2010年12月15日水曜日

15日 水曜日、友引

+ Linux Kernel release: 2.6.35.10
http://www.linux.org/news/2010/12/14/0001.html

Vulnerability in Citrix Access Gateway legacy authentication support could result in command injection
http://support.citrix.com/article/CTX127613

Internet Explorer の脆弱性の修正について(MS10-090)
http://www.ipa.go.jp/security/ciadr/vul/20101215-ms10-090.html

JVNTA10-348A Microsoft 製品における複数の脆弱性に対するアップデート
http://jvn.jp/cert/JVNTA10-348A/index.html

JVN#33301529 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN33301529/index.html

JVN#21120853 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN21120853/index.html

JVN#30273074 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN30273074/index.html

JVN#62275332 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN62275332/index.html

JVNDB-2010-002300 Apache Portable Utility ライブラリの apr_brigade_split_line 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002300.html

JVNDB-2010-002014 Perl の Safe モジュールにおける任意のコードを挿入または実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002014.html

JVNDB-2010-001966 PHP のセッションシリアライザにおける任意のセッション変数に変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001966.html

JVNDB-2010-001879 JP1/NETM 製品 におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001879.html

JVNDB-2010-001836 PHP におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001836.html

JVNDB-2010-001457 PHP の xmlrpc 拡張におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001457.html

JVNDB-2010-001233 PHP の Linear Congruential Generator における値を推測される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001233.html

JVNDB-2009-002447 GNU Libtool の libltdl における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002447.html

JVNDB-2009-002095 fetchmail における任意の SSL サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002095.html

JVNDB-2010-002501 Apple Safari の WebKit におけるロケーションバーの URL を偽装される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002501.html

JVNDB-2010-002500 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002500.html

JVNDB-2010-002499 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002499.html

JVNDB-2010-002498 Apple Safari および Google Chrome の WebKit における同一生成元ポリシーを回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002498.html

JVNDB-2010-002497 Apple Safari の WebKit 内にある JavaScript 実装における整数アンダーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002497.html

JVNDB-2010-002496 Apple Safari の WebKit 内にある JavaScript 実装におけるユーザを追跡可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002496.html

JVNDB-2010-002495 Apple Safari の WebKit における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002495.html

JVNDB-2010-000065 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000065.html

JVNDB-2010-000064 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000064.html

JVNDB-2010-000063 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000063.html

JVNDB-2010-000062 Internet Explorer におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000062.html

JVNDB-2010-001669 Samba の chain_reply 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001669.html

JVNDB-2009-002356 Apache Tomcat の Windows インストーラにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002356.html

JVNDB-2010-001070 Apache Tomcat におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001070.html

JVNDB-2010-001071 Apache Tomcat におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001071.html

JVNDB-2009-001843 Apache APR-util の apr_strmatch_precompile 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001843.html

JVNDB-2009-001844 Apache APR-util の XML パーサにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001844.html

JVNDB-2009-001845 Apache APR-util の apr_brigade_vprintf 関数における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001845.html

JVNDB-2009-001562 Apache HTTP Server における AllowOverride ディレクティブの処理に関する権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001562.html

JVNDB-2009-001892 Apache httpd の mod_deflate モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001892.html

JVNDB-2009-001884 Apache HTTP Server の mod_proxy におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001884.html

JVNDB-2009-002188 Apache HTTP Server の mod_proxy_ftp モジュールにおけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002188.html

JVNDB-2009-002187 Apache HTTP Server の ap_proxy_ftp_handler 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002187.html

JVNDB-2009-002474 PHP におけるスーパーグローバル配列 SESSION の割り込み領域が破壊される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002474.html

JVNDB-2009-002473 PHP の htmlspecialchars 関数におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002473.html

JVNDB-2009-002405 PHP の proc_open 関数における任意の環境でプログラムを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002405.html

