2010年11月12日金曜日

12日 金曜日、仏滅

+ Linux Kernel 'l2tp_ip_sendmsg()' and 'pppol2tp_sendmsg()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/44762

UPADTE: Transport Layer Security Renegotiation Vulnerability
http://support.citrix.com/article/CTX123359

Scripting with Unix Date
http://isc.sans.edu/diary.html?storyid=9925

Power Audio Editor v7.4.3.230 (.cda) Denial of Service Vulnerability
http://www.exploit-db.com/exploits/15495/

VbsEdit v 4.7.2.0 (.vbs) Buffer Overflow Vulnerability
http://www.exploit-db.com/exploits/15494/

Visual MP3 Splitter & Joiner 6.1 (.wav) Buffer Overflow Vulnerability
http://www.exploit-db.com/exploits/15493/

Banshee 'LD_LIBRARY_PATH' Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/44752

Linux Kernel 'l2tp_ip_sendmsg()' and 'pppol2tp_sendmsg()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/44762



+ Linux Kernel Block Layer Denial of Service Vulnerabilities
http://secunia.com/advisories/42176/

- CVE-2010-1646 sudo PATH variable privilege escalation
http://blogs.sun.com/security/entry/cve_2010_1646_sudo_path
http://secunia.com/advisories/42198/

- Linux Kernel Socket Filter Memory Leak Weakness
http://secunia.com/advisories/42187/

UPDATE: APSB10-26: Security update available for Adobe Flash Player
http://www.adobe.com/support/security/bulletins/apsb10-26.html

SYM10-011: Security Advisories Relating to Symantec Products - Norton Mobile Security Beta Information Disclosure
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20101111_00

Check Point Software Technologies : Apple Directory Services Memory Corruption - CVE-2010-1840
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34250

Mandriva : [MDVSA-2010:226] dhcp Denial-of-service Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34241

SuSE : [SUSE-SA:2010:057] Linux kernel Privilege-escalation Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34227

Acros Security : [ASPR #2010-11-10-1] Remote Binary Planting in Microsoft PowerPoint 2010
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34246

Acros Security : [ASPR #2010-11-10-2] Remote Binary Planting in Microsoft Word 2010
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34247

Acros Security : [ASPR #2010-11-10-3] Remote Binary Planting in Microsoft Excel 2010
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34248

Apple : [APPLE-SA-2010-11-10-1] Mac OS X v10.6.5 and Security Update 2010-007
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34242

Core Security Technologies : [CORE-2010-1018] Landesk OS command injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34249

FreeBSD : [FreeBSD-SA-10:09.pseudofs] pseudofs Information Disclosure
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34243

Independent Researcher : Babylon Cross-Application Scripting Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34245

NRIセキュア、管理サーバー不要の電子メール誤配信防止ソフト
http://itpro.nikkeibp.co.jp/article/NEWS/20101111/354072/?ST=security

PUBLIC ADVISORY: 11.11.10: Apple Mobile OfficeImport Framework Excel Parsing Memory Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=881

Fake AV scams via Skype Chat
http://isc.sans.edu/diary.html?storyid=9922

Oracle OpenSolaris Sudo "secure path" Security Bypass
http://secunia.com/advisories/42198/

IBM HTTP Server "mod_dav" Denial of Service Vulnerabilities
http://secunia.com/advisories/42231/

Drupal Node Relativity Module Multiple Vulnerabilities
http://secunia.com/advisories/42169/

SUSE update for kernel
http://secunia.com/advisories/42173/

Mono Unsafe Library Loading Vulnerability
http://secunia.com/advisories/42174/

Linux Kernel Block Layer Denial of Service Vulnerabilities
http://secunia.com/advisories/42176/

Linux Kernel Socket Filter Memory Leak Weakness
http://secunia.com/advisories/42187/

Drupal Category Tokens Module Script Insertion Vulnerability
http://secunia.com/advisories/42168/

Fedora update for libsmi
http://secunia.com/advisories/42214/

KaiBB Multiple Vulnerabilities
http://secunia.com/advisories/41945/

Emuci eBlog "id" and "keyword" SQL Injection Vulnerabilities
http://secunia.com/advisories/42201/

Apple QuickTime Sorenson Video 3 Array-Indexing Vulnerability
http://secunia.com/advisories/39259/

Fedora update for seamonkey
http://secunia.com/advisories/42224/

Red Hat update for java-1.5.0-ibm
http://secunia.com/advisories/42218/

FileCOPA Directory Traversal Vulnerability
http://secunia.com/advisories/42161/

FreeBSD "pfs_getextattr()" Privilege Escalation Vulnerability
http://secunia.com/advisories/42200/

