2010年10月19日火曜日

19日 火曜日、友引

+ Apache HTTP Server 2.0.64, 2.2.17 Released
http://www.apache.org/dist/httpd/Announcement2.0.html
http://www.apache.org/dist/httpd/Announcement2.2.html

+ SECURITY: CVE-2010-1452
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2009-1891
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2009-3095
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2009-3094
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2009-3555
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2010-0434
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2008-2364
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2010-0425
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ SECURITY: CVE-2008-2939
http://www.apache.org/dist/httpd/CHANGES_2.0.64

+ CVE-2010-1623: Fix a denial of service attack against apr_brigade_split_line().
http://www.apache.org/dist/httpd/Announcement2.2.html
http://www.apache.org/dist/httpd/CHANGES_2.2.17

+ CVE-2009-3560, CVE-2009-3720: Fix two buffer over-read flaws in the bundled copy of expat which could cause applications to crash while parsing specially-crafted XML documents.
http://www.apache.org/dist/httpd/Announcement2.2.html

ServerProtect 5.8においてスパイウェアパターンファイルの配信ができない現象について
http://www.trendmicro.co.jp/support/news.asp?id=1480

ウイルスバスター コーポレートエディション 10.5 Critical Patch 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1483

プレス発表
情報セキュリティ安心相談窓口を開設
~情報セキュリティ関連の相談に一元的に対応する窓口~
http://www.ipa.go.jp/about/press/20101019.html

情報セキュリティ対策を自動化する標準仕様"SCAP"セミナー開催のお知らせ
~CVSSハンズオン編~
http://www.ipa.go.jp/security/vuln/seminar/lab_semi_scap_2010_2.html

JVNDB-2010-001946 PHP の strrchr 関数における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001946.html

JVNDB-2010-001873 FreeType のデモプログラムにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001873.html

JVNDB-2010-001872 FreeType の Mac_Read_POST_Resource 関数におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001872.html

JVNDB-2010-001871 FreeType の gray_render_span 関数における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001871.html

JVNDB-2010-001870 FreeType の Mac_Read_POST_Resource 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001870.html

JVNDB-2010-001869 FreeType の psh_glyph_find_strong_points 関数における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001869.html

JVNDB-2010-001868 FreeType の ftmulti.c におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001868.html

JVNDB-2010-001840 PHP の SplObjectStorage における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001840.html

JVNDB-2010-001836 PHP におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001836.html

JVNDB-2010-001457 PHP の xmlrpc 拡張におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001457.html

JVNDB-2009-002474 PHP におけるスーパーグローバル配列 SESSION の割り込み領域が破壊される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002474.html

JVNDB-2009-002473 PHP の htmlspecialchars 関数におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002473.html

JVNDB-2009-002446 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002446.html

JVNDB-2009-002179 PHP における exif のチェックに関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002179.html

JVNDB-2009-002178 PHP の php_openssl_apply_verification_policy 関数における証明書の検証処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002178.html

JVNDB-2009-001875 PHP の exif_read_data 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001875.html

JVNDB-2009-001407 PHP における同じ Web サーバ上でホストされた別サイトの振る舞いを変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001407.html

JVNDB-2009-001337 FreeType における入力処理に関する整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001337.html

JVNDB-2009-001201 PHP の JSON_parser 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001201.html

JVNDB-2008-001495 複数の DNS 実装にキャッシュポイズニングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001495.html

JVNDB-2008-001465 FreeType2 における一つずれエラーの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001465.html

JVNDB-2008-001464 FreeType2 におけるメモリ破壊の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001464.html

JVNDB-2008-001463 FreeType2 におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001463.html

JVNDB-2008-000084 PHP におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000084.html

JVNDB-2009-002612 Google Chrome の Gears プラグインにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002612.html

JVNDB-2009-002611 Google Chrome の src/webkit/glue/webframeloaderclient_impl.cc におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002611.html

JVNDB-2009-002610 Google Chrome のブラックリストにおける危険なファイルのダウンロードを強制される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002610.html

JVNDB-2009-002609 Google Chrome における X.509 証明書の処理に関する任意の SSL サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002609.html

JVNDB-2008-002489 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002489.html

