<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-271993289796750713</id><updated>2012-02-03T16:41:56.802+09:00</updated><category term='友引'/><category term='Windows XP'/><category term='Fedora'/><category term='RTM'/><category term='Happy 12th Birthday Google'/><category term='バンクーバー2010'/><category term='設定画面'/><category term='Solaris 11'/><category term='CentOS 5.4'/><category term='先負'/><category term='ノーマンロックウェルの誕生日'/><category term='Miramer'/><category term='五山送り火'/><category term='iPhone OS 3.0'/><category term='ハッピーハロウィン'/><category term='Apple'/><category term='ディジーガレスピーの誕生日'/><category term='宮沢賢治の誕生日'/><category term='iOS 4.1'/><category term='ミステリーサークル'/><category term='葛飾北斎250周年'/><category term='CentOS 5.3'/><category term='Adobe Acrobat'/><category term='アートクローキー生誕90周年'/><category term='ガンジーの誕生日'/><category term='Ubuntu 10.04 LTS'/><category term='Safari'/><category term='メリークリスマス'/><category term='Mac OS X'/><category term='Doodle 4 Google グランプリ作品'/><category term='iOS'/><category term='なめ猫'/><category term='CentOS 5.2'/><category term='ウイルスバスター2010'/><category term='オズの魔法使い71周年'/><category term='Windows Vista'/><category term='MySQL'/><category term='チャイコフスキー生誕170年'/><category term='ペルセウス座流星群'/><category term='ハッピーホリデー'/><category term='メアリーブレア生誕100周年'/><category term='ジョンレノン生誕70周年'/><category term='Cracking'/><category term='Thunderbird'/><category term='MEMO'/><category term='April Fool'/><category term='ワールドカップ'/><category term='Adobe AIR'/><category term='Red Hat Enterprise Linux 6 Beta 1'/><category term='iOS 4.3'/><category term='メアリーカサットの誕生日'/><category term='IIS'/><category term='Lanikai'/><category term='Setup'/><category term='2010 FIFA ワールドカップ ファイナル'/><category term='iPhone'/><category term='パックマン生誕30周年'/><category term='ウイルスバスター2011'/><category term='iTunes'/><category term='アンデルセン生誕105周年'/><category term='牧野富太郎の誕生日'/><category term='CLファイナル'/><category term='Release Candidate'/><category term='テトリス'/><category term='ジャックイヴクストー生誕100周年'/><category term='iOS 4.2'/><category term='ハンス・クリスティアン・エルステッドの誕生日'/><category term='横山大観生誕143周年'/><category term='Firefox 4.0'/><category term='バーコードの発明'/><category term='Beta Testing'/><category term='Microsoft'/><category term='月面着陸40周年'/><category term='原始家族プリンストーン50周年'/><category term='大安'/><category term='Service Pack'/><category term='ハッピーバレンタイン'/><category term='イサムノグチの誕生日'/><category term='アントニオ・ヴィヴァルディの誕生日'/><category term='Oracle'/><category term='Windows Security Essentials'/><category term='セサミストリート40周年'/><category term='QuickTime'/><category term='Security Advisory'/><category term='Mozilla'/><category term='Doodle4-Googleグランプリ作品'/><category term='七夕'/><category term='アースデー'/><category term='仏滅'/><category term='黒澤 明 生誕100年'/><category term='Internet Explorer 9'/><category term='SP2'/><category term='エルジークリスラージーガーの誕生日'/><category term='Windows 7'/><category term='サミュエル・モールスの誕生日'/><category term='ガリレオの天体観測から400年'/><category term='植物学の日'/><category term='ReactOS'/><category term='php'/><category term='CentOS 5.5'/><category term='ストラヴィンスキーの誕生日'/><category term='皆既日食'/><category term='横浜開港150周年'/><category term='ひな祭り'/><category term='ニコラ テスラの誕生日'/><category term='赤口'/><category term='Adobe Flash Player'/><category term='CentOS 6.0'/><category term='Install'/><category term='先勝'/><category term='TETRIS'/><category term='雛祭り'/><category term='iOS 5'/><title type='text'>:: IT Security Neophyte Investigator's MEMO ::</title><subtitle type='html'>情報セキュリティ新米調査員：お仕事のメモ代わりに調査結果をまとめています。</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default?start-index=101&amp;max-results=100'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>544</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-6057959222889138422</id><published>2012-02-03T11:15:00.002+09:00</published><updated>2012-02-03T16:41:56.814+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='赤口'/><title type='text'>3日 金曜日、赤口</title><content type='html'>&lt;br /&gt;[ANNOUNCE] Apache Lucy (incubating) 0.3.0 released&lt;br /&gt;http://incubator.apache.org/lucy/&lt;br /&gt;&lt;br /&gt;不正請求の画面でお困りのお客さまのトラブルを解決する&lt;br /&gt;『おまかせ！不正請求クリーンナップサービス?』提供開始&lt;br /&gt;～面倒な作業なしで専門の技術者が問題解決までご案内～&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1732&lt;br /&gt;&lt;br /&gt;コンピュータウイルス・不正アクセスの届出状況[1月分]について&lt;br /&gt;http://www.ipa.go.jp/security/txt/2012/02outline.html&lt;br /&gt;&lt;br /&gt;JVNVU#382755: Apple Mac OS X における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU382755/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#410281: Apple Mac OS X CoreText に解放済みメモリ使用 (use-after-free) の脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU410281/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#403593: Apple Mac OS X ATS にメモリ破損の脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU403593/index.html&lt;br /&gt;&lt;br /&gt;Google、マルウエアスキャン機能「Bouncer」をAndroid Marketに導入&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120203/380062/?ST=security&lt;br /&gt;&lt;br /&gt;Critical PHP bug patched&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=12520&lt;br /&gt;&lt;br /&gt;PHP php_register_variable_ex() Lets Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026631&lt;br /&gt;&lt;br /&gt;Novell iPrint Server "attributes-natural-language" Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/47805/&lt;br /&gt;&lt;br /&gt;Fortinet FortiOS (FortiGate) "fields_sorted_opt" Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47693/&lt;br /&gt;&lt;br /&gt;libpng "png_formatted_warning()" Off-by-One Vulnerability&lt;br /&gt;http://secunia.com/advisories/47827/&lt;br /&gt;&lt;br /&gt;TYPO3 Modern FAQ Extension Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47823/&lt;br /&gt;&lt;br /&gt;pragmaMx "message" Script Insertion Vulnerability&lt;br /&gt;http://secunia.com/advisories/47841/&lt;br /&gt;&lt;br /&gt;TYPO3 Kitchen recipe Extension SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/47437/&lt;br /&gt;&lt;br /&gt;Drupal Security Issue and Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/47796/&lt;br /&gt;&lt;br /&gt;HTC Products Wi-Fi Credentials Disclosure Weakness&lt;br /&gt;http://secunia.com/advisories/47837/&lt;br /&gt;&lt;br /&gt;phpLDAPadmin "base" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47852/&lt;br /&gt;&lt;br /&gt;Ubuntu update for usbmuxd&lt;br /&gt;http://secunia.com/advisories/47809/&lt;br /&gt;&lt;br /&gt;Red Hat update for openssl&lt;br /&gt;http://secunia.com/advisories/47808/&lt;br /&gt;&lt;br /&gt;Blue Coat Reporter OpenSSL Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47863/&lt;br /&gt;&lt;br /&gt;Blue Coat Reporter OpenSSL Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47807/&lt;br /&gt;&lt;br /&gt;EMC Documentum Content Server Privilege Escalation Vulnerability&lt;br /&gt;http://secunia.com/advisories/47860/&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ libpng 1.5.8 released&lt;br /&gt;http://www.libpng.org/pub/png/libpng.html&lt;br /&gt;http://www.libpng.org/pub/png/src/libpng-1.5.8-README.txt&lt;br /&gt;&lt;br /&gt;+- libpng 1.5.4 through 1.5.7 contain a one-byte (stack) buffer-overrun bug in png_formatted_warning()&lt;br /&gt;http://www.libpng.org/pub/png/libpng.html&lt;br /&gt;&lt;br /&gt;+ PHP 5.3.10 Released!&lt;br /&gt;http://www.php.net/&lt;br /&gt;http://www.php.net/releases/5_3_10.php&lt;br /&gt;http://www.php.net/ChangeLog-5.php#5.3.10&lt;br /&gt;&lt;br /&gt;+ RHSA-2012:0095 Moderate: ghostscript security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0095.html&lt;br /&gt;&lt;br /&gt;+ RHSA-2012:0093 Critical: php security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0093.html&lt;br /&gt;&lt;br /&gt;+ RHSA-2012:0096 Moderate: ghostscript security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0096.html&lt;br /&gt;&lt;br /&gt;+- Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51705&lt;br /&gt;&lt;br /&gt;+ PHP 'crypt()' Function Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49376&lt;br /&gt;&lt;br /&gt;- Fixed arbitrary remote code execution vulnerability reported by Stefan Esser, CVE-2012-0830&lt;br /&gt;http://www.php.net/&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0075.php&lt;br /&gt;http://www.securityfocus.com/bid/51830&lt;br /&gt;&lt;br /&gt;- Memory leak/Denial of service.&lt;br /&gt;http://www.samba.org/samba/security/CVE-2012-0817&lt;br /&gt;&lt;br /&gt;- PHP CVE-2012-0057 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51806&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Apache MRUnit 0.8.0-incubating released&lt;br /&gt;http://www.apache.org/dyn/closer.cgi/incubator/mrunit/&lt;br /&gt;&lt;br /&gt;MySQL Connector/ODBC 5.1.10 is available!&lt;br /&gt;http://dev.mysql.com/downloads/connector/odbc/5.1.html&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Slony-I 2.1.1 &amp;amp; 1.2.23 released&lt;br /&gt;http://www.slony.info/&lt;br /&gt;&lt;br /&gt;HPSBGN02740 SSRT100741 rev.1 - HP Operations Manager, Operations Agent, Performance Agent, Service Health Reporter, Service Health Optimizer, Performance Manager, Remote Execution of Arbitrary Code&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03179825%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;RHSA-2012:0092 Critical: php53 security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0092.html&lt;br /&gt;&lt;br /&gt;Code Audit Labs : [CAL-2012-0004] Opera - Integer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37556&lt;br /&gt;&lt;br /&gt;Independant Researcher : Bugzilla - Spoofing Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37554&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2012:0079-01] Firefox - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37549&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2012:0080-01] Thunderbird - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37550&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2012:0084-01] SeaMonkey - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37551&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2012:0085-01] Thunderbird - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37552&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBMU02739 SSRT100280 rev.1 - HP Data Protector Media Operations, Remote Ex&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00011.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2012:012 ] apache&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00006.html&lt;br /&gt;&lt;br /&gt;GLSA (Gentoo Linux Security Advisory) publication changes&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00012.html&lt;br /&gt;&lt;br /&gt;[CAL-2012-0004] opera array integer overflow&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00010.html&lt;br /&gt;&lt;br /&gt;Fwd: RA-Guard: Advice on the implementation (feedback requested)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00009.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2012-02-01-1 OS X Lion v10.7.3 and Security Update 2012-001&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00007.html&lt;br /&gt;&lt;br /&gt;Call For Paper&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00008.html&lt;br /&gt;&lt;br /&gt;新たな「Androidウイルス」出現、SymbianやWindows Mobileから移植&lt;br /&gt;エフセキュアが報告、有料SMSにメッセージを勝手に送信&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120202/380050/?ST=security&lt;br /&gt;&lt;br /&gt;ソリトン、標的型攻撃マルウエア対策ソフトを販売&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120202/380016/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001201 Drupal 用 Panels モジュールにおけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001201.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001163 OpenSSL におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001163.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001264 Sudo の sudo_debug 関数における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001264.html&lt;br /&gt;&lt;br /&gt;VU#410281 Apple Mac OS X CoreText embedded font vulnerability&lt;br /&gt;http://www.kb.cert.org/vuls/id/410281&lt;br /&gt;&lt;br /&gt;VU#403593 Apple Mac OS X ATS data-font memory corruption vulnerability&lt;br /&gt;http://www.kb.cert.org/vuls/id/403593&lt;br /&gt;&lt;br /&gt;REMOTE: Icona SpA C6 Messenger DownloaderActiveX Control Arbitrary File Download and Execute&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://www.exploit-db.com/exploits/18449&lt;br /&gt;&lt;br /&gt;REMOTE: Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57&lt;br /&gt;http://www.exploit-db.com/exploits/18448&lt;br /&gt;&lt;br /&gt;REMOTE: Webkit normalize bug for android 2.2 (CVE-2010-1759)&lt;br /&gt;http://www.exploit-db.com/exploits/18446&lt;br /&gt;&lt;br /&gt;DoS/PoC: NetSarang Xlpd Printer Daemon 4 Denial of Service Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/18454&lt;br /&gt;&lt;br /&gt;DoS/PoC: OfficeSIP Server 3.1 Denial Of Service Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/18453&lt;br /&gt;&lt;br /&gt;Novell iPrint Server "attributes-natural-language" Remote Code Execution&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0081.php&lt;br /&gt;&lt;br /&gt;Samba "smbd" Daemon Memory Leak Remote Denial of Service Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0080.php&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Code Execution and Security Bypass Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0079.php&lt;br /&gt;&lt;br /&gt;EMC Documentum Content Server Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0078.php&lt;br /&gt;&lt;br /&gt;Bugzilla Account Impersonation and Cross Site Request Forgery&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0077.php&lt;br /&gt;&lt;br /&gt;Mozilla Products Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0076.php&lt;br /&gt;&lt;br /&gt;PHP "php_register_variable_ex()" Parameter Handling Memory Corruption&lt;br /&gt;http://www.vupen.com/english/ADV-2012-0075.php&lt;br /&gt;&lt;br /&gt;PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51830&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/Seamonkey Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51756&lt;br /&gt;&lt;br /&gt;Mozilla Firefox IPv6 Literal Syntax Cross Domain Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51786&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51754&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey XUL Document Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48360&lt;br /&gt;&lt;br /&gt;Apache Tomcat Hash Collision Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51200&lt;br /&gt;&lt;br /&gt;Apache Tomcat Request Object Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51442&lt;br /&gt;&lt;br /&gt;Apache Tomcat Parameter Handling Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51447&lt;br /&gt;&lt;br /&gt;Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses&lt;br /&gt;http://www.securityfocus.com/bid/49762&lt;br /&gt;&lt;br /&gt;Apache Tomcat AJP Protocol Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49353&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48667&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48456&lt;br /&gt;&lt;br /&gt;glFusion 'users.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46575&lt;br /&gt;&lt;br /&gt;glFusion SQL Injection and Arbitrary File Upload Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51650&lt;br /&gt;&lt;br /&gt;Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50828&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Prior To 10.7.3 CoreText Use After Free Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51812&lt;br /&gt;&lt;br /&gt;JBoss Operations Network Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51095&lt;br /&gt;&lt;br /&gt;HP Data Protector 'DBServer.exe' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47004&lt;br /&gt;&lt;br /&gt;Moodle Multiple Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51450&lt;br /&gt;&lt;br /&gt;Todd Miller Sudo 'Sudo_Debug()' Path Resolution Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51719&lt;br /&gt;&lt;br /&gt;MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50929&lt;br /&gt;&lt;br /&gt;BackupPC 'index.cgi' Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50406&lt;br /&gt;&lt;br /&gt;Polipo POST/PUT Requests HTTP Header Processing Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49908&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51705&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51706&lt;br /&gt;&lt;br /&gt;Apache HTTP Server Scoreboard Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51407&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey SVG Polygon Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48358&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey XUL Document Use-After-Free Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48373&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey 'Array.reduceRight()' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48372&lt;br /&gt;&lt;br /&gt;Mozilla Firefox and Thunderbird CVE-2011-2364 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48367&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Cookie Cross Domain Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48376&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2012-0099 Remote Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51500&lt;br /&gt;&lt;br /&gt;Suhosin Extension Transparent Cookie Encryption Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51574&lt;br /&gt;&lt;br /&gt;PHP 'crypt()' Function Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49376&lt;br /&gt;&lt;br /&gt;PHP CVE-2012-0057 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51806&lt;br /&gt;&lt;br /&gt;RETIRED: Apple Mac OS X Prior to 10.7.3 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51798&lt;br /&gt;&lt;br /&gt;Sunway ForceControl Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49747&lt;br /&gt;&lt;br /&gt;OpenSSL OCSP Stapling 'ClientHello' Handshake Message Parsing Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46264&lt;br /&gt;&lt;br /&gt;OpenSSL TLS Server Extension Parsing Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44884&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Ogg Vorbis Files Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51753&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey nsDOMAttribute Use After Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51755&lt;br /&gt;&lt;br /&gt;OpenSSL Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51281&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-6057959222889138422?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/6057959222889138422/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2012/02/3.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6057959222889138422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6057959222889138422'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2012/02/3.html' title='3日 金曜日、赤口'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-3032174285199531070</id><published>2012-02-02T10:16:00.000+09:00</published><updated>2012-02-02T16:33:44.675+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='大安'/><title type='text'>2日 木曜日、大安</title><content type='html'>&lt;br /&gt;Trend Micro ビジネスセキュリティ6.0 Service Pack 3 Critical Patch (build 4254)公開のお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1730&lt;br /&gt;&lt;br /&gt;「CRYPTRECシンポジウム2012」開催のお知らせ&lt;br /&gt;http://www.ipa.go.jp/security/event/2012/crypt-sympo2012/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#763355 HTC 製 Android 端末に Wi-Fi 認証情報漏えいの脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU763355/index.html&lt;br /&gt;&lt;br /&gt;JVN#33021167 Pocket WiFi (GP02) におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN33021167/index.html&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Information, and Conduct Cross-Site Scripting Attacks and Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026627&lt;br /&gt;&lt;br /&gt;HP Data Protector Media Operations Lets Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026626&lt;br /&gt;&lt;br /&gt;EMC Documentum Content Server Lets Local Administrative Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026624&lt;br /&gt;&lt;br /&gt;REMOTE: Webkit normalize bug for android 2.2 (CVE-2010-1759)&lt;br /&gt;http://www.exploit-db.com/exploits/18446&lt;br /&gt;&lt;br /&gt;WebKit 'Node.normalize' Method Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40665&lt;br /&gt;&lt;br /&gt;Wireshark Versions Prior to 1.4.5/1.2.16 Multiple Remote Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47392&lt;br /&gt;&lt;br /&gt;Subversion 'mod_dav_svn' Multiple Denial of Service and Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48091&lt;br /&gt;&lt;br /&gt;PHP CVE-2011-2202 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48259&lt;br /&gt;&lt;br /&gt;cURL/libcURL GSS/Negotiate Feature Spoofing Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48434&lt;br /&gt;&lt;br /&gt;libTIFF ThunderCode Decoder Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46951&lt;br /&gt;&lt;br /&gt;PHP 'substr_replace()' Use After Free Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46843&lt;br /&gt;&lt;br /&gt;FreeType Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;Apple iOS Libinfo Component CVE-2011-3441 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50641&lt;br /&gt;&lt;br /&gt;RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49229&lt;br /&gt;&lt;br /&gt;Apple iOS and Mac OS X CFNetwork Cross Domain Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50115&lt;br /&gt;&lt;br /&gt;SquirrelMail Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42399&lt;br /&gt;&lt;br /&gt;SquirrelMail Multiple HTML Injection, Cross Site Scripting, and Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48648&lt;br /&gt;&lt;br /&gt;Apple Safari ImageIO TIFF Image Handling Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48833&lt;br /&gt;&lt;br /&gt;Apple Mac OS X ColorSync (CVE-2011-0200) Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48416&lt;br /&gt;&lt;br /&gt;SquirrelMail 'mail_fetch' Remote Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40291&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48456&lt;br /&gt;&lt;br /&gt;Apple iTunes CoreAudio (CVE-2011-3252) Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50065&lt;br /&gt;&lt;br /&gt;Mozilla Firefox and SeaMonkey 'Firefox Recovery Key.html' Insecure File Permissions Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51787&lt;br /&gt;&lt;br /&gt;PHP 'crypt()' Function Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49376&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 'Flic' Movie File Handling Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50404&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 Movie File Handling Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50401&lt;br /&gt;&lt;br /&gt;PHP Prior to 5.3.7 Multiple NULL Pointer Dereference Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49249&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 Movie File Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50400&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Keychain Certificate Settings Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49429&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;About the security content of OS X Lion v10.7.3 and Security Update 2012-001&lt;br /&gt;http://support.apple.com/kb/HT5130&lt;br /&gt;&lt;br /&gt;CentOS alert CESA-2012:0085 (thunderbird)&lt;br /&gt;http://lwn.net/Alerts/478685/&lt;br /&gt;&lt;br /&gt;CentOS alert CESA-2012:0080 (thunderbird)&lt;br /&gt;http://lwn.net/Alerts/478687/&lt;br /&gt;&lt;br /&gt;CentOS alert CESA-2012:0079 (firefox)&lt;br /&gt;http://lwn.net/Alerts/478688/&lt;br /&gt;&lt;br /&gt;CentOS alert CESA-2012:0084 (seamonkey)&lt;br /&gt;http://lwn.net/Alerts/478691/&lt;br /&gt;&lt;br /&gt;Firefox 10 is now available&lt;br /&gt;http://mozilla.jp/firefox/10.0/releasenotes/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+- RHSA-2012:0084-1: Critical: seamonkey security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0084.html&lt;br /&gt;対象名：Red Hat 4 (seamonkey パッケージ)&lt;br /&gt;コメント：使用パッケージが対象ではない&lt;br /&gt;&lt;br /&gt;+ RHSA-2012:0086-1: Moderate: openssl security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0086.html&lt;br /&gt;対象名：Red Hat 4 (openssl パッケージ)&lt;br /&gt;&lt;br /&gt;+? PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47950&lt;br /&gt;CVE-2011-1938&lt;br /&gt;対象名：PHP 5.x&lt;br /&gt;コメント：少々古いが報告していないようです。&lt;br /&gt;&lt;br /&gt;- HPSBMU02739 SSRT100280 rev.1 - HP Data Protector Media Operations, Remote Execution of Arbitrary Code&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03179046%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] JMeter 2.6 is released&lt;br /&gt;http://jmeter.apache.org/docs/changes.html&lt;br /&gt;&lt;br /&gt;Multiple vulnerabilities in OpenEMR&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00003.html&lt;br /&gt;&lt;br /&gt;802.1X password exploit on many HTC Android devices&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00001.html&lt;br /&gt;&lt;br /&gt;ESA-2012-009: EMC Documentum Content Server privilege elevation vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00004.html&lt;br /&gt;&lt;br /&gt;Security advisory for Bugzilla 4.2rc2, 4.0.4, 3.6.8 and 3.4.14&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00002.html&lt;br /&gt;&lt;br /&gt;[Announce] Apache HTTP Server 2.2.22 Released&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00000.html&lt;br /&gt;&lt;br /&gt;XSS phpLDAPadmin: 1.2.0.5 (Debian package) and 1.2.2 (sourceforge)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00005.html&lt;br /&gt;&lt;br /&gt;IPA重要インフラ情報セキュリティシンポジウム2012&lt;br /&gt;http://www.ipa.go.jp/security/event/2012/cip_sympo/index.html&lt;br /&gt;&lt;br /&gt;IIJがDDoS対策の容量を拡大、1Gbps超える攻撃にも耐える&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120201/379906/?ST=security&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2399-1] php5 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37546&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBMU02738 SSRT100748] HP - Network Automation - Unauthorized Access Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37547&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBUX02737 SSRT100747] HP-UX - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37548&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1351-1] AccountsService - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37545&lt;br /&gt;&lt;br /&gt;ISC Feature of the Week: ISC Search&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=12496&lt;br /&gt;&lt;br /&gt;Apple and Apache security fixes and releases&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=12502&lt;br /&gt;&lt;br /&gt;RHSA-2012:0085 Critical: thunderbird security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0085.html&lt;br /&gt;&lt;br /&gt;Bugzilla Bugs Permit Remote Cross-Site Request Forgery and Remote Authenticated Account Impersonation Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026623&lt;br /&gt;&lt;br /&gt;Novell iPrint 'attributes-natural-language' Buffer Overflow Lets Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026618&lt;br /&gt;&lt;br /&gt;Mozilla Thunderbird IPv6 Address Processing Lets Remote Users Bypass Same-Origin Restrictions to Obtain Error Messages&lt;br /&gt;http://www.securitytracker.com/id/1026610&lt;br /&gt;&lt;br /&gt;Mozilla Seamonkey IPv6 Address Processing Lets Remote Users Bypass Same-Origin Restrictions to Obtain Error Messages&lt;br /&gt;http://www.securitytracker.com/id/1026609&lt;br /&gt;&lt;br /&gt;RealNetworks RealPlayer Malformed AAC File Parsing Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/5HP2V0A6AW.html&lt;br /&gt;&lt;br /&gt;RealNetworks RealPlayer genr Sample Size Parsing Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/5JP2X0A6AS.html&lt;br /&gt;&lt;br /&gt;RealNetwork RealPlayer MPG Width Integer Underflow Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/5KP2Y0A6AK.html&lt;br /&gt;&lt;br /&gt;RealNetworks RealPlayer ATRC Code Data Parsing Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/5IP2W0A6AC.html&lt;br /&gt;&lt;br /&gt;VU#763355: 802.1X password exploit on many HTC Android devices&lt;br /&gt;http://www.kb.cert.org/vuls/id/763355&lt;br /&gt;&lt;br /&gt;OpenEMR File Inclusion and Command Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47781/&lt;br /&gt;&lt;br /&gt;Red Hat update for thunderbird&lt;br /&gt;http://secunia.com/advisories/47791/&lt;br /&gt;&lt;br /&gt;Red Hat update for firefox&lt;br /&gt;http://secunia.com/advisories/47789/&lt;br /&gt;&lt;br /&gt;Red Hat update for thunderbird&lt;br /&gt;http://secunia.com/advisories/47800/&lt;br /&gt;&lt;br /&gt;MiTalk Messenger for Android Security Bypass Security Issue&lt;br /&gt;http://secunia.com/advisories/47767/&lt;br /&gt;&lt;br /&gt;Ubuntu update for accountsservice&lt;br /&gt;http://secunia.com/advisories/47834/&lt;br /&gt;&lt;br /&gt;phpShowtime Directory and Image File Disclosure Weakness&lt;br /&gt;http://secunia.com/advisories/47802/&lt;br /&gt;&lt;br /&gt;Pale Moon Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47751/&lt;br /&gt;&lt;br /&gt;MindManager Insecure Library Loading Vulnerability&lt;br /&gt;http://secunia.com/advisories/47797/&lt;br /&gt;&lt;br /&gt;GForge Community Edition / Advanced Server Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47790/&lt;br /&gt;&lt;br /&gt;ManageEngine Applications Manager Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47724/&lt;br /&gt;&lt;br /&gt;Red Hat update for seamonkey&lt;br /&gt;http://secunia.com/advisories/47778/&lt;br /&gt;&lt;br /&gt;Red Hat update for JBoss products&lt;br /&gt;http://secunia.com/advisories/47793/&lt;br /&gt;&lt;br /&gt;Ubuntu update for software-properties&lt;br /&gt;http://secunia.com/advisories/47833/&lt;br /&gt;&lt;br /&gt;Mozilla Firefox / Thunderbird Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47839/&lt;br /&gt;&lt;br /&gt;Mozilla SeaMonkey Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47840/&lt;br /&gt;&lt;br /&gt;Mozilla Firefox / Thunderbird Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47816/&lt;br /&gt;&lt;br /&gt;Emobile Pocket WiFi GP02 Cross-Site Request Forgery Vulnerability&lt;br /&gt;http://secunia.com/advisories/47795/&lt;br /&gt;&lt;br /&gt;Bugzilla Spoofing and Cross-Site Request Forgery Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47814/&lt;br /&gt;&lt;br /&gt;4images "cat_parent_id" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47811/&lt;br /&gt;&lt;br /&gt;Oracle Multiple Products Web Form Hash Collision Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/47819/&lt;br /&gt;&lt;br /&gt;Pligg CMS 'status' Parameter SQL Injection Vulnerability&lt;br /&gt;2012-12-29&lt;br /&gt;http://www.securityfocus.com/bid/51273&lt;br /&gt;&lt;br /&gt;PHP 'ZipArchive::addGlob' and 'ZipArchive::addPattern' Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49252&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51754&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49616&lt;br /&gt;&lt;br /&gt;X.Org libXfont LZW Decompression 'BufCompressedFill()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49124&lt;br /&gt;&lt;br /&gt;libpng Malformed cHRM Divide-By-Zero Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49744&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47950&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-0447 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51757&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51752&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird Cross Domain Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51765&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Ogg Vorbis Files Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51753&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-3032174285199531070?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/3032174285199531070/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2012/02/2.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3032174285199531070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3032174285199531070'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2012/02/2.html' title='2日 木曜日、大安'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-2835633336393748701</id><published>2012-02-01T11:04:00.002+09:00</published><updated>2012-02-01T16:53:18.294+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='仏滅'/><title type='text'>1日 水曜日、仏滅</title><content type='html'>&lt;br /&gt;RHSA-2012:0080&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Critical: thunderbird security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0080.html&lt;br /&gt;&lt;br /&gt;RHSA-2012:0079&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Critical: firefox security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0079.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-09 Firefox Recovery Key.html is saved with unsafe permission&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-09.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-08 Crash with malformed embedded XSLT stylesheets&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-08.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-07 Potential Memory Corruption When Decoding Ogg Vorbis files&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-07.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-06 Uninitialized memory appended when encoding icon images may cause information disclosure&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-06.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-05 Frame scripts calling into untrusted objects bypass security checks&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-05.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-04 Child nodes from nsDOMAttribute still accessible after removal of nodes&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-04.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-03 ＜iframe＞ element exposed across domains via name attribute&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-03.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-02 Overly permissive IPv6 literal syntax&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-02.html&lt;br /&gt;&lt;br /&gt;MFSA 2012-01 Miscellaneous memory safety hazards (rv:10.0/ rv:1.9.2.26)&lt;br /&gt;http://www.mozilla.org/security/announce/2012/mfsa2012-01.html&lt;br /&gt;&lt;br /&gt;FAXシステムメンテナンスのお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1728&lt;br /&gt;&lt;br /&gt;JVNDB-2011-003658 Support Incident Tracker の translate.php における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-003658.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001257 Support Incident Tracker におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001257.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001256 Support Incident Tracker におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001256.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001255 Support Incident Tracker における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001255.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-003657 Support Incident Tracker における任意の PHP コードを実行可能な言語ファイルに挿入される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-003657.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001254 Support Incident Tracker における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001254.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001253 Support Incident Tracker におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001253.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001252 Support Incident Tracker の incident_attachments.php における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001252.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001251 Support Incident Tracker におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001251.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001250 Support Incident Tracker の move_uploaded_file.php における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001250.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001249 Support Incident Tracker の ftp_upload_file.php における任意の PHP コードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001249.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001248 Support Incident Tracker の config.php における任意の PHP コードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001248.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001247 Support Incident Tracker の incident_attachments.php における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001247.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001246 Support Incident Tracker の search.php におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001246.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001245 Support Incident Tracker の ftp_upload_file.php における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001245.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-000010 Pocket WiFi (GP02) におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-000010.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001244 OpenNMS におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001244.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001243 Aryadad CMS の Default.aspx における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001243.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001242 WordPress 用 Theme Tuner プラグインにおける任意の PHP コードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001242.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001241 Acidcat CMS におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001241.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001240 Lead Capture Page System におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001240.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001239 OpenSSH における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001239.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001238 Schneider Electric Modicon Quantum PLC におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001238.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001237 Schneider Electric Modicon Quantum PLC におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001237.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001236 Schneider Electric Modicon Quantum PLC におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001236.html&lt;br /&gt;&lt;br /&gt;JVN#33021167 Pocket WiFi (GP02) におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN33021167/index.html&lt;br /&gt;&lt;br /&gt;「脆弱性体験学習ツールAppGoatハンズオンセミナー」開催のご案内&lt;br /&gt;http://www.ipa.go.jp/security/vuln/seminar/lab_semi_appgoat_2012_1.html&lt;br /&gt;&lt;br /&gt;Mozilla Firefox IPv6 Address Processing Lets Remote Users Bypass Same-Origin Restrictions to Obtain Error Messages&lt;br /&gt;http://www.securitytracker.com/id/1026608&lt;br /&gt;&lt;br /&gt;Mozilla Thunderbird Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site Scripting Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026607&lt;br /&gt;&lt;br /&gt;Mozilla Firefox Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site Scripting Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026605&lt;br /&gt;&lt;br /&gt;DoS/PoC: EdrawSoft Office Viewer Component ActiveX 5.6 (officeviewermme.ocx) BoF PoC&lt;br /&gt;http://www.exploit-db.com/exploits/18440&lt;br /&gt;&lt;br /&gt;- DoS/PoC: sudo 1.8.0 - 1.8.3p1 Format String Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/18436&lt;br /&gt;&lt;br /&gt;LuraWave JP2 Browser Plug-In 'npjp2.dll' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51732&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey nsDOMAttribute Use After Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51755&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51754&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/Seamonkey Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51756&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51706&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Ogg Vorbis Files Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51753&lt;br /&gt;&lt;br /&gt;PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50907&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2140 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49083&lt;br /&gt;&lt;br /&gt;PHP CVE-2011-2202 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48259&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ Apache HTTP 2.2.22 released&lt;br /&gt;http://www.apache.org/dist/httpd/Announcement2.2.html&lt;br /&gt;http://ftp.meisei-u.ac.jp/mirror/apache/dist//httpd/CHANGES_2.2.22&lt;br /&gt;&lt;br /&gt;+ Postfix 2.9 Patchlevel 0, Postfix 2.8 Patchlevel 8 released&lt;br /&gt;http://mirror.postfix.jp/postfix-release/index.html&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.9.0.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.8.8.HISTORY&lt;br /&gt;&lt;br /&gt;+ Suhosin Patch 0.9.10 released&lt;br /&gt;http://www.hardened-php.net/suhosin/download.html&lt;br /&gt;http://www.hardened-php.net/suhosin/download.html#suhosin_patch_0.9.10&lt;br /&gt;&lt;br /&gt;+ GnuPG 1.4.12 released&lt;br /&gt;http://lists.gnupg.org/pipermail/gnupg-announce/2012q1/000313.html&lt;br /&gt;&lt;br /&gt;+ Critical: firefox security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0079.html&lt;br /&gt;&lt;br /&gt;++ Oracle Security Alert for CVE-2011-5035&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/alert-cve-2011-5035-1506603.html&lt;br /&gt;&lt;br /&gt;Linux kernel 3.3-rc2 released&lt;br /&gt;http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=summary&lt;br /&gt;&lt;br /&gt;HS12-006 uCosminexus製品におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS12-006/index.html&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-006/index.html&lt;br /&gt;&lt;br /&gt;HS12-005 JP1製品におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS12-005/index.html&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-005/index.html&lt;br /&gt;&lt;br /&gt;HS12-004 JP1/IT Desktop Management - Managerにおけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS12-004/index.html&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-004/index.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2399-2] php5 regression fix&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00190.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2399-1] php5 security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00189.html&lt;br /&gt;&lt;br /&gt;VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00188.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02724 SSRT100650 rev.3 - HP-UX Running System Administration Manag&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00187.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02697 SSRT100591 rev.2 - HP-UX Running Java, Remote Unauthorized A&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00186.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02737 SSRT100747 rev.1 - HP-UX Running OpenSSL, Remote Denial of S&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-01/msg00185.html&lt;br /&gt;&lt;br /&gt;“500万台感染のAndroidウイルス”、正体はアドウエアの可能性大&lt;br /&gt;広告を表示させてお金もうけ、端末の乗っ取りなどは行わない&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120201/379863/?ST=security&lt;br /&gt;&lt;br /&gt;「高まるセキュリティの懸念、一人ひとりが適切な対応を」――官房長官&lt;br /&gt;2月1日から「情報セキュリティ月間」開始&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20120201/379866/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2011-003656 Linux kernel の hfs_mac2asc 関数におけるスタックベースのバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-003656.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001235 Linux kernel の NFS 実装におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001235.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001234 Linux kernel におけるサービス運用妨害 (アサーションエラーおよび kernel oops) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001234.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001233 Linux kernel におけるサービス運用妨害 (NULL ポインタデリファレンスおよび kernel oops) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001233.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001232 Linux kernel の xfs_readlink 関数におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001232.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001231 Linux kernel におけるサービス運用妨害 (NULL ポインタデリファレンスおよび OOPS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001231.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001230 Linux kernel の tpm_read 関数 における TPM コマンドの結果を読まれる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001230.html&lt;br /&gt;&lt;br /&gt;JVNDB-2012-001229 Linux kernel の mem_write 関数における権限を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001229.html&lt;br /&gt;&lt;br /&gt;OSINT tactics: parsing from FOCA for Maltego&lt;br /&gt;http://isc.sans.edu/diary/OSINT+tactics+parsing+from+FOCA+for+Maltego/12481&lt;br /&gt;&lt;br /&gt;Firefox 10 and VMWare advisories and updates&lt;br /&gt;http://isc.sans.edu/diary/Firefox+10+and+VMWare+advisories+and+updates/12490&lt;br /&gt;&lt;br /&gt;RHSA-2012:0073&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Low: Red Hat Enterprise Linux 4 - 30 day End Of Life Notice&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0073.html&lt;br /&gt;&lt;br /&gt;RHSA-2012:0079&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Critical: firefox security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2012-0079.html&lt;br /&gt;&lt;br /&gt;ProFTPD Response Pool Use-After-Free Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/unixfocus/5MP3Q0A60W.html&lt;br /&gt;&lt;br /&gt;InduSoft WebStudio CEServer Operation 0x15 Code Execution Vulnerability | 0 Comments and 0 Reactions&lt;br /&gt;http://www.securiteam.com/securitynews/5NP3R0A60M.html&lt;br /&gt;&lt;br /&gt;InduSoft WebStudio Unauthenticated Operations Code Execution Vulnerabilityy | 0 Comments and 0 Reactions&lt;br /&gt;http://www.securiteam.com/securitynews/5OP3S0A60C.html&lt;br /&gt;&lt;br /&gt;HP Data Protector LogBackupLocationStatus SQL Injection Vulnerabilty | 0 Comments and 0 Reactions&lt;br /&gt;http://www.securiteam.com/securitynews/5PP3T0A60S.html&lt;br /&gt;&lt;br /&gt;TWiki Input Validation Flaw in 'Organization' Field Permits Cross-Site Scripting Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026604&lt;br /&gt;&lt;br /&gt;IBM SPSS SamplePower VsVIEW6 ActiveX Control Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026603&lt;br /&gt;&lt;br /&gt;IBM SPSS Data Collection ActiveX Controls Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026602&lt;br /&gt;&lt;br /&gt;FishEye / Crucible Webwork 2 Code Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/47780/&lt;br /&gt;&lt;br /&gt;RESTEasy JAXB XML Entity References Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/47832/&lt;br /&gt;&lt;br /&gt;RESTEasy XML Entity References Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/47818/&lt;br /&gt;&lt;br /&gt;HostBill Ticket Subject Code Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/47799/&lt;br /&gt;&lt;br /&gt;SilverStripe Page Title Script Insertion Vulnerability&lt;br /&gt;http://secunia.com/advisories/47812/&lt;br /&gt;&lt;br /&gt;Debian update for php5&lt;br /&gt;http://secunia.com/advisories/47785/&lt;br /&gt;&lt;br /&gt;VMware ESX Server Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47758/&lt;br /&gt;&lt;br /&gt;VMware ESXi Server Python Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/47608/&lt;br /&gt;&lt;br /&gt;Hitachi JP1/IT Resource Management Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47825/&lt;br /&gt;&lt;br /&gt;Hitachi JP1/IT Service Level Management Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47804/&lt;br /&gt;&lt;br /&gt;Hitachi JP1/IT Desktop Management Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47774/&lt;br /&gt;&lt;br /&gt;Hitachi uCosminexus Products Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47815/&lt;br /&gt;&lt;br /&gt;Hitachi uCosminexus EUR Print Manager Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47773/&lt;br /&gt;&lt;br /&gt;HP Network Automation Unspecified Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/47826/&lt;br /&gt;&lt;br /&gt;HP Network Automation Unspecified Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/47738/&lt;br /&gt;&lt;br /&gt;TWiki User Organization Script Insertion Vulnerability&lt;br /&gt;http://secunia.com/advisories/47784/&lt;br /&gt;&lt;br /&gt;Mibew Messenger Cross-Site Request Forgery Vulnerability&lt;br /&gt;http://secunia.com/advisories/47787/&lt;br /&gt;&lt;br /&gt;LuraWave JP2 Browser Plug-In File Processing Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/47831/&lt;br /&gt;&lt;br /&gt;LuraWave JP2 ActiveX Control File Processing Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/47350/&lt;br /&gt;&lt;br /&gt;Image Hosting Script DPI "showseries" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/47786/&lt;br /&gt;&lt;br /&gt;Debian update for curl&lt;br /&gt;http://secunia.com/advisories/47764/&lt;br /&gt;&lt;br /&gt;sudo "sudo_debug()" Format String Privilege Escalation Vulnerability&lt;br /&gt;http://secunia.com/advisories/47743/&lt;br /&gt;&lt;br /&gt;Red Hat update for php&lt;br /&gt;http://secunia.com/advisories/47820/&lt;br /&gt;&lt;br /&gt;Red Hat update for ruby&lt;br /&gt;http://secunia.com/advisories/47821/&lt;br /&gt;&lt;br /&gt;Red Hat update for ruby&lt;br /&gt;http://secunia.com/advisories/47822/&lt;br /&gt;&lt;br /&gt;Apache httpOnly Cookie Disclosure&lt;br /&gt;http://www.exploit-db.com/exploits/18442/&lt;br /&gt;&lt;br /&gt;Adobe Flash Player MP4 SequenceParameterSetNALUnit Remote Code Execution Exploit&lt;br /&gt;http://www.exploit-db.com/exploits/18437/&lt;br /&gt;&lt;br /&gt;PHP CVE-2011-2202 Security Bypass Vulnerability&lt;br /&gt;2012-02-01&lt;br /&gt;http://www.securityfocus.com/bid/48259&lt;br /&gt;&lt;br /&gt;PHP Web Form Hash Collision Denial Of Service Vulnerability&lt;br /&gt;2012-02-01&lt;br /&gt;http://www.securityfocus.com/bid/51193&lt;br /&gt;&lt;br /&gt;PHP Exif Extension 'exif_read_data()' Function Remote Denial of Service Vulnerability&lt;br /&gt;2012-02-01&lt;br /&gt;http://www.securityfocus.com/bid/46365&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;Ruby Hash Collision Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51198&lt;br /&gt;&lt;br /&gt;Ruby Random Number Values Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49126&lt;br /&gt;&lt;br /&gt;Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51194&lt;br /&gt;&lt;br /&gt;Samba SWAT Cross Site Request Forgery Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48899&lt;br /&gt;&lt;br /&gt;Xen 'x86_64 __addr_ok()' Local Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49370&lt;br /&gt;&lt;br /&gt;Samba 'client/mount.cifs.