2010年11月17日水曜日

17日 水曜日、先負

- Linux Kernel Invalid 'fs' and 'gs' Registry Denial of Service Vulnerability
http://www.securityfocus.com/bid/44500

SUSE update for Multiple Packages
http://secunia.com/advisories/42252/

Apple Mac OS X Dovecot Memory Aliasing Security Issue
http://secunia.com/advisories/42278/

OpenFabrics Enterprise Distribution (OFED) "libsdp" Security Issue
http://secunia.com/advisories/42281/

libsdp Insecure Temporary Files Security Issue
http://secunia.com/advisories/42242/

OpenSSL TLS Server Extension Parsing Race Condition Vulnerability
http://secunia.com/advisories/42243/

Eclipse Help Server Two Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/42236/

VMware ESX / ESXi Server Update for Multiple Packages
http://secunia.com/advisories/42280/

IBM WebSphere Commerce Sample Store Pages Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/42250/

IBM WebSphere Commerce Organization Admin Console SQL Injection Vulnerability
http://secunia.com/advisories/42249/

VMware ESX Server Multiple Vulnerabilities
http://secunia.com/advisories/42240/

HP LaserJet Printers PJL Directory Traversal Vulnerability
http://secunia.com/advisories/42238/

IBM WebSphere Portal "SemanticTagService.js" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/42245/

Joomla! Al-Furqan Component "surano" SQL Injection Vulnerability
http://secunia.com/advisories/42232/

Gentoo update for glibc
http://secunia.com/advisories/42208/

Nuked-Klan Boutique Module "catid" SQL Injection Vulnerability
http://secunia.com/advisories/42221/

BPowerHouse BPRealestate "rpPassword" SQL Injection Vulnerability
http://secunia.com/advisories/42268/

BPowerHouse BPConferenceReporting "passw" SQL Injection Vulnerability
http://secunia.com/advisories/42269/

BPowerHouse BPDirectory "tbPassword" SQL Injection Vulnerability
http://secunia.com/advisories/42274/

BPowerHouse BPAffiliateTracking "txtpas" SQL Injection Vulnerability
http://secunia.com/advisories/42277/

DServe Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/42259/

NolaPro Two SQL Injection Vulnerabilities
http://secunia.com/advisories/42210/

[ANNOUNCE] Apache Whirr 0.2.0-incubating released
http://www.apache.org/dyn/closer.cgi/incubator/whirr/
https://issues.apache.org/jira/browse/WHIRR/fixforversion/12315339

http://www.infoteria.com/サイトのシステムメンテナンスのお知らせ
http://asteria.jp/news/20101117-111926.html

ウイルスバスター2011 プログラムアップデートについて
http://www.trendmicro.co.jp/support/news.asp?id=1489

InterScan WebManager Lite Service Pack 2 用Critical Patch 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1491

HS10-029: Collaboration - File SharingにおけるDoS脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-029/index.html

HS10-028: Groupmax Integrated Desktop, Groupmax Client Light Ex, Groupmax World Wide Web Desktopにおけるバッファオーバーフローの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-028/index.html

Adobe Reader および Acrobat の脆弱性(APSB10-28)について
http://www.ipa.go.jp/security/ciadr/vul/20101117-adobe.html

カード番号をトークン化するデータ保護ソフト、RSAセキュリティが投入
http://itpro.nikkeibp.co.jp/article/NEWS/20101117/354242/?ST=security

Adobe Reader 及び Acrobat の脆弱性に関する注意喚起
http://www.jpcert.or.jp/at/2010/at100031.txt

JPCERT/CC WEEKLY REPORT 2010-11-17
http://www.jpcert.or.jp/wr/2010/wr104401.html

JVNVU#298081 Adobe Flash に脆弱性
http://jvn.jp/cert/JVNVU298081/index.html

Reference on Open Source Digital Forensics
http://isc.sans.edu/diary.html?storyid=9955

FreeType Buffer Overflow in ft_var_readpackedpoints() Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Nov/1024745.html

CUPS Server 'cups/ipp.c' Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44530

FreeType 'ft_var_readpackedpoints()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44214

Mozilla Firefox and SeaMonkey Gopher Parser Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44253

Mozilla Firefox SeaMonkey and Thunderbird 'LD_LIBRARY_PATH' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44251

Mozilla Firefox SeaMonkey and Thunderbird 'LookupGetterOrSetter' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44249

Mozilla Firefox SeaMonkey and Thunderbird CVE-2010-3176 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44243

Multiple Browser Wild Card Certificate Spoofing Vulnerability
http://www.securityfocus.com/bid/42817

