2010年2月12日金曜日

12日 金曜日、仏滅




 
 
PUBLIC ADVISORY: 02.09.10: Microsoft PowerPoint OEPlaceholderAtom Use-After-Free Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=840

PUBLIC ADVISORY: 02.09.10: Microsoft PowerPoint LinkedSlideAtom Heap Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=841

PUBLIC ADVISORY: 02.09.10: Microsoft PowerPoint OEPlaceholderAtom Invalid Array Indexing Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=842

JVNVU#869993 Panda Security ActiveScan におけるコンポーネントのデジタル署名を検証しない問題
http://jvn.jp/cert/JVNVU869993/index.html

JVNTA10-040A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA10-040A/index.html

JVNDB-2010-001031 Oracle Database および Oracle Application Server の Unzip コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001031.html

JVNDB-2010-001030 Oracle Database の Oracle Spatial コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001030.html

JVNDB-2010-001029 Oracle Database の RDBMS コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001029.html

JVNDB-2010-001028 Oracle Database の Logical Standby コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001028.html

JVNDB-2010-001027 Oracle Database の Oracle Spatial コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001027.html

JVNDB-2010-001026 Oracle Database の Oracle Data Pump コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001026.html

JVNDB-2010-001025 Oracle Database の Application Express Application Builder コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001025.html

JVNDB-2010-001024 Oracle Database の Oracle OLAP コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001024.html

JVNDB-2010-001023 Oracle Database の Listener コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001023.html

Adobe Acrobat Flaw Lets Remote Users Issue Cross-Domain Requests
http://securitytracker.com/alerts/2010/Feb/1023586.html

Adobe Flash Player Flaw Lets Remote Users Issue Cross-Domain Requests
http://securitytracker.com/alerts/2010/Feb/1023585.html

Adobe BlazeDS Unspecified Flaw Lets Remote Users Access Files on the Target System
http://securitytracker.com/alerts/2010/Feb/1023584.html

Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37864

Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38044

Microsoft PowerPoint 'OEPlaceholderAtom' Record Corrupt Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38104




+ PHP-SA-2/11/2010: PHP 5.2.12/5.3.1 session.save_path safe_mode and open_basedir bypass
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31741
http://www.securityfocus.com/bid/38182

+ Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/37942
+ Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37945
+ Apache Tomcat WAR File Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37944

+ Linux Kernel 'selinux_bprm_committing_creds()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/38175

HPSBMA02488 SSRT100013 rev.1 - HP ProLiant Support Pack 8.30 for Windows, Remote Code Execution, Information Disclosure
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01997644

HPSBNS02475 SSRT090068 rev.2 - HP NonStop Servers, Execution of Arbitrary Code in Privileged Mode
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01923646&admit=109447626+1265939351858+28353475

HPSBPI02507 SSRT100012 rev.2 - HP DreamScreen, Remote Disclosure of Information
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02009377&admit=109447626+1265939376701+28353475

Security Vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) Protocols Affects Multiple Server Products in the Sun Java Enterprise System Suite
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1

Patches Delivering OBP Firmware Versions 4.30.3, 4.30.3.b or 4.30.4 (WITHDRAWN) may Cause a System to Fail to Boot
http://sunsolve.sun.com/search/document.do?assetkey=1-66-276870-1

APSB10-07: Security Advisory for Adobe Reader and Acrobat
http://www.adobe.com/support/security/bulletins/apsb10-07.html

APSB10-06: Security update available for Adobe Flash Player
http://www.adobe.com/support/security/bulletins/apsb10-06.html

APSB10-05: Security update available for BlazeDS
http://www.adobe.com/support/security/bulletins/apsb10-05.html

Mozilla Developer Preview (Gecko 1.9.3a1) available for download
https://developer.mozilla.org/devnews/index.php/2010/02/10/mozilla-developer-preview-gecko-1-9-3a1-available-for-download/

Cisco Security Advisory: Multiple Vulnerabilities in Cisco IronPort Encryption Appliance
http://www.cisco.com/warp/public/707/cisco-sa-20100210-ironport.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in IronPort Encryption Appliance
http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html

