2014年5月2日金曜日

2日 金曜日、先勝













+ MS14-021 - 緊急 Internet Explorer 用のセキュリティ更新プログラム (2965111)
https://technet.microsoft.com/ja-jp/library/security/MS14-021
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1776

+ UPDATE: HPSBMU03009 rev.2 - HP CloudSystem Foundation and Enterprise Software v8.0 running OpenSSL, Remote Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04249113-2%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ UPDATE: HPSBMU02998 rev.3 - HP System Management Homepage (SMH) running OpenSSL on Linux and Windows, Remote Disclosure of Information, Denial of Service (DoS)
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04239372-3%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ HPSBST03004 rev.1 - HP IBRIX X9320 Storage running OpenSSL, Remote Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04264595-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

+ PHP 5.5.12 released
http://www.php.net/archive/2014.php#id2014-04-30-1
http://www.php.net/ChangeLog-5.php#5.5.12

+ VU#673313 Google Search Appliance dynamic navigation cross-site scripting vulnerability
http://www.kb.cert.org/vuls/id/673313
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0362

+ Google Chrom 34.0.1847.131 m 32-bit DLL Order Hijacking
http://cxsecurity.com/issue/WLB-2014050004

+ iTunes for Windows runs rogue program when opening associated files
http://cxsecurity.com/issue/WLB-2014050002

ワコール、不正アクセスで閉鎖していた通販サイトを約1カ月ぶりに再開
http://itpro.nikkeibp.co.jp/article/NEWS/20140501/554265/?ST=security

「パスワードは定期的に変更を」、三井住友カードをかたるフィッシング
http://itpro.nikkeibp.co.jp/article/NEWS/20140501/554202/?ST=security

Flash Playerに危険な脆弱性、悪用した攻撃が出現
http://itpro.nikkeibp.co.jp/article/NEWS/20140501/554182/?ST=security

IEの深刻なゼロデイ脆弱性、MSが「回避策まとめ」を公開
http://itpro.nikkeibp.co.jp/article/NEWS/20140501/554162/?ST=security

JVNVU#95235811 Emerson Avocent MergePoint Unity にディレクトリトラバーサルの脆弱性
http://jvn.jp/vu/JVNVU95235811/

JVNVU#94401838 OpenSSL の heartbeat 拡張に情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU94401838/

0 件のコメント:

コメントを投稿