2014年11月27日木曜日

27日 木曜日、先負

+ UPDATE: マイクロソフト セキュリティ アドバイザリ (2755801) Internet Explorer 上の Adobe Flash Player の脆弱性に対応する更新プログラム
https://technet.microsoft.com/ja-jp/library/security/2755801

+ RHSA-2014:1911 Moderate: ruby security update
https://rhn.redhat.com/errata/RHSA-2014-1911.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8080
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8090

+ RHSA-2014:1912 Moderate: ruby security update
https://access.redhat.com/errata/RHSA-2014:1912
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4975
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8080
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8090

+ Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076

+ HPSBGN03202 rev.1 - HP CMS: Configuration Manager running OpenSSL, Remote Disclosure of Information
https://h20565.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04507568&docLocale=ja_JP
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566

+ SA62180 MantisBT Multiple Vulnerabilities
http://secunia.com/advisories/62180/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8598
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8986
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8987
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9089

+ SA60087 Microsoft Windows Flash Player Vulnerability
http://secunia.com/advisories/60087/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8439

+ SA60219 Google Chrome Flash Player Vulnerability
http://secunia.com/advisories/60219/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8439

+ SA60217 Adobe Flash Player Arbitrary Code Execution Vulnerability
http://secunia.com/advisories/60217/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8439

+ PHP 5.x / Bash Shellshock Proof Of Concept
http://cxsecurity.com/issue/WLB-2014110176
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271

+ PHP 5.6.1 open_basedir exist file check bypass
http://cxsecurity.com/issue/WLB-2014110192

+ Android Settings Pendingintent Leak
http://cxsecurity.com/issue/WLB-2014110189
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8609

+ Android SMS Resend
http://cxsecurity.com/issue/WLB-2014110188
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8610

+ Android WAPPushManager SQL Injection
http://cxsecurity.com/issue/WLB-2014110187
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8507

+ MantisBT 'view_all_set.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/71298

+ Linux Kernel 'espfix64' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/71250

+ phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
http://www.securityfocus.com/bid/71247
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8959

+ phpMyAdmin CVE-2014-8958 Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/71243
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8958

「脅迫ウイルス」が企業の大きな脅威に、業務データを失う恐れ
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/111800105/?ST=security

ESET製セキュリティ対策ソフトの新版発売、ボットネット対策機能を搭載
http://itpro.nikkeibp.co.jp/atcl/news/14/112602033/?ST=security

ソニーピクチャーズにサイバー攻撃か、米メディアが報道
http://itpro.nikkeibp.co.jp/atcl/news/14/112602024/?ST=security

REMOTE: Pandora FMS SQLi Remote Code Execution
http://www.exploit-db.com/exploits/35380

LOCAL: Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 (.wax) SEH Buffer Overflow
http://www.exploit-db.com/exploits/35377

DoS/PoC: Elipse E3 HTTP Denial of Service
http://www.exploit-db.com/exploits/35379

DoS/PoC: Android WAPPushManager - SQL Injection
http://www.exploit-db.com/exploits/35382

0 件のコメント:

コメントを投稿