2010年10月29日金曜日

29日 金曜日、赤口

+ Linux kernel 2.6.27.55, 2.6.32.25, 2.6.35.8 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.55

+ RHSA-2010:0811-1: Important: cups security update
http://rhn.redhat.com/errata/RHSA-2010-0811.html

Linux kernel Kernel release: 2.6.27.55
http://www.linux.org/news/2010/10/29/0001.html

【USダウンロードサーバダウンのお知らせ】
http://www-935.ibm.com/services/jp/index.wss/offerfamily/its/b1331513

RHSA-2010:0812-1: Moderate: thunderbird security update
http://rhn.redhat.com/errata/RHSA-2010-0812.html

プレス発表
「2009年 国内における情報セキュリティ事象被害状況調査」報告書の公開について
~ 中小企業はウェブ関連のセキュリティ対策推進や適切な情報源の理解・認識が必要 ~
http://www.ipa.go.jp/about/press/20101029.html

JVN#72541530 Active! mail 6 における HTTP ヘッダインジェクションの脆弱性
http://jvn.jp/jp/JVN72541530/index.html

JVNVU#402231 Adobe Shockwave Player に脆弱性
http://jvn.jp/cert/JVNVU402231/index.html

JVNVU#298081 Adobe Flash に脆弱性
http://jvn.jp/cert/JVNVU298081/index.html

Ubuntu update for xulrunner
http://secunia.com/advisories/42003/

Adobe Shockwave Player Has Multiple Flaws That Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024664.html

LibSMI smiGetNode Buffer Overflow When Long OID Is Given In Numerical Form
http://securityreason.com/securityalert/7853

HP Virtual Connect Enterprise Manager (VCEM) Arbitrary File Download
http://securityreason.com/securityalert/7852

Oracle Sun Java System Web Server - HTTP Response Splitting
http://securityreason.com/securityalert/7851

Home FTP Server Post-Auth Directory Traversal
http://www.exploit-db.com/exploits/15349/




+ Microsoft Windows Environment Variable Expansion Library Loading Vulnerability
http://secunia.com/advisories/41984/

+- Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44242
http://www.exploit-db.com/exploits/15344/

[ANNOUNCE] Apache MINA 2.0.1 released
http://mina.apache.org/downloads.html

APSB10-25: Security update available for Shockwave Player
http://www.adobe.com/support/security/bulletins/apsb10-25.html

APSA10-05: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat
http://www.adobe.com/support/security/advisories/apsa10-05.html

UPDATE: APSA10-04: Security Advisory for Adobe Shockwave Player
http://www.adobe.com/support/security/advisories/apsa10-04.html

HPSBMA02607 SSRT100214 rev.1 - HP Insight Control for Linux, Remote Cross Site Request Forgery (CSRF)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02573692

HPSBMA02606 SSRT100321 rev.1 - HP Insight Orchestration Software for Windows, Remote Arbitrary File Download, Unauthorized Access
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02573285

HPSBMA02602 SSRT100317 rev.1 - HP Insight Control Performance Management for Windows, Remote Cross Site Scripting (XSS), Privilege Escalation, Cross Site Request Forgery (CSRF)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02563642

HPSBMA02598 SSRT100314 rev.2 - HP Insight Control Virtual Machine Management for Windows, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Cross Site Request Forgery (CSRF)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02560655

HPSBMA02605 SSRT100238 rev.1 - HP Insight Managed System Setup Wizard for Windows, Remote Arbitrary File Download
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02573176

HPSBMA02604 SSRT100320 rev.1 - HP Insight Recovery for Windows, Remote Cross Site Scripting (XSS), Arbitrary File Download
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02571464

HPSBMA02600 SSRT100239 rev.1 - HP Insight Control Performance Management for Windows, Remote Arbitrary File Download
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02574359

サイトメンテナンスのお知らせ [2010/10/28(木)22:00?24:00]
http://asteria.jp/news/20101028-165634.html

Mandriva : [MDVSA-2010:213] xulrunner unspecified vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34039

Red Hat : [RHSA-2010:0810-01] Critical: seamonkey security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34047

SuSE : [SUSE-SA:2010:052] glibc code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34042

SuSE : [SUSE-SA:2010:053] Linux kernel privilege escalation
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34043

Ubuntu Security Notice : [USN-1011-1] Firefox buffer-overflow vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34040

Cisco : [cisco-sa-20101027-cs] CiscoWorks Common Services Arbitrary Code Execution Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34048

Digital Security Research Group : [DSECRG-09-032] Oracle Application Server - Linked XSS vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34053

DSecRG : [DSECRG-09-029] Oracle BI Publisher Enterprise 10 - Response Splitting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34061

