2009年12月17日木曜日

17日 木曜日、赤口

Samba 3.5.0pre2がリリースされました
http://samba.org/samba/ftp/pre/WHATSNEW-3-5-0pre2.txt

Vulnerability in Citrix NetScaler and Citrix Access Gateway Enterprise Edition Could Result in Denial of Service
http://support.citrix.com/article/CTX123649

Transport Layer Security Renegotiation Vulnerability
http://support.citrix.com/article/CTX123359

Kernel release: 2.6.31.9-rc1
http://www.linux.org/news/2009/12/16/0002.html

Kernel release: 2.6.27.42-rc1
http://www.linux.org/news/2009/12/16/0001.html

Trend Micro ビジネスセキュリティ 6.0 Service Pack 1 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1342

JVNDB-2009-002336 Apple Mac OS X の IOKit におけるキーボードのファームウェアが変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002336.html

JVNDB-2009-002335 Apple Mac OS X の International Components for Unicode (ICU) におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002335.html

JVNDB-2009-002334 Apple Mac OS X のヘルプビューアにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002334.html

JVNDB-2009-002333 Apple Mac OS X の FTP Server における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002333.html

JVNDB-2009-002332 Apple Mac OS X の Christos Zoulas file におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002332.html

JVNDB-2009-002179 PHP における exif のチェックに関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002179.html

JVNDB-2009-002178 PHP の php_openssl_apply_verification_policy 関数における証明書の検証処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002178.html

JVNDB-2009-002177 PHP の imagecolortransparent 関数におけるカラーインデックスの処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002177.html

JVNDB-2009-002153 FreeRADIUS における Tunnel-Password 属性値の処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002153.html

JVNDB-2009-002116 Apple QuickTime の FlashPix ファイルの処理におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002116.html

JVNDB-2009-002115 Apple QuickTime におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002115.html

JVNDB-2009-002018 libxml2 および libxml の Notation または Enumeration 属性タイプの処理におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002018.html

JVNDB-2009-002015 Subversion の libsvn_delta ライブラリにおける整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002015.html

JVNDB-2009-001956 複数の Mozilla 製品 における任意の SSL サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001956.html

JVNDB-2008-001963 SSH 通信において一部データが漏えいする可能性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001963.html

JVNDB-2008-001141 OpenLDAP の slapd におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001141.html

JVNDB-2008-001140 OpenLDAP の slapd における二重開放によるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001140.html

JVNDB-2007-000935 OpenLDAP の LDAP リクエストの取り扱いの不備によるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000935.html

overlay.xul is back
http://isc.sans.org/diary.html?storyid=7765

McAfee Labs Report on VoIP Vulnerabilities
http://www.avertlabs.com/research/blog/index.php/2009/12/16/mcafee-labs-report-on-voip-vulnerabilities/

Cisco WebEx WRF Player Buffer Overflows Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023360.html

Xpdf Buffer Overflow in FoFiType1::parse Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023356.html

Easy File Sharing Web Server Discloses File Listing Database to Remote Users
http://securitytracker.com/alerts/2009/Dec/1023355.html

Mozilla Firefox and Sea Monkey Content Injection Spoofing Vulnerability
http://www.securityfocus.com/bid/37370

Mozilla Firefox and SeaMonkey 'liboggplay' Media Library Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/37369

Mozilla Firefox and Sea Monkey Insecure Protocol Location Bar Spoofing Vulnerability
http://www.securityfocus.com/bid/37367

Mozilla Firefox and SeaMonkey Theora Video Library Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/37368

Mozilla Firefox and SeaMonkey NTLM Credential Reflection Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/37366

Mozilla Firefox 'window.opener' Property Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37365

Mozilla Firefox CVE-2009-3981 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37363

Mozilla Firefox CVE-2009-3982 JavaScript Engine Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/37364

Mozilla Firefox CVE-2009-3980 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/37362

Mozilla Firefox CVE-2009-3979 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/37361