JVNDB-2009-002608 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002608.html

JVNDB-2009-002607 Google Chrome の getSVGDocument メソッドにおけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002607.html

JVNDB-2009-002606 Google Chrome におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002606.html

JVNDB-2009-002605 Google Chrome における data: URI をブロックしない脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002605.html

JVNDB-2009-002604 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002604.html

JVNDB-2009-002603 Google Chrome における任意の HTTPS サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002603.html

JVNDB-2009-002602 Google Chrome にて使用される Google V8 における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002602.html

JVNDB-2009-002601 Google Chrome の tooltip manager におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002601.html

JVNDB-2009-002600 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002600.html

JVNDB-2009-002599 Google Chrome における任意の Web スクリプトを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002599.html

JVNDB-2009-002598 Google Chrome の chrome/common/gfx/url_elider.cc におけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002598.html

JVNDB-2009-002597 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002597.html

JVNDB-2009-002596 Google Chrome BETA におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002596.html

JVNDB-2009-002595 Google Chrome における Adobe Acrobat の JavaScript の制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002595.html

JVNDB-2009-002594 Google Chrome で使用される Skia における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002594.html

JVNDB-2009-002593 Google Chrome の ParamTraits::Read 関数におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002593.html

JVNDB-2009-002592 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002592.html

JVNDB-2009-002591 Google Chrome におけるクロスサイトスクリプティングを誘導される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002591.html

JVNDB-2009-002590 Google Chrome におけるクロスサイトスクリプティングを誘導される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002590.html

JVNDB-2009-002589 Google Chrome における IsWebSafeScheme 制限を満たしていない URL をタブで開かれる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002589.html

JVNDB-2009-002588 Google Chrome の V8 JavaScript エンジンにおける同一生成元ポリシーを回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002588.html

JVNDB-2009-002587 Google Chrome における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002587.html

JVNDB-2009-002586 Google Chrome の JavaScript 実装における偽装したポップアップメッセージに従って行動させられる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002586.html

JVNDB-2008-002488 Google Chrome におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002488.html

JVNDB-2008-002487 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002487.html

JVNDB-2009-002585 Google Chrome の net/base/escape.cc における整数アンダーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002585.html

JVNDB-2009-002584 Google Chrome の SaveAs 機能におけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002584.html

JVNDB-2009-002583 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002583.html

JVNDB-2009-002582 Google Chrome における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002582.html

JVNDB-2009-002581 Google Chrome の src/jsregexp.cc におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002581.html

JVNDB-2009-002580 Google Chrome における javascript: URI をブロックしない脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002580.html

JVNDB-2009-002579 Google Chrome の browser kernel におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002579.html

JVNDB-2009-002578 Google Chrome における任意の https サイトになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002578.html

IBM Informix Dynamic Server Flaws Let Remote and Remote Authenticated Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024602.html

IBM Rational Quality Manager Default Administrative Account Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024601.html




+ [Announce] GnuPG 1.4.11 released
http://lists.gnupg.org/pipermail/gnupg-announce/2010q4/000303.html

+ CVE-2010-1797 Buffer Overflow Vulnerability in FreeType
http://blogs.sun.com/security/entry/cve_2010_1797_buffer_overflow

+- Antivirus detection after malware execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00152.html

+ GNU glibc Dynamic Linker '$ORIGIN' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44154
http://www.exploit-db.com/exploits/15274/

- Windows Server 2008 Color Control Panel Insecure Library Loading Vulnerability
http://secunia.com/advisories/41874/

APSB10-24: Security update available for InDesign
http://www.adobe.com/support/security/bulletins/apsb10-24.html

APSB10-23: Security update available for RoboHelp
http://www.adobe.com/support/security/bulletins/apsb10-23.html

CESA-2010:0768 (java-1.6.0-openjdk)
http://lwn.net/Alerts/410392/

phpMyAdmin 3.3.8-rc1 is released
http://sourceforge.net/news/?group_id=23067&id=292906