High-Tech Bridge SA : [HTB22653] Authentication bypass in phpLiterAdmin
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34051

High-Tech Bridge SA : [HTB22642] XSS vulnerability in Zomplog
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34066

Independent Researcher : Secunia PSI Insecure Library Loading Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34056

Red Hat : [RHSA-2010:0807-01] Critical: java-1.5.0-ibm security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34044

Red Hat : [RHSA-2010:0808-01] Critical: firefox security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34045

Red Hat : [RHSA-2010:0809-01] Critical: xulrunner security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34046

rPath : [rPSA-2010-0073-1] lftp
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34057

rPSA : [rPSA-2010-0072-1] curl denial-of-service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34059

rPSA : [rPSA-2010-0075-1] sudo
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34060

Secunia : Winamp VP6 Content Parsing Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34063

Slackware Linux : [SSA:2010-300-01] seamonkey
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34041

「非出会い系」での児童被害、半数以上が「健全」サイトで発生
フィルタリングしても被害の恐れ、ただし被害者の9割以上は利用せず
http://itpro.nikkeibp.co.jp/article/Research/20101028/353586/?ST=security

[USN-1011-2] Thunderbird vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00272.html

[ MDVSA-2010:213 ] xulrunner
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00270.html

nSense-2010-002: Teamspeak 2 Windows client
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00271.html

[USN-1011-1] Firefox vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-10/msg00268.html

JVNDB-2010-001173 Apache HTTP Server の ap_proxy_ajp_request 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001173.html

JVNDB-2010-001071 Apache Tomcat におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001071.html

JVNDB-2010-001070 Apache Tomcat におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001070.html

JVNDB-2010-000039 Lhaplus における実行ファイル読み込みに関する脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000039.html

JVNDB-2009-002188 Apache HTTP Server の mod_proxy_ftp モジュールにおけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002188.html

JVNDB-2009-002187 Apache HTTP Server の ap_proxy_ftp_handler 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002187.html

JVNDB-2009-001892 Apache httpd の mod_deflate モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001892.html

JVNDB-2009-001884 Apache HTTP Server の mod_proxy におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001884.html

JVNDB-2009-001562 Apache HTTP Server における AllowOverride ディレクティブの処理に関する権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001562.html

JVNDB-2009-001282 Apache HTTP Server の mod_proxy_ajp モジュールにおける情報漏えいの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001282.html

JVNDB-2010-002208 複数の Microsoft 製品の Comctl32.dll におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002208.html

JVNDB-2010-002207 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002207.html

JVNDB-2010-002206 Microsoft Excel および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002206.html

JVNDB-2010-002205 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002205.html

JVNDB-2010-002204 Microsoft Excel における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002204.html

JVNDB-2010-002203 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002203.html

JVNDB-2010-002202 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002202.html

JVNDB-2010-002201 複数の Microsoft 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002201.html

JVNDB-2010-002200 Microsoft Excel における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002200.html

JVNDB-2010-002199 Microsoft Excel および Microsoft Office における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002199.html

CVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability
http://isc.sans.edu/diary.html?storyid=9835

TeamSpeak Client Voice Packet Processing Vulnerability
http://secunia.com/advisories/42014/

SUSE update for kernel
http://secunia.com/advisories/42001/

SUSE update for glibc
http://secunia.com/advisories/42002/

Google Chrome Flash Player Unspecified Code Execution Vulnerability
http://secunia.com/advisories/42031/

Adobe Reader / Acrobat Unspecified Code Execution Vulnerability
http://secunia.com/advisories/42030/

Adobe Flash Player Unspecified Code Execution Vulnerability
http://secunia.com/advisories/41917/

FrontAccounting Two SQL Injection Vulnerabilities
http://secunia.com/advisories/41976/

Weborf HTTP Request Processing Denial of Service Vulnerability
http://secunia.com/advisories/40590/

Palm Pre WebOS Multiple Vulnerabilities
http://secunia.com/advisories/42023/

n2 n2view Authentication Bypass Vulnerability
http://secunia.com/advisories/42007/

Spring Security Constraints Security Bypass Vulnerability
http://secunia.com/advisories/42024/

HP Storage Essentials LDAP Authentication Security Bypass Vulnerability
http://secunia.com/advisories/42022/

ENOVIA Unspecified Vulnerability
http://secunia.com/advisories/42029/

Fedora update for subversion
http://secunia.com/advisories/42016/

Microsoft Windows Environment Variable Expansion Library Loading Vulnerability
http://secunia.com/advisories/41984/

Ubuntu update for firefox
http://secunia.com/advisories/41761/

Red Hat update for firefox
http://secunia.com/advisories/41969/

Red Hat update for seamonkey
http://secunia.com/advisories/41965/

Red Hat update for xulrunner
http://secunia.com/advisories/41966/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/42019/