Mozilla Firefox SeaMonkey and Thunderbird 'nsBarProp' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44248

Mozilla Firefox and Thunderbird CVE-2010-3175 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44245

Mozilla Firefox SeaMonkey and Thunderbird 'document.write' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44247

Mozilla Firefox SeaMonkey Thunderbird Modal Calls Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44252

D-Link DIR-300 'tools_admin.php' Security Bypass Vulnerability
http://www.securityfocus.com/bid/44743

Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44014

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/44013

Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43992

Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/43994

GNU glibc Dynamic Linker '$ORIGIN' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44154

GNU glibc Dynamic Linker 'LD_AUDIT' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44347

bzip2 'BZ2_decompress' Function Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43331

Oracle Communications Messaging Server CVE-2010-3564 Webmail Remote Vulnerability
http://www.securityfocus.com/bid/43963

Linux Kernel ALSA 'sound/core/control.c' Local Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43787

Linux Kernel 915 GEM IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44067

Oracle Java SE and Java for Business CVE-2010-3550 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44040

Linux Kernel Invalid 'fs' and 'gs' Registry Denial of Service Vulnerability
http://www.securityfocus.com/bid/44500

Linux Kernel 'drivers/net/niu.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/43098

Linux Kernel 'PKT_CTRL_CMD_STATUS' Invalid Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/43551

Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/44027

Oracle Java SE and Java for Business CVE-2010-3566 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43988

Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44032

Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability
http://www.securityfocus.com/bid/44017

Oracle Java SE and Java for Business CVE-2010-3556 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43971

Oracle Java SE and Java for Business CVE-2010-3559 HeadspaceSoundbank.nGetName Vulnerability
http://www.securityfocus.com/bid/44026

Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability
http://www.securityfocus.com/bid/44030

Linux Kernel SCTP HMAC Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43701

Linux Kernel 'set_ftrace_filter' File Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/43684

Linux Kernel Ptrace (CVE-2010-3301) Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43355

Linux Kernel 'video4linux' IOCTL and IP Multicast 'getsockopt' Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43239

Linux Kernel 'sctp_outq_flush()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/43480

Linux Kernel 'SIOCGIWSSID' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42885

MIT Kerberos KDC 'kdc_authdata.c' NULL Pointer Denial Of Service Vulnerability
http://www.securityfocus.com/bid/43756

Linux Kernel DRM Module IOCTL Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42577

Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44016

Oracle Java SE and Java for Business CVE-2010-3573 Same Origin Bypass Vulnerability
http://www.securityfocus.com/bid/44028

PHPShop 'name_new' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44763

Samba SID Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43212




+ Linux kernel 2.6.37-rc2 released
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2

+ RHSA-2010:0889-1: Important: freetype security update
http://rhn.redhat.com/errata/RHSA-2010-0889.html

+ OpenSSL 0.9.8p, 1.0.0b released
http://www.openssl.org/source/exp/CHANGES
http://www.openssl.org/source/exp/CHANGES

+ TLS extension parsing race condition.
http://www.openssl.org/news/secadv_20101116.txt
http://isc.sans.edu/diary.html?storyid=9946
http://www.securitytracker.com/id?1024743
http://secunia.com/advisories/42243/
http://www.securityfocus.com/bid/44884

++ Perl MIME Boundary 'multipart_init' Unspecified Security Vulnerability
http://www.securityfocus.com/bid/44892

- MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
http://www.securityfocus.com/bid/38043

APSB10-28: Security updates available for Adobe Reader and Acrobat
http://www.adobe.com/support/security/bulletins/apsb10-28.html

UPDATE: APSA10-05: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat
http://www.adobe.com/support/security/advisories/apsa10-05.html

Survey Shows Client/Server and Early Web Applications are the New Top Priorities for Modernization
http://www.nexaweb.com/about/news-events/press-releases/default.cfm?id=56

RHSA-2010:0888 Important: openssl security update
http://rhn.redhat.com/errata/RHSA-2010-0888.html

RHSA-2010:0889 Important: freetype security update
http://rhn.redhat.com/errata/RHSA-2010-0889.html

RHSA-2010:0890 Moderate: pidgin security update
http://rhn.redhat.com/errata/RHSA-2010-0890.html

RHSA-2010:0891 Moderate: pam security update
http://rhn.redhat.com/errata/RHSA-2010-0891.html

RHSA-2010:0892 Moderate: openswan security update
http://rhn.redhat.com/errata/RHSA-2010-0892.html

