2010年9月15日水曜日

15日 水曜日、先負

Google Chrome 6.0.472.59 Stable and Beta released
http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html

Postfix 2.8 Snapshot 20100914
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.8-20100914.HISTORY

ASTERIA フォーラム2010(秋)開催
http://asteria.jp/news/20100914-170958.html

ウイルス検索エンジン VSAPI 9.200 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1470

5分で読める要約レポートを出力、インターコムが情報漏えい対策ソフトの新版「MaLion 3」を発表
http://itpro.nikkeibp.co.jp/article/NEWS/20100914/351974/?ST=security

2010年9月 Microsoft セキュリティ情報 (緊急 4件含) に関する注意喚起
http://www.jpcert.or.jp/at/2010/at100023.txt

JPCERT/CC WEEKLY REPORT 2010-09-15
http://www.jpcert.or.jp/wr/2010/wr103501.html

US-CERT Technical Cyber Security Alert TA10-257A -- Microsoft Updates for Multiple Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/Cert/2010-09/msg00000.html

JVNTA10-257A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA10-257A/index.html

JVNVU#275289 Adobe Flash に脆弱性
http://jvn.jp/cert/JVNVU275289/index.html

JVNVU#491991 Adobe Reader および Acrobat にバッファオーバーフローの脆弱性
http://jvn.jp/cert/JVNVU491991/index.html

Slackware update for sudo
http://secunia.com/advisories/41428/

Slackware update for samba
http://secunia.com/advisories/41424/

Fedora update for samba
http://secunia.com/advisories/41454/

Red Hat update for samba
http://secunia.com/advisories/41454/

Red Hat update for samba3x
http://secunia.com/advisories/41450/

Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/41390/

IBM Lotus Domino iCalendar Stack Overflow in MAILTO Processing Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024448.html

Samba SID Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43212

Todd Miller Sudo Runas Group Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43019




+ 2010 年 9 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms10-sep.mspx

+ MS10-061 - 緊急: 印刷スプーラー サービスの脆弱性により、リモートでコードが実行される (2347290)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-061.mspx
http://www.securityfocus.com/bid/43073

+ MS10-062 - 緊急: MPEG-4 コーデックの脆弱性により、リモートでコードが実行される (975558)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-062.mspx
http://www.securityfocus.com/bid/43039

+ MS10-063 - 緊急: Unicode スクリプト プロセッサの脆弱性により、リモートでコードが実行される (2320113)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-063.mspx
http://www.securityfocus.com/bid/43068

+ MS10-064 - 緊急: Microsoft Outlook の脆弱性により、リモートでコードが実行される (2315011)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-064.mspx
http://www.securityfocus.com/bid/43063

+ MS10-065 - 重要: Microsoft インターネット インフォメーション サービス (IIS) の脆弱性により、リモートでコードが実行される (2267960)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-065.mspx
http://www.securityfocus.com/bid/41314
http://www.securityfocus.com/bid/43140
http://www.securityfocus.com/bid/43138

+ MS10-066 - 重要: リモート プロシージャー コールの脆弱性により、リモートでコードが実行される (982802)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-066.mspx
http://www.securityfocus.com/bid/43119

+ MS10-067 - 重要: ワードパッドのテキスト コンバーターの脆弱性により、リモートでコードが実行される (2259922)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-067.mspx
http://www.securityfocus.com/bid/43122

+ MS10-068 - 重要: Local Security Authority Subsystem Service (LSASS) の脆弱性により、特権が昇格される (983539)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-068.mspx
http://www.securityfocus.com/bid/43037

+ MS10-069 - 重要: Windows クライアント/サーバー ランタイム サブシステムの脆弱性により、特権が昇格される (2121546)
http://www.microsoft.com/japan/technet/security/bulletin/ms10-069.mspx
http://www.securityfocus.com/bid/43121

+ Samba 3.3.14, 3.4.9, 3.5.5 Security Release Available
http://news.samba.org/releases/3.3.14/
http://www.samba.org/samba/history/samba-3.3.14.html
http://news.samba.org/releases/3.4.9/
http://www.samba.org/samba/history/samba-3.4.9.html
http://news.samba.org/releases/3.5.5/
http://www.samba.org/samba/history/samba-3.5.5.html

+ Buffer Overrun Vulnerability
http://www.samba.org/samba/security/CVE-2010-3069.html
http://secunia.com/advisories/41354/
http://securitytracker.com/alerts/2010/Sep/1024434.html
http://www.vupen.com/english/advisories/2010/2378
http://www.securityfocus.com/bid/43212