Oracle Mojarra Cryptographic Padding Oracle Information Disclosure
http://secunia.com/advisories/41981/

AlstraSoft E-Friends Local File Inclusion and Arbitrary File Upload Vulnerabilities
http://secunia.com/advisories/42013/

CiscoWorks Common Services Buffer Overflow Vulnerability
http://secunia.com/advisories/42011/

Drupal Watcher Module Multiple Vulnerabilities
http://secunia.com/advisories/41952/

Red Hat update for java-1.5.0-ibm
http://secunia.com/advisories/41967/

NetBSD update for openssl
http://secunia.com/advisories/41961/

IBM HTTP Server Information Disclosure and Denial of Service Vulnerabilities
http://secunia.com/advisories/42027/

Mozilla Thunderbird "document.write()" and DOM Insertion Vulnerability
http://secunia.com/advisories/41975/

Fedora update for sepostgresql
http://secunia.com/advisories/42018/

IBM HTTP Server "mod_dav" Denial of Service Vulnerability
http://secunia.com/advisories/42028/

Fedora update for apr-util
http://secunia.com/advisories/42015/

Adobe Reader and Acrobat Flaw in 'authplay.dll' Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024660.html

Adobe Flash Player Flaw Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Oct/1024659.html

Palm webOS Camera Application Lets Local Users Overwrite Arbitrary Files
http://securitytracker.com/alerts/2010/Oct/1024658.html

HP LoadRunner Web Tours Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Oct/1024657.html

Palm webOS Doc Viewer Flaw in Processing Word Documents Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Oct/1024656.html

Vulnerability Note VU#298081: Adobe Flash code execution vulnerability
http://www.kb.cert.org/vuls/id/298081

FreePBX Recordings Interface Code Execution Vulnerability
http://www.securiteam.com/unixfocus/6T03G2A00K.html

IBM Proventia Mail Security System Insecure Direct Object Reference Vulnerability
http://www.securiteam.com/securitynews/6U03H2A00C.html

IBM Proventia Network Mail Security System - Cross-Site Request Forgery Vulnerabilities
http://www.securiteam.com/securitynews/6V03I2A00I.html

Adobe Acrobat and Reader "authplay.dll" Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2811

Adobe Flash Player Content Processing Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2810

Palm webOS Multiple Code Execution and File Overwrite Vulnerabilities
http://www.vupen.com/english/advisories/2010/2809

Fedora Security Update Fixes Multiple Local Kernel Vulnerabilities
http://www.vupen.com/english/advisories/2010/2808

Fedora Security Update Fixes Ocsinventory-Agent Vulnerability
http://www.vupen.com/english/advisories/2010/2807

Fedora Security Update Fixes Apr-util Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2806

Fedora Security Update Fixes Subversion Unauthorized Access Issue
http://www.vupen.com/english/advisories/2010/2805

Fedora Security Update Fixes SEPostgreSQL Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2804

Fedora Security Update Fixes Firefox and Xulrunner Vulnerabilities
http://www.vupen.com/english/advisories/2010/2803

Fedora Security Update Fixes NSS Certificate Processing Vulnerability
http://www.vupen.com/english/advisories/2010/2802

Redhat Security Update Fixes SeaMonkey Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2801

Redhat Security Update Fixes XULRunner Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2800

Redhat Security Update Fixes Firefox Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2799

Redhat Security Update Fixes Java Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2798

Ubuntu Security Update Fixes Firefox Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2797

Slackware Security Update Fixes Seamonkey Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2796

XBMC 9.04.1r20672 soap_action_name post upnp sscanf Buffer Overflow
http://www.exploit-db.com/exploits/15347/

Platinum SDK Library post upnp sscanf Buffer Overflow Vulnerability
http://www.exploit-db.com/exploits/15346/

Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability
http://www.exploit-db.com/exploits/15344/

Firefox Memory Corruption Proof of Concept (Simplified)
http://www.exploit-db.com/exploits/15342/

Firefox Interleaving document.write and appendChild Denial of Service
http://www.exploit-db.com/exploits/15341/

Linux Kernel GFS2 Directory Rename NULL Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/42124

Adobe Shockwave Player 'dirapi.dll' CVE-2010-4084 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44520

Linux Kernel CVE-2010-2240 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/42505

libHX 'HX_split()' Remote Heap-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42592

Mozilla Firefox SeaMonkey and Thunderbird 'document.write' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44247

Mozilla Firefox SeaMonkey Thunderbird Modal Calls Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44252

Mozilla Firefox SeaMonkey and Thunderbird 'LookupGetterOrSetter' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44249

