2010年10月26日火曜日

26日 火曜日、先負

[ANNOUNCE] Commons Daemon 1.0.4 Released
http://commons.apache.org/daemon/

JVNVU#537223 glibc に権限昇格の脆弱性
http://jvn.jp/cert/JVNVU537223/index.html

JVNVU#362983 Linux カーネルにおける RDS プロトコルの実装に脆弱性
http://jvn.jp/cert/JVNVU362983/index.html

JVNDB-2010-002188 Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002188.html

JVNDB-2010-002187 Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002187.html

JVNDB-2010-002186 Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002186.html

JVNDB-2010-002185 Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002185.html

JVNDB-2010-002184 Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002184.html

JVNDB-2010-002183 複数の Microsoft 製品の OpenType Font フォーマットドライバにおける権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002183.html

JVNDB-2010-002182 複数の Microsoft 製品の OpenType Font フォーマットドライバにおける権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002182.html

JVNDB-2010-002181 複数の Microsoft 製品のカーネルモードドライバにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002181.html

JVNDB-2010-002180 複数の Microsoft 製品のカーネルモードドライバにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002180.html

JVNDB-2010-001999 Windows プログラムの DLL 読み込みに脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001999.html

JVNDB-2010-001454 Linux 上で稼働する IBM DB2 におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001454.html

Adobe Acrobat Reader Acrord32.dll Use After Free Vulnerability
http://www.securiteam.com/windowsntfocus/6Y03H1F00Q.html

SAP Management Console Multiple DoS Vulnerabilities
http://www.securiteam.com/securitynews/6X03G1F00E.html

HP ProCurve 2610 Switch In-band Agent Denial of Service vulnerability
http://www.securiteam.com/securitynews/6X03G1F00E.html

HP ProCurve Threat Management Services unauthorized Data Injection and Denial of Service vulnerabilities
http://www.securiteam.com/securitynews/6Z03I1F00C.html

HP ProCurve 2610 Switches running DHCP Denial of Service Vulnerability
http://www.securiteam.com/securitynews/6B03K1F00A.html

GNU C Library LD_PRELOAD Environment Variable May Let Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Oct/1024636.html




+ RHSA-2010:0792-1: Important: kernel security update
http://rhn.redhat.com/errata/RHSA-2010-0792.html

+ RHSA-2010:0793-1: Important: glibc security update
http://rhn.redhat.com/errata/RHSA-2010-0793.html

- Microsoft Windows 'lpksetup.exe' 'oci.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44414

UPDATE: APSB10-21: Security updates available for Adobe Reader and Acrobat
http://www.adobe.com/support/security/bulletins/apsb10-21.html

CESA-2010:0781 (seamonkey)
http://lwn.net/Alerts/411533/

CESA-2010:0779 (kernel)
http://lwn.net/Alerts/411534/

CESA-2010:0780 (thunderbird)
http://lwn.net/Alerts/411535/

CESA-2010:0781 (seamonkey)
http://lwn.net/Alerts/411536/

CESA-2010:0782 (firefox)
http://lwn.net/Alerts/411537/

CESA-2010:0785 (quagga)
http://lwn.net/Alerts/411539/

CESA-2010:0788 (pidgin)
http://lwn.net/Alerts/411540/

phpMyAdmin 3.3.8 is released
http://sourceforge.net/news/?group_id=23067&id=293153

Squid 3.1.9 released
http://www.squid-cache.org/Versions/
http://www.squid-cache.org/Versions/v3/3.1/

NTP 4.2.6p3-RC7 released
http://archive.ntp.org/ntp4/ChangeLog-stable-rc

NTP 4.2.7p71 released
http://archive.ntp.org/ntp4/ChangeLog-dev

ASTERIAフォーラム2010秋(10/7開催)講演資料ダウンロード受付
http://asteria.jp/news/20101025-175517.html

Tpro EXPO 2010 出展レポート公開のお知らせ
http://asteria.jp/news/20101025-160920.html

Mandriva : [MDVSA-2010:212] glibc - Privilege Escalation Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34013