RHBA-2010:0099-1: libgtop2 bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0099.html

[USN-899-1] Tomcat vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00120.html

[SECURITY] [DSA 1994-1] New ajaxterm packages fix session hijacking
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00118.html

[security bulletin] HPSBMA02488 SSRT100013 rev.1 - HP ProLiant Support Pack 8.30 for Windows, Re
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00123.html

[security bulletin] HPSBPI02507 SSRT100012 rev.2 - HP DreamScreen, Remote Disclosure of Informat
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00122.html

[ MDVSA-2010:035 ] openoffice.org
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00121.html

[Onapsis Security Advisory 2010-002] SAP J2EE Engine MDB Path Traversal
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00117.html

[Onapsis Security Advisory 2010-004] SAP J2EE Authentication Phishing Vector
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00115.html

[Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00116.html

[SECURITY] [DSA 1993-1] New otrs2 packages fix SQL injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00114.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco IronPort Encryption Appliance
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00107.html

[security bulletin] HPSBMA02486 SSRT090049 rev.1 - HP OpenView Network Node Manager (OV NNM) Jav
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00113.html

[security bulletin] HPSBMA02484 SSRT090076 rev.1 - HP Network Node Manager (NNM), Remote Executi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00110.html

[USN-898-1] gnome-screensaver vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00106.html

[USN-897-1] MySQL vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00111.html

Windows SMB NTLM Authentication Weak Nonce Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00108.html

Trustwaves SpiderLabs Security Advisory TWSL2010-001
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00112.html

stratsec Security Advisory SS-2010-003 - Microsoft SMB Client Pool Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00105.html

Mandriva : openoffice.org
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31737

Onapsis : SAP J2EE Engine MDB Path Traversal
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31739

Onapsis : SAP J2EE Authentication Phishing Vector
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31740

SecurityReason.com : PHP 5.2.12/5.3.1 session.save_path safe_mode and open_basedir bypass
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31741

Cisco : Multiple Vulnerabilities in Cisco IronPort Encryption Appliance
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31738

Debian : New otrs2 packages fix SQL injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31736

Hewlett-Packard : HP Network Node Manager (NNM), Remote Execution of Arbitrary Commands
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31742

Hewlett-Packard : HP OpenView Network Node Manager (OV NNM) Java Runtime Environment (JRE) and Java Developer Kit (JDK
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31743

Ubuntu Security Notice : MySQL vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31723

Ubuntu Security Notice : gnome-screensaver vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31732

Core Security Technologies : Microsoft Office Excel / Word OfficeArtSpgr Container Pointer Overwrite Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31725

WindowsやOfficeに多数の脆弱性、マイクロソフトがパッチを公開
セキュリティ情報が13件、すべてのWindowsユーザーが対象
http://itpro.nikkeibp.co.jp/article/NEWS/20100211/344425/?ST=security

マカフィー、セキュリティ対策ソフトのアップデートを提供
パフォーマンスや検出機能を強化、ユーザーインタフェースも変更
http://itpro.nikkeibp.co.jp/article/NEWS/20100211/344477/?ST=security

Google Chrome Bugs Let Remote Users Execute Arbitrary Code and Obtain Information
http://securitytracker.com/alerts/2010/Feb/1023583.html

HP DreamScreen Discloses Arbitrary Files to Remote Users
http://securitytracker.com/alerts/2010/Feb/1023581.html

HP OpenView Network Node Manager Unspecified Bug Lets Remote Users Execute Arbitrary Commands
http://securitytracker.com/alerts/2010/Feb/1023580.html

Cisco IronPort Flaws Let Remote Users View Arbitrary Files and Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023579.html

eSmile "cid" SQL Injection Vulnerability
http://secunia.com/advisories/38548/

Opera TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/38546/

Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/38545/

Debian update for otrs2
http://secunia.com/advisories/38544/

myPHP Guestbook Information Disclosure Security Issue
http://secunia.com/advisories/38542/