JVNDB-2009-002404 PHP における multipart/form-data POST リクエストの処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002404.html

JVNDB-2009-002402 PHP の tempnam 関数における safe_mode の制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002402.html

JVNDB-2009-002177 PHP の imagecolortransparent 関数におけるカラーインデックスの処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002177.html

JVNDB-2009-002179 PHP における exif のチェックに関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002179.html

JVNDB-2009-002178 PHP の php_openssl_apply_verification_policy 関数における証明書の検証処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002178.html

JVNDB-2009-001875 PHP の exif_read_data 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001875.html

JVNDB-2005-000874 UnZip のファイル解凍時におけるパーミッションの処理に競合状態の脆弱性
http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000874.html

JVNDB-2008-001181 UnZip の NEEDBITS マクロにおける無効なバッファ領域を参照してしまう問題
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001181.html

JVNDB-2010-001499 PostgreSQL における任意の Tcl コードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001499.html

JVNDB-2010-001498 PostgreSQL における任意の Perl コードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001498.html

SAP NetWeaver Business Client Buffer Overflow in 'sapwdpcd.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Dec/1024890.html




+ 2010 年 12 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms10-dec.mspx

+ MS10-090 Internet Explorer 用の累積的なセキュリティ更新プログラム (2416400)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-090.mspx
http://www.securityfocus.com/bid/44536/exploit

+ MS10-091 OpenType フォント (OTF) ドライバーの脆弱性により、リモートでコードが実行される (2296199)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-091.mspx

+ MS10-094 Windows Media エンコーダーの脆弱性により、リモートでコードが実行される (2447961)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-094.mspx

+ MS10-096 Windows アドレス帳の脆弱性により、リモートでコードが実行される (2423089)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-096.mspx
http://www.securityfocus.com/bid/42648/exploit

+ MS10-097 インターネット接続のサインアップ ウィザードの安全でないライブラリのロードにより、リモートでコードが実行される (2443105)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-097.mspx
http://www.securityfocus.com/bid/42713/exploit

+ MS10-098 Windows カーネルモード ドライバーの脆弱性により、特権が昇格される (2436673)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-098.mspx

+ MS10-099 ルーティングとリモート アクセスの脆弱性により、特権が昇格される (2440591)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-099.mspx

+ MS10-101 Windows Netlogon サービスの脆弱性により、サービス拒否が起こる (2207559)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-101.mspx

-+ MS10-103 Microsoft Publisher の脆弱性により、リモートでコードが実行される (2292970)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-103.mspx

+ MS10-105 Microsoft Office グラフィック フィルターの脆弱性により、リモートでコードが実行される (968095)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-105.mspx
対象名:Office XP/Excel 2003

+ マイクロソフト セキュリティ アドバイザリ (2458511): Internet Explorer の脆弱性により、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/2458511.mspx
http://www.microsoft.com/technet/security/advisory/2458511.mspx

+ Linux Kernel 'x25_parse_facilities()' CVE-2010-4164 Remote Denial of Service Vulnerabilit
http://www.securityfocus.com/bid/45055

- MS10-092 タスク スケジューラの脆弱性により、特権が昇格される (2305420)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-092.mspx
http://www.securityfocus.com/bid/44357/exploit

- MS10-093 Windows ムービー メーカーの脆弱性により、リモートでコードが実行される (2424434)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-093.mspx

- MS10-095 Microsoft Windows の脆弱性により、リモートでコードが実行される (2385678)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-095.mspx
http://www.securityfocus.com/bid/45295/exploit

- MS10-100 承認 ユーザー インターフェイスの脆弱性により、特権が昇格される (2442962)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-100.mspx

- MS10-102 Hyper-V の脆弱性により、サービス拒否が起こる (2345316)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-102.mspx

- MS10-104 Microsoft SharePoint の脆弱性により、リモートでコードが実行される (2455005)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-104.mspx