Ubuntu Security Notice : [USN-1008-3] libvirt update - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34017

Ubuntu Security Notice : [USN-1009-1] GNU C Library vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34018

Debian : [DSA 2122-1] New glibc packages fix local privilege escalation
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34022

Hewlett-Packard : [HPSBMA02593 SSRT100237 rev.1] - HP Virtual Connect Enterprise Manager (VCEM) for Windows, Remote Ar
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34023

Mandriva : [MDVSA-2010:211] mozilla-thunderbird - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34014

Mandriva : [MDVSA-2010:210] firefox - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34015

Mandriva : [MDVSA-2010:209] libsmi - Buffer Overflow Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34016

Slackware Linux : [SSA:2010-295-01] glibc - Multiple Updates
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34019

Slackware Linux : [SSA:2010-295-03] mozilla-thunderbird - Multiple Updates
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34020

Slackware Linux : [SSA:2010-295-02] mozilla-firefox - Multiple Updates
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34021

JVNDB-2010-002179 64-bit プラットフォーム上で稼働している Microsoft .NET Framework の JIT コンパイラにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002179.html

JVNDB-2010-002178 複数の Microsoft 製品の Embedded OpenType Font Engine における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002178.html

JVNDB-2010-002177 複数の Microsoft 製品の Media Player Network Sharing Service における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002177.html

JVNDB-2010-002176 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002176.html

JVNDB-2010-002175 Microsoft Internet Explorer における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002175.html

JVNDB-2010-002174 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002174.html

JVNDB-2010-002173 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002173.html

JVNDB-2010-002172 Microsoft Internet Explorer の HTML コンテンツ作成の実装における削除済みの重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002172.html

JVNDB-2010-002171 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002171.html

JVNDB-2010-002170 Microsoft Internet Explorer における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002170.html

JVNDB-2010-001999 Windows プログラムの DLL 読み込みに脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001999.html

JVNDB-2010-001596 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001596.html

JVNDB-2010-001501 MIT Kerberos 5 の GSS-API ライブラリにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001501.html

[USN-959-2] PAM vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00207.html

How Visual Studio Makes Your Applications Vulnerable to Binary Planting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00206.html

IPv6 security myths
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00199.html

Aardvark Topsite XSS vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00205.html

[ MDVSA-2010:212 ] glibc
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00198.html

[USN-1008-3] libvirt update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00197.html

[USN-1009-1] GNU C Library vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00200.html

[ MDVSA-2010:211 ] mozilla-thunderbird
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00201.html

Vulnerabilities in W-Agora
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00203.html

[ MDVSA-2010:210 ] firefox
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00196.html

Cyber Security Awareness Month - Day 25 - Using Home Computers for Work
http://isc.sans.edu/diary.html?storyid=9808

SQL Slammer Clean-up: Switching Viewpoints
http://isc.sans.edu/diary.html?storyid=9811

AutoPlay Media Studio Insecure Library Loading Vulnerability
http://secunia.com/advisories/41991/

GetRight Insecure Library Loading Vulnerability
http://secunia.com/advisories/41992/

ProShow Producer Insecure Library Loading Vulnerability
http://secunia.com/advisories/41990/

Moodle phpCAS Multiple Vulnerabilities
http://secunia.com/advisories/41980/

Wondershare DVD Slideshow Builder Insecure Library Loading Vulnerability
http://secunia.com/advisories/41987/

Wondershare Flash Gallery Factory Insecure Library Loading Vulnerability
http://secunia.com/advisories/41988/

Jamb CMS Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/41979/

MinaliC Directory Traversal and Denial of Service Vulnerabilities
http://secunia.com/advisories/41982/

OTRS AgentTicketZoom Script Insertion Vulnerability
http://secunia.com/advisories/41978/

Blue Coat ProxyAV Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/41964/

monotone Empty Command Strings Denial of Service
http://secunia.com/advisories/41960/

IBM Tivoli Access Manager for e-business Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/41974/