Jetty-6.1.26.RC0 released
http://svn.codehaus.org/jetty/jetty/branches/jetty-6.1/VERSION.txt

rPath : [rPSA-2010-0058-1] bzip2 bzip2-extras integer overflow vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33961

rPath : [rPSA-2010-0059-1] kernel root access
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33962

rPath : [rPSA-2010-0060-1] httpd mod_ssl
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33963

トレンドマイクロ、仮想マシン向けセキュリティ対策製品を販売
http://itpro.nikkeibp.co.jp/article/NEWS/20101018/353108/?ST=security

Antivirus detection after malware execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00152.html

Holoo Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00150.html

Sahar Money Manager Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00149.html

Rafe 7 Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00147.html

Brilliant Accounting System (59) Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00148.html

Accounting Pro 2003 Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00146.html

Xilisoft Video Converter Ultimate Insecure Library Loading Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00151.html

Secunia Research: RealPlayer QCP Sample Chunk Parsing Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00145.html

rPSA-2010-0066-1 samba samba-client samba-server samba-swat
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00144.html

rPSA-2010-0065-1 krb5 krb5-server krb5-services krb5-workstation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00143.html

rPSA-2010-0064-1 libtiff
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00142.html

rPSA-2010-0063-1 perl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00141.html

rPSA-2010-0060-1 httpd mod_ssl
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00140.html

rPSA-2010-0059-1 kernel
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00139.html

rPSA-2010-0058-1 bzip2 bzip2-extras
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00138.html

Cyber Security Awareness Month - Day 18 - What you should tell your boss when there's a crisis
http://isc.sans.edu/diary.html?storyid=9760

Blue Coat ProxySG Lets Remote Users Bypass JavaScript Filtering
http://securitytracker.com/alerts/2010/Oct/1024600.html

RealPlayer Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024598.html

IBM solidDB Packet Processing Error Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Oct/1024597.html

SAP BusinessObjects Axis2 Default Admin Password
http://securityreason.com/securityalert/7839

RealNetworks RealPlayer Malformed IVR Object Index Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6D0372A00W.html

Microsoft Word 2003 MSO Null Pointer Dereference Vulnerability
http://www.securiteam.com/windowsntfocus/6C0362A00Q.html

RealNetworks RealPlayer FLV Parsing Multiple Integer Overflow Vulnerabilities
http://www.securiteam.com/windowsntfocus/6E0382A00O.html

HP OpenView Network Node Manager Execution of Arbitrary Code and DoS Vulnerabilities
http://www.securiteam.com/securitynews/6N03A2A00Q.html

HP OpenView Network Node Manager Arbitrary Code Execution vulnerabilities
http://www.securiteam.com/securitynews/6F0392A00Y.html

PCDJ Karaoki Insecure Executable Loading Vulnerability
http://secunia.com/advisories/41903/

Ease Jukebox Insecure Library Loading Vulnerability
http://secunia.com/advisories/41902/

Rocket U2 UniData Multiple Denial of Service Vulnerabilities
http://secunia.com/advisories/41867/

CrossFTP Directory Traversal Vulnerability
http://secunia.com/advisories/41852/

RealWin Packet Processing Buffer Overflow Vulnerabilities
http://secunia.com/advisories/41849/

Windows Server 2008 Color Control Panel Insecure Library Loading Vulnerability
http://secunia.com/advisories/41874/

Aasync Filename Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/41855/

32bit FTP Client Filename Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/41854/

Sun Solaris Apache HTTP Server Multiple Vulnerabilities
http://secunia.com/advisories/41884/

FTP Synchronizer FTP Response Processing Vulnerability
http://secunia.com/advisories/41860/

IBM Java Multiple Vulnerabilities
http://secunia.com/advisories/41882/

Kisisel Radyo Script Two Vulnerabilities
http://secunia.com/advisories/41816/

FTPPad Server Response Buffer Overflow Vulnerability
http://secunia.com/advisories/41858/

Fujitsu Interstage Products Directory Traversal Vulnerability
http://secunia.com/advisories/41889/

IBM solidDB Multiple Denial of Service Vulnerabilities
http://secunia.com/advisories/41873/

RealPlayer Enterprise Multiple Vulnerabilities
http://secunia.com/advisories/41743/

SUSE update for kernel
http://secunia.com/advisories/41896/

Blue Coat ProxySG Active Content Transformation Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/2699