+ RHSA-2010:0697-1: Critical: samba security and bug fix update
http://rhn.redhat.com/errata/RHSA-2010-0697.html

- Linux Kernel ''TIOCGICOUNT'' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43226

- Linux Kernel 'CHELSIO_GET_QSET_NUM' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43221

HPSBGN02577 SSRT100224 rev.1 - 3Com OfficeConnect Gigabit VPN Firewall (3CREVF100-73), Remote Cross Site Scripting (XSS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02507909

Stack buffer overflow vulnerability in Lotus Domino iCalendar functionality
http://www-01.ibm.com/support/docview.wss?uid=swg21446515

Microsoft Security Advisory (973811): Extended Protection for Authentication
http://www.microsoft.com/technet/security/advisory/973811.mspx

Microsoft Security Advisory (2401593): Vulnerability in Outlook Web Access Could Allow Elevation of Privilege
http://www.microsoft.com/technet/security/advisory/2401593.mspx

マイクロソフト セキュリティ アドバイザリ (2401593): Outlook Web Access の脆弱性により、特権が昇格される
http://www.microsoft.com/japan/technet/security/advisory/2401593.mspx

マイクロソフト セキュリティ アドバイザリ(973811): 認証に対する保護の強化
http://www.microsoft.com/japan/technet/security/advisory/973811.mspx

RHSA-2010:0698-1: Critical: samba3x security update
http://rhn.redhat.com/errata/RHSA-2010-0698.html

Microsoft : Vulnerability in Print Spooler Service Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33677

Microsoft : Vulnerability in MPEG-4 Codec Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33678

Microsoft : Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33679

Microsoft : Vulnerability in Microsoft Outlook Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33680

Microsoft : Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33681

Microsoft : Vulnerability in Remote Procedure Call Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33682

Microsoft : Vulnerability in WordPad Text Converters Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33683

Microsoft : Vulnerability in Local Security Authority Subsystem Service Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33684

Microsoft : Vulnerability in Windows Client/Server Runtime Subsystem Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33685

AmnPardaz Security Research Team : Adobe LiveCycle ES DLL Hijacking Exploit (.dll)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33676

Mandriva : [MDVSA-2010:180] rpm Privilege Escalation
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33672

NCNIPC : Wireshark 1.4.0 Malformed SNMP V1 Packet Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33675

Secunia : MailEnable SMTP Service Two Denial of Service Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33674

ZDI : ZDI-10-169: Novell Netware SSHD.NLM Remote Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33661

ZDI : ZDI-10-170: Apple Safari Webkit Runin Remote Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33662

ZDI : ZDI-10-171: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33663

ZDI : ZDI-10-172: Mozilla Firefox tree Object Removal Remote Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33664

ZDI : ZDI-10-173: Mozilla Firefox nsTreeSelection Dangling Pointer Remote Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33665

Mandriva : [MDVSA-2010:175] Fix for Sudo Privilege Elevation
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33667

Mandriva : [MDVSA-2010:176] tomcat5 Information Disclosure
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33668

Mandriva : [MDVSA-2010:177] tomcat5 Directory Traversal
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33669

Mandriva : [MDVSA-2010:178] ocsinventory Multiple SQL-injection Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33670

Mandriva : [MDVSA-2010:179] libglpng Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33671

Debian : [DSA 2097-2] New phpmyadmin packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33673

Mandriva : [MDVSA-2010:174] quagga buffer overflow
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33666

JVNDB-2010-002006 Linux kernel の DNS resolution 機能における任意の CIFS マウントを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002006.html

JVNDB-2010-002005 Linux kernel の xfs_swapext 関数における読み込み権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002005.html

JVNDB-2010-002004 Linux kernel の mext_check_arguments 関数におけるファイルを上書きされる脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002004.html

JVNDB-2010-002003 Linux kernel の NFS サーバにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002003.html

JVNDB-2010-002002 Linux kernel の CIFS 実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002002.html

Adobe Readerのゼロデイ脆弱性、修正版を10月4日の週に公開
別のゼロデイ脆弱性も修正、公開され次第適用を
http://itpro.nikkeibp.co.jp/article/NEWS/20100915/352032/?ST=security

Flash Playerに新たな脆弱性が発覚、ゼロデイ攻撃が出現
Adobe ReaderやAcrobatも影響、修正版は2010年9月末以降に提供
http://itpro.nikkeibp.co.jp/article/NEWS/20100915/352031/?ST=security

September 2010 Microsoft Black Tuesday Summary
http://isc.sans.edu/diary.html?storyid=9547

