2010年9月9日木曜日

9日 木曜日、先負

+? ActivePerl 5.12.2.1202 released
http://www.activestate.com/activeperl/downloads

zenphoto "a" SQL Injection Vulnerability
http://secunia.com/advisories/41350/

zenphoto "user" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/41342/

WordPress Events Manager Extended Plugin Script Insertion Vulnerabilities
http://secunia.com/advisories/41294/

Adobe Reader / Acrobat Font Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/41340/

Gentoo update for sarg
http://secunia.com/advisories/41326/

Nagios XI Status/Dashboard Pages Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/41121/

Debian update for freetype
http://secunia.com/advisories/41315/

phpMyAdmin Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/41210/

Beehive Forum Cross-Site Scripting and Request Forgery Vulnerabilities
http://secunia.com/advisories/41339/

ColdGen ColdOfficeView "EventID" and "UserID" SQL Injection Vulnerabilities
http://secunia.com/advisories/41332/

ColdGen ColdUserGroup Cross-Site Scripting and SQL Injection Vulnerabilities
http://secunia.com/advisories/41335/

Textpattern "q" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/41305/

ColdGen ColdCalendar "EventID" SQL Injection Vulnerability
http://secunia.com/advisories/41333/

Linux Kernel "xfs_ioc_fsgetxattr()" Memory Leak
http://secunia.com/advisories/41284/

ColdGen ColdBookmarks "BookmarkID" SQL Injection Vulnerability
http://secunia.com/advisories/41334/

Apple Safari Multiple Vulnerabilities
http://secunia.com/advisories/41334/

HP ProLiant Onboard Administrator Powered By LO100i Denial of Service
http://secunia.com/advisories/41343/

IP.Board Script Insertion Vulnerability
http://secunia.com/advisories/41314/

Red Hat update for thunderbird
http://secunia.com/advisories/41329/

Gentoo update for acroread
http://secunia.com/advisories/41325/

Red Hat update for seamonkey
http://secunia.com/advisories/41318/

Integard Home and Pro Web Interface Buffer Overflow Vulnerability
http://secunia.com/advisories/41312/

Mozilla Thunderbird Multiple Vulnerabilities
http://secunia.com/advisories/41304/

Red Hat update for firefox
http://secunia.com/advisories/41302/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/41299/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/41297/

Ubuntu update for LFTP
http://secunia.com/advisories/41311/

Red Hat update for rpm
http://secunia.com/advisories/41336/

Red Hat update for sudo
http://secunia.com/advisories/41338/

Gentoo update for clamav
http://secunia.com/advisories/41324/

Ubuntu update for sudo
http://secunia.com/advisories/41307/

Red Hat update for kernel
http://secunia.com/advisories/41341/

Mozilla Thunderbird updated to version 3.1.3 also, more here: http://www.mozillamessaging.com/en-US/thunderbird/3.1.3/releasenotes/
http://isc.sans.edu/diary.html?storyid=9520

Adobe Acrobat/Reader 0-day in Wild, Adobe Issues Advisory
http://isc.sans.edu/diary.html?storyid=9523

Microsoft Movie Maker Remote Code Execution (MS10-016)
http://securityreason.com/securityalert/7739

HP LaserJet Printers, HP Digital Senders Unauthorized File Access Vulnerability
http://www.securiteam.com/securitynews/5PP2V2A2KQ.html

Microsoft Windows Media Player Codec Retrieval Dangling Pointer Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/5QP2W2A2KW.html

Cisco Wireless LAN Controller Flaws Let Remote Authenticated Users Gain Elevated Privileges and Remote Users Bypass ACLs and Deny Service
http://securitytracker.com/alerts/2010/Sep/1024408.html

Mozilla Thunderbird DLL Loading Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024407.html

Mozilla Firefox DLL Loading Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024406.html

Mozilla Thunderbird Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Obtain Potentially Sensitive Information, and Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024403.html

Mozilla Firefox Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Obtain Potentially Sensitive Information, and Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024401.html

Apple Safari Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Sep/1024400.html

HP ProLiant G6 Lights-Out 100 Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Sep/1024398.html

Microsoft Movie Maker Remote Code Execution (MS10-016)
http://securityreason.com/securityalert/7739