Mozilla Firefox/SeaMonkey GeckoActiveXObject Exception Message COM Object Enumeration Vulnerability
http://www.securityfocus.com/bid/37360




+ Security Vulnerability in the Apache 1.3 "mod_perl" Module Component "Status.pm" May Lead to Unauthorized Access to Data
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274110-1

+ Security vulnerability in Solaris Pidgin (see pidgin(1)), Versions Prior to 2.5.9 may Lead to Execution of Arbitrary Code or a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266908-1

+ Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274250-1

+ An Integer Overflow Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274390-1

+ Dovecot 1.2.9 released
http://www.dovecot.org/list/dovecot-news/2009-December/000145.html

+ PSN-2009-12-609: NTP Mode 7 Denial-of-Service Vulnerability
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2009-12-609&viewMode=view

- Logical Domains (LDoms) Manager (ldm(1M)) 1.2 Patch 142840-03 (WITHDRAWN) May Cause the Control Domain to Panic When the ldmd Service is Re-enabled
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274090-1

SYM09-017: セキュリティ アドバイザリー - Symantec Veritas VRTSweb にリモートコード実行と権限昇格の脆弱性
http://www.symantec.com/ja/jp/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091209_00

Zimbra Collaboration Suite 5.0.21/6.0.4 released
http://files.zimbra.com/website/docs/archives/5.0/Zimbra%20OS%20Release%20Notes%205.0.21.pdf
http://files.zimbra.com/website/docs/Zimbra%20OS%20Release%20Notes%206.0.4.pdf

Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml

Document ID: 337645: Basic Quorum drive is inaccessible and cluster service will not start
http://seer.entsupport.symantec.com/docs/337645.htm

Debian : New cacti packages fix insufficient input sanitising
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31260

Independent Researcher : File Access Vulnerability in Easy File Sharing Web Server
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31270

Red Hat : Critical: seamonkey security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31264

Red Hat : Critical: firefox security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31265

Red Hat : Important: xpdf security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31266

Red Hat : Important: gpdf security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31267

Red Hat : Important: kdegraphics security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31268

[SECURITY] [DSA 1956-1] New xulrunner packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00248.html

rPSA-2009-0161-1 hwdata kernel
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00247.html

[SECURITY] [DSA 1955-1] New network-manager/network-manager-applet packages fix info
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00244.html

Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00245.html

{PRL} QuickHeal antivirus 2010 Local Privilege Escalation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00246.html

[security bulletin] HPSBMA02416 SSRT090008 rev.4 - HP OpenView Network Node Manager (OV NNM), Re
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00243.html

Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00242.html

VideoCache 1.9.2 vccleaner root vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00241.html

[SECURITY] [DSA 1954-1] New cacti packages fix insufficient input sanitising
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00240.html

[ISecAuditors Security Advisories] WP-Forum <= 2.3 SQL Injection vulnerabilities http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00237.html

Family Connections <= 2.1.3 Multiple Remote Vulnerabilities http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00236.html

FW: [Full-disclosure] File Access Vulnerability in Easy File Sharing Web Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00238.html

File Access Vulnerability in Easy File Sharing Web Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00239.html

[SECURITY] [DSA-1953-1] New expat packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00235.html

Beware the Attack of the Christmas Greeting Cards !
http://isc.sans.org/diary.html?storyid=7759

Cisco WebEx WRF Player Vulnerabilities
http://isc.sans.org/diary.html?storyid=7762

Sun Solaris "mod_perl" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37799/

Sun Solaris 10 "mod_perl" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37798/

Sun Solaris Gimp BMP Image Parsing Integer Overflow Vulnerability
http://secunia.com/advisories/37797/

IBM WebSphere Application Server JAAS-J2C Authentication Data Disclosure
http://secunia.com/advisories/37796/

Red Hat update for kdegraphics
http://secunia.com/advisories/37793/

HB-NS NewsScript "topic" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37792/

Red Hat update for Sun Java Runtime
http://secunia.com/advisories/37791/

Nortel CallPilot Web VPN Same Origin Policy Bypass
http://secunia.com/advisories/37789/

