ソフト名:Documents Seller component for Joomla! 2.5.1
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11289
2010-02-02
AutartiTarot component for Joomla!
AutartiTarot component for Joomla! 1.0.3
未対応
RFI
http://packetstormsecurity.org/1001-exploits/joomlaautartitarot-traversal.txt
未対応
RFI
http://packetstormsecurity.org/1001-exploits/joomlaautartitarot-traversal.txt
JE Event Calendars component for Joomla!
ソフト名:JE Event Calendars component for Joomla! 1.b0
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11292
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11292
JE Quiz component for Joomla!
ソフト名:JE Quiz component for Joomla! 1.b01
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11287
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11287
2010-01-30
HP System Management Homepage
HP System Management Homepage 2.1.15-210、3.0.0-64、3.0.0-68、3.0.2-77
回避策あり
XSS
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0586.html
回避策あり
XSS
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0586.html
Sun Java System Application Server
ソフト名:Sun Java System Application Server 7.0
回避策:あり
脆弱性:XSS, DoS攻撃
ソース:
回避策:あり
脆弱性:XSS, DoS攻撃
ソース:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200942-1
CVE:CVE-2010-0389, CVE-2010-0386
危険性:Medium Risk
Ingres Database
Ingres Database 9.3
未対応
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://intevydis.blogspot.com/2010/01/ingres-93-heap-overflow.html
未対応
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://intevydis.blogspot.com/2010/01/ingres-93-heap-overflow.html
Ingres Database
Ingres Database 9.3
未対応
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://intevydis.blogspot.com/2010/01/ingres-93-heap-overflow.html
未対応
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://intevydis.blogspot.com/2010/01/ingres-93-heap-overflow.html
SUSE Linux Enterprise
SUSE Linux Enterprise 10 SP3
回避策あり。
セキュリティ制限の回避
CVE-2010-0230
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
回避策あり。
セキュリティ制限の回避
CVE-2010-0230
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
Kunena component for Joomla!
ソフト名:Kunena component for Joomla! 1.5.9
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11279
回避策:未対応
脆弱性:SQLインジェクション
ソース:http://www.exploit-db.com/exploits/11279
Linux Kernel
Linux Kernel 2.6.32.3以前
バージョンアップで対応
DoS攻撃
CVE-2010-0003
http://www.openwall.com/lists/oss-security/2010/01/12/1
バージョンアップで対応
DoS攻撃
CVE-2010-0003
http://www.openwall.com/lists/oss-security/2010/01/12/1
Geo++ GNCASTER
Geo++ GNCASTER 1.4.0.7
バージョンアップで対応
機密情報の奪取
リモートコード実行
サーバのクラッシュ
http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication
バージョンアップで対応
機密情報の奪取
リモートコード実行
サーバのクラッシュ
http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication
日立製品
日立製品
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS09-019/index.html
バッファオーバーフロー
リモートコード実行
アプリケーションのクラッシュ
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS09-019/index.html
登録:
投稿 (Atom)