2010年3月26日金曜日

26日 金曜日、赤口

ウイルス検索エンジン VSAPI 9.120 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1384

JVNDB-2010-001194 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001194.html

JVNDB-2010-001193 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001193.html

JVNDB-2010-001192 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001192.html

JVNDB-2010-001191 Apple Safari の WebKit における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001191.html

JVNDB-2010-001190 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001190.html

JVNDB-2010-001189 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001189.html

JVNDB-2010-001188 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001188.html

JVNDB-2010-001187 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001187.html




+ RHSA-2010:0162-1: Important: openssl security update
http://rhn.redhat.com/errata/RHSA-2010-0162.html

+ RHSA-2010:0163-1: Moderate: openssl security update
http://rhn.redhat.com/errata/RHSA-2010-0163.html

+ RHSA-2010:0165-1: Moderate: nss security update
http://rhn.redhat.com/errata/RHSA-2010-0165.html

+ RHSA-2010:0166-1: Moderate: gnutls security update
http://rhn.redhat.com/errata/RHSA-2010-0166.html

+ RHSA-2010:0167-1: Moderate: gnutls security update
http://rhn.redhat.com/errata/RHSA-2010-0167.html

+ RHSA-2010:0168-1: Moderate: httpd security and enhancement update
http://rhn.redhat.com/errata/RHSA-2010-0168.html

+ RHSA-2010:0173-2: Important: openssl096b security update
http://rhn.redhat.com/errata/RHSA-2010-0173.html

+ RHSA-2010:0175-1: Low: httpd security, bug fix, and enhancement update
http://rhn.redhat.com/errata/RHSA-2010-0175.html

+ OpenSSL 'bn_wexpend()' Error Handling Unspecified Vulnerability
http://www.securityfocus.com/bid/38562

- HPSBUX02509 SSRT100032 rev.1 - HP-UX Running NFS/ONCplus, NFS Inadvertently Enabled
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02026642

- RHSA-2010:0164-1: Moderate: openssl097a security update
http://rhn.redhat.com/errata/RHSA-2010-0164.html

- Microsoft Internet Explorer Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/38951

[Announce] Apache Qpid version 0.6 is released
http://www.apache.org/dist/qpid/0.6

HPSBMA02436 SSRT080064 rev.1 - HP Project and Portfolio Management Center (PPMC), Remote Cross Site Scripting (XSS)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01762443&admit=109447627+1269566153893+28353475

Postgres participating in Google Summer of Code 2010
http://www.postgresql.org/about/news.1189

Suhosin-Extension 0.9.30 released
http://www.hardened-php.net/suhosin/changelog.html

Document ID: 347809: Disks from IBM XIV array appear as Symmetrix and IBM disks in Veritas Enterprise Administrator (VEA).
http://seer.entsupport.symantec.com/docs/347809.htm

RHBA-2010:0174-1: strace bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0174.html

Red Hat : Important: openssl security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32085

Red Hat : Moderate: openssl security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32086

Red Hat : Moderate: openssl097a security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32087

Red Hat : Moderate: nss security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32088

Red Hat : Moderate: gnutls security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32089

Red Hat : Moderate: gnutls security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32090

Red Hat : Moderate: httpd security and enhancement update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32091

Red Hat : Important: openssl096b security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32092

Cisco : Cisco Unified Communications Manager Express Denial of Service Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32093

Cisco : Cisco IOS Software H.323 Denial of Service Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32094

Cisco : Cisco IOS Software IPsec Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32095

Cisco : Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32096

Cisco : Cisco IOS Software NAT Skinny Call Control Protocol Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32097

Cisco : Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32098

Cisco : Cisco IOS Software Crafted TCP Packet Denial of Service Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32099

Cisco : Pulse CMS Arbitrary File Writing Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32102

Compass Security : OpenCMS OAMP Comments Module XSS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32105

フィンランドの人気サイトからパスワード流出、最多は「salasana」
12万7000件以上のユーザー情報が漏えい、安易なパスワードが多数
http://itpro.nikkeibp.co.jp/article/NEWS/20100326/346226/?ST=security

Gmailに「なりすまし検出機能」、怪しいログインを警告
IPアドレスからログイン元を特定、いつもと異なる場合はユーザーに通知
http://itpro.nikkeibp.co.jp/article/NEWS/20100326/346257/?ST=security

F5がゲートウエイ製品に本人認証システムとの連携機能を追加
http://itpro.nikkeibp.co.jp/article/NEWS/20100325/346203/?ST=security

Multiple Vulnerabilities in EASY Enterprise DMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00216.html

=?Windows-1252?Q?There_is_a?= =?Windows-1252?Q?_Permanent?= =?Windows-1252?Q?-type_C
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00220.html

Ruxcon 2010 Call For Papers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00219.html

[security bulletin] HPSBUX02508 SSRT100007 rev.1 - HP-UX Running sendmail with STARTTLS Enab
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00215.html

[security bulletin] HPSBMA02436 SSRT080064 rev.1 - HP Project and Portfolio Management Center (P
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00214.html

Hackito Ergo Sum Conference (Paris 8-10 April 2010) : Schedule
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00218.html

[ MDVSA-2010:066 ] kernel
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00213.html

Vulnerabilities in WeBAM
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00212.html

"Copyright Lawsuit filed against you"
http://isc.sans.org/diary.html?storyid=8497

Responding to "Copyright Lawsuit filed against you"
http://isc.sans.org/diary.html?storyid=8500

