2011年3月4日金曜日

4日 金曜日、赤口

+ RHSA-2011:0318-1: Important: libtiff security update
http://rhn.redhat.com/errata/RHSA-2011-0318.html

+ bsd ftpd (libc/glob) resource exhaustion
http://securityreason.com/securityalert/8116

+ Linux Kernel Buffer Overflow ldm_frag_add() Elevated Privileges
http://securityreason.com/securityalert/8115

+? PHP Exif Extension 'exif_read_data()' Function Remote DoS
http://securityreason.com/securityalert/8114

+ Linux Kernel RDS Congestion Map Update Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/46676

RHSA-2011:0320 Important: libcgroup security update
http://rhn.redhat.com/errata/RHSA-2011-0320.html

CESA-2011:0318 (libtiff)
http://lwn.net/Alerts/431026/

CESA-2011:0307 (mailman)
http://lwn.net/Alerts/431027/

CESA-2011:0305 (samba)
http://lwn.net/Alerts/431028/

CESA-2011:0313 (seamonkey)
http://lwn.net/Alerts/431029/

CESA-2011:0312 (thunderbird)
http://lwn.net/Alerts/431030/

CESA-2011:0310 (firefox)
http://lwn.net/Alerts/431031/

Microsoft Security Bulletin Advance Notification for March 2011
http://www.microsoft.com/technet/security/bulletin/ms11-mar.mspx

D99Y Team : PhotoPost PHP 4.8c (showgallery.php) Cross Site Scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35189

D99Y Team : CubeCart 2.0.6 SQL injection / Cross Site Scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35190

Independent Researcher : VidiScript (index.php) Cross Site Scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35188

Red Hat : [RHSA-2011:0305-01] samba: Important Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35179

Red Hat : [RHSA-2011:0306-01] samba3x: Important Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35180

Red Hat : [RHSA-2011:0307-01] mailman: Moderate Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35181

Red Hat : [RHSA-2011:0308-01] mailman: Moderate Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35182

Red Hat : [RHSA-2011:0309-01] pango: Critical Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35183

Red Hat : [RHSA-2011:0310-01] firefox: Critical Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35184

Red Hat : [RHSA-2011:0311-01] thunderbird: Critical Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35185

Red Hat : [RHSA-2011:0312-01] thunderbird: Moderate Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35186

Red Hat : [RHSA-2011:0313-01] seamonkey: Critical Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35187

Slackware Linux : [SSA:2011-060-01] mozilla-firefox: Security Update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35178

Ubuntu Security Notice : [USN-1082-1] Pango vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35177

シマンテックからアンドロイド携帯向けセキュリティソフト
http://itpro.nikkeibp.co.jp/article/NEWS/20110303/357943/?ST=security

JVNDB-2011-001154 Sielco Sistemi Winlog にバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001154.html

JVNDB-2011-001153 MOXA Device Manager MDM Tool にバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001153.html

JVNDB-2011-001152 SCADA Engine BACnet OPC Client におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001152.html

JVNDB-2011-001151 Majordomo 2 におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001151.html

JVNDB-2011-001150 Automated Solutions Modbus/TCP Master OPC Server におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001150.html

JVNDB-2011-001149 Cisco Tandberg E, EX および C Series における root アカウントのデフォルト認証情報の問題
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001149.html

JVNDB-2011-001148 Apache Tomcat におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001148.html

JVNDB-2010-002768 Apache Tomcat におけるワーキングディレクトリ外のファイルを読み書きされる脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002768.html

JVNDB-2010-002767 Apache Tomcat の HTML Manager Interface におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002767.html

Poor man's DLP solution
http://isc.sans.edu/diary.html?storyid=10147

Rogue apps inside Android Marketplace
http://isc.sans.edu/diary.html?storyid=10480

Oracle Document Capture ActiveX Insecure method and Buffer Overflow Vulnerabilities
http://www.securiteam.com/windowsntfocus/5NP2V0U3PI.html

Oracle Document Capture ImportBodyText File reading Vulnerability
http://www.securiteam.com/windowsntfocus/5OP2W0U3PE.html

Microsoft Internet Explorer Animation Use-after-free Vulnerability
http://www.securiteam.com/windowsntfocus/5EP320U3PO.html

