2010年5月4日火曜日

4日 火曜日 (みどりの日)

+ PHP dechunk Filter Signed Comparison Error Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/May/1023937.html

+ PHP HTTP Chunked Encoding Processing Signedness Vulnerability
http://secunia.com/advisories/39573/

PostgreSQL 9.0 Beta 1 Now Available
http://www.postgresql.org/about/news.1198

Red Hat : Low: Red Hat Enterprise Linux 3 - 6-Month End Of Life Notice
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32468

Debian : New squidguard packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32467

MustLive : Cross-Site Scripting vulnerability in Mango
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32472

Corelan Security Team : NolaPro Enterprise multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32470

Independent Researcher : A vulnerability in
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32471

Mandriva : Security Announce kernel
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32466

Secunia : Secunia Research: Internet Download Manager FTP Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32469

[ MDVSA-2010:089 ] gnutls
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-05/msg00003.html

Puntal (index.php) Remote File Inclusion Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-05/msg00004.html

[SECURITY] [DSA 2040-1] New squidguard packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-05/msg00002.html

Cross-Site Scripting vulnerability in Mango
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-05/msg00001.html

A vulnerability in Kaspersky Antivirus
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-05/msg00000.html

SIFT review in the ISSA Toolsmith
http://isc.sans.org/diary.html?storyid=8737

Social engineering via paper mail
http://isc.sans.org/diary.html?storyid=8734

Adobe Photoshop TIFF File Processing Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/May/1023936.html

MDaemon Directory Traversal Flaw in SUBSCRIBE Command Lets Remote Users View Certain Files on the Target System
http://securitytracker.com/alerts/2010/May/1023935.html

ProSSHD 1.2 remote post-auth exploit (w/ASLR and DEP bypass)
http://www.exploit-db.com/exploits/12495

Table JX Component for Joomla Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1053

Card View JX Component for Joomla Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1052

OpenMairie openCatalogue "dsn[phptype]" File Inclusion Vulnerability
http://www.vupen.com/english/advisories/2010/1051

OpenMairie openCimetiere "path_om" File Inclusion Vulnerabilities
http://www.vupen.com/english/advisories/2010/1050

Adobe Photoshop CS4 TIFF Handling Buffer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/1049

NolaPro Multiple Cross Site Scripting and SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2010/1048

ABC Backup ZIP Archive Handling Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/1047

InternetSoft Urgent Backup Archive Handling Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/1046

Fedora Security Update Fixes GNU Nano Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/1045

Fedora Security Update Fixes OpenDCHub Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/1044

Debian Security Update Fixes squidGuard Filter Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/1043

Mandriva Security Update Fixes Kernel Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/1042

Joomla! DJ-Classifieds Component Script Insertion and File Upload Vulnerabilities
http://secunia.com/advisories/39681/

Mesut Manset Haber Security Bypass Vulnerability
http://secunia.com/advisories/39682/

NolaPro "linenum" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/39674/

NolaPro Cross-Site Scripting and SQL Injection Vulnerabilities
http://secunia.com/advisories/39671/

Scratcher Two Vulnerabilities
http://secunia.com/advisories/39631/

DBHcms Cross-Site Scripting and Script Insertion
http://secunia.com/advisories/39691/

Comersus Power Pack Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/39715/

Comersus Cart Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/39695/

NIBE RCU 11 Multiple Vulnerabilities
http://secunia.com/advisories/39637/

B2B Gold Script "id" SQL Injection Vulnerability
http://secunia.com/advisories/39710/

KrM Haber Database Disclosure Security Issue
http://secunia.com/advisories/39700/

ABC Backup ZIP Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/39701/

Urgent Backup ZIP Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/39699/

Campsite "article_id" SQL Injection Vulnerability
http://secunia.com/advisories/39580/

MDaemon Mailing List Subscription Directory Traversal
http://secunia.com/advisories/39672/

Geeklog Forum Cross-Site Scripting Vulnerability
http://secunia.com/advisories/39683/

LXR Cross Referencer Cross-Site Scripting Vulnerability
http://secunia.com/advisories/39686/

Password Manager Daemon "key_file" Parameter Security Issue
http://secunia.com/advisories/39684/

openMairie openCatalogue "dsn[phptype]" Local File Inclusion Vulnerability
http://secunia.com/advisories/39688/

Fedora update for opendchub
http://secunia.com/advisories/39664/

Debian update for squidguard
http://secunia.com/advisories/39679/

openMairie openCimetiere File Inclusion Vulnerabilities
http://secunia.com/advisories/39687/

JobPost "iType" SQL Injection Vulnerability
http://secunia.com/advisories/39708/

Adobe Photoshop CS4 TIFF File Processing Vulnerabilities
http://secunia.com/advisories/39711/

ProSSHD 'scp_get()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38487

Microsoft Windows Movie Maker and Producer '.mswmm' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38515

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
http://www.securityfocus.com/bid/38959

OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36844

Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
http://www.securityfocus.com/bid/23742

Sendmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/37543

Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/37985

Wireshark ERF File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36591

Wireshark 1.2.2 and 1.0.9 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36846

Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
http://www.securityfocus.com/bid/37407

Wireshark 1.2.0 Multiple Vulnerabilities
http://www.securityfocus.com/bid/35748

Todd Miller Sudo 'sudoedit' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38362

squidGuard Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36800

Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
http://www.securityfocus.com/bid/39308

D-Bus 'dbus_signature_validate()' Type Signature Denial of Service Vulnerability
http://www.securityfocus.com/bid/31602

Opera Web Browser Asynchronous Document Modifications Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/39855

Joomla! 'com_grid' Component Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/39854

no$gba '.nds' File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39852

GNU nano Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/39502

Gallo 'gfw_smarty.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/39890

Torrent Hoster 'forgot_password.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/39889

Password Manager Daemon (pwmd) Binary Key File Insecure Encryption Vulnerability
http://www.securityfocus.com/bid/39882

IslamSound Multiple Remote SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/39880

Geeklog Forum Plugin Anonymous Usernames Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/39873

Acritum Femitter Server 1.03 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/39868

DBHcms Cross Site Scripting and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/39866

LXR Cross Referencer 'title' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/39865

Mango Blog 'archives.cfm/search' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/39864

0 件のコメント:

コメントを投稿