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/38326&lt;br /&gt;&lt;br /&gt;Samba 'etc/mtab' File Appending Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49939&lt;br /&gt;&lt;br /&gt;Linux Kernel NFS File Locking Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49141&lt;br /&gt;&lt;br /&gt;Linux Kernel 'fs/partitions/osf.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46878&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ib_uverbs_poll_cq()' Function Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46488&lt;br /&gt;&lt;br /&gt;PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50907&lt;br /&gt;&lt;br /&gt;PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47950&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ib_uverbs_poll_cq()' Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46073&lt;br /&gt;&lt;br /&gt;Linux Kernel SCTP Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49373&lt;br /&gt;&lt;br /&gt;Linux Kernel SCTP INIT/INIT-ACK Chunk Length Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47308&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47343&lt;br /&gt;&lt;br /&gt;Linux Kernel Netfilter and Econet Local Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46919&lt;br /&gt;&lt;br /&gt;Linux Kernel Request Handling 'cm.c' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46839&lt;br /&gt;&lt;br /&gt;Samba SWAT 'user' Field Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48901&lt;br /&gt;&lt;br /&gt;Samba 'mount.cifs' Utility Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37992&lt;br /&gt;&lt;br /&gt;Linux Kernel Signal Code Spoofing Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47003&lt;br /&gt;&lt;br /&gt;Linux Kernel GFS2 'fs/gfs2/file.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48677&lt;br /&gt;&lt;br /&gt;Linux Kernel 'inet_diag_bc_audit()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48333&lt;br /&gt;&lt;br /&gt;Xen SAHF Emulation Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49375&lt;br /&gt;&lt;br /&gt;Linux Kernel FSGEOMETRY_V1 IOCTL Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46417&lt;br /&gt;&lt;br /&gt;Expat XML Parsing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37203&lt;br /&gt;&lt;br /&gt;Python 'audioop' Module Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40370&lt;br /&gt;&lt;br /&gt;Python 'audioop' Module Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40863&lt;br /&gt;&lt;br /&gt;Linux Kernel 'agp_ioctl()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47534&lt;br /&gt;&lt;br /&gt;Linux Kernel 'agp_allocate_memory/agp_create_user_memory' Local Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47535&lt;br /&gt;&lt;br /&gt;Python 'urllib' and 'urllib2' Modules Information Disclosure and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47024&lt;br /&gt;&lt;br /&gt;Python Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/44533&lt;br /&gt;&lt;br /&gt;Linux Kernel '/proc/[pid]/stat' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47791&lt;br /&gt;&lt;br /&gt;Linux Kernel '/proc/PID/io' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49408&lt;br /&gt;&lt;br /&gt;Linux Kernel 'next_pidmap()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47497&lt;br /&gt;&lt;br /&gt;Linux Kernel Bluetooth 'l2cap_sock.c' and 'rfcomm/sock.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48441&lt;br /&gt;&lt;br /&gt;Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/36097&lt;br /&gt;&lt;br /&gt;Python CGIHTTPServer Module Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46541&lt;br /&gt;&lt;br /&gt;Red Hat Xen Hypervisor Implementation Local Guest Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48058&lt;br /&gt;&lt;br /&gt;Linux Kernel SSID Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48538&lt;br /&gt;&lt;br /&gt;Linux Kernel OOPS 'qdisc_dev()' Dereference Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48641&lt;br /&gt;&lt;br /&gt;Linux Kernel 'agp_ioctl()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47843&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47796&lt;br /&gt;&lt;br /&gt;Xen 'get_free_port()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48048&lt;br /&gt;&lt;br /&gt;Linux Kernel Multiple Local Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46616&lt;br /&gt;&lt;br /&gt;Linux Kernel 'oops' on Reset NULL Pointer Dereference Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46793&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2012-0100 Local Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51475&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50494&lt;br /&gt;&lt;br /&gt;Linux Kernel CVE-2012-0056 Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51625&lt;br /&gt;&lt;br /&gt;MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50929&lt;br /&gt;&lt;br /&gt;PostgreSQL 'intarray' Module 'gettoken()' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46084&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50802&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-0604 Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46217&lt;br /&gt;&lt;br /&gt;RESTEasy JaxB XML Entity References Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51766&lt;br /&gt;&lt;br /&gt;HostBill PHP Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51763&lt;br /&gt;&lt;br /&gt;FishEye and Crucible Webwork 2 Framework Remote Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51762&lt;br /&gt;&lt;br /&gt;SilverStripe 'Title' Parameter HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51761&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-0447 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51757&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/Seamonkey Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/51756&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey nsDOMAttribute Use After Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51755&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51754&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Ogg Vorbis Files Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51753&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51752&lt;br /&gt;&lt;br /&gt;Hitachi JP1 Products Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51749&lt;br /&gt;&lt;br /&gt;RESTEasy XML Entity References Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51748&lt;br /&gt;&lt;br /&gt;Hitachi JP1/IT Desktop Management Manager Unspecified Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51747&lt;br /&gt;&lt;br /&gt;HP Network Automation Remote Unauthorized Access Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51746&lt;br /&gt;&lt;br /&gt;Hitachi uCosminexus Products Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51745&lt;br /&gt;&lt;br /&gt;LuraWave JP2 ActiveX Control 'jp2_x.dll' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51744&lt;br /&gt;&lt;br /&gt;Clixint Technologies DPI 'showseries' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51734&lt;br /&gt;&lt;br /&gt;LuraWave JP2 Browser Plug-In 'npjp2.dll' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51732&lt;br /&gt;&lt;br /&gt;TWiki 'organization' Field HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51731&lt;br /&gt;&lt;br /&gt;Joomla! 'com_crhotels' Component 'catid' Parameter Remote SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/51728&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-2835633336393748701?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/2835633336393748701/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2012/02/1.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/2835633336393748701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/2835633336393748701'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2012/02/1.html' title='1日 水曜日、仏滅'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-8588326942563908219</id><published>2011-11-02T10:46:00.002+09:00</published><updated>2011-11-02T11:02:32.843+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='仏滅'/><category scheme='http://www.blogger.com/atom/ns#' term='横山大観生誕143周年'/><title type='text'>2日 水曜日、仏滅</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: right;"&gt;&lt;a href="http://2.bp.blogspot.com/-1QJxopJSBCI/TrCkjahHRBI/AAAAAAAAA4M/cmpkAEtdtD0/s1600/Google-20111102-%25E6%25A8%25AA%25E5%25B1%25B1%25E5%25A4%25A7%25E8%25A6%25B3%25E7%2594%259F%25E8%25AA%2595143%25E5%2591%25A8%25E5%25B9%25B4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="78" src="http://2.bp.blogspot.com/-1QJxopJSBCI/TrCkjahHRBI/AAAAAAAAA4M/cmpkAEtdtD0/s200/Google-20111102-%25E6%25A8%25AA%25E5%25B1%25B1%25E5%25A4%25A7%25E8%25A6%25B3%25E7%2594%259F%25E8%25AA%2595143%25E5%2591%25A8%25E5%25B9%25B4.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;+ Multiple vulnerabilities in Adobe Flashplayer&lt;br /&gt;http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_adobe_flashplayer2&lt;br /&gt;&lt;br /&gt;+ Multiple vulnerabilities in Adobe Flashplayer&lt;br /&gt;http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_adobe_flashplayer1&lt;br /&gt;&lt;br /&gt;+ Multiple Buffer Overflow vulnerabilities in GIMP&lt;br /&gt;http://blogs.oracle.com/sunsecurity/entry/multiple_buffer_overflow_vulnerabilities_in&lt;br /&gt;&lt;br /&gt;+ Microsoft Windows Kernel Word File Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50462&lt;br /&gt;&lt;br /&gt;+- Linux Kernel '/mm/oom_kill.c' Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50459&lt;br /&gt;&lt;br /&gt;HPSBMU02712 SSRT100649 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code&lt;br /&gt;https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03054052%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;Wireshark 1.6.3 Released&lt;br /&gt;http://www.wireshark.org/docs/relnotes/wireshark-1.6.3.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBMU02712 SSRT100649 rev.1 - HP OpenView Network Node Manager (OV NNM), Re&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00005.html&lt;br /&gt;&lt;br /&gt;Oracle Hyperion Financial Management TList6 ActiveX Control Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00009.html&lt;br /&gt;&lt;br /&gt;XSS and SQL Injection Vulnerabilities on Symphony CMS 2.2.3&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00008.html&lt;br /&gt;&lt;br /&gt;XSS Vulnerabilities in eFront&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00007.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:162 ] kdelibs4&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00006.html&lt;br /&gt;&lt;br /&gt;GDTelcom Speedtest ActiveX Control "FTPDownLoad Class"-ActiveX.dll Remote Denial of Service Vuln&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00004.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201111-01 ] Chromium, V8: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00003.html&lt;br /&gt;&lt;br /&gt;IBSng all version Cross-Site Scripting Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00002.html&lt;br /&gt;&lt;br /&gt;CVE-2011-3682: 2WIRE-SINGTEL 2701HGV-E/2700HGV-2/2700HG GATEWAY ROUTER MANAGEMEN&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00001.html&lt;br /&gt;&lt;br /&gt;DDIVRT-2011-33 IBM WebSphere Application Server help Servlet Plug-in Bundle Directory Tr&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-11/msg00000.html&lt;br /&gt;&lt;br /&gt;Oracle DataDirect ODBC Drivers HOST Attribute arsqls24.dll Stack Based Buffer Overflow PoC (*.oce)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00215.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2333-1] phpldapadmin security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00212.html&lt;br /&gt;&lt;br /&gt;PlotLineControl ActiveX Control "LinePutPoint" Integer Overflow&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00214.html&lt;br /&gt;&lt;br /&gt;YaTFTPSvr TFTP Server Directory Traversal Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00216.html&lt;br /&gt;&lt;br /&gt;Apples Mail.app mail of death&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00213.html&lt;br /&gt;&lt;br /&gt;Securiteam&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/Securiteam/&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2332-1] python-django security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00211.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02707 SSRT100626 rev.2 - HP-UX Apache Web Server, Remote Denial of&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00210.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02702 SSRT100606 rev.5 - HP-UX Apache Web Server, Remote Denial of&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00209.html&lt;br /&gt;&lt;br /&gt;シマンテックがAndroid端末用セキュリティソフトの新版&lt;br /&gt;遠隔操作でアラームを鳴らす機能などを追加&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111102/372023/?ST=security&lt;br /&gt;&lt;br /&gt;化学メーカーを狙った「標的型攻撃」が相次ぐ、国内企業も被害&lt;br /&gt;世界中で48社がターゲットに、米シマンテックが報告&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111102/372022/?ST=security&lt;br /&gt;&lt;br /&gt;JVN#98649286 CSWorks の LiveData Service におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN98649286/index.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000095 CSWorks の LiveData Service におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000095.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002643 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002643.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002642 Google Chrome における URL バーを偽造される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002642.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002641 Google Chrome における MIME タイプに関する詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002641.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002640 Linux 上で稼働する Google Chrome における PIC および PIE コンパイラオプションの使用に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002640.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002639 Google Chrome における詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002639.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002638 Google Chrome におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002638.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002637 Google Chrome にて使用される libxml2 におけるメモリ二重開放の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002637.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002636 Google Chrome におけるサービス運用妨害 (out-of-bounds read) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002636.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002635 Google Chrome にて使用される Google V8 におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002635.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002634 Google Chrome における詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002634.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002633 Google Chrome におけるサービス運用妨害 (out-of-bounds read) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002633.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002632 Google Chrome にて使用される Google V8 における詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002632.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002631 Google Chrome における、詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002631.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002630 Google Chrome のサービス運用妨害の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002630.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002629 Google Chrome における詳細不明な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002629.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002628 Google Chrome におけるサービス運用妨害 (out-of-bounds read) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002628.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002627 Cisco IOS の cat6000-dot1x コンポーネントにおけるサービス運用妨害 (トラフィックストーム) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002627.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002626 Cisco CiscoWorks Common Services における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002626.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002625 Cisco IOS の ethernet-lldp コンポーネントにおけるサービス運用妨害 (デバイスクラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002625.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002624 NexusPHP の thanks.php における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002624.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002623 OCS Inventory NG の ocsinventory におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002623.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002622 OpenOffice.org および LibreOffice の oowriter におけるサービス運用妨害 (クラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002622.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002621 Simple Machines Forum におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002621.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002620 KENT-WEB WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002620.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002619 IBM WebSphere ILOG Rule Team Server の content/error.jsp におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002619.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002618 Simple Machines Forum における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002618.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002617 Novell ZENworks Handheld Management (ZHM) の ZfHSrvr.exe における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002617.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002616 Novell ZENworks Handheld Management (ZHM) の ZfHSrvr.exe における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002616.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000094 複数のスカイアークシステム製品におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000094.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000093 複数のスカイアークシステム製品におけるアクセス制限不備の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000093.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002615 Asterisk Open Source の chan_sip.c におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002615.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002614 ATCOM Netvolution における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002614.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002613 BlackBerry Collaboration Service における任意のユーザアカウントへログインされる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002613.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002612 ATCOM Netvolution の default.asp における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002612.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002611 ATCOM Netvolution の default.asp におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002611.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002610 ATCOM Netvolution におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002610.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002609 ATCOM Netvolution の default.asp における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002609.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002608 MIT Kerberos の krb5_db2_lockout_audit 関数におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002608.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002607 MIT Kerberos の lookup_lockout_policy 関数におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002607.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002606 MIT Kerberos の krb5_ldap_lockout_audit 関数におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002606.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002605 MIT Kerberos の kdb_ldap プラグインにおけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002605.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002604 Empathy の theme_adium_append_message 関数におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002604.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002603 Empathy の theme_adium_append_message 関数におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002603.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002602 HP MFP Digital Sending ソフトウェアにおける重要なワークフローメタデータ情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002602.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002601 Linux kernel の napi_reuse_skb 関数におけるサービス運用妨害 (NULL ポインタデリファレンス) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002601.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002600 Cisco Adaptive Security Appliances デバイスにおけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002600.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002599 Cisco IOS の ipv6 コンポーネントにおけるフィンガープリンティング攻撃を誘導される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002599.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002598 Cisco IOS の cat6000-dot1x コンポーネントにおけるサービス運用妨害 (トラフィックストーム) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002598.html&lt;br /&gt;&lt;br /&gt;Honeynet Project: Android Reverse Engineering (A.R.E.) Virtual Machine released&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11926&lt;br /&gt;&lt;br /&gt;Secure languages &amp;amp; frameworks&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11929&lt;br /&gt;&lt;br /&gt;Linux Kernel clock_gettime() Negative Divisor Bug Lets Local Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026261&lt;br /&gt;&lt;br /&gt;HP OpenView Network Node Manager Bugs Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026260&lt;br /&gt;&lt;br /&gt;Novell GroupWise Messenger Discloses Arbitrary Memory Contents to Remote Users&lt;br /&gt;http://www.securitytracker.com/id/1026257&lt;br /&gt;&lt;br /&gt;IBM AIX BIND Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46641/&lt;br /&gt;&lt;br /&gt;Gentoo update for chromium and v8&lt;br /&gt;http://secunia.com/advisories/46636/&lt;br /&gt;&lt;br /&gt;NJStar Communicator MiniSmtp Packet Processing Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46630/&lt;br /&gt;&lt;br /&gt;Joomla! Alameda Component "storeid" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46635/&lt;br /&gt;&lt;br /&gt;Squid DNS Replies Invalid Free Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46609/&lt;br /&gt;&lt;br /&gt;CSWorks LiveData Service TCP Packets Processing Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46625/&lt;br /&gt;&lt;br /&gt;Megatops YaTFTPSvr Directory Traversal Vulnerability&lt;br /&gt;http://secunia.com/advisories/46665/&lt;br /&gt;&lt;br /&gt;Oracle Hyperion Enterprise Performance Management arsqls24.dll Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46652/&lt;br /&gt;&lt;br /&gt;WordPress ClassiPress Theme "twitter_id" and "facebook_id" Script Insertion Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46658/&lt;br /&gt;&lt;br /&gt;Joomla! Vik Real Estate Extension "contract" and "imm" SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46661/&lt;br /&gt;&lt;br /&gt;Joomla! HM Community Component Script Insertion and SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46656/&lt;br /&gt;&lt;br /&gt;Novell Messenger Server Process Memory Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/46677/&lt;br /&gt;&lt;br /&gt;Gobby Two Weaknesses&lt;br /&gt;http://secunia.com/advisories/46698/&lt;br /&gt;&lt;br /&gt;net6 Two Weaknesses&lt;br /&gt;http://secunia.com/advisories/46605/&lt;br /&gt;&lt;br /&gt;Debian update for python-django&lt;br /&gt;http://secunia.com/advisories/46614/&lt;br /&gt;&lt;br /&gt;Debian update for radvd&lt;br /&gt;http://secunia.com/advisories/46639/&lt;br /&gt;&lt;br /&gt;Debian update for tor&lt;br /&gt;http://secunia.com/advisories/46640/&lt;br /&gt;&lt;br /&gt;Ubuntu update for empathy&lt;br /&gt;http://secunia.com/advisories/46684/&lt;br /&gt;&lt;br /&gt;Openswan Cryptographic Helper Use-After-Free Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46681/&lt;br /&gt;&lt;br /&gt;WordPress Simple Balance Theme "s" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46671/&lt;br /&gt;&lt;br /&gt;eFront Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46613/&lt;br /&gt;&lt;br /&gt;SUSE update for java-1_6_0-openjdk&lt;br /&gt;http://secunia.com/advisories/46695/&lt;br /&gt;&lt;br /&gt;Debian update for phpldapadmin&lt;br /&gt;http://secunia.com/advisories/46672/&lt;br /&gt;&lt;br /&gt;Fedora update for kernel&lt;br /&gt;http://secunia.com/advisories/46687/&lt;br /&gt;&lt;br /&gt;Fujitsu Interstage HTTP Server Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46648/&lt;br /&gt;&lt;br /&gt;NJStar Communicator 3.00 MiniSMTP Server Remote Exploit&lt;br /&gt;http://www.exploit-db.com/exploits/18057&lt;br /&gt;&lt;br /&gt;Linux Kernel TCP Sequence Number Generation Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49289&lt;br /&gt;&lt;br /&gt;KDE KSSL Common Name SSL Certificate Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49925&lt;br /&gt;&lt;br /&gt;Linux Kernel 'clock_gettime()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50311&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3553 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50246&lt;br /&gt;&lt;br /&gt;IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49362&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50231&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3561 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50250&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50234&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50242&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3554 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50216&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50224&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50248&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50211&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3549 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50223&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50243&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3521 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50215&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50220&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3550 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50226&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3546 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50239&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;Oracle Java SE Rhino Script Engine Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50218&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3516 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50229&lt;br /&gt;&lt;br /&gt;KDE KSSL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/36229&lt;br /&gt;&lt;br /&gt;ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37118&lt;br /&gt;&lt;br /&gt;Apache Tomcat AJP Protocol Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49353&lt;br /&gt;&lt;br /&gt;ISC BIND 9 DNSSEC Bogus NXDOMAIN Response Remote Cache Poisoning Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37865&lt;br /&gt;&lt;br /&gt;Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verification Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/33151&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 13.0.782.215 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49279&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 14.0.835.202 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49938&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 14.0.835.163 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49658&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 15.0.874.102 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50360&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 12.0.742.112 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48479&lt;br /&gt;&lt;br /&gt;Google Chrome prior to 14.0.835.163 PDF File Handling Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49933&lt;br /&gt;&lt;br /&gt;Oracle Hyperion Financial Management 'TList6.ocx' ActiveX Control Insecure Method Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50476&lt;br /&gt;&lt;br /&gt;GE Proficy Historian Data Archiver Service Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50475&lt;br /&gt;&lt;br /&gt;GE Proficy Plant Application Components Remote Stack Based Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50474&lt;br /&gt;&lt;br /&gt;GE Proficy Historian Web Administrator Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50473&lt;br /&gt;&lt;br /&gt;HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50471&lt;br /&gt;&lt;br /&gt;Symphony Multiple SQL Injection and Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50470&lt;br /&gt;&lt;br /&gt;eFront Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50469&lt;br /&gt;&lt;br /&gt;IBSng 'str' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50468&lt;br /&gt;&lt;br /&gt;Google App Engine Python SDK 'FakeFile' Object Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50464&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel Word File Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50462&lt;br /&gt;&lt;br /&gt;Linux Kernel '/mm/oom_kill.c' Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50459&lt;br /&gt;&lt;br /&gt;Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50456&lt;br /&gt;&lt;br /&gt;vBulletin Multiple Remote File Include Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50455&lt;br /&gt;&lt;br /&gt;Domain Shop 'index.php' Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50454&lt;br /&gt;&lt;br /&gt;BroadWin WebAccess Client 'bwocxrun.ocx ' Multiple Remote Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49428&lt;br /&gt;&lt;br /&gt;Microsoft Windows AFD Driver CVE-2011-2005 Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49941&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 'Flic' Movie File Handling Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50404&lt;br /&gt;&lt;br /&gt;phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50331&lt;br /&gt;&lt;br /&gt;Apache APR 'apr_fnmatch()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47820&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49957&lt;br /&gt;&lt;br /&gt;Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47929&lt;br /&gt;&lt;br /&gt;Django Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49573&lt;br /&gt;&lt;br /&gt;NJStar Communicator MiniSMTP Server Remote Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50452&lt;br /&gt;&lt;br /&gt;Joomla! Alameda Component 'storeid' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50451&lt;br /&gt;&lt;br /&gt;Squid Proxy Caching Server CNAME Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50449&lt;br /&gt;&lt;br /&gt;Multiple SKYARC System Products Unspecified Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50448&lt;br /&gt;&lt;br /&gt;Novell Messenger Server Memory Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50443&lt;br /&gt;&lt;br /&gt;net6 Session Hijacking and Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50442&lt;br /&gt;&lt;br /&gt;YaTFTPSvr TFTP Server Directory Traversal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50441&lt;br /&gt;&lt;br /&gt;Openswan Crpyotgraphic Helper Use After Free Remote Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50440&lt;br /&gt;&lt;br /&gt;Joomla! 'com_hmcommunity' Component Multiple Input Validation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50439&lt;br /&gt;&lt;br /&gt;e107 CMS jbShop Plugin 'item_id' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50438&lt;br /&gt;&lt;br /&gt;phpAlbum Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50437&lt;br /&gt;&lt;br /&gt;Joomla Component JEEMA SMS Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50436&lt;br /&gt;&lt;br /&gt;Joomla Component Vik Real Estate Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50435&lt;br /&gt;&lt;br /&gt;WordPress WP Glossary Plugin 'ajax.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50434&lt;br /&gt;&lt;br /&gt;WordPress Classipress Theme Multiple HTML Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50433&lt;br /&gt;&lt;br /&gt;Barter Sites Joomla! Component Multiple HTML Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50432&lt;br /&gt;&lt;br /&gt;PROMOTIC ActiveX Control 'GetPromoticSite' Method Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50430&lt;br /&gt;&lt;br /&gt;GFI Faxmaker Divide-By-Zero Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50429&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-8588326942563908219?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/8588326942563908219/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/11/2.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/8588326942563908219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/8588326942563908219'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/11/2.html' title='2日 水曜日、仏滅'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-1QJxopJSBCI/TrCkjahHRBI/AAAAAAAAA4M/cmpkAEtdtD0/s72-c/Google-20111102-%25E6%25A8%25AA%25E5%25B1%25B1%25E5%25A4%25A7%25E8%25A6%25B3%25E7%2594%259F%25E8%25AA%2595143%25E5%2591%25A8%25E5%25B9%25B4.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-2113136406353274834</id><published>2011-10-31T10:24:00.000+09:00</published><updated>2011-10-31T16:13:30.813+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='友引'/><category scheme='http://www.blogger.com/atom/ns#' term='ハッピーハロウィン'/><title type='text'>31日 月曜日、友引</title><content type='html'>&lt;br /&gt;JVN#56667137 複数のスカイアークシステム製品におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN56667137/index.html&lt;br /&gt;&lt;br /&gt;JVN#41032068 複数のスカイアークシステム製品におけるアクセス制限不備の脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN41032068/index.html&lt;br /&gt;&lt;br /&gt;REMOTE: BroadWin WebAccess SCADA/HMI Client Remote Code Execution&lt;br /&gt;http://www.exploit-db.com/exploits/18051&lt;br /&gt;&lt;br /&gt;DoS/PoC: Oracle DataDirect ODBC Drivers HOST Attribute arsqls24.dll Stack Based Buffer Overflow PoC&lt;br /&gt;http://www.exploit-db.com/exploits/18052&lt;br /&gt;&lt;br /&gt;DoS/PoC: Microsys PROMOTIC 8.1.4 ActiveX GetPromoticSite Unitialized Pointer&lt;br /&gt;http://www.exploit-db.com/exploits/18049&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: right;"&gt;&lt;a href="http://4.bp.blogspot.com/-Y7Ud_7xmI1M/Tq34gonxOMI/AAAAAAAAA4E/SAIhypc1lLU/s1600/Google-20111031-%25E3%2583%258F%25E3%2583%25AD%25E3%2583%25BC%25E3%2582%25A6%25E3%2582%25A3%25E3%2583%25B3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://4.bp.blogspot.com/-Y7Ud_7xmI1M/Tq34gonxOMI/AAAAAAAAA4E/SAIhypc1lLU/s200/Google-20111031-%25E3%2583%258F%25E3%2583%25AD%25E3%2583%25BC%25E3%2582%25A6%25E3%2582%25A3%25E3%2583%25B3.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;+ Linux Kernel Network Bridge NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50417&lt;br /&gt;&lt;br /&gt;[ANNOUNCEMENT] Apache Commons Digester 3.1 released!&lt;br /&gt;http://commons.apache.org/digester/download_digester.cgi&lt;br /&gt;&lt;br /&gt;[courier-announce] Courier and courier-imap builds 20111028&lt;br /&gt;http://www.courier-mta.org/download.php&lt;br /&gt;&lt;br /&gt;UPDATE: HPSBUX02715 SSRT100623 rev.3 - HP-UX Containers (SRP), Local Unauthorized Access and Increased Privileges&lt;br /&gt;https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03057703%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;Benetl, a free ETL tool for postgreSQL, is out in version 3.8&lt;br /&gt;http://www.postgresql.org/about/news.1361&lt;br /&gt;&lt;br /&gt;PostgreSQL Data Sync released&lt;br /&gt;http://www.postgresql.org/about/news.1360&lt;br /&gt;&lt;br /&gt;LedgerSMB 1.3.0 Released&lt;br /&gt;http://www.postgresql.org/about/news.1359&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2329-1] torque - Buffer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37003&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBMU02714 SSRT100244] - HP - Network Node Manager i - Information Disclosure Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36996&lt;br /&gt;&lt;br /&gt;High-Tech Bridge SA : [HTB23052] SPIP - Path Disclosure Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37002&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1402-01] FreeType - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37004&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1409-01] OpenSSL - Security Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37005&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1238-2] Puppet - Man-In-The-Middle Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37006&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1247-1] Nova - Information Disclosure Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37007&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1248-1] KDE-Libs - Spoofing Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37008&lt;br /&gt;&lt;br /&gt;VMware : [VMSA-2011-0013] Multiple Products - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37009&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-311] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37010&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-312] Apple - QuickTime - Code Execution Isshe&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37011&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-313] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37012&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-314] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37013&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-315] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37014&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-316] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37015&lt;br /&gt;&lt;br /&gt;Cisco : [cisco-sa-20111026-webex] Cisco - WebEx Player - Multiple Buffer Overflow Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36997&lt;br /&gt;&lt;br /&gt;Cisco : [cisco-sa-20111026-csa] Cisco - Security Agent - Multiple Code Execution Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36998&lt;br /&gt;&lt;br /&gt;Cisco : [cisco-sa-20111026-cucm] Cisco - Unified Communications Manager - Directory Traversal Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36999&lt;br /&gt;&lt;br /&gt;Cisco : [cisco-sa-20111026-uccx] Cisco - Unified Contact Center Express - Directory Traversal Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37000&lt;br /&gt;&lt;br /&gt;Cisco : [cisco-sa-20111026-camera] Cisco - Video Surveillance IP Cameras - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=37001&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-24] Squid - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36982&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-25] Pure-FTPd - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36983&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-26] libxml2 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36984&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBUX02700 SSRT100506] HP-UX - VEA - Denial-Of-Service and Code Execution Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36972&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1238-1] Puppet - Man-In-The-Middle Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36974&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1239-1] Linux kernel - EC2 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36975&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1240-1] Linux kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36976&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1241-1] Linux Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36977&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1242-1] Linux Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36978&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1243-1] Linux Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36979&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1245-1] Linux Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36980&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-308] Cisco - WebEx Player - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36985&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-309] Novell - iPrint Client - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36986&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-310] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36987&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-296] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36988&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-297] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36989&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-298] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36990&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-299] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36991&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-300] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36992&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-301] Adobe - Reader - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36993&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-302] Adobe - Reader - Buffer Overflow and Code Execution Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36994&lt;br /&gt;&lt;br /&gt;Cisco : Cisco Nexus OS (NX-OS) - Command Injection Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36968&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-22] PostgreSQL - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36995&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-23] Apache - mod_authnz_external - SQL Injection Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36995&lt;br /&gt;&lt;br /&gt;Independant Researcher : zFtp Server - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36981&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:161] postgresql - Weak Encrypted Password Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36964&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1401-01] xen - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36963&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1237-1] PAM - Multiple Denial-Of-Service Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36962&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2326-1] PAM - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36966&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2327-1] libfcgi-perl - Authentication Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36970&lt;br /&gt;&lt;br /&gt;Debian : [DSA 2328-1] Freetype - Denial-Of-Service and Code Execution Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36973&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-21] Asterisk - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36971&lt;br /&gt;&lt;br /&gt;Independant Researcher : [TC-SA-2011-01] OmniTouch - Instant Communication Suite - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36965&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2325-1] kfreebsd-8 - Buffer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36967&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2323-1] radvd security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00205.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2331-1] tor security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00206.html&lt;br /&gt;&lt;br /&gt;[PT-2011-30] Disclosure of sensitive information in D-Link DIR-300 Router&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00204.html&lt;br /&gt;&lt;br /&gt;[PT-2011-29] Arbitrary file reading and arbitrary code execution in Router Manager for D-&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00203.html&lt;br /&gt;&lt;br /&gt;[PT-2011-21] SQL injection vulnerability in OneOrZero AIMS&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00202.html&lt;br /&gt;&lt;br /&gt;[PT-2011-20] Authorization bypass vulnerability in OneOrZero AIMS&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00201.html&lt;br /&gt;&lt;br /&gt;VMSA-2011-0013 VMware third party component updates for VMware vCenter Server, vCenter Updat&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00199.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02715 SSRT100623 rev.2 - HP-UX Containers (SRP), Local Unauthorize&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00198.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02719 SSRT100658 rev.1 - HP-UX Running BIND, Remote Denial of Serv&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00197.html&lt;br /&gt;&lt;br /&gt;ZDI-11-316 : Apple QuickTime H264 Matrix Conversion Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00196.html&lt;br /&gt;&lt;br /&gt;ZDI-11-315 : Apple QuickTime FLC Delta Decompression Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00195.html&lt;br /&gt;&lt;br /&gt;ZDI-11-314 : Apple Quicktime PnPixPat PatType 3 Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00194.html&lt;br /&gt;&lt;br /&gt;ZDI-11-313 : Apple QuickTime FLC RLE Packet Count Decompression Remote Code Execution Vulner&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00192.html&lt;br /&gt;&lt;br /&gt;ZDI-11-312 : Apple QuickTime Atom Hierarachy Argument Size Mismatch Remote Code Execution Vu&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00193.html&lt;br /&gt;&lt;br /&gt;ZDI-11-311 : Apple Quicktime Empty URL Data Handler Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00191.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2330-1] simplesamlphp security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00190.html&lt;br /&gt;&lt;br /&gt;eFront &amp;lt;= 3.6.10 (build 11944) Multiple Security Vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00207.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2329-1] torque security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00174.html&lt;br /&gt;&lt;br /&gt;foofus.net security advisory - Toshiba eStudio Multifunction Printer Information Leakage&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00189.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-26-1 QuickTime 7.7.1&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00188.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-26 ] libxml2: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00187.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-25 ] Pure-FTPd: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00186.