- MS10-106 Microsoft Exchange Server の脆弱性により、サービス拒否が起こる (2407132)
http://www.microsoft.com/japan/technet/security/bulletin/MS10-106.mspx

CESA-2010:0898 (kvm)
http://lwn.net/Alerts/419801/

CESA-2010:0976 (bind)
http://lwn.net/Alerts/419799/

CESA-2010:0978 (openssl)
http://lwn.net/Alerts/419800/

HPSBMA02615 SSRT100228 rev.1 - HP Insight Diagnostics Online Edition Running on Linux and Windows, Remote Cross Site Scripting (XSS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02652463&admit=109447626+1292381665332+28353475

HPSBMA02616 SSRT100231 rev.1 - HP Insight Management Agents Running on Linux and Windows, Remote Full Path Disclosure
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02653973&admit=109447626+1292381646902+28353475

HPSBOV02618 SSRT100354 rev.1 - HP OpenVMS Integrity Servers, Local Denial of Service (DoS), Gain Privileged Access
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02656471&admit=109447626+1292381726279+28353475

UPDATE: Microsoft Security Advisory (973811): Extended Protection for Authentication
http://www.microsoft.com/technet/security/advisory/973811.mspx

UPDATE: Microsoft Security Advisory (2458511): Vulnerability in Internet Explorer Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/2458511.mspx

UPDATE: Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/2269637.mspx

UPDATE: マイクロソフト セキュリティ アドバイザリ (2269637): 安全でないライブラリのロードにより、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/2269637.mspx

UPDATE: マイクロソフト セキュリティ アドバイザリ (2458511): Internet Explorer の脆弱性により、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/2458511.mspx

UPDATE: マイクロソフト セキュリティ アドバイザリ(973811): 認証に対する保護の強化
http://www.microsoft.com/japan/technet/security/advisory/973811.mspx

Debian : [DSA-2133-1] New collectd packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34470

eVuln : [EV0160] "url" BBCode XSS in slickMsg
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34471

Microsoft : Cumulative Security Update for Internet Explorer
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34485

Microsoft : Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34486

Microsoft : Vulnerability in Task Scheduler Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34487

Microsoft : Vulnerability in Windows Movie Maker Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34488

Microsoft : Vulnerability in Windows Media Encoder Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34489

Microsoft : Vulnerability in Microsoft Windows Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34490

Microsoft : Vulnerability in Windows Address Book Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34491

Microsoft : Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34492

Microsoft : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34493

Microsoft : Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34494

Microsoft : Vulnerability in Consent User Interface Could Allow Elevation of Privilege
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34495

Microsoft : Vulnerability in Windows Netlogon Service Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34496

Microsoft : Vulnerability in Hyper-V Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34497

Microsoft : Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34498

Microsoft : Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34499

Microsoft : Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34500

Microsoft : Vulnerability in Microsoft Exchange Server Could Allow Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34501

SuSE : [SUSE-SA:2010:060] Linux kernel
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34459

Core Security Technologies : [CORE-2010-0728] Symantec Intel Handler Service Remote Denial-of-Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34478

Red Hat : [RHSA-2010:0975-01] Important: bind security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34462

Red Hat : [RHSA-2010:0976-01] Important: bind security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34463

Red Hat : [RHSA-2010:0977-01] Moderate: openssl security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34464

Red Hat : [RHSA-2010:0978-01] Moderate: openssl security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34465

Red Hat : [RHSA-2010:0979-01] Moderate: openssl security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34466

SuSE : [SUSE-SA:2010:059] exim
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34458

Debian : [DSA 2132-1] New xulrunner packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34469

Maksymilian Arciemowicz : PHP 5.3.3 NumberFormatter::getSymbol Integer Overflow
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34472

Slackware Linux : [SSA:2010-344-01] seamonkey
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34460

Solutionary, Inc. : [SERT-VDN-1002] Novell Vibe 3 BETA OnPrem Stored Cross-site Scripting Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34473

