2011年10月25日火曜日

25日 火曜日、先勝


+ Linux kernel 3.0.8 released
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.8

CESA-2011:1401 (xen)
http://lwn.net/Alerts/464281/

ウイルスバスター 月額版 サーバメンテナンスのお知らせ(2011年11月1日)
http://www.trendmicro.co.jp/support/news.asp?id=1670

JVNVU#659251 MIT Kerberos 5 KDC に複数の脆弱性
http://jvn.jp/cert/JVNVU659251/index.html

JVN#80971236 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN80971236/index.html

JVN#89764731 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN89764731/index.html

JVN#36684331 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN36684331/index.html

JVNDB-2011-002485 HP Data Protector における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002485.html

JVNDB-2011-000082 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000082.html

JVNDB-2011-000081 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000081.html

JVNDB-2011-000080 WEB FORUM におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000080.html

JVNDB-2011-002484 Apple Mac OS X の QuickTime Player におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002484.html

JVNDB-2011-002483 Apple Mac OS X の MediaKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002483.html

JVNDB-2011-002482 Apple Mac OS X の kernel におけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002482.html

JVNDB-2011-002481 Apple Mac OS X の kernel におけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002481.html

JVNDB-2011-002480 Apple Mac OS X の IOGraphics におけるパスワード要求を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002480.html

JVNDB-2011-002479 Apple Mac OS X の File Systems コンポーネントにおける WebDAV セッションをハイジャックされる脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002479.html

JVNDB-2011-002478 Apple Mac OS X の CoreStorage における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002478.html

JVNDB-2011-002477 Apple Mac OS X の CoreProcesses コンポーネントにおけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002477.html

JVNDB-2011-002476 Apple Mac OS X の CFNetwork におけるユーザを追跡可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002476.html

JVNDB-2011-002475 Apple Mac OS X の Apple Type Services (ATS) におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002475.html

JVNDB-2011-002474 pple Mac OS X の Apple Type Services (ATS) における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002474.html

JVNDB-2011-002473 Apple Mac OS X の CoreMedia における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002473.html

JVNDB-2011-002472 D-Link DCS-2121 カメラの /etc/rc.d/rc.local におけるシェルアクセスを取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002472.html

JVNDB-2011-002471 D-Link DCS-2121 カメラの recorder_test.cgi における任意のコマンドを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002471.html

JVNDB-2011-002470 Apple iOS の設定コンポーネントにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002470.html

JVNDB-2011-002469 Apple iOS の設定コンポーネントにおける詳細不明な影響を受ける脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002469.html

JVNDB-2011-002468 Apple iOS のホームスクリーンコンポーネントにおける重要な状態情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002468.html

JVNDB-2011-002467 Apple iOS の UIKit アラートコンポーネントにおけるサービス運用妨害 (デバイスハング) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002467.html

JVNDB-2011-002466 Apple iOS の WiFi コンポーネントにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002466.html

JVNDB-2011-002465 Apple iOS および Apple TV の Data Security コンポーネントにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002465.html

JVNDB-2011-002464 Apple iOS および Safari で使用される WebKit におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002464.html

JVNDB-2011-002463 Apple iOS のキーボードコンポーネントにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002463.html

JVNDB-2011-002462 Apple iOS の CalDAV における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002462.html

JVNDB-2011-002461 Apple iOS のカレンダーにおけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002461.html

JVNDB-2011-002460 Apple iOS の CFNetwork における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002460.html

JVNDB-2011-002459 Apple iOS の CoreGraphics の FreeType における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002459.html

JVNDB-2011-002458 Apple iOS の Data Access コンポーネントにおけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002458.html

JVNDB-2011-002457 Apple iOS の OfficeImport におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002457.html

JVNDB-2011-002456 Apple iOS の OfficeImport におけるメモリ二重解放の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002456.html

JVNDB-2011-002455 OneOrZero AIMS に複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002455.html

JVNDB-2011-002454 複数の Apple 製品で使用される WebKit におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002454.html