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-24 ] Squid: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00185.html&lt;br /&gt;&lt;br /&gt;DDIVRT-2011-35 Cisco Unified Contact Center Express Directory Traversal [CVE-2011-33&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00184.html&lt;br /&gt;&lt;br /&gt;ZDI-11-310 : Adobe Reader Compound Glyph Index Sign Extension Remote Code Execution Vulnerab&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00183.html&lt;br /&gt;&lt;br /&gt;ZDI-11-309 : Novell iPrint Client nipplib.dll GetDriverSettings Remote Code Execution Vulner&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00182.html&lt;br /&gt;&lt;br /&gt;ZDI-11-308 : Cisco WebEx Player ATAS32.DLL linesProcessed Remote Code Execution Vulnerabilit&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00181.html&lt;br /&gt;&lt;br /&gt;ZDI-11-307 : Oracle Java MixerSequencer.nAddControllerEventCallback Remote Code Execution Vu&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00180.html&lt;br /&gt;&lt;br /&gt;ZDI-11-306 : Oracle Java IIOP Deserialization Type Confusion Remote Code Execution Vulnerabi&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00178.html&lt;br /&gt;&lt;br /&gt;ZDI-11-305 : Oracle Java Applet Rhino Script Engine Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00179.html&lt;br /&gt;&lt;br /&gt;ZDI-11-304 : Apple Quicktime Advanced Audio Codec Frame Parsing Remote Code Execution Vulner&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00177.html&lt;br /&gt;&lt;br /&gt;ZDI-11-303 : Apple QuickTime H264 Stream frame_cropping Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00176.html&lt;br /&gt;&lt;br /&gt;SANS AppSec 2012 CFP is Open&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00175.html&lt;br /&gt;&lt;br /&gt;JVN#72640744 複数の D-Link 製品におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN72640744/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#402731 Enspire eClient に SQL インジェクションの脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU402731/index.html&lt;br /&gt;&lt;br /&gt;プレス発表&lt;br /&gt;複数のD-Link製品におけるセキュリティ上の弱点（脆弱性）の注意喚起&lt;br /&gt;http://www.ipa.go.jp/about/press/20111028.html&lt;br /&gt;&lt;br /&gt;The Sub Critical Control? Evidence Collection&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11914&lt;br /&gt;&lt;br /&gt;IBM Lotus Sametime Configuration Servlet Lets Remote Users Obtain Configuration Data&lt;br /&gt;http://www.securitytracker.com/id/1026255&lt;br /&gt;&lt;br /&gt;Cisco NX-OS Command Validation Flaw Lets Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026254&lt;br /&gt;&lt;br /&gt;HP Power Manager 'formExportDataLogs' Buffer Overflow&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8482&lt;br /&gt;&lt;br /&gt;Apple Safari Webkit libxslt Arbitrary File Creation&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8481&lt;br /&gt;&lt;br /&gt;Ubuntu update for backuppc&lt;br /&gt;http://secunia.com/advisories/46621/&lt;br /&gt;&lt;br /&gt;VMware vCenter Products JRE Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46651/&lt;br /&gt;&lt;br /&gt;HP-UX update for BIND&lt;br /&gt;http://secunia.com/advisories/46633/&lt;br /&gt;&lt;br /&gt;VMware ESX Server Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46529/&lt;br /&gt;&lt;br /&gt;Enspire eClient Unspecified SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46638/&lt;br /&gt;&lt;br /&gt;Tor TLS Certificate Reuse User De-Anonymisation Security Issue&lt;br /&gt;http://secunia.com/advisories/46634/&lt;br /&gt;&lt;br /&gt;VMware ESXi Server "sblim-sfcb" Integer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46650/&lt;br /&gt;&lt;br /&gt;Gentoo update for libxml2&lt;br /&gt;http://secunia.com/advisories/46601/&lt;br /&gt;&lt;br /&gt;BackupPC "num" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46615/&lt;br /&gt;&lt;br /&gt;Cisco NX-OS / Unified Computing System "section" and "less" Privilege Escalation Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46569/&lt;br /&gt;&lt;br /&gt;D-Link Products SSH Server Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46637/&lt;br /&gt;&lt;br /&gt;FFFTP Insecure Executable Loading Vulnerability&lt;br /&gt;http://secunia.com/advisories/46649/&lt;br /&gt;&lt;br /&gt;IBM Lotus Sametime Configuration Servlet Authentication Security Issue&lt;br /&gt;http://secunia.com/advisories/46647/&lt;br /&gt;&lt;br /&gt;SUSE update for kernel&lt;br /&gt;http://secunia.com/advisories/46608/&lt;br /&gt;&lt;br /&gt;HP-UX BIND Requests Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2244.php&lt;br /&gt;&lt;br /&gt;Tor Security Update Fixes Multiple Information Disclosure Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2243.php&lt;br /&gt;&lt;br /&gt;IBM DB2 for Linux, UNIX and Windows "STMM" Security Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2242.php&lt;br /&gt;&lt;br /&gt;IBM Lotus Sametime Configuration Servlet Remote Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2241.php&lt;br /&gt;&lt;br /&gt;VMware Products Code Execution and Denial of Service Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2240.php&lt;br /&gt;&lt;br /&gt;Enspire eClient Data Processing Remote SQL Injection Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2239.php&lt;br /&gt;&lt;br /&gt;Winamp Data Processing Multiple Heap and Integer Overflow Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2238.php&lt;br /&gt;&lt;br /&gt;LOCAL: Xorg 1.4 to 1.11.2 File Permission Change PoC&lt;br /&gt;http://www.exploit-db.com/exploits/18040&lt;br /&gt;&lt;br /&gt;LOCAL: GTA SA-MP server.cfg Buffer Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18038&lt;br /&gt;&lt;br /&gt;DoS/PoC: GFI Faxmaker - Fax Viewer v10.0[build 237] DoS (Poc).&lt;br /&gt;http://www.exploit-db.com/exploits/18043&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2311 ZFS Component Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50266&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2312 'ZFS' Sub Component Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50269&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3536 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50262&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-2286 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50265&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2304 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50257&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2313 Local Solaris Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50254&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3508 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50201&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3515 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50235&lt;br /&gt;&lt;br /&gt;Oracle Sun Product Suite CVE-2011-3537 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50259&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3535 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50255&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3534 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50251&lt;br /&gt;&lt;br /&gt;RETIRED: Linux Kernel kexec-tools Multiple Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49944&lt;br /&gt;&lt;br /&gt;Linux Kernel CVE-2011-3589 kexec-tools 'mkdumprd' Utility Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50415&lt;br /&gt;&lt;br /&gt;Empathy 'nickname' Field Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50323&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3541 Remote Networking Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44032&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4469 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46400&lt;br /&gt;&lt;br /&gt;Cisco Nexus OS 'section' and 'less' Local Command Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50347&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business NTLM Credentials Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46411&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business Java Runtime Environment CVE-2010-4454 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46391&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0871 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48142&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0802 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48149&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0864 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48139&lt;br /&gt;&lt;br /&gt;Apache APR 'apr_fnmatch()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47820&lt;br /&gt;&lt;br /&gt;Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47929&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3574 Remote Networking Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44011&lt;br /&gt;&lt;br /&gt;Microsoft Windows Local DNS Cache Poisoning Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50281&lt;br /&gt;&lt;br /&gt;radvd Multiple Local and Remote Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50395&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3573 Same Origin Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44028&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3571 ICC Profile Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43965&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3572 Remote Sound Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44030&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3570 Remote Deployment Toolkit Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44020&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business 'defaultReadObject' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44016&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3568 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44012&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3565 JPEGImageWriter.writeImage Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43985&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3567 Remote 2D Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43992&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3566 ICC Profile Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43988&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3562 Remote 2D Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43979&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3563 BasicServiceImpl Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43999&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3561 Remote CORBA Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44013&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3560 Remote Networking Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44024&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3559 HeadspaceSoundbank.nGetName Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44026&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3557 Remote Swing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44014&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3558 Remote Java Web Start Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44021&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3556 Remote 2D Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43971&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3554 Remote CORBA Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43994&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3555 Remote ActiveX Plug-in Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44038&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3553 Remote Swing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44035&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44023&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3551 Remote Networking Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44009&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3549 HTTP Response Splitting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44027&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3550 Remote Java Web Start Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44040&lt;br /&gt;&lt;br /&gt;Cisco IOS 'ethernet-lldp' Component Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50377&lt;br /&gt;&lt;br /&gt;MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40235&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-3548 Remote JNDI Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44017&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4472 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46404&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4470 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46387&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4471 Remote Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46399&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4474 Remote Java DB Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46407&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4467 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46395&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4422 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46402&lt;br /&gt;&lt;br /&gt;Oracle Java 'Applet2ClassLoader' Class Unsigned Applet Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46388&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business Java Runtime Environment Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46386&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4451 Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46405&lt;br /&gt;&lt;br /&gt;Oracle Java Floating-Point Value Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46091&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4473 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46403&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4475 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46410&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4468 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46393&lt;br /&gt;&lt;br /&gt;Cisco IOS dot1x Port Handling Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50375&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4450 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46397&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46394&lt;br /&gt;&lt;br /&gt;Oracle Java Applet Clipboard Injection Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46406&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4448 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46398&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4447 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46409&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CIFSFindNext()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49295&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47343&lt;br /&gt;&lt;br /&gt;Linux Kernel CIFS Mount Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49626&lt;br /&gt;&lt;br /&gt;Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48687&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0815 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48143&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business ICC Profile Multiple Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48137&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0865 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48147&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0873 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48148&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0867 Remote Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48144&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-0814 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48145&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47796&lt;br /&gt;&lt;br /&gt;X.Org X11 File Read Permission Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50196&lt;br /&gt;&lt;br /&gt;ISC BIND 9 Unspecified Packet Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48566&lt;br /&gt;&lt;br /&gt;Multiple Browser Wild Card Certificate Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42817&lt;br /&gt;&lt;br /&gt;libuser 'luseradd' Default Password Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45791&lt;br /&gt;&lt;br /&gt;SBLIM-SFCB Multiple Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/40475&lt;br /&gt;&lt;br /&gt;OpenSSL Ciphersuite Downgrade Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/45164&lt;br /&gt;&lt;br /&gt;OpenSSL Ciphersuite Modification Allows Disabled Cipher Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45254&lt;br /&gt;&lt;br /&gt;Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/36377&lt;br /&gt;&lt;br /&gt;Plici Search 'p48-search.html' Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50428&lt;br /&gt;&lt;br /&gt;SjXjV 'post.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50426&lt;br /&gt;&lt;br /&gt;D-Link DIR-300 Unspecified Remote Code Execution and Remote File Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50424&lt;br /&gt;&lt;br /&gt;simpleSAMLphp Multiple Remote Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50423&lt;br /&gt;&lt;br /&gt;Joomla! Techfolio Component 'catid' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50422&lt;br /&gt;&lt;br /&gt;Opera Web Browser Escape Sequence Stack Buffer Overflow Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50421&lt;br /&gt;&lt;br /&gt;eFront 'professor.php' Script Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50419&lt;br /&gt;&lt;br /&gt;Empathy 'nickname' Field 'me-type' Event Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50418&lt;br /&gt;&lt;br /&gt;Linux Kernel Network Bridge NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50417&lt;br /&gt;&lt;br /&gt;Tor Directory Remote Information Disclosure Vulnerability Bridge Enumeration Weaknesses&lt;br /&gt;http://www.securityfocus.com/bid/50414&lt;br /&gt;&lt;br /&gt;FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50412&lt;br /&gt;&lt;br /&gt;Touhou Hisouten Unspecified Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50411&lt;br /&gt;&lt;br /&gt;IBM Lotus Sametime Configuration Servlet Authentication Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50410&lt;br /&gt;&lt;br /&gt;bzexe '/tmp/$prog' Insecure Temporary File Creation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50409&lt;br /&gt;&lt;br /&gt;Serendipity Karma Plugin Unspecified Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50408&lt;br /&gt;&lt;br /&gt;BackupPC 'index.cgi' Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50406&lt;br /&gt;&lt;br /&gt;D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50405&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-2113136406353274834?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/2113136406353274834/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/31.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/2113136406353274834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/2113136406353274834'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/31.html' title='31日 月曜日、友引'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Y7Ud_7xmI1M/Tq34gonxOMI/AAAAAAAAA4E/SAIhypc1lLU/s72-c/Google-20111031-%25E3%2583%258F%25E3%2583%25AD%25E3%2583%25BC%25E3%2582%25A6%25E3%2582%25A3%25E3%2583%25B3.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-3691768050682382400</id><published>2011-10-28T09:48:00.002+09:00</published><updated>2011-10-28T16:30:13.340+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='大安'/><title type='text'>28日 金曜日、大安</title><content type='html'>&lt;br /&gt;Trend Micro Mobile Security 7.0 Critical Patch 公開のお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1672&lt;br /&gt;&lt;br /&gt;VMSA-2011-0013: VMware third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX&lt;br /&gt;http://www.vmware.com/security/advisories/VMSA-2011-0013.html&lt;br /&gt;&lt;br /&gt;UPDATE: HS11-019: DoS Vulnerability in Hitachi Web Server&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-019/index.html&lt;br /&gt;&lt;br /&gt;UPDATE: HS11-019: Hitachi Web ServerにおけるRangeヘッダによるDoS脆弱性&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-019/index.html&lt;br /&gt;&lt;br /&gt;プレス発表&lt;br /&gt;複数のD-Link製品におけるセキュリティ上の弱点（脆弱性）の注意喚起&lt;br /&gt;http://www.ipa.go.jp/about/press/20111028.html&lt;br /&gt;&lt;br /&gt;JVNVU#402731 Enspire eClient に SQL インジェクションの脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU402731/index.html&lt;br /&gt;&lt;br /&gt;JVN#50227837 東方緋想天におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN50227837/index.html&lt;br /&gt;&lt;br /&gt;JVN#72640744 複数の D-Link 製品におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN72640744/index.html&lt;br /&gt;&lt;br /&gt;JVN#62336482 FFFTP における実行ファイル読み込みに関する脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN62336482/index.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000089 東方緋想天におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000089.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000092 複数の D-Link 製品におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000092.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000091 FFFTP における実行ファイル読み込みに関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000091.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002597 Cisco CiscoWorks Common Services の Home Page コンポーネントにおける任意のコマンドを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002597.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002596 Cisco Show and Share における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002596.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002595 Cisco Show and Share における複数の管理者用ページにアクセスされる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002595.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002594 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002594.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002593 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002593.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002592 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002592.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002591 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002591.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002590 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002590.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002589 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002589.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002588 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002588.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002587 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002587.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002586 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002586.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002585 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002585.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002584 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002584.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002583 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002583.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002582 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002582.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002581 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002581.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002580 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002580.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002579 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002579.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002578 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002578.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002577 Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002577.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002576 Windows 上で稼働する Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002576.html&lt;br /&gt;&lt;br /&gt;Critical Control 19: Data Recovery Capability&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11905&lt;br /&gt;&lt;br /&gt;Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/36377&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ HPSBUX02719 SSRT100658 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS)&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03070783%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;対象名：HP-UX B.11.11/11.23&lt;br /&gt;&lt;br /&gt;UPDATE: HPSBUX02715 SSRT100623 rev.2 - HP-UX Containers (SRP), Local Unauthorized Access and Increased Privileges&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03057703%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;「マニュアル」のGR4000/GS4000/GS3000マニュアル訂正資料(Ver.10-10-/K対応)を更新しました。&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/network/manual/manualtop.html&lt;br /&gt;&lt;br /&gt;ウェブルートがセキュリティソフトの新版などを展示会に出展&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111027/371598/?ST=security&lt;br /&gt;&lt;br /&gt;シマンテック、約2週間で社内のボットネットを洗い出すサービスを発表&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111027/371549/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002575 FreeBSD の "linux emulation" サポートにおけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002575.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002574 IBM DB2 Express Edition の FreeBSD の db2rspgn における権限を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002574.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002573 QNX Neutrino RTOS の runtime linker におけるファイルを上書きされる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002573.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002572 Oracle Solaris における Remote Quota Server の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002572.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002571 Oracle OpenSSO における認証の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002571.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002570 Oracle Sun Products Suite の Oracle Communications Unified コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002570.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002569 Oracle OpenSSO における認証の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002569.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002568 Oracle Sun Products Suite の Oracle Communications Unified コンポーネントおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002568.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002567 Oracle Sun Products Suite の Oracle Waveset コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002567.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002566 Oracle Solaris 11 Express における iSCSI DataMover の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002566.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002565 racle Solaris における Kernel/Performance Counter BackEnd Module の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002565.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002564 Oracle Solaris における Process File System (procfs) の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002564.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002563 Oracle Solaris における LDAP library の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002563.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002562 Oracle Solaris における ZFS の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002562.html&lt;br /&gt;&lt;br /&gt;Critical Control 18: Incident Response Capabilities&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11899&lt;br /&gt;&lt;br /&gt;Software Update Potpourri&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11902&lt;br /&gt;&lt;br /&gt;Trend Micro InterScan Web Security Lets Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026252&lt;br /&gt;&lt;br /&gt;Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026251&lt;br /&gt;&lt;br /&gt;HP-UX Containers Lets Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026250&lt;br /&gt;&lt;br /&gt;VU#402731: Enspire eClient SQL injection allows authentication bypass&lt;br /&gt;http://www.kb.cert.org/vuls/id/402731&lt;br /&gt;&lt;br /&gt;SUSE update for puppet&lt;br /&gt;http://secunia.com/advisories/46628/&lt;br /&gt;&lt;br /&gt;Debian update for torque&lt;br /&gt;http://secunia.com/advisories/46577/&lt;br /&gt;&lt;br /&gt;HP-UX Containers Unspecified Privilege Escalation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46617/&lt;br /&gt;&lt;br /&gt;Red Hat update for openssl&lt;br /&gt;http://secunia.com/advisories/46629/&lt;br /&gt;&lt;br /&gt;Gentoo update for squid&lt;br /&gt;http://secunia.com/advisories/46604/&lt;br /&gt;&lt;br /&gt;Gentoo update for pure-ftpd&lt;br /&gt;http://secunia.com/advisories/46603/&lt;br /&gt;&lt;br /&gt;Apple QuickTime Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46618/&lt;br /&gt;&lt;br /&gt;HP Network Node Manager i JMX Console Security Bypass Security Issue&lt;br /&gt;http://secunia.com/advisories/46627/&lt;br /&gt;&lt;br /&gt;Libxml2 Two XSLT Double Free Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46632/&lt;br /&gt;&lt;br /&gt;SPIP Unspecified SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46622/&lt;br /&gt;&lt;br /&gt;Winamp Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/45279/&lt;br /&gt;&lt;br /&gt;Cisco Multiple Products Directory Traversal Vulnerability&lt;br /&gt;http://secunia.com/advisories/46600/&lt;br /&gt;&lt;br /&gt;Trend Micro InterScan Web Security Suite "patchCmd" Privilege Escalation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46610/&lt;br /&gt;&lt;br /&gt;Cisco WebEx Player WRF File Processing Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46607/&lt;br /&gt;&lt;br /&gt;Oracle Solaris Vino Framebuffer Update Handling Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46619/&lt;br /&gt;&lt;br /&gt;Joomla! YJ Contact Us Component "view" Local File Inclusion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46588/&lt;br /&gt;&lt;br /&gt;Fedora update for radvd&lt;br /&gt;http://secunia.com/advisories/46626/&lt;br /&gt;&lt;br /&gt;Online Subtitles Workshop "comment" Script Insertion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46616/&lt;br /&gt;&lt;br /&gt;Drupal Organic groups Module Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/46623/&lt;br /&gt;&lt;br /&gt;Cisco Video Surveillance IP Cameras RTSP TCP Packets Processing Denial of Service&lt;br /&gt;http://secunia.com/advisories/46612/&lt;br /&gt;&lt;br /&gt;Cisco Video Surveillance IP Cameras RTSP TCP Packets Processing Denial of Service&lt;br /&gt;http://secunia.com/advisories/46611/&lt;br /&gt;&lt;br /&gt;OpenLDAP "UTF8StringNormalize()" Off-by-One Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46599/&lt;br /&gt;&lt;br /&gt;Cisco Security Agent Outside In Technology File Processing Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46631/&lt;br /&gt;&lt;br /&gt;Novell iPrint Client "GetDriverSettings()" Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46606/&lt;br /&gt;&lt;br /&gt;Winamp Data Processing Multiple Heap and Integer Overflow Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2238.php&lt;br /&gt;&lt;br /&gt;HP-UX Containers Local Unauthorized Access and Privilege Escalation&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2237.php&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris Vino GNOME Desktop Sharing Server Denial of Service&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2236.php&lt;br /&gt;&lt;br /&gt;OpenLDAP "UTF8StringNormalize()" Remote Off-by-one Buffer Overflow&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2235.php&lt;br /&gt;&lt;br /&gt;Cisco WebEx Player WRF and ATAS32 Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2234.php&lt;br /&gt;&lt;br /&gt;Cisco Security Agent Outside-In Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2233.php&lt;br /&gt;&lt;br /&gt;Cisco Video Surveillance IP Cameras Denial of Service Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2232.php&lt;br /&gt;&lt;br /&gt;Cisco Unified Contact Center Express Directory Traversal Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2231.php&lt;br /&gt;&lt;br /&gt;Organic Groups for Drupal Access Bypass Remote Unauthorized Access&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2230.php&lt;br /&gt;&lt;br /&gt;Apple QuickTime Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2229.php&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 Pict File Handling Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50399&lt;br /&gt;&lt;br /&gt;RETIRED: Apple QuickTime Prior To 7.7.1 Multiple Arbitrary Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50388&lt;br /&gt;&lt;br /&gt;Apple Mac OS X FLIC Files CVE-2011-3223 Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50101&lt;br /&gt;&lt;br /&gt;Apple QuickTime CVE-2011-3221 Movie File Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50131&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 TKHD Atoms Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50403&lt;br /&gt;&lt;br /&gt;phpScheduleIt 'reserve.php' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/31520&lt;br /&gt;&lt;br /&gt;Apple Mac OS X FlashPix Files CVE-2011-3222 Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50100&lt;br /&gt;&lt;br /&gt;Apple Mac OS X QuickTime Player CVE-2011-3228 Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50127&lt;br /&gt;&lt;br /&gt;Apple Mac OS X QuickTime 'Save for Web' Feature HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50122&lt;br /&gt;&lt;br /&gt;Apple Mac OS X CoreMedia H.264 Encoded Movie Files Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50068&lt;br /&gt;&lt;br /&gt;Apple QuickTime CVE-2011-3220 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50130&lt;br /&gt;&lt;br /&gt;X.Org X11 File Read Permission Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50196&lt;br /&gt;&lt;br /&gt;X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50002&lt;br /&gt;&lt;br /&gt;OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49469&lt;br /&gt;&lt;br /&gt;Linux Kernel GHASH Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50366&lt;br /&gt;&lt;br /&gt;torque 'job name' Argument Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48374&lt;br /&gt;&lt;br /&gt;Vino Framebuffer Request Processing Multiple Remote Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47681&lt;br /&gt;&lt;br /&gt;Mozilla Firefox RegExp Remote Integer Underflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49809&lt;br /&gt;&lt;br /&gt;libxml2 'XPATH' Expressions Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45617&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 'Flic' Movie File Handling Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50404&lt;br /&gt;&lt;br /&gt;RoundCube Webmail Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50402&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 Movie File Handling Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50401&lt;br /&gt;&lt;br /&gt;Apple QuickTime Prior To 7.7.1 Movie File Handling Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50400&lt;br /&gt;&lt;br /&gt;Enspire eClient Unspecified SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50398&lt;br /&gt;&lt;br /&gt;HP-UX Containers Unspecified Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50396&lt;br /&gt;&lt;br /&gt;radvd Multiple Local and Remote Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50395&lt;br /&gt;&lt;br /&gt;Toshiba e-Studio Devices Password Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50392&lt;br /&gt;&lt;br /&gt;eFront 3.6.10 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50391&lt;br /&gt;&lt;br /&gt;SPIP Versions Prior to 1.9.2k Unspecified SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50390&lt;br /&gt;&lt;br /&gt;WordPress WPtouch Plugin 'ajax.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50389&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-3691768050682382400?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/3691768050682382400/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/28.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3691768050682382400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3691768050682382400'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/28.html' title='28日 金曜日、大安'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-9201755543789714426</id><published>2011-10-27T13:12:00.000+09:00</published><updated>2011-10-27T13:12:21.760+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><category scheme='http://www.blogger.com/atom/ns#' term='QuickTime'/><title type='text'>QuickTime 7.7.1 のセキュリティアップデート</title><content type='html'>&lt;br /&gt;&lt;pre wrap=""&gt;About the security content of QuickTime 7.7.1&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;a class="moz-txt-link-freetext" href="http://support.apple.com/kb/HT5016"&gt;http://support.apple.com/kb/HT5016&lt;/a&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;上記 URL の QuickTime 7.7.1 のセキュリティアップデートの翻訳&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;pre wrap=""&gt;1) QuickTime&lt;br /&gt;　QuickTime が H.264 エンコードされた動画ファイルを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3219)&lt;br /&gt;&lt;br /&gt;2) QuickTime&lt;br /&gt;　QuickTime が動画ファイルの URL データハンドラを取り扱う際に初期化されてないメモリへアクセスすることが原因で、メモリ上のコンテンツを取得される脆弱性。(CVE-2011-3220)&lt;br /&gt;&lt;br /&gt;3) QuickTime&lt;br /&gt;　QuickTime が動画ファイルの atom 階層を取り扱う際に実装上の欠陥が存在することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-20113221)&lt;br /&gt;&lt;br /&gt;4) QuickTime&lt;br /&gt;　QuickTime Player の "Save for Web" にクロスサイトスクリプティングの欠陥が存在することが原因で、ローカルドメインからスクリプトを注入される脆弱性。(CVE-2011-3218)&lt;br /&gt;&lt;br /&gt;5) QuickTime&lt;br /&gt;　QuickTime が FlashPix ファイルを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3222)&lt;br /&gt;&lt;br /&gt;6) QuickTime&lt;br /&gt;　QuickTime が FLIC ファイルを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3223)&lt;br /&gt;&lt;br /&gt;7) QuickTime&lt;br /&gt;　QuickTime が動画ファイルを取り扱う際に複数のメモリ破壊が発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3228)&lt;br /&gt;&lt;br /&gt;8) QuickTime&lt;br /&gt;　PICT ファイルの取り扱いにおいて整数オーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3247)&lt;br /&gt;&lt;br /&gt;9) QuickTime&lt;br /&gt;　QuickTime の動画ファイルに埋め込まれたフォントテーブルの取り扱いにおいて署名問題が存在することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3248)&lt;br /&gt;&lt;br /&gt;10) QuickTime&lt;br /&gt;　FLC エンコードされた動画ファイルの取り扱いにおいてバッファオーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3249)&lt;br /&gt;&lt;br /&gt;11) QuickTime&lt;br /&gt;　JPEG2000 エンコードされた動画ファイルの取り扱いにおいて整数オーバーフローが発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3250)&lt;br /&gt;&lt;br /&gt;12) QuickTime&lt;br /&gt;　QuickTime の動画ファイル内の TKHD atom の取り扱いにおいてメモリ破壊が発生することが原因で、アプリケーションを異常終了させたり任意のコードを実行されたりする脆弱性。(CVE-2011-3251)&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-9201755543789714426?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/9201755543789714426/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/quicktime-771.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/9201755543789714426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/9201755543789714426'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/quicktime-771.html' title='QuickTime 7.7.1 のセキュリティアップデート'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-3171182931779158013</id><published>2011-10-27T11:06:00.000+09:00</published><updated>2011-10-27T16:31:14.900+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='仏滅'/><title type='text'>27日 木曜日、仏滅</title><content type='html'>&lt;br /&gt;Lotus Notes の一太郎ファイルビューアーにおけるバッファーオーバーフローの潜在的な脆弱性の問題&lt;br /&gt;http://www-06.ibm.com/ibm/jp/security/info/lotus/si20111025a.html&lt;br /&gt;&lt;br /&gt;JVNVU#784211 Apple Quicktime における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU784211/index.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002561 Oracle Supply Chain Products Suite の Oracle Agile Product Supplier Collaboration for Process コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002561.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002560 Oracle Industry Applications の Health Sciences - Oracle Thesaurus Management System コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002560.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002559 Oracle Industry Applications の Health Sciences - Oracle Clinical、Remote Data Capture における脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002559.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002558 Oracle Virtualization の Sun Ray コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002558.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002557 Oracle Linux の Oracle Validated 処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002557.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002556 複数の Oracle Sun 製品における Integrated Lights Out Manager CLI の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002556.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002555 Oracle PeopleSoft Enterprise HRMS における JPM の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002555.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002554 Oracle PeopleSoft Enterprise HRMS における Talent Acquisition Manager の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002554.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002553 Oracle PeopleSoft Enterprise HRMS における Candidate Gateway の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002553.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002552 Oracle PeopleSoft Enterprise PeopleTools におけるセキュリティの処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002529.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002551 Oracle PeopleSoft Enterprise PeopleTools における Personalization の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002551.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002550 Oracle PeopleSoft Enterprise HRMS における eDevelopment の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002550.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002549 Oracle PeopleSoft Enterprise HRMS における eProfile の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025549.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002548 Oracle Siebel CRM の Siebel Core - UIF Server コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025548.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002547 Oracle Siebel CRM の Siebel Core - UIF Client コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025547.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002546 Oracle Siebel CRM の Siebel Apps - Marketing コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025546.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002545 Oracle Solaris における Zone の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025545.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002544 Oracle Solaris における Kernel/Filesystem の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025544.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002543 Oracle Solaris における DTrace Software Library の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025543.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002542 Oracle Solaris における Network Status Monitor の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025542.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002541 Oracle Solaris における ZFS の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025541.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002540 Oracle Solaris における ZFS の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025540.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002539 Oracle Solaris における libnsl の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025539.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002538 Oracle Solaris における xscreensaver の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025538.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002537 Oracle Solaris における ZFS の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025537.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002536 Oracle Sun Products Suite の複数の製品における Web Container の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025536.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002535 Oracle Database Server の Application Express コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025535.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002534 Oracle Database Server の Core RDBMS コンポーネントおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025534.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002533 Oracle Database Server の Database Vault コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025533.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002532 Oracle Database Server の Database Vault コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025532.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002531 Oracle Database Server の Oracle Text コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025531.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002530 Oracle E-Business Suite の Oracle Applications Framework コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025530.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002529 Oracle E-Business Suite の Oracle Application Object Library コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025529.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002528 Oracle E-Business Suite の Oracle Application Object Library コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025528.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002527 Oracle E-Business Suite の Oracle Application Object Library コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025527.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002526 Oracle E-Business Suite の Oracle Application Object Library コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025526.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002525 Oracle Fusion Middleware の Oracle Outside In Technology コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025525.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002524 Oracle Fusion Middleware の Oracle Web Services Manager コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025524.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002523 Oracle Fusion Middleware の Oracle Business Intelligence Enterprise Edition コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025523.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002522 Oracle WebLogic Server における Web Services の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025522.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002521 Oracle WebLogic Server における JMS の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025521.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002520 Oracle WebLogic Server における WLS Security の処理に関する脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025520.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002519 Oracle Fusion Middleware の Oracle Containers for J2EE コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025519.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002518 Oracle Fusion Middleware の Oracle WebLogic Portal コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025158.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002517 Oracle Fusion Middleware の Oracle Web Services Manager コンポーネントにおける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-0025157.html&lt;br /&gt;&lt;br /&gt;Critical Control 17:Penetration Tests and Red Team Exercises&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11887&lt;br /&gt;&lt;br /&gt;Mozilla Firefox RegExp Remote Integer Underflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49809&lt;br /&gt;&lt;br /&gt;libxml2 'XPATH' Expressions Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45617&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+- HPSBUX02715 SSRT100623 rev.1 - HP-UX Containers (SRP), Local Unauthorized Access and Increased Privileges&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03057703%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;+ GCC 4.6.2 released&lt;br /&gt;http://gcc.gnu.org/gcc-4.6/&lt;br /&gt;&lt;br /&gt;+ SA46591: Linux Kernel XFS "xfs_readlink()" Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46591/&lt;br /&gt;http://www.securityfocus.com/bid/50370&lt;br /&gt;&lt;br /&gt;+ SA46584: Linux Kernel ghash NULL Pointer Dereference Vulnerability&lt;br /&gt;http://secunia.com/advisories/46584/&lt;br /&gt;http://www.securityfocus.com/bid/50366&lt;br /&gt;&lt;br /&gt;+ OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50384&lt;br /&gt;&lt;br /&gt;++ Cisco IOS Fingerprinting ICMPv6 Echo Request Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50379&lt;br /&gt;&lt;br /&gt;++ Cisco IOS 'ethernet-lldp' Component Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50377&lt;br /&gt;&lt;br /&gt;++ Cisco IOS dot1x Port Handling Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50375&lt;br /&gt;&lt;br /&gt;- HPSBMU02714 SSRT100244 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Unauthorized Disclosure of Information&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03057508%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;- Multiple Denial of Service vulnerabilities in Vino GNOME desktop sharing server&lt;br /&gt;http://blogs.oracle.com/sunsecurity/entry/multiple_denial_of_service_vulnerabilities&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Apache Archiva 1.4-M1 Released!