Solutionary, Inc. : [SERT-VDN-1000] ManageEngine EventLog Analyzer Syslog Remote Denial of Service Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34474

Solutionary, Inc. : [SERT-VDN-1001] ManageEngine EventLog Analyzer Multiple Cross-site Scripting (XSS) Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34475

Ubuntu Security Notice : [USN-1032-1] Exim vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34457

Debian : [DSA-2130-1] New BIND packages fix denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34467

Debian : [DSA-2131-1] New exim4 packages fix remote code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34468

[ MDVSA-2010:253 ] bind
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00119.html

USBsploit 0.5b - added: Railgun[only] - process migration - EXE, PDF, LNK replacements &
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00120.html

Honggfuzz
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00118.html

VUPEN Security Research - RealPlayer RA5 Data Handling Heap Overflow Vulnerability (VUPEN-SR
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00117.html

VUPEN Security Research - RealPlayer RealMedia Data Handling Heap Overflow Vulnerabilities (VUPE
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00116.html

VUPEN Security Research - RealPlayer AAC Data Handling Buffer Overflow Vulnerability (VUPEN-
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00114.html

VUPEN Security Research - RealPlayer Audio Data Handling Buffer Overflow Vulnerability (VUPEN
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00115.html

VUPEN Security Research - RealPlayer Sound Data Handling Buffer Overflow Vulnerability (VUPEN
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00113.html

[ MDVSA-2010:252 ] perl-CGI-Simple
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00112.html

[SECURITY] [DSA-2133-1] New collectd packages fix denial of service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00111.html

IEに細工されたHTML文書の閲覧で任意のコードを実行される危険な脆弱性が発覚、JVNが緊急警告
http://itpro.nikkeibp.co.jp/article/NEWS/20101214/355216/?ST=security

PUBLIC ADVISORIES LIST: 12.14.10: Microsoft Internet Explorer CSS Style Table Layout Uninitialized Memory Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=885

PUBLIC ADVISORIES LIST: 12.14.10: Microsoft Internet Explorer HTML Object Memory Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=886

RHSA-2010:0981: Critical: HelixPlayer removal
http://rhn.redhat.com/errata/RHSA-2010-0981.html

December 2010 Microsoft Black Tuesday Summary
http://isc.sans.edu/diary.html?storyid=10081

FontForge .BDF Font File Stack-Based Buffer Overflow
http://securityreason.com/securityalert/7959

Microsoft Exchange Server RPC Processing Flaw Lets Remote Authenticated Users Deny Service
http://www.securitytracker.com/id?1024888

Microsoft Office Graphics Filters Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1024887

Microsoft SharePoint Input Validation Flaw in Processing SOAP Requests Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1024886

Microsoft Publisher Bugs Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1024885

Microsoft Hyper-V Input Validation Flaw Lets Local Guest Operating System Users Deny Service
http://www.securitytracker.com/id?1024884

Windows Netlogon Service Lets Remote Authenticated Users Deny Service
http://www.securitytracker.com/id?1024883

Windows Consent User Interface Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id?1024882

Windows Routing and Remote Access NDProxy Buffer Overflow Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id?1024881

Windows Kernel Buffer Overflows and Memory Corruption Errors Let Local Users Gain Elevated Privileges
http://www.securitytracker.com/id?1024880

Microsoft Windows Internet Connection Signup Wizard May Load DLLs Unsafely and Remotely Execute Arbitrary Code
http://www.securitytracker.com/id?1024879

Windows Address Book May Load DLLs Unsafely and Remotely Execute Arbitrary Code
http://www.securitytracker.com/id?1024878

Microsoft Windows May Load DLLs Unsafely and Remotely Execute Arbitrary Code
http://www.securitytracker.com/id?1024877

Windows Media Encoder May Load DLLs Unsafely and Remotely Execute Arbitrary Code
http://www.securitytracker.com/id?1024876