Fedora update for glibc
http://secunia.com/advisories/41971/

Debian update for glibc
http://secunia.com/advisories/41940/

Ubuntu update for glibc
http://secunia.com/advisories/41941/

Fedora update for ocsinventory-agent
http://secunia.com/advisories/41970/

Moodle phpMyAdmin Module Multiple Vulnerabilities
http://secunia.com/advisories/41954/

HP Data Protector Media Operations 'SignInName' Parameter Overflow Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Oct/1024634.html

IBM Tivoli Access Manager Input Validation Flaw Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Oct/1024633.html

Blue Coat ProxyAV Permits Cross-Site Request Forgery Attacks
http://securitytracker.com/alerts/2010/Oct/1024632.html

Linux Kernel tcf_act_police_dump() Function Lets Local Users Obtain Portions of Kernel Memory
http://securitytracker.com/alerts/2010/Oct/1024603.html

Vulnerability Note VU#537223: GNU C library dynamic linker expands $ORIGIN in setuid library search path
http://www.kb.cert.org/vuls/id/537223

Vulnerability Note VU#362983: Linux kernel RDS protocol vulnerability
http://www.kb.cert.org/vuls/id/362983

Winamp 5.5.8.2985 (in_mod plugin) Stack Overflow (Friendly Version)
http://www.exploit-db.com/exploits/15312/

IBM WebSphere Application Server Components Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2775

IBM Tivoli Access Manager for e-business Cross Site Scripting Issues
http://www.vupen.com/english/advisories/2010/2774

SAP BusinessObjects Information Disclosure and Privilege Escalation
http://www.vupen.com/english/advisories/2010/2773

Fedora Security Update Fixes Glibc ORIGIN Expansion Vulnerability
http://www.vupen.com/english/advisories/2010/2772

Fedora Security Update Fixes Ocsinventory-Agent Vulnerability
http://www.vupen.com/english/advisories/2010/2771

Slackware Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2770

Slackware Security Update Fixes Thunderbird Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2769

Slackware Security Update Fixes Glibc ORIGIN Expansion Vulnerability
http://www.vupen.com/english/advisories/2010/2768

Mandriva Security Update Fixes Glibc Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2010/2767

Mandriva Security Update Fixes Thunderbird Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2766

Mandriva Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2765

Mandriva Security Update Fixes LibSMI Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2764

Ubuntu Security Update Fixes libvirt Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2763

Debian Security Update Fixes Glibc Privilege Escalation Vulnerabilities
http://www.vupen.com/english/advisories/2010/2762

GNU glibc Dynamic Linker 'LD_AUDIT' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44347

Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44219

RETIRED: Zoki Catalog 'search_text' parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/44398

PAM MOTD Module Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/41465

PostgreSQL PL/Perl and PL/Tcl Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43747

Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42633

Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42625

Oracle MySQL Prior to 5.1.49 'WITH ROLLUP' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42596

Oracle MySQL 'EXPLAIN' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42599

Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/40100

Oracle MySQL Prior to 5.1.49 'JOIN' Statement Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42646

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
http://www.securityfocus.com/bid/40109

Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/40257

Oracle MySQL 'COM_FIELD_LIST' Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40106

Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
http://www.securityfocus.com/bid/41524

Usagi Project mipv6-daemon ND Options Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41522

libHX 'HX_split()' Remote Heap-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42592

MIT Kerberos KDC 'kdc_authdata.c' NULL Pointer Denial Of Service Vulnerability
http://www.securityfocus.com/bid/43756

Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44009

Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44032

Oracle Java SE and Java for Business CVE-2010-3573 Same Origin Bypass Vulnerability
http://www.securityfocus.com/bid/44028

Oracle Java SE and Java for Business CVE-2010-3560 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44024

Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44014

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability
http://www.securityfocus.com/bid/44017

Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/44027

MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40235

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/44013

Oracle Java SE and Java for Business CVE-2010-3550 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44040

Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44035

Oracle Java SE and Java for Business CVE-2010-3559 HeadspaceSoundbank.nGetName Vulnerability
http://www.securityfocus.com/bid/44026