JVNDB-2011-002453 複数の Apple 製品で使用される WebKit におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002453.html

JVNDB-2011-002452 Apple iTunes で使用される CoreFoundation におけるサービス運用妨害 (DoS) の脆弱性 7.6 2011/10/12 2011/10/24
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002452.html

SA46583 Linux-PAM "pam_env" Module Two Vulnerabilities
http://secunia.com/advisories/46583/





+ Postfix stable release 2.8.6, 2.7.7, 2.6.13, 2.5.16
http://www.postfix.org/announcements/postfix-2.8.6.html
http://mirror.postfix.jp/postfix-release/official/postfix-2.8.6.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.7.7.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.6.13.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.5.16.HISTORY

+ Linux kernel 3.1 released
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1

- Moderate: xen security and bug fix update
http://rhn.redhat.com/errata/RHSA-2011-1401.html

- libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability
http://www.securityfocus.com/bid/48474

- Linux-PAM 'pam_env' Module Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/50343

[ANNOUNCEMENT] Apache Commons-DbUtils 1.4 released!
http://commons.apache.org/dbutils/download_dbutils.cgi

[ANNOUNCE] Benetl, a free ETL tool for postgreSQL, out in version 3.8
http://www.benetl.net/

UPDATE: HPSBUX02700 SSRT100506 rev.2 - HP-UX running VEA, Remote Denial of Service (DoS), Execution of Arbitrary Code
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c02962262%25257CdocLocale%25253Dja_JP&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

Gentoo Linux : [GLSA 201110-20] Clam AntiVirus - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36941

Mandriva : [MDVSA-2011:159] krb5 - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36942

Mandriva : [MDVSA-2011:160] krb5 - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36943

Gentoo Linux : [GLSA 201110-17] Avahi - Denial-Of-Service Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36938

Gentoo Linux : [GLSA 201110-18] rgmanager - Privilege Escalation Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36939

Gentoo Linux : [GLSA 201110-19] X.Org - X Server - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36940

Mandriva : [MDVSA-2011:157] freetype2 - Code Execution and Denial-Of-Service Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36945

Mandriva : [MDVSA-2011:158] phpmyadmin - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36946

Red Hat : [RHSA-2011:1386-01] Kernel - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36959

Red Hat : [RHSA-2011:1391-01] httpd - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36960

Red Hat : [RHSA-2011:1392-01] httpd - Security Bypass Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36961

Stefan Schurtz : [SSCHADV2011-033] Metasploit - Cross-site Scripting Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36950

Ubuntu Security Notice : [USN-1236-1] Linux Kernel - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36931

Ubuntu Security Notice : [USN-1235-1] Open-iSCSI - File Overwrite Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36932

Ubuntu Security Notice : [Ubuntu: 1232-3] X.Org - X server - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36933

Gentoo Linux : [GLSA 201110-14] D-Bus - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36935

Gentoo Linux : [GLSA 201110-15] GnuPG - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36936

Gentoo Linux : [GLSA 201110-16] Cyrus IMAP Server - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36937

Hewlett-Packard : [HPSBMU02716 SSRT100651] HP Data Protector Notebook Extension - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36947

Hewlett-Packard : [HPSBPI02711 SSRT100647] HP - MFP Digital Sending Software - Information Disclosure Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36948

HTB Team : [HTB23050] Tine - Cross-site Scripting Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36952

Independant Researcher : Oracle Database - Buffer Overflow Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36954

Independant Researcher : Oracle Database Server - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36955

Independant Researcher : Oracle Database Server - SQL Injection Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36956

Red Hat : [RHSA-2011:1385-01] kdelibs and kdelibs3 - Spoofing Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36958

Stefan Schurtz : [SSCHADV2011-031] Yet Another CMS - SQL Injection and Cross-site Scripting Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36957

Ubuntu Security Notice : [USN-1192-3] Firefox - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36934

Debian : [DSA 2324-1] Wireshark - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=36944

[SECURITY] [DSA 2326-1] pam security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00145.html

TC-SA-2011-01: Multiple vulnerabilities in OmniTouch Instant Communication Suite
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00149.html