Windows Movie Maker May Load DLLs Unsafely and Remotely Execute Arbitrary Code
http://www.securitytracker.com/id?1024875

Microsoft Windows Task Scheduler Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id?1024874

Windows OpenType Font Driver Memory Corruption Flaws Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1024873

Microsoft Internet Explorer Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Domain Attacks
http://www.securitytracker.com/id?1024872

IBM Lotus Mobile Connect Input Validation Hole Permits Cross-Site Scripting Attacks
http://www.securitytracker.com/id?1024871

Novell ZENworks Desktop Management Buffer Overflows Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1024870

Microsoft Office Drawing Shape Container Parsing Vulnerability
http://www.securiteam.com/windowsntfocus/6Q036150KO.html

Microsoft Office Word Document Stack Overflow Vulnerability
http://www.securiteam.com/windowsntfocus/6T039150KA.html

SAP BusinessObjects Crystal Reports Server CMS.exe Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6S038150KU.html

Microsoft PowerPoint PP7X32.DLL Record Parsing Vulnerability
http://www.securiteam.com/windowsntfocus/6R037150KO.html

Microsoft Office Word Document Buffer Overflow Vulnerability
http://www.securiteam.com/windowsntfocus/6C03B150KG.html

Microsoft Office Word Document Array Indexing Vulnerability
http://www.securiteam.com/windowsntfocus/6D03C150KW.html

Microsoft Office Word Return Value Handling Vulnerability
http://www.securiteam.com/windowsntfocus/6B03A150KM.html

Microsoft Windows win32k.sys Driver Multiple Vulnerabilities
http://secunia.com/advisories/42612/

Microsoft Office Graphics Filters Multiple Vulnerabilities
http://secunia.com/advisories/35600/

Microsoft Exchange Server RPC Denial of Service Vulnerability
http://secunia.com/advisories/42633/

Microsoft Windows Internet Connection Signup Wizard Insecure Library Loading Vulnerability
http://secunia.com/advisories/42611/

Microsoft Office Publisher Multiple Vulnerabilities
http://secunia.com/advisories/42630/

Microsoft Windows BranchCache Insecure Library Loading Vulnerability
http://secunia.com/advisories/42630/

Microsoft SharePoint Document Conversions Launcher Service Vulnerability
http://secunia.com/advisories/42631/

Microsoft Windows Hyper-V VMBus Denial of Service Vulnerability
http://secunia.com/advisories/42617/

Microsoft Windows Movie Maker Insecure Library Loading Vulnerability
http://secunia.com/advisories/42607/

Microsoft Windows Netlogon RPC Service Denial of Service Vulnerability
http://secunia.com/advisories/42615/

Microsoft Windows OpenType Font Driver Three Vulnerabilities
http://secunia.com/advisories/42604/

Microsoft Windows Routing and Remote Access NDProxy Buffer Overflow
http://secunia.com/advisories/42613/

Microsoft Windows Consent User Interface Privilege Escalation Vulnerability
http://secunia.com/advisories/42614/

echoping Two Buffer Overflow Vulnerabilities
http://secunia.com/advisories/42619/

SUSE update for kernel
http://secunia.com/advisories/42585/

Symantec Antivirus Alert Management System Denial of Service Vulnerability
http://secunia.com/advisories/42593/

Novell ZENworks Desktop Management Multiple Vulnerabilities
http://secunia.com/advisories/42598/

Fedora update for fontforge
http://secunia.com/advisories/42577/

Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/42605/

Fedora update for openttd
http://secunia.com/advisories/42578/

SAP Crystal Reports Print ActiveX Control Buffer Overflow Vulnerability
http://secunia.com/advisories/42305/

LiteSpeed Web Server HTTP Header Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/42592/

