2010年8月10日火曜日

10日 火曜日、先勝

Ubuntu update for w3m
http://secunia.com/advisories/40888/

Ubuntu update for openldap
http://secunia.com/advisories/40886/

AoAAudioExtractor 2.0.0.0 ActiveX PoC (SEH)
http://www.exploit-db.com/exploits/14593/

OpenLDAP 'modrdn' Request Multiple Vulnerabilities
http://www.securityfocus.com/bid/41770




+ Sudo 1.7.4p2 released
http://www.sudo.ws/sudo/news.html
http://www.sudo.ws/sudo/stable.html#1.7.4p2

+ OpenSSL "ssl3_get_key_exchange()" Use-After-Free Vulnerability
http://secunia.com/advisories/40906/
http://securitytracker.com/alerts/2010/Aug/1024296.html
http://www.vupen.com/english/advisories/2010/2038
http://www.securityfocus.com/bid/42306

- Cisco Security Advisory: SNMP Version 3 Authentication Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtml

MustLive : Cross-Site Scripting vulnerability in Mozilla Firefox, Opera and other browsers
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33378

JVNDB-2010-001802 Oracle Sun Java System Application Server および Oracle GlassFish Enterprise Server の GUI における脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001802.html

JVNDB-2010-001801 Oracle Solaris Studio における脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001801.html

JVNDB-2010-001800 Oracle OpenSSO Enterprise における脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001800.html

JVNDB-2010-001799 Oracle OpenSSO Enterprise の OpenSSO コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001799.html

JVNDB-2010-001798 Oracle OpenSSO Enterprise の Access Manager / OpenSSO コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001798.html

JVNDB-2010-001797 Oracle Sun Convergence における脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001797.html

JVNDB-2010-001796 Oracle Sun Java System Web Proxy Server の管理サーバにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001796.html

Free/inexpensive tools for monitoring systems/networks
http://isc.sans.edu/diary.html?storyid=9358

ZDI-10-146: Apple Webkit Anchor Tag Mouse Click Event Dispatch Remote Code Execution Vulnera
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00108.html

ZDI-10-145: Novell ZENWorks Remote Management Agent Weak Authentication Remote Code Executio
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00107.html

ZDI-10-144: Apple Webkit Rendering Counter Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00106.html

Nagios XI 2009R1.2B Multiple CSRF
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00105.html

ZDI-10-143: Novell Sentinel Log Manager Multiple Servlet Remote Code Execution Vulnerabiliti
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00104.html

SQL injection vulnerability in allinta CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00101.html

XSS vulnerability in allinta CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00100.html

SQL injection vulnerability in allinta CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00099.html

XSS vulnerability in allinta CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00103.html

XSS vulnerability in Eden Platform
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00102.html

XSS vulnerability in Eden Platform
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00098.html

XSS vulnerability in allinta CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00097.html

QQ Computer Manager TSKsp.sys Driver Local Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00096.html

cgTestimonial 2.2 Joomla Component Multiple Remote Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00093.html

[SECURITY] [DSA 2090-1] New socat packages fix arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00094.html

Tycoon Baseball Script "game_id" SQL Injection Vulnerability
http://secunia.com/advisories/40920/

ZNC Denial of Service Vulnerabilities
http://secunia.com/advisories/40919/

Debian update for cabextract
http://secunia.com/advisories/40854/

Joomla! cgTestimonial Component Cross-Site Scripting and Arbitrary File Upload
http://secunia.com/advisories/40926/

Babiloo Insecure Temporary Files Security Issue
http://secunia.com/advisories/40884/

Debian update for socat
http://secunia.com/advisories/40914/

OpenSSL "ssl3_get_key_exchange()" Use-After-Free Vulnerability
http://secunia.com/advisories/40906/

RSA enVision Denial of Service Vulnerability
http://secunia.com/advisories/40924/

cabextract -- 1, Infinite loop in MS-ZIP
http://securityreason.com/securityalert/7649

LibTIFF 'td_stripbytecount' NULL Pointer Dereference Remote Denial of Service
http://securityreason.com/securityalert/7648

OpenSSL Key Exchange Memory Corruption Error Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Aug/1024296.html

dBpowerAMP Audio Player 2 (FileExists) ActiveX Buffer Overflow Exploit
http://www.exploit-db.com/exploits/14586/