&lt;br /&gt;http://archiva.apache.org/docs/1.4-M1/release-notes.html&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Apache Derby 10.8.2.2 released&lt;br /&gt;http://db.apache.org/derby/derby_downloads.html&lt;br /&gt;&lt;br /&gt;RHSA-2011:1409&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Moderate: openssl security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1409.html&lt;br /&gt;&lt;br /&gt;About the security content of QuickTime 7.7.1&lt;br /&gt;http://support.apple.com/kb/HT5016&lt;br /&gt;&lt;br /&gt;Google Chrome 15.0.874.106 released&lt;br /&gt;http://googlechromereleases.blogspot.com/2011/10/stable-channel-update_26.html&lt;br /&gt;&lt;br /&gt;CESA-2011:1402 (freetype)&lt;br /&gt;http://lwn.net/Alerts/464550/&lt;br /&gt;&lt;br /&gt;HPSBUX02702 SSRT100606 rev.5 - HP-UX Apache Web Server, Remote Denial of Service (DoS)&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c02997184%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;PHP 5.4 beta2 released&lt;br /&gt;http://www.php.net/archive/2011.php#id-1&lt;br /&gt;&lt;br /&gt;ZDI-11-302 : Adobe Reader U3D TIFF Resource Buffer Overflow Remote Code Execution Vulnerabil&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00173.html&lt;br /&gt;&lt;br /&gt;ZDI-11-301 : Adobe Reader U3D PICT 0Eh Encoding Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00172.html&lt;br /&gt;&lt;br /&gt;ZDI-11-300 : Adobe Reader U3D PICT 10h Encoding Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00171.html&lt;br /&gt;&lt;br /&gt;ZDI-11-299 : Adobe Reader PICT Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00170.html&lt;br /&gt;&lt;br /&gt;ZDI-11-298 : Adobe Reader U3D IFF RGBA Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00169.html&lt;br /&gt;&lt;br /&gt;ZDI-11-297 : Adobe Reader U3D PCX Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00168.html&lt;br /&gt;&lt;br /&gt;ZDI-11-296 : Adobe Reader BMP Image RLE Decoding Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00166.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Cisco Security Agent Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00167.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Buffer Overflow Vulnerabilities in the Cisco WebEx Player&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00165.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Cisco Unified Contact Center Express Directory Traversal Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00164.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00163.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Cisco Unified Communications Manager Directory Traversal Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00162.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBMU02714 SSRT100244 rev.1 - HP Network Node Manager i (NNMi) for HP-U&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00161.html&lt;br /&gt;&lt;br /&gt;Path disclosure in SPIP&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00160.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-23 ] Apache mod_authnz_external: SQL injection&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00159.html&lt;br /&gt;&lt;br /&gt;Androidを狙う新手口、アプリをアップデートするとウイルスに&lt;br /&gt;エフセキュアが報告、インストール時に追加のアクセス許可&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111027/371504/?ST=security&lt;br /&gt;&lt;br /&gt;衆院事務局がウイルス感染問題で初会合、「報道でサイバー攻撃の可能性を認識」&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111027/371481/?ST=security&lt;br /&gt;&lt;br /&gt;Cisco Video Surveillance IP Cameras RTSP Processing Flaw Lets Remote Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026248&lt;br /&gt;&lt;br /&gt;Cisco WebEx Player Buffer Overflows Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026244&lt;br /&gt;&lt;br /&gt;Cisco Unified Communications Manager Directory Traversal Flaw Lets Remote Users Obtain Files&lt;br /&gt;http://www.securitytracker.com/id/1026243&lt;br /&gt;&lt;br /&gt;Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026242&lt;br /&gt;&lt;br /&gt;WordPress BackWPUp Remote Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6U03G1P2UA.html&lt;br /&gt;&lt;br /&gt;Linux Kernel XFS "xfs_readlink()" Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46591/&lt;br /&gt;&lt;br /&gt;WordPress NextGEN Gallery Plugin Cross-Site Scripting and Request Forgery Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46602/&lt;br /&gt;&lt;br /&gt;phpMyFAQ Code Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46582/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux-ti-omap4&lt;br /&gt;http://secunia.com/advisories/46571/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux&lt;br /&gt;http://secunia.com/advisories/46585/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux-mvl-dove&lt;br /&gt;http://secunia.com/advisories/46587/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux-ec2&lt;br /&gt;http://secunia.com/advisories/46589/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux&lt;br /&gt;http://secunia.com/advisories/46590/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux-lts-backport-maverick&lt;br /&gt;http://secunia.com/advisories/46595/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux-fsl-imx51&lt;br /&gt;http://secunia.com/advisories/46598/&lt;br /&gt;&lt;br /&gt;Ubuntu update for nova&lt;br /&gt;http://secunia.com/advisories/46597/&lt;br /&gt;&lt;br /&gt;Google Chrome Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46594/&lt;br /&gt;&lt;br /&gt;OpenStack Compute (Nova) "EC2_SECRET_KEY" Credentials Disclosure Weakness&lt;br /&gt;http://secunia.com/advisories/46576/&lt;br /&gt;&lt;br /&gt;SUSE update for hplip&lt;br /&gt;http://secunia.com/advisories/46593/&lt;br /&gt;&lt;br /&gt;Linux Kernel ghash NULL Pointer Dereference Vulnerability&lt;br /&gt;http://secunia.com/advisories/46584/&lt;br /&gt;&lt;br /&gt;Ubuntu update for kde4libs&lt;br /&gt;http://secunia.com/advisories/46592/&lt;br /&gt;&lt;br /&gt;Gentoo update for mod_authnz_external&lt;br /&gt;http://secunia.com/advisories/46581/&lt;br /&gt;&lt;br /&gt;IBM WebSphere ILOG Rule Team Server Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46574/&lt;br /&gt;&lt;br /&gt;HP Network Node Manager i (NNMi) Remote Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2228.php&lt;br /&gt;&lt;br /&gt;IBM WebSphere ILOG Rule Team Server Cross Site Scripting Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2227.php&lt;br /&gt;&lt;br /&gt;phpMyFAQ ImageManager Library Remote PHP Code Injection Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2226.php&lt;br /&gt;&lt;br /&gt;Google Chrome Multiple Memory Corruption and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2225.php&lt;br /&gt;&lt;br /&gt;Novell iPrint Client for Windows Activex Remote Code Execution Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2224.php&lt;br /&gt;&lt;br /&gt;Novell ZENworks 7 Handheld Management Directory Traversal Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2223.php&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 13.0.782.215 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49279&lt;br /&gt;&lt;br /&gt;libxml2 'XPATH' Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44779&lt;br /&gt;&lt;br /&gt;libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48056&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 14.0.835.163 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49658&lt;br /&gt;&lt;br /&gt;GNU libc glob(3) 'pattern' Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47671&lt;br /&gt;&lt;br /&gt;Multiple Vendors STARTTLS Implementation Plaintext Arbitrary Command Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46767&lt;br /&gt;&lt;br /&gt;Squid 'DNS' Reply Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42645&lt;br /&gt;&lt;br /&gt;Squid Web Proxy Cache HTCP Request Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/38212&lt;br /&gt;&lt;br /&gt;Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/36091&lt;br /&gt;&lt;br /&gt;Squid Proxy String Processing NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42982&lt;br /&gt;&lt;br /&gt;Squid Header-Only Packets Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37522&lt;br /&gt;&lt;br /&gt;Squid Proxy Gopher Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49356&lt;br /&gt;&lt;br /&gt;Squid Multiple Remote Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/35812&lt;br /&gt;&lt;br /&gt;Cisco WebEx WRF and ATAS32 File Format Multiple Remote Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50373&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2011-3000 HTTP Response Splitting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49849&lt;br /&gt;&lt;br /&gt;Mozilla Firefox CVE-2011-2995 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49810&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey Enter Key Dialog Bypass Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49811&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey/Thunderbird CVE-2011-2999 Cross Domain Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49848&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2441 Multiple Remote Stack Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49581&lt;br /&gt;&lt;br /&gt;Novell iPrint Client 'nipplib.dll' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50367&lt;br /&gt;&lt;br /&gt;X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50002&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50220&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3521 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50215&lt;br /&gt;&lt;br /&gt;Oracle Java SE Rhino Script Engine Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50218&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2436 Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49578&lt;br /&gt;&lt;br /&gt;Apple iTunes CoreAudio (CVE-2011-3252) Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50065&lt;br /&gt;&lt;br /&gt;Apple Mac OS X CoreMedia H.264 Encoded Movie Files Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50068&lt;br /&gt;&lt;br /&gt;OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49469&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel CVE-2011-3347 VLAN Packets Handling Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50312&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel Ethernet Bridge Interface Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50313&lt;br /&gt;&lt;br /&gt;Linux Kernel TCP Sequence Number Generation Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49289&lt;br /&gt;&lt;br /&gt;Linux Kernel Generic Receive Offload (GRO) CVE-2011-2723 Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48929&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2433 Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49576&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2435 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49575&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader U3D Tiff Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49572&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2434 Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49577&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2438 Multiple Remote Stack Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49580&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2437 Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49579&lt;br /&gt;&lt;br /&gt;Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47437&lt;br /&gt;&lt;br /&gt;Oracle Outside In Technology Lotus 123 File Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47435&lt;br /&gt;&lt;br /&gt;Retired: Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50361&lt;br /&gt;&lt;br /&gt;IBM WebSphere ILOG Rule Team Server 'project' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50056&lt;br /&gt;&lt;br /&gt;FreeType Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;KDE KSSL Common Name SSL Certificate Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49925&lt;br /&gt;&lt;br /&gt;Cyrus IMAP Server 'split_wildmats()' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49534&lt;br /&gt;&lt;br /&gt;phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50385&lt;br /&gt;&lt;br /&gt;OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50384&lt;br /&gt;&lt;br /&gt;NextGEN Gallery for WordPress Cross Site Scripting and Cross Site Request Forgery Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50383&lt;br /&gt;&lt;br /&gt;Online Subtitles Workshop 'video_comments.php' HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50382&lt;br /&gt;&lt;br /&gt;XAMPP Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50381&lt;br /&gt;&lt;br /&gt;Trendmicro IWSS 3.1 Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50380&lt;br /&gt;&lt;br /&gt;Cisco IOS Fingerprinting ICMPv6 Echo Request Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50379&lt;br /&gt;&lt;br /&gt;Cisco Adaptive Security Appliances (ASA) 5500 'platform-sw' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50378&lt;br /&gt;&lt;br /&gt;Cisco IOS 'ethernet-lldp' Component Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50377&lt;br /&gt;&lt;br /&gt;Cisco CiscoWorks Common Services Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50376&lt;br /&gt;&lt;br /&gt;Cisco IOS dot1x Port Handling Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50375&lt;br /&gt;&lt;br /&gt;PrestaShop Presta2PhpList Module 'list' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50374&lt;br /&gt;&lt;br /&gt;Multiple Cisco Products (CVE-2011-3315) Directory Traversal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50372&lt;br /&gt;&lt;br /&gt;Cisco Video Surveillance 2421, 2500, and 2600 Series IP Cameras Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50371&lt;br /&gt;&lt;br /&gt;Linux Kernel 'xfs_readlink()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50370&lt;br /&gt;&lt;br /&gt;Novell ZENworks Handheld Management 'Common.dll' Directory Traversal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50369&lt;br /&gt;&lt;br /&gt;IBM WebSphere ILOG Rule Team Server Unspecified Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50368&lt;br /&gt;&lt;br /&gt;Linux Kernel GHASH Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50366&lt;br /&gt;&lt;br /&gt;vtiger CRM 'index.php' Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50364&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-3171182931779158013?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/3171182931779158013/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/27.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3171182931779158013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3171182931779158013'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/27.html' title='27日 木曜日、仏滅'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-1590278429345287927</id><published>2011-10-26T17:28:00.000+09:00</published><updated>2011-10-26T17:28:03.344+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='友引'/><title type='text'>26日 水曜日、友引</title><content type='html'>&lt;br /&gt;+ Linux kernel 3.0.8 released&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.8&lt;br /&gt;&lt;br /&gt;+ Important: freetype security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1402.html&lt;br /&gt;&lt;br /&gt;+ Sudo 1.7.8p1, 1.8.3p1 released&lt;br /&gt;http://www.sudo.ws/sudo/stable.html#1.7.8p1&lt;br /&gt;http://www.sudo.ws/sudo/stable.html#1.8.3p1&lt;br /&gt;&lt;br /&gt;- Linux Kernel 'net/can/raw.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47835&lt;br /&gt;&lt;br /&gt;- Linux Kernel 'bcm_release()' NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47503&lt;br /&gt;&lt;br /&gt;? Linux Kernel 'perf' Utility Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49140&lt;br /&gt;&lt;br /&gt;? Linux Kernel KSM Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48101&lt;br /&gt;&lt;br /&gt;Google Chrome 15.0.874.102 released&lt;br /&gt;http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html&lt;br /&gt;&lt;br /&gt;SafeSyncモバイルクライアント バージョン1.3（iOS/Android）にログインできない現象について&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1671&lt;br /&gt;&lt;br /&gt;zFtp Server &amp;lt;= 2011-04-13 | "STAT,CWD" Remote Denial of Service Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00155.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-22 ] PostgreSQL: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00156.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2328-1] freetype security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00154.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBUX02700 SSRT100506 rev.2 - HP-UX running VEA, Remote Denial of Servi&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00153.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:161 ] postgresql&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00152.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-21 ] Asterisk: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00151.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2327-1] libfcgi-perl security-update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00150.html&lt;br /&gt;&lt;br /&gt;「DMで偽サイトに誘導」――Twitter悪用のフィッシングに注意&lt;br /&gt;英ソフォスが報告、目的はパスワードの奪取&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111026/371422/?ST=security&lt;br /&gt;&lt;br /&gt;テラス、SSHリモート操作を動画記録する監査証跡SaaSを開始&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111025/371350/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002516 Apple Mac OS X のオープンディレクトリにおけるパスワードデータを閲覧される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002516.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002515 Apple Mac OS X の QuickTime における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002515.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002514 Apple Mac OS X の libsecurity における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002514.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002513 Apple Mac OS X のオープンディレクトリにおけるパスワード要求を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002513.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002512 Apple Mac OS X の SMB ファイルサーバコンポーネントにおける閲覧制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002512.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002511 Apple Mac OS X の User Documentation コンポーネントにおける任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002511.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002510 Apple Mac OS X の QuickTime におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002510.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002509 Apple Mac OS X の QuickTime におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002509.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002508 Apple Mac OS X の QuickTime における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002508.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002507 Apple Mac OS X の QuickTime における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002507.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002506 Django の CSRF 保護メカニズムにおける認証されずに偽造されたリクエストを誘発される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002506.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002505 Django におけるキャッシュポイズニング攻撃を誘発される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002505.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002504 Django の URLField 実装内にある verify_exists 機能における任意の GET リクエストを誘発される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002504.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002503 Django の URLField 実装内にある verify_exists 機能におけるサービス運用妨害 (リソース消費) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002503.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002502 Django の django.contrib.sessions におけるセッションを変更される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002502.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002501 Cisco TelePresence Video Communication Servers の管理インターフェイスにおけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002501.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002500 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002500.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002499 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002499.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002498 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002498.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002497 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002497.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002496 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002496.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002495 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002495.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002494 Apple Mac OS X の Application Firewall のデバッグログ機能における権限を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002494.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002493 Apple iOS および Apple TV のカーネルにおけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002493.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002492 Apple iOS および Mac OS X の CFNetwork における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002492.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002491 Mac OS X 上で稼動する Apple Safari のプライベートブラウズ機能におけるユーザを追跡可能な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002491.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002490 Mac OS X 上で動作する Apple Safari の SSL 実装における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002490.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002489 Mac OS X 上で動作する Apple Safari における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002489.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002488 Apple Safari におけるディレクトリトラバーサルの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002488.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002487 Apple Mac OS X の Apple Type Services (ATS) における整数符号エラーの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002487.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002486 Apple Mac OS の Open Directory におけるパスワード変更の制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002486.html&lt;br /&gt;&lt;br /&gt;Critical Control 17:Penetration Tests and Red Team Exercises&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11887&lt;br /&gt;&lt;br /&gt;Recurring reporting made easy?&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11884&lt;br /&gt;&lt;br /&gt;VMware ESXi and ESX updates to third party libraries and ESX Service Console&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8480&lt;br /&gt;&lt;br /&gt;HP MFP Digital Sending Software Running on Window Local Information Disclosure&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8479&lt;br /&gt;&lt;br /&gt;astersik open source 1.8.7 Remote crash vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8478&lt;br /&gt;&lt;br /&gt;OCS Inventory NG 2.0.1 Persistent XSS&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8477&lt;br /&gt;&lt;br /&gt;ibm db2 9.7 Exploiting the linker&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8476&lt;br /&gt;&lt;br /&gt;Linux Kernel ext4 Extent Splitting Bug in ext4_ext_convert_to_initialized() Lets Local Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026240&lt;br /&gt;&lt;br /&gt;Xen Buffer Overflow in SCSI Emulation Lets a Local Guest User Cause the Guest to Crash&lt;br /&gt;http://www.securitytracker.com/id/1026238&lt;br /&gt;&lt;br /&gt;Cisco Network Registrar Default Credentials Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6L03H1F2UE.html&lt;br /&gt;&lt;br /&gt;Cisco IOS XR Software IP Packet Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6P03L1F2UU.html&lt;br /&gt;&lt;br /&gt;Cisco Media Experience Engine 5600 Default Credentials Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6N03J1F2UM.html&lt;br /&gt;&lt;br /&gt;Cisco IOS XR Software SSHv1 Denial of Service Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6K03G1F2UK.html&lt;br /&gt;&lt;br /&gt;Cisco Unified IP Phones 7900 Series Multiple Vulnerabilities&lt;br /&gt;http://www.securiteam.com/securitynews/6M03I1F2UW.html&lt;br /&gt;&lt;br /&gt;Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6Q03M1F2UO.html&lt;br /&gt;&lt;br /&gt;Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities&lt;br /&gt;http://www.securiteam.com/securitynews/6O03K1F2UC.html&lt;br /&gt;&lt;br /&gt;PrestaShop Presta2PhpList Module "list" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46531/&lt;br /&gt;&lt;br /&gt;Red Hat update for freetype&lt;br /&gt;http://secunia.com/advisories/46596/&lt;br /&gt;&lt;br /&gt;McAfee Web Gateway Unspecified Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46570/&lt;br /&gt;&lt;br /&gt;Gentoo update for postgresql&lt;br /&gt;http://secunia.com/advisories/46568/&lt;br /&gt;&lt;br /&gt;Alcatel-Lucent OmniTouch 8400 Instant Communication Suite Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46562/&lt;br /&gt;&lt;br /&gt;Alcatel-Lucent Business integrated Communication Solution Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46565/&lt;br /&gt;&lt;br /&gt;Ubuntu update for puppet&lt;br /&gt;http://secunia.com/advisories/46578/&lt;br /&gt;&lt;br /&gt;Zope Unspecified Vulnerability&lt;br /&gt;http://secunia.com/advisories/46586/&lt;br /&gt;&lt;br /&gt;Novell Netware HTTP Server ByteRange Filter Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46572/&lt;br /&gt;&lt;br /&gt;zFTPServer "CWD" Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46559/&lt;br /&gt;&lt;br /&gt;Puppet "certdnsnames" Puppet Master Impersonation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46550/&lt;br /&gt;&lt;br /&gt;Wing FTP Server Unspecified Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/46413/&lt;br /&gt;&lt;br /&gt;Wing FTP Server Unspecified Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/46558/&lt;br /&gt;&lt;br /&gt;SUSE update for etherape&lt;br /&gt;http://secunia.com/advisories/46567/&lt;br /&gt;&lt;br /&gt;SUSE update for fail2ban&lt;br /&gt;http://secunia.com/advisories/46555/&lt;br /&gt;&lt;br /&gt;Alsbtain Bulletin "act" Local File Inclusion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46566/&lt;br /&gt;&lt;br /&gt;Gentoo update for asterisk&lt;br /&gt;http://secunia.com/advisories/46548/&lt;br /&gt;&lt;br /&gt;Ubuntu update for pam&lt;br /&gt;http://secunia.com/advisories/46580/&lt;br /&gt;&lt;br /&gt;Debian update for libfcgi-perl&lt;br /&gt;http://secunia.com/advisories/46579/&lt;br /&gt;&lt;br /&gt;Debian update for pam&lt;br /&gt;http://secunia.com/advisories/46549/&lt;br /&gt;&lt;br /&gt;Debian update for freetype&lt;br /&gt;http://secunia.com/advisories/46544/&lt;br /&gt;&lt;br /&gt;SUSE update for cyrus-imapd&lt;br /&gt;http://secunia.com/advisories/46347/&lt;br /&gt;&lt;br /&gt;SUSE update for opera&lt;br /&gt;http://secunia.com/advisories/46552/&lt;br /&gt;&lt;br /&gt;PacketFence "p" and "destination_url" Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46553/&lt;br /&gt;&lt;br /&gt;Red Hat update for xen&lt;br /&gt;http://secunia.com/advisories/46554/&lt;br /&gt;&lt;br /&gt;SUSE update for clamav&lt;br /&gt;http://secunia.com/advisories/46563/&lt;br /&gt;&lt;br /&gt;Novell NetWare Apache Requests Processing Remote Denial of Service&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2222.php&lt;br /&gt;&lt;br /&gt;Zope Security Update Fixes Unspecified Remote Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2221.php&lt;br /&gt;&lt;br /&gt;BlueZone Desktop Multiple Malformed files Local Denial of Service Vulnerabilities&lt;br /&gt;http://www.exploit-db.com/exploits/18030&lt;br /&gt;&lt;br /&gt;Cyrus IMAP Server 'split_wildmats()' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49534&lt;br /&gt;&lt;br /&gt;FreeType Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;Linux Kernel SSID Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48538&lt;br /&gt;&lt;br /&gt;Linux Kernel 'net/can/raw.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47835&lt;br /&gt;&lt;br /&gt;Apache 'mod_authnz_external' Module SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48653&lt;br /&gt;&lt;br /&gt;Linux Kernel 'agp_allocate_memory/agp_create_user_memory' Local Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47535&lt;br /&gt;&lt;br /&gt;Linux Kernel 'next_pidmap()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47497&lt;br /&gt;&lt;br /&gt;Linux Kernel 'bcm_release()' NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47503&lt;br /&gt;&lt;br /&gt;GNU libc glob(3) 'GLOB_LIMIT' Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43819&lt;br /&gt;&lt;br /&gt;Linux Kernel I/O-Warrior USB Device Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46069&lt;br /&gt;&lt;br /&gt;Linux Kernel 'fs/partitions/ldm.c' Buffer Overflow and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46512&lt;br /&gt;&lt;br /&gt;Linux Kernel 'agp_ioctl()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47534&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47343&lt;br /&gt;&lt;br /&gt;Linux Kernel Unix Socket Backlog Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46637&lt;br /&gt;&lt;br /&gt;Linux Kernel Comedi Driver Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49411&lt;br /&gt;&lt;br /&gt;Linux Kernel CIFS Mount Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49626&lt;br /&gt;&lt;br /&gt;Linux Kernel 'perf' Utility Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49140&lt;br /&gt;&lt;br /&gt;Linux Kernel 'taskstats' Access Restriction Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50314&lt;br /&gt;&lt;br /&gt;Linux Kernel 'fs/befs/linuxvfs.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49256&lt;br /&gt;&lt;br /&gt;Linux Kernel '/proc/PID/io' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49408&lt;br /&gt;&lt;br /&gt;Linux kernel l2cap Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48472&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel VLAN Packets Handling Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48907&lt;br /&gt;&lt;br /&gt;Linux Kernel 'inet_diag_bc_audit()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48333&lt;br /&gt;&lt;br /&gt;Linux Kernel OOPS 'qdisc_dev()' Dereference Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48641&lt;br /&gt;&lt;br /&gt;Linux Kernel eCryptfs Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49108&lt;br /&gt;&lt;br /&gt;Linux Kernel IPv6 Fragment Identification Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48802&lt;br /&gt;&lt;br /&gt;Linux Kernel Generic Receive Offload (GRO) CVE-2011-2723 Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48929&lt;br /&gt;&lt;br /&gt;Linux Kernel TCP Sequence Number Generation Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49289&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CIFSFindNext()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49295&lt;br /&gt;&lt;br /&gt;Linux Kernel KSM Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48101&lt;br /&gt;&lt;br /&gt;Linux Kernel EXT4 Extent Format File Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48697&lt;br /&gt;&lt;br /&gt;PostgreSQL Index Function Session State Modification Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37333&lt;br /&gt;&lt;br /&gt;Linux Kernel Validate 'map_count' Variable Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46492&lt;br /&gt;&lt;br /&gt;PostgreSQL 'bitsubstr' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37973&lt;br /&gt;&lt;br /&gt;Linux Kernel 'inotify_init1()' Double Free Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47296&lt;br /&gt;&lt;br /&gt;Linux Kernel 'oops' on Reset NULL Pointer Dereference Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46793&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47796&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/media/radio/si4713-i2c.c' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48804&lt;br /&gt;&lt;br /&gt;Linux Kernel 'mremap()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47321&lt;br /&gt;&lt;br /&gt;Linux Kernel 'x25_parse_facilities()' Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44642&lt;br /&gt;&lt;br /&gt;Linux Kernel NFS File Locking Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49141&lt;br /&gt;&lt;br /&gt;Linux Kernel SCTP INIT/INIT-ACK Chunk Length Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47308&lt;br /&gt;&lt;br /&gt;Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/40305&lt;br /&gt;&lt;br /&gt;PostgreSQL 'intarray' Module 'gettoken()' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46084&lt;br /&gt;&lt;br /&gt;PostgreSQL Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/40215&lt;br /&gt;&lt;br /&gt;PostgreSQL PL/Perl and PL/Tcl Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43747&lt;br /&gt;&lt;br /&gt;PostgreSQL 'RESET ALL' Unauthorized Access Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40304&lt;br /&gt;&lt;br /&gt;PostgreSQL Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/36314&lt;br /&gt;&lt;br /&gt;PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/34090&lt;br /&gt;&lt;br /&gt;PostgreSQL JOIN Hashtable Size Integer Overflow Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/38619&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;PostgreSQL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37334&lt;br /&gt;&lt;br /&gt;QEMU 'scsi_disk_emulate_command()' Function Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49545&lt;br /&gt;&lt;br /&gt;Linux Kernel Netfilter 'ipt_CLUSTERIP.c' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46921&lt;br /&gt;&lt;br /&gt;Linux Kernel Acorn Econet Protocol Implementation Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47990&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel Ethernet Bridge Interface Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50313&lt;br /&gt;&lt;br /&gt;Linux Kernel 'clock_gettime()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50311&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel CVE-2011-3347 VLAN Packets Handling Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50312&lt;br /&gt;&lt;br /&gt;Xen DMA Requests IOMMU Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49146&lt;br /&gt;&lt;br /&gt;Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48687&lt;br /&gt;&lt;br /&gt;Python CGIHTTPServer Module Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46541&lt;br /&gt;&lt;br /&gt;Linux Kernel 'taskstats.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48383&lt;br /&gt;&lt;br /&gt;Pango HarfBuzz Engine Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49723&lt;br /&gt;&lt;br /&gt;Linux Kernel CIFS Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47381&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/char/tpm/tpm.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46866&lt;br /&gt;&lt;br /&gt;Opera Web Browser Tree Traversing Use-After-Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50320&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49303&lt;br /&gt;&lt;br /&gt;Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49549&lt;br /&gt;&lt;br /&gt;RETIRED: SAP Management Console OSExecute Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50348&lt;br /&gt;&lt;br /&gt;phpLDAPadmin 'functions.php' Remote PHP Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50331&lt;br /&gt;&lt;br /&gt;Joomla YJ Contact us Component 'view' Parameter Local File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50362&lt;br /&gt;&lt;br /&gt;Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50361&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 15.0.874.102 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50360&lt;br /&gt;&lt;br /&gt;OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50359&lt;br /&gt;&lt;br /&gt;Zope 2.12.20/2.13.6 and Prior Unspecified Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50357&lt;br /&gt;&lt;br /&gt;Puppet 'certdnsnames' Certificate Validation Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50356&lt;br /&gt;&lt;br /&gt;Wing FTP Server Versions Prior to 4.0.1 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50355&lt;br /&gt;&lt;br /&gt;PacketFence Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50353&lt;br /&gt;&lt;br /&gt;BlueZone Desktop File Processing Multiple Remote Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50352&lt;br /&gt;&lt;br /&gt;BlueZone Desktop '.ztf' File Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50351&lt;br /&gt;&lt;br /&gt;Alsbtain Bulletin Multiple Local File Include Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50350&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-1590278429345287927?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/1590278429345287927/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/26.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1590278429345287927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1590278429345287927'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/26.html' title='26日 水曜日、友引'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-650399680527302699</id><published>2011-10-25T10:05:00.000+09:00</published><updated>2011-10-25T16:32:06.981+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='先勝'/><title type='text'>25日 火曜日、先勝</title><content type='html'>&lt;br /&gt;+ Linux kernel 3.0.8 released&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.8&lt;br /&gt;&lt;br /&gt;CESA-2011:1401 (xen)&lt;br /&gt;http://lwn.net/Alerts/464281/&lt;br /&gt;&lt;br /&gt;ウイルスバスター 月額版 サーバメンテナンスのお知らせ（2011年11月1日）&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1670&lt;br /&gt;&lt;br /&gt;JVNVU#659251 MIT Kerberos 5 KDC に複数の脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU659251/index.html&lt;br /&gt;&lt;br /&gt;JVN#80971236 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN80971236/index.html&lt;br /&gt;&lt;br /&gt;JVN#89764731 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN89764731/index.html&lt;br /&gt;&lt;br /&gt;JVN#36684331 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN36684331/index.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002485 HP Data Protector における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002485.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000082 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000082.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000081 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000081.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000080 WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000080.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002484 Apple Mac OS X の QuickTime Player におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002484.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002483 Apple Mac OS X の MediaKit における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002483.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002482 Apple Mac OS X の kernel におけるアクセス制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002482.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002481 Apple Mac OS X の kernel におけるアクセス制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002481.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002480 Apple Mac OS X の IOGraphics におけるパスワード要求を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002480.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002479 Apple Mac OS X の File Systems コンポーネントにおける WebDAV セッションをハイジャックされる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002479.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002478 Apple Mac OS X の CoreStorage における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002478.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002477 Apple Mac OS X の CoreProcesses コンポーネントにおけるアクセス制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002477.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002476 Apple Mac OS X の CFNetwork におけるユーザを追跡可能な脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002476.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002475 Apple Mac OS X の Apple Type Services (ATS) におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002475.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002474 pple Mac OS X の Apple Type Services (ATS) における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002474.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002473 Apple Mac OS X の CoreMedia における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002473.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002472 D-Link DCS-2121 カメラの /etc/rc.d/rc.local におけるシェルアクセスを取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002472.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002471 D-Link DCS-2121 カメラの recorder_test.cgi における任意のコマンドを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002471.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002470 Apple iOS の設定コンポーネントにおける重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002470.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002469 Apple iOS の設定コンポーネントにおける詳細不明な影響を受ける脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002469.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002468 Apple iOS のホームスクリーンコンポーネントにおける重要な状態情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002468.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002467 Apple iOS の UIKit アラートコンポーネントにおけるサービス運用妨害 (デバイスハング) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002467.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002466 Apple iOS の WiFi コンポーネントにおける重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002466.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002465 Apple iOS および Apple TV の Data Security コンポーネントにおける重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002465.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002464 Apple iOS および Safari で使用される WebKit におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002464.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002463 Apple iOS のキーボードコンポーネントにおける重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002463.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002462 Apple iOS の CalDAV における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002462.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002461 Apple iOS のカレンダーにおけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002461.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002460 Apple iOS の CFNetwork における重要な情報を取得される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002460.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002459 Apple iOS の CoreGraphics の FreeType における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002459.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002458 Apple iOS の Data Access コンポーネントにおけるアクセス制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002458.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002457 Apple iOS の OfficeImport におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002457.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002456 Apple iOS の OfficeImport におけるメモリ二重解放の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002456.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002455 OneOrZero AIMS に複数の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002455.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002454 複数の Apple 製品で使用される WebKit におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002454.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002453 複数の Apple 製品で使用される WebKit におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002453.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002452 Apple iTunes で使用される CoreFoundation におけるサービス運用妨害 (DoS) の脆弱性&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;7.6&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;2011/10/12&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;2011/10/24&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002452.html&lt;br /&gt;&lt;br /&gt;SA46583 Linux-PAM "pam_env" Module Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46583/&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ Postfix stable release 2.8.6, 2.7.7, 2.6.13, 2.5.16&lt;br /&gt;http://www.postfix.org/announcements/postfix-2.8.6.html&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.8.6.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.7.7.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.6.13.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.5.16.HISTORY&lt;br /&gt;&lt;br /&gt;+ Linux kernel 3.1 released&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1&lt;br /&gt;&lt;br /&gt;- Moderate: xen security and bug fix update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1401.html&lt;br /&gt;&lt;br /&gt;- libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48474&lt;br /&gt;&lt;br /&gt;- Linux-PAM 'pam_env' Module Multiple Local Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50343&lt;br /&gt;&lt;br /&gt;[ANNOUNCEMENT] Apache Commons-DbUtils 1.4 released!&lt;br /&gt;http://commons.apache.org/dbutils/download_dbutils.cgi&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Benetl, a free ETL tool for postgreSQL, out in version 3.8&lt;br /&gt;http://www.benetl.net/&lt;br /&gt;&lt;br /&gt;UPDATE: HPSBUX02700 SSRT100506 rev.2 - HP-UX running VEA, Remote Denial of Service (DoS), Execution of Arbitrary Code&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c02962262%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-20] Clam AntiVirus - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36941&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:159] krb5 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36942&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:160] krb5 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36943&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-17] Avahi - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36938&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-18] rgmanager - Privilege Escalation Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36939&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-19] X.Org - X Server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36940&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:157] freetype2 - Code Execution and Denial-Of-Service Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36945&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:158] phpmyadmin - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36946&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1386-01] Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36959&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1391-01] httpd - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36960&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1392-01] httpd - Security Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36961&lt;br /&gt;&lt;br /&gt;Stefan Schurtz : [SSCHADV2011-033] Metasploit - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36950&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1236-1] Linux Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36931&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1235-1] Open-iSCSI - File Overwrite Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36932&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [Ubuntu: 1232-3] X.Org - X server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36933&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-14] D-Bus - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36935&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-15] GnuPG - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36936&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-16] Cyrus IMAP Server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36937&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBMU02716 SSRT100651] HP Data Protector Notebook Extension - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36947&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBPI02711 SSRT100647] HP - MFP Digital Sending Software - Information Disclosure Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36948&lt;br /&gt;&lt;br /&gt;HTB Team : [HTB23050] Tine - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36952&lt;br /&gt;&lt;br /&gt;Independant Researcher : Oracle Database - Buffer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36954&lt;br /&gt;&lt;br /&gt;Independant Researcher : Oracle Database Server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36955&lt;br /&gt;&lt;br /&gt;Independant Researcher : Oracle Database Server - SQL Injection Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36956&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1385-01] kdelibs and kdelibs3 - Spoofing Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36958&lt;br /&gt;&lt;br /&gt;Stefan Schurtz : [SSCHADV2011-031] Yet Another CMS - SQL Injection and Cross-site Scripting Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36957&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1192-3] Firefox - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36934&lt;br /&gt;&lt;br /&gt;Debian : [DSA 2324-1] Wireshark - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36944&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2326-1] pam security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00145.html&lt;br /&gt;&lt;br /&gt;TC-SA-2011-01: Multiple vulnerabilities in OmniTouch Instant Communication Suite&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00149.html&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2325-1] kfreebsd-8 security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00144.