Stonesoft StoneGate SSL VPN Same Origin Policy Bypass
http://secunia.com/advisories/37788/

Red Hat update for xpdf
http://secunia.com/advisories/37787/

Juniper Networks Secure Access Web VPN Same Origin Policy Bypass
http://secunia.com/advisories/37786/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/37785/

Red Hat update for kernel
http://secunia.com/advisories/37784/

Mozilla Thunderbird JavaScript Engine Memory Corruption
http://secunia.com/advisories/37783/

Red Hat update for gpdf
http://secunia.com/advisories/37781/

Red Hat update for kernel
http://secunia.com/advisories/37779/

Fedora update for merkaartor
http://secunia.com/advisories/37778/

Red Hat update for kernel
http://secunia.com/advisories/37774/

Debian update for firefox-sage
http://secunia.com/advisories/37773/

IBM WebSphere Application Server Two Vulnerabilities
http://secunia.com/advisories/37772/

PyForum Multiple Vulnerabilities
http://secunia.com/advisories/37764/

iGaming CMS Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/37762/

Dubsite CMS Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/37761/

daloRADIUS "error" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37751/

Mail Manager Pro Cross-Site Request Forgery
http://secunia.com/advisories/37750/

Designs by JM CMS "pageid" SQL Injection Vulnerability
http://secunia.com/advisories/37738/

SitioOnline Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/37736/

Linkster "CID" SQL Injection Vulnerability
http://secunia.com/advisories/37732/

Sun Solaris Adobe Flash Player Multiple Vulnerabilities
http://secunia.com/advisories/37725/

ScriptsEz Mini Hosting Panel Cross-Site Request Forgery
http://secunia.com/advisories/37721/

Easy Banner Pro Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/37718/

Digital Scribe Cross-Site Scripting and SQL Injection Vulnerabilities
http://secunia.com/advisories/37715/

Horde Application Framework Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/37709/

Red Hat update for firefox
http://secunia.com/advisories/37704/

Red Hat update for seamonkey
http://secunia.com/advisories/37703/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/37699/

Citrix Access Gateway Web VPN Same Origin Policy Bypass
http://secunia.com/advisories/37696/

VMware vCenter Lab Manager WebWorks Help Cross-Site Scripting
http://secunia.com/advisories/37692/

Debian update for expat
http://secunia.com/advisories/37688/

Debian update for asterisk
http://secunia.com/advisories/37677/

KDE KPDF "FoFiType1::parse()" Integer Underflow Vulnerability
http://secunia.com/advisories/37641/

Mozilla Seamonkey GeckoActiveXObject Discloses Installed COM Objects to Remote Users
http://securitytracker.com/alerts/2009/Dec/1023347.html

Mozilla Firefox GeckoActiveXObject Discloses Installed COM Objects to Remote Users
http://securitytracker.com/alerts/2009/Dec/1023346.html

Mozilla Seamonkey 'window.opener' Flaw May Let Remote Users Gain Chrome Privileges
http://securitytracker.com/alerts/2009/Dec/1023345.html

Mozilla Firefox 'window.opener' Flaw May Let Remote Users Gain Chrome Privileges
http://securitytracker.com/alerts/2009/Dec/1023344.html

Mozilla Seamonkey Lets Remote Users Spoof URL Status and Contents
http://securitytracker.com/alerts/2009/Dec/1023343.html

Mozilla Firefox Lets Remote Users Spoof URL Status and Contents
http://securitytracker.com/alerts/2009/Dec/1023342.html

Mozilla Seamonkey NTLM Implementation Flaw Lets Remote Users Conduct Authentication Reflection Attacks
http://securitytracker.com/alerts/2009/Dec/1023341.html

Mozilla Seamonkey Bugs in libtheora Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023338.html

Mozilla Seamonkey Bugs in liboggplay Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023336.html

Mozilla Seamonkey Bugs in JavaScript Engine and Browser Engine Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023334.html

Mozilla Thunderbird JavaScript Engine Memory Corruption Vulnerabilities
http://www.vupen.com/english/advisories/2009/3558

