2009年12月4日金曜日

4日 金曜日、先負

+ Linux kernel 2.6.30.10 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.10

サーバメンテナンスのお知らせ(2009年12月7日)
http://www.trendmicro.co.jp/support/news.asp?id=1335

JVNDB-2009-002295 Mozilla Firefox の長大な文字列の処理における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002295.html

JVNDB-2009-002294 Mozilla Firefox の XPCOM 実装における任意の JavaScript を実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002294.html

JVNDB-2009-002293 Mozilla Firefox/SeaMonkey の GIF 画像パーサにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002293.html

Apple released some Java updates today APPLE-SA--1 & 2 (for 10.5 and 10.6). Fixes a number of security issues so updating is a good idea.
http://isc.sans.org/diary.html?storyid=7684

Adobe Illustrator Buffer Overflow in Processing DSC Comment Field Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Dec/1023276.html

DISA UNIX Security Readiness Review (SRR) Evaluation Scripts Let Local Users Gain Root Privileges
http://securitytracker.com/alerts/2009/Dec/1023265.html

Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37085

Mozilla Firefox CVE-2009-3382 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36866

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34765

acpid Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34692

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Mozilla Firefox and SeaMonkey 'libpr0n' GIF Parser Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36855

Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36856

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

Mozilla Firefox Download Manager World Writable File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36852

Mozilla Firefox Form History Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36853

Mozilla Firefox 'document.getSelect' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36858

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Mozilla Firefox XPCOM Utility Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36857

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

libwmf WMF Image File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34792

Libpng 1-bit Interlaced Images Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35233

Adobe Illustrator Encapsulated Postscript File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37192

DAZ Studio Scripting Support Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/37176

udev Path Encoding Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34539

Adobe Flash Player APSB09-19 Multiple Unspecified Remote Vulnerabilities
http://www.securityfocus.com/bid/37199




+ Linux kernel 2.6.32 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32
http://www.linux.org/news/2009/12/03/0001.html

+ Multiple Security Vulnerabilities in the libexpat Library May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1

+ Security Vulnerability in wget(1) Related to Certificate Parsing may Allow Encrypted HTTP Communication to be Intercepted Using a Man-in-the-Middle (MITM) Attack
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273590-1

+ Two Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273551-1

+ Security vulnerability in Solaris Pidgin (see pidgin(1)), Versions Prior to 2.5.9 may Lead to Execution of Arbitrary Code or a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266908-1

+ Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272230-1

+ Multiple Security Vulnerabilities in the libexpat Library May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1

+ FreeBSD-SA-09:17.freebsd-update: Inappropriate directory permissions in freebsd-update(8)
http://security.freebsd.org/advisories/FreeBSD-SA-09:17.freebsd-update.asc

+ FreeBSD-SA-09:16.rtld: Improper environment sanitization in rtld(1)
http://security.freebsd.org/advisories/FreeBSD-SA-09:16.rtld.asc

+ FreeBSD-SA-09:15.ssl: SSL protocol flaw
http://security.freebsd.org/advisories/FreeBSD-SA-09:15.ssl.asc

+ libpng 1.2.41 released
http://www.libpng.org/pub/png/libpng.html

[ANNOUNCE] Apache CouchDB 0.9.2 has been released
http://couchdb.apache.org/downloads.html

[ANNOUNCE] Apache CouchDB 0.10.1 has been released
http://couchdb.apache.org/downloads.html

Official support for NVIDIA graphics cards on amd64 architecture
http://www.freebsd.org/news/newsflash.html#event20091203:01
http://www.nvnews.net/vbulletin/showthread.php?t=142120

MySQL 5.1.42 (Not yet released)
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-42.html

PostgreSQL Data Wizard 9.12 released
http://www.postgresql.org/about/news.1168

PostgreSQL@FOSDEM 2010 - Call for talks
http://www.postgresql.org/about/news.1167

CompareData 1.6.0 is released
http://www.postgresql.org/about/news.1165

New Open Source Project for PostgreSQL web front end
http://www.postgresql.org/about/news.1164

DeZign for Databases V6.0 Adds Support for Bidirectional Synchronization of Models and Databases
http://www.postgresql.org/about/news.1163

DeZign for Databases V6 Adds Support for Bidirectional Synchronization of Models and Databases
http://www.postgresql.org/about/news.1162

MySQL 5.0.89 (Not yet released)
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-89.html

UPDATE: Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml

定期サーバメンテナンスのお知らせ(2009年12月11日)
http://www.trendmicro.co.jp/support/news.asp?id=1332