Oracle Java SE and Java for Business CVE-2010-3555 Remote ActiveX Plug-in Vulnerability
http://www.securityfocus.com/bid/44038

Oracle Java SE and Java for Business CVE-2010-3558 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44021

Oracle Java SE and Java for Business CVE-2010-3570 Remote Deployment Toolkit Vulnerability
http://www.securityfocus.com/bid/44020

Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability
http://www.securityfocus.com/bid/44030

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability
http://www.securityfocus.com/bid/44023

Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44016

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43992

Winamp 5.581 and Prior Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/44094

Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/43994

Oracle Java SE and Java for Business CVE-2010-3556 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43971

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

Oracle Java SE and Java for Business CVE-2010-3566 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43988

Oracle Java SE and Java for Business CVE-2010-3563 BasicServiceImpl Vulnerability
http://www.securityfocus.com/bid/43999

Oracle Java SE and Java for Business CVE-2010-3571 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43965

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

Squid Proxy String Processing NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42982

dbus-glib 'access' Flag Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42347

Samba SID Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43212

Adobe Acrobat and Reader CVE-2010-3658 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43738

Adobe Acrobat and Reader CVE-2010-3657 Denial of Service Vulnerability
http://www.securityfocus.com/bid/43744

Adobe Acrobat and Reader CVE-2010-3631 Array Indexing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43733

Adobe Acrobat and Reader CVE-2010-3629 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43732

Adobe Acrobat and Reader Thumbnails Use-After-Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43746

Adobe Acrobat and Reader CVE-2010-3656 Denial of Service Vulnerability
http://www.securityfocus.com/bid/43741

Adobe Acrobat and Reader CVE-2010-3632 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43735

Adobe Acrobat and Reader CVE-2010-3625 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43730

Adobe Acrobat and Reader CVE-2010-3628 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43734

Adobe Acrobat and Reader CVE-2010-3626 Font Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43727

Adobe Acrobat and Reader NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/43737

Adobe Acrobat and Reader for Mac CVE-2010-3624 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43736

Adobe Acrobat and Reader 'ACE.dll' ICC Streams Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43729

Adobe Acrobat and Reader CVE-2010-3620 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43725

Adobe Acrobat and Reader CVE-2010-2890 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43722

Adobe Acrobat and Reader for Linux CVE-2010-2887 Multiple Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/43740

Adobe Reader 'CoolType.dll' TTF Font Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43057

Adobe Acrobat and Reader ICC Parsing Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43726

Adobe Acrobat and Reader CVE-2010-3619 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43724

Adobe Acrobat and Reader CVE-2010-3623 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43731

Adobe Acrobat and Reader CVE-2010-2889 Font Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43723

Adobe Flash Player CVE-2010-2884 Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43205

FreeType 'seac' Calls Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/42621

FreeType Rendering Engine Position Value Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43700

FreeType BDF Font File Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42624

OpenOffice Impress File Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/42202

RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42293

Adobe Shockwave Player Director rcsL Chunk Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42682

Microsoft IIS Request Header Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43138

phpCAS Service Ticket Validation Session Hijacking Vulnerability
http://www.securityfocus.com/bid/42162

phpCAS Proxy Mode Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/43585

MIM:InfiniX Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34750

phpMyAdmin Configuration File PHP Code Injection Vulnerability
http://www.securityfocus.com/bid/42591

phpMyAdmin Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/42584

GNU glibc Dynamic Linker '$ORIGIN' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44154

libvirt Multiple Local Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/41981

Microsoft Windows 'lpksetup.exe' 'oci.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44414

Festival Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44395

AutoPlay Media Studio 'dwmapi.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44394

MinaliC Directory Traversal and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/44393

Headlight Software GetRight 'SvcTagLib.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44391

Wondershare DVD Slideshow Builder 'dwmapi.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44389

Wondershare Flash Gallery Factory 'dwmapi.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44387

Photodex ProShow Producer Multiple DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44386

OTRS 'AgentTicketZoom' HTML Injection Vulnerability
http://www.securityfocus.com/bid/44384

0 件のコメント:

コメントを投稿