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-20 ] Clam AntiVirus: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00143.html&lt;br /&gt;&lt;br /&gt;phpLDAPadmin &amp;lt;= 1.2.1.1 (query_engine) Remote PHP Code Injection Exploit&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00148.html&lt;br /&gt;&lt;br /&gt;jara 1.6 sql injection vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00147.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:160 ] krb5&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00142.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:159 ] krb5&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00141.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-18 ] rgmanager: Privilege escalation&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00140.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-17 ] Avahi: Denial of Service&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00139.html&lt;br /&gt;&lt;br /&gt;[CVE-2011-2569] Cisco Nexus OS (NX-OS) - Command "injection" / sanitization issues.&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00146.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-16 ] Cyrus IMAP Server: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00138.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-15 ] GnuPG: User-assisted execution of arbitrary code&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00137.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-14 ] D-Bus: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00136.html&lt;br /&gt;&lt;br /&gt;またもやYouTubeで乗っ取り、今度はマイクロソフトが被害&lt;br /&gt;動画を全て消去、コメント欄には「アダルト動画まだ？」&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111025/371321/?ST=security&lt;br /&gt;&lt;br /&gt;Critical Control 16: Secure Network Engineering&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11878&lt;br /&gt;&lt;br /&gt;Vulnerability Note VU#659251 Multiple MIT KRB5 KDC daemon vulnerabilities&lt;br /&gt;http://www.kb.cert.org/vuls/id/659251&lt;br /&gt;&lt;br /&gt;FreeType Type 1 Font Processing Flaw Lets Remote Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026237&lt;br /&gt;&lt;br /&gt;FreeType Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46575/&lt;br /&gt;&lt;br /&gt;phpLDAPadmin Cross-Site Scripting and Code Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46551/&lt;br /&gt;&lt;br /&gt;Gentoo update for dbus&lt;br /&gt;http://secunia.com/advisories/46547/&lt;br /&gt;&lt;br /&gt;Gentoo update for gnupg&lt;br /&gt;http://secunia.com/advisories/46541/&lt;br /&gt;&lt;br /&gt;Gentoo update for avahi&lt;br /&gt;http://secunia.com/advisories/46503/&lt;br /&gt;&lt;br /&gt;Gentoo update for rgmanager&lt;br /&gt;http://secunia.com/advisories/46498/&lt;br /&gt;&lt;br /&gt;SUSE update for krb5&lt;br /&gt;http://secunia.com/advisories/46546/&lt;br /&gt;&lt;br /&gt;Gentoo update for cyrus-imapd&lt;br /&gt;http://secunia.com/advisories/46530/&lt;br /&gt;&lt;br /&gt;Oracle AutoVue ActiveX Control Insecure Method Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46473/&lt;br /&gt;&lt;br /&gt;Cyclope Internet Filtering Proxy Request Processing Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46556/&lt;br /&gt;&lt;br /&gt;Toshiba E-Studio Multifunction Printers Management Interface Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/46408/&lt;br /&gt;&lt;br /&gt;Linux Kernel ext4 Extent Splitting Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46489/&lt;br /&gt;&lt;br /&gt;TYPO3 PMK SlimBox Extension Cross-Site Scripting and File Disclosure Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46437/&lt;br /&gt;&lt;br /&gt;TYPO3 PMK Shadowbox Extension Cross-Site Scripting and File Disclosure Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46499/&lt;br /&gt;&lt;br /&gt;Debian update for kfreebsd-8&lt;br /&gt;http://secunia.com/advisories/46564/&lt;br /&gt;&lt;br /&gt;Jara "id" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46493/&lt;br /&gt;&lt;br /&gt;OpenEMR Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46560/&lt;br /&gt;&lt;br /&gt;WordPress Chennai Theme "s" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46561/&lt;br /&gt;&lt;br /&gt;Joomla! Freestyle FAQs and Testimonials Components Unspecified SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46573/&lt;br /&gt;&lt;br /&gt;Gentoo update for xorg-server&lt;br /&gt;http://secunia.com/advisories/46496/&lt;br /&gt;&lt;br /&gt;LOCAL: Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18027&lt;br /&gt;&lt;br /&gt;DoS/PoC: BlueZone Malformed .zft file Local Denial of Service&lt;br /&gt;http://www.exploit-db.com/exploits/18029&lt;br /&gt;&lt;br /&gt;DoS/PoC: zFTP Server "cwd/stat" Remote Denial-of-Service&lt;br /&gt;http://www.exploit-db.com/exploits/18028&lt;br /&gt;&lt;br /&gt;McAfee Web Gateway Web Acces Cross Site Scripting Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2220.php&lt;br /&gt;&lt;br /&gt;Alcatel-Lucent Instant Communication Suite Cross Site Scripting Issues&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2219.php&lt;br /&gt;&lt;br /&gt;Oracle AutoVue AutoVueX ActiveX Multiple Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2218.php&lt;br /&gt;&lt;br /&gt;FreeType Type 1 Fonts Processing Multiple Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2217.php&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;JBoss Enterprise Application Platform Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/39710&lt;br /&gt;&lt;br /&gt;FreeType 'src/psaux/t1decode.c' Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48619&lt;br /&gt;&lt;br /&gt;libpng PNG File Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48618&lt;br /&gt;&lt;br /&gt;libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48474&lt;br /&gt;&lt;br /&gt;libpng Buffer Overflow and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48660&lt;br /&gt;&lt;br /&gt;Linux Kernel epoll Subsystem 'eventpoll.c' Multiple Local Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46630&lt;br /&gt;&lt;br /&gt;LibTIFF Multiple Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47338&lt;br /&gt;&lt;br /&gt;Asterisk Manager Interface Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46897&lt;br /&gt;&lt;br /&gt;Asterisk SIP Authentication Request User Enumeration Weakness&lt;br /&gt;http://www.securityfocus.com/bid/48485&lt;br /&gt;&lt;br /&gt;Asterisk Multiple Remote Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48431&lt;br /&gt;&lt;br /&gt;Asterisk Uninitalized Variable SIP Channel Driver Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50177&lt;br /&gt;&lt;br /&gt;Asterisk UPDTL Packets Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46474&lt;br /&gt;&lt;br /&gt;Asterisk Manager Interface Arbitrary Command Execution Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47537&lt;br /&gt;&lt;br /&gt;Asterisk TCP/TLS Server NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46898&lt;br /&gt;&lt;br /&gt;QEMU 'scsi_disk_emulate_command()' Function Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49545&lt;br /&gt;&lt;br /&gt;Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50199&lt;br /&gt;&lt;br /&gt;ClamAV Prior to 0.96.5 Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45152&lt;br /&gt;&lt;br /&gt;Symantec Veritas Enterprise Administrator Service Multiple Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49014&lt;br /&gt;&lt;br /&gt;Symantec Backup Exec for Windows Servers Unauthorized Access Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47824&lt;br /&gt;&lt;br /&gt;ClamAV Hash Manager Off-By-One Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48891&lt;br /&gt;&lt;br /&gt;bzip2 'BZ2_decompress' Function Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43331&lt;br /&gt;&lt;br /&gt;ClamAV 'vba_read_project_strings()' Double Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46470&lt;br /&gt;&lt;br /&gt;ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43555&lt;br /&gt;&lt;br /&gt;Linux-HA OCF Resource Agents 'LD_LIBRARY_PATH' Multiple Local Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/44359&lt;br /&gt;&lt;br /&gt;Avahi 'avahi-core/socket.c' Zero Size Packet Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/41075&lt;br /&gt;&lt;br /&gt;Avahi 'avahi-core/socket.c' NULL UDP Packet Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46446&lt;br /&gt;&lt;br /&gt;FreeType Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/36296&lt;br /&gt;&lt;br /&gt;Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49659&lt;br /&gt;&lt;br /&gt;Opera Web Browser SVG Layout Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50044&lt;br /&gt;&lt;br /&gt;MIT Kerberos Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50273&lt;br /&gt;&lt;br /&gt;MIT Kerberos krb5-appl FTP Daemon EGID Remote Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48571&lt;br /&gt;&lt;br /&gt;GnuPG 'GPGSM Tool' Certificate Importing Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/41945&lt;br /&gt;&lt;br /&gt;Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49030&lt;br /&gt;&lt;br /&gt;Wireshark Lua Script File Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49528&lt;br /&gt;&lt;br /&gt;D-Bus Nested Variants Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45377&lt;br /&gt;&lt;br /&gt;D-Bus Configuration Insecure Temporary File Creation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48460&lt;br /&gt;&lt;br /&gt;D-Bus Message Byte Order Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48216&lt;br /&gt;&lt;br /&gt;Multiple Cytel Products Remote Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49924&lt;br /&gt;&lt;br /&gt;FreeBSD UNIX Domain Socket Local Privilege Escalation Vulnerabiity&lt;br /&gt;http://www.securityfocus.com/bid/49862&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-1985) Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49968&lt;br /&gt;&lt;br /&gt;SAP Management Console OSExecute Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50348&lt;br /&gt;&lt;br /&gt;Cisco Nexus OS 'section' and 'less' Local Command Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50347&lt;br /&gt;&lt;br /&gt;Alcatel-Lucent OmniTouch 8400 Instant Communications Suite Multiple Input Validation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50346&lt;br /&gt;&lt;br /&gt;zFTP Server 'cwd/stat' Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50345&lt;br /&gt;&lt;br /&gt;InverseFlow Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50344&lt;br /&gt;&lt;br /&gt;Linux-PAM 'pam_env' Module Multiple Local Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50343&lt;br /&gt;&lt;br /&gt;McAfee Web Gateway Web Access Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50341&lt;br /&gt;&lt;br /&gt;e107 'cmd' Parameter Remote Command Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50339&lt;br /&gt;&lt;br /&gt;Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50338&lt;br /&gt;&lt;br /&gt;OpenEMR Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50336&lt;br /&gt;&lt;br /&gt;WordPress ThemeCity 's' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50334&lt;br /&gt;&lt;br /&gt;Oracle AutoVue 'AutoVueX.ocx' ActiveX Control 'Export3DBom()' Insecure Method Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50333&lt;br /&gt;&lt;br /&gt;Oracle AutoVue 'AutoVueX.ocx' ActiveX Control 'ExportEdaBom()' Insecure Method Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50332&lt;br /&gt;&lt;br /&gt;phpLDAPadmin 0.9.4b 'common.php' Local File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50328&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-650399680527302699?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/650399680527302699/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/25.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/650399680527302699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/650399680527302699'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/25.html' title='25日 火曜日、先勝'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-3137045906903292235</id><published>2011-10-24T10:52:00.000+09:00</published><updated>2011-10-24T16:27:54.086+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='赤口'/><title type='text'>24日 月曜日、赤口</title><content type='html'>&lt;br /&gt;+ Postfix stable release 2.8.6, 2.7.7, 2.6.13, 2.5.16&lt;br /&gt;http://www.postfix.org/announcements/postfix-2.8.6.html&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.8.6.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.7.7.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.6.13.HISTORY&lt;br /&gt;http://mirror.postfix.jp/postfix-release/official/postfix-2.5.16.HISTORY&lt;br /&gt;&lt;br /&gt;UPDATE: Security updates available for Adobe Reader and Acrobat&lt;br /&gt;http://www.adobe.com/support/security/bulletins/apsb11-24.html&lt;br /&gt;&lt;br /&gt;CESA-2011:1386 (kernel)&lt;br /&gt;http://lwn.net/Alerts/464073/&lt;br /&gt;&lt;br /&gt;CESA-2011:1392 (httpd)&lt;br /&gt;http://lwn.net/Alerts/464072/&lt;br /&gt;&lt;br /&gt;Thunderbird Beta Channel: latest update available&lt;br /&gt;http://www.mozilla.org/thunderbird/all-beta.html&lt;br /&gt;http://www.mozilla.org/thunderbird/8.0beta/releasenotes/&lt;br /&gt;&lt;br /&gt;phpMyAdmin 3.4.7 is released&lt;br /&gt;http://sourceforge.net/news/?group_id=23067&amp;amp;id=304138&lt;br /&gt;&lt;br /&gt;SA46491: Gentoo update for clamav&lt;br /&gt;http://secunia.com/advisories/46491/&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-1985) Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49968&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;+ MySQL Community Server 5.5.17 has been released&lt;br /&gt;http://dev.mysql.com/tech-resources/interviews/thomas-ulin-mysql-55.html&lt;br /&gt;http://dev.mysql.com/doc/refman/5.5/en/news-5-5-17.html&lt;br /&gt;&lt;br /&gt;+ Linux kernel 3.0.5, 3.0.6, 3.0.7 released&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.5&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.6&lt;br /&gt;http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.0.7&lt;br /&gt;&lt;br /&gt;+ Sudo 1.7.8, 1.8.3 released&lt;br /&gt;http://www.sudo.ws/sudo/news.html&lt;br /&gt;http://www.sudo.ws/sudo/stable.html#1.7.8&lt;br /&gt;http://www.sudo.ws/sudo/stable.html#1.8.3&lt;br /&gt;&lt;br /&gt;+ Linux Kernel 'ext4_ext_insert_extent()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50322&lt;br /&gt;&lt;br /&gt;++ [CPUOct2011] Oracle Critical Patch Update Advisory - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/jp/topics/ojkb155517-518195-ja.html&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] Apache OpenWebBeans 1.1.2 release&lt;br /&gt;http://www.apache.org/dyn/closer.cgi/openwebbeans/1.1.2/&lt;br /&gt;&lt;br /&gt;Apache Subversion 1.7.1 Released&lt;br /&gt;http://subversion.apache.org/download/#recommended-release&lt;br /&gt;&lt;br /&gt;HPSBMP02713 SSRT100651 rev.2 - Replaced by Document ID c03058866 - HPSBMU02716 SSRT100651&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03054543%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;HPSBMU02716 SSRT100651 rev.1 - HP Data Protector Notebook Extension, Remote Execution of Arbitrary Code&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03058866%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;HPSBOV02497 SSRT090245 rev.4 - HP TCP/IP Services for OpenVMS Running NTP, Remote Execution of Arbitrary Code, Denial of Service (DoS)&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c01961959%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;HPSBPI02711 SSRT100647 rev.1 - HP MFP Digital Sending Software Running on Windows, Local Information Disclosure&lt;br /&gt;https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03052686%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;FreeBSD 9.0-RC1 released&lt;br /&gt;http://www.freebsd.org/news/newsflash.html#event20111023:01&lt;br /&gt;&lt;br /&gt;チャットサポートの一時的な停止につきまして（2011年11月5日）&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1668&lt;br /&gt;&lt;br /&gt;ペンタセキュリティ、WAFに仮想アプライアンス版を追加&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111021/371202/?ST=security&lt;br /&gt;&lt;br /&gt;TeamSHATTER Security Advisory: SQL Injection Vulnerability in Oracle DROP INDEX for spatial datatype&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00135.html&lt;br /&gt;&lt;br /&gt;TeamSHATTER Security Advisory: Database Vault Account Management Vulnerabilites&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00134.html&lt;br /&gt;&lt;br /&gt;TeamSHATTER Security Advisory: Buffer Overflow in Oracle Database (CTXSYS.DRVDISP.TABLEFUNC_ASOWN fu&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00133.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:158 ] phpmyadmin&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00132.html&lt;br /&gt;&lt;br /&gt;VUPEN Security Research - Microsoft Internet Explorer "X-UA-COMPATIBLE" Use-after &lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00130.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:157 ] freetype2&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00129.html&lt;br /&gt;&lt;br /&gt;inCommand Technologies, Inc. Cross-site Scripting Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00131.html&lt;br /&gt;&lt;br /&gt;Metasploit 4.1.0 Web UI stored XSS vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00128.html&lt;br /&gt;&lt;br /&gt;tcpdump and IPv6&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11872&lt;br /&gt;&lt;br /&gt;Oracle Java SE Critical Patch Update&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11869&lt;br /&gt;&lt;br /&gt;Red Hat update for kernel&lt;br /&gt;http://secunia.com/advisories/46543/&lt;br /&gt;&lt;br /&gt;Elgg pg/search SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46514/&lt;br /&gt;&lt;br /&gt;Google Chrome NSS Insecure Library Loading Vulnerability&lt;br /&gt;http://secunia.com/advisories/46471/&lt;br /&gt;&lt;br /&gt;GNOME Empathy Nickname Script Insertion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46510/&lt;br /&gt;&lt;br /&gt;Network Security Services Insecure Library Loading Vulnerability&lt;br /&gt;http://secunia.com/advisories/46557/&lt;br /&gt;&lt;br /&gt;Red Hat update for httpd&lt;br /&gt;http://secunia.com/advisories/46456/&lt;br /&gt;&lt;br /&gt;Red Hat update for httpd&lt;br /&gt;http://secunia.com/advisories/46542/&lt;br /&gt;&lt;br /&gt;WHMCompleteSolution "templatefile" Local File Inclusion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46312/&lt;br /&gt;&lt;br /&gt;Ubuntu update for linux&lt;br /&gt;http://secunia.com/advisories/46539/&lt;br /&gt;&lt;br /&gt;Ubuntu update for open-iscsi&lt;br /&gt;http://secunia.com/advisories/46535/&lt;br /&gt;&lt;br /&gt;Pre Studio Business Cards Designer "id" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46545/&lt;br /&gt;&lt;br /&gt;Joomla! Multiple NoNumber Extensions Local File Inclusion and PHP Code Execution&lt;br /&gt;http://secunia.com/advisories/46459/&lt;br /&gt;&lt;br /&gt;SUSE update for ldns&lt;br /&gt;http://secunia.com/advisories/46470/&lt;br /&gt;&lt;br /&gt;Debian update for wireshark&lt;br /&gt;http://secunia.com/advisories/46482/&lt;br /&gt;&lt;br /&gt;Schneider Electric Products UnitelWay Device Driver Privilege Escalation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46534/&lt;br /&gt;&lt;br /&gt;Check Point Products ByteRange Filter Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46474/&lt;br /&gt;&lt;br /&gt;Ubuntu update for acpid&lt;br /&gt;http://secunia.com/advisories/46540/&lt;br /&gt;&lt;br /&gt;Medium severity flaw in QNX Neutrino RTOS&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8475&lt;br /&gt;&lt;br /&gt;MS11-064 TCP/IP Stack Denial of Service&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8474&lt;br /&gt;&lt;br /&gt;MS11-077 .fon Kernel-Mode Buffer Overrun PoC&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8473&lt;br /&gt;&lt;br /&gt;Mozilla Firefox Array.reduceRight() Integer Overflow Exploit&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8472&lt;br /&gt;&lt;br /&gt;HP Onboard Administrator (OA), Remote Unauthorized Access&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8471&lt;br /&gt;&lt;br /&gt;Citect Buffer Overflow in UnitelWay Driver Lets Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026234&lt;br /&gt;&lt;br /&gt;REMOTE:&amp;nbsp;Oracle AutoVue 20.0.1 AutoVueX ActiveX Control SaveViewStateToFile Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/18016&lt;br /&gt;&lt;br /&gt;REMOTE: HP Power Manager 'formExportDataLogs' Buffer Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18015&lt;br /&gt;&lt;br /&gt;DoS/PoC:&amp;nbsp;Google Chrome Denial Of Service (DoS)&lt;br /&gt;http://www.exploit-db.com/exploits/18025&lt;br /&gt;&lt;br /&gt;DoS/PoC:&amp;nbsp;MS11-077 Win32k Null Pointer De-reference Vulnerability POC&lt;br /&gt;http://www.exploit-db.com/exploits/18024&lt;br /&gt;&lt;br /&gt;DoS/PoC:&amp;nbsp;Google Chrome PoC, killing thread&lt;br /&gt;http://www.exploit-db.com/exploits/18019&lt;br /&gt;&lt;br /&gt;DoS/PoC:&amp;nbsp;Cyclope Internet Filtering Proxy 4.0 - CEPMServer.exe DoS (Poc)&lt;br /&gt;http://www.exploit-db.com/exploits/18017&lt;br /&gt;&lt;br /&gt;Schneider Electric Products UnitelWay Device Driver Local Buffer Overflow&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2216.php&lt;br /&gt;&lt;br /&gt;OCS Inventory NG Data Processing Cross Site Scripting Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2215.php&lt;br /&gt;&lt;br /&gt;IBM WebSphere Application Server for z/OS WS-Security Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2214.php&lt;br /&gt;&lt;br /&gt;Oracle Database Server Database Vault 'DV_ACCTMGR' Privileges Remote Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50219&lt;br /&gt;&lt;br /&gt;Oracle Database 'CTXSYS.DRVDISP' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50199&lt;br /&gt;&lt;br /&gt;Oracle Database CVE-2011-3512 SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50203&lt;br /&gt;&lt;br /&gt;TYPO3 pdf_generator2 Extension Remote Commend Execution and Remote File Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50304&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49303&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49957&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel CVE-2011-3347 VLAN Packets Handling Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50312&lt;br /&gt;&lt;br /&gt;phpMyAdmin Setup Interface Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50175&lt;br /&gt;&lt;br /&gt;phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49306&lt;br /&gt;&lt;br /&gt;Progea Movicon Multiple Heap Based Buffer Overflow and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49605&lt;br /&gt;&lt;br /&gt;Cisco TelePresence Video Communication Server 'User-Agent' HTTP Header HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50084&lt;br /&gt;&lt;br /&gt;Apple iOS Free Type Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50002&lt;br /&gt;&lt;br /&gt;HP Power Manager 'formExportDataLogs' Buffer Overflow Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37867&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50242&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50211&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50224&lt;br /&gt;&lt;br /&gt;Elgg 'limit' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50327&lt;br /&gt;&lt;br /&gt;SportsPHool 'mainnav' Parameter Remote File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50325&lt;br /&gt;&lt;br /&gt;Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50324&lt;br /&gt;&lt;br /&gt;Empathy 'nickname' Field Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50323&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ext4_ext_insert_extent()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50322&lt;br /&gt;&lt;br /&gt;Oracle AutoVue 'AutoVueX.ocx' ActiveX Control 'SaveViewStateToFile()' Insecure Method Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50321&lt;br /&gt;&lt;br /&gt;Opera Web Browser Tree Traversing Use-After-Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50320&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-3137045906903292235?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/3137045906903292235/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/24.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3137045906903292235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/3137045906903292235'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/24.html' title='24日 月曜日、赤口'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-1178911441247867111</id><published>2011-10-21T10:47:00.000+09:00</published><updated>2011-10-21T16:59:36.225+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='メアリーブレア生誕100周年'/><category scheme='http://www.blogger.com/atom/ns#' term='先負'/><title type='text'>21日 金曜日、先負</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;2011/10/20 Samba 3.6.1がリリースされました&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://wiki.samba.gr.jp/mediawiki/index.php?title=%E3%83%A1%E3%82%A4%E3%83%B3%E3%83%9A%E3%83%BC%E3%82%B8&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;ウイルスバスター2012 プログラムアップデートのお知らせ&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.trendmicro.co.jp/support/news.asp?id=1667&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;UPDATE: Oracle Critical Patch Update Advisory - October 2011&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;ソフトウェア等の脆弱性関連情報に関する届出状況&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;[2011年第3四半期（7月～9月）]&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.ipa.go.jp/security/vuln/report/vuln2011q3.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNVU#819894: libpng における sCAL チャンクの処理に脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvn.jp/cert/JVNVU819894/index.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNVU#707943: Windows プログラムの DLL 読み込みに脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvn.jp/cert/JVNVU707943/index.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVN#44724673: Java Web Start において許可されていないシステムクラスが実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvn.jp/jp/JVN44724673/index.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNTA11-286A: Apple Mac OS Xにおける複数の脆弱性に対するアップデート&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvn.jp/cert/JVNTA11-286A/index.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNTA11-284A: Microsoft 製品における複数の脆弱性に対するアップデート&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvn.jp/cert/JVNTA11-284A/index.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002451 Microsoft Internet Explorer 8 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002451.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002450 Microsoft Internet Explorer 9 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002450.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002449 Microsoft Internet Explorer 6 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002449.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002448 Microsoft Internet Explorer 6 から 8 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002448.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002447 Microsoft Internet Explorer 6 から 9 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002447.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002446 Microsoft Internet Explorer 6 から 9 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002446.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002445 Microsoft Windows XP および Windows Server 2003 の afd.sys における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002445.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002444 Microsoft Windows XP および Windows Server 2003 における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002444.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002443 Microsoft Forefront UAG の MicrosoftClient.jar における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002443.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002442 Microsoft Forefront UAG 2010 におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002442.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002441 Microsoft Forefront UAG 2010 におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002441.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002440 Microsoft Forefront UAG 2010 における CRLF インジェクションの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002440.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002439 Microsoft .NET Framework および Silverlight における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002439.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002438 Microsoft Windows のカーネルモードドライバ内にある win32k.sys における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002438.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002437 Microsoft Windows の win32k.sys のバッファオーバーフローの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002437.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002436 Microsoft Windows の win32k.sys におけるサービス運用妨害 (システムハング) の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002436.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002435 Microsoft Windows の win32k.sys における権限昇格またはサービス運用妨害 (DoS) の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002435.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002434 Microsoft Windows Vista および Windows 7 の Windows Media Center における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002434.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002433 Microsoft Windows の Microsoft Active Accessibility コンポーネントにおける権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002433.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002432 複数の Microsoft 製品における任意のファイルを読まれる脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002432.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002431 Microsoft Windows SharePoint Services および SharePoint Foundation におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002431.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002430 複数の Microsoft SharePoint 製品の EditForm.aspx におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002430.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002429 複数の Microsoft SharePoint 製品におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002429.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002428 Microsoft Internet Explorer における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002428.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002427 Microsoft Internet Explorer における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002427.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002426 Microsoft Host Integration Server におけるサービス運用妨害 (SNA サーバサービスの休止) の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002426.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002425 Microsoft Host Integration Server におけるサービス運用妨害 (SNA サーバサービスの休止) の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002425.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002424 Apple iTunes で使用される CoreMedia におけるバッファオーバーフローの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002424.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002423 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002423.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002422 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002422.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002421 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002421.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002420 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002420.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002419 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002419.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002418 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002418.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002417 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002417.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002416 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002416.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002415 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002415.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002414 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002414.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002413 Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002413.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002412 複数の Microsoft SharePoint 製品におけるクロスサイトスクリプティングの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002412.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002411 Microsoft Office 2003 および 2007 における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002411.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002410 Microsoft Office 2007 および 2010 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002410.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002409 Windows Server 2003 および 2008 の WINS における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002409.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002408 Microsoft Excel 2003 における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002408.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002407 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002407.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002406 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002406.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002405 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002405.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002404 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002404.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002403 Microsoft Windows における権限昇格の脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002403.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002402 Adobe Reader および Acrobat における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002402.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002401 Adobe Reader および Acrobat の CoolType.dll におけるスタックベースのバッファオーバーフローの脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002401.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002400 Adobe Reader および Acrobat における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002400.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JVNDB-2011-002399 Adobe Reader および Acrobat における任意のコードを実行される脆弱性&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002399.html&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Independant Researcher : Django - Multiple Issues&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36928&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Red Hat : [RHSA-2011:1379-01] krb5 - Denial-Of-Service Issue&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36924&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Red Hat : [RHSA-2011:1380-01] java-1.6.0-openjdk - Multiple Issues&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36925&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Red Hat : [RHSA-2011:1384-01] java-1.6.0-sun - Multiple Issues&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36926&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Red Hat : QEMU - Buffer Overflow Issue&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36927&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Cisco : [cisco-sa-20111019-sns] Cisco Show and Share - Multiple Issues&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36929&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;New Flash Click Jacking Exploit&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://isc.sans.edu/diary.html?storyid=11857&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;JBoss Worm&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://isc.sans.edu/diary.html?storyid=11860&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Check Point UTM-1 Edge / Safe@Office WebUI Multiple Vulnerabilities&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://secunia.com/advisories/46486/&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;DoS/Poc: Opera ＜= 11.51 Use After Free Crash PoC&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.exploit-db.com/exploits/18014&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;HP Power Manager 'formExportDataLogs' Buffer Overflow Remote Code Execution Vulnerability&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.securityfocus.com/bid/37867&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.securityfocus.com/bid/50242&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.securityfocus.com/bid/50211&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;http://www.securityfocus.com/bid/50224&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: right;"&gt;&lt;a href="http://4.bp.blogspot.com/-UCKB7-rCRPw/TqDX0LX_TNI/AAAAAAAAA34/4iSqnWr2vCI/s1600/Google-20111021-%25E3%2583%25A1%25E3%2582%25A2%25E3%2583%25AA%25E3%2583%25BC%25E3%2583%2596%25E3%2583%25AC%25E3%2582%25A2%25E7%2594%259F%25E8%25AA%2595100%25E5%2591%25A8%25E5%25B9%25B4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="132" src="http://4.bp.blogspot.com/-UCKB7-rCRPw/TqDX0LX_TNI/AAAAAAAAA34/4iSqnWr2vCI/s320/Google-20111021-%25E3%2583%25A1%25E3%2582%25A2%25E3%2583%25AA%25E3%2583%25BC%25E3%2583%2596%25E3%2583%25AC%25E3%2582%25A2%25E7%2594%259F%25E8%25AA%2595100%25E5%2591%25A8%25E5%25B9%25B4.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;+ Samba 3.6.1 Available for Download&lt;br /&gt;http://www.samba.org/samba/history/samba-3.6.1.html&lt;br /&gt;http://www.samba.org/samba/history/&lt;br /&gt;&lt;br /&gt;+ Important: kernel security, bug fix, and enhancement update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1386.html&lt;br /&gt;&lt;br /&gt;+ Moderate: httpd security and bug fix update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1392.html&lt;br /&gt;&lt;br /&gt;+ Linux Kernel 'taskstats' Access Restriction Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50314&lt;br /&gt;http://www.redhat.com/security/data/cve/CVE-2011-2494.html&lt;br /&gt;&lt;br /&gt;+ Linux Kernel 'clock_gettime()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50311&lt;br /&gt;&lt;br /&gt;- Linux Kernel EXT4 Extent Format File Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48697&lt;br /&gt;&lt;br /&gt;RHSA-2011:1391 Moderate: httpd security and bug fix update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1391.html&lt;br /&gt;&lt;br /&gt;CESA-2011:1380 (java-1.6.0-openjdk)&lt;br /&gt;http://lwn.net/Alerts/463927/&lt;br /&gt;&lt;br /&gt;CESA-2011:1385 (kdelibs)&lt;br /&gt;http://lwn.net/Alerts/463929/&lt;br /&gt;&lt;br /&gt;[SECURITY] [DSA 2324-1] wireshark security update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00127.html&lt;br /&gt;&lt;br /&gt;GotRoot Security Challenge&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00126.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBPI02711 SSRT100647 rev.1 - HP MFP Digital Sending Software Running on Wi&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00120.html&lt;br /&gt;&lt;br /&gt;OCS Inventory NG 2.0.1 Persistent XSS (CVE-2011-4024)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00125.html&lt;br /&gt;&lt;br /&gt;Oracle DataDirect Multiple Native Wire Protocol ODBC Drivers HOST Attribute Stack Based Buffer Overf&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00124.html&lt;br /&gt;&lt;br /&gt;Yet Another CMS 1.0 SQL Injection &amp;amp; XSS vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00119.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: CiscoWorks Common Services Arbitrary Command Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00118.html&lt;br /&gt;&lt;br /&gt;Cisco Security Advisory: Cisco Show and Share Security Vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00117.html&lt;br /&gt;&lt;br /&gt;[security bulletin] HPSBMU02716 SSRT100651 rev.1 - HP Data Protector Notebook Extension, Remote&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00123.html&lt;br /&gt;&lt;br /&gt;Multiple vulnerabilities in Tine 2.0&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00122.html&lt;br /&gt;&lt;br /&gt;ZDI-11-295 : Apple QuickTime FlashPix JPEG Tables Selector Remote Code Execution Vulnerabili&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00116.html&lt;br /&gt;&lt;br /&gt;DNS Poisoning via Port Exhaustion&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00121.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-13 ] Tor: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00115.html&lt;br /&gt;&lt;br /&gt;MITKRB5-SA-2011-006 KDC denial of service vulnerabilities [CVE-2011-1527 CVE-&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00114.html&lt;br /&gt;&lt;br /&gt;Critical Control 13: Limitation and Control of Network Ports, Protocols, and Services&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11845&lt;br /&gt;&lt;br /&gt;Evil Printers Sending Mail&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11848&lt;br /&gt;&lt;br /&gt;IBM WebSphere Application Server for z/OS JAX-WS Applications Unspecified Vulnerability&lt;br /&gt;http://secunia.com/advisories/46469/&lt;br /&gt;&lt;br /&gt;KaiBB Cross-Site Scripting and SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/45311/&lt;br /&gt;&lt;br /&gt;wizmall "BID" and "UID" SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46440/&lt;br /&gt;&lt;br /&gt;wizmall Two File Disclosure Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46484/&lt;br /&gt;&lt;br /&gt;Splunk Cross-Site Scripting and Denial of Service Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46462/&lt;br /&gt;&lt;br /&gt;Fedora update for java-1.6.0-openjdk&lt;br /&gt;http://secunia.com/advisories/46538/&lt;br /&gt;&lt;br /&gt;Honeywell EBI Temaline Remote Installer ActiveX Control "DownloadURL()" Insecure Method&lt;br /&gt;http://secunia.com/advisories/46497/&lt;br /&gt;&lt;br /&gt;Fedora update for tomcat6&lt;br /&gt;http://secunia.com/advisories/46537/&lt;br /&gt;&lt;br /&gt;HP MFP Digital Sending Software Workflow Metadata Information Disclosure Weakness&lt;br /&gt;http://secunia.com/advisories/46532/&lt;br /&gt;&lt;br /&gt;CiscoWorks Common Services Home Page Component Command Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46533/&lt;br /&gt;&lt;br /&gt;Cisco Show and Share Security Bypass Security Issue and File Upload Vulnerability&lt;br /&gt;http://secunia.com/advisories/46465/&lt;br /&gt;&lt;br /&gt;Red Hat update for krb5&lt;br /&gt;http://secunia.com/advisories/46480/&lt;br /&gt;&lt;br /&gt;Red Hat update for java-1.6.0-sun&lt;br /&gt;http://secunia.com/advisories/46490/&lt;br /&gt;&lt;br /&gt;Simple PHP Forum Script "id" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46485/&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer DOM Modification Race Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/windowsntfocus/6O03H002UW.html&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer layout-grid-char style Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/windowsntfocus/6P03I002UQ.html&lt;br /&gt;&lt;br /&gt;Lotus Notes XLS viewer malformed BIFF record heap overflow Vulnerability&lt;br /&gt;http://www.securiteam.com/windowsntfocus/6T03M002UC.html&lt;br /&gt;&lt;br /&gt;7T Interactive Graphical SCADA System Memory Corruption Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6S03L002US.html&lt;br /&gt;&lt;br /&gt;Oracle Java ICC Profile Multi-Language 'curv' Tag Parsing Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6R03K002US.html&lt;br /&gt;&lt;br /&gt;Oracle Java ICC Profile 'bfd ' Tag Parsing Code Execution Vulnerability&lt;br /&gt;http://www.securiteam.com/securitynews/6Q03J002UU.html&lt;br /&gt;&lt;br /&gt;Avaya Identity Engines Ignition Server Remote Code Execution Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2213.php&lt;br /&gt;&lt;br /&gt;MIT Kerberos Packets Processing Remote Denial of Service Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2212.php&lt;br /&gt;&lt;br /&gt;HP MFP Digital Sending Software Local Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2211.php&lt;br /&gt;&lt;br /&gt;Novell ZENworks Configuration Management Multiple Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2210.php&lt;br /&gt;&lt;br /&gt;Novell ZENworks Handheld Management Code Execution and Dir Traversal&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2209.php&lt;br /&gt;&lt;br /&gt;Cisco Show and Share Unauthorized Access and Code Execution&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2208.php&lt;br /&gt;&lt;br /&gt;Cisco CiscoWorks Common Services Command Execution Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2207.php&lt;br /&gt;&lt;br /&gt;Oracle Java Multiple Remote Code Execution and Security Bypass&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2206.php&lt;br /&gt;&lt;br /&gt;Oracle and Sun Products Multiple Code Execution and Security Bypass&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2205.php&lt;br /&gt;&lt;br /&gt;DoS/PoC: UnrealIRCd 3.2.8.1 Local Configuration Stack Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18011&lt;br /&gt;&lt;br /&gt;DoS/PoC: Opera ＜= 11.52 Stack Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18008&lt;br /&gt;&lt;br /&gt;DoS/PoC: Oracle DataDirect Multiple Native Wire Protocol ODBC Drivers HOST Attribute Stack Based Buffer Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/18007&lt;br /&gt;&lt;br /&gt;DoS/PoC: Opera ＜= 11.52 PoC Denial of Service&lt;br /&gt;http://www.exploit-db.com/exploits/18006&lt;br /&gt;&lt;br /&gt;SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/36887&lt;br /&gt;&lt;br /&gt;Linux Kernel '/proc/PID/io' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49408&lt;br /&gt;&lt;br /&gt;Linux Kernel TCP Sequence Number Generation Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49289&lt;br /&gt;&lt;br /&gt;Linux Kernel SCTP INIT/INIT-ACK Chunk Length Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47308&lt;br /&gt;&lt;br /&gt;Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48687&lt;br /&gt;&lt;br /&gt;Wireshark Lua Script File Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49528&lt;br /&gt;&lt;br /&gt;acpid Multiple Local Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45915&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CIFSFindNext()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49295&lt;br /&gt;&lt;br /&gt;Xen DMA Requests IOMMU Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49146&lt;br /&gt;&lt;br /&gt;Linux Kernel Generic Receive Offload (GRO) CVE-2011-2723 Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48929&lt;br /&gt;&lt;br /&gt;Linux Kernel eCryptfs Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49108&lt;br /&gt;&lt;br /&gt;Linux Kernel 'taskstats.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48383&lt;br /&gt;&lt;br /&gt;Linux Kernel CIFS Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47381&lt;br /&gt;&lt;br /&gt;Linux Kernel 'mremap()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47321&lt;br /&gt;&lt;br /&gt;Linux Kernel IPv6 Fragment Identification Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48802&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/char/tpm/tpm.