2011年3月7日月曜日

7日 月曜日、仏滅

+ Samba 3.5.8 Available for Download
http://samba.org/samba/history/samba-3.5.8.html

+ HS11-003: Cosminexusにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-003/index.html
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-003/index.html

HPSBUX02633 SSRT100387 改訂版1 - Javaを実行中のHP-UX、リモートサービス拒否(DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docLocale=ja_JP&docId=emr_na-c02737263

HPSBPI02635 SSRT100391 改訂版1 - Windowsで実行中のHP Web Jetadmin、管理リソースに対するローカルの不正アクセス
http://www11.itrc.hp.com/service/cki/docDisplay.do?docLocale=ja_JP&docId=emr_na-c02737262

PGCon 2011 - schedule released
http://www.postgresql.org/about/news.1298

Samba 3.5.8がリリースされました。バグフィックスです。
http://wiki.samba.gr.jp/mediawiki/index.php?title=%E3%83%A1%E3%82%A4%E3%83%B3%E3%83%9A%E3%83%BC%E3%82%B8

XSS in CubeCart <= 2.0.7
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00066.html

Quick Polls Local File Inclusion & Deletion Vulnerabilities (CVE-2011-1099)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00067.html

[SECURITY] [DSA 2184-1] isc-dhcp security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00071.html

[SECURITY] [DSA 2183-1] nbd security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00070.html

[ MDVSA-2011:041 ] firefox
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00069.html

[DCA-2011-0009] Weborf 0.12.4 Denial-of-Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00068.html

[DCA-2011-0006] Hiawatha 7.4 - Denial-of-Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00065.html

[SECURITY] [DSA 2182-1] logwatch security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00064.html

Mutare Software EVM - CSRF and XSS Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00063.html

Google、Android Marketで公開したマルウエアの対策を明らかに
http://itpro.nikkeibp.co.jp/article/NEWS/20110307/358018/?ST=security

JVN#97334690 IBM Lotus におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN97334690/index.html

JVN#26301278 IBM WebSphere Application Server におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN26301278/index.html

JVN#16308183 IBM DB2 におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN16308183/index.html

JVNDB-2011-001179 Adobe Flash Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001179.html

JVNDB-2011-001178 Adobe Flash Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001178.html

JVNDB-2011-001177 Adobe Flash Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001177.html

JVNDB-2011-001176 Adobe Flash Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001176.html

JVNDB-2011-001175 Adobe Flash Player における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001175.html

JVNDB-2011-001174 複数の Microsoft 製品の Kerberos 実装における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001174.html

JVNDB-2011-001173 複数の Microsoft 製品の Kerberos 実装における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001173.html

JVNDB-2011-001172 複数の Microsoft 製品の win32k.sys における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001172.html

JVNDB-2011-001171 複数の Microsoft 製品の win32k.sys における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001171.html

JVNDB-2011-001170 複数の Microsoft 製品の win32k.sys における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001170.html

JVNDB-2011-001169 複数の Microsoft 製品の win32k.sys における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001169.html

JVNDB-2011-001168 複数の Microsoft 製品の win32k.sys における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001168.html

JVNDB-2011-001167 Microsoft Windows XP の Trace Events 機能における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001167.html

JVNDB-2011-001166 複数の Microsoft 製品の Local Security Authority Subsystem Service における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001166.html

JVNDB-2011-001165 複数の Microsoft 製品の Client/Server Run-time Subsystem における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001165.html

JVNDB-2011-000019 OTRS における OS コマンドインジェクションの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000019.html

Metasploit 3.6.0 Released!
http://www.metasploit.com/redmine/projects/pro/wiki/Release_Notes_360

Asterisk UPDTL Packets Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/46474

socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42112

MoinMoin 'refuri' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/46476

Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46572

ISC DHCP Server DHCPv6 Decline Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/46035

TeXmacs 'LD_LIBRARY_PATH' Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/44360




+ Dovecot 2.0.11 released
http://www.dovecot.org/list/dovecot-news/2011-March/000186.html

+ MySQL 5.1.56 released
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-56.html