RealPlayer RA5 Data Handling Heap Overflow Vulnerability
http://www.securiteam.com/securitynews/5CP300U3PS.html

Microsoft Office Publisher Memory Corruption Vulnerability
http://www.securiteam.com/securitynews/5DP310U3PC.html

RealPlayer AAC Data Handling Buffer Overflow Vulnerability
http://www.securiteam.com/securitynews/5PP2X0U3PA.html

RealPlayer RealMedia Data Handling Heap Overflow Vulnerabilities
http://www.securiteam.com/securitynews/5QP2Y0U3PS.html

HP MFP Digital Sending Software Managed Devices Security Bypass
http://secunia.com/advisories/43618/

HP-UX update for OpenSSL
http://secunia.com/advisories/43600/

xtcModified eCommerce Shopsoftware Multiple Vulnerabilities
http://secunia.com/advisories/43584/

Support Incident Tracker Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/43612/

Debian update for dtc
http://secunia.com/advisories/43523/

phpWebSite "local" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/43615/

Drupal Spaces Module Security Bypass Security Issue
http://secunia.com/advisories/43608/

Apple iTunes Multiple Vulnerabilities
http://secunia.com/advisories/43582/

Debian update for pywebdav
http://secunia.com/advisories/43571/

Domain Technologie Control Multiple Vulnerabilities
http://secunia.com/advisories/43609/

Red Hat update for libtiff
http://secunia.com/advisories/43585/

Novell Vibe OnPrem Unspecified Vulnerability
http://secunia.com/advisories/43606/

SUSE update for tomcat5
http://secunia.com/advisories/42848/

Ubuntu update for linux-lts-backport-maverick
http://secunia.com/advisories/43454/

Ubuntu update for thunderbird
http://secunia.com/advisories/43607/

EnterpriseDB Postgres Plus Advanced Server DBA Management Server Vulnerability
http://secunia.com/advisories/43590/

PolarSSL Diffie-Hellman Key Exchange Vulnerability
http://secunia.com/advisories/43595/

syslog-ng Premium Edition Multiple Vulnerabilities
http://secunia.com/advisories/43620/

syslog-ng Premium Edition Multiple Vulnerabilities
http://secunia.com/advisories/43587/

Drupal Secure Pages Module Redirection Weakness
http://secunia.com/advisories/43591/

IBM WebSphere Application Server Community Edition Java Double Literal Denial of Service
http://secunia.com/advisories/43619/

PyWebDAV MySQL Authentication SQL Injection Vulnerability
http://secunia.com/advisories/43602/

SUSE update for avahi
http://secunia.com/advisories/43605/

Debian update for pango1.0
http://secunia.com/advisories/43559/

LibTIFF "EXPAND2D()" Buffer Overflow Vulnerability
http://secunia.com/advisories/43593/

bsd ftpd (libc/glob) resource exhaustion
http://securityreason.com/securityalert/8116

Linux Kernel Buffer Overflow ldm_frag_add() Elevated Privileges
http://securityreason.com/securityalert/8115

PHP Exif Extension 'exif_read_data()' Function Remote DoS
http://securityreason.com/securityalert/8114

[security bulletin] HPSBPI02640 SSRT100410 rev.1 - HP MFP Digital Sending Software Running on Wi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00057.html

[security bulletin] HPSBUX02638 SSRT100339 rev.1 - HP-UX Running OpenSSL, Remote Execution o
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00036.html

[ MDVSA-2011:040 ] pango
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00056.html

HTB22837: Path disclosure in PrestaShop
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00055.html

HTB22865: XSS vulnerability in xtcModified
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00054.html

HTB22853: XSS vulnerability in Pragyan CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00053.html

HTB22856: XSS vulnerability in Pragyan CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00052.html

HTB22855: XSRF (CSRF) in Pragyan CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00051.html

HTB22866: XSS vulnerability in xtcModified
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00050.html

HTB22857: Path disclosure in Tribiq CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00049.html

HTB22863: XSS vulnerability in xtcModified
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00048.html

[USN-1050-1] Thunderbird vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00046.html

[USN-1083-1] Linux kernel vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00033.html

iDefense Security Advisory 03.02.11: Apple CoreGraphics Library Heap Memory Corruption Vulnerabilit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00045.html

[USN-1080-2] Linux kernel vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00042.html

ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerabil
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00031.html