BlackEnergy DDoS
http://isc.sans.edu/diary.html?storyid=9550

Secunia Research: Microsoft Outlook Content Parsing Integer Underflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00115.html

ZDI-10-177: IBM Lotus Domino iCalendar MAILTO Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00113.html

[ MDVSA-2010:182 ] kdegraphics
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00114.html

[FLOCK-SA-2010-04] Flock Browser: window.open() Method Javascript Same-Origin Policy
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00117.html

[FLOCK-SA-2010-03] Flock Browser: javascript: url with a leading NULL byte can bypass cr
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00112.html

[FLOCK-SA-2010-02] Flock Browser: A malicious RSS feed can bypass cross origin protectio
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00111.html

[FLOCK-SA-2010-01] Flock Browser: A malformed favourite can bypass cross origin protecti
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00110.html

New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00116.html

[USN-987-1] Samba vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00108.html

[security bulletin] HPSBMA02566 SSRT100045 rev.1 - HP System Management Homepage (SMH) for Linux
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00107.html

[ MDVSA-2010:181 ] ntop
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00106.html

[SECURITY] [DSA 2108-1] New cvsnt package fixes arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00104.html

CVE-2010-3200 : Microsoft Word 2003 MSO Null Pointer Dereference Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00102.html

rPSA-2010-0056-1 httpd mod_ssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00103.html

ZDI-10-174: Hewlett-Packard Data Protector DtbClsLogin Utf8cpy Remote Code Execution Vul
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00101.html

ZDI-10-176: Mozilla Firefox normalizeDocument Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00109.html

[DCA-00016 - Nokia E72 Keyboard Password bypass]
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00100.html

Web challenges from RootedCON2010 CTF - Contest
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00105.html

Vulnerability Note VU#491991: Adobe Reader and Acrobat Font Parsing Buffer Overflow Vulnerability
http://www.kb.cert.org/vuls/id/491991

Microsoft Internet Explorer boundElements Property Use-after-free Vulnerability
http://www.securiteam.com/windowsntfocus/5XP36152KE.html

Microsoft Internet Explorer Table Element Use-after-free Vulnerability
http://www.securiteam.com/windowsntfocus/5YP37152KY.html

Autonomy KeyView wkssr.dll Record Parsing Buffer Overflows
http://www.securiteam.com/windowsntfocus/5JP3B152KA.html

Autonomy KeyView rtfsr.dll RTF Parsing Signedness Error Vulnerability
http://www.securiteam.com/windowsntfocus/5IP3A152KU.html

Novell iPrint Client Browser Plugin operation Parameter Code Execution Vulnerability
http://www.securiteam.com/unixfocus/5ZP38152KE.html

Apple Webkit SVG First-Letter Style Code Execution Vulnerability
http://www.securiteam.com/securitynews/5AP39152KQ.html

Microsoft Exchange Server Outlook Web Access Cross-Site Request Forgery
http://secunia.com/advisories/41421/

Microsoft Outlook Content Parsing Integer Underflow Vulnerability
http://secunia.com/advisories/34075/

Microsoft Windows Client/Server Runtime Subsystem Privilege Escalation
http://secunia.com/advisories/41420/

Microsoft Windows Print Spooler Service Insufficient User Permission Restrictions
http://secunia.com/advisories/41292/

Microsoft Windows LSASS Implementation Buffer Overflow Vulnerability
http://secunia.com/advisories/41419/

Microsoft Products Unicode Scripts Processor Memory Corruption Vulnerability
http://secunia.com/advisories/41396/

Microsoft Windows MPEG-4 Codec Content Parsing Vulnerability
http://secunia.com/advisories/41395/

Microsoft Windows RPC Response Processing Vulnerability
http://secunia.com/advisories/41412/

Microsoft Windows WordPad Text Converters Document Parsing Vulnerability
http://secunia.com/advisories/41416/

Microsoft IIS Repeated Parameter Request Denial of Service
http://secunia.com/advisories/41399/

Microsoft IIS FastCGI Request Header Buffer Overflow Vulnerability
http://secunia.com/advisories/41375/

Kingsoft Antivirus kavfm.sys IOCTL Handling Vulnerability
http://secunia.com/advisories/41393/

IBM Lotus Domino iCalendar Email Address Parsing Buffer Overflow
http://secunia.com/advisories/41433/

ALZip Insecure Library Loading Vulnerability
http://secunia.com/advisories/41448/

Ubuntu update for samba
http://secunia.com/advisories/41447/

OpenX Video Plugin Open Flash Chart Vulnerability
http://secunia.com/advisories/41402/