Drupal Graphviz Filter Module Arbitrary Command Execution Vulnerability
http://secunia.com/advisories/38540/

Ubuntu update for gnome-screensaver
http://secunia.com/advisories/38532/

Cisco IronPort Multiple Vulnerabilities
http://secunia.com/advisories/38525/

Hyleos ChemView ActiveX Control Buffer Overflow Vulnerabilities
http://secunia.com/advisories/38523/

CommodityRentals Books/eBooks Rentals Script "cat_id" SQL Injection
http://secunia.com/advisories/38520/

CommodityRentals CD Rentals Script "cat_id" SQL Injection Vulnerability
http://secunia.com/advisories/38519/

Interspire Knowledge Manager Multiple Vulnerabilities
http://secunia.com/advisories/38465/

HP OpenView Network Node Manager Java JDK / JRE Multiple Vulnerabilities
http://secunia.com/advisories/38539/

eZoneScripts.com phpMiniSite Script Authentication Security Bypass
http://secunia.com/advisories/38537/

RSLinx EDS Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/38531/

NetPBM "xpmtoppm" XPM Processing Vulnerability
http://secunia.com/advisories/38530/

JDownloader Click'n'Load 2 Command Execution Vulnerability
http://secunia.com/advisories/38529/

HP Network Node Manager Arbitrary Command Execution Vulnerability
http://secunia.com/advisories/38528/

ARWScripts Fonts Script "f" Local File Inclusion Vulnerability
http://secunia.com/advisories/38518/

Ubuntu update for mysql-dfsg-5 and mysql-dfsg-5.1
http://secunia.com/advisories/38517/

Limny File Upload Security Issue
http://secunia.com/advisories/38516/

osTicket SQL Injection and Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/38515/

Coppermine Photo Gallery Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38514/

Panda ActiveScan "as2stubie.dll" Unverified CAB Installation
http://secunia.com/advisories/38485/

MS10-015 may cause Windows XP to blue screen
http://isc.sans.org/diary.html?storyid=8209

The Mysterious Blue Screen
http://isc.sans.org/diary.html?storyid=8215

Critical Update for AD RMS
http://isc.sans.org/diary.html?storyid=8218

Twitpic, EXIF and GPS: I Know Where You Did it Last Summer
http://isc.sans.org/diary.html?storyid=8203

Datacenters and Directory Traversals
http://isc.sans.org/diary.html?storyid=8206

Vulnerability in TLS/SSL Could Allow Spoofing
http://isc.sans.org/diary.html?storyid=8200

Cisco IronPort Remote Code Execution and File Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2010/0363

Opera TLS Session Renegotiation Plaintext Injection Vulnerability
http://www.vupen.com/english/advisories/2010/0362

Google Chrome Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0361

HP Network Node Manager Remote Command Execution Vulnerability
http://www.vupen.com/english/advisories/2010/0360

HP OpenView Network Node Manager JRE/JDK Vulnerabilities
http://www.vupen.com/english/advisories/2010/0359

NetPBM "xpmtoppm" Converter Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0358

Panda Security ActiveScan "as2stubie.dll" File Download Vulnerability
http://www.vupen.com/english/advisories/2010/0354

Hyleos ChemView v1.9.5.1 (HyleosChemView.ocx) Heap Spray Exploit (meta)
http://www.exploit-db.com/exploits/11413

Radasm .rap file local buffer overflow vulnerability
http://www.exploit-db.com/exploits/11408

Radasm v2.2.1.6 (.rap) Universal Buffer Overflow Exploit
http://www.exploit-db.com/exploits/11400

WM Downloader v3.0.0.9 PLS PLA Exploit (WinXP SP3)
http://www.exploit-db.com/exploits/11384

Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35828

Microsoft Visual Studio Active Template Library NULL String Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35830

Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/37942

Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37945

Apache Tomcat WAR File Directory Traversal Vulnerability
http://www.securityfocus.com/bid/37944

GNU Libtool 'libltdl' Library Search Path Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37128

OpenOffice EMF File Parser Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/36291

OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36200

Joomla! Mochigames Component 'cid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37931

CARTwebERP Joomla! Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/37581

Kunena ('com_kunena') Joomla! Component 'func' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36020

Joomla! 'com_perchagallery' Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37642

Bible Study Joomla! Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/37583

Joomla! BeeHeard Component 'category_id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37495

Joomla! JbPublishDownFp Component 'cid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37932

Joomla! JoomClip Component 'cat' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37049

Joomla! CB Resume Builder 'group_id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36598

Joomla! Ajax Chat Component 'ajcuser.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/36731

Joomla! Fastball Component SQL Injection Vulnerability
http://www.securityfocus.com/bid/36520

Almond Classifieds Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
http://www.securityfocus.com/bid/35815

Joomla! AlphaUserPoints Component 'username2points' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36383

Joomla! Foobla Suggestions Component 'idea_id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36425

Agora 'action' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/36207

Joomla! iF Portfolio Nexus Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37050

Joomla! BF Survey Pro 'catid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37585

Joomla! JEEMA Article Collection Component 'catid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37449

Joomla! 'com_ninjamonial' Component 'testimID' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36122

Joomla! DigiStore Component Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/37433

Joomla! 'com_jphoto' Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/37279

'com_jumi' Component for Joomla! Backdoor Vulnerability
http://www.securityfocus.com/bid/36883

Joomla! and Mambo 'com_mosres' Component Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35202

Google Chrome prior to 4.0.249.89 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/38177

Oracle 11gR2 Multiple Remote Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/38115

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34042

OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38146

Kunena Prior to 1.5.7 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/38193

HP DreamScreen Unspecified Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38190

CommodityRentals Books/eBooks Rental Software 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38189

Newgen OmniDocs 'ForceChangePassword.jsp' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38188

CommodityRentals CD Rental Software 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38184

SAP J2EE Engine Core Unspecified Phishing Vulnerability
http://www.securityfocus.com/bid/38183

PHP 'session_save_path()' 'safe_mode' Restriction-Bypass Vulnerability
http://www.securityfocus.com/bid/38182

SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
http://www.securityfocus.com/bid/38181

vBulletin 2.3 Cross-Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38180

vBulletin Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/38179

KDE Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/36845

MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/35609

MySQL Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/37297

MySQL MyISAM Table Privileges Secuity Bypass Vulnerability
http://www.securityfocus.com/bid/29106

MySQL with yaSSL SSL Certificate Handling Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37943

MySQL 5.0.51a Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37640

MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability
http://www.securityfocus.com/bid/31486

Accellion File Transfer Appliance Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/38176

MySQL MyISAM Table Symbolic Link Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37075

MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
http://www.securityfocus.com/bid/38043

gnome-screensaver Monitor Removal Lock Bypass Vulnerability
http://www.securityfocus.com/bid/38149

Microsoft Internet Explorer URI Validation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/37884

Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38044

Microsoft Windows SMB NTLM Authentication Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/38085

Microsoft Windows Kerberos 'Ticket-Granting-Ticket' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38110

Microsoft Data Analyzer 'max3activex.dll' ActiveX Control Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38045

Microsoft Paint JPEG Image Processing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38042

vBulletin Adsense Component 'viewpage.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38167

Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/32620

Sun Java Web Start and Java Plug-in JAR File Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/32892

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/32608

Linux e1000e Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37523

FeedDemon 'outline' Tag Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33630

Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37864

Microsoft DirectX DirectShow AVI File Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38112

Microsoft Windows Client/Server Run-time Subsystem Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38098

Microsoft Windows SMB Client Pool Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38093

Vermillion FTP Daemon 'Port' Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38011

IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36615

Drupal Graphviz Filter Module Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/38178

Linux Kernel 'selinux_bprm_committing_creds()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/38175

HP OpenView Network Node Manager Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/38174

RSLinx EDS File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38171

Cisco IronPort Encryption Appliance WebSafe Servlet Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38170

Cisco IronPort Encryption Appliance HTTPS Server Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38169

Cisco IronPort Encryption Appliance Administration Interface Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38168

0 件のコメント:

コメントを投稿