc.sans.org/diary.html?storyid=7717

OSSEC 2.3 released
http://isc.sans.org/diary.html?storyid=7723
http://www.ossec.net/main/ossec-v23-released

Facebook announces privacy improvements
http://isc.sans.org/diary.html?storyid=7726

Vulnerability Note VU#433821 DISA UNIX SRR scripts execute untrusted programs as root
http://www.kb.cert.org/vuls/id/433821

CA Service Desk Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37655/

IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
http://secunia.com/advisories/37653/

Piwik "unserialize()" PHP Code Execution
http://secunia.com/advisories/37649/

Webmin / Usermin Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37648/

Red Hat update for java-1.5.0-ibm
http://secunia.com/advisories/37646/

GNU Core Utilities "distcheck" Insecure Temporary Directory Security Issue
http://secunia.com/advisories/37645/

Red Hat update for libtool
http://secunia.com/advisories/37644/

Red Hat update for ntp
http://secunia.com/advisories/37643/

PHPIDS "unserialize()" PHP Code Execution
http://secunia.com/advisories/37642/

Ubuntu update for ntp
http://secunia.com/advisories/37639/

Debian update for ntp
http://secunia.com/advisories/37636/

Red Hat update for ntp
http://secunia.com/advisories/37634/

Ubuntu update for grub2
http://secunia.com/advisories/37632/

NTP Mode 7 Request Denial of Service
http://secunia.com/advisories/37629/

SEIL Routers PPP Access Concentrator Replay Vulnerability
http://secunia.com/advisories/37628/

AlefMentor Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/37626/

IBM Java 6 Denial of Service Vulnerabilities
http://secunia.com/advisories/37625/

IBM Java Denial of Service Vulnerabilities
http://secunia.com/advisories/37613/

Viscacha Multiple Script Insertion Vulnerabilities
http://secunia.com/advisories/37608/

HP Application Recovery Manager "MSG_PROTOCOL" Buffer Overflow
http://secunia.com/advisories/37600/

Adobe Flash Player Multiple Vulnerabilities
http://secunia.com/advisories/37584/

IBM Java Multiple Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/3458

Webmin and Usermin Unspecified Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/3457

Adobe Flash Player and AIR Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2009/3456

Moodle Multiple Input Validation and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/3455

HP Application Recovery Manager Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/3454

Coreutils "distcheck" Insecure Temporary Directory Permissions Issue
http://www.vupen.com/english/advisories/2009/3453

CA Service Desk Unspecified Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/3452

NTP Mode 7 Packets Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3441

THOMSON TG585n 7.4.3.2 (user.ini) Arbitrary Download Vulnerability
http://www.exploit-db.com/exploits/10362

Audio Workstation 6.4.2.4.3 pls Buffer Overflow (meta)
http://www.exploit-db.com/exploits/10363

Audio Workstation v6.4.2.4.0 (.pls) Universal Local BoF Exploit
http://www.exploit-db.com/exploits/10359

VLC Media Player RTSP Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37236

RETIRED: Adobe Flash Player APSB09-19 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/37199

Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37200

Intel Indeo Codec Media Content Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/37251

XChat 'PySys_SetArgv' Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/33444

Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37085

Microsoft Windows DNS Server Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/30132

Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35828

Microsoft WordPad and Office Text Converters Word 97 File Parsing Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37216

Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37214

Microsoft Project Invalid Resource Memory Allocation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37211

Microsoft Internet Explorer 'CAttrArray' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37213

Microsoft Protected Extensible Authentication Protocol Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/37198

Microsoft Protected Extensible Authentication Protocol Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37197

Microsoft Windows LSASS ISAKMP Message Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37218

Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37212

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

Notepad++ 'C' and 'CPP' File Handling Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36426

mpg123 'store_id3_text()' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34381

OpenEXR Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35838

HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/37261

gnome-screensaver Timeout Security Bypass Vulnerability
http://www.securityfocus.com/bid/37240

MySQL Empty Binary String Literal Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/31081

MySQL MyISAM Table Privileges Secuity Bypass Vulnerability
http://www.securityfocus.com/bid/29106

MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/35609

YOOtheme Warp5 Joomla! Component 'yt_color' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/37239

Ruby BigDecimal Library Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35278

Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vulnerability
http://www.securityfocus.com/bid/33769

PHP 5.2.10 and Prior Versions Multiple Vulnerabilities
http://www.securityfocus.com/bid/36449

PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/37079

Chipmunk Newsletter 'admin/addlist.php' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37238

PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35440

PHP 5.2.8 and Prior Versions Multiple Vulnerabilities
http://www.securityfocus.com/bid/33927

Symantec Veritas VRTSweb Incoming Data Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37012

PHP 'tempname()' 'safe_mode' Restriction-Bypass Vulnerability
http://www.securityfocus.com/bid/36555

PHP 'proc_open()' 'safe_mode_protected_env_var' Restriction-Bypass Vulnerability
http://www.securityfocus.com/bid/37138

GD Graphics Library '_gdGetColors' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36712

Corehttp 'src/http.c ' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37237

GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37141

Sisplet CMS 'new.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/37235

Shibboleth Redirection URL HTML Injection Vulnerability
http://www.securityfocus.com/bid/37241

Subversion Binary Delta Processing Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35983

MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability
http://www.securityfocus.com/bid/31486

OpenSSL 'zlib' Compression Memory Leak Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/31692

Sisplet CMS Komentar.PHP Remote File Include Vulnerability
http://www.securityfocus.com/bid/23334

AROUNDMe 'components/core/connect.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/37234

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

YABSoft Advanced Image Hosting Script 'search.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/37233

Mono Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/30471

Mono 'System.Web' HTTP Header Injection Vulnerability
http://www.securityfocus.com/bid/30867

Mono System.Math BigInteger Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/26279

PhpShop Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37227

Polipo Malformed HTTP GET Request Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37226

Multiple Vendor Clientless SSL VPN Products Same Origin Policy Bypass Vulnerability
http://www.securityfocus.com/bid/37152

Wireshark 1.2.2 and 1.0.9 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36846

UBB.threads Multiple File Include Vulnerabilities
http://www.securityfocus.com/bid/37205

libcdaudio 'cddb.c' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/32122

Grip CDDB Response Multiple Matches Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/12770

Multiple Symantec Products Intel Common Base Agent Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/34671

EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
http://www.securityfocus.com/bid/36566

Python Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/30491

Python zlib Module Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/28715

Python ImageOP Module Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/25696

Achievo Document Types Section Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/37219

EMC RepliStor Server 'rep_serv.exe' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36738

Achievo Scheduler Category HTML Injection Vulnerability
http://www.securityfocus.com/bid/37220

nginx HTTP Request Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36384

nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36839

Linux Kernel 'ip_frag_reasm() ' Null Pointer Deference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37231

Elkagroup Image Gallery 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37229

Linux Kernel KVM Large SMP Instruction Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/37130

HTMLDOC 'html' File Handling Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35727

Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/35587

JasPer 1.900.1 Multiple Vulnerabilities
http://www.securityfocus.com/bid/31470

iWeb Server URL Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37228

Netpbm 'pamperspective' Utility Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31871

ImageMagick TIFF File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35111

Graphviz Graph Parser Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31648

D-Bus 'dbus_signature_validate()' Type Signature Denial of Service Vulnerability
http://www.securityfocus.com/bid/31602

OpenBSD XMM Exceptions Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36589

Quiksoft EasyMail 'AddAttachment()' Method ActiveX Control Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36440

Sendmail check_relay Access Bypassing Vulnerability
http://www.securityfocus.com/bid/6548

Novell iPrint Client Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/37242

BigAnt IM Server HTTP GET Request Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36407

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

CUPS File Descriptors Handling Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/37048

CUPS 'kerberos' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36958

NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37255

GNU GRUB Local Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36968

Drupal Randomizer Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/37274

NetArt Media Real Estate Portal 'Username' Field SQL Injection Vulnerability
http://www.securityfocus.com/bid/37265

Invision Power Board '.txt' File MIME-Type Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/37263

Webmin and Usermin Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/37259

TestLink Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37258

0 件のコメント:

コメントを投稿