Zeus wants to do your taxes
http://isc.sans.org/diary.html?storyid=8503

Vulnerability Note VU#512705: Broadcom NetXtreme managment firmware ASF buffer overflow
http://www.kb.cert.org/vuls/id/512705

HP-UX update for sendmail
http://secunia.com/advisories/39088/

Discuz! "Referer" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/39104/

Alkacon OpenCms Comments Module Script Insertion Vulnerability
http://secunia.com/advisories/39099/

INVOhost Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/39095/

justVisual CMS "p" Local File Inclusion Vulnerability
http://secunia.com/advisories/39093/

Red Hat update for gnutls
http://secunia.com/advisories/39127/

Red Hat update for gnutls
http://secunia.com/advisories/39084/

Red Hat update for openssl097a
http://secunia.com/advisories/39126/

Red Hat update for openssl
http://secunia.com/advisories/39125/

Red Hat update for openssl
http://secunia.com/advisories/39124/

Red Hat update for openssl096b
http://secunia.com/advisories/39092/

Red Hat update for httpd
http://secunia.com/advisories/39100/

Red Hat update for nss
http://secunia.com/advisories/39089/

Interchange HTTP Response Splitting Vulnerability
http://secunia.com/advisories/39103/

HP Project and Portfolio Management Center Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/39105/

Drupal Menu Block Module Script Insertion Vulnerability
http://secunia.com/advisories/39109/

Drupal Mime Mail Module Arbitrary Code Execution Vulnerability
http://secunia.com/advisories/39118/

Sandbox Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/39064/

Cisco IOS TCP Options Denial of Service Vulnerability
http://secunia.com/advisories/39078/

Cisco IOS H.323 Two Denial of Service Vulnerabilities
http://secunia.com/advisories/39067/

Cisco IOS SIP Implementation Multiple Vulnerabilities
http://secunia.com/advisories/39068/

Cisco IOS Label Distribution Protocol Denial of Service
http://secunia.com/advisories/39065/

Cisco IOS NAT SCCP Fragmentation Denial of Service
http://secunia.com/advisories/39062/

Cisco IOS IPsec IKE Packet Denial of Service
http://secunia.com/advisories/39057/

SAP GUI version 7.00 BExGlobal Active-X unsecure method
http://www.exploit-db.com/exploits/11879

eDisplay Personal FTP server 1.0.0 Multiple Post-Authentication Stack BOF
http://www.exploit-db.com/exploits/11877

KenWard's Zipper v1.400 Buffer Overflow - Method 2
http://www.exploit-db.com/exploits/11872

Redhat Security Update Fixes httpd "mod_proxy_ajp" Vulnerabilities
http://www.vupen.com/english/advisories/2010/0715

Redhat Security Update Fixes GnuTLS Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/0714

GnuTLS X.509 Certificate Serial Number Extraction Vulnerability
http://www.vupen.com/english/advisories/2010/0713

Redhat Security Update Fixes NSS TLS Plaintext Injection Vulnerability
http://www.vupen.com/english/advisories/2010/0712

Redhat Security Update Fixes OpenSSL and OpenSSL097a Vulnerabilities
http://www.vupen.com/english/advisories/2010/0711

OpenSSL TLS Connection Record Handling Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0710

Cisco IOS IPsec Internet Key Exchange Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0709

Cisco IOS NAT SCCP Fragmentation Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0708

Cisco IOS Multiprotocol Label Switching Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0707

Cisco IOS H.323 Implementation Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/0706

Cisco IOS Session Initiation Protocol Code Execution and DoS Issues
http://www.vupen.com/english/advisories/2010/0705

Cisco IOS Unified Communications Manager Express Denial of Service
http://www.vupen.com/english/advisories/2010/0704

Cisco IOS TCP Packet Processing Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0703

Fedora Security Update Fixes Firefox and Xulrunner Vulnerabilities
http://www.vupen.com/english/advisories/2010/0702

Ubuntu Security Update Fixes Samba Directory Traversal Vulnerability
http://www.vupen.com/english/advisories/2010/0701

Ubuntu Security Update Fixes Puppet Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0700

Ubuntu Security Update Fixes krb5 Two Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/0699

Mandriva Security Update Fixes Kernel Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/0698

Apple Safari 4 Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38955

Joomla! CKForms Component 'fid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38785

Drupal Mime Mail Module PHP Code Execution Vulnerability
http://www.securityfocus.com/bid/38950

Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37325

GNU Tar and GNU Cpio Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38628

Apache Subrequest Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38580

Sendmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/37543

GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
http://www.securityfocus.com/bid/38959

Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38491

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

OpenSSL 'bn_wexpend()' Error Handling Unspecified Vulnerability
http://www.securityfocus.com/bid/38562

OpenSSL 'dtls1_retrieve_buffered_fragment()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38533

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

Easy-Clanpage User 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/28329

Microsoft Internet Explorer Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/38951

UltraISO CCD and IMG File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34363

Crimson Editor '.cfg' File Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38900

Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38027

Linux Kernel 'do_pages_move()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38144

Linux e1000e Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37523

Oracle Java SE and Java For Business March 2010 Advanced Notification
http://www.securityfocus.com/bid/38973

JINAIS IRC Message Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38972

New-CMS 'pg' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/38971

justVisual 'p' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/38970

Smart PC Recorder MP3 File Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38969

Cisco TFTP Server Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38968

WeBAM Denial of Service Vulnerability and CAPTCHA Bypass Vulnerability
http://www.securityfocus.com/bid/38967

EASY ENTERPRISE Multiple Vulnerabilities
http://www.securityfocus.com/bid/38966

INVOhost Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38962

0 件のコメント:

コメントを投稿