+- Zimbra Collaboration Suite 5.0.26, 6.0.10 released
http://files.zimbra.com/website/docs/archives/5.0/Zimbra%20OS%20Release%20Notes%205.0.26.pdf
http://files.zimbra.com/website/docs/Zimbra%20OS%20Release%20Notes%206.0.10.pdf

+ Linux Kernel DNS Resolver Key NULL Pointer Dereference Vulnerability
http://secunia.com/advisories/43594/
http://www.securitytracker.com/id/1025162
http://www.securityfocus.com/bid/46732

+ GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/46740

Apache httpd 2.3.11-beta Released
http://www.apache.org/dist/httpd/Announcement2.3.txt

MySQL 5.1.57 (Not yet released)
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-57.html

MySQL 5.5.11 (Not yet released)
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-11.html

MySQL 5.5.10 (Not yet released)
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-10.html

Debian : [DSA-2177-1] pywebdav: SQL injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35206

Debian : [DSA-2178-1] pango1.0: NULL pointer dereference
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35207

Debian : [DSA-2180-1] iceape: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35208

Debian : [DSA 2181-1] subversion security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35222

Hewlett-Packard : HP MFP Digital Sending Software Running on Windows, Authentication Bypass
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35209

High-Tech Bridge SA : [HTB22837] Path disclosure in PrestaShop
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35210

High-Tech Bridge SA : [HTB22853] XSS vulnerability in Pragyan CMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35211

High-Tech Bridge SA : [HTB22855] XSRF (CSRF) in Pragyan CMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35213

High-Tech Bridge SA : [HTB22856] XSS vulnerability in Pragyan CMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35214

High-Tech Bridge SA : [HTB22857] Path disclosure in Tribiq CMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35216

High-Tech Bridge SA : [HTB22863] XSS vulnerability in xtcModified
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35217

High-Tech Bridge SA : [HTB22865] XSS vulnerability in xtcModified
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35218

High-Tech Bridge SA : [HTB22866] XSS vulnerability in xtcModified
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35219

Mandriva : [MDVSA-2011:040] pango
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35205

Red Hat : [RHSA-2011:0318-01] libtiff: Important Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35204

Androidマーケットにウイルス混入アプリ、50種類以上が公開
5万件から20万件がダウンロード、現在では削除済み
http://itpro.nikkeibp.co.jp/article/NEWS/20110307/358014/?ST=security

韓国を狙った大規模DDoS攻撃、IPAが国内ユーザーへも緊急対策を呼びかけ
http://itpro.nikkeibp.co.jp/article/NEWS/20110304/358003/?ST=security

ウイルス対策ソフトの2本パック、マカフィーが限定販売
http://itpro.nikkeibp.co.jp/article/NEWS/20110304/357991/?ST=security

JVN#97334690 IBM Lotus におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN97334690/index.html

JVN#26301278 IBM WebSphere Application Server におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN26301278/index.html

JVN#16308183 IBM DB2 におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN16308183/index.html

JVNDB-2011-001164 複数の Microsoft 製品の JScript および VBScript スクリプトエンジンにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001164.html

JVNDB-2011-001163 Microsoft Visio の ELEMENTS.DLL における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001163.html

JVNDB-2011-001162 Microsoft Visio の LZW ストリーム圧縮機能における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001162.html

JVNDB-2011-001161 Windows Server 2003 上で稼働する Microsoft Active Directory におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001161.html

JVNDB-2011-001160 複数の Microsoft 製品の Windows OpenType Compact Font Format ドライバにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001160.html

JVNDB-2011-001159 Microsoft Internet Explorer 8 における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001159.html

JVNDB-2011-001158 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001158.html

JVNDB-2011-001157 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001157.html

JVNDB-2011-001156 Hitachi Tuning Manager Software におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001156.html

JVNDB-2011-001155 IntelliCom NetBiter NB100 および NB200 プラットフォームに複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001155.html

JVNDB-2011-000018 IBM Lotus におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000018.html

JVNDB-2011-000017 IBM WebSphere Application Server におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000017.html

JVNDB-2011-000016 IBM DB2 におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000016.html