Advanced File Vault(eSellerateControl350.dll) Activex Heap Spray 0-day
http://www.exploit-db.com/exploits/14580/

Fat Player 0.6b WAV File Processing Buffer Overflow (SEH)
http://www.exploit-db.com/exploits/14591/

myMP3-Player v3.0 Buffer Overflow Exploit
http://www.exploit-db.com/exploits/14581/

Linux Kernel <= 2.6.33.3 SCTP INIT Remote DoS
http://www.exploit-db.com/exploits/14594/

Visual MP3 Splitter & Joiner 6.1 Denial of Service Vulnerability
http://www.exploit-db.com/exploits/14587/

QQ Computer Manager TSKsp.sys Local Denial of Service Exploit
http://www.exploit-db.com/exploits/14584/

ffdshow Video Codec Denial of Service Vulnerability
http://www.exploit-db.com/exploits/14582/

OpenSSL "ssl3_get_key_exchange()" Use-after-free Vulnerability
http://www.vupen.com/english/advisories/2010/2038

Cisco Firewall Services Module Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/2037

Novell Sentinel Log Manager Unauthorized File Access Vulnerability
http://www.vupen.com/english/advisories/2010/2036

Bugzilla Information Disclosure and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2035

IBM WebSphere Service Registry and Repository Cross Site Scripting
http://www.vupen.com/english/advisories/2010/2034

Cisco Wireless Control System Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/2033

Mandriva Security Update Fixes LibTIFF Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2032

Ubuntu Security Update Fixes PCSC-Lite Buffer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2031

Debian Security Update Fixes Socat Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2030

Fat Player '.wav' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42068

Novell ZENworks Remote Management Password Security Bypass Vulnerability
http://www.securityfocus.com/bid/42175

WebKit CSS Counters Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42036

Autonomy KeyView Filter Module Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/41928

Multiple Mozilla Products 'importScripts()' Method Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41871

Multiple Mozilla Products Script Filename Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41860

Mozilla Firefox 'about:blank' Document URI Spoofing Vulnerability
http://www.securityfocus.com/bid/41055

Mozilla Firefox and Thunderbird Character Mapping Security Weakness
http://www.securityfocus.com/bid/41866

Bugzilla Multiple Vulnerabilities
http://www.securityfocus.com/bid/42275

Mozilla Firefox and Sea Monkey Location Bar Spoofing Vulnerability
http://www.securityfocus.com/bid/41968

libpng Memory Corruption and Memory Leak Vulnerabilities
http://www.securityfocus.com/bid/41174

Multiple Mozilla Products CSS Selectors Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41872

Mozilla Firefox and Thunderbird Canvas Element Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41878

Mozilla Firefox, Thunderbird, and SeaMonkey 'nsTreeSelection' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41853

Mozilla Firefox and SeaMonkey 'NodeIterator' Use-After-Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41845

Mozilla Firefox and SeaMonkey Plugin Parameters Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41842

Mozilla Firefox, Thunderbird and SeaMonkey CSS Values Integer Overflow Vulnerability
http://www.securityfocus.com/bid/41852

Mozilla Firefox and Thunderbird 'SJOW' Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/41868

Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1211 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/41859

Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1212 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/41865

Mozilla Firefox and SeaMonkey DOM Cloning Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41849

Novell Sentinel Log Manager Multiple Tomcat Servlet Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/42271

PHP-Nuke 'Web_Links' Module SQL Injection Vulnerability
http://www.securityfocus.com/bid/41546

RETIRED: KDPics 'index.php3' Remote File Include Vulnerability
http://www.securityfocus.com/bid/42312

KDPics Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/21515

Pragyan CMS Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34707

Pragyan CMS 'form.lib.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/30235

HP OpenView Network Node Manager 'OvJavaLocale' Cookie Value Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/42154

Net-SNMP Remote Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/29623

Git 'gitdir' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41891

PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities
http://www.securityfocus.com/bid/41991

PHP 'SplObjectStorage' Unserializer Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/40948

PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38708

myMP3-Player '.m3u' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38835

Preation Eden Platform Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/42321

Allinta CMS Multiple SQL Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/42320

Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42316

ffdshow '.mp4' File Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42305

Nagios XI Multiple Cross Site Request Forgery Vulnerabilities
http://www.securityfocus.com/bid/42322

Mini-stream Ripper '.m3u' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42309

OpenSSL 'ssl3_get_key_exchange()' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42306

0 件のコメント:

コメントを投稿