PaysiteReviewCMS "q" and "image" Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/41431/

ALShow Insecure Library Loading Vulnerability
http://secunia.com/advisories/41414/

ALSee Insecure Library Loading Vulnerability
http://secunia.com/advisories/41415/

Debian update for cvsnt
http://secunia.com/advisories/41358/

CVSNT Branch Name Arbitrary File Creation Vulnerability
http://secunia.com/advisories/41345/

Mailman List Description Two Script Insertion Vulnerabilities
http://secunia.com/advisories/41265/

Joomla Mosets Tree Component Image File Upload Security Issue
http://secunia.com/advisories/41429/

MyHobbySite "username" and "password" SQL Injection Vulnerabilities
http://secunia.com/advisories/41355/

Samba SID Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/41354/

Adobe LiveCycle Designer Insecure Library Loading Vulnerability
http://secunia.com/advisories/41417/

IBM Products for Lotus Quickr Axis2 Vulnerability
http://secunia.com/advisories/41445/

IBM AIX sa_snap Two Vulnerabilities
http://secunia.com/advisories/41446/

xMatters Information Disclosure Security Issue
http://secunia.com/advisories/41422/

HP System Management Homepage Information Disclosure Vulnerability
http://secunia.com/advisories/41427/

SUSE update for kernel
http://secunia.com/advisories/41432/

Google Chrome Flash Plugin Unspecified Code Execution Vulnerability
http://secunia.com/advisories/41443/

SoMud Insecure Library Loading Vulnerability
http://secunia.com/advisories/41413/

gDoc Fusion Insecure Library Loading Vulnerability
http://secunia.com/advisories/41407/

Microsoft Outlook Web Access Authentication Flaw Lets Remote Users Hijack User Sessions
http://securitytracker.com/alerts/2010/Sep/1024445.html

Windows Client-Server Runtime Subsystem Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Sep/1024444.html

Microsoft Local Security Authority Subsystem Service (LSASS) Heap Overflow Lets Remote Authenticated Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024443.html

Microsoft WordPad Parsing Error in Text Converters Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024442.html

Microsoft Windows RPC Memory Allocation Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024441.html

Microsoft Internet Information Services Bugs Let Remote Users Bypass Authentication, Deny Service, and Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024440.html

Microsoft Outlook Heap Overflow Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024439.html

Microsoft Office Unicode Font Parsing in USP10.DLL Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024438.html

Windows Unicode Scripts Processor Font Parsing Error in USP10.DLL Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024437.html

Windows MPEG-4 Codec Processing Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024436.html

Windows Print Spooler Access Permission Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024435.html

Samba Buffer Overflow in sid_parse() Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024434.html

HP System Management Homepage Information Disclosure Flaw Lets Remote Authenticated Users Gain Root Access
http://securitytracker.com/alerts/2010/Sep/1024433.html

IBM AIX Buffer Overflow in sa_snap Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Sep/1024430.html

Microsoft Windows CSRSS Privilege Escalation Vulnerability (MS10-069)
http://www.vupen.com/english/advisories/2010/2390

Microsoft Windows Active Directory LSASS Heap Overflow (MS10-068)
http://www.vupen.com/english/advisories/2010/2389

Microsoft Windows WordPad Text Converters Code Execution (MS10-067)
http://www.vupen.com/english/advisories/2010/2388

Microsoft Windows RPC Unmarshalling Remote Code Execution (MS10-066)
http://www.vupen.com/english/advisories/2010/2387

Microsoft Internet Information Services (IIS) Multiple Vulnerabilities (MS10-065)
http://www.vupen.com/english/advisories/2010/2386

Microsoft Office Outlook TNEF Heap Overflow Vulnerability (MS10-064)
http://www.vupen.com/english/advisories/2010/2385

Microsoft Windows and Office Uniscribe Font Parsing Vulnerability (MS10-063)
http://www.vupen.com/english/advisories/2010/2384

Microsoft Windows MPEG-4 Codec Integer Underflow Vulnerability (MS10-062)
http://www.vupen.com/english/advisories/2010/2383

Microsoft Windows Print Spooler Service Impersonation (MS10-061)
http://www.vupen.com/english/advisories/2010/2382

IBM Lotus Domino iCalendar Remote Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2381

IBM Lotus Sametime Connect Webcontainer Unspecified Vulnerability
http://www.vupen.com/english/advisories/2010/2380

IBM FileNet/Content Manager Services for Lotus Quickr Axis2 Vulnerability
http://www.vupen.com/english/advisories/2010/2379

Samba "sid_parse()" and "dom_sid_parse()" Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2378

