2014年3月20日木曜日

20日 木曜日、先負

+ RHSA-2014:0316 Important: thunderbird security update
http://rhn.redhat.com/errata/RHSA-2014-0316.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1493
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1505
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1508
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1509
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1510
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1511
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1512
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1513
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1514

+ CESA-2014:0310 Critical CentOS 6 firefox Update
http://lwn.net/Alerts/591067/

+ CESA-2014:0311 Critical CentOS 5 php Update
http://lwn.net/Alerts/591068/

+ Cisco AsyncOS Software Code Execution Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140319-asyncos
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2119

+ McAfee Asset Manager Input Validation Flaws Let Remote Authenticated Users Inject SQL Commands and Download Files
http://www.securitytracker.com/id/1029927

+ Apache HTTP Server Two Denial of Service Vulnerabilities
http://secunia.com/advisories/57399/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6438
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0098

+ Apache HTTP Server 2.4.7 mod_log_config denial of service
http://cxsecurity.com/issue/WLB-2014030150

+ Apache HTTP Server 2.4.7 dav_xml_get_cdata DoS
http://cxsecurity.com/issue/WLB-2014030149

+ OpenSSH 6.5 wildcards on AcceptEnv remote bypass environment restrictions
http://cxsecurity.com/issue/WLB-2014030148
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2532

サーバメンテナンスのお知らせ(2014/3/31)
http://app.trendmicro.co.jp/support/news.asp?id=2096

モバイルアプリの9割には攻撃可能な脆弱性、HPの調査で明らかに
http://itpro.nikkeibp.co.jp/article/NEWS/20140319/544723/?ST=security

「Suicaポイントクラブ」に不正アクセス、約92万件のログイン失敗
http://itpro.nikkeibp.co.jp/article/NEWS/20140319/544694/?ST=security

REMOTE: Quantum vmPRO - Backdoor Command
http://www.exploit-db.com/exploits/32367

REMOTE: SePortal 2.5 - SQL Injection Vulnerabilty
http://www.exploit-db.com/exploits/32359

REMOTE: Loadbalancer.org Enterprise VA 7.5.2 - Static SSH Key
http://www.exploit-db.com/exploits/32371

REMOTE: Quantum DXi V1000 2.2.1 - Static SSH Key
http://www.exploit-db.com/exploits/32372

LOCAL: MP3Info 0.8.5a - SEH Buffer Overflow Exploit
http://www.exploit-db.com/exploits/32358

LOCAL: Quantum vmPRO 3.1.2 - Privilege Escalation
http://www.exploit-db.com/exploits/32370

0 件のコメント:

コメントを投稿