VMSA-2010-0016: VMware ESXi and ESX third party updates for Service Console and Likewise components
http://www.vmware.com/security/advisories/VMSA-2010-0016.html

Mandriva : [MDVSA-2010:232] cups fixes for multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34276

Mandriva : [MDVSA-2010:233] cups
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34277

Mandriva : [MDVSA-2010:234] cups Multiple Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34278

Mandriva : [MDVSA-2010:235] freetype2 Multiple Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34279

Mandriva : [MDVSA-2010:236] freetype2
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34280

YGN Ethical Hacker Group : Eclipse IDE Help Server Local Cross Site Scripting (XSS) Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34282

Apple : [APPLE-SA-2010-11-15-1] Mac OS X Server v10.6.5 (10H575)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34281

Gentoo Linux : [GLSA 201011-01] GNU C library: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34284

OpenSSL TLS Extension Parsing Race Condition
http://isc.sans.edu/diary.html?storyid=9946

Acrobat and Adobe Reader Security Update
http://isc.sans.edu/diary.html?storyid=9949

HP OpenView Network Node Manager (OV NNM) Execution of Arbitrary Code Vulnerability
http://www.securiteam.com/securitynews/6I0371P0AU.html

Adobe Acrobat Reader ICC mluc Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6J0381P0AC.html

Adobe Acrobat Reader Multimedia Playing Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6K0391P0AY.html

IBM TSM FastBack Server _Eventlog Format String Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6S03A1P0AI.html

HP and Red Hat Directory Server for HP-UX Local Disclosure of Information and Privilege Escalation Vulnerabilities
http://www.securiteam.com/securitynews/6H0361P0AG.html

OpenSSL Buffer Overflow in TLS Server Extension Parsing May Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Nov/1024743.html

HP LaserJet Printer Printer Job Language (PJL) Interface Directory Traversal Flaw Lets Remote Users View Arbitrary Files
http://securitytracker.com/alerts/2010/Nov/1024741.html

CUPS Internet Printing Protocol Packets Use-after-free Vulnerability
http://www.vupen.com/english/advisories/2010/2992

VMware ESX Security Update Fixes Code Execution and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2010/2991

VMware ESXi Security Update Fixes Code Execution and DoS Vulnerabilities
http://www.vupen.com/english/advisories/2010/2990

Hitachi Form Products Unspecified Remote Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/2989

Eclipse IDE Help Pages Two Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/2988

HP LaserJet Printers Printer Job Language Directory Traversal Vulnerability
http://www.vupen.com/english/advisories/2010/2987

Apple Mac OS X Security Update Fixes Dovecot Memory Aliasing Issue
http://www.vupen.com/english/advisories/2010/2986

OpenTTD Client Disconnection Handling Use-after-free Vulnerability
http://www.vupen.com/english/advisories/2010/2985

Mandriva Security Update Fixes CUPS Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2984

Gentoo Security Update Fixes GNU C Library Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2983

Safari 5.02 Stack Overflow Denial of Service
http://www.exploit-db.com/exploits/15558/

Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44219

Digium Zaptel Multiple Local Privilege Escalation and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/32575

Openswan 'XAUTH' Remote Buffer Overflow and Command Injection Vulnerabilities
http://www.securityfocus.com/bid/43588

Pidgin 'libpurple' Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/44283

FreeType 'ft_var_readpackedpoints()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44214

Linux Kernel XDR Implementation Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42249

Google Chrome 'Math.Random()' Random Number Generation Vulnerability
http://www.securityfocus.com/bid/36185

PAM 'pam_namespace' Module Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44590

Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
http://www.securityfocus.com/bid/43487

pam-xauth Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/42472

Adobe Reader 9.4 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44638

Adobe Acrobat, Reader, and Flash CVE-2010-3654 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44504

FreeType TrueType Font Handling 'ttinterp.c' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44643

OpenSSL 'ssl3_get_key_exchange()' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42306

YUI Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44420

monotone Denial Of Service Vulnerability
http://www.securityfocus.com/bid/44383

ISC DHCP Server Relay-Forward Empty Link-Address Field Denial of Service Vulnerability
http://www.securityfocus.com/bid/44615

MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
http://www.securityfocus.com/bid/38043

MySQL MyISAM Table Symbolic Link Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37075

Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42633

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
http://www.securityfocus.com/bid/40109

Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/40257

Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/40100

Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42625

CUPS Server 'cups/ipp.c' Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44530

CUPS 'cupsFileOpen' function Symlink Attack Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/41131

CUPS 'texttops' Filter NULL-pointer Dereference Vulnerability
http://www.securityfocus.com/bid/40943