IBM AIX Local Buffer Overflow and File Deletion Vulnerabilities
http://www.vupen.com/english/advisories/2010/2377

IBM Proventia Network Mail Security System Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2376

Apache Traffic Server DNS Poisoning and Spoofing Vulnerability
http://www.vupen.com/english/advisories/2010/2375

Fedora Security Update Fixes Libglpng Integer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2374

Fedora Security Update Fixes Django Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/2373

Fedora Security Update Fixes Sudo Runas Group Matching Vulnerability
http://www.vupen.com/english/advisories/2010/2372

Fedora Security Update Fixes lvm2 Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/2371

Fedora Security Update Fixes Quagga Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2370

Fedora Security Update Fixes phpMyAdmin Cross Site Scripting
http://www.vupen.com/english/advisories/2010/2369

Fedora Security Update Fixes SLiM PATH Assignment Vulnerability
http://www.vupen.com/english/advisories/2010/2368

Fedora Security Update Fixes Firefox and Xulrunner Vulnerabilities
http://www.vupen.com/english/advisories/2010/2367

Fedora Security Update Fixes Thunderbird and Sunbird Vulnerabilities
http://www.vupen.com/english/advisories/2010/2366

Fedora Security Update Fixes libgdiplus Integer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2365

Fedora Security Update Fixes Kernel Multiple Local Vulnerabilities
http://www.vupen.com/english/advisories/2010/2364

Fedora Security Update Fixes libmikmod Heap Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2363

Mandriva Security Update Fixes RPM Package Manager Vulnerabilities
http://www.vupen.com/english/advisories/2010/2362

Mandriva Security Update Fixes Libglpng Integer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2361

Mandriva Security Update Fixes OCS Inventory Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2360

Mandriva Security Update Fixes Tomcat Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2359

Mandriva Security Update Fixes Sudo Runas Group Matching Vulnerability
http://www.vupen.com/english/advisories/2010/2358

Mandriva Security Update Fixes Quagga Buffer Overflow and DoS
http://www.vupen.com/english/advisories/2010/2357

Mandriva Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2356

Mandriva Security Update Fixes Kernel Privilege Escalation and DoS
http://www.vupen.com/english/advisories/2010/2355

Slackware Security Update Fixes Seamonkey Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2354

Slackware Security Update Fixes Thunderbird Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2353

Slackware Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2352

SuSE Security Update Fixes Kernel Privilege Escalation and DoS
http://www.vupen.com/english/advisories/2010/2351

Debian Security Update Fixes CVSNT Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/2350

Adobe Acrobat and Reader Flash Content Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2349

Adobe Flash Player Content Processing Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2348

IBM Lotus Domino iCalendar Email Address Stack Buffer Overflow Vulnerability
http://www.exploit-db.com/exploits/15005/

MOAUB #14 - Novell iPrint Client Browser Plugin ExecuteRequest debug Parameter Stack Overflow
http://www.exploit-db.com/exploits/15001/

Samba SID Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43212

WebKit 'window.open()' method Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38375

Flock Browser Malformed Bookmark HTML Injection Vulnerability
http://www.securityfocus.com/bid/42556

Microsoft Windows CSRSS Memory Allocation Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43121

RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/43115

Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43063

WebKit SVG Animation Elements User After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35334

Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/41462

Microsoft IIS 5.1 Alternate Data Stream Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/41314

Nokia E72 Keyboard Password Validation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/43214

Novell iPrint Client Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/42100

Apache Subrequest Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38580

Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38491

ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36074

Linux Kernel 'XFS_IOC_FSGETXATTR' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43022

Linux Kernel ''TIOCGICOUNT'' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43226

Mantis Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/43224

Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43222

Linux Kernel 'CHELSIO_GET_QSET_NUM' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43221

IBM Lotus Sametime Connect Web Container Unspecified Vulnerability
http://www.securityfocus.com/bid/43220

IBM Lotus Domino iCalendar Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43219

PECL Alternative PHP Cache 'apc.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/43218

Joomla JGen Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/43210

xMatters Notification Throughput Details Report Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43209

HP System Management Homepage Unspecified Information Disclosure Vulnerability.
http://www.securityfocus.com/bid/43208

Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
http://www.securityfocus.com/bid/43140

Microsoft IIS Request Header Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43138

Microsoft WordPad Text Converter Word 97 File Parsing Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43122

Microsoft Windows RPC Memory Allocation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43119

Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43073

Microsoft Windows and Office Uniscribe Font Parsing Engine Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43068

Microsoft MPEG-4 Codec Media File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43039

Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43037

0 件のコメント:

コメントを投稿