2010年2月18日木曜日

18日 木曜日、大安

InterScan for Domino 3.0 Windows版 Patch5 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1366

JVNDB-2009-002502 Linux kernel の poll_mode_io ファイルにおけるドライバの I/O モードを変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002502.html

JVNDB-2009-002501 Linux kernel におけるドライバの動作およびログレベルを変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002501.html

JVNDB-2010-001057 Linux kernel における SCSI ホストの属性に任意の変更を加えられる脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001057.html

JVNDB-2006-000995 Linux kernel の do_coredump 関数における任意のファイルを改ざんされる脆弱性
http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-000995.html

JVNDB-2010-001056 Linux kernel の net/ipv4/route.c 用の特定のレッドハットパッチにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001056.html

JVNDB-2010-001055 Linux kernel の fasync_helper 関数における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001055.html

JVNDB-2009-002500 Linux kernel の hfs サブシステムにおけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002500.html

JVNDB-2009-002499 Linux kernel の drivers/firewire/ohci.c におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002499.html

JVNDB-2009-002498 Linux kernel の fuse_direct_io 関数におけるサービス運用妨害 (DoS)の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002498.html

JVNDB-2009-002497 Linux kernel の gdth_read_event 関数における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002497.html

JVNDB-2009-002446 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002446.html

JVNDB-2009-002319 SSL および TLS プロトコルに脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002319.html

JVNDB-2009-002138 Apple Mac OS の SMB サブシステムにおけるファイル共有の制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002138.html

JVNDB-2009-000036 Apache Tomcat における情報漏えいの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000036.html

Mozilla Firefox showModalDialog Validation Flaw Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Feb/1023614.html

Mozilla Firefox Use-After-Free Error in HTML Parser Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023613.html

Cisco ASA TCP, SIP, SCCP, DTLS, and IKE Processing Flaws Let Remote Users Deny Service
http://securitytracker.com/alerts/2010/Feb/1023612.html

Mozilla Firefox Web Workers Array Buffer Overflow Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023611.html

Mozilla Firefox Browser Engine Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023610.html

Mozilla Firefox and SeaMonkey 'showModalDialog' method Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38289

Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38288

Mozilla Firefox and SeaMonkey Web Workers Array Data Type Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38285

Drupal iTweak Upload Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/38292

Samba MS-RPC Remote Shell Command Execution Vulnerability
http://www.securityfocus.com/bid/23972






 
+ Linux Kernel USB Information Disclosure and Denial of Service
http://secunia.com/advisories/38601/

- A Security Vulnerability in the ntp Daemon (xntpd(1M)) May Lead to a Denial of the Solaris Network Time Protocol(NTP) Service
http://sunsolve.sun.com/search/document.do?assetkey=1-66-275590-1

- Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20100217-fwsm.shtml
http://securitytracker.com/alerts/2010/Feb/1023609.html
http://www.securityfocus.com/bid/38274

[ANNOUNCE] PostgreSQL Code Factory 10.2 released
http://www.sqlmaestro.com/products/postgresql/codefactory/download/

[ANN] Apache Tomcat Native 1.1.20 released
http://tomcat.apache.org/native-doc/miscellaneous/changelog.html

MySQL Workbench 5.2.16 Beta 6 Available
http://wb.mysql.com/?p=406

Firefox 3.5.8 and 3.0.18 security updates now available
http://developer.mozilla.org/devnews/index.php/2010/02/17/firefox-3-5-8-and-3-0-18-security-updates-now-available/

PostgreSQL-PLPerl-Call-1.004 released
http://search.cpan.org/~timb/PostgreSQL-PLPerl-Call-1.004/

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
http://www.cisco.com/warp/public/707/cisco-sa-20100217-asa.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
http://www.cisco.com/warp/public/707/cisco-amb-20100217-asa.shtml

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent
http://www.cisco.com/warp/public/707/cisco-sa-20100217-csa.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco Security Agent
http://www.cisco.com/warp/public/707/cisco-amb-20100217-csa.shtml

IBM Lotus Domino LDAP buffer overflow vulnerability advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21420749

RHSA-2010:0112-1: Critical: firefox security update
http://rhn.redhat.com/errata/RHSA-2010-0112.html

RHSA-2010:0113-1: Critical: seamonkey security update
http://rhn.redhat.com/errata/RHSA-2010-0113.html

ADOBE READERとACROBATに危険な脆弱性、対策は新版へのアップデート
緊急度は「クリティカル」、すべてのプラットフォームが影響
http://itpro.nikkeibp.co.jp/article/NEWS/20100218/344721/?ST=security

Defining Clouds - " A Cloud by any Other Name Would be a Lot Less Confusing"
http://isc.sans.org/diary.html?storyid=8251

Multiple Security Updates for ESX 3.x and ESXi 3.x
http://isc.sans.org/diary.html?storyid=8254

Cisco ASA5500 Security Updates - cisco-sa-20100217-asa
http://isc.sans.org/diary.html?storyid=8257

Cisco Security Agent Security Updates: cisco-sa-20100217-csa
http://isc.sans.org/diary.html?storyid=8260