JVNDB-2010-001228 OpenSSL の kssl_keytab_is_available 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001228.html

JVNDB-2010-001227 OpenSSL の ssl3_get_record 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001227.html

JVNDB-2010-001310 複数の Oracle 製品の Java Runtime Environment コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001310.html

JVNDB-2010-001311 複数の Oracle 製品の Java Runtime Environment コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001311.html

JVNDB-2010-001317 複数の Oracle 製品の HotSpot Server コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001317.html

JVNDB-2008-001502 Microsoft SQL Server の insert ステートメントに関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001502.html

JVNDB-2008-001503 Microsoft SQL Server のバックアップファイルのレコードサイズに関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001503.html

JVNDB-2008-001501 Microsoft SQL Server の SQL データ型の処理に関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001501.html

JVNDB-2008-001500 Microsoft SQL Server のメモリ再配置の際メモリページを初期化しない脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001500.html

JVNDB-2008-002253 Microsoft SQL Server の sp_replwritetovarbin 拡張ストアド プロシージャの処理における脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002253.html

[DCA-2011-0003]: LMS Web Ensino - Multiple XSS, Session Fixation, CSRF and SQL Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00062.html

[DCA-2011-0002]: TOTVS ERP Microsiga Protheus - Users Enumeration
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00061.html

[DCA-2011-0001] TP-LINK TL-WR740N Multiple Vulnerabilities - Stored XSS - We
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00060.html

[SECURITY] [DSA 2181-1] subversion security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00059.html

[SECURITY] [DSA 2180-1] iceape security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-03/msg00058.html

韓国国内で発生しているDDoS攻撃について
http://www.ipa.go.jp/security/topics/alert20110304.html

情報セキュリティ技術動向調査(2010 年下期)
http://www.ipa.go.jp/security/fy22/reports/tech1-tg/indexb.html

DroidDream android malware analysis
http://isc.sans.edu/diary.html?storyid=10495

DDOS, the new black?
http://isc.sans.edu/diary.html?storyid=10483

Oracle Document Capture Actbar2.ocx Insecure Method vulnerability
http://www.securiteam.com/windowsntfocus/5ZP2V1F3PO.html

Microsoft Office Publisher Record Array Indexing Vulnerability
http://www.securiteam.com/windowsntfocus/5CP2Y1F3PK.html

Microsoft Office Publisher Size Value Heap Corruption Vulnerability
http://www.securiteam.com/windowsntfocus/5BP2X1F3PS.html

Microsoft Office Publisher "pubconv.dll" Array Indexing Vulnerability
http://www.securiteam.com/windowsntfocus/5OP301F3PS.html

SAP Crystal Reports Print ActiveX Control Buffer Overflow
http://www.securiteam.com/windowsntfocus/5PP311F3PI.html

Oracle Document Capture empop3.dll Insecure Method Vulnerability
http://www.securiteam.com/securitynews/5AP2W1F3PW.html

RealPlayer "cook" Uninitialized Memory Vulnerability
http://www.securiteam.com/securitynews/5QP321F3PM.html

Debian update for subversion
http://secunia.com/advisories/43583/

Apache Subversion mod_dav_svn NULL Pointer Dereference Vulnerability
http://secunia.com/advisories/43603/

AltiGen AltiServ Gateway Service Memory Corruption Vulnerability
http://secunia.com/advisories/43528/

Linux Kernel DNS Resolver Key NULL Pointer Dereference Vulnerability
http://secunia.com/advisories/43594/

Fedora update for moodle
http://secunia.com/advisories/43604/

Red Hat update for libcgroup
http://secunia.com/advisories/43611/

Gri Insecure Temporary Files Security Issue
http://secunia.com/advisories/43575/

Q libtool Search Path Privilege Escalation Security Issue
http://secunia.com/advisories/43581/

Ubuntu update for firefox and xulrunner
http://secunia.com/advisories/43597/

Debian update for iceape
http://secunia.com/advisories/43530/

RhinOS "gradient.php" File Disclosure Vulnerability
http://secunia.com/advisories/43614/