[SECURITY] [DSA 2325-1] kfreebsd-8 security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00144.html

[ GLSA 201110-20 ] Clam AntiVirus: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00143.html

phpLDAPadmin <= 1.2.1.1 (query_engine) Remote PHP Code Injection Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00148.html

jara 1.6 sql injection vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00147.html

[ MDVSA-2011:160 ] krb5
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00142.html

[ MDVSA-2011:159 ] krb5
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00141.html

[ GLSA 201110-18 ] rgmanager: Privilege escalation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00140.html

[ GLSA 201110-17 ] Avahi: Denial of Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00139.html

[CVE-2011-2569] Cisco Nexus OS (NX-OS) - Command "injection" / sanitization issues.
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00146.html

[ GLSA 201110-16 ] Cyrus IMAP Server: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00138.html

[ GLSA 201110-15 ] GnuPG: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00137.html

[ GLSA 201110-14 ] D-Bus: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00136.html

またもやYouTubeで乗っ取り、今度はマイクロソフトが被害
動画を全て消去、コメント欄には「アダルト動画まだ?」
http://itpro.nikkeibp.co.jp/article/NEWS/20111025/371321/?ST=security

Critical Control 16: Secure Network Engineering
http://isc.sans.edu/diary.html?storyid=11878

Vulnerability Note VU#659251 Multiple MIT KRB5 KDC daemon vulnerabilities
http://www.kb.cert.org/vuls/id/659251

FreeType Type 1 Font Processing Flaw Lets Remote Users Deny Service
http://www.securitytracker.com/id/1026237

FreeType Multiple Vulnerabilities
http://secunia.com/advisories/46575/

phpLDAPadmin Cross-Site Scripting and Code Injection Vulnerabilities
http://secunia.com/advisories/46551/

Gentoo update for dbus
http://secunia.com/advisories/46547/

Gentoo update for gnupg
http://secunia.com/advisories/46541/

Gentoo update for avahi
http://secunia.com/advisories/46503/

Gentoo update for rgmanager
http://secunia.com/advisories/46498/

SUSE update for krb5
http://secunia.com/advisories/46546/

Gentoo update for cyrus-imapd
http://secunia.com/advisories/46530/

Oracle AutoVue ActiveX Control Insecure Method Vulnerabilities
http://secunia.com/advisories/46473/

Cyclope Internet Filtering Proxy Request Processing Denial of Service Vulnerability
http://secunia.com/advisories/46556/

Toshiba E-Studio Multifunction Printers Management Interface Security Bypass Vulnerability
http://secunia.com/advisories/46408/

Linux Kernel ext4 Extent Splitting Denial of Service Vulnerability
http://secunia.com/advisories/46489/

TYPO3 PMK SlimBox Extension Cross-Site Scripting and File Disclosure Vulnerabilities
http://secunia.com/advisories/46437/

TYPO3 PMK Shadowbox Extension Cross-Site Scripting and File Disclosure Vulnerabilities
http://secunia.com/advisories/46499/

Debian update for kfreebsd-8
http://secunia.com/advisories/46564/

Jara "id" SQL Injection Vulnerability
http://secunia.com/advisories/46493/

OpenEMR Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/46560/

WordPress Chennai Theme "s" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/46561/

Joomla! Freestyle FAQs and Testimonials Components Unspecified SQL Injection Vulnerability
http://secunia.com/advisories/46573/

Gentoo update for xorg-server
http://secunia.com/advisories/46496/

LOCAL: Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
http://www.exploit-db.com/exploits/18027

DoS/PoC: BlueZone Malformed .zft file Local Denial of Service
http://www.exploit-db.com/exploits/18029

DoS/PoC: zFTP Server "cwd/stat" Remote Denial-of-Service
http://www.exploit-db.com/exploits/18028

McAfee Web Gateway Web Acces Cross Site Scripting Vulnerability
http://www.vupen.com/english/ADV-2011-2220.php

Alcatel-Lucent Instant Communication Suite Cross Site Scripting Issues
http://www.vupen.com/english/ADV-2011-2219.php

