StationX : IT Security for Home or Business StationX : IT Security for Home or Business StationX : IT Security for Home or Business
Security Home IT Security Services IT Security Research Free Security Software Secure Hosting StationX Contacts IT security Support Hotline
Latest Security News
 

Vulnerabilities News:



This page is created dynamically and was last updated : 18 March, 2010 GMT

 
 
Detailed Security News Detailed Vulnerabilities & Alerts Detailed Virus Alerts and News
Vulnerabilities and Alerts:

SecurityFocus Vulnerabilities:
IT Security Dot 

18 Mar

:

Vuln: Bible Study Joomla! Component 'controller' Parameter Local File Include...


Bible Study Joomla! Component 'controller' Parameter Local File Include Vulnerability


IT Security Dot 

18 Mar

:

Vuln: Energizer DUO USB Battery Charger Unauthorized Access Vulnerability


Energizer DUO USB Battery Charger Unauthorized Access Vulnerability


IT Security Dot 

18 Mar

:

Vuln: Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability


Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability


IT Security Dot 

18 Mar

:

Vuln: Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability


Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability


IT Security Dot 

Bugtraq: Sahana 0.6.2.2 Authentication Bypass


Sahana 0.6.2.2 Authentication Bypass


IT Security Dot 

Bugtraq: Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vuln...


Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability


IT Security Dot 

Bugtraq: Secunia Research: Quicksilver Forums Backup Information Disclosure


Secunia Research: Quicksilver Forums Backup Information Disclosure


IT Security Dot 

Bugtraq: Secunia Research: Quicksilver Forums "mysqldump" Password Disclosure


Secunia Research: Quicksilver Forums "mysqldump" Password Disclosure


IT Security Dot 

More rss feeds from SecurityFocus


News, Infocus, Columns, Vulnerabilities, Bugtraq ...


Microsoft Vulnerabilities:
IT Security Dot 

9 Mar

:

MS10-017 - Important: Vulnerabilities in Microsoft Office Excel Could Allow R...


Bulletin Severity Rating:Important - This security update resolves seven privately reported vulnerabilities in Microsoft Office Excel. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Mar

:

MS10-016 - Important: Vulnerability in Windows Movie Maker Could Allow Remote...


Bulletin Severity Rating:Important - This security update addresses a privately reported vulnerability in Windows Movie Maker and Microsoft Producer 2003. Windows Live Movie Maker, which is available for Windows Vista and Windows 7, is not affected by this vulnerability. The vulnerability could allow remote code execution if an attacker sent a specially crafted Movie Maker or Microsoft Producer project file and persuaded the user to open the specially crafted file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Feb

:

MS10-015 - Important: Vulnerabilities in Windows Kernel Could Allow Elevation...


Bulletin Severity Rating:Important - This security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on to the system and then ran a specially crafted application. To exploit either vulnerability, an attacker must have valid logon credentials and be able to log on locally. The vulnerabilities could not be exploited remotely or by anonymous users.


IT Security Dot 

9 Feb

:

MS10-014 - Important: Vulnerability in Kerberos Could Allow Denial of Service...


Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a specially crafted ticket renewal request is sent to the Windows Kerberos domain from an authenticated user on a trusted non-Windows Kerberos realm. The denial of service could persist until the domain controller is restarted.


IT Security Dot 

9 Feb

:

MS10-013 - Critical: Vulnerability in Microsoft DirectShow Could Allow Remote...


Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in Microsoft DirectShow. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Feb

:

MS10-012 - Important: Vulnerabilities in SMB Server Could Allow Remote Code E...


Bulletin Severity Rating:Important - This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.


IT Security Dot 

9 Feb

:

MS10-011 - Important: Vulnerability in Windows Client/Server Run-time Subsyst...


Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Microsoft Windows Client/Server Run-time Subsystem (CSRSS). The vulnerability could allow elevation of privilege if an attacker logs on to the system and starts a specially crafted application designed to continue running after the attacker logs out. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.


IT Security Dot 

9 Feb

:

MS10-010 - Important: Vulnerability in Windows Server 2008 Hyper-V Could Allo...


Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.


IT Security Dot 

9 Feb

:

MS10-009 - Critical: Vulnerabilities in Windows TCP/IP Could Allow Remote Cod...


Bulletin Severity Rating:Critical - This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.


IT Security Dot 

9 Feb

:

MS10-008 - Critical: Cumulative Security Update of ActiveX Kill Bits (978262)


Bulletin Severity Rating:Critical - This security update addresses a privately reported vulnerability for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000 and Windows XP, Important for all supported editions of Windows Vista and Windows 7, Moderate for all supported editions of Windows Server 2003, and Low for all supported editions of Windows Server 2008 and Windows Server 2008 R2.


IT Security Dot 

9 Feb

:

MS10-007 - Critical: Vulnerability in Windows Shell Handler Could Allow Remot...


Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not impacted by this security update. The vulnerability could allow remote code execution if an application, such as a Web browser, passes specially crafted data to the ShellExecute API function through the Windows Shell Handler.