MFSA 2010-63 XMLHttpRequest の statusText を通じた情報漏えい
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-63.html

MFSA 2010-62 designMode ドキュメントへのコピー&ペーストやドラッグ&ドロップによる XSS
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-62.html

MFSA 2010-61 object 要素の type 属性を使ってドキュメントの文字エンコーディングを上書きすることによる UTF-7 XSS
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-61.html

MFSA 2010-59 SJOW によって外部オブジェクトを含むスコープチェーンが作成される
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-59.html

MFSA 2010-58 data: URL に含まれた悪質なフォントによる Mac 版のクラッシュ
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-58.html

MFSA 2010-57 normalizeDocument におけるクラッシュとリモートコード実行
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-57.html

MFSA 2010-56 nsTreeContentView におけるダングリングポインタ脆弱性
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-56.html

MFSA 2010-55 XUL ツリーの削除によるクラッシュとリモートコード実行
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-55.html

MFSA 2010-54 nsTreeSelection におけるダングリングポインタ脆弱性
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-54.html

MFSA 2010-53 nsTextFrameUtils::TransformText におけるヒープバッファオーバーフロー
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-53.html

MFSA 2010-52 Windows XP における DLL 読み込み脆弱性
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-52.html

MFSA 2010-51 DOM プラグイン配列を使用したダングリングポインタ脆弱性
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-51.html

MFSA 2010-50 フレームセットの整数オーバーフロー脆弱性
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-50.html

MFSA 2010-49 様々なメモリ安全性の問題 (rv:1.9.2.9/ 1.9.1.12)
http://www.mozilla-japan.org/security/announce/2010/mfsa2010-49.html

JVNDB-2010-001978 Adobe Shockwave Player の DIRAPIX.dll における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001978.html

JVNDB-2010-001977 Adobe Shockwave Player の DIRAPI モジュールにおける整数符号エラーの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001977.html

JVNDB-2010-001976 Adobe Shockwave Player におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001976.html

JVNDB-2010-001975 Adobe Shockwave Player の IML32.dll における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001975.html

JVNDB-2010-001974 Adobe Shockwave Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001974.html




+ Dovecot 2.0.2 released
http://www.dovecot.org/list/dovecot-news/2010-September/000170.html

+ Tcl/Tk 8.5.9 released
http://www.tcl.tk/software/tcltk/8.5.html

+ RHSA-2010:0681-1: Critical: firefox security update
https://rhn.redhat.com/errata/RHSA-2010-0681.html

+- RHSA-2010:0680-1: Critical: seamonkey security update
http://rhn.redhat.com/errata/RHSA-2010-0680.html

+ Linux Kernel "xfs_ioc_fsgetxattr()" Memory Leak
http://secunia.com/advisories/41284/

+ FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43060

- Linux Kernel 'snd_seq_oss_open()' Multiple Local Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/43062

MySQL Enterprise Monitor 2.2.3 Is Now Available
https://enterprise.mysql.com/monitoring/download.php

[ANNOUNCE] libnetfilter_conntrack 0.9.0 release
http://www.netfilter.org/projects/libnetfilter_conntrack/
http://www.netfilter.org/news.html#
http://www.iptables.org/news.html#

About the security content of iOS 4.1 for iPhone and iPod touch
http://support.apple.com/kb/HT4334

APSA10-02: Security Advisory for Adobe Reader and Acrobat
http://www.adobe.com/support/security/advisories/apsa10-02.html

Firefox 3.6.9 and 3.5.12 security updates now available
https://developer.mozilla.org/devnews/index.php/2010/09/07/firefox-3-6-9-and-3-5-12-security-updates-now-available/

Firefox 4.0b5 released
http://www.mozilla.com/en-US/firefox/4.0b5/releasenotes/

PMASA-2010-7: XSS attack on setup script
http://www.phpmyadmin.net/home_page/security/PMASA-2010-7.php

HPSBMA02516 SSRT090232 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02067559&admit=109447627+1283996932836+28353475

HPSBMA02576 SSRT090231 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02498535&admit=109447626+1283996951140+28353475

