2010年8月17日火曜日

17日 火曜日、友引

JVNVU#320233 Wyse ThinOS LPD サービスにバッファオーバーフローの脆弱性
http://jvn.jp/cert/JVNVU320233/index.html

Blue Coat ProxySG Privilege Enforcement Bypass Vulnerability
http://secunia.com/advisories/40992/

MUSE v4.9.0.006 (.pls) Local Universal Buffer Overflow [SEH]
http://www.exploit-db.com/exploits/14664/

MUSE v4.9.0.006 (.m3u) Local Buffer Overflow Exploit
http://www.exploit-db.com/exploits/14663/




+ Dovecot 2.0.0 released
http://www.dovecot.org/list/dovecot-news/2010-August/000167.html

+ CVE-2010-3014: Coda Filesystem Kernel Memory Disclosure
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00196.html
http://archives.neohapsis.com/archives/bugtraq/current/0198.html

+ Linux Kernel EXT4 Multiple Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/42477

- Struts 2.2.1 General Availability Release
http://struts.apache.org/2.2.1/
http://struts.apache.org/2.2.1/docs/version-notes-221.html

- Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41446

- Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
http://www.securityfocus.com/bid/42467

[ANNOUNCE] Apache CouchDB 1.0.1 has been released
http://couchdb.apache.org/notice/1.0.1.html

CVE-2010-3014: Coda Filesystem Kernel Memory Disclosure
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00196.html

[ MDVSA-2010:154 ] cabextract
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00194.html

[ MDVSA-2010:153 ] apache
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00193.html

[USN-971-1] OpenJDK vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00195.html

[ MDVSA-2010:152 ] apache
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00192.html

Xilisoft Video Converter Wizard 3 ogg file processing DoS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00189.html

XSS vulnerability in CMSimple
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00191.html

XSS vulnerability in CMSimple
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00190.html

XSS vulnerability in CMSimple
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00188.html

XSRF (CSRF) in CMSimple
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00187.html

XSS vulnerability in pimcore
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00185.html

[ MDVSA-2010:151 ] libmikmod
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00186.html

Jgrid 1.0 Joomla Component Local File Inclusion Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00183.html

Insecure secure cookie in Tornado
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00182.html

[ MDVSA-2010:150 ] libsndfile
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00177.html

Easy FTP Server v1.7.0.11 DELE, STOR, RNFR, RMD, XRMD Command Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00176.html

ACollab Multiple Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00175.html

iDefense Security Advisory 08.10.10: Microsoft Office RTF Parsing Engine Memory Corruption Vulnerabi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00174.html

JVNDB-2010-001829 Siemens Simatic WinCC および Simatic PCS 7 の SCADA システムにおける権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001829.html

JVNDB-2010-001828 複数の Mozilla 製品におけるスクリプトパラメータに関する重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001828.html

JVNDB-2010-001827 複数の Mozilla 製品における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001827.html

JVNDB-2010-001826 複数の Mozilla 製品における SSL セキュリティステータスを偽装される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001826.html

JVNDB-2010-001825 複数の Mozilla 製品の startDocumentLoad 関数における脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001825.html

JVNDB-2010-001824 複数の Mozilla 製品におけるクロスサイトスクリプティングを誘導される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001824.html

JVNDB-2010-001496 Apple Safari における window オブジェクトの処理に脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001496.html

JVNDB-2010-001333 複数の Oracle 製品の ImageIO コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001333.html

JVNDB-2010-001331 複数の Oracle 製品の ImageIO コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001331.html

JVNDB-2010-001327 複数の Oracle 製品の Java 2D コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001327.html

JVNDB-2010-001325 複数の Oracle 製品の Java 2D コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001325.html

JVNDB-2010-001323 複数の Oracle 製品の Sound コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001323.html

JVNDB-2010-001322 複数の Oracle 製品の Java 2D コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001322.html

JVNDB-2010-001319 複数の Oracle 製品の Sound コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001319.html

JVNDB-2010-001318 複数の Oracle 製品の Sound コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001318.html

JVNDB-2010-001152 IBM Lotus Domino Web Access の ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001152.html

Blind Elephant: A New Web Application Fingerprinting Tool
http://isc.sans.edu/diary.html?storyid=9412

The Strange Case of Doctor Jekyll and Mr. ED
http://isc.sans.edu/diary.html?storyid=9388

Palm Pre WebOS Multiple Vulnerabilities
http://secunia.com/advisories/40975/

KnowledgeTree Web Service Document Upload Manager Vulnerability
http://secunia.com/advisories/40986/

Zomplog Cross-Site Scripting and Request Forgery Vulnerabilities
http://secunia.com/advisories/40988/

Fedora update for ssmtp
http://secunia.com/advisories/41009/

Ruby WEBrick UTF-7 Error Message Cross-Site Scripting Vulnerability
http://secunia.com/advisories/41003/

Fedora update for httpd
http://secunia.com/advisories/41008/

SUSE update for flash-player
http://secunia.com/advisories/40913/

Fedora update for drupal
http://secunia.com/advisories/41007/

Vulnerability Note VU#320233: Wyse ThinOS LPD service buffer overflow vulnerability
http://www.kb.cert.org/vuls/id/320233

glpng PNG Processing Two Integer Overflow Vulnerabilities
http://securityreason.com/securityalert/7662

123 Flashchat version 7.8 Multiple Remote Vulnerabilities
http://www.exploit-db.com/exploits/14658/

Rosoft media player 4.4.4 SEH Buffer Overflow
http://www.exploit-db.com/exploits/14651/

Microsoft Windows Kerberos "Pass The Ticket" Replay Vulnerability
http://www.vupen.com/english/advisories/2010/2097

Ruby WEBrick Error Pages Handling Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/2096

Fedora Security Update Fixes Apache Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2095

Fedora Security Update Fixes Drupal Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2094

Fedora Security Update Fixes Perl Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2093

Fedora Security Update Fixes Ssmtp Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2092

SuSE Security Update Fixes Flash Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2091

Mandriva Security Update Fixes Libsndfile Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/2090

libmikmod Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42464

libmikmod Version 3.1.12 Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/41917

Retired: CruxCMS 'login.php' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/41501

CMSQLite 'admin/mediaAdmin.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/42465

Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41446

File Sharing Wizard 'HEAD' Command Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40928

FreeType Compact Font Format (CFF) Multiple Stack Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/42241

Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/42148

Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/41963

uplusware UplusFtp Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38102

libmikmod Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38114

Ruby WEBrick UTF-7 Encoding Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40895

Ingress Database Server Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/24585

Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/42203

Rosoft Media Player '.m3u' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42338

Multiple Vendor ToolTalk Heap Overflow Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41598

libsndfile Audio Data Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/35126

Wyse ThinOS Remote LPD Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42482

123 Flash Chat Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/42478

Linux Kernel EXT4 Multiple Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/42477

OpenJDK 'IcedTea' Plugin Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42476

Xilisoft Video Converter '.ogg' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42473

pam-xauth Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/42472

Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
http://www.securityfocus.com/bid/42467

Zomplog 'message' Parameter Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/42457

PHP-Fusion 'maincore.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/42456

Joomla! 'com_weblinks' Component 'Itemid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/42455

Easy FTP Server (AKA UplusFTP) Multiple Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/42469

ACollab 'sign_in.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/42461

0 件のコメント:

コメントを投稿