ZDI-11-102: PostgreSQL Plus Advanced Server DBA Management Server Remote Authentication Bypa
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00032.html

ZDI-11-101: Apple iPhone Webkit Library Javascript Array sort Method Remote Code Execution V
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00044.html

ZDI-11-100: Apple Webkit Root HTMLBRElement Style Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00043.html

ZDI-11-099: Apple Webkit Font Glyph Layout Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00041.html

ZDI-11-098: Apple Safari Webkit Runin Box Promotion Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00040.html

ZDI-11-097: Apple Webkit setOuterText Memory Corruption Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00039.html

ZDI-11-096: Apple Safari WebKit Range Object Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00038.html

ZDI-11-095: Apple Webkit Error Message Mutation Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00037.html

iDefense Security Advisory 03.01.11: Alcatel-Lucent OmniPCX Enterprise CS CGI Cookie Buffer Over
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00035.html

[SECURITY] [DSA 2179-1] dtc security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00034.html

[SECURITY] [DSA 2178-1] pango1.0 security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00029.html

[SECURITY] [DSA 2177-1] pywebdav security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00030.html

HP MFP Digital Sending Software Lets Local Users Disable Authentication
http://www.securitytracker.com/id/1025155

IBM WebSphere Application Server Data Disclosure and Security Bypass
http://www.vupen.com/english/advisories/2011/0564

Apache Tomcat ServletSecurity Annotation Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2011/0563

EnterpriseDB Postgres Plus Advanced Server Authentication Bypass
http://www.vupen.com/english/advisories/2011/0562

HP MFP Digital Sending Software Local Authentication Bypass Vulnerability
http://www.vupen.com/english/advisories/2011/0561

HP-UX OpenSSL Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2011/0560

Apple iTunes Code Execution and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2011/0559

Ubuntu Security Update Fixes Multiple Pango Vulnerabilities
http://www.vupen.com/english/advisories/2011/0558

Ubuntu Security Update Fixes Kernel Privilege Escalation and DoS
http://www.vupen.com/english/advisories/2011/0557

Debian Security Update Fixes DTC Multiple SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2011/0556

Debian Security Update Fixes Pango Reallocation Failure Vulnerability
http://www.vupen.com/english/advisories/2011/0555

Debian Security Update Fixes PyWebDAV SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2011/0554

PyWebDAV Data Processing Multiple SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2011/0553

Mandriva Security Update Fixess WebKit Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0552

Redhat Security Update Fixess LibTIFF Fax4Decode Buffer Overflow
http://www.vupen.com/english/advisories/2011/0551

REMOTE: TIOD v1.3.3 for iPhone / iPod touch Directory Traversal
http://www.exploit-db.com/exploits/16271/

Mozilla Firefox/SeaMonkey Cross-Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/46652

Mozilla Firefox/SeaMonkey 'eval()' Function Security Bypass Vulnerability
http://www.securityfocus.com/bid/46643

Mozilla Firefox and SeaMonkey JavaScript Worker Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46663

Mozilla Firefox and SeaMonkey 'JSON.stringify()' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46661

Mozilla Firefox and SeaMonkey JavaScript String Values Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46650

Mozilla Firefox and SeaMonkey JavaScript Non-Local Variables Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46648

Mozilla Firefox SeaMonkey and Thunderbird CVE-2011-0053 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/46645

libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46658

libTIFF TIFF Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46657

RETIRED: PhotoPost PHP 'showgallery.php' Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46649

All Enthusiast PhotoPost PHP Pro Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/12157

Google Chrome prior to 9.0.597.107 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/46614

Mozilla Firefox/SeaMonkey Text Run Construction Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46660

Mozilla Firefox and Thunderbird JPEG Image Decoding Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46651

Mozilla Firefox CVE-2011-0062 Multiple Unspecified Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/46647

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2011-01 through -10 Multiple Vulnerabilities
http://www.securityfocus.com/bid/46368

OpenSSL TLS Server Extension Parsing Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44884

OpenSSL Ciphersuite Downgrade Security Weakness
http://www.securityfocus.com/bid/45164

OpenSSL J-PAKE Security Bypass Vulnerability
http://www.securityfocus.com/bid/45163

Pango 'hb_buffer_ensure()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46632

Avahi 'avahi-core/socket.c' NULL UDP Packet Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46446