Ubuntu update for pango1.0
http://secunia.com/advisories/43592/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/43616/

Novell Vibe OnPrem Unspecified Flaw Lets Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id/1025163

Linux Kernel dns_resolver Key Processing Error Lets Local Users Deny Service
http://www.securitytracker.com/id/1025162

Subversion mod_dav_svn Null Pointer Dereference Lets Remote Users Deny Service
http://www.securitytracker.com/id/1025161

libcgroup Controller List Heap Overflow Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id/1025158

libcgroup Lets Local Users Spoof NETLINK Messages
http://www.securitytracker.com/id/1025157

IBM Tivoli Netcool OMNIbus Input Validation Flaw in Web GUI Lets Remote Users Inject SQL Commands
http://www.securitytracker.com/id/1025156

REMOTE: Allied Telesyn TFTP Server 1.9 Long Filename Overflow
http://www.exploit-db.com/exploits/16350/

Ubuntu Security Update Fixes Thunderbird Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0580

Ubuntu Security Update Fixes Firefox and Xulrunner Vulnerabilities
http://www.vupen.com/english/advisories/2011/0579

Fedora Security Update Fixes Firefox and Xulrunner Vulnerabilities
http://www.vupen.com/english/advisories/2011/0578

Fedora Security Update Fixes Moodle Multiple Information Disclosure
http://www.vupen.com/english/advisories/2011/0577

Fedora Security Update Fixes Request Tracker Insecure Pass Hashing
http://www.vupen.com/english/advisories/2011/0576

Fedora Security Update Fixes Gitolite Directory Traversal Vulnerability
http://www.vupen.com/english/advisories/2011/0575

Fedora Security Update Fixes Q Libtool Untrusted Path Vulnerability
http://www.vupen.com/english/advisories/2011/0574

Fedora Security Update Fixes CouchDB Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2011/0573

Fedora Security Update Fixes Telepathy-gabble Update Validation Issue
http://www.vupen.com/english/advisories/2011/0572

Fedora Security Update Fixes Moin Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2011/0571

Fedora Security Update Fixes phpMyAdmin Bookmarks Vulnerability
http://www.vupen.com/english/advisories/2011/0570

Redhat Security Update Fixes Libcgroup Privilege Escalation and DoS
http://www.vupen.com/english/advisories/2011/0569

Debian Security Update Fixes Subversion Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2011/0568

Apache Subversion HTTP Server "mod_dav_svn" Denial of Service
http://www.vupen.com/english/advisories/2011/0567

Debian Security Update Fixes Iceape Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0566

Mandriva Security Update Fixes Avahi Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2011/0565

Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46734

WebKit CVE-2011-0135 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46709

WebKit CVE-2011-0155 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46721

WebKit CVE-2011-0150 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46717

WebKit CVE-2011-0152 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46718

WebKit CVE-2011-0147 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46702

WebKit CVE-2011-0148 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46708

WebKit CVE-2011-0143 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46695

WebKit CVE-2011-0144 Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46699

GNU Libtool 'libltdl' Library Search Path Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37128

Citrix Access Gateway User Credentials Command Injection Vulnerability
http://www.securityfocus.com/bid/45402

libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46658

libTIFF TIFF Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46657

JBoss Enterprise Application Platform Multiple Vulnerabilities
http://www.securityfocus.com/bid/39710

Oracle Passlogix v-GO Self-Service Password Reset Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/46452

Moodle Prior to 1.9.11/2.0.2 Multiple Vulnerabilities
http://www.securityfocus.com/bid/46646

libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
http://www.securityfocus.com/bid/46578

PHP Speedy Plugin for WordPress 'admin_container.php' Remote PHP Code Execution Vulnerability
http://www.securityfocus.com/bid/46743

Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/46741

GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/46740

TOTVS ERP Microsiga Protheus Username Enumeration Weakness
http://www.securityfocus.com/bid/46739

TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/46738

Limelight Software 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/46735

Linux Kernel 'dns_key.c' NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/46732

RhinOS 'gradient.php' Multiple Directory Traversal Vulnerabilities
http://www.securityfocus.com/bid/46731

0 件のコメント:

コメントを投稿