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.cisco.com/warp/public/707/cisco-sa-20100908-wlc.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.cisco.com/warp/public/707/cisco-amb-20100908-wlc.shtml

UPDATE: HS10-025: JP1/NETM/Remote Control Agentにおける認証バイパスの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-025/index.html

Debian : [DSA-2105-1] New freetype packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33637

Gentoo Linux : [GLSA 201009-03] sudo: Privilege Escalation
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33630

Gentoo Linux : [GLSA 201009-04] SARG: User-assisted execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33638

Ubuntu Security Notice : [USN-983-1] Sudo vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33633

Ubuntu Security Notice : [USN-984-1] LFTP vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33634

Debian : [DSA-2104-1] New quagga packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33632

Mandriva : [MDVSA-2010:171] lvm2
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33635

Moritz Naumann IT Consulting & Services : XSS in Horde Application Framework v3.3.8 icon_browser.php
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33628

AmnPardaz Security Research Team : chillyCMS Multiple Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33627

Debian : [DSA-2103-1] New smbind packages fix sql injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33631

Independent Researcher : Joomla Component Clantools version 1.2.3 Multiple Blind SQL Injection Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33629

Independent Researcher : nmap <= 5.21 is vulnerable to Windows DLL Hijacking Vulnerability. http://www.criticalwatch.com/support/security-advisories.aspx?AID=33636

ESA-2010-015: EMC Celerra NFS authentication bypass vulnerability using IP spoofing.
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00058.html

[USN-985-1] mountall vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00057.html

ESA-2010-016: RSA, The Security Division of EMC, releases security hot fix for a potential v
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00055.html

ESA-2010-014: RSA, The Security Division of EMC, releases security hot fixes for potential v
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00056.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00054.html

[security bulletin] HPSBMA02574 SSRT100038 rev.1 - HP ProLiant G6 Lights-Out 100, Remote Man
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00050.html

[SECURITY] [DSA 2098-2] New typo3-src packages fix regression
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00047.html

[SECURITY] [DSA-2105-1] New freetype packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00043.html

[ GLSA 201009-06 ] Clam AntiVirus: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00053.html

[ GLSA 201009-05 ] Adobe Reader: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00052.html

[ GLSA 201009-04 ] SARG: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00046.html

etax 2010 failure to validate remote ssl certificate properly
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00051.html

[USN-984-1] LFTP vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00048.html

Joomla Component Aardvertiser 2.1 free Blind SQL Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00049.html

Recent developments in FireWire Attacks
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00042.html

Call for Participation - GameSec 2010 - Berlin, Germany
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00044.html

プレス発表
「組込みシステムのセキュリティへの取組みガイド(2010年度改訂版)」を公開
~情報家電で利用が拡大するIPv6等の新技術を安全に利用する上で考慮すべき対応策を掲載~
http://www.ipa.go.jp/about/press/20100907.html

JVNVU#954431 Apple Safari における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNVU954431/index.html

JVNDB-2010-001973 Apple Mac OS X の libsecurity における SSL サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001973.html

JVNDB-2010-001972 Apple Mac OS X の CoreGraphics におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001972.html

JVNDB-2010-001971 ClamAV の libclamav/mspack.c における qtm_decompress 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001971.html

JVNDB-2010-001970 Apple Mac OS X の CFNetwork における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001970.html

JVNDB-2010-001969 Apple Mac OS X の Apple Type Services におけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001969.html

JVNDB-2010-001840 PHP の SplObjectStorage における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001840.html

JVNDB-2010-001669 Samba の chain_reply 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001669.html

JVNDB-2010-001663 sudo の secure path 機能における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001663.html

JVNDB-2010-001457 PHP の xmlrpc 拡張におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001457.html

JVNDB-2010-001452 sudo における任意のコマンドを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001452.html

JVNDB-2010-001371 複数のアンチウィルス製品に脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001371.html

JVNDB-2010-001234 PHP の safe_mode 実装におけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001234.html

JVNDB-2010-001149 sudo における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001149.html

JPCERT/CC WEEKLY REPORT
http://www.jpcert.or.jp/wr/2010/wr103401.html

Adobe Acrobat / Reader SING Font Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2331

Apple Safari WebKit and Library Loading Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2330

phpMyAdmin Setup Script Request Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/2329