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34100

Oracle Java SE and Java for Business CVE-2010-3555 Remote ActiveX Plug-in Vulnerability
http://www.securityfocus.com/bid/44038

OpenSSL Ciphersuite Modification Allows Disabled Cipher Security Bypass Vulnerability
http://www.securityfocus.com/bid/45254

Oracle Java Floating-Point Value Denial of Service Vulnerability
http://www.securityfocus.com/bid/46091

Samba 'FD_SET' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46597

Linux Kernel 'setup_arg_pages()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/44301

Linux Kernel Unix Sockets Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/45037

Linux Kernel 'hmid_ds structure' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45054

Linux Kernel 'perf_event_mmap()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/44861

Linux Kernel TCP_MAXSEG Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/44830

Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44219

Linux Kernel ETHTOOL_GRXCLSRLALL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44427

Linux Kernel 'net/sched/act_police.c' File Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42529

Linux Kernel Econet Protocol Multiple Local Vulnerabilities
http://www.securityfocus.com/bid/45072

Linux Kernel 'PKT_CTRL_CMD_STATUS' Invalid Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/43551

Linux Kernel ALSA 'sound/core/control.c' Local Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43787

Linux Kernel SCTP HMAC Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43701

Linux Kernel Ptrace (CVE-2010-3301) Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43355

Linux Kernel ''TIOCGICOUNT'' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43226

Linux Kernel 'CHELSIO_GET_QSET_NUM' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43221

Linux Kernel 'sctp_outq_flush()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/43480

Linux Kernel Rose Protocol 'srose_ndigis' Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/43368

Linux Kernel 'EQL_GETMASTRCFG' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43229

Linux Kernel 'drivers/net/niu.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/43098

Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44242

Linux Kernel 'set_ftrace_filter' File Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/43684

Linux Kernel 'do_io_submit()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43353

Linux Kernel 915 GEM IOCTL Local Memory Overwrite Vulnerability
http://www.securityfocus.com/bid/44067

Linux Kernel 'irda_bind()' Null Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/42900

Linux Kernel JFS xattr Namespace Rules Security Bypass Vulnerability
http://www.securityfocus.com/bid/42589

Linux Kernel GFS2 Directory Rename NULL Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/42124

XFS Deleted Inode Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42527

Linux Kernel 'XFS_IOC_FSGETXATTR' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/43022

Linux Kernel 'snd_seq_oss_open()' Multiple Local Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/43062

Linux Kernel EXT4 Multiple Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/42477

Linux Kernel 'keyctl_session_to_parent()' Null Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/42932

Linux Kernel 'SIOCGIWSSID' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42885

Linux Kernel KVM Intel VT-x Extension NULL Pointer Denial of Service Vulnerability
http://www.securityfocus.com/bid/42582

Linux Kernel Btrfs Integer Overflow Information Disclosure Vulnerability
http://www.securityfocus.com/bid/41854

Linux Kernel CIFS 'CIFSSMBWrite()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42242

Linux Kernel Btrfs Overwrite Append-Only Files Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/41847

Linux Kernel XDR Implementation Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42249

Linux Kernel CIFS DNS Lookup Cache Poisoning Vulnerability
http://www.securityfocus.com/bid/41904

Linux Kernel ethtool 'info.rule_cnt' Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41223

Linux Kernel CVE-2010-2066 Donor File Security Bypass Vulnerability
http://www.securityfocus.com/bid/41466

Linux Kernel 'pppol2tp_xmit' Null Pointer Deference Denial of Service Vulnerability
http://www.securityfocus.com/bid/41077

Linux Kernel XSF 'SWAPEXT' IOCTL Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/40920

NetSupport Manager Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45728

Pragyan CMS Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46683

xtcModified Multiple HTML Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46681

HP MFP Digital Sending Software Unspecified Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/46679

Linux Kernel RDS Congestion Map Update Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/46676

Microsoft March 2011 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/46675

phpWebSite 'local' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/46673

Novell Vibe OnPrem CVE-2011-0464 Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/46672

Support Incident Tracker (SiT!) Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46671

PolarSSL Diffie Hellman Key Exchange Security Bypass Vulnerability
http://www.securityfocus.com/bid/46670

TIOD for Apple iPhone/iPod touch Directory Traversal Vulnerability
http://www.securityfocus.com/bid/46666

Gri Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/46664

0 件のコメント:

コメントを投稿