CUPS Web Interface Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40897

CUPS Web Interface Unspecified Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/40889

MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34409

MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40235

MIT Kerberos AES and RC4 Decryption Integer Underflow Vulnerabilities
http://www.securityfocus.com/bid/37749

MIT Kerberos 'NegTokenInit' Token Handling Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34257

MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34408

Linux Kernel CVE-2010-0291 'mmap()' and 'mremap()' Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/37906

Linux Kernel VM/VFS 'invalidatepage()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39569

Linux Kernel NFS Automount 'symlinks' Denial of Service Vulnerability
http://www.securityfocus.com/bid/39044

Linux Kernel 'do_pages_move()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38144

Linux Kernel 'find_keyring_by_name()' Local Memory Corruption Vulnerability
http://www.securityfocus.com/bid/39719

Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38027

Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/43594

Xpdf 'FoFiType1::parse()' Array Indexing Error Vulnerability
http://www.securityfocus.com/bid/43841

Xpdf 'Gfx::getPos()' (CVE-2010-3702) Unitialized Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/43845

Mozilla Firefox SeaMonkey and Thunderbird 'nsBarProp' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44248

Mozilla Firefox SeaMonkey and Thunderbird CVE-2010-3176 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44243

Multiple Browser Wild Card Certificate Spoofing Vulnerability
http://www.securityfocus.com/bid/42817

Mozilla Firefox and Thunderbird CVE-2010-3175 Multiple Memory-Corruption Vulnerabilities
http://www.securityfocus.com/bid/44245

FreeType Stack Buffer Overflow and Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/42285

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Mozilla Firefox 3.5/3.6 Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44425

Mozilla Firefox SeaMonkey and Thunderbird 'document.write' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44247

Mozilla Firefox SeaMonkey Thunderbird Modal Calls Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44252

Mozilla Firefox SeaMonkey and Thunderbird 'LookupGetterOrSetter' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44249

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

FreeType Rendering Engine Position Value Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43700

Mozilla Firefox SeaMonkey and Thunderbird 'LD_LIBRARY_PATH' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44251

Mozilla Firefox and SeaMonkey Gopher Parser Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/44253

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
http://www.securityfocus.com/bid/38043

MySQL MyISAM Table Symbolic Link Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37075

Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42633

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
http://www.securityfocus.com/bid/40109

Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/40257

Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/40100

Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/42625

CUPS Server 'cups/ipp.c' Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/44530

CUPS 'cupsFileOpen' function Symlink Attack Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/41131

CUPS 'texttops' Filter NULL-pointer Dereference Vulnerability
http://www.securityfocus.com/bid/40943

CUPS Web Interface Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40897

CUPS Web Interface Unspecified Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/40889

MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34409

MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/40235

MIT Kerberos AES and RC4 Decryption Integer Underflow Vulnerabilities
http://www.securityfocus.com/bid/37749

MIT Kerberos 'NegTokenInit' Token Handling Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34257

MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34408

Linux Kernel CVE-2010-0291 'mmap()' and 'mremap()' Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/37906

Linux Kernel VM/VFS 'invalidatepage()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39569

Linux Kernel NFS Automount 'symlinks' Denial of Service Vulnerability
http://www.securityfocus.com/bid/39044

Linux Kernel 'do_pages_move()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38144

Linux Kernel 'find_keyring_by_name()' Local Memory Corruption Vulnerability
http://www.securityfocus.com/bid/39719

Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38027

Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/43594

Xpdf 'FoFiType1::parse()' Array Indexing Error Vulnerability
http://www.securityfocus.com/bid/43841

Xpdf 'Gfx::getPos()' (CVE-2010-3702) Unitialized Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/43845

FreeType Stack Buffer Overflow and Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/42285

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Mozilla Firefox 3.5/3.6 Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44425

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

FreeType Rendering Engine Position Value Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/43700

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44009

Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44035

ClanSphere Information Disclosure, SQL Injection and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/44897

IceBB SQL Injection and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/44895

Perl MIME Boundary 'multipart_init' Unspecified Security Vulnerability
http://www.securityfocus.com/bid/44892

openEngine 'website.php' Local File Include and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44888

NolaPro Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/44885

OpenSSL TLS Server Extension Parsing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44884

Jetty Web Server Plugin for Eclipse Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44883

DServe Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44881

Raised Eyebrow CMS 'venue.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/44880

AbleDating 'forum.php' HTML Injection Vulnerability
http://www.securityfocus.com/bid/44879

Simea CMS 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/44878

Maian Media Component for Joomla! 'cat' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/44877

BPowerHouse Multiple Products Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/44876

0 件のコメント:

コメントを投稿