LANDesk Management Gateway Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/42188/

Red Hat update for firefox
http://secunia.com/advisories/42216/

Red Hat update for krb5
http://secunia.com/advisories/42227/

Red Hat update for poppler
http://secunia.com/advisories/42226/

Red Hat update for nss
http://secunia.com/advisories/42213/

Red Hat update for freetype
http://secunia.com/advisories/42212/

Red Hat update for glibc
http://secunia.com/advisories/42215/

Red Hat update for cups
http://secunia.com/advisories/42219/

Red Hat update for bzip2
http://secunia.com/advisories/42223/

Red Hat update for kernel
http://secunia.com/advisories/42225/

Fedora update for proftpd
http://secunia.com/advisories/42217/

ProFTPd mod_site_misc Directory Traversal
http://www.securiteam.com/unixfocus/6R0360A0AY.html

Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Nov/1024729.html

LANDesk Management Gateway Input Validation Error Lets Remote Authenticated Administrators Injection Operating System Commands
http://securitytracker.com/alerts/2010/Nov/1024728.html

FreeBSD pseudofs Mutex Unlocking Error Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Nov/1024724.html

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/2958

LANDesk Management Gateway Cross Site Request Forgery Vulnerability
http://www.vupen.com/english/advisories/2010/2957

FreeBSD Security Update Fixes Pseudofs Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2010/2956

Redhat Security Update Fixes Java Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2955

Redhat Security Update Fixes Glibc Privilege Escalation Vulnerabilities
http://www.vupen.com/english/advisories/2010/2954

Redhat Security Update Fixes Flash Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2953

Redhat Security Update Fixes CUPS Use-after-free Vulnerability
http://www.vupen.com/english/advisories/2010/2952

Redhat Security Update Fixes OpenJDK Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2951

Redhat Security Update Fixes FreeType Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2950

Redhat Security Update Fixes Kerberos Uninitialized Pointer Vulnerability
http://www.vupen.com/english/advisories/2010/2949

Redhat Security Update Fixes NSS Certificate Processing Vulnerability
http://www.vupen.com/english/advisories/2010/2948

Redhat Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2947

Redhat Security Update Fixes Samba Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2946

Redhat Security Update Fixes Poppler Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2945

Redhat Security Update Fixes Bzip2 Integer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2944

Redhat Security Update Fixes Kernel Privilege Escalation and DoS Issues
http://www.vupen.com/english/advisories/2010/2943

Fedora Security Update Fixes Pidgin Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/2942

Fedora Security Update Fixes ProFTPD Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2941

Fedora Security Update Fixes SeaMonkey Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2940

Fedora Security Update Fixes LibSMI Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/2939

Ubuntu Security Update Fixes Libxml2 Memory Corruption Vulnerability
http://www.vupen.com/english/advisories/2010/2938

Ubuntu Security Update Fixes libvpx Memory Corruption Vulnerability
http://www.vupen.com/english/advisories/2010/2937

Mandriva Security Update Fixes DHCP Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2936

Mp3-Nator 2.0 Buffer Overflow Exploit (SEH)
http://www.exploit-db.com/exploits/15489/

ProFTPD Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/44562

libguestfs Disk Format Specifier Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44166

Apple iOS and Mac OS X URI Stack Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41049

Expat XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37203

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36097

Todd Miller Sudo 'secure path' Security Bypass Vulnerability
http://www.securityfocus.com/bid/40538

Oracle MySQL Prior to 5.1.49 'JOIN' Statement Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42646

Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42633

Oracle MySQL 'TEMPORARY InnoDB' Tables Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42598

Oracle MySQL Prior to 5.1.51 Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/43676

Oracle MySQL Prior to 5.1.49 Malformed 'BINLOG' Arguments Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42638

Oracle MySQL Prior to 5.1.49 'WITH ROLLUP' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42596

Oracle MySQL 'EXPLAIN' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42599

Oracle MySQL 'ALTER DATABASE' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/41198

Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42625

Linux Kernel 'net/core/filter.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44758

Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44242

Mozilla Firefox SeaMonkey and Thunderbird CVE-2010-3174 Memory-Corruption Vulnerability
http://www.securityfocus.com/bid/44246

Mozilla Firefox SeaMonkey and Thunderbird DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/44250

Apple Mac OS X Apple Type Services Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44805

Apple AppKit String Containing Bidirectional Text Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44803

Apple Mac OS X Apple Type Services Embedded Font Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44802

KaiBB 'staff/index.php' SQL Injection and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/44797

E-Xoopport eCal 'katid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/44791

XT:Commerce 'street' Field Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/44788

GDL 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/44786

QtWeb Browser Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44783

Symantec Norton Mobile Security Beta for Android Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44767

0 件のコメント:

コメントを投稿