Red Hat update for openssl
http://secunia.com/advisories/42621/

Red Hat update for openssl
http://secunia.com/advisories/42620/

Red Hat update for openssl
http://secunia.com/advisories/42434/

Debian update for collectd
http://secunia.com/advisories/42491/

Red Hat update for bind
http://secunia.com/advisories/42623/

Red Hat update for bind
http://secunia.com/advisories/42441/

Internet Explorer CSS Import Rule Processing Memory Corruption Vulnerability
http://secunia.com/advisories/42510/

Microsoft Exchange Server Remote Denial of Service Vulnerability (MS10-106)
http://www.vupen.com/english/advisories/2010/3228

Microsoft Office Graphics Filters Code Execution Vulnerabilities (MS10-105)
http://www.vupen.com/english/advisories/2010/3227

Microsoft Office SharePoint Remote Code Execution Vulnerability (MS10-104)
http://www.vupen.com/english/advisories/2010/3226

Microsoft Office Publisher Multiple Code Execution Vulnerabilities (MS10-103)
http://www.vupen.com/english/advisories/2010/3225

Microsoft Windows Hyper-V Local Denial of Service Vulnerability (MS10-102)
http://www.vupen.com/english/advisories/2010/3224

Microsoft Windows Netlogon Service Remote Denial of Service (MS10-101)
http://www.vupen.com/english/advisories/2010/3223

Microsoft Windows Consent User Interface Privilege Escalation (MS10-100)
http://www.vupen.com/english/advisories/2010/3222

Microsoft Windows Kernel NDProxy Buffer Overflow Privilege Escalation (MS10-099)
http://www.vupen.com/english/advisories/2010/3221

Microsoft Windows Win32k Kernel-Mode Drivers Privilege Escalation (MS10-098)
http://www.vupen.com/english/advisories/2010/3220

Microsoft Windows Internet Connection Signup Wizard Library Loading (MS10-097)
http://www.vupen.com/english/advisories/2010/3219

Microsoft Windows BranchCache Insecure Library Loading (MS10-095)
http://www.vupen.com/english/advisories/2010/3218

Microsoft Windows Media Encoder Insecure Library Loading (MS10-094)
http://www.vupen.com/english/advisories/2010/3217

Microsoft Movie Maker Insecure Library Loading Vulnerability (MS10-093)
http://www.vupen.com/english/advisories/2010/3216

Microsoft Windows OpenType Font (OTF) Driver Code Execution (MS10-091)
http://www.vupen.com/english/advisories/2010/3215

Microsoft Internet Explorer Code Execution and Information Disclosure (MS10-090)
http://www.vupen.com/english/advisories/2010/3214

Google Chrome Multiple Memory Corruption and Denial of Service
http://www.vupen.com/english/advisories/2010/3213

Crystal Reports "PrintControl" ActiveX Control Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/3212

IBM Security Update Fixes ENOVIA Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/3211

IBM Rational ClearQuest Code Execution and Information Disclosure
http://www.vupen.com/english/advisories/2010/3210

IBM Lotus Mobile Connect HTTP-AS Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/3209

ISC DHCP Failover Peer Port TCP Packet Handling Denial of Service
http://www.vupen.com/english/advisories/2010/3208

Adobe Photoshop CS5 Security Update Fixes Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/3207

Symantec Products Alert Handler Service Remote Denial of Service
http://www.vupen.com/english/advisories/2010/3207

Xerox WorkCentre Scan to Email Merging Information Disclosure
http://www.vupen.com/english/advisories/2010/3205

SuSE Security Update Fixes Exim Buffer Overflow and Privilege Escalation
http://www.vupen.com/english/advisories/2010/3204

Redhat Security Update Fixes OpenSSL DoS and Security Bypass
http://www.vupen.com/english/advisories/2010/3203

Redhat Security Update Fixes BIND DoS and Wrong ACL Vulnerabilities
http://www.vupen.com/english/advisories/2010/3202

Fedora Security Update Fixes Thunderbird Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/3201

Fedora Security Update Fixes FontForge Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/3200

Fedora Security Update Fixes OpenTTD Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/3199