KDE KPDF "FoFiType1::parse()" Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/3555

VMware Products WebWorks Help Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/3551

TYPO3 Extensions Multiple SQL Injection and Cross Site Scripting Issues
http://www.vupen.com/english/advisories/2009/3550

Horde Application Framework Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/3549

IBM WebSphere Application Server Cross Site Request Forgery Issue
http://www.vupen.com/english/advisories/2009/3548

Mozilla Products Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/3547

VideoCache 1.9.2 vccleaner root vulnerability
http://www.exploit-db.com/exploits/10487

Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability
http://www.exploit-db.com/exploits/10484

QuickHeal antivirus 2010 Local Privilege Escalation
http://www.exploit-db.com/exploits/10475

RHSA-2009:1674-1: Critical: firefox security update
http://rhn.redhat.com/errata/RHSA-2009-1674.html

RHSA-2009:1680-1: Important: xpdf security update
http://rhn.redhat.com/errata/RHSA-2009-1680.html

RHSA-2009:1681-1: Important: gpdf security update
http://rhn.redhat.com/errata/RHSA-2009-1681.html

RHSA-2009:1682-1: Important: kdegraphics security update
http://rhn.redhat.com/errata/RHSA-2009-1682.html

Adobe Flash Player and AIR Multiple Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/37269

Adobe Flash Player and AIR (CVE-2009-3797) Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37273

Ez Cart 'sid' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/37311

ZABBIX Denial Of Service and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37309

ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/37308

ZABBIX 'NET_TCP_LISTEN()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/37306

Linux Kernel 'ip_frag_reasm() ' Null Pointer Deference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37231

IBM WebSphere Application Server Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36458

IBM WebSphere Application Server JNDI Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/37355

Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37354

Horde Application Framework Administration Interface Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/37351

Linux Kernel 'drivers/firewire/ohci.c' NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/37339

Adobe Flash Player and AIR 'exception_count' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/37267

Adobe Flash Player and AIR (CVE-2009-3798) Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/37275

Adobe Flash Player and AIR Data Injection Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37270

Adobe Flash Player and AIR JPEG File Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37266

IBM WebSphere Application Server Administrative Console HTML Injection Vulnerability
http://www.securityfocus.com/bid/37015

PostgreSQL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/37334

HP OpenView Network Node Manager 'OvOSLocale' Cookie Parameter Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34294

HP OpenView Network Node Manager 'OvAcceptLang' Parameter Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34134

HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34135

PostgreSQL Index Function Session State Modification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37333

Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34383

NetworkManager Permission Enforcement Multiple Local Vulnrabilities
http://www.securityfocus.com/bid/33966

Cacti Multiple Cross Site Scripting and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/37109

Adobe Acrobat Reader Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36600

Adobe Reader and Acrobat 'newplayer()' JavaScript Method Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37331

GIMP BMP Image Parsing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/37006

Pidgin 'msn_slplink_process_msg()' NULL Pointer Dereference Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36071

Mozilla Firefox and SeaMonkey MFSA 2009-65 through -71 Multiple Vulnerabilities
http://www.securityfocus.com/bid/37349

Expat Unspecified XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37203

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

Sun Java SE Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35922

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34240

Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35939

Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35943

Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35944

JNLPAppletLauncher Arbitrary File Creation Vulnerability
http://www.securityfocus.com/bid/35946

Sun Java Applet Font.createFont Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/17981

Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/32620

Multiple Vendor Clientless SSL VPN Products Same Origin Policy Bypass Vulnerability
http://www.securityfocus.com/bid/37152

Merkaartor Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/36529

Mozilla Firefox and Sea Monkey Content Injection Spoofing Vulnerability
http://www.securityfocus.com/bid/37370

Recipe Script Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/37359

Quick Heal Antivirus Insecure Program File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37358

WP-Forum Wordpress Plugin Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37357

Article Directory 'login.php' SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37356

Digital Scribe Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37353

Cisco WebEx WRF File Handling Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/37352

Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37350

0 件のコメント:

コメントを投稿