ラベル セキュリティの強度不足 の投稿を表示しています。 すべての投稿を表示
ラベル セキュリティの強度不足 の投稿を表示しています。 すべての投稿を表示

2011-01-25

2010-11-23

Apple Safari

ソフト名:Apple Safari 4.0~5.0.2
回避策:アップデートにて対応
脆弱性:リモートコード実行, セキュリティの強度不足, スプーフィング攻撃, 整数オーバーフロー, 整数アンダーフロー, アプリケーションのクラッシュ, アフターフリーエラー, メモリアクセスエラー, メモリ破壊エラー, メモリ破壊
ソース:
http://support.apple.com/kb/HT4455
http://www.securityfocus.com/bid/44950
http://www.securityfocus.com/bid/44952
http://www.securityfocus.com/bid/44953
http://www.securityfocus.com/bid/44954
http://www.securityfocus.com/bid/44955
http://www.securityfocus.com/bid/44956
http://www.securityfocus.com/bid/44957
http://www.securityfocus.com/bid/44958
http://www.securityfocus.com/bid/44959
http://www.securityfocus.com/bid/44960
http://www.securityfocus.com/bid/44961
http://www.securityfocus.com/bid/44962
http://www.securityfocus.com/bid/44963
http://www.securityfocus.com/bid/44964
http://www.securityfocus.com/bid/44965
http://www.securityfocus.com/bid/44967
http://www.securityfocus.com/bid/44969
http://www.securityfocus.com/bid/44970
http://www.securityfocus.com/bid/44971
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3803
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3804
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3805
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3808
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3809
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3810
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3811
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3812
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3813
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3816
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3817
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3818
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3819
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3820
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3821
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3822
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3823
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3824
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3826
http://secunia.com/advisories/42264
http://www.vupen.com/english/advisories/2010/3025
CVE:CVE-2010-3803, CVE-2010-3804, CVE-2010-3805, CVE-2010-3808, CVE-2010-3809, CVE-2010-3810, CVE-2010-3811, CVE-2010-3812, CVE-2010-3813, CVE-2010-3816, CVE-2010-3817, CVE-2010-3818, CVE-2010-3819, CVE-2010-3820, CVE-2010-3821, CVE-2010-3822, CVE-2010-3823, CVE-2010-3824, CVE-2010-3826
危険性:High Risk

2010-11-19

Cisco製品

ソフト名:Cisco Unified Videoconferencing 3515 Multipoint Control Unit (MCU), Cisco Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, Cisco Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Cisco Unified Videoconferencing 3545 System/5110 System/5115 System/5230 System
回避策:cisco-sr-20101117-cuvcにて対応
脆弱性:不可変のユーザー名とパスワードの包含, リモートコマンド実行, セキュリティの強度不足, 機密情報の奪取, 不正アクセス, ユーザーセッションの乗っ取り, クッキーのストア, FTPサーバーの使用可能性, リモートアクセス, DoS攻撃
ソース:
http://www.cisco.com/warp/public/707/cisco-sr-20101117-cuvc.shtml
http://www.trustmatta.com/advisories/MATTA-2010-001.txt
http://www.securityfocus.com/bid/44922
http://www.securityfocus.com/bid/44923
http://www.securityfocus.com/bid/44924
http://www.securityfocus.com/bid/44925
http://www.securityfocus.com/bid/44926
http://www.securityfocus.com/bid/44927
http://www.securityfocus.com/bid/44928
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3037
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3038
http://secunia.com/advisories/42248
CVE:CVE-2010-3037, CVE-2010-3038
危険性:High Risk

2010-11-12

AusweisApp

ソフト名:AusweisApp 1.0
回避策:未対応
脆弱性:セキュリティの強度不足, リモートコード実行, マンインミドル攻撃
ソース:
https://www.ausweisapp.bund.de/pweb/index.do
http://janschejbal.wordpress.com/2010/11/09/ausweisapp-gehackt-malware-uber-autoupdate/
http://secunia.com/advisories/42163
危険性:High Risk

IBM Omnifind

ソフト名:IBM Omnifind 8.x Enterprise/9.1 Enterprise
回避策:未対応
脆弱性:セッションの乗っ取り, セキュリティの強度不足, 不正アクセス, 機密情報の奪取, DoS攻撃, 権限の昇格, 無限ループ
ソース:
http://archives.neohapsis.com/archives/bugtraq/2010-11/0090.html
http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt
http://www-01.ibm.com/software/data/enterprise-search/omnifind-enterprise/
http://www.exploit-db.com/exploits/15476/
http://www.securityfocus.com/bid/44740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3892
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3893
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3896
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3897
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3898
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3899
http://www.vupen.com/english/advisories/2010/2933
CVE:CVE-2010-3892, CVE-2010-3893, CVE-2010-3896, CVE-2010-3897, CVE-2010-3898, CVE-2010-3899
危険性:Medium Risk