IT Security Dot 

9 Feb

:

MS10-006 - Critical: Vulnerabilities in SMB Client Could Allow Remote Code Ex...


Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a malicious SMB server.


IT Security Dot 

9 Feb

:

MS10-005 - Moderate: Vulnerability in Microsoft Paint Could Allow Remote Code...


Bulletin Severity Rating:Moderate - This security update resolves a privately reported vulnerability in Microsoft Paint. The vulnerability could allow remote code execution if a user viewed a specially crafted JPEG image file using Microsoft Paint. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Feb

:

MS10-004 - Important: Vulnerabilities in Microsoft Office PowerPoint Could Al...


Bulletin Severity Rating:Important - This security update resolves six privately reported vulnerabilities in Microsoft Office PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Feb

:

MS10-003 - Important: Vulnerability in Microsoft Office (MSO) Could Allow Rem...


Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


Redhat Vulnerabilities:
IT Security Dot 

RHEA-2010:0156-1: new packages: kmod-lpfc-rhel5u4-8.2.0.63-1.1


Red Hat Enterprise Linux: New kmod-lpfc-rhel5u4-8.2.0.63-1.0 packages are now available for Red Hat Enterprise Linux 5.4. These packages are a temporary driver update which enables the following hardware: Emulex LightPulse Fibre Channel Host Bus Adapters.


IT Security Dot 

RHEA-2010:0157-1: Virtio drivers for kernel 2.4.21-63.EL


Red Hat Enterprise Linux: This new package provides signed, para-virtualized block and network drivers for Red Hat Enterprise Linux 3 as a KVM virtualized guest.


IT Security Dot 

RHBA-2010:0134-1: device-mapper bug fix update


Red Hat Enterprise Linux: An updated device-mapper package that fixes a bug is now available.


IT Security Dot 

RHBA-2010:0150-1: lvm2 bug-fix update


Red Hat Enterprise Linux: Updated lvm2 packages that fix a bug are now available.


IT Security Dot 

RHBA-2010:0151-1: cyrus-sasl bug fix update


Red Hat Enterprise Linux: Updated cyrus-sasl packages that resolve an issue are now available.


IT Security Dot 

RHBA-2010:0152-1: freeradius bug fix update


Red Hat Enterprise Linux: An updated freeradius package that fixes a bug is now available.


IT Security Dot 

RHSA-2010:0153-2: Moderate: thunderbird security update


Red Hat Enterprise Linux: An updated thunderbird package that fixes several security issues is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2009-0689, CVE-2009-1571, CVE-2009-2462, CVE-2009-2463, CVE-2009-2466, CVE-2009-2470, CVE-2009-3072, CVE-2009-3075, CVE-2009-3076, CVE-2009-3077, CVE-2009-3274, CVE-2009-3376, CVE-2009-3380, CVE-2009-3979, CVE-2010-0159


IT Security Dot 

RHSA-2010:0154-2: Moderate: thunderbird security update


Red Hat Enterprise Linux: An updated thunderbird package that fixes several security issues is now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2009-0689, CVE-2009-1571, CVE-2009-2462, CVE-2009-2463, CVE-2009-2466, CVE-2009-2470, CVE-2009-3072, CVE-2009-3075, CVE-2009-3076, CVE-2009-3077, CVE-2009-3274, CVE-2009-3376, CVE-2009-3380, CVE-2009-3979, CVE-2010-0159


IT Security Dot 

RHSA-2010:0155-1: Moderate: java-1.4.2-ibm security and bug fix update


Red Hat Enterprise Linux: Updated java-1.4.2-ibm packages that fix one security issue and a bug are now available for Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. CVE-2009-3555


Secunia Vulnerabilities:

[CaRP] XML error: mismatched tag at line 45
CERT Vulnerabilities:
IT Security Dot 

TA10-068A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA10-055A: Malicious Activity Associated with "Aurora" Interne...


Malicious Activity Associated with "Aurora" Internet Explorer Exploit


IT Security Dot 

TA10-040A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA10-021A: Microsoft Internet Explorer Vulnerabilities


Microsoft Internet Explorer Vulnerabilities


IT Security Dot 

TA10-013A: Adobe Reader and Acrobat Vulnerabilities


Adobe Reader and Acrobat Vulnerabilities


IT Security Dot 

TA10-012B: Microsoft Windows EOT Font and Adobe Flash Player 6 Vulnerabilities


Microsoft Windows EOT Font and Adobe Flash Player 6 Vulnerabilities


IT Security Dot 

TA10-012A: Oracle Updates for Multiple Vulnerabilities


Oracle Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-343A: Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR


Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR


IT Security Dot 

TA09-342A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-314A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IGX Vulnerabilities:

[CaRP] Success (0)

[CaRP] XML error: mismatched tag at line 10


This page is created dynamically and was last updated : 18 March, 2010 GMT


 
Home | Services | Research | Sales | Hosting | Contacts | Hot line | Site map | Adult | Links | Penetration Testing
Copyright © 2010. Station X Ltd. All rights reserved. Legal Notices Privacy Policy
seduction sex tips