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46866&lt;br /&gt;&lt;br /&gt;Linux Kernel EXT4 Extent Format File Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48697&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49616&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49957&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3544 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50218&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3521 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50215&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50248&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50234&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50243&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3560 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50236&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3554 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50216&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50231&lt;br /&gt;&lt;br /&gt;OCS Inventory NG Unspecified HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50011&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50224&lt;br /&gt;&lt;br /&gt;KDE KSSL Common Name SSL Certificate Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49925&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48667&lt;br /&gt;&lt;br /&gt;Apache Tomcat AJP Protocol Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49353&lt;br /&gt;&lt;br /&gt;Apache Tomcat NIO Connector Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46164&lt;br /&gt;&lt;br /&gt;Apache Tomcat SecurityManager Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46177&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48456&lt;br /&gt;&lt;br /&gt;Apache Tomcat HTML Manager Interface HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46174&lt;br /&gt;&lt;br /&gt;ldns 'rr.c' Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49748&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50211&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50242&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey CVE-2011-2993 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49248&lt;br /&gt;&lt;br /&gt;Mozilla Firefox and Thunderbird CVE-2011-2991 JavaScript Memory-Corruption Vulnerabiility&lt;br /&gt;http://www.securityfocus.com/bid/49243&lt;br /&gt;&lt;br /&gt;Cyclope Internet Filtering Proxy 'user' HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50317&lt;br /&gt;&lt;br /&gt;MetaSploit Framework 'project[name]' Field HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50315&lt;br /&gt;&lt;br /&gt;Linux Kernel 'taskstats' Access Restriction Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50314&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel Ethernet Bridge Interface Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50313&lt;br /&gt;&lt;br /&gt;Red Hat Linux Kernel CVE-2011-3347 VLAN Packets Handling Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50312&lt;br /&gt;&lt;br /&gt;Linux Kernel 'clock_gettime()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50311&lt;br /&gt;&lt;br /&gt;IBM WebSphere Application Server JAX-WS Unspecified Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50310&lt;br /&gt;&lt;br /&gt;PreProjects Pre Studio Business Cards Designer 'page.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50309&lt;br /&gt;&lt;br /&gt;Skype Technologies Skype Client for Windows File Transfer Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50308&lt;br /&gt;&lt;br /&gt;Tine Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50307&lt;br /&gt;&lt;br /&gt;TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50306&lt;br /&gt;&lt;br /&gt;Oracle DataDirect Multiple Native Wire Protocol ODBC Driver Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50305&lt;br /&gt;&lt;br /&gt;TYPO3 pdf_generator2 Extension Remote Commend Execution and Remote File Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50304&lt;br /&gt;&lt;br /&gt;Novell ZENworks Handheld Management Multiple Unspecified Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50303&lt;br /&gt;&lt;br /&gt;wizmall Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50302&lt;br /&gt;&lt;br /&gt;osCommerce Remote File Upload and File Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50301&lt;br /&gt;&lt;br /&gt;wizmall Multiple Remote File Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50300&lt;br /&gt;&lt;br /&gt;KaiBB SQL Injection and Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50299&lt;br /&gt;&lt;br /&gt;Splunk Web component Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50298&lt;br /&gt;&lt;br /&gt;Splunk 'segment' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50296&lt;br /&gt;&lt;br /&gt;Innovate Portal 'cat' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50295&lt;br /&gt;&lt;br /&gt;CMS Mini 'name' Parameter Directory Traversal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50294&lt;br /&gt;&lt;br /&gt;Uiga Personal Portal SQL Injection and Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50293&lt;br /&gt;&lt;br /&gt;Simple Free PHP Forum Script 'index.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50292&lt;br /&gt;&lt;br /&gt;fims File Management System 'password' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50291&lt;br /&gt;&lt;br /&gt;fims File Management System 'f' Parameter Arbitrary File Download Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50290&lt;br /&gt;&lt;br /&gt;OpenEMR 'add_edit_issue.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50289&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-1178911441247867111?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/1178911441247867111/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/21.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1178911441247867111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1178911441247867111'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/21.html' title='21日 金曜日、先負'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-UCKB7-rCRPw/TqDX0LX_TNI/AAAAAAAAA34/4iSqnWr2vCI/s72-c/Google-20111021-%25E3%2583%25A1%25E3%2582%25A2%25E3%2583%25AA%25E3%2583%25BC%25E3%2583%2596%25E3%2583%25AC%25E3%2582%25A2%25E7%2594%259F%25E8%25AA%2595100%25E5%2591%25A8%25E5%25B9%25B4.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-1922984445654530121</id><published>2011-10-20T10:08:00.000+09:00</published><updated>2011-10-20T16:25:42.842+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='友引'/><title type='text'>20日 木曜日、友引</title><content type='html'>ウイルスバスター2011 プログラムアップデートのお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1665&lt;br /&gt;&lt;br /&gt;1. 2011年 第3四半期 脆弱性対策情報データベース JVN iPediaの登録状況（総括）&lt;br /&gt;http://www.ipa.go.jp/security/vuln/report/JVNiPedia2011q3.html&lt;br /&gt;&lt;br /&gt;WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN80971236/&lt;br /&gt;&lt;br /&gt;JVN#89764731: WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN89764731/&lt;br /&gt;&lt;br /&gt;WEB FORUM におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://www.jpcert.or.jp/&lt;br /&gt;&lt;br /&gt;Critical Control 13: Limitation and Control of Network Ports, Protocols, and Services&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11845&lt;br /&gt;&lt;br /&gt;Evil Printers Sending Mail&lt;br /&gt;http://isc.sans.edu/index.html&lt;br /&gt;&lt;br /&gt;HP MFP Digital Sending Software Lets Local Users Obtain Potentially Sensitive Information&lt;br /&gt;http://www.securitytracker.com/id/1026228&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;++ Microsoft Windows Local DNS Cache Poisoning Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50281&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;+ Moderate: kdelibs and kdelibs3 security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1385.html&lt;br /&gt;&lt;br /&gt;DHCP 4.2.3 released&lt;br /&gt;https://www.isc.org/software/dhcp/423&lt;br /&gt;&lt;br /&gt;HPSBNS02701 SSRT100598 rev.1 - HP NonStop Servers running Samba, Remote Denial of Service (DoS), Unauthorized Disclosure of Information, Unauthorized Modification, Unauthorized Access to Files, Cross Site Scripting (XSS)&lt;br /&gt;https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c03008543%25257CdocLocale%25253Dja_JP&amp;amp;javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&lt;br /&gt;&lt;br /&gt;NTP 4.2.6p5-RC1 released&lt;br /&gt;http://support.ntp.org/bin/view/Main/SoftwareDownloads&lt;br /&gt;http://archive.ntp.org/ntp4/ChangeLog-stable-rc&lt;br /&gt;&lt;br /&gt;ウイルスバスター モバイル for Androidでオンラインユーザ登録が行えない現象について&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1666&lt;br /&gt;&lt;br /&gt;Trend Micro ServerProtect for NetApp 5.8 Patch 1 公開のお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1664&lt;br /&gt;&lt;br /&gt;UPDATE: Oracle Critical Patch Update Advisory - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html&lt;br /&gt;&lt;br /&gt;HS11-023: Multiple vulnerabilities were found in JP1/Cm2/Network Node Manager i.&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-023/index.html&lt;br /&gt;&lt;br /&gt;UPDATE: HS11-019: Hitachi Web ServerにおけるRangeヘッダによるDoS脆弱性&lt;br /&gt;http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-019/index.html&lt;br /&gt;&lt;br /&gt;Independant Researcher : Dolphin - PHP Code Injection Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36922&lt;br /&gt;&lt;br /&gt;Independant Researcher : Site () School - SQL Injection &amp;amp; Cross-site Scripting Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36923&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:156] tomcat5 - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36914&lt;br /&gt;&lt;br /&gt;Positive Technologies : [PT-2011-14] BoonEx Dolphin - SQL Injection Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36921&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1377-01] postgresql - Authentication Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36917&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1378-01] postgresql84 - Authentication Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36918&lt;br /&gt;&lt;br /&gt;SuSE : [SUSE-SA:2011:041] Linux - kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36919&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1231-1] PHP - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36920&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-13] Tor - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36913&lt;br /&gt;&lt;br /&gt;Independant Researcher : [JVNDB-2011-000085]- DAEMON Tools IOCTL - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36903&lt;br /&gt;&lt;br /&gt;Independant Researcher : Java - DNS Poisoning Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36912&lt;br /&gt;&lt;br /&gt;Independant Researcher : X.Org - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36915&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:155] SystemTap - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36905&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:154] SystemTap - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36907&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:153] libxfont - Buffer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36908&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:152] ncompress - Integer Underflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36909&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:151] libpng - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36910&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-295] Apple - QuickTime - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36916&lt;br /&gt;&lt;br /&gt;Asterisk : [AST-2011-012] Asterisk - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36904&lt;br /&gt;&lt;br /&gt;Independant Researcher : [foofus-20111016] Toshiba - EStudio Multifunction Printer - Authentication Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36901&lt;br /&gt;&lt;br /&gt;Independant Researcher : WordPress - Simple:Press Forum - Code Execution and Full Path Disclosure Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36906&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:149] Cyrus IMAP Server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36885&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:150] squid - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36891&lt;br /&gt;&lt;br /&gt;Sense of Security : [SOS-11-012] WordPress - BackWPUp plugin - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36890&lt;br /&gt;&lt;br /&gt;Slackware Linux : [SSA:2011-284-01] Slackware - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36882&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-12] Unbound - Multiple Denial-Of-Service Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36892&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1371-01] Pidgin - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36883&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1369-01] httpd - Excessive Memory Usage Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36884&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1230-1] Quassel - Information Disclosure Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36881&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-290] Microsoft - Internet Explorer - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36886&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-289] Microsoft - Internet Explorer - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36887&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-288] Microsoft - Internet Explorer - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36888&lt;br /&gt;&lt;br /&gt;ZDI : [ZDI-11-287] Microsoft - Internet Explorer - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36889&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-08] feh - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36893&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-09] Conky - Privilege Escalation Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36894&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-10] GNU Wget - File Overwrite Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36895&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-11] Adobe - Flash Player - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36896&lt;br /&gt;&lt;br /&gt;Facebookのパスワードが1万件以上流出の恐れ、真偽は未確認&lt;br /&gt;パスワードの使い回しは禁物、サービスごとに変更を&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111020/371101/?ST=security&lt;br /&gt;&lt;br /&gt;JPCERT/CC WEEKLY REPORT&lt;br /&gt;http://www.jpcert.or.jp/wr/2011/wr114001.html&lt;br /&gt;&lt;br /&gt;The old new Stuxnet...DuQu?&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11836&lt;br /&gt;&lt;br /&gt;Oracle Critical Patch Update&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11839&lt;br /&gt;&lt;br /&gt;Cisco Show and Share Lets Remote Users Access Some Administrative Pages and Remote Authenticated Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026227&lt;br /&gt;&lt;br /&gt;CiscoWorks Common Services Home Page Input Validation Flaw Lets Remote Users Execute Arbitrary Commands&lt;br /&gt;http://www.securitytracker.com/id/1026226&lt;br /&gt;&lt;br /&gt;Oracle OpenSSO Bugs Let Remote Users Deny Service and Partially Access Data&lt;br /&gt;http://www.securitytracker.com/id/1026225&lt;br /&gt;&lt;br /&gt;Oracle Communications Unified Communications Suite Lets Local Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026224&lt;br /&gt;&lt;br /&gt;Oracle Waveset User Administration Bug Lets Remote Users Partially Access and Modify Data and Partially Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026223&lt;br /&gt;&lt;br /&gt;Sun GlassFish Enterprise Server Web Container Bug Lets Remote Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026222&lt;br /&gt;&lt;br /&gt;Microsoft Publisher 'Pubconv.dll' Memory Corruption Error Lets Remote Users Execute Arbitrary Code&lt;br /&gt;http://www.securitytracker.com/id/1026220&lt;br /&gt;&lt;br /&gt;Oracle Java Runtime Environment (JRE) Lets Remote Users Decrypt SSL/TLS Traffic&lt;br /&gt;http://www.securitytracker.com/id/1026216&lt;br /&gt;&lt;br /&gt;Oracle Java Runtime Environment (JRE) Multiple Flaws Let Remote Users Execute Arbitrary Code and Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026215&lt;br /&gt;&lt;br /&gt;Kerberos KDC Null Pointer Dereference Bugs Let Remote Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026213&lt;br /&gt;&lt;br /&gt;Check Point Safe@Office Input Validation Flaws Permits Cross-Site Scripting and Cross-Site Request Forgery Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026212&lt;br /&gt;&lt;br /&gt;Solaris Lets Remote Users Gain Full Control and Local Users Access and Modify Data and Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026211&lt;br /&gt;&lt;br /&gt;Sun Ray Authentication Component Flaw Lets Remote Users Partially Access and Modify Data and Cause Partial Denail of Service Conditions&lt;br /&gt;http://www.securitytracker.com/id/1026210&lt;br /&gt;&lt;br /&gt;Oracle Linux Lets Remote Authenticated Users Partially Access and Modifiy Data&lt;br /&gt;http://www.securitytracker.com/id/1026209&lt;br /&gt;&lt;br /&gt;Oracle Health Sciences Industry Applications Bugs Let Remote Users Partially Modify Data&lt;br /&gt;http://www.securitytracker.com/id/1026207&lt;br /&gt;&lt;br /&gt;Ubuntu update for krb5&lt;br /&gt;http://secunia.com/advisories/46488/&lt;br /&gt;&lt;br /&gt;Oracle Integrated Lights Out Manager Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/46509/&lt;br /&gt;&lt;br /&gt;Moodle Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46427/&lt;br /&gt;&lt;br /&gt;Oracle OpenSSO Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46527/&lt;br /&gt;&lt;br /&gt;Oracle OpenSSO Data Manipulation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46528/&lt;br /&gt;&lt;br /&gt;Novell ZENworks Configuration Management AdminStudio ActiveX Controls Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46466/&lt;br /&gt;&lt;br /&gt;Kerberos KDC Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46494/&lt;br /&gt;&lt;br /&gt;Oracle Communications Unified Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46526/&lt;br /&gt;&lt;br /&gt;Yet Another CMS Two SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46483/&lt;br /&gt;&lt;br /&gt;Ubuntu update for xorg-server&lt;br /&gt;http://secunia.com/advisories/46495/&lt;br /&gt;&lt;br /&gt;Red Hat update for java-1.6.0-openjdk&lt;br /&gt;http://secunia.com/advisories/46481/&lt;br /&gt;&lt;br /&gt;Dolphin "eval()" PHP Code Execution Vulnerability&lt;br /&gt;http://secunia.com/advisories/46457/&lt;br /&gt;&lt;br /&gt;Dolphin "iIDcat" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46500/&lt;br /&gt;&lt;br /&gt;Oracle Waveset User Administration Vulnerability&lt;br /&gt;http://secunia.com/advisories/46525/&lt;br /&gt;&lt;br /&gt;Oracle Solaris Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46522/&lt;br /&gt;&lt;br /&gt;Oracle Sun Java System Application Server Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46524/&lt;br /&gt;&lt;br /&gt;Oracle Glassfish Products Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46523/&lt;br /&gt;&lt;br /&gt;Oracle WebLogic Server Information Disclosure and Privilege Escalation Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46520/&lt;br /&gt;&lt;br /&gt;Oracle WebLogic Portal Unspecified Vulnerability&lt;br /&gt;http://secunia.com/advisories/46519/&lt;br /&gt;&lt;br /&gt;Oracle Outside In Technology Denial of Service Weakness&lt;br /&gt;http://secunia.com/advisories/46518/&lt;br /&gt;&lt;br /&gt;Oracle Business Intelligence BI Platform Security Unspecified Vulnerability&lt;br /&gt;http://secunia.com/advisories/46517/&lt;br /&gt;&lt;br /&gt;Oracle Application Server Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46516/&lt;br /&gt;&lt;br /&gt;Oracle JRockit Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46521/&lt;br /&gt;&lt;br /&gt;Oracle Java SE Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46512/&lt;br /&gt;&lt;br /&gt;Sun Ray Server Software Authentication Unspecified Vulnerability&lt;br /&gt;http://secunia.com/advisories/46511/&lt;br /&gt;&lt;br /&gt;Gentoo update for tor&lt;br /&gt;http://secunia.com/advisories/46472/&lt;br /&gt;&lt;br /&gt;SUSE update for gimp&lt;br /&gt;http://secunia.com/advisories/46479/&lt;br /&gt;&lt;br /&gt;Fedora update for awstats&lt;br /&gt;http://secunia.com/advisories/46478/&lt;br /&gt;&lt;br /&gt;Fedora update for ldns&lt;br /&gt;http://secunia.com/advisories/46476/&lt;br /&gt;&lt;br /&gt;Fedora update for quagga&lt;br /&gt;http://secunia.com/advisories/46475/&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Enterprise Human Resource Management System Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46505/&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft PeopleTools Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46515/&lt;br /&gt;&lt;br /&gt;Oracle Agile PLM for Process Information Disclosure Vulnerability&lt;br /&gt;http://secunia.com/advisories/46507/&lt;br /&gt;&lt;br /&gt;Oracle Siebel CRM Three Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46506/&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46504/&lt;br /&gt;&lt;br /&gt;Oracle Remote Data Capture RDC Help Data Manipulation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46508/&lt;br /&gt;&lt;br /&gt;Oracle Thesaurus Management System TMS Help Data Manipulation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46513/&lt;br /&gt;&lt;br /&gt;Oracle Database Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46502/&lt;br /&gt;&lt;br /&gt;X.Org xserver File Locking Weakness and Security Issue&lt;br /&gt;http://secunia.com/advisories/46460/&lt;br /&gt;&lt;br /&gt;Avaya Identity Engines Ignition Server GIOP Processing Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/46501/&lt;br /&gt;&lt;br /&gt;Avaya Identity Engines Ignition Server GIOP Processing Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/46492/&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/SeaMonkey CVE-2011-2990 Information Disclosure and Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49246&lt;br /&gt;&lt;br /&gt;Mozilla Firefox, SeaMonkey, and Thunderbird CVE-2011-2987 Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49226&lt;br /&gt;&lt;br /&gt;Mozilla Firefox, SeaMonkey, and Thunderbird CVE-2011-2988 Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49242&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2011-0084 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49213&lt;br /&gt;&lt;br /&gt;Mozilla Firefox and Thunderbird CVE-2011-2989 WebGL Memory-Corruption Vulnerabiility&lt;br /&gt;http://www.securityfocus.com/bid/49239&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2011-2985 Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49224&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50237&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3549 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50223&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50220&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3550 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50226&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50248&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50234&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50231&lt;br /&gt;&lt;br /&gt;KDE KSSL Common Name SSL Certificate Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49925&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3546 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50239&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3561 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50250&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50243&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3516 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50229&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3553 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50246&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50242&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50224&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50211&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3554 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50216&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3560 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50236&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3544 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50218&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3521 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50215&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;MIT Kerberos Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50273&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2010-4448 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46398&lt;br /&gt;&lt;br /&gt;FreeBSD UNIX Domain Socket Local Privilege Escalation Vulnerabiity&lt;br /&gt;http://www.securityfocus.com/bid/49862&lt;br /&gt;&lt;br /&gt;Tor Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45953&lt;br /&gt;&lt;br /&gt;Tor Unspecified Buffer Overflow, Denial of Service and Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45832&lt;br /&gt;&lt;br /&gt;Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46618&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48456&lt;br /&gt;&lt;br /&gt;Apache Tomcat AJP Protocol Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49353&lt;br /&gt;&lt;br /&gt;AWStats 'awredir.pl' Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49749&lt;br /&gt;&lt;br /&gt;ldns 'rr.c' Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49748&lt;br /&gt;&lt;br /&gt;Quagga Multiple Remote Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49784&lt;br /&gt;&lt;br /&gt;OpenOffice Microsoft Word File Format Importer Multiple Unspecified Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49969&lt;br /&gt;&lt;br /&gt;Opera Web Browser Information Disclosure and Unspecified Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49388&lt;br /&gt;&lt;br /&gt;apt SSL Certificate Validation Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50288&lt;br /&gt;&lt;br /&gt;Plone CMFEditions Component (CVE-2011-4030) Remote Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50287&lt;br /&gt;&lt;br /&gt;Boonex Dolphin 'xml/get_list.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50286&lt;br /&gt;&lt;br /&gt;Cisco Show and Share CVE-2011-2585 Arbitrary File Upload Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50285&lt;br /&gt;&lt;br /&gt;CiscoWorks Common Services Remote Command Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50284&lt;br /&gt;&lt;br /&gt;Moodle Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50283&lt;br /&gt;&lt;br /&gt;Cisco Show and Share Anonymous Access Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50282&lt;br /&gt;&lt;br /&gt;Microsoft Windows Local DNS Cache Poisoning Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50281&lt;br /&gt;&lt;br /&gt;WHMCompleteSolution 'cart.php' Local File Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50280&lt;br /&gt;&lt;br /&gt;D-Link DCS-2121 Password Field Remote Command Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50277&lt;br /&gt;&lt;br /&gt;1024 CMS 1.1.0 Beta 'force_download.php' Local File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50275&lt;br /&gt;&lt;br /&gt;Novell ZENworks Configuration Management AdminStudio Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50274&lt;br /&gt;&lt;br /&gt;Yet Another CMS Multiple SQL Injection and Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50272&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50268&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50267&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-2286 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50265&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50264&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50263&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3536 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50262&lt;br /&gt;&lt;br /&gt;Oracle Sun Product Suite CVE-2011-3537 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50259&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3506 Remote Oracle OpenSSO Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50252&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50249&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3542 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50244&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-3527 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50241&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-3519 Remote Oracle Applications Framework Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50233&lt;br /&gt;&lt;br /&gt;Oracle Supply Chain Products Suite CVE-2011-3532 Remote Oracle Agile Product Supplier Collaboration&lt;br /&gt;http://www.securityfocus.com/bid/50227&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-2303 Remote Oracle Application Object Library Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50225&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-2302 Remote Oracle Application Object Library Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50221&lt;br /&gt;&lt;br /&gt;Oracle Database Server CVE-2011-3511 Remote Database Vault Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50219&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-3523 Remote Oracle Web Services Manager Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50209&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2319 Remote Oracle WebLogic Server Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50206&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2255 Remote Oracle WebLogic Portal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50205&lt;br /&gt;&lt;br /&gt;Opera 11.52 released&lt;br /&gt;http://www.opera.com/docs/changelogs/windows/1152/&lt;br /&gt;&lt;br /&gt;CESA-2011:1377 (postgresql)&lt;br /&gt;http://lwn.net/Alerts/463689/&lt;br /&gt;&lt;br /&gt;CESA-2011:1378 (postgresql84)&lt;br /&gt;http://lwn.net/Alerts/463690/&lt;br /&gt;&lt;br /&gt;phpMyAdmin 3.4.7-rc1 is released&lt;br /&gt;http://sourceforge.net/news/?group_id=23067&amp;amp;id=304070&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-1922984445654530121?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/1922984445654530121/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/20.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1922984445654530121'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/1922984445654530121'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/20.html' title='20日 木曜日、友引'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-165075379822249679</id><published>2011-10-19T11:00:00.001+09:00</published><updated>2011-10-19T11:05:03.177+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='先勝'/><title type='text'>19日 水曜日、先勝</title><content type='html'>&lt;br /&gt;RHSA-2011:1379-1: Moderate: krb5 security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1379.html&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ J2SE JDK/JRE 1.6.0_29 released&lt;br /&gt;http://www.oracle.com/technetwork/java/javase/6u29-relnotes-507960.html&lt;br /&gt;&lt;br /&gt;+ Oracle Critical Patch Update Advisory - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html&lt;br /&gt;&lt;br /&gt;+ Oracle Java SE Critical Patch Update Advisory - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html&lt;br /&gt;&lt;br /&gt;+ Critical: java-1.6.0-openjdk security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1380.html&lt;br /&gt;&lt;br /&gt;- SA46468: HP Data Protector Multiple Unspecified Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46468/&lt;br /&gt;&lt;br /&gt;- PHP Prior to 5.3.7 Multiple NULL Pointer Dereference Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49249&lt;br /&gt;&lt;br /&gt;- PHP CVE-2011-2202 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48259&lt;br /&gt;&lt;br /&gt;- PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47950&lt;br /&gt;&lt;br /&gt;BIND 9.9.0a3 released&lt;br /&gt;https://www.isc.org/software/bind/990a3&lt;br /&gt;&lt;br /&gt;UPDATE: Cisco IOS Software Data-Link Switching Vulnerability&lt;br /&gt;http://www.cisco.com/warp/public/707/cisco-sa-20110928-dlsw.shtml&lt;br /&gt;&lt;br /&gt;UPDATE: Cisco IOS Software IP Service Level Agreement Vulnerability&lt;br /&gt;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-ipsla&lt;br /&gt;&lt;br /&gt;ウイルスバスター for Mac プログラムアップデートのお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1634&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:156 ] tomcat5&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00113.html&lt;br /&gt;&lt;br /&gt;Dolphin ＜= 7.0.7 (member_menu_queries.php) Remote PHP Code Injection&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00112.html&lt;br /&gt;&lt;br /&gt;Site@School 2.4.10 SQL Injection &amp;amp; XSS vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00111.html&lt;br /&gt;&lt;br /&gt;[PT-2011-14] SQL injection vulnerability in BoonEx Dolphin&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00110.html&lt;br /&gt;&lt;br /&gt;「セサミストリート」でアダルト動画！？YouTubeで乗っ取り発覚&lt;br /&gt;不適切な動画が20分間掲載、プロフィルも改ざん&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111019/371021/?ST=security&lt;br /&gt;&lt;br /&gt;Critical Control 12 : Malware Defense&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11830&lt;br /&gt;&lt;br /&gt;ClamAV Recursion Level Handling Vulnerability&lt;br /&gt;http://secunia.com/advisories/46455/&lt;br /&gt;&lt;br /&gt;TYPO3 phpMyAdmin Extension Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46463/&lt;br /&gt;&lt;br /&gt;Joomla! Information Disclosure Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46421/&lt;br /&gt;&lt;br /&gt;SUSE update for cups&lt;br /&gt;http://secunia.com/advisories/46409/&lt;br /&gt;&lt;br /&gt;SUSE update for cups&lt;br /&gt;http://secunia.com/advisories/46448/&lt;br /&gt;&lt;br /&gt;SUSE update for libopenssl&lt;br /&gt;http://secunia.com/advisories/46452/&lt;br /&gt;&lt;br /&gt;SUSE update for libopenssl&lt;br /&gt;http://secunia.com/advisories/46453/&lt;br /&gt;&lt;br /&gt;GNUBoard URL SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46443/&lt;br /&gt;&lt;br /&gt;SUSE update for php5&lt;br /&gt;http://secunia.com/advisories/46425/&lt;br /&gt;&lt;br /&gt;SUSE update for kdelibs4&lt;br /&gt;http://secunia.com/advisories/46439/&lt;br /&gt;&lt;br /&gt;SUSE update for wireshark&lt;br /&gt;http://secunia.com/advisories/46449/&lt;br /&gt;&lt;br /&gt;SUSE update for libreoffice&lt;br /&gt;http://secunia.com/advisories/46450/&lt;br /&gt;&lt;br /&gt;SUSE update for popt&lt;br /&gt;http://secunia.com/advisories/46451/&lt;br /&gt;&lt;br /&gt;SUSE update for tomcat6&lt;br /&gt;http://secunia.com/advisories/46454/&lt;br /&gt;&lt;br /&gt;Microsoft Office Publisher Document Insertion Buffer Overflow Vulnerability&lt;br /&gt;http://secunia.com/advisories/46438/&lt;br /&gt;&lt;br /&gt;Ubuntu update for php5&lt;br /&gt;http://secunia.com/advisories/46374/&lt;br /&gt;&lt;br /&gt;Piwik Multiple Unspecified Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46461/&lt;br /&gt;&lt;br /&gt;Asterisk SIP Channel Driver Uninitialised Variables Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46420/&lt;br /&gt;&lt;br /&gt;WordPress WP Photo Album Plus Plugin "wppa-album" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46467/&lt;br /&gt;&lt;br /&gt;HP Data Protector Multiple Unspecified Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46468/&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware Bugs Let Remote Users Partially Access and Modify Data and Remote and Local Users Partially Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026206&lt;br /&gt;&lt;br /&gt;Piwik Data Processing Multiple Unspecified Remote Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2204.php&lt;br /&gt;&lt;br /&gt;Microsoft Publisher "Pubconv.dll" Document Insertion Memory Corruption&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2203.php&lt;br /&gt;&lt;br /&gt;HP Data Protector Notebook Extension Multiple Remote Code Execution&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2202.php&lt;br /&gt;&lt;br /&gt;phpMyAdmin "phpmyadmin.css.php" Remote Path Disclosure Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2201.php&lt;br /&gt;&lt;br /&gt;phpMyAdmin Setup Interface Data Processing Cross Site Scripting&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2200.php&lt;br /&gt;&lt;br /&gt;Check Point UTM-1 Edge and Safe@Office WebUI Multiple Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2199.php&lt;br /&gt;&lt;br /&gt;Microsys Promotic Directory Traversal and Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2198.php&lt;br /&gt;&lt;br /&gt;OPC Systems .NET Remote Procedural Call Denial of Service Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2197.php&lt;br /&gt;&lt;br /&gt;Honeywell TEMA Remote Installer ActiveX Code Execution Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2196.php&lt;br /&gt;&lt;br /&gt;atvise webMI HTTP Requests Processing Multiple Remote Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2195.php&lt;br /&gt;&lt;br /&gt;IRAI AUTOMGEN Project File Processing Buffer Overflow Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2194.php&lt;br /&gt;&lt;br /&gt;Asterisk SIP Channel Driver Unitialized Variable Denial of Service Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2193.php&lt;br /&gt;&lt;br /&gt;Joomla! Data Processing Multiple Information Disclosure Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2192.php&lt;br /&gt;&lt;br /&gt;Drupal Cumulus Module Data Processing Cross Site Scripting Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2191.php&lt;br /&gt;&lt;br /&gt;Drupal Certificate Login Module Remote SQL Injection Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2190.php&lt;br /&gt;&lt;br /&gt;OneOrZero AIMS Authentication Bypass and SQL Injection Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2189.php&lt;br /&gt;&lt;br /&gt;D-Link DIR-685 Xtreme N Storage Router WPA/WPA2 Encryption Issue&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2188.php&lt;br /&gt;&lt;br /&gt;GoAhead Webserver Multiple Parameter Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2187.php&lt;br /&gt;&lt;br /&gt;REMOTE: Apple Safari Webkit libxslt Arbitrary File Creation&lt;br /&gt;http://www.exploit-db.com/exploits/17993&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50268&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50267&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-2286 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50265&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50264&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50263&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3536 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50262&lt;br /&gt;&lt;br /&gt;Oracle Sun Product Suite CVE-2011-3537 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50259&lt;br /&gt;&lt;br /&gt;Oracle Sun Products Suite CVE-2011-3506 Remote Oracle OpenSSO Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50252&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50249&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3542 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50244&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-3527 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50241&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-3519 Remote Oracle Applications Framework Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50233&lt;br /&gt;&lt;br /&gt;Oracle Supply Chain Products Suite CVE-2011-3532 Remote Oracle Agile Product Supplier Collaboration&lt;br /&gt;http://www.securityfocus.com/bid/50227&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-2303 Remote Oracle Application Object Library Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50225&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-2302 Remote Oracle Application Object Library Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50221&lt;br /&gt;&lt;br /&gt;Oracle Database Server CVE-2011-3511 Remote Database Vault Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50219&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-3523 Remote Oracle Web Services Manager Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50209&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2319 Remote Oracle WebLogic Server Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50206&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2255 Remote Oracle WebLogic Portal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50205&lt;br /&gt;&lt;br /&gt;RETIRED: Oracle October 2011 Critical Patch Update Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50119&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49303&lt;br /&gt;&lt;br /&gt;Symantec IM Manager Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49742&lt;br /&gt;&lt;br /&gt;Apple Mac OS X FlashPix Files CVE-2011-3222 Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50100&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2312 'ZFS' Sub Component Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50269&lt;br /&gt;&lt;br /&gt;X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50002&lt;br /&gt;&lt;br /&gt;RETIRED: Oracle Java SE Critical Patch Update October 2011 Advance Notification&lt;br /&gt;http://www.securityfocus.com/bid/50118&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;Oracle Linux CVE-2011-2306 Oracle Validation Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50194&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;Multiple Cisco Products CVE-2011-2738 Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49627&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48667&lt;br /&gt;&lt;br /&gt;Apache Tomcat HTTP DIGEST Authentication CVE-2011-1184 Multiple Security Weaknesses&lt;br /&gt;http://www.securityfocus.com/bid/49762&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48456&lt;br /&gt;&lt;br /&gt;Apache Tomcat AJP Protocol Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49353&lt;br /&gt;&lt;br /&gt;Quagga Multiple Remote Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49784&lt;br /&gt;&lt;br /&gt;ClamAV Recursion Level Handling Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50183&lt;br /&gt;&lt;br /&gt;rpm-python RPM File Handling Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49799&lt;br /&gt;&lt;br /&gt;Joomla! 'com_jfuploader' Arbitrary File Upload Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44559&lt;br /&gt;&lt;br /&gt;phpMyAdmin Setup Interface Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50175&lt;br /&gt;&lt;br /&gt;PHP 'ZipArchive::addGlob' and 'ZipArchive::addPattern' Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49252&lt;br /&gt;&lt;br /&gt;PHP Prior to 5.3.7 Multiple NULL Pointer Dereference Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49249&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/41991&lt;br /&gt;&lt;br /&gt;PHP CVE-2011-2202 Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48259&lt;br /&gt;&lt;br /&gt;PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47950&lt;br /&gt;&lt;br /&gt;WebKit 'libxslt' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48840&lt;br /&gt;&lt;br /&gt;Avaya Identity Engines Ignition Server Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50271&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-3539 Local Solaris Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50270&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2311 ZFS Component Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50266&lt;br /&gt;&lt;br /&gt;Oracle Sun Products CVE-2011-3522 Local SPARC T3, Netra SPARC T3, Sun Fire, Sun Blade Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50261&lt;br /&gt;&lt;br /&gt;Oracle Siebel CRM CVE-2011-2316 Siebel Apps - Marketing Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50260&lt;br /&gt;&lt;br /&gt;Oracle Sun Products CVE-2011-2327 Local Oracle Communications Unified Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50258&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2304 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50257&lt;br /&gt;&lt;br /&gt;Oracle Siebel CRM CVE-2011-3518 Siebel Core - UIF Client Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50256&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3535 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50255&lt;br /&gt;&lt;br /&gt;Oracle Solaris CVE-2011-2313 Local Solaris Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50254&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft Products CVE-2011-3528 Remote PeopleSoft Enterprise HRMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50253&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3534 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50251&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3561 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50250&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50248&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft CVE-2011-3520 PeopleSoft Enterprise PeopleTools Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50247&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3553 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50246&lt;br /&gt;&lt;br /&gt;Oracle Industry Applications CVE-2011-3538 Remote Sun Ray Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50245&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50243&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50242&lt;br /&gt;&lt;br /&gt;Oracle Industry Applications CVE-2011-2309 Remote Health Sciences - Oracle Clinical, Remote Data Cap&lt;br /&gt;http://www.securityfocus.com/bid/50240&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3546 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50239&lt;br /&gt;&lt;br /&gt;Oracle PeopleSoft CVE-2011-3530 PeopleSoft Enterprise HRMS Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50238&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50237&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3560 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50236&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3515 Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50235&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50234&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-2308 Oracle Application Object Library Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50232&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50231&lt;br /&gt;&lt;br /&gt;Oracle Siebel CRM CVE-2011-3526 Remote Siebel Core - UIF Server Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50230&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3516 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50229&lt;br /&gt;&lt;br /&gt;Oracle Waveset CVE-2011-2310 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50228&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3550 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50226&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50224&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3549 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50223&lt;br /&gt;&lt;br /&gt;Oracle Database CVE-2011-2322 Remote Database Vault Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50222&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50220&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3544 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50218&lt;br /&gt;&lt;br /&gt;Oracle E-Business Suite CVE-2011-3513 Oracle Application Object Library Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50217&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3554 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50216&lt;br /&gt;&lt;br /&gt;Oracle Java SE and Java for Business CVE-2011-3521 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50215&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3543 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50214&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-3510 Remote Oracle Business Intelligence Enterprise Edition Vulner&lt;br /&gt;http://www.securityfocus.com/bid/50213&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2237 Remote Oracle Web Services Manager Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50212&lt;br /&gt;&lt;br /&gt;Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50211&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2318 Oracle WebLogic Server Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50210&lt;br /&gt;&lt;br /&gt;Oracle OpenSSO CVE-2011-3517 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50208&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-3541 Oracle Outside In Technology Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50207&lt;br /&gt;&lt;br /&gt;Oracle Database CVE-2011-3512 Remote Core RDBMS Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50203&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2314 Oracle Containers for J2EE Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50202&lt;br /&gt;&lt;br /&gt;Oracle Sun Solaris CVE-2011-3508 Remote Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50201&lt;br /&gt;&lt;br /&gt;Oracle Database CVE-2011-2301 Oracle Text Local Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50199&lt;br /&gt;&lt;br /&gt;Oracle Fusion Middleware CVE-2011-2320 Remote WebLogic Server Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50198&lt;br /&gt;&lt;br /&gt;Oracle Database CVE-2011-3525 Remote Application Express Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50197&lt;br /&gt;&lt;br /&gt;X.Org X11 File Read Permission Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50196&lt;br /&gt;&lt;br /&gt;Site@School 'index.php' Cross Site Scripting and SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50195&lt;br /&gt;&lt;br /&gt;X.Org X11 File Enumeration Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50193&lt;br /&gt;&lt;br /&gt;PAM 'update-motd' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50192&lt;br /&gt;&lt;br /&gt;Joomla NoNumber! Extension Manager Plugin Local File Include and PHP code Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50191&lt;br /&gt;&lt;br /&gt;TYPO3 T3blog Extension Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50190&lt;br /&gt;&lt;br /&gt;Check Point UTM-1 Edge and Safe Multiple Unspecified Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50189&lt;br /&gt;&lt;br /&gt;Joomla! Unspecified Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50188&lt;br /&gt;&lt;br /&gt;Boonex Dolphin 'member_menu_queries.php' PHP Code Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50185&lt;br /&gt;&lt;br /&gt;Piwik Prior to 1.6 Multiple Unspecified Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50182&lt;br /&gt;&lt;br /&gt;HP Data Protector Unspecified Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50181&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-165075379822249679?