2010-10-22

G.Rodola PyFTPdlib

ソフト名:G.Rodola PyFTPdlib 0.1~0.4.0
回避策:アップデートにて対応
脆弱性:セキュリティの強度不足, ブルートフォース攻撃
ソース:
http://code.google.com/p/pyftpdlib/issues/detail?id=71
http://code.google.com/p/pyftpdlib/issues/detail?id=73
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7263
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7264
CVE:CVE-2008-7263, CVE-2008-7264
危険性:Medium Risk

G.Rodola PyFTPdlib

ソフト名:G.Rodola PyFTPdlib 0.1/0.1.1
回避策:アップデートにて対応
脆弱性:セキュリティの強度不足, DoS攻撃, ディレクトリトラバーサル, ブルートフォース攻撃, FTPバウンス攻撃
ソース:
http://code.google.com/p/pyftpdlib/issues/detail?id=3
http://code.google.com/p/pyftpdlib/issues/detail?id=9
http://code.google.com/p/pyftpdlib/issues/detail?id=11
http://code.google.com/p/pyftpdlib/issues/detail?id=20
http://code.google.com/p/pyftpdlib/issues/detail?id=25
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6736
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6739
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6741
CVE:CVE-2007-6736, CVE-2007-6737, CVE-2007-6739, CVE-2007-6740, CVE-2007-6741
危険性:Medium Risk

Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird

ソフト名:Mozilla Firefox 3.5 Linux~3.6.9, Mozilla Seamonkey 2.0 Alpha 1~2.0.8, Mozilla Thunderbird 3.0~3.1.4
回避策:MFSA 2010-72にて対応
脆弱性:セキュリティの強度不足
ソース:
http://www.mozilla.org/security/announce/2010/mfsa2010-72.html
http://www.securityfocus.com/bid/44228
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3173
http://secunia.com/advisories/41244
http://secunia.com/advisories/41890
http://secunia.com/advisories/41923
http://www.vupen.com/english/advisories/2010/2726
CVE:CVE-2010-3173
危険性:Low Risk

2010-10-20

NETGEAR CG3100D

ソフト名:NETGEAR CG3100D 5.5.2
回避策:未対応
脆弱性:権限の昇格, セキュリティ制限の回避, セキュリティの強度不足, メニューのロード, 不正アクセス, ルータのリセット
ソース:
http://seclists.org/fulldisclosure/2010/Oct/197
http://www.netgear.com/
http://www.securityfocus.com/bid/44102
危険性:High Risk

2010-10-01

Drupal Memcache

ソフト名:Drupal Memcache 5.x-1.0~6.x-1.x-dev
回避策:SA-CONTRIB-2010-098にて対応
脆弱性:XSS, セキュリティの強度不足, 認証資格情報の奪取
ソース:
http://drupal.org/node/927016
http://www.securityfocus.com/bid/43606
http://secunia.com/advisories/41663
危険性:Medium Risk

2010-09-03

Rainbow Portal Rainbow CMS

ソフト名:Rainbow Portal Rainbow CMS 2.0/2.0.0.1881e
回避策:未対応
脆弱性:XSS, SQLインジェクション, セキュリティの強度不足, 認証資格情報の奪取
ソース:
http://www.exploit-db.com/exploits/14870/
http://www.rainbowportal.net/
http://www.securityfocus.com/bid/42934
危険性:Medium Risk

2010-08-31

2010-08-27

Joomla!

ソフト名:Joomla! 1.5
回避策:未対応
脆弱性:セキュリティの強度不足
ソース:
http://www.joomla.org/
http://www.exploit-db.com/exploits/14722/
危険性:Low Risk

2010-08-24

Google Chrome

ソフト名:Google Chrome 5.0.375.125~5.0.375.99
回避策:アップデートにて対応
脆弱性:リモートコード実行, 不特定のエラー, スプーフィング攻撃, DoS攻撃, セキュリティの強度不足, メモリ破壊, システムのクラッシュ
ソース:
http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
http://www.securityfocus.com/bid/42571
http://secunia.com/advisories/41014
http://www.vupen.com/english/advisories/2010/2127
危険性:High Risk

2010-08-18

Adobe Acrobat, Adobe Reader

ソフト名:Adobe Acrobat 6.0~9.3.3(Professional), Adobe Reader 6.0~9.3.3
回避策:未対応
脆弱性:セキュリティの強度不足
ソース:
http://pdfsig-collision.florz.de/
http://www.securityfocus.com/bid/42377
危険性:Low Risk

2Wire 2700HGV-2 Gateway

ソフト名:2Wire 2700HGV-2 Gateway 5.29.117.3
回避策:未対応
脆弱性:セキュリティの強度不足, ブルートフォース攻撃, 不正アクセス
ソース:
http://www.2wire.com/
http://yehg.net/lab/pr0js/advisories/2wire/%5B2wire%5D_session_hijacking_vulnerability
http://secunia.com/advisories/40922
危険性:Low Risk