Oracle AutoVue AutoVueX ActiveX Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/ADV-2011-2218.php

FreeType Type 1 Fonts Processing Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/ADV-2011-2217.php

PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/49241

JBoss Enterprise Application Platform Multiple Vulnerabilities
http://www.securityfocus.com/bid/39710

FreeType 'src/psaux/t1decode.c' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/48619

libpng PNG File Denial Of Service Vulnerability
http://www.securityfocus.com/bid/48618

libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability
http://www.securityfocus.com/bid/48474

libpng Buffer Overflow and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/48660

Linux Kernel epoll Subsystem 'eventpoll.c' Multiple Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/46630

LibTIFF Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/47338

Asterisk Manager Interface Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/46897

Asterisk SIP Authentication Request User Enumeration Weakness
http://www.securityfocus.com/bid/48485

Asterisk Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/48431

Asterisk Uninitalized Variable SIP Channel Driver Denial of Service Vulnerability
http://www.securityfocus.com/bid/50177

Asterisk UPDTL Packets Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/46474

Asterisk Manager Interface Arbitrary Command Execution Security Bypass Vulnerability
http://www.securityfocus.com/bid/47537

Asterisk TCP/TLS Server NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46898

QEMU 'scsi_disk_emulate_command()' Function Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/49545

Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/50199

ClamAV Prior to 0.96.5 Multiple Vulnerabilities
http://www.securityfocus.com/bid/45152

Symantec Veritas Enterprise Administrator Service Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/49014

Symantec Backup Exec for Windows Servers Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/47824

ClamAV Hash Manager Off-By-One Denial of Service Vulnerability
http://www.securityfocus.com/bid/48891

bzip2 'BZ2_decompress' Function Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43331

ClamAV 'vba_read_project_strings()' Double Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46470

ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability
http://www.securityfocus.com/bid/43555

Linux-HA OCF Resource Agents 'LD_LIBRARY_PATH' Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/44359

Avahi 'avahi-core/socket.c' Zero Size Packet Denial Of Service Vulnerability
http://www.securityfocus.com/bid/41075

Avahi 'avahi-core/socket.c' NULL UDP Packet Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46446

FreeType Font Document Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/50155

Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36296

Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/49659

Opera Web Browser SVG Layout Memory Corruption Vulnerability
http://www.securityfocus.com/bid/50044

MIT Kerberos Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/50273

MIT Kerberos krb5-appl FTP Daemon EGID Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/48571

GnuPG 'GPGSM Tool' Certificate Importing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/41945

Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/49030

Wireshark Lua Script File Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/49528

D-Bus Nested Variants Denial of Service Vulnerability
http://www.securityfocus.com/bid/45377

D-Bus Configuration Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/48460

D-Bus Message Byte Order Denial of Service Vulnerability
http://www.securityfocus.com/bid/48216

Multiple Cytel Products Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/49924

FreeBSD UNIX Domain Socket Local Privilege Escalation Vulnerabiity
http://www.securityfocus.com/bid/49862

Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-1985) Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/49968

SAP Management Console OSExecute Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/50348

Cisco Nexus OS 'section' and 'less' Local Command Injection Vulnerabilities
http://www.securityfocus.com/bid/50347

Alcatel-Lucent OmniTouch 8400 Instant Communications Suite Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/50346

zFTP Server 'cwd/stat' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/50345

InverseFlow Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/50344

Linux-PAM 'pam_env' Module Multiple Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/50343

McAfee Web Gateway Web Access Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/50341

e107 'cmd' Parameter Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/50339

Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/50338

OpenEMR Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/50336

WordPress ThemeCity 's' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/50334

Oracle AutoVue 'AutoVueX.ocx' ActiveX Control 'Export3DBom()' Insecure Method Vulnerability
http://www.securityfocus.com/bid/50333

Oracle AutoVue 'AutoVueX.ocx' ActiveX Control 'ExportEdaBom()' Insecure Method Vulnerability
http://www.securityfocus.com/bid/50332

phpLDAPadmin 0.9.4b 'common.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/50328

0 件のコメント:

コメントを投稿