Joomla RWCards Component "controller" File Inclusion Vulnerability
http://secunia.com/advisories/38638/

Multiple File Attachments Mail Form Arbitrary File Upload Security Issue
http://secunia.com/advisories/38630/

Limny Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/38616/

Erotik Auktionshaus "id" SQL Injection Vulnerability
http://secunia.com/advisories/38614/

Red Hat update for kernel
http://secunia.com/advisories/38610/

Red Hat update for NetworkManager
http://secunia.com/advisories/38606/

Red Hat update for mysql
http://secunia.com/advisories/38604/

FTP On The Go HTTP Request Processing Denial of Service
http://secunia.com/advisories/38603/

Red Hat update for mysql
http://secunia.com/advisories/38602/

Linux Kernel USB Information Disclosure and Denial of Service
http://secunia.com/advisories/38601/

Trendnet TV-IP201 Directory Traversal Vulnerability
http://secunia.com/advisories/38599/

Kerberos KDC Authorization Denial of Service Vulnerability
http://secunia.com/advisories/38598/

Ubuntu update for ruby1.9
http://secunia.com/advisories/38586/

Ubuntu update for squid
http://secunia.com/advisories/38572/

VMware ESX Server update for net-snmp
http://secunia.com/advisories/38562/

Facebook Photo Uploader ActiveX Unspecified Vulnerability
http://secunia.com/advisories/38495/

Cisco Firewall Services Module SCCP Protocol Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Feb/1023609.html

Cisco ASA NTLMv1 Authentication Error Lets Remote Users Bypass Authentication
http://securitytracker.com/alerts/2010/Feb/1023608.html

Cisco Security Agent TCP Processing Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Feb/1023607.html

Cisco Security Agent Management Center Input Validation Flaws Let Remote Authenticated Users Download Files and Inject SQL Commands
http://securitytracker.com/alerts/2010/Feb/1023606.html

iTunes 9.0.1 .pls file handling buffer overflow
http://www.exploit-db.com/exploits/11491

MIT Kerberos KDC AS and TGS Requests Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0401

VMware ESX Net-snmp GETBULK Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0400

Adobe Acrobat and Reader PDF Handling Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/0399

SAP J2EE Engine Message-Driven Bean Directory Traversal Issue
http://www.vupen.com/english/advisories/2010/0398

SAP NetWeaver WebDynpro Runtime Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/0397

SAP JAVA CORE Authentication Mechanism Phishing Vulnerability
http://www.vupen.com/english/advisories/2010/0396

Juniper Installer Service Remote Stack Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0395

Firewall Builder Iptables Script Insecure Temporary File Vulnerability
http://www.vupen.com/english/advisories/2010/0389

gnome-screensaver Monitor Removal Lock Bypass Vulnerability
http://www.securityfocus.com/bid/38149

Apple iTunes '.pls' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36478

Apache Error Log Escape Sequence Injection Vulnerability
http://www.securityfocus.com/bid/9930

Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35510

Rising Online Virus Scanner ActiveX Control 'Scan()' Method Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38282

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Calendarix Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/13825

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

KDE Screensaver Unlock Dialog Race Condition Lock Bypass Vulnerability
http://www.securityfocus.com/bid/38214

Linux e1000 Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37519

Linux e1000e Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37523

Linux Kernel RTL8169 NIC 'RxMaxSize' Frame Size Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37521

Cisco ASA 5500 NTLM Protocol Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/38276

NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37255

Joomla! 'com_rwcards' Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/38267

odlican.net CMS 'upload.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/38128

Pardus Sun-Java Insecure Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38268

Joomla! 'com_acprojects' Component SQL Injection Vulnerability
http://www.securityfocus.com/bid/37897

Mozilla Firefox and SeaMonkey 'showModalDialog' method Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38289

Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38288

Mozilla Firefox/Thunderbird/SeaMonkey HTML Parser Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38287

Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/38286

Mozilla Firefox and SeaMonkey Web Workers Array Data Type Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38285

Drupal Advanced Help Injection and Export Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/38284

Cisco ASA 5500 Series SIP Traffic (CVE-2010-0569) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38281

Cisco ASA 5500 WebVPN DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/38280

Cisco ASA 5500 IKE Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/38279

Cisco ASA 5500 Crafted TCP Segment Denial of Service Vulnerability
http://www.securityfocus.com/bid/38278

Cisco ASA 5500 Series SIP Traffic (CVE-2010-0150) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38277

Cisco ASA Appliance TCP Connection Exhaustion Denial of Service Vulnerability
http://www.securityfocus.com/bid/38275

Cisco Firewall Services Module SCCP Inspection Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38274

Cisco Security Agent Unspecified Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38273

Cisco Management Center for Cisco Security Agents SQL Injection Vulnerability
http://www.securityfocus.com/bid/38272

Cisco Security Agent Management Center Directory Traversal Vulnerability
http://www.securityfocus.com/bid/38271

Joomla! 'com_acteammember' Component SQL Injection Vulnerability
http://www.securityfocus.com/bid/38270

Joomla! 'com_acstartseite' Component SQL Injection Vulnerability
http://www.securityfocus.com/bid/38269

0 件のコメント:

コメントを投稿