IP.Board "defaults.php" Data Handling Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/2328

Horde Application Framework "subdir" Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/2327

Redhat Security Update Fixes Thunderbird Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2326

Redhat Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2325

Redhat Security Update Fixes Seamonkey Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2324

Mozilla Products Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2323

Redhat Security Update Fixes RPM Package Manager Vulnerabilities
http://www.vupen.com/english/advisories/2010/2322

Redhat Security Update Fixes Kernel Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2010/2321

Redhat Security Update Fixes Sudo Runas Group Matching Vulnerability
http://www.vupen.com/english/advisories/2010/2320

Ubuntu Security Update Fixes lftp File Overwrite Vulnerability
http://www.vupen.com/english/advisories/2010/2319

Ubuntu Security Update Fixes Sudo Runas Group Matching Vulnerability
http://www.vupen.com/english/advisories/2010/2318

Debian Security Update Fixes Multiple FreeType Vulnerabilities
http://www.vupen.com/english/advisories/2010/2317

Gentoo Security Update Fixes Multiple ClamAV Vulnerabilities
http://www.vupen.com/english/advisories/2010/2316

Gentoo Security Update Fixes Acroread Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2315

Gentoo Security Update Fixes Sarg Buffer OVerflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/2314

Gentoo Security Update Fixes Sudo Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2313

Sudo Runas Group Matching Local Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2010/2312

MOAUB #8 - Microsoft Office Visio DXF File Stack based Overflow
http://www.exploit-db.com/exploits/14944/

Linux Kernel 'snd_seq_oss_open()' Multiple Local Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/43062

EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
http://www.securityfocus.com/bid/42134

Wireshark 0.8.20 through 1.2.8 Multiple Vulnerabilities
http://www.securityfocus.com/bid/40728

Wireshark DOCSIS Dissector Denial of Service Vulnerability
http://www.securityfocus.com/bid/39950

Wireshark 0.10.8 to 1.0.14 and 1.2.0 to 1.2.9 Multiple Vulnerabilities
http://www.securityfocus.com/bid/42618

Winamp and libmikmod Module Decoder Plugin Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/37374

RETIRED: libmikmod Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38114

Linux Kernel GFS2 Directory Rename NULL Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/42124

Linux Kernel Btrfs Integer Overflow Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41854

Linux Kernel Btrfs Overwrite Append-Only Files Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/41847

Linux Kernel CIFS DNS Lookup Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/41904

RETIRED: Mozilla Thunderbird 'dwmapi.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42744

RETIRED: Mozilla SeaMonkey 'dwmapi.dll DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42768

RETIRED: Linux Kernel 'IrDA' Protocol NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/42936

FreeType Compact Font Format (CFF) Multiple Stack Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/42241

FreeType Stack Buffer Overflow and Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/42285

FreeType BDF Font File Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42624

Oracle Java SE and Java for Business CVE-2010-0094 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/39075

Microsoft Visio 'DXF' File Insertion Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39836

TYPO3 Core TYPO3-SA-2010-012 Multiple Remote Security Vulnerabilities
http://www.securityfocus.com/bid/42029

Google Chrome prior to 6.0.472.53 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/42952

RSA Access Manager Server Cache Update Security Bypass Vulnerability
http://www.securityfocus.com/bid/43085

openSUSE Novell Client 'novfs' Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43071

Cisco Wireless LAN Controller CVE-2010-0575 ACL Security Bypass Vulnerability
http://www.securityfocus.com/bid/43069

Cisco Wireless LAN Controllers (CVE-2010-3033) Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43067

Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43066

Cisco Wireless LAN Controller HTTP Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/43065

Cisco Wireless LAN Controller CVE-2010-0575 ACL Security Bypass Vulnerability
http://www.securityfocus.com/bid/43064

Cisco Wireless LAN Controllers (CVE-2010-2842) Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43061

FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43060

Cisco Wireless LAN Controller IKE Packet Handling Denial of Service Vulnerability
http://www.securityfocus.com/bid/43059

Adobe Reader 'CoolType.dll' TTF Font Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43057

TextPattern 'txplib_db.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/43055

Invision Power Board BBCode Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/43053

0 件のコメント:

コメントを投稿