RealNetworks RealPlayer Multiple Remote Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2698

Sun Security Update Fixes Apache Security Bypass and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2010/2697

Sun Security Update Fixes LibTIFF Integer Overflow and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2010/2696

Sun Security Update Fixes Tomcat Information Disclosure and DoS
http://www.vupen.com/english/advisories/2010/2695

Sun Security Update Fixes Fetchmail Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2694

Sun Solaris Pidgin MSN Service Location Protocol DoS Vulnerability
http://www.vupen.com/english/advisories/2010/2693

SuSE Security Update Fixes Kernel Privilege Escalation Vulnerabilities
http://www.vupen.com/english/advisories/2010/2692

Fedora Security Update Fixes PostgreSQL Privilege Escalation
http://www.vupen.com/english/advisories/2010/2691

Fedora Security Update Fixes Java Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2690

Fedora Security Update Fixes Rekonq Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/2689

Fedora Security Update Fixes Poppler Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2688

Mandriva Security Update Fixes Freeciv Code Execution and File Disclosure
http://www.vupen.com/english/advisories/2010/2687

FatPlayer 0.6b Malicious WAV Buffer Overflow Vulnerability (SEH)
http://www.exploit-db.com/exploits/15279/

GNU C library dynamic linker $ORIGIN expansion Vulnerability
http://www.exploit-db.com/exploits/15274/

Oracle Solaris CVE-2010-3509 'rpc.cmsd' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43933

iDevSpot iSupport 'index.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/26961

TRUC 'login_reset_password_page.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38445

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Apache 'mod_proxy' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35565

Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/41963

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34663

Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38491

Apache 'mod_deflate' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35623

Apache 'mod_isapi' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38494

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Adobe InDesign 'ibfs32.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42718

Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43992

Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43779

Multiple Java Runtime Implementations UTF-8 Input Validation Vulnerability
http://www.securityfocus.com/bid/30633

Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44016

Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability
http://www.securityfocus.com/bid/44030

Samba SID Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43212

Samba 'SMB1 Packet Chaining' Unspecified Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/40884

MIT Kerberos kadmind 'server_stubs.c' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/39247

MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40235

LibTIFF Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/41295

LibTIFF Multiple Remote Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35652

LibTIFF FAX3 Decoder Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/40823

LibTIFF Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/41088

Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities
http://www.securityfocus.com/bid/40305

Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
http://www.securityfocus.com/bid/40302

Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42102

Linux Kernel 'video4linux' IOCTL and IP Multicast 'getsockopt' Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43239

bzip2 'BZ2_decompress' Function Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43331

Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43316

Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44035

Oracle Java SE and Java for Business CVE-2010-3573 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44028

Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44032

Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/44027

Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44014

Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability
http://www.securityfocus.com/bid/44017

Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/44013

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Communications Messaging Server CVE-2010-3564 Webmail Remote Vulnerability
http://www.securityfocus.com/bid/43963

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/43994

Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44009

PostgreSQL PL/Perl and PL/Tcl Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43747

IBM Informix Dynamic Server 'oninit.exe' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44192

IBM Informix Dynamic Server DBINFO keyword Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44190

AVG Antivirus 'hcp://' Protocol Handler Security Bypass Vulnerability
http://www.securityfocus.com/bid/44189

IBM Informix Dynamic Server Integer Overflow Vulnerability
http://www.securityfocus.com/bid/44187

McAfee VirusScan 'hcp://' Protocol Handler Security Bypass Vulnerability
http://www.securityfocus.com/bid/44184

Cobbler Kickstart Template Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44174

IBM Rational Quality Manager and Test Lab Manager Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44172

Accounting Pro 2003 Multiple DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44171

Xilisoft Video Converter Multiple DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44170

Adobe RoboHelp Server and RoboHelp Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44168

Adobe RoboHelp Server and RoboHelp Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44167

libguestfs Disk Format Specifier Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44166

PCDJ Karaoki 'saMon2.exe' Executable Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44162

Audiotool Ease Jukebox 'wmaudsdk.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44161

IBM solidDB Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/44158

Windows Server 2008 Color Control Panel DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44157

GNU glibc Dynamic Linker '$ORIGIN' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44154

0 件のコメント:

コメントを投稿