Turbolinux Security Update Fixes CUPS File Overwrite Vulnerability
http://www.vupen.com/english/advisories/2010/3198

Turbolinux Security Update Fixes ProFTPD Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/3197

Debian Security Update Fixes collectd Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/3196

RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/45307

Microsoft Internet Explorer Uninitialized Object CVE-2010-3340 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45255

Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44011

Microsoft Internet Explorer CSS Tags Uninitialized Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44536

Oracle Java SE and Java for Business CVE-2010-3573 Same Origin Bypass Vulnerability
http://www.securityfocus.com/bid/44028

Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability
http://www.securityfocus.com/bid/44030

Oracle Java SE and Java for Business CVE-2010-3571 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43965

Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/44012

Oracle Java SE and Java for Business CVE-2010-3566 ICC Profile Vulnerability
http://www.securityfocus.com/bid/43988

Oracle Java SE and Java for Business CVE-2010-3570 Remote Deployment Toolkit Vulnerability
http://www.securityfocus.com/bid/44020

Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43992

Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/44016

Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability
http://www.securityfocus.com/bid/43985

HP-UX Threaded Processes Unspecified Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/45219

Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43979

Oracle Communications Messaging Server CVE-2010-3564 Webmail Remote Vulnerability
http://www.securityfocus.com/bid/43963

Oracle Java SE and Java for Business CVE-2010-3556 Remote 2D Vulnerability
http://www.securityfocus.com/bid/43971

Oracle Java SE and Java for Business CVE-2010-3558 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44021

Oracle Java SE and Java for Business CVE-2010-3560 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44024

Oracle Java SE and Java for Business CVE-2010-3563 BasicServiceImpl Vulnerability
http://www.securityfocus.com/bid/43999

Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/44013

Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44014

Oracle Java SE and Java for Business CVE-2010-3559 HeadspaceSoundbank.nGetName Vulnerability
http://www.securityfocus.com/bid/44026

Real Networks RealPlayer Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/45327

Microsoft Internet Explorer Uninitialized HTML Element CVE-2010-3346 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45261

Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability
http://www.securityfocus.com/bid/43994

Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability
http://www.securityfocus.com/bid/44035

Oracle Java SE and Java for Business CVE-2010-3550 Remote Java Web Start Vulnerability
http://www.securityfocus.com/bid/44040

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability
http://www.securityfocus.com/bid/44023

Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability
http://www.securityfocus.com/bid/44017

Oracle Java SE and Java for Business CVE-2010-3555 Remote ActiveX Plug-in Vulnerability
http://www.securityfocus.com/bid/44038

Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44009

Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/44027

Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability
http://www.securityfocus.com/bid/44032

Microsoft Internet Explorer Select HTML Element Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45260

Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45297

Microsoft SharePoint Malformed SOAP Request Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45264

Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43316

Microsoft Windows COM Object Validation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/40574

ISC BIND 9 'RRSIG' Record Type Negative Cache Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45133

ISC BIND Key Algorithm Rollover Security Vulnerability
http://www.securityfocus.com/bid/45137

ISC BIND 9 DNSSEC Validation Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45385

Microsoft .NET Framework JIT Compiler Optimization Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/43781

Microsoft Internet Connection Wizard DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42713

Microsoft Windows Kernel 'CreateDIBPalette()' Function Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/42291

Microsoft Windows Address Book 'wab32res.dll' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42648

Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42855

Microsoft Windows Movie Maker 'hhctrl.ocx' DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/42659

Microsoft Windows Kernel Task Scheduler Service Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44357

Perl CGI.pm Header Values Newline Handling Unspecified Security Vulnerability
http://www.securityfocus.com/bid/45145

Hitachi Multiple Products GIF File Parsing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36309

Hitachi Multiple Business Logic Products Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35793

Hitachi Multiple Products GIF File Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36311

Linux Kernel CVE-2010-4073 Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45073