Debian : New request-tracker packages fix session hijack vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31033

Debian : New gforge packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31034

FreeBSD : ssl
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31036

FreeBSD : rtld
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31037

FreeBSD : freebsd-update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31038

Mandriva : mozilla-thunderbird
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31029

Red Hat : Important: kernel-rt security, bug fix, and enhancement update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31035

Slackware Linux : slackware-security bind
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31030

Debian : New openldap2.3/openldap packages fix SSL certificate verification weakness
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31032

RHBA-2009:1634-1: glibc bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1634.html

最も安全な国別ドメインは「日本」、「カメルーン」は3割以上が危険
米マカフィーが2700万サイトを調査、「危険なサイト」の割合を算出
http://itpro.nikkeibp.co.jp/article/Research/20091203/341530/?ST=security

「ワンクリック詐欺」の相談が過去最多、1カ月で900件を突破
IPAが注意喚起、「安易に『はい』をクリックするな!」
http://itpro.nikkeibp.co.jp/article/Research/20091203/341529/?ST=security

FreeBSD Security Advisory FreeBSD-SA-09:15.ssl [REVISED]
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00047.html

[ MDVSA-2009:310 ] openssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00045.html

CORE-2009-0911: DAZ Studio Arbitrary Command Execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00043.html

[USN-863-1] QEMU vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00044.html

[ MDVSA-2009:309 ] ntp
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00041.html

[ MDVSA-2009:308 ] gnutls
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00046.html

[ MDVSA-2009:113-1 ] cyrus-sasl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00042.html

[ MDVSA-2009:112-1 ] ipsec-tools
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00036.html

[ MDVSA-2009:108-1 ] zsh
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00039.html

[ MDVSA-2009:107-1 ] acpid
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00035.html

[ MDVSA-2009:106-1 ] libwmf
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00038.html

[ MDVSA-2009:103-1 ] udev
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00037.html

[SECURITY] [DSA 1945-1] New gforge packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00032.html

[SECURITY] [DSA 1944-1] New request-tracker packages fix session hijack vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00031.html

[ MDVSA-2009:197-3 ] nss
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00033.html

[ MDVSA-2009:217-3 ] mozilla-thunderbird
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00034.html

FreeBSD Security Advisory FreeBSD-SA-09:17.freebsd-update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00029.html

FreeBSD Security Advisory FreeBSD-SA-09:16.rtld
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00030.html

FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00028.html

U.S. Defense Information Systems Agency (DISA) Unix Security Readiness Review (SRR) root compromise
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00040.html

Adobe Illustrator CS4 (V14.0.0) Encapsulated Postscript (.eps) Overlong DSC Comment Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00026.html

[ MDVSA-2009:121-1 ] lcms
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00025.html

[SECURITY] [DSA 1943-1] New openldap2.3/openldap packages fix SSL certificate verification weakn
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-12/msg00024.html

Avast false positives
http://isc.sans.org/diary.html?storyid=7681

FreeBSD 'freebsd-update' Unsafe Directory Permissions Lets Local Users Read Certain Files
http://securitytracker.com/alerts/2009/Dec/1023263.html

transfig ".fig" File Parsing Buffer Overflow
http://secunia.com/advisories/37577/

FreeBSD freebsd-update Insecure Directory Permissions
http://secunia.com/advisories/37575/

Sun Java System Portal Server Gateway Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/37574/

Drupal Taxonomy Timer Module SQL Injection Vulnerability
http://secunia.com/advisories/37573/

Xfig ".fig" File Parsing Buffer Overflow
http://secunia.com/advisories/37571/

Debian update for openldap
http://secunia.com/advisories/37569/

Sun Products NSS TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/37566/

Adobe Illustrator Encapsulated Postscript Parsing Vulnerability
http://secunia.com/advisories/37563/

IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
http://secunia.com/advisories/37545/

FreeBSD OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/37544/

Fedora update for wget
http://secunia.com/advisories/37539/

Fedora update for libsndfile
http://secunia.com/advisories/37538/

Slackware update for bind
http://secunia.com/advisories/37528/

Golden FTP Server "DELE" Command Directory Traversal Vulnerability
http://secunia.com/advisories/37527/

SUSE update for kernel
http://secunia.com/advisories/37521/

Joomla Kide Shoutbox Component Security Bypass
http://secunia.com/advisories/37508/

Cacti Cross-Site Request Forgery
http://secunia.com/advisories/37484/

Adobe Illustrator Encapsulated Postscript Memory Corruption Vulnerability
http://www.vupen.com/english/advisories/2009/3396

IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2009/3395

Sun Java System Portal Server Gateway Cross Site Scripting Issues
http://www.vupen.com/english/advisories/2009/3394

Sun Products SSL/TLS Session Renegotiation Plaintext Injection Issue
http://www.vupen.com/english/advisories/2009/3393

Taxonomy Timer Module for Drupal Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/3388

OrzHTTPd Format String Exploit
http://www.exploit-db.com/exploits/10282

PHP 'ini_restore()' Memory Information Disclosure Vulnerability
http://www.exploit-db.com/exploits/10296

DAZ Studio Arbitrary Command Execution
http://www.exploit-db.com/exploits/10295

Adobe Illustrator CS4 v14.0.0 Encapsulated Postscript (.eps) Buffer Overflow Exploit
http://www.exploit-db.com/exploits/10281

NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35017

PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34090

Wireshark 1.2.2 and 1.0.9 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36846

GStreamer gst-plugins-good 'gstpngdec.c' PNG Output Buffer Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35172

Wireshark ERF File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36591

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36097

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

GnuTLS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35952

GnuTLS Prior to 2.6.6 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34783

Cyrus SASL 'sasl_encode64()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34961

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34765

acpid Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34692

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

Sun Solaris Sockets Direct Protocol (SDP) Driver 'sdp(7D)' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36904

Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37085

Microsoft Windows Embedded OpenType Font Engine Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36029

Microsoft Windows Kernel NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36939

RT Session Fixation Vulnerability
http://www.securityfocus.com/bid/37162

Microsoft Windows Kernel GDI Data Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36941

Mozilla Firefox CVE-2009-3382 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36866

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Wget NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36205

OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36844

Mozilla Firefox XPCOM Utility Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36857

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Microsoft Active Directory LDAP Request Stack Exhaustion Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36918

Mozilla Firefox and SeaMonkey 'libpr0n' GIF Parser Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36855

Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36856

Mozilla Firefox Download Manager World Writable File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36852

Mozilla Firefox Form History Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36853

GNU Tar Dot_Dot Function Remote Directory Traversal Vulnerability
http://www.securityfocus.com/bid/25417

libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/32326

libxml XML Entity Name Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31126

GNU TAR and CPIO safer_name_suffix Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/26445

libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32331

udev Netlink Message Validation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34536

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314

PostgreSQL Multiple Privilege Escalation and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/27163

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35949

Apache 'mod_deflate' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35623

Linux Kernel 'nfs4_proc_lock()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36936

Linux Kernel 'megaraid_sas' Driver Insecure File Permission Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37019

libsndfile CAF Processing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33963

libsndfile VOC and AIFF Processing Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34978

Huawei MT882 Cross Site Scripting and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/37194

Linux kernel 'O_EXCL' NFSv4 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36472

phpMyFAQ 2.5.4 and Prior Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/37180

Linux Kernel eCryptfs Lower Dentry Null Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36639

Linux Kernel 2.4 and 2.6 Multiple Local Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/36304

Linux Kernel 'pipe.c' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36901

Linux Kernel '/drivers/net/r8169.c' Out-of-IOMMU Error Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36706

Linux Kernel with SELinux 'mmap_min_addr' Low Memory NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36051

Xfig and Transfig '.fig' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37193

Linux Kernel 'PER_CLEAR_ON_SETID' Incomplete Personality List Access Validation Weakness
http://www.securityfocus.com/bid/35647

Linux Kernel '__scm_destroy()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32154

Linux Kernel Multiple Protocols Local Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/36176

Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35185

Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35930

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

Adobe Illustrator Encapsulated Postscript File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37192

Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34405

Linux Kernel 'sendmsg()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32516

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Libpng 1-bit Interlaced Images Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35233

GForge Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/37195

Thatware 'root_path' Parameter Multiple Remote File Include Vulnerabilities
http://www.securityfocus.com/bid/37191

udev Path Encoding Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34539

FreeBSD 'freebsd-update' Utility Insecure Directory Permissions Vulnerability
http://www.securityfocus.com/bid/37190

ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/37118

FreeBSD 'execl()' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37154

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Expat Unspecified XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37203

QEMU Virtio Networking Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37201

Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37200

Adobe Flash Player APSB09-19 Multiple Unspecified Remote Vulnerabilities
http://www.securityfocus.com/bid/37199

Microsoft December 2009 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/37196

DAZ Studio Scripting Support Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/37176

0 件のコメント:

コメントを投稿