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/165075379822249679/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/19.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/165075379822249679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/165075379822249679'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/19.html' title='19日 水曜日、先勝'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-6932263733080066196</id><published>2011-10-18T10:17:00.001+09:00</published><updated>2011-10-18T16:18:16.844+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='赤口'/><title type='text'>18日 火曜日、赤口</title><content type='html'>&lt;br /&gt;CESA-2011:1371 (pidgin)&lt;br /&gt;http://lwn.net/Alerts/463346/&lt;br /&gt;&lt;br /&gt;PMASA-2011-16: XSS in setup.&lt;br /&gt;http://www.phpmyadmin.net/home_page/security/PMASA-2011-16.php&lt;br /&gt;&lt;br /&gt;プレス発表&lt;br /&gt;脅威を増す標的型のサイバー攻撃に関する注意喚起&lt;br /&gt;～セキュリティ対応状況の確認と対策の徹底を～&lt;br /&gt;http://www.ipa.go.jp/about/press/20111018.html&lt;br /&gt;&lt;br /&gt;日本オラクル、DBファイアウォール製品を11月出荷&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111018/370976/?ST=security&lt;br /&gt;&lt;br /&gt;Linux Kernel Null Pointer Dereference in AppArmor Lets Local Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026200&lt;br /&gt;&lt;br /&gt;phpMyAdmin Input Validation Flaw in Setup Interface Permits Cross-Site Scripting Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026199&lt;br /&gt;&lt;br /&gt;Logsurfer Double Free Memory Error in prepare_exec() Lets Local Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026198&lt;br /&gt;&lt;br /&gt;GNUBoard Input Validation Flaw in '/bbs/tb.php' Lets Remote Users Inject SQL Commands&lt;br /&gt;http://www.securitytracker.com/id/1026197&lt;br /&gt;&lt;br /&gt;Asterisk SIP Channel Driver Uninitialized Variable Access Bug Lets Remote Users Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026191&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;+ RHSA-2011:1377-1: Moderate: postgresql security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1377.html&lt;br /&gt;&lt;br /&gt;- SA46423: Linux Kernel "apparmor_setprocattr()" Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46423/&lt;br /&gt;http://www.securityfocus.com/bid/50172&lt;br /&gt;&lt;br /&gt;- RHSA-2011:1378-1: Moderate: postgresql84 security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1378.html&lt;br /&gt;&lt;br /&gt;* libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48474&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] PostgreSQL Data Sync released (new software)&lt;br /&gt;http://www.sqlmaestro.com/products/postgresql/datasync/&lt;br /&gt;&lt;br /&gt;Apache James Mime4j 0.7.1 released&lt;br /&gt;http://james.apache.org/newsarchive.html#a111711&lt;br /&gt;&lt;br /&gt;Apache James Protocols 1.6-beta1 released&lt;br /&gt;http://james.apache.org/newsarchive.html#a111611&lt;br /&gt;&lt;br /&gt;Data Exfiltration and Output Devices - An Overlooked Threat&lt;br /&gt;http://www.cert.org/blogs/insider_threat/2011/10/data_exfiltration_and_output_devices_-_an_overlooked_threat.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:155 ] systemtap&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00109.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:154 ] systemtap&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00104.html&lt;br /&gt;&lt;br /&gt;AST-2011-012: Remote crash vulnerability in SIP channel driver&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00108.html&lt;br /&gt;&lt;br /&gt;ZDI-11-290 : Microsoft Internet Explorer SetExpandedClipRect Remote,Code Execution Vulnerabi&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00107.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:153 ] libxfont&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00103.html&lt;br /&gt;&lt;br /&gt;ZDI-11-289 : Microsoft Internet Explorer swapNode Handling Remote Code,Execution Vulnerabili&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00106.html&lt;br /&gt;&lt;br /&gt;ZDI-11-288 : Microsoft Internet Explorer Select Element Insufficient,Type Checking Remote Co&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00105.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:152 ] ncompress&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00102.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:151 ] libpng&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00096.html&lt;br /&gt;&lt;br /&gt;[Announcement] ClubHack Magazine - Call for Articles&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00101.html&lt;br /&gt;&lt;br /&gt;WordPress Plugin BackWPUp 2.1.4 - Security Advisory - SOS-11-012&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00100.html&lt;br /&gt;&lt;br /&gt;DAEMON Tools IOCTL local denial-of-service vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00099.html&lt;br /&gt;&lt;br /&gt;foofus.net Security Advisory - Toshiba eStudio Multifunction Printer Authentication Bypass&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00098.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:150 ] squid&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00095.html&lt;br /&gt;&lt;br /&gt;ZDI-11-287 : Internet Explorer Select Element Cache Remote Code Execution Vulnerability&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00094.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-12 ] Unbound: Denial of Service&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00093.html&lt;br /&gt;&lt;br /&gt;[slackware-security] httpd (SSA:2011-284-01)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00092.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:149 ] cyrus-imapd&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00091.html&lt;br /&gt;&lt;br /&gt;半年で900件の「標的型攻撃」、警察庁が発表&lt;br /&gt;ウイルスで盗んだメールを悪用する「標的型メール」も出現&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111018/370961/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002375 GoAhead Webserver にクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002375.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002374 D-Link DIR-685 Xtreme N Storage Router の暗号化通信に脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002374.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002373 Quagga の ecommunity_ecom2str 関数におけるにおけるヒープベースのバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002373.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002372 Quagga の ospf_flood 関数におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002372.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000088 iOS 上の Safari におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000088.html&lt;br /&gt;&lt;br /&gt;Critical Control 11: Account Monitoring and Control&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11824&lt;br /&gt;&lt;br /&gt;WordPress BackWPup Plugin "BackWPupJobTemp" File Inclusion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46435/&lt;br /&gt;&lt;br /&gt;Linux Kernel "apparmor_setprocattr()" Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46423/&lt;br /&gt;&lt;br /&gt;phpMyAdmin "setup.php" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46431/&lt;br /&gt;&lt;br /&gt;Logsurfer "prepare_exec()" Double-Free Vulnerability&lt;br /&gt;http://secunia.com/advisories/46389/&lt;br /&gt;&lt;br /&gt;WordPress WordPress Users Plugin "uid" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46442/&lt;br /&gt;&lt;br /&gt;Novell Open Enterprise Server DSfW Group Policy Object Security Bypass Security Issue&lt;br /&gt;http://secunia.com/advisories/46444/&lt;br /&gt;&lt;br /&gt;BlueZone Desktop iSeries Printer ZAP File Processing Buffer Overflow&lt;br /&gt;http://secunia.com/advisories/46382/&lt;br /&gt;&lt;br /&gt;aSgbookPHP URL Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46464/&lt;br /&gt;&lt;br /&gt;Fedora update for puppet&lt;br /&gt;http://secunia.com/advisories/46458/&lt;br /&gt;&lt;br /&gt;Gentoo update for unbound&lt;br /&gt;http://secunia.com/advisories/46433/&lt;br /&gt;&lt;br /&gt;Novell Open Enterprise Server Configuration Lets Remote Authenticated Users Gain Elevated Privileges&lt;br /&gt;http://www.securitytracker.com/id/1026190&lt;br /&gt;&lt;br /&gt;REMOTE: Apple Safari file:// Arbitrary Code Execution&lt;br /&gt;http://www.exploit-db.com/exploits/17986/&lt;br /&gt;&lt;br /&gt;RETIRED: Apple Safari Prior to 5.1.1 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50089&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer 'SwapNode()' CVE-2011-2000 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49965&lt;br /&gt;&lt;br /&gt;Apple Safari CVE-2011-3230 'file://' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50162&lt;br /&gt;&lt;br /&gt;SystemTap DWARF Expression Handling Two Divide-By-Zero Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47934&lt;br /&gt;&lt;br /&gt;WordPress Light Post Plugin 'abspath' Parameter Remote File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50080&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Select Element CVE-2011-1999 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49964&lt;br /&gt;&lt;br /&gt;X.Org libXfont LZW Decompression 'BufCompressedFill()' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49124&lt;br /&gt;&lt;br /&gt;GNU gzip LZW Compression Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37886&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Virtual Function Table CVE-2011-2001 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49966&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CIFSFindNext()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49295&lt;br /&gt;&lt;br /&gt;Linux Kernel 'FUSE_NOTIFY_INVAL_ENTRY' Message Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49527&lt;br /&gt;&lt;br /&gt;Linux Kernel 'fs/befs/linuxvfs.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49256&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Option Element CVE-2011-1996 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49961&lt;br /&gt;&lt;br /&gt;Libpurple Yahoo Protocol 'YMSG' NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46837&lt;br /&gt;&lt;br /&gt;Pidgin 'silc_private_message()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49912&lt;br /&gt;&lt;br /&gt;Unbound 'sock_list' Structure Allocation Remote Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/38701&lt;br /&gt;&lt;br /&gt;Unbound DNS Resolver Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47986&lt;br /&gt;&lt;br /&gt;Cyrus IMAP Server 'split_wildmats()' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49534&lt;br /&gt;&lt;br /&gt;ldns 'rr.c' Remote Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49748&lt;br /&gt;&lt;br /&gt;Netzip Classic '.zip' File Parsing Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46059&lt;br /&gt;&lt;br /&gt;libpng PNG File Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48618&lt;br /&gt;&lt;br /&gt;libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48474&lt;br /&gt;&lt;br /&gt;Puppet Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49909&lt;br /&gt;&lt;br /&gt;Openswan IKE Packet NULL Pointer Dereference Remote Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49984&lt;br /&gt;&lt;br /&gt;libpng Buffer Overflow and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48660&lt;br /&gt;&lt;br /&gt;Microsoft Windows TCP/IP QOS CVE-2011-1965 Remote Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48990&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49616&lt;br /&gt;&lt;br /&gt;Apple Safari 'libxml' (CVE-2011-0216) Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48832&lt;br /&gt;&lt;br /&gt;RETIRED: Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50086&lt;br /&gt;&lt;br /&gt;RETIRED: Apple Mac OS X Prior to 10.7.2 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50085&lt;br /&gt;&lt;br /&gt;Cyrus IMAPd NTTP Logic Error Authentication Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49949&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2110 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48268&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0579 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47847&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0620 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47807&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0609 'SWF' File Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46860&lt;br /&gt;&lt;br /&gt;FlexNet License Server Manager Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49191&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2429 Security Control Bypass Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49718&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2428 Logic Error Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49716&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2430 Streaming Media Logic Error Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49717&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2427 AVM Stack Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49715&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2444 Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49710&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2424 Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49186&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2426 AVM Stack Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49714&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2139 Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49086&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2425 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49085&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2417 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49084&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2140 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49083&lt;br /&gt;&lt;br /&gt;Adobe Flash Player 'flash.display' Class Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49082&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2136 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49079&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2416 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49081&lt;br /&gt;&lt;br /&gt;Adobe Flash Player 'BitmapData.scroll' Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49080&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2415 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49077&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2134 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49074&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2137 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49075&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2414 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49076&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2107 Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48107&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-2130 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49073&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0628 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47961&lt;br /&gt;&lt;br /&gt;Adobe Flash Player ActionScript Virtual Machine CVE-2011-0618 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47815&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0625 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47813&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0626 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47814&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0624 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47812&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0623 Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47811&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0621 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47808&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0619 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47806&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0622 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47809&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0627 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47810&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0611 'SWF' File Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47314&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0608 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46283&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-0589 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46202&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0607 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46282&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0574 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46193&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0575 DLL Loading Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46197&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0558 Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46194&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0578 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46195&lt;br /&gt;&lt;br /&gt;Adobe Flash Player Font Parsing Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46196&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0573 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46192&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0572 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46191&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0571 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46190&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0561 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46189&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0560 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46188&lt;br /&gt;&lt;br /&gt;FlexNet License Server Manager 'lmadmin' Component Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48927&lt;br /&gt;&lt;br /&gt;Adobe Flash Player CVE-2011-0559 Remote Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46186&lt;br /&gt;&lt;br /&gt;OcoMon Multiple Unspecified SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47424&lt;br /&gt;&lt;br /&gt;Novell GroupWise Internet Agent 'TZID' Variable Parsing Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46025&lt;br /&gt;&lt;br /&gt;Conky 'tmp/.cesf' Insecure Temporary File Creation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46184&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey 'Array.reduceRight()' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48372&lt;br /&gt;&lt;br /&gt;feh '--wget-timestamp' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/41161&lt;br /&gt;&lt;br /&gt;feh 'feh_unique_filename()' Predictable Filename Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46182&lt;br /&gt;&lt;br /&gt;Adobe Acrobat and Reader CVE-2011-2438 Multiple Remote Stack Buffer Overflow Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49580&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49303&lt;br /&gt;&lt;br /&gt;Microsoft Excel Conditional Expression CVE-2011-1989 Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49518&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/media/dvb/ttpci/av7110_ca' IOCTL Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45986&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/scsi/bfa/bfa_core.c' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45262&lt;br /&gt;&lt;br /&gt;Linux Kernel CVE-2010-4073 Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45073&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel '.fon' Font File Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49975&lt;br /&gt;&lt;br /&gt;Ruby on Rails 'WEBrick::HTTPRequest' Module HTTP Header Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46423&lt;br /&gt;&lt;br /&gt;Linux Kernel Generic Receive Offload (GRO) Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47056&lt;br /&gt;&lt;br /&gt;Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49957&lt;br /&gt;&lt;br /&gt;Linux Kernel NFS Access Control List (ACL) Allocation Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46766&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ethtool.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45972&lt;br /&gt;&lt;br /&gt;Linux Kernel 'task_show_regs()' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46421&lt;br /&gt;&lt;br /&gt;Linux Kernel SCTP Local Race Condition Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45661&lt;br /&gt;&lt;br /&gt;Linux Kernel Validate 'map_count' Variable Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46492&lt;br /&gt;&lt;br /&gt;Linux Kernel 'install_special_mapping()' Local Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45323&lt;br /&gt;&lt;br /&gt;Linux Kernel IGB Panic VLAN Packet Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45208&lt;br /&gt;&lt;br /&gt;Linux Kernel Unix Socket Backlog Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46637&lt;br /&gt;&lt;br /&gt;Linux Kernel 'posix-cpu-timers.c' Local Race Condition Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45028&lt;br /&gt;&lt;br /&gt;Xen 'fixup_page_fault()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45099&lt;br /&gt;&lt;br /&gt;PtokaX Directory Traversal And Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50179&lt;br /&gt;&lt;br /&gt;Dominant Creature BBG RPG 'msg.php' Parameter Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50178&lt;br /&gt;&lt;br /&gt;Asterisk Uninitalized Variable SIP Channel Driver Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50177&lt;br /&gt;&lt;br /&gt;BackWPup Plugin for WordPress 'wp_export_generate.php' Local and Remote File Include Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50176&lt;br /&gt;&lt;br /&gt;phpMyAdmin Setup Interface Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50175&lt;br /&gt;&lt;br /&gt;WordPress Users Plugin "uid" Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50174&lt;br /&gt;&lt;br /&gt;Gnuboard 'board.php' SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50173&lt;br /&gt;&lt;br /&gt;Linux Kernel 'apparmor_setprocattr()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50172&lt;br /&gt;&lt;br /&gt;Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50171&lt;br /&gt;&lt;br /&gt;Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50170&lt;br /&gt;&lt;br /&gt;Multiple Toshiba e-Studio Devices Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50168&lt;br /&gt;&lt;br /&gt;asgbookphp 'index.php' Cross Site Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50167&lt;br /&gt;&lt;br /&gt;BlueZone Desktop '.zap' File Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50166&lt;br /&gt;&lt;br /&gt;RuubikCMS 'f' Parameter Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50165&lt;br /&gt;&lt;br /&gt;WordPress WP Photo Album Plus Plugin 'wppa-album' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50164&lt;br /&gt;&lt;br /&gt;Apple Safari 'safari-extension://' URL Handling Directory Traversal Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50163&lt;br /&gt;&lt;br /&gt;Apple iOS Free Type Font Document Multiple Memory Corruption Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50155&lt;br /&gt;&lt;br /&gt;Quassel Core Insecure File Permissions Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50148&lt;br /&gt;&lt;br /&gt;Sybase M-Business Anywhere Multiple Unspecified Remote Privilege Escalation Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50145&lt;br /&gt;&lt;br /&gt;WordPress Contact Form Plugin 'wpcf_easyform_formid' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50142&lt;br /&gt;&lt;br /&gt;Xenon 'id' Parameter Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50141&lt;br /&gt;&lt;br /&gt;EC-CUBE Multiple Unspecified SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50140&lt;br /&gt;&lt;br /&gt;DBD::mysqlPP Unspecified SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50139&lt;br /&gt;&lt;br /&gt;Joomla! Directory Tree Component SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50138&lt;br /&gt;&lt;br /&gt;PROMOTIC Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50133&lt;br /&gt;&lt;br /&gt;Joomla! eTree Component 'id' Parameter Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50132&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Prior to 10.7.2 CVE-2011-3221 Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50131&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-6932263733080066196?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/6932263733080066196/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/18.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6932263733080066196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6932263733080066196'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/18.html' title='18日 火曜日、赤口'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-923160063002588718</id><published>2011-10-17T09:49:00.003+09:00</published><updated>2011-10-17T16:14:10.626+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='大安'/><title type='text'>17日 月曜日、大安</title><content type='html'>&lt;br /&gt;- TCP and UDP Ports required to access vCenter Server, ESX hosts, and other network components&lt;br /&gt;http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=1012382&amp;amp;sliceId=1&amp;amp;docTypeID=DT_KB_1_1&lt;br /&gt;&lt;br /&gt;プレス発表&lt;br /&gt;第7回IPA情報セキュリティ標語・ポスターコンクール　受賞作品決定&lt;br /&gt;～大賞として、標語部門は「セキュリティ　ぼくと世界の　かけ橋だ」、&lt;br /&gt;　 ポスター部門は「ネットで世界と人と気持ちもつながっている」を選定～&lt;br /&gt;http://www.ipa.go.jp/about/press/20111017.html&lt;br /&gt;&lt;br /&gt;JVN#41657660 iOS 上の Safari におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN41657660/index.html&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;+ MS11-064 : Vulnerabilities in TCP/IP Stack Could&lt;br /&gt;http://www.exploit-db.com/exploits/17981/&lt;br /&gt;&lt;br /&gt;Fixed in Apache Tomcat 6.0.34 (not yet released)&lt;br /&gt;http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.34_(not_yet_released)&lt;br /&gt;&lt;br /&gt;The Apache Software Foundation Statement on Apache OpenOffice.org&lt;br /&gt;https://blogs.apache.org/foundation/entry/the_apache_software_foundation_statement&lt;br /&gt;&lt;br /&gt;Hosted Email Security　製品メンテナンス延期のお知らせ&lt;br /&gt;http://www.trendmicro.co.jp/support/news.asp?id=1663&lt;br /&gt;&lt;br /&gt;プレス発表&lt;br /&gt;「EC-CUBE」におけるセキュリティ上の弱点（脆弱性）の注意喚起&lt;br /&gt;http://www.ipa.go.jp/about/press/20111014.html&lt;br /&gt;&lt;br /&gt;カスペルスキーが法人向けセキュリティソフトの新版を発表&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111014/370819/?ST=security&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002371 Perl モジュール Crypt::DSA における署名を偽装される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002371.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002370 Quagga の ospfd 内の ospf_packet.c におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002370.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002369 Quagga の ospf6_lsa.c 内にある ospf6_lsa_is_changed 関数におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002369.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002368 Quagga の ospf6d 内にある OSPFv3 実装におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002368.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000087 EC-CUBE における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000087.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000086 DBD::mysqlPP における SQL インジェクションの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000086.html&lt;br /&gt;&lt;br /&gt;JVNDB-2010-002869 Novell GroupWise の GroupWise Internet Agent (GWIA) におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002869.html&lt;br /&gt;&lt;br /&gt;JVNDB-2010-002868 Novell GroupWise の GroupWise Internet Agent (GWIA) におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002868.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002367 phpPgAdmin におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002367.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002366 Novell GroupWise の GroupWise Internet Agent における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002366.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002365 Novell GroupWise の GroupWise Internet Agent における整数符号エラーの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002365.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002364 Novell GroupWise の WebAccess におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002364.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002363 Novell Identity Manager におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002363.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002362 Novell Identity Manager におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002362.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002361 Novell GroupWise の GWIA 内にある gwia.exe におけるスタックベースのバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002361.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002360 Novell GroupWise の GWIA 内にある gwwww1.dll におけるヒープベースのバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002360.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002359 複数の VMware 製品におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002359.html&lt;br /&gt;&lt;br /&gt;[PTResearch] SAP DIAG Decompress plugin for Wireshark&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00090.html&lt;br /&gt;&lt;br /&gt;DC4420 - London DEFCON - October meet - Tuesday October 18th 2011&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00089.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-11 ] Adobe Flash Player: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00088.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-10 ] Wget: User-assisted file creation or overwrite&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00087.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-09 ] Conky: Privilege escalation&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00086.html&lt;br /&gt;&lt;br /&gt;[ GLSA 201110-08 ] feh: Multiple vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00085.html&lt;br /&gt;&lt;br /&gt;DNS Sinkhole Parser Script Update&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11818&lt;br /&gt;&lt;br /&gt;BXR 0.6.8 SQL injection vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8470&lt;br /&gt;&lt;br /&gt;Pre Podcast Portal SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8469&lt;br /&gt;&lt;br /&gt;Prado Portal XSS vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8468&lt;br /&gt;&lt;br /&gt;APBoard 2.1.0 SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8467&lt;br /&gt;&lt;br /&gt;xt:Commerce Gambio 2008 - 2010 SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8466&lt;br /&gt;&lt;br /&gt;Sybase M-Business Anywhere Bugs Let Remote Users Gain Elevated Access Rights&lt;br /&gt;http://www.securitytracker.com/id/1026189&lt;br /&gt;&lt;br /&gt;Opera Nested SVG Content Processing Code Execution Vulnerability&lt;br /&gt;http://secunia.com/advisories/46375/&lt;br /&gt;&lt;br /&gt;Gentoo update for feh&lt;br /&gt;http://secunia.com/advisories/46356/&lt;br /&gt;&lt;br /&gt;Ubuntu update for quassel&lt;br /&gt;http://secunia.com/advisories/46445/&lt;br /&gt;&lt;br /&gt;Sybase M-Business Anywhere Two Unspecified Privilege Escalation Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46424/&lt;br /&gt;&lt;br /&gt;WordPress Contact Form Plugin "wpcf_easyform_formid" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46434/&lt;br /&gt;&lt;br /&gt;EC-CUBE Two Unspecified SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46446/&lt;br /&gt;&lt;br /&gt;PROMOTIC Directory Traversal and ActiveX Control Buffer Overflow Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46430/&lt;br /&gt;&lt;br /&gt;Joomla! eTree Component "id" and "user_id" SQL Injection Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46441/&lt;br /&gt;&lt;br /&gt;Red Hat update for pidgin&lt;br /&gt;http://secunia.com/advisories/46376/&lt;br /&gt;&lt;br /&gt;Gentoo update for conky&lt;br /&gt;http://secunia.com/advisories/46353/&lt;br /&gt;&lt;br /&gt;Gentoo update for wget&lt;br /&gt;http://secunia.com/advisories/46324/&lt;br /&gt;&lt;br /&gt;Gentoo update for adobe-flash&lt;br /&gt;http://secunia.com/advisories/46322/&lt;br /&gt;&lt;br /&gt;Fedora update for openswan&lt;br /&gt;http://secunia.com/advisories/46384/&lt;br /&gt;&lt;br /&gt;Fedora update for cyrus-imapd&lt;br /&gt;http://secunia.com/advisories/46388/&lt;br /&gt;&lt;br /&gt;Sybase M-Business Anywhere Unauthorized Access Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2186.php&lt;br /&gt;&lt;br /&gt;Opera Browser SVG Data Processing Remote Code Execution&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2185.php&lt;br /&gt;&lt;br /&gt;Apple Numbers for iOS Excel Document Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2184.php&lt;br /&gt;&lt;br /&gt;Apple Pages for iOS Word Document Code Execution Vulnerability&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2183.php&lt;br /&gt;&lt;br /&gt;Apple Safari Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2182.php&lt;br /&gt;&lt;br /&gt;Apple OS X Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2181.php&lt;br /&gt;&lt;br /&gt;Apple TV Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2180.php&lt;br /&gt;&lt;br /&gt;Apple iOS Multiple Code Execution and Information Disclosure&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2179.php&lt;br /&gt;&lt;br /&gt;Apple iTunes Multiple Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2178.php&lt;br /&gt;&lt;br /&gt;BlackBerry Enterprise Server Collaboration Service Unauthorized Access&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2177.php&lt;br /&gt;&lt;br /&gt;Google App Engine SDK for Python Code Execution Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2176.php&lt;br /&gt;&lt;br /&gt;Hitachi JP1/Cm2/Network Node Manager i Multiple Vulnerabilities&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2175.php&lt;br /&gt;&lt;br /&gt;VMware ESXi and ESX Multiple Code Execution and Denial of Service&lt;br /&gt;http://www.vupen.com/english/ADV-2011-2174.php&lt;br /&gt;&lt;br /&gt;DoS/PoC: BlueZone Desktop .zap file Local Denial of Service Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/17982/&lt;br /&gt;&lt;br /&gt;DoS/PoC: MS11-064 TCP/IP Stack Denial of Service&lt;br /&gt;http://www.exploit-db.com/exploits/17981/&lt;br /&gt;&lt;br /&gt;phpMyAdmin 3.4.6 is released&lt;br /&gt;http://sourceforge.net/news/?group_id=23067&amp;amp;id=304006&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-923160063002588718?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/923160063002588718/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/17.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/923160063002588718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/923160063002588718'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/17.html' title='17日 月曜日、大安'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-6629193152686363570</id><published>2011-10-14T10:05:00.004+09:00</published><updated>2011-10-14T16:32:03.808+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='友引'/><title type='text'>14日 金曜日、友引</title><content type='html'>&lt;br /&gt;- Moderate: pidgin security update&lt;br /&gt;http://rhn.redhat.com/errata/RHSA-2011-1371.html&lt;br /&gt;&lt;br /&gt;bind10-devel-20111014 now available&lt;br /&gt;https://lists.isc.org/mailman/listinfo/bind10-users&lt;br /&gt;&lt;br /&gt;[ANNOUNCE] pgpoolAdmin 3.1.0 released&lt;br /&gt;http://pgfoundry.org/projects/pgpool/&lt;br /&gt;&lt;br /&gt;Squid 3.1.16 released&lt;br /&gt;http://www.squid-cache.org/Versions/v3/3.1/&lt;br /&gt;&lt;br /&gt;Squid 3.2.0.13 released&lt;br /&gt;http://www.squid-cache.org/Versions/v3/3.2/RELEASENOTES.html&lt;br /&gt;&lt;br /&gt;JVNVU#800227 OneOrZero AIMS に複数の脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU800227/index.html&lt;br /&gt;&lt;br /&gt;JVN#44496332 EC-CUBE における SQL インジェクションの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN44496332/index.html&lt;br /&gt;&lt;br /&gt;JVN#51216285 DBD::mysqlPP における SQL インジェクションの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN51216285/index.html&lt;br /&gt;&lt;br /&gt;JVNTA11-286A Apple Mac OS Xにおける複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNTA11-286A/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#971123 Apple Mac OS Xにおける複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU971123/index.html&lt;br /&gt;&lt;br /&gt;JVNTA11-284A Microsoft 製品における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNTA11-284A/index.html&lt;br /&gt;&lt;br /&gt;HTB Team : [HTB23049] Pretty Link WordPress Plugin - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36873&lt;br /&gt;&lt;br /&gt;HTB Team : [HTB23048] BugFree - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36874&lt;br /&gt;&lt;br /&gt;Independant Researcher : Internet Explorer - Multiple Code Execution Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36879&lt;br /&gt;&lt;br /&gt;SEC Consult : [SEC Consult SA-20111012-0] Microsoft Forefront UAG - Remote Access Agent Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36880&lt;br /&gt;&lt;br /&gt;Apple : [APPLE-SA-2011-10-12-6 ] iOS - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36876&lt;br /&gt;&lt;br /&gt;Apple : [APPLE-SA-2011-10-12-5 ] iOS - Memory Corruption Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36877&lt;br /&gt;&lt;br /&gt;Apple : [APPLE-SA-2011-10-12-2] Apple TV - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36878&lt;br /&gt;&lt;br /&gt;Emaze Networks : ZOHO - ManageEngine ADSelfService and Administrative Access - Authentication Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36855&lt;br /&gt;&lt;br /&gt;Hewlett-Packard : [HPSBMU02710 SSRT100601] HP - Onboard Administrator (OA) - Security Bypass Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36857&lt;br /&gt;&lt;br /&gt;iDEFENSE : Microsoft - Internet Explorer - Memory Corruption Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36875&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:148] Samba - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36864&lt;br /&gt;&lt;br /&gt;Red Hat : [RHSA-2011:1364-01] kdelibs - Spoofing Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36854&lt;br /&gt;&lt;br /&gt;Ubuntu Security Notice : [USN-1227-1] Linux - kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36853&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2319-1] Policykit - Privilege Escalation Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36846&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2320-1] dokuwiki - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36847&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2321-1] Moin - Cross-site Scripting Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36848&lt;br /&gt;&lt;br /&gt;Debian : [DSA-2322-1] Bugzilla - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36849&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-06] PHP - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36859&lt;br /&gt;&lt;br /&gt;Independant Researcher : Google - App Engine SDK - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36863&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:145] libxml2 - Double Free Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36850&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:146] CUPS - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36851&lt;br /&gt;&lt;br /&gt;Mandriva : [MDVSA-2011:147] CUPS - Buffer Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36852&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-078] .NET Framework and Microsoft Silverlight - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36865&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-081] Internet Explorer - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36866&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-075] Microsoft - Active Accessibility - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36867&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-076] Windows - Media Center - Code Execution Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36868&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-077] Windows - Kernel - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36869&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-079] Microsoft - Frontend Unified Access Gateway - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36870&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-080] Anciallary Function Driver - Privilege Escalation Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36871&lt;br /&gt;&lt;br /&gt;Microsoft : [MS11-082] Host Integration Server - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36872&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-07] vsftpd - Denial-Of-Service Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36858&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-05] GnuTLS - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36860&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-04] Dovecot - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36861&lt;br /&gt;&lt;br /&gt;Gentoo Linux : [GLSA 201110-03] - Bugzilla - Multiple Issues&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36862&lt;br /&gt;&lt;br /&gt;NGS Secure Research : Apple - OSX and iPhone ImageIO - Heap Overflow Issue&lt;br /&gt;http://www.criticalwatch.com/support/security-advisories.aspx?AID=36856&lt;br /&gt;&lt;br /&gt;Critical Control 9 - Controlled Access Based on the Need to Know&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11812&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Oracle Critical Patch Update Pre-Release Announcement - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html&lt;br /&gt;&lt;br /&gt;Oracle Java SE Critical Patch Update Pre-Release Announcement - October 2011&lt;br /&gt;http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html&lt;br /&gt;&lt;br /&gt;JVN#07414354 DAEMON Tools におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN07414354/index.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002358 Cherokee の Cherokee-admin におけるクロスサイトリクエストフォージェリの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002358.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002357 Cherokee の generate_admin_password 関数における admin パスワードを推測される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002357.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002356 Linux kernel の net/core/net_namespace.c におけるサービス運用妨害 (メモリ破損) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002356.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002355 Plone で使用される Zope における任意のコマンドを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002355.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002354 Plone の CMFEditions コンポーネントにおけるサブオブジェクトにアクセスされる脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002354.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002353 gitolite の Admin Defined Commands (ADC) 機能におけるディレクトリトラバーサルの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002353.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002352 EtherApe の add_conversation 関数におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002352.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000085 DAEMON Tools におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000085.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000084 Pligg におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000084.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-000083 Plume におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000083.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002351 Apache HTTP Server の mod_proxy モジュールにおけるイントラネットサーバにリクエストを送信される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002351.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002350 IBM AIX の QLogic adapters 用 Fibre Channel ドライバにおけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002350.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002349 Check Point の 複数の製品における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002349.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002348 Exim の src/dkim.c 内の dkim_exim_verify_finish 関数における任意のコードを実行される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002348.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002347 Ted Felix acpid の acpid.c におけるサービス運用妨害 (デーモンハング) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002347.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002346 Linux kernel の net/dns_resolver/dns_key.c におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002346.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002345 RealNetworks RealPlayer の ActiveX コントロールにおけるクロスゾーンスクリプティングの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002345.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002344 Adobe Photoshop Elements におけるバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002344.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002343 Quassel の CtcpParser::packedReply メソッドにおけるサービス運用妨害 (クラッシュ) の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002343.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002342 VMware の Spring Framework および Spring Security におけるセキュリティ制限を回避される脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002342.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002341 UPnP 対応の複数のルータにアクセス制限不備の脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002341.html&lt;br /&gt;&lt;br /&gt;JVNDB-2011-002340 Iceni Argus にバッファオーバーフローの脆弱性&lt;br /&gt;http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002340.html&lt;br /&gt;&lt;br /&gt;iDefense Security Advisory 10.12.11: Apple Mobile OfficeImport Framework Word Document Parsing Memor&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00084.html&lt;br /&gt;&lt;br /&gt;iDefense Security Advisory 10.12.11: Apple MobileSafari Attachment Viewing Cross Site Scripting Vuln&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00083.html&lt;br /&gt;&lt;br /&gt;Multiple G-WAN vulnerabilities&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00082.html&lt;br /&gt;&lt;br /&gt;SEC Consult SA-20111012-0 :: Client-side remote file upload &amp;amp; command execution in M&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00080.html&lt;br /&gt;&lt;br /&gt;VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00079.html&lt;br /&gt;&lt;br /&gt;Security-Assessment.com Advisory: Destination Search Admin Console Access Control Bypass&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00081.html&lt;br /&gt;&lt;br /&gt;Two Remote Code Execution Vulnerabilities in Internet Explorer&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00078.html&lt;br /&gt;&lt;br /&gt;iDefense Security Advisory 10.11.11: Microsoft Internet Explorer Object Handling Memory Corruption V&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00076.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-6 Numbers for iOS v1.5&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00075.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-5 Pages for iOS v1.5&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00074.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-4 Safari 5.1.1&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00077.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-3 OS X Lion v10.7.2 and Security Update 2011-006&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00073.