Linux Kernel 'SNDRV_HDSP_IOCTL_GET_CONFIG_INFO' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45058

Linux Kernel Block Layer Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/44793

Linux Kernel 'x25_parse_facilities()' CVE-2010-4164 Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45055

Linux Kernel 'hdsp.c' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45063

Linux Kernel 'hmid_ds structure' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45054

Linux Kernel Futex Macros Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/44754

Linux Kernel 'drivers/scsi/gdth.c' IOCTL Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44648

Linux Kernel FBIOGET_VBLANK 'drivers/video/sis/sis_main.c' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43810

Linux Kernel 'net/core/filter.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44758

Linux Kernel Rose Protocol 'srose_ndigis' Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43368

Linux Kernel 'net/sched/act_police.c' File Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42529

Linux Kernel 'PKT_CTRL_CMD_STATUS' Invalid Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/43551

Linux Kernel ALSA 'sound/core/control.c' Local Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43787

Linux Kernel 'ipc/sem.c' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43809

Linux Kernel JFS xattr Namespace Rules Security Bypass Vulnerability
http://www.securityfocus.com/bid/42589

Linux Kernel CIFS 'CIFSSMBWrite()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42242

Linux Kernel XSF 'SWAPEXT' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40920

Linux Kernel 'do_io_submit()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43353

Microsoft Internet Explorer CSS Parsing Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45246

collectd 'cu_rrd_create_file()' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/45075

SAP NetWeaver Business Client ActiveX Control Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/45396

BlogCFC Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/45395

Google Urchin 'urchin.cgi' Local File Include Vulnerability
http://www.securityfocus.com/bid/45393

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45392

IBM ENOVIA 'emxFramework.FilterParameterPattern' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/45391

Google Chrome prior to 8.0.552.224 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/45390

SAP Crystal Reports Print ActiveX Control Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45387

Microsoft Windows Consent User Interface Registry Key Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45318

Microsoft Windows OpenType Font (OTF) Driver CMAP Table Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45316

Microsoft Windows OpenType Font (OTF) Driver Double-Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45315

Microsoft Windows OpenType Font (OTF) Driver Invalid Array Index Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45311

Microsoft Windows CVE-2010-3944 'Win32k.sys' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45298

Microsoft Windows BranchCache DLL Loading Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/45295

Microsoft Hyper-V VMBus Denial of Service Vulnerability
http://www.securityfocus.com/bid/45293

Microsoft Windows 'Win32k.sys' Cursor Linking Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45289

Microsoft Windows CVE-2010-3941 'Win32k.sys' Double Free Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45287

Microsoft Windows 'Win32k.sys' Double Free Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45286

Microsoft Office TIFF Image Converter (CVE-2010-3950) Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45285

Microsoft Office FlashPix Image Converter (CVE-2010-3952) Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45283

Microsoft Publisher Array Index Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45282

Microsoft Publisher (CVE-2010-3954) Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45281

Microsoft Publisher 'pubconv.dll' Array Index Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45280

Microsoft Publisher 'pubconv.dll' Heap Based Buffer Overflow Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45279

Microsoft Office FlashPix Image Converter (CVE-2010-3951) Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45278

Microsoft Publisher Size Value Heap Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45277

Microsoft Office TIFF Image Converter (CVE-2010-3949) Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45275

Microsoft Office TIFF Image Converter (CVE-2010-3947) Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45274

Microsoft Office PICT Image Converter (CVE-2010-3946) Integer Overflow Vulnerability
http://www.securityfocus.com/bid/45273

Microsoft 'Netlogon' RPC Null Pointer Dereference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45271

Microsoft Office CGM Image Converter (CVE-2010-3945) Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45270

Microsoft Windows Kernel NDProxy Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45269

Microsoft Internet Explorer CVE-2010-3348 Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45263

Microsoft Internet Explorer Uninitialized Object CVE-2010-3343 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45259

Microsoft Internet Explorer CVE-2010-3342 Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45256

0 件のコメント:

コメントを投稿