2010年3月19日金曜日

19日 金曜日、大安

JVNTA10-068A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA10-068A/index.html

JVNDB-2010-001171 Microsoft Internet Explorer における解放済みメモリを使用する脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001171.html

JVNDB-2010-001170 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001170.html

JVNDB-2010-001169 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001169.html

JVNDB-2010-001168 複数の Microsoft 製品におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001168.html

JVNDB-2010-001167 複数の Microsoft 製品におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001167.html

JVNDB-2010-001166 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001166.html

JVNDB-2010-001165 複数の Microsoft 製品における任意のコードを実行される脆弱性http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001165.html

JVNDB-2010-001164 Microsoft Office Excel における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001164.html

JVNDB-2010-001163 Microsoft Windows Movie Maker および Microsoft Producer におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001163.html




- The "zpool create" Command May Dump Core When Used on Systems Running Sun Cluster 3.2
http://sunsolve.sun.com/search/document.do?assetkey=1-66-242426-1

[ANNOUNCE] Apache Mahout 0.3 Released
http://www.apache.org/dyn/closer.cgi/lucene/mahout
http://issues.apache.org/jira/browse/MAHOUT/fixforversion/12314281

phpMyAdmin at Google Summer of Code 2010
http://sourceforge.net/news/?group_id=23067&id=284219

RHEA-2010:0156-1: new packages: kmod-lpfc-rhel5u4-8.2.0.63-1.1
http://rhn.redhat.com/errata/RHEA-2010-0156.html

RHEA-2010:0157-1: Virtio drivers for kernel 2.4.21-63.EL
http://rhn.redhat.com/errata/RHEA-2010-0157.html

Independent Researcher : Citrix Web interface - Source code disclosure?
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32043

Dangers of copy&paste
http://isc.sans.org/diary.html?storyid=8449

IBM DB2 Content Manager Web Services Single Sign-on Flaw Has Unspecified Impact
http://securitytracker.com/alerts/2010/Mar/1023726.html

DotNetNuke Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38920/

Nensor CMS File Inclusion Vulnerabilities
http://secunia.com/advisories/39019/

Sahana Disaster Management System Authentication Security Bypass
http://secunia.com/advisories/39020/

Joomla VXDate Component SQL Injection and Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/39024/

ManageEngine ServiceDesk Plus "woID" SQL Injection Vulnerability
http://secunia.com/advisories/39032/

IBM DB2 Content Manager Information Integrator Security Issue
http://secunia.com/advisories/39025/

Drupal Email Input Filter Module PHP Code Execution Vulnerability
http://secunia.com/advisories/39034/

Drupal Tag Order Module Script Insertion Vulnerability
http://secunia.com/advisories/39030/

Transmission "tr_magnetParse()" Magnet Parsing Buffer Overflows
http://secunia.com/advisories/39031/

VariCAD Products DWB Processing Buffer Overflow
http://secunia.com/advisories/39027/

Drupal Keys Module Cross-Site Reques Forgery Vulnerability
http://secunia.com/advisories/39026/

Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/39029/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/39001/

Google Picasa for Mac JPEG Processing Memory Corruption
http://secunia.com/advisories/38753/

NinkoBB Cross-Site Request Forgery
http://secunia.com/advisories/39016/

Red Hat update for java-1.4.2-ibm
http://secunia.com/advisories/39028/

IBM DB2 Content Manager Web Services Single Sign-on Vulnerability
http://www.vupen.com/english/advisories/2010/0656

Transmission "tr_magnetParse()" Magnet Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0655

myMP3-Player Playlist Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0654

VariCAD Products "DWB" File Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0653

SugarCRM Document Name Handling Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/0652

Redhat Security Update Fixes Java TLS/SSL Renegotiation Issue
http://www.vupen.com/english/advisories/2010/0651

Redhat Security Update Fixes Thunderbird Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/0650

Redhat Security Update Fixes Kernel Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/0649

Mozilla SeaMonkey Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0648

Google Chrome Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0647

Google Picasa for Mac JPEG Image Integer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0646

ZippHo 3.0.6 (.zip) 0day stack buffer overflow PoC exploit
http://www.exploit-db.com/exploits/11797

MediaCoder (.lst) file local Buffer Overflow Exploit
http://www.exploit-db.com/exploits/11794

SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38769

PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38708

Mozilla Firefox and SeaMonkey NTLM Credential Reflection Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/37366

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35769

Mozilla Thunderbird Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38831

Bible Study Joomla! Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/37583

Energizer DUO USB Battery Charger Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/38571

Google Picasa JPEG Image Processing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38384

OSSIM 'file' Parameter Directory Traversal Vulnerability
http://www.securityfocus.com/bid/38780

OSSIM 'what' Parameter Multiple Remote Command Execution Vulnerabilities
http://www.securityfocus.com/bid/38779

OSSIM 'repository_attachment.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/37377

ABO.CMS 'c.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38847

chillyCMS 'admin/index.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38846

ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
http://www.securityfocus.com/bid/38844

Softsaurus CMS Multiple Remote File Include Vulnerabilities
http://www.securityfocus.com/bid/38842

DotNetNuke Search Function Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38841

Nensor CMS Local File Include and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38839

Citrix Web Interface Source Code Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38838

MPlayer WAV File Remote Null Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/38837

ZippHo '.zip' File Stack-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38836

myMP3-Player '.m3u' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38835

ManageEngine ServiceDesk Plus 'woID' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38834

0 件のコメント:

コメントを投稿