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-2 Apple TV Software Update 4.4&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00071.html&lt;br /&gt;&lt;br /&gt;APPLE-SA-2011-10-12-1 iOS 5 Software Update&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00072.html&lt;br /&gt;&lt;br /&gt;CORE-2011-0106: Microsoft Publisher 2007 Pubconv.dll Memory Corruption&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00070.html&lt;br /&gt;&lt;br /&gt;Multiple vulnerabilities in BugFree&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00067.html&lt;br /&gt;&lt;br /&gt;Multiple vulnerabilities in Pretty Link WordPress Plugin&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00068.html&lt;br /&gt;&lt;br /&gt;LedgerSMB 1.3.0 released, includes anti-XSRF framework&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00066.html&lt;br /&gt;&lt;br /&gt;[ MDVSA-2011:148 ] samba&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00064.html&lt;br /&gt;&lt;br /&gt;Google App Enging SDK Code Execution Vulnerability (CVE 2011-1364)&lt;br /&gt;http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00065.html&lt;br /&gt;&lt;br /&gt;Joomla Camelcitydb2 2.2 SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8465&lt;br /&gt;&lt;br /&gt;E-Xoopport Samsara 3.1 eCal Module Blind SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8464&lt;br /&gt;&lt;br /&gt;Joomla Component Multiple Blind SQL Injection Vulnerabilities&lt;br /&gt;http://securityreason.com/securityalert/8463&lt;br /&gt;&lt;br /&gt;WAnewsletter v 2.1.2 SQL Injection Vulnerability&lt;br /&gt;http://securityreason.com/securityalert/8462&lt;br /&gt;&lt;br /&gt;Joomla Slideshow SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8461&lt;br /&gt;&lt;br /&gt;Virtue Book Store SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8460&lt;br /&gt;&lt;br /&gt;Nuked-Klan Partenaires NK 1.5 Blind SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8459&lt;br /&gt;&lt;br /&gt;Joomla Restaurant Guide Cross Site Scripting / Local File Inclusion / SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8458&lt;br /&gt;&lt;br /&gt;GeekLog 1.3.8 SQL Injection&lt;br /&gt;http://securityreason.com/securityalert/8457&lt;br /&gt;&lt;br /&gt;Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://securityreason.com/securityalert/8456&lt;br /&gt;&lt;br /&gt;Atmail WebMail &amp;lt; v6.2.0 Reflected XSS&lt;br /&gt;http://securityreason.com/securityalert/8455&lt;br /&gt;&lt;br /&gt;TimeTrack 1.2.4 Joomla Component Multiple SQL Injection Vulnerabilities&lt;br /&gt;http://securityreason.com/securityalert/8454&lt;br /&gt;&lt;br /&gt;allinta CMS SQL injection vulnerability&lt;br /&gt;http://securityreason.com/securityalert/8453&lt;br /&gt;&lt;br /&gt;Cisco TelePresence Video Communication Server Input Validation Flaw Permits Cross-Site Scripting Attacks&lt;br /&gt;http://www.securitytracker.com/id/1026186&lt;br /&gt;&lt;br /&gt;Mac OS X Multiple Flaws Lets Local Users Gain Elevated Privileges and Remote Users Execute Arbitrary Code and Deny Service&lt;br /&gt;http://www.securitytracker.com/id/1026184&lt;br /&gt;&lt;br /&gt;VU#800227: OneOrZero AIMS authentication bypass and SQLi vulnerabilities&lt;br /&gt;http://www.kb.cert.org/vuls/id/800227&lt;br /&gt;&lt;br /&gt;D-Link DIR-685 Xtreme N Storage Router Encryption Failure Weakness&lt;br /&gt;http://secunia.com/advisories/46380/&lt;br /&gt;&lt;br /&gt;WordPress Pretty Link Plugin Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46432/&lt;br /&gt;&lt;br /&gt;IBM OS/400 HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness&lt;br /&gt;http://secunia.com/advisories/46414/&lt;br /&gt;&lt;br /&gt;DAEMON Tools Unspecified Denial of Service Vulnerability&lt;br /&gt;http://secunia.com/advisories/46416/&lt;br /&gt;&lt;br /&gt;Apple TV Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46415/&lt;br /&gt;&lt;br /&gt;WordPress teachPress Plugin "root" Two Local File Inclusion Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46436/&lt;br /&gt;&lt;br /&gt;Apple iOS Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46377/&lt;br /&gt;&lt;br /&gt;Simple Machines Forum Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46386/&lt;br /&gt;&lt;br /&gt;VMware ESX / ESXi Server Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46397/&lt;br /&gt;&lt;br /&gt;BugFree Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46428/&lt;br /&gt;&lt;br /&gt;Apple Safari Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46412/&lt;br /&gt;&lt;br /&gt;Drupal Certificate Login Module SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46393/&lt;br /&gt;&lt;br /&gt;Minitube Insecure Temporary Files Security Issue&lt;br /&gt;http://secunia.com/advisories/46429/&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46417/&lt;br /&gt;&lt;br /&gt;Apple Pages for iOS OfficeArtMetafileHeader Record Parsing Vulnerability&lt;br /&gt;http://secunia.com/advisories/46418/&lt;br /&gt;&lt;br /&gt;Apple Numbers for iOS Two Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46419/&lt;br /&gt;&lt;br /&gt;Fedora update for phpPgAdmin&lt;br /&gt;http://secunia.com/advisories/46426/&lt;br /&gt;&lt;br /&gt;REMOTE: PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability&lt;br /&gt;http://www.exploit-db.com/exploits/17975/&lt;br /&gt;&lt;br /&gt;REMOTE: Mozilla Firefox Array.reduceRight() Integer Overflow&lt;br /&gt;http://www.exploit-db.com/exploits/17976/&lt;br /&gt;&lt;br /&gt;REMOTE: JBoss AS Remote Exploit v2&lt;br /&gt;http://www.exploit-db.com/exploits/17977/&lt;br /&gt;&lt;br /&gt;DoS/PoC: MS11-077 .fon Kernel-Mode Buffer Overrun PoC&lt;br /&gt;http://www.exploit-db.com/exploits/17978/&lt;br /&gt;&lt;br /&gt;Linux Kernel Unix Sockets Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45037&lt;br /&gt;&lt;br /&gt;Linux Kernel Futex Macros Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44754&lt;br /&gt;&lt;br /&gt;Xen 'drivers/xen/blkback/blkback.c' Local Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45029&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CHELSIO_GET_QSET_NUM' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43221&lt;br /&gt;&lt;br /&gt;XFS Deleted Inode Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42527&lt;br /&gt;&lt;br /&gt;Linux Kernel 'net/sched/act_police.c' File Memory Leak Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42529&lt;br /&gt;&lt;br /&gt;Linux Kernel Xen Hypervisor Implementation Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43578&lt;br /&gt;&lt;br /&gt;Linux Kernel 'execve()' Memory Expansion 'OOM-killer' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45004&lt;br /&gt;&lt;br /&gt;Linux Kernel 'hci_uart_tty_open()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45014&lt;br /&gt;&lt;br /&gt;Xen 'vbd_create()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45795&lt;br /&gt;&lt;br /&gt;Linux Kernel 'net/core/filter.c' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44758&lt;br /&gt;&lt;br /&gt;Linux Kernel 'net/' Subsystem Socket Filter CVE-2010-4161 Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45064&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/scsi/gdth.c' IOCTL Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44648&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ipc/sem.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43809&lt;br /&gt;&lt;br /&gt;Linux Kernel 'SNDRV_HDSP_IOCTL_GET_CONFIG_INFO' IOCTL Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45058&lt;br /&gt;&lt;br /&gt;Linux Kernel 'hdsp.c' IOCTL Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45063&lt;br /&gt;&lt;br /&gt;Linux Kernel TIOCGICOUNT 'serial_core.c' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43806&lt;br /&gt;&lt;br /&gt;Linux Kernel 'hmid_ds structure' Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45054&lt;br /&gt;&lt;br /&gt;Linux Kernel 'inet_diag.c' Netlink Message Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44665&lt;br /&gt;&lt;br /&gt;Linux Kernel Multiple 'net/' Subsystems Local Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/44630&lt;br /&gt;&lt;br /&gt;Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44219&lt;br /&gt;&lt;br /&gt;Linux Kernel Reliable Datagram Sockets (RDS) Protocol Local Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44549&lt;br /&gt;&lt;br /&gt;Linux Kernel 'setup_arg_pages()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44301&lt;br /&gt;&lt;br /&gt;Linux Kernel Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44354&lt;br /&gt;&lt;br /&gt;Linux Kernel ALSA 'sound/core/control.c' Local Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43787&lt;br /&gt;&lt;br /&gt;Xen 'blkback/blktap/netback' Leaked Kernel Thread Local Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45039&lt;br /&gt;&lt;br /&gt;Linux Kernel 'sctp_outq_flush()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43480&lt;br /&gt;&lt;br /&gt;Linux Kernel 'do_io_submit()' Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43353&lt;br /&gt;&lt;br /&gt;Linux Kernel 'XFS_IOC_FSGETXATTR' Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/43022&lt;br /&gt;&lt;br /&gt;Linux Kernel GFS2 Directory Rename NULL Pointer Dereference Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42124&lt;br /&gt;&lt;br /&gt;Linux Kernel EXT4 Multiple Local Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/42477&lt;br /&gt;&lt;br /&gt;Linux Kernel 'io_submit_one()' NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44755&lt;br /&gt;&lt;br /&gt;Linux Kernel USB interface Local Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/39042&lt;br /&gt;&lt;br /&gt;Linux Kernel 'ecryptfs_uid_hash()' Local Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/42237&lt;br /&gt;&lt;br /&gt;WebKit Multiple Unspecifeid Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50066&lt;br /&gt;&lt;br /&gt;Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50086&lt;br /&gt;&lt;br /&gt;Linux Kernel 'mpt2sas' Local Privilege Escalation and Information Disclosure Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47185&lt;br /&gt;&lt;br /&gt;'glibc' Library 'locale/programs/locale.c' Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47370&lt;br /&gt;&lt;br /&gt;GNU glibc 'fnmatch()' Function Stack Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46563&lt;br /&gt;&lt;br /&gt;MIT Kerberos KDC LDAP File Descriptor Leak Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46265&lt;br /&gt;&lt;br /&gt;MIT Kerberos 5 1.3.x Checksum Multiple Remote Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45118&lt;br /&gt;&lt;br /&gt;MIT Kerberos KDC Principal Name LDAP Request NULL Pointer Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46271&lt;br /&gt;&lt;br /&gt;WordPress Filedownload Local File Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49669&lt;br /&gt;&lt;br /&gt;PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49241&lt;br /&gt;&lt;br /&gt;PcVue ActiveX Control Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49795&lt;br /&gt;&lt;br /&gt;phpPgAdmin Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49914&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Option Element CVE-2011-1996 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49961&lt;br /&gt;&lt;br /&gt;Microsoft Forefront Unified Access Gateway 'MicrosoftClient.Jar' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49983&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Select Element CVE-2011-1999 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49964&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey 'Array.reduceRight()' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48372&lt;br /&gt;&lt;br /&gt;Microsoft Silverlight &amp;amp; .NET Framework Inheritance Restriction Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49999&lt;br /&gt;&lt;br /&gt;Microsoft Windows Active Accessibility DLL Loading Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49976&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45015&lt;br /&gt;&lt;br /&gt;Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50103&lt;br /&gt;&lt;br /&gt;Apple Mac OS X CVE-2011-0231 Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50098&lt;br /&gt;&lt;br /&gt;Supermicro IPMI Web Interface Multiple Security Bypass Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50097&lt;br /&gt;&lt;br /&gt;WordPress Pretty Link Plugin Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50096&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-6629193152686363570?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/6629193152686363570/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/14.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6629193152686363570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/6629193152686363570'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/14.html' title='14日 金曜日、友引'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-8910676353195495108</id><published>2011-10-13T14:48:00.000+09:00</published><updated>2011-10-13T14:48:39.495+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='iOS 5'/><category scheme='http://www.blogger.com/atom/ns#' term='iOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><title type='text'>iOS 5 のセキュリティアップデート</title><content type='html'>About the security content of iOS 5 Software Update&lt;br /&gt;&lt;br /&gt;http://support.apple.com/kb/HT4999&lt;br /&gt;&lt;br /&gt;上記 URL の iOS のセキュリティアップデートの翻訳&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: monospace; white-space: pre-wrap;"&gt;1) CalDAV&lt;/span&gt;&lt;br /&gt;&lt;pre wrap=""&gt;　CalDAV が信頼あるサーバによる SSL 証明書をチェックしていないことが原因で、CalDAV カレンダーサーバからユーザの認証情報または他の機密情報を妨害される脆弱性。(CVE-2011-3253)&lt;br /&gt;&lt;br /&gt;2) Calendar&lt;br /&gt;　カレンダーが招待状を取り扱う際にスクリプト挿入問題が存在することが原因で、ローカルドメインにスクリプトを挿入される脆弱性。(CVE-2011-3254)&lt;br /&gt;&lt;br /&gt;3) CFNetwork&lt;br /&gt;　ユーザの AppleID のパスワードとユーザをロギングしたファイルがシステム上のアプリケーションから読み込み可能なことが原因で、重要な情報を取得される脆弱性。(CVE-2011-3255)&lt;br /&gt;&lt;br /&gt;4) CFNetwork&lt;br /&gt;　CFNetwork が HTTP クッキーを取り扱い際の問題が原因で、ドメイン外のサーバにクッキー情報を送信してしまう脆弱性。(CVE-2011-3246)&lt;br /&gt;&lt;br /&gt;5) CoreFoundation&lt;br /&gt;　CoreFoundation が文字列のトークン化処理の際にメモリ破壊が発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0259)&lt;br /&gt;&lt;br /&gt;6) CoreGraphics&lt;br /&gt;　freetype に複数のメモリ破壊が存在することが原因で、細工されたフォントを処理する際に任意コードを実行される脆弱性。(CVE-2011-3256)&lt;/pre&gt;&lt;pre wrap=""&gt;7) CoreMedia&lt;br /&gt;　CoreMedia がクロスサイト・リダイレクトを取り扱う際にクロスオリジン問題が存在することが原因で、他のサイトから動画データを取得される脆弱性。(CVE-2011-0187)&lt;br /&gt;&lt;br /&gt;8) Data Access&lt;br /&gt;　同一のサーバに接続する複数の Exchange メールサーバのアカウントを設定されている場合に、セッションが異なるアカウントに対応する正当なクッキー情報を受信することが原因で、異なるアカウントでのデータが正しく同期されない脆弱性。(CVE-2011-3257)&lt;br /&gt;&lt;br /&gt;9) Data Security&lt;br /&gt;　DigiNotar によって処理される複数の証明書によって不正な証明書問題が存在することが原因で、ユーザの認証情報または他の機密情報を妨害される脆弱性。&lt;br /&gt;&lt;br /&gt;10) Data Security&lt;br /&gt;　MD5 ハッシュアルゴリズムを用いてサインされた証明書が iOS によって受理された場合に、このアルゴリズムに脆弱であることが原因で、重要な情報を取得される脆弱性。(CVE-2011-3427)&lt;br /&gt;&lt;br /&gt;11) Data Security&lt;br /&gt;　SSL の SSLv3 及び TLS 1.0 だけがサポートされている場合に、これらが脆弱であることが原因で、SSL 接続を複合化される脆弱性。(CVE-2011-3389)&lt;br /&gt;&lt;br /&gt;12) Home screen&lt;br /&gt;　four-finger アプリでアプリケーションを切り替える時に、表示が前のアプリケーションの状態を表示することが原因で、アプリケーションの重要な情報を取得される脆弱性。(CVE-2011-3431)&lt;br /&gt;&lt;br /&gt;13) ImageIO&lt;br /&gt;　TIFF が CCITT Group 4 でエンコードされた TIFF 画像を取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0192)&lt;br /&gt;&lt;br /&gt;14) ImageIO&lt;br /&gt;　ImageIO がCCITT Group 4 でエンコードされた TIFF 画像を取り扱う際にヒープオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0241)&lt;br /&gt;&lt;br /&gt;15) International Components for Unicode&lt;br /&gt;　ICU生成処理においてほとんど大文字の長い文字列とキーを照合する際にバッファオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0206)&lt;br /&gt;&lt;br /&gt;16) Kernal&lt;br /&gt;　カーネルが失敗した TCP 接続からメモリを即座に再要求することに失敗することが原因で、端末がリセットする脆弱性。(CVE-2011-3259)&lt;br /&gt;&lt;br /&gt;17) Kernel&lt;br /&gt;　IPV6 ソケットオプションを取り扱う際に NULL ポインタ逆参照が発生することが原因で、システムがリセットする脆弱性。(CVE-2011-1132)&lt;br /&gt;&lt;br /&gt;18) Keyboards&lt;br /&gt;　パスワードの最後の文字を入力したキーボードが次に使用されたときに表示することが原因で、パスワードの最後の文字を特定される脆弱性。(CVE-2011-3245)&lt;br /&gt;&lt;br /&gt;19) libxml&lt;br /&gt;　libxml が XML データを取り扱う際に１バイトヒープオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0216)&lt;br /&gt;&lt;br /&gt;20) OfficeImport&lt;br /&gt;　OfficeImport がマイクロソフト Word ファイルを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-3260)&lt;br /&gt;&lt;br /&gt;21) OfficeImport&lt;br /&gt;　OfficeImport が Excel ファイルを取り扱い際に二重メモリ解放が発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-3261)&lt;br /&gt;&lt;br /&gt;22) OfficeImport&lt;br /&gt;　OfficeImport がマイクロソフト Office ファイルを取り扱う際にメモリ破壊が発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0208)&lt;br /&gt;&lt;br /&gt;23) OfficeImport&lt;br /&gt;　OfficeImport が Excel ファイルを取り扱う際にメモリ破壊が発生することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0184)&lt;br /&gt;&lt;br /&gt;24) Safari&lt;br /&gt;　iOS は HTTP Content-Disposition ヘッダーの 'attachment' 値をサポートしていないが、このヘッダー値で供給されたファイル内のスクリプトはサーバ上の他のリソースにフルアクセスできることで、サイトスクリプティング攻撃を許す脆弱性。(CVE-2011-3426)&lt;br /&gt;&lt;br /&gt;25) Settings&lt;br /&gt;　ベアレンタル制限機能はパスコートによって設定を保護されているが、そのパスコードがディスク上にプレインテキストで保持されていることが原因で、端末への物理的な攻撃によりパスコードを回収される脆弱性。(CVE-2011-3429)&lt;br /&gt;&lt;br /&gt;26) Settings&lt;br /&gt;　設定プロファイル経由で適用された設定が英語以外の言語下では適切に機能しないことが原因で、設定が結果として適切な表示をしない脆弱性。(CVE-2011-3430)&lt;br /&gt;&lt;br /&gt;27) UIKit Alerts&lt;br /&gt;　非常に長い tel: URI の受理ダイアログを描画する時に、最大テキスト長を超えていると iOS がハングする脆弱性。(CVE-2011-3432)&lt;br /&gt;&lt;br /&gt;28) WebKit&lt;br /&gt;　WebKit に複数のメモリ破壊の問題が存在することが原因で、アプリケーションが異常終了したり任意のコードを実行されたりする脆弱性。(CVE-2011-0218, CVE-2011-0221, CVE-2011-0222, CVE-2011-0225, CVE-2011-0232, CVE-2011-0233, CVE-2011-0234, CVE-2011-0235, CVE-2011-0238, CVE-2011-0254, CVE-2011-0255, CVE-2011-0981, CVE-2011-0983, CVE-2011-1109, CVE-2011-1114, CVE-2011-1115, CVE-2011-1117, CVE-2011-1121, CVE-2011-1188, CVE-2011-1203, CVE-2011-1204, CVE-2011-1288, CVE-2011-1293, CVE-2011-1296, CVE-2011-1449, CVE-2011-1451, CVE-2011-1453, CVE-2011-1457, CVE-2011-1462, CVE-2011-1797, CVE-2011-2338, CVE-2011-2339, CVE-2011-2341, CVE-2011-2351, CVE-2011-2352, CVE-2011-2354, CVE-2011-2356, CVE-2011-2359, CVE-2011-2788, CVE-2011-2790, CVE-2011-2792, CVE-2011-2797, CVE-2011-2799, CVE-2011-2809, CVE-2011-2813, CVE-2011-2814, CVE-2011-2816, CVE-2011-2817, CVE-2011-2818, CVE-2011-2820, CVE-2011-2823, CVE-2011-2827, CVE-2011-2831, CVE-2011-3232, CVE-2011-3234, CVE-2011-3235, CVE-2011-3236, CVE-2011-3237, CVE-2011-3244)&lt;br /&gt;&lt;br /&gt;29) WebKit&lt;br /&gt;　ユーザ名を埋め込まれた URL を取り扱う際にクロスオリジン問題が存在することが原因で、クロスサイトスクリプティング攻撃を受ける脆弱性。(CVE-2011-0242)&lt;br /&gt;&lt;br /&gt;30) WebKit&lt;br /&gt;　DOM ノードを取り扱う際にクロスオリジン問題が存在することが原因で、クロスサイトスクリプティング攻撃を受ける脆弱性。(CVE-2011-1295)&lt;br /&gt;&lt;br /&gt;31) WebKit&lt;br /&gt;　DOM 履歴オブジェクトを取り扱う際に URL スヌーフィング問題が存在することが原因で、アドレスバーに異なる URL を表示される脆弱性。(CVE-2011-1107)&lt;br /&gt;&lt;br /&gt;32) WebKit&lt;br /&gt;　WebKit が libxslt を使用する際に設定問題が存在することが原因で、任意のコードを実行される脆弱性。(CVE-2011-1774)&lt;br /&gt;&lt;br /&gt;33) WebKit&lt;br /&gt;　WebKit が HTML 5 のドラッグ＆ドロップを取り扱う際にクロスオリジン問題が存在することが原因で、重要な情報を取得される脆弱性。(CVE-2011-0166)&lt;br /&gt;&lt;br /&gt;34) WebKit&lt;br /&gt;　Web Workers を取り扱い際にクロスオリジン問題が存在することが原因で、重要な情報を取得される脆弱性。(CVE-2011-1190)&lt;br /&gt;&lt;br /&gt;35) WebKit&lt;br /&gt;　window.open メソッドを取り扱う際にクロスオリジン問題が存在することが原因で、クロスサイトスクリプティング攻撃を受ける脆弱性。(CVE-2011-2805)&lt;br /&gt;&lt;br /&gt;36) WebKit&lt;br /&gt;　機能していない DOM ウィンドウを取り扱う際にクロスオリジン問題が存在すること原因で、クロスサイトスクリプティング攻撃を受ける脆弱性。(CVE-2011-3243)&lt;br /&gt;&lt;br /&gt;37) WebKit&lt;br /&gt;　document.documentURI 属性を取り扱う際にクロスサイトオリジン問題が存在することが原因で、クロスサイトスクリプティング攻撃を受ける脆弱性。(CVE-2011-2819)&lt;br /&gt;&lt;br /&gt;38) WebKit&lt;br /&gt;　以前にロードしたイベントを取り扱う際にクロスオリジン問題が存在することが原因で、フレーム内でユーザが閲覧した URL を追跡される脆弱性。(CVE-2011-2800)&lt;br /&gt;&lt;br /&gt;39) WiFi&lt;br /&gt;　パスコードや暗号化されたキーを含む WiFi 認証情報がシステムのアプリケーションから読み込み可能なファイルに記録されることが原因で、認証情報を取得される脆弱性。(CVE-2011-3434)&lt;br /&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;/pre&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-8910676353195495108?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/8910676353195495108/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/ios-5.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/8910676353195495108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/8910676353195495108'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/ios-5.html' title='iOS 5 のセキュリティアップデート'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-7514998659954159210</id><published>2011-10-13T10:43:00.000+09:00</published><updated>2011-10-13T16:22:22.251+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='先勝'/><title type='text'>13日 木曜日、先勝</title><content type='html'>&lt;br /&gt;About the security content of Numbers for iOS v1.5&lt;br /&gt;http://support.apple.com/kb/HT5004&lt;br /&gt;&lt;br /&gt;About the security content of Pages for iOS v1.5&lt;br /&gt;http://support.apple.com/kb/HT5003&lt;br /&gt;&lt;br /&gt;About the security content of Safari 5.1.1&lt;br /&gt;http://support.apple.com/kb/HT5000&lt;br /&gt;&lt;br /&gt;About the security content of OS X Lion v10.7.2 and Security Update 2011-006&lt;br /&gt;http://support.apple.com/kb/HT5002&lt;br /&gt;&lt;br /&gt;About the security content of Apple TV Software Update 4.4&lt;br /&gt;http://support.apple.com/kb/HT5001&lt;br /&gt;&lt;br /&gt;About the security content of iOS 5 Software Update&lt;br /&gt;http://support.apple.com/kb/HT4999&lt;br /&gt;&lt;br /&gt;VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console&lt;br /&gt;http://www.vmware.com/security/advisories/VMSA-2011-0012.html&lt;br /&gt;&lt;br /&gt;ソニーPSNなどに9万件超の「なりすまし」、不正侵入は確認されず&lt;br /&gt;正規ユーザーのアカウントでログイン試行、カード情報の漏洩もなし&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111013/370625/?ST=security&lt;br /&gt;&lt;br /&gt;IEに危険な脆弱性、Webアクセスでウイルス感染の恐れ&lt;br /&gt;セキュリティ情報8件が公開、2件は深刻度が「緊急」&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111013/370624/?ST=security&lt;br /&gt;&lt;br /&gt;JVNVU#756679 BlueZ-hcidump におけるヒープオーバーフローの脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU756679/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#377475 VLC Media Player に脆弱性&lt;br /&gt;http://jvn.jp/cert/JVNVU377475/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#585859 Apple Safari における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU585859/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#971123 Apple Mac OS Xにおける複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU971123/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#727187 Apple TV における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU727187/index.html&lt;br /&gt;&lt;br /&gt;JVNVU#177979 Apple iOS における複数の脆弱性に対するアップデート&lt;br /&gt;http://jvn.jp/cert/JVNVU177979/index.html&lt;br /&gt;&lt;br /&gt;JVN#07414354 DAEMON Tools におけるサービス運用妨害 (DoS) の脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN07414354/index.html&lt;br /&gt;&lt;br /&gt;JVN#04013920 Pligg におけるクロスサイトスクリプティングの脆弱性&lt;br /&gt;http://jvn.jp/jp/JVN04013920/index.html&lt;br /&gt;&lt;br /&gt;Critical OS X Vulnerability Patched&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11797&lt;br /&gt;&lt;br /&gt;Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information&lt;br /&gt;http://www.securitytracker.com/id/1026180&lt;br /&gt;&lt;br /&gt;BlackBerry Enterprise Server Collaboration Service Bug Lets Remote Users Impersonate Intra-organization Messages&lt;br /&gt;http://www.securitytracker.com/id/1026179&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey 'Array.reduceRight()' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48372&lt;br /&gt;&lt;br /&gt;Microsoft Silverlight &amp;amp; .NET Framework Inheritance Restriction Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49999&lt;br /&gt;&lt;br /&gt;Microsoft Windows Active Accessibility DLL Loading Arbitrary Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49976&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/45015&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ PSN-2011-10-392: Cross-site scripting injection in J-Web administrator logs&lt;br /&gt;https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&amp;amp;txtAlertNumber=PSN-2011-10-392&amp;amp;viewMode=view&lt;br /&gt;&lt;br /&gt;+ PSN-2011-10-391: Junos kernel crash in Next-Gen MVPN scenario&lt;br /&gt;https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&amp;amp;txtAlertNumber=PSN-2011-10-391&amp;amp;viewMode=view&lt;br /&gt;&lt;br /&gt;+? Apache APR 'apr_fnmatch()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47820&lt;br /&gt;&lt;br /&gt;++ ActivePerl 5.14.2.1402 released&lt;br /&gt;http://www.activestate.com/activeperl/downloads&lt;br /&gt;&lt;br /&gt;- PHP 'grapheme_extract()' NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46429&lt;br /&gt;&lt;br /&gt;[ANN] Apache log4net 1.2.11 Released&lt;br /&gt;http://logging.apache.org/log4net/release/release-notes.html&lt;br /&gt;&lt;br /&gt;2269637: セキュリティで保護されていないライブラリのロードにより、リモートでコードが実行される&lt;br /&gt;http://technet.microsoft.com/ja-jp/security/advisory/2269637&lt;br /&gt;&lt;br /&gt;Cisco Security Response: Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability&lt;br /&gt;http://www.cisco.com/en/US/products/products_security_response09186a0080b98d0b.html&lt;br /&gt;&lt;br /&gt;Sybase IQが、IMJのSaaS型インハウスSEOツール「MTL KEYWORDS」のデータベースとして採用&lt;br /&gt;http://www.sybase.jp/detail?id=1095188&amp;amp;contentOnly=true&lt;br /&gt;&lt;br /&gt;New Insider Threat Demonstration Series Launched&lt;br /&gt;http://www.cert.org/insider_threat/demonstrations/ITDS01.mp4&lt;br /&gt;&lt;br /&gt;Insider Threat Control Technical Note Released&lt;br /&gt;http://www.cert.org/archive/pdf/11tn024.pdf&lt;br /&gt;&lt;br /&gt;FFRが標的型攻撃マルウエアの有無を検査するサービスを開始&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111012/370599/?ST=security&lt;br /&gt;&lt;br /&gt;エフセキュアがセキュリティソフトの新バージョンを発表&lt;br /&gt;http://itpro.nikkeibp.co.jp/article/NEWS/20111012/370555/?ST=security&lt;br /&gt;&lt;br /&gt;Critical Control 8 - Controlled Use of Administrative Privileges&lt;br /&gt;http://isc.sans.edu/diary.html?storyid=11794&lt;br /&gt;&lt;br /&gt;Apple Safari Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Execute Arbitrary Code, and Bypass Cookie Restrictions&lt;br /&gt;http://www.securitytracker.com/id/1026178&lt;br /&gt;&lt;br /&gt;SilverStripe URL Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46390/&lt;br /&gt;&lt;br /&gt;ManageEngine ADSelfService Plus Security Bypass Vulnerability&lt;br /&gt;http://secunia.com/advisories/46381/&lt;br /&gt;&lt;br /&gt;SUSE update for libqt4&lt;br /&gt;http://secunia.com/advisories/46371/&lt;br /&gt;&lt;br /&gt;Contao URL "getPageIdFromURL()" Cross-Site Scripting Vulnerability&lt;br /&gt;http://secunia.com/advisories/46396/&lt;br /&gt;&lt;br /&gt;Hitachi JP1/Cm2/Network Node Manager Unspecified Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46411/&lt;br /&gt;&lt;br /&gt;WordPress Light Post Plugin "abspath" File Inclusion Vulnerability&lt;br /&gt;http://secunia.com/advisories/46422/&lt;br /&gt;&lt;br /&gt;SUSE update for Qt&lt;br /&gt;http://secunia.com/advisories/46410/&lt;br /&gt;&lt;br /&gt;Google App Engine SDK for Python Cross-Site Request Forgery Vulnerability&lt;br /&gt;http://secunia.com/advisories/46357/&lt;br /&gt;&lt;br /&gt;SUSE update for tomcat5&lt;br /&gt;http://secunia.com/advisories/46407/&lt;br /&gt;&lt;br /&gt;MyBB MyStatus Plugin "statid" SQL Injection Vulnerability&lt;br /&gt;http://secunia.com/advisories/46360/&lt;br /&gt;&lt;br /&gt;BlackBerry Enterprise Server Instant Messaging User Impersonation Vulnerability&lt;br /&gt;http://secunia.com/advisories/46370/&lt;br /&gt;&lt;br /&gt;Apple iTunes Multiple Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46339/&lt;br /&gt;&lt;br /&gt;POSH Cross-Site Scripting and File Inclusion Vulnerabilities&lt;br /&gt;http://secunia.com/advisories/46354/&lt;br /&gt;&lt;br /&gt;Red Hat update for kdelibs&lt;br /&gt;http://secunia.com/advisories/46383/&lt;br /&gt;&lt;br /&gt;DMXready Polling Booth Manager SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8452&lt;br /&gt;&lt;br /&gt;iJoomla Magazine 3.0.1 Remote File Inclusion&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8451&lt;br /&gt;&lt;br /&gt;A-Blog v2.0 (sources/search.php) SQL Injection Exploit&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8450&lt;br /&gt;&lt;br /&gt;ColdGen - coldbookmarks v1.22 Remote 0day SQL Injection vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8449&lt;br /&gt;&lt;br /&gt;ColdUserGroup 1.06 Blind SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8448&lt;br /&gt;&lt;br /&gt;PHP Classifieds ADS Blind SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8447&lt;br /&gt;&lt;br /&gt;UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8446&lt;br /&gt;&lt;br /&gt;ColdGen - coldcalender v2.06 Remote 0day SQL Injection&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8445&lt;br /&gt;&lt;br /&gt;Mechbunny PaysiteReviewCMS Permanent XSS Vulnerabilities&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8444&lt;br /&gt;&lt;br /&gt;Virtue Shopping Mall (detail.php prodid) SQL Injection Vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8443&lt;br /&gt;&lt;br /&gt;Zenphoto 1.3 Security problems&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8442&lt;br /&gt;&lt;br /&gt;CubeCart 4.3.3 SQL Injection and XSS&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8441&lt;br /&gt;&lt;br /&gt;Joomla Component Clantools version 1.2.3 Multiple Blind SQL Injection Vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8440&lt;br /&gt;&lt;br /&gt;MySource Matrix 3.28.3 (height) Remote Reflected XSS Vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8439&lt;br /&gt;&lt;br /&gt;CMS WebManager-Pro Vulnerabilities&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8438&lt;br /&gt;&lt;br /&gt;chillyCMS Multiple Vulnerabilities&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8437&lt;br /&gt;&lt;br /&gt;HINNENDAHL.COM Gaestebuch 1.2 Remote File Inclusion Vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8436&lt;br /&gt;&lt;br /&gt;MODx Revolution 2.0.2-pl Reflected Cross-site Scripting&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8435&lt;br /&gt;&lt;br /&gt;Auto CMS XSS vulnerability&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8434&lt;br /&gt;&lt;br /&gt;ApPHP Calendar XSS CSRF&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;br /&gt;http://securityreason.com/securityalert/8433&lt;br /&gt;&lt;br /&gt;REMOTE: Mozilla Firefox Array.reduceRight() Integer Overflow Exploit&lt;br /&gt;http://www.exploit-db.com/exploits/17974/&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-1985) Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49968&lt;br /&gt;&lt;br /&gt;AzeoTech DAQFactory Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48955&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel 'Win32k.sys' TrueType Font File Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49973&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel '.fon' Font File Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49975&lt;br /&gt;&lt;br /&gt;Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-2011) Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49981&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Virtual Function Table CVE-2011-2001 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49966&lt;br /&gt;&lt;br /&gt;Microsoft Windows AFD Driver CVE-2011-2005 Local Privilege Escalation Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49941&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Body Element CVE-2011-2000 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49965&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Select Element CVE-2011-1999 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49964&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Option Element CVE-2011-1996 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49961&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer 'Jscript9.dll' CVE-2011-1998 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49963&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer 'OLEAuto32.dll' CVE-2011-1995 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49960&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer Uninitalized Object CVE-2011-1993 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49947&lt;br /&gt;&lt;br /&gt;Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/39635&lt;br /&gt;&lt;br /&gt;Microsoft Internet Explorer OnLoad Event CVE-2011-1997 Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49962&lt;br /&gt;&lt;br /&gt;Apple QuickTime CVE-2011-0252 STTS Atoms Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49038&lt;br /&gt;&lt;br /&gt;PHP 'OpenSSL' Extension Multiple Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46977&lt;br /&gt;&lt;br /&gt;Multiple Vendors STARTTLS Implementation Plaintext Arbitrary Command Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46767&lt;br /&gt;&lt;br /&gt;PHP 'Intl' Extension 'NumberFormatter::setSymbol()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46968&lt;br /&gt;&lt;br /&gt;WebKit 'libxslt' Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48840&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 13.0.782.215 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49279&lt;br /&gt;&lt;br /&gt;Webkit Address Bar URI Spoofing Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47020&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 13.0.782.107 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48960&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 14.0.835.163 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49658&lt;br /&gt;&lt;br /&gt;WebKit 'HTML5' Drag and Drop Cross-Origin Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46811&lt;br /&gt;&lt;br /&gt;PHP 'Zip' Extension 'zip_fread()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46975&lt;br /&gt;&lt;br /&gt;WebKit Embedded URL Cross Domain Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48859&lt;br /&gt;&lt;br /&gt;Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/41544&lt;br /&gt;&lt;br /&gt;Apache Tomcat SecurityManager Security Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46177&lt;br /&gt;&lt;br /&gt;Apache Tomcat HTML Manager Interface HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46174&lt;br /&gt;&lt;br /&gt;FreeType 'src/psaux/t1decode.c' Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48619&lt;br /&gt;&lt;br /&gt;Apache Tomcat NIO Connector Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46164&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-1797 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48858&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 12.0.742.112 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48479&lt;br /&gt;&lt;br /&gt;ISC BIND 9 'RRSIG' Record Type Negative Cache Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45133&lt;br /&gt;&lt;br /&gt;Apache APR 'apr_fnmatch()' Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47820&lt;br /&gt;&lt;br /&gt;Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49303&lt;br /&gt;&lt;br /&gt;Python 'audioop' Module Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40370&lt;br /&gt;&lt;br /&gt;ISC BIND 9 Unspecified Packet Processing Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48566&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-1457 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48856&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-1462 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48857&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-1453 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48855&lt;br /&gt;&lt;br /&gt;PHP 'Zip' Extension 'stream_get_contents()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46969&lt;br /&gt;&lt;br /&gt;PHP Stream Component Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46970&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 11.0.696.57 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47604&lt;br /&gt;&lt;br /&gt;WebKit MathML Tags Use-After-Free Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48824&lt;br /&gt;&lt;br /&gt;Google Chrome Prior to 10.0.648.204 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47029&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-1288 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48854&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0222 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48844&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0225 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48845&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0232 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48846&lt;br /&gt;&lt;br /&gt;WebKit FrameOwner Element Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48847&lt;br /&gt;&lt;br /&gt;WebKit Malformed XHTML Tags Use After Free Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48823&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0235 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48848&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0238 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48850&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0255 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48853&lt;br /&gt;&lt;br /&gt;WebKit 'NamedNodeMap.cpp' Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48852&lt;br /&gt;&lt;br /&gt;Google Chrome prior to 9.0.597.94 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46262&lt;br /&gt;&lt;br /&gt;WebKit Multiple Unspecifeid Remote Code Execution Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50066&lt;br /&gt;&lt;br /&gt;Google Chrome prior to 10.0.648.127 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46785&lt;br /&gt;&lt;br /&gt;Google Chrome prior to 9.0.597.107 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46614&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0221 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48843&lt;br /&gt;&lt;br /&gt;WebKit CVE-2011-0218 Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48842&lt;br /&gt;&lt;br /&gt;Apple Mac OS X Quicklook Office File Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48440&lt;br /&gt;&lt;br /&gt;Apple Mac OS X QuickLook Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46965&lt;br /&gt;&lt;br /&gt;Apple Mac OS X IPV6 Socket Options (CVE-2010-1132) Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48422&lt;br /&gt;&lt;br /&gt;Apple Mac OS X QuickTime Cross Domain Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46992&lt;br /&gt;&lt;br /&gt;Apple Mac OS X ICU (CVE-2011-0206) Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48429&lt;br /&gt;&lt;br /&gt;Mozilla Firefox/Thunderbird/SeaMonkey CVE-2011-3232 YARR Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49850&lt;br /&gt;&lt;br /&gt;libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46658&lt;br /&gt;&lt;br /&gt;Apple Safari ImageIO TIFF Image Handling Heap Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48833&lt;br /&gt;&lt;br /&gt;SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49778&lt;br /&gt;&lt;br /&gt;PHP 'shmop_read()' Remote Integer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46786&lt;br /&gt;&lt;br /&gt;PHP Exif Extension 'exif_read_data()' Function Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46365&lt;br /&gt;&lt;br /&gt;PHP 'phar/phar_object.c' Format String Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46854&lt;br /&gt;&lt;br /&gt;OTRS Unspecified Remote Command Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46947&lt;br /&gt;&lt;br /&gt;libzip '_zip_name_locate()' NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46354&lt;br /&gt;&lt;br /&gt;PHP 'grapheme_extract()' NULL Pointer Dereference Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46429&lt;br /&gt;&lt;br /&gt;PHP 'zend_strtod()' Function Floating-Point Value Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45668&lt;br /&gt;&lt;br /&gt;PHP 'open_basedir' Security-Bypass Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44723&lt;br /&gt;&lt;br /&gt;GNU Mailman 'Full name' Field Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/46464&lt;br /&gt;&lt;br /&gt;ISC BIND Key Algorithm Rollover Security Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/45137&lt;br /&gt;&lt;br /&gt;ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37118&lt;br /&gt;&lt;br /&gt;ISC BIND 9 DNSSEC Bogus NXDOMAIN Response Remote Cache Poisoning Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/37865&lt;br /&gt;&lt;br /&gt;Apple Mac OS X CoreFoundation (CVE-2011-0259) Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50067&lt;br /&gt;&lt;br /&gt;Python 'urllib' and 'urllib2' Modules Information Disclosure and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/47024&lt;br /&gt;&lt;br /&gt;Apple Mac OS X CoreMedia H.264 Encoded Movie Files Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50068&lt;br /&gt;&lt;br /&gt;Python 'audioop' Module Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/40863&lt;br /&gt;&lt;br /&gt;libpng Buffer Overflow and Denial of Service Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/48660&lt;br /&gt;&lt;br /&gt;jabberd XML Parsing Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48250&lt;br /&gt;&lt;br /&gt;ISC BIND 9 Large RRSIG RRsets Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48007&lt;br /&gt;&lt;br /&gt;libpng PNG File Denial Of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48618&lt;br /&gt;&lt;br /&gt;Apple Mobile OfficeImport Framework Excel Record Memory Corruption Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44799&lt;br /&gt;&lt;br /&gt;Apple Mac OS X QuickLook Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/44812&lt;br /&gt;&lt;br /&gt;Apple Mobile Safari for iOS 4.2.1 Unspecified Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/46832&lt;br /&gt;&lt;br /&gt;Linux Kernel TCP Sequence Number Generation Security Weakness&lt;br /&gt;http://www.securityfocus.com/bid/49289&lt;br /&gt;&lt;br /&gt;Linux Kernel Generic Receive Offload (GRO) CVE-2011-2723 Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48929&lt;br /&gt;&lt;br /&gt;Samba 'etc/mtab' File Appending Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49939&lt;br /&gt;&lt;br /&gt;Adobe Flash Media Server NULL Pointer Dereference Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49103&lt;br /&gt;&lt;br /&gt;Samba 'client/mount.cifs.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/38326&lt;br /&gt;&lt;br /&gt;OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50047&lt;br /&gt;&lt;br /&gt;Linux Kernel 'drivers/media/radio/si4713-i2c.c' Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48804&lt;br /&gt;&lt;br /&gt;Linux Kernel 'fs/befs/linuxvfs.c' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49256&lt;br /&gt;&lt;br /&gt;Linux Kernel 'inet_diag_bc_audit()' Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48333&lt;br /&gt;&lt;br /&gt;Linux kernel l2cap Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48472&lt;br /&gt;&lt;br /&gt;Linux Kernel 'CIFSFindNext()' Function Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/49295&lt;br /&gt;&lt;br /&gt;Linux Kernel EFI Partition Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/47796&lt;br /&gt;&lt;br /&gt;Linux Kernel EXT4 Extent Format File Local Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/48697&lt;br /&gt;&lt;br /&gt;Google App Engine SDK Cross Site Request Forgery Vulnerability And Command Execution Weaknesses&lt;br /&gt;http://www.securityfocus.com/bid/50075&lt;br /&gt;&lt;br /&gt;TUGZip ZIP File Remote Buffer Overflow Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/31913&lt;br /&gt;&lt;br /&gt;Joomla! JCE Component Multiple Directory Traversal Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/49338&lt;br /&gt;&lt;br /&gt;Microsoft Publisher '.pub' File 'pubconv.dll' Memory Corruption Remote Code Execution Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50090&lt;br /&gt;&lt;br /&gt;Apple Safari Prior to 5.1.1 Multiple Security Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50089&lt;br /&gt;&lt;br /&gt;WebKit Inactive DOM Windows Cross Domain Scripting Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50088&lt;br /&gt;&lt;br /&gt;Apple Kernel TCP Exhaustion Denial of Service Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50087&lt;br /&gt;&lt;br /&gt;Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50086&lt;br /&gt;&lt;br /&gt;Cisco TelePresence Video Communication Server 'User-Agent' HTTP Header HTML Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50084&lt;br /&gt;&lt;br /&gt;BugFree Multiple Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50083&lt;br /&gt;&lt;br /&gt;WordPress GD Star Rating Plugin 'de' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50082&lt;br /&gt;&lt;br /&gt;Filmis SQL Injection and Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50081&lt;br /&gt;&lt;br /&gt;WordPress Light Post Plugin 'abspath' Parameter Remote File Include Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50080&lt;br /&gt;&lt;br /&gt;Hitachi JP1/Cm2/Network Node Manager Multiple Unspecified Remote Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50079&lt;br /&gt;&lt;br /&gt;Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50078&lt;br /&gt;&lt;br /&gt;POSH Local File Include and Cross Site Scripting Vulnerabilities&lt;br /&gt;http://www.securityfocus.com/bid/50077&lt;br /&gt;&lt;br /&gt;MyBB MyStatus 'statid' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50073&lt;br /&gt;&lt;br /&gt;Joomla! Sgicatalog Component 'id' Parameter SQL Injection Vulnerability&lt;br /&gt;http://www.securityfocus.com/bid/50072&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/271993289796750713-7514998659954159210?l=isneophyte.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isneophyte.blogspot.com/feeds/7514998659954159210/comments/default' title='コメントの投稿'/><link rel='replies' type='text/html' href='http://isneophyte.blogspot.com/2011/10/13.html#comment-form' title='0 件のコメント'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/7514998659954159210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/271993289796750713/posts/default/7514998659954159210'/><link rel='alternate' type='text/html' href='http://isneophyte.blogspot.com/2011/10/13.html' title='13日 木曜日、先勝'/><author><name>Bouno Tokyo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-271993289796750713.post-6989090582299115556</id><published>2011-10-12T11:56:00.001+09:00</published><updated>2011-10-12T11:56:29.795+09:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iTunes'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><title type='text'>iTunes 10.5 のセキュリティアップデート</title><content type='html'>&lt;br /&gt;About the security content of iTunes 10.5&lt;br /&gt;http://support.apple.com/kb/HT4981&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;上記 URL の iTunes のセキュリティアップデートの翻訳&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;pre wrap=""&gt;1) CoreFoundation&lt;br /&gt;　文字列のトークン化の取り扱いの際にメモリ破壊が発生することが原因で、中間者攻撃を許しアプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-0259)&lt;br /&gt;&lt;br /&gt;2) ColorSync&lt;br /&gt;　埋め込み ColorSync プロファイルを持つ画像を取り扱い際に整数オーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-0200)&lt;br /&gt;&lt;br /&gt;3) CoreAudio&lt;br /&gt;　拡張音声コードでエンコードされた音声ストリームを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-3252)&lt;br /&gt;&lt;br /&gt;4) CoreMedia&lt;br /&gt;　H.264 エンコードされた動画ファイルを取り扱う際にバッファオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-3219)&lt;br /&gt;&lt;br /&gt;5) ImageIO&lt;br /&gt;　ImageIO が TIFF 画像を取り扱う際にヒープオーバーフローが発生することが原因で、アプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-0204)&lt;br /&gt;&lt;br /&gt;6) ImageIO&lt;br /&gt;　ImageIO が TIFF 画像を取り扱う際に再入可能問題が存在することが原因で、アプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2011-0215)&lt;br /&gt;&lt;br /&gt;7) WebKit&lt;br /&gt;　WebKit に存在する複数のメモリ破壊が原因で、中間者攻撃を許しアプリケーションが異常終了したり任意のコードを実行される脆弱性。(CVE-2010-1823, CVE-2011-0164, CVE-2011-0218, CVE-2011-0221, CVE-2011-0222, CVE-2011-0223, CVE-2011-0225, CVE-2011-0232, CVE-2011-0233, CVE-2011-0234, CVE-2011-0235, CVE-2011-0237, CVE-2011-0238, CVE-2011-0240, CVE-2011-0253, CVE-2011-0254, CVE-2011-0255, CVE-2011-0981, CVE-2011-0983, CVE-2011-1109, CVE-2011-1114, CVE-2011-1115, CVE-2011-1117, CVE-2011-1121, CVE-2011-1188, CVE-2011-1203, CVE-2011-1204, CVE-2011-1288, CVE-2011-1293, CVE-2011-1296, CVE-2011-1440, CVE-2011-1449, CVE-2011-1451, CVE-2011-1453, CVE-2011-1457, CVE-2011-1462, CVE-2011-1797, CVE-2011-2338, CVE-2011-2339, CVE-2011-2341, CVE-2011-2351, CVE-2011-2352, CVE-2011-2354, CVE-2011-2356, CVE-2011-2359, CVE-2011-2788, CVE-2011-2790, CVE-2011-2792, CVE-2011-2797, CVE-2011-2799, CVE-2011-2809, CVE-2011-2811, CVE-2011-2813, CVE-2011-2814, CVE-2011-2815, CVE-2011-2816, CVE-2011-2817, CVE-2011-2818, CVE-2011-2820, CVE-2011-2823, CVE-2011-2827, CVE-2011-2831, CVE-2011-3232, CVE-2011-3233, CVE-2011-3234, CVE-2011-3235, CVE-2011-3236, CVE-2011-32