Mozilla Firefox and SeaMonkey Gopher Parser Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44253

Mozilla Firefox SeaMonkey and Thunderbird 'nsBarProp' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44248

Mozilla Firefox SeaMonkey and Thunderbird 'LD_LIBRARY_PATH' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44251

GNU glibc Dynamic Linker 'LD_AUDIT' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44347

Mozilla Firefox SeaMonkey and Thunderbird CVE-2010-3176 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44243

Mozilla Firefox and Thunderbird CVE-2010-3175 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44245

Mozilla Firefox 3.5/3.6 Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44425

Linux Kernel CIFS DNS Lookup Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/41904

Linux Kernel XSF 'SWAPEXT' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40920

Linux Kernel CVE-2010-2066 Donor File Security Bypass Vulnerability
http://www.securityfocus.com/bid/41466

Linux Kernel XDR Implementation Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42249

Linux Kernel Bluetooth Sysfs File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38898

Xen 'arch/ia64/xen/faults.c' Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40776

Linux Kernel CIFS 'CIFSSMBWrite()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42242

Multiple Browser Wild Card Certificate Spoofing Vulnerability
http://www.securityfocus.com/bid/42817

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Oracle Java SE and Java for Business CVE-2010-3566 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43988

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44016

Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43992

Oracle Java SE and Java for Business CVE-2010-3573 Same Origin Bypass Vulnerability
http://www.securityfocus.com/bid/44028

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Communications Messaging Server CVE-2010-3564 Webmail Remote Vulnerability
http://www.securityfocus.com/bid/43963

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44035

Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44032

Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/44027

Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44014

Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44009

Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability
http://www.securityfocus.com/bid/44017

Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/43994

Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/44013

Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44242

Adobe Shockwave Player 'dirapi.dll' CVE-2010-2581 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44512

Adobe Shockwave Player rcsL Chunk EAX Register Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44291

Adobe Acrobat, Reader and Flash CVE-2010-3654 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44504

Free Joke Script Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/33760

WP-Lytebox 'main.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/35098

AIMP 'MP3' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44369

Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44219

GNU glibc 'ld.so' ELF Header Parsing Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/40063

GNU glibc Dynamic Linker '$ORIGIN' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44154

glibc and eglibc 'nis/nss_nis/nis-pwd.c' Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/37885

Multiple BSD Platforms 'strfmon()' Function Integer Overflow Weakness
http://www.securityfocus.com/bid/28479

Subversion Server 'SVNPathAuthz' Restriction Security Bypass Vulnerability
http://www.securityfocus.com/bid/43678

Linux Kernel 915 GEM IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44067

MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40235

Oracle Java SE and Java for Business CVE-2010-3556 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43971

Oracle Java SE and Java for Business CVE-2010-3550 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44040

Oracle Java SE and Java for Business CVE-2010-3559 HeadspaceSoundbank.nGetName Vulnerability
http://www.securityfocus.com/bid/44026

Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability
http://www.securityfocus.com/bid/44030

OpenSSL 'ssl3_get_key_exchange()' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42306

Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40827

Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/41963

OCS Inventory NG Agent 'Backend.pm' Perl Module Handling Code Execution Vulnerability
http://www.securityfocus.com/bid/35593

Apache APR-util 'apr_brigade_split_line' Denial of Service Vulnerability
http://www.securityfocus.com/bid/43673

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/40215

PostgreSQL PL/Perl and PL/Tcl Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43747

CVS CVE-2010-3846 RCS File Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44528

TFTgallery 'thumbnailformpost.inc.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/44523

Platinum UPnP Library Post UPnP Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44522

Adobe Shockwave Player 'IML32.dll' CVE-2010-4089 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44521

Adobe Shockwave Player 'dirapi.dll' CVE-2010-4088 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44519

Adobe Shockwave Player 'IML32.dll' CVE-2010-4087 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44518

Adobe Shockwave Player 'dirapi.dll' CVE-2010-4086 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44517

Adobe Shockwave Player 'dirapi.dll' CVE-2010-3655 Stack Overflow Vulnerability
http://www.securityfocus.com/bid/44516

Adobe Shockwave Player CVE-2010-4090 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44515

Adobe Shockwave Player CVE-2010-2582 Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44514

Adobe Shockwave Player 'dirapi.dll' CVE-2010-4085 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44513

ENOVIA Unspecified Security Vulnerability
http://www.securityfocus.com/bid/44509

Weborf HTTP Request Denial Of Service Vulnerability
http://www.securityfocus.com/bid/44506

n2 n2view Authentication Security Bypass Vulnerability
http://www.securityfocus.com/bid/44503

Teamspeak Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44502

Feindura CMS Groupware Multiple Local File Include and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44501

Drupal Watcher Module Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44499

0 件のコメント:

コメントを投稿