StationX : IT Security for Home or Business StationX : IT Security for Home or Business StationX : IT Security for Home or Business
Security Home IT Security Services IT Security Research Free Security Software Secure Hosting StationX Contacts IT security Support Hotline
Latest Security News
 

Vulnerabilities News:



This page is created dynamically and was last updated : 03 July, 2009 GMT

 
 
Detailed Security News Detailed Vulnerabilities & Alerts Detailed Virus Alerts and News
Vulnerabilities and Alerts:

SecurityFocus Vulnerabilities:
IT Security Dot 

3 Jul

:

Vuln: phpMyAdmin SQL bookmark HTML Injection Vulnerability


phpMyAdmin SQL bookmark HTML Injection Vulnerability


IT Security Dot 

3 Jul

:

Vuln: Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability


Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability


IT Security Dot 

3 Jul

:

Vuln: Drupal Cross-Site Scripting, Code Injection and Information Disclosure ...


Drupal Cross-Site Scripting, Code Injection and Information Disclosure Vulnerabilities


IT Security Dot 

3 Jul

:

Vuln: LibTIFF 'tif_lzw.c' Remote Buffer Underflow Vulnerability


LibTIFF 'tif_lzw.c' Remote Buffer Underflow Vulnerability


IT Security Dot 

Bugtraq: Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explor...


Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome


IT Security Dot 

Bugtraq: [SECURITY] [DSA 1825-1] New nagios2/nagios3 packages fix arbitrary c...


[SECURITY] [DSA 1825-1] New nagios2/nagios3 packages fix arbitrary code execution


IT Security Dot 

Bugtraq: [oCERT-2009-007] FCKeditor input sanitization errors


[oCERT-2009-007] FCKeditor input sanitization errors


IT Security Dot 

Bugtraq: One Click Ownage [White Paper and Scripts]


One Click Ownage [White Paper and Scripts]


IT Security Dot 

More rss feeds from SecurityFocus


News, Infocus, Columns, Vulnerabilities, Bugtraq ...


Microsoft Vulnerabilities:
IT Security Dot 

9 Jun

:

MS09-027 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Rem...


Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


IT Security Dot 

9 Jun

:

MS09-026 - Important: Vulnerability in RPC Could Allow Elevation of Privilege...


Bulletin Severity Rating:Important - This security update resolves a publicly disclosed vulnerability in the Windows remote procedure call (RPC) facility where the RPC Marshalling Engine does not update its internal state appropriately. The vulnerability could allow an attacker to execute arbitrary code and take complete control of an affected system. Supported editions of Microsoft Windows are not delivered with any RPC servers or clients that are subject to exploitation of this vulnerability. In a default configuration, users could not be attacked by exploitation of this vulnerability. However, the vulnerability is present in the Microsoft Windows RPC runtime and could affect third-party RPC applications.


IT Security Dot 

9 Jun

:

MS09-025 - Important: Vulnerabilities in Windows Kernel Could Allow Elevation...


Bulletin Severity Rating:Important - This security update resolves two publicly disclosed and two privately reported vulnerabilities in the Windows kernel that could allow elevation of privilege. An attacker who successfully exploited any of these vulnerabilities could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.


IT Security Dot 

9 Jun

:

MS09-024 - Critical: Vulnerability in Microsoft Works Converters Could Allow ...


Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in the Microsoft Works converters. The vulnerability could allow remote code execution if a user opens a specially crafted Works file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Jun

:

MS09-023 - Moderate: Vulnerability in Windows Search Could Allow Information ...


Bulletin Severity Rating:Moderate - This security update resolves a privately reported vulnerability in Windows Search. The vulnerability could allow information disclosure if a user performs a search that returns a specially crafted file as the first result or if the user previews a specially crafted file from the search results. By default, the Windows Search component is not installed on Microsoft Windows XP and Windows Server 2003. It is an optional component available for download. Windows Search installed on supported editions of Windows Vista and Windows Server 2008 is not affected by this vulnerability.


IT Security Dot 

9 Jun

:

MS09-022 - Critical: Vulnerabilities in Windows Print Spooler Could Allow Rem...


Bulletin Severity Rating:Critical - This security update resolves three privately reported vulnerabilities in Windows Print Spooler. The most severe vulnerability could allow remote code execution if an affected server received a specially crafted RPC request. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.


IT Security Dot 

9 Jun

:

MS09-021 - Critical: Vulnerabilities in Microsoft Office Excel Could Allow Re...


Bulletin Severity Rating:Critical - This security update resolves several privately reported vulnerabilities that could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed record object. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


IT Security Dot 

9 Jun

:

MS09-020 - Important: Vulnerabilities in Internet Information Services (IIS) ...


Bulletin Severity Rating:Important - This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Internet Information Services (IIS). The vulnerabilities could allow elevation of privilege if an attacker sent a specially crafted HTTP request to a Web site that requires authentication. These vulnerabilities allow an attacker to bypass the IIS configuration that specifies which type of authentication is allowed, but not the file system-based access control list (ACL) check that verifies whether a file is accessible by a given user. Successful exploitation of these vulnerabilities would still restrict the attacker to the permissions granted to the anonymous user account by the file system ACLs.


IT Security Dot 

9 Jun

:

MS09-019 - Critical: Cumulative Security Update for Internet Explorer (969897)


Bulletin Severity Rating:Critical - This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe of the vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

9 Jun

:

MS09-018 - Critical: Vulnerabilities in Active Directory Could Allow Remote C...


Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in implementations of Active Directory on Microsoft Windows 2000 Server and Windows Server 2003, and Active Directory Application Mode (ADAM) when installed on Windows XP Professional and Windows Server 2003. The more severe vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.


IT Security Dot 

12 May

:

MS09-017 - Critical: Vulnerabilities in Microsoft Office PowerPoint Could All...


Bulletin Severity Rating:Critical - This security update resolves a publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

14 Apr

:

MS09-016 - Important: Vulnerabilities in Microsoft ISA Server and Forefront T...


Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE). These vulnerabilities could allow denial of service if an attacker sends specially crafted network packets to the affected system, or information disclosure or spoofing if a user clicks on a malicious URL or visits a Web site that contains content controlled by the attacker.


IT Security Dot 

14 Apr

:

MS09-015 – Moderate: Blended Threat Vulnerability in SearchPath Could Allow...


Bulletin Severity Rating:Moderate - This security update resolves a publicly disclosed vulnerability in the Windows SearchPath function that could allow elevation of privilege if a user downloaded a specially crafted file to a specific location, then opened an application that could load the file under certain circumstances.


IT Security Dot 

14 Apr

:

MS09-014 - Critical: Cumulative Security Update for Internet Explorer (963027)


Bulletin Severity Rating:Critical - This security update resolves four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user connects to an attacker's server by way of the HTTP protocol. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


IT Security Dot 

14 Apr

:

MS09-013 - Critical: Vulnerabilities in Windows HTTP Services Could Allow Rem...


Bulletin Severity Rating:Critical - This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft Windows HTTP Services (WinHTTP). The most severe vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


Redhat Vulnerabilities:
IT Security Dot 

RHBA-2009:1142-1: yum bug fix update


Red Hat Enterprise Linux: An updated yum package that resolves an issue with RHN Snapshot Rollback is now available.


IT Security Dot 

RHBA-2009:1137-1: bind bug fix update


Red Hat Enterprise Linux: Updated bind packages that resolve an issue are now available for Red Hat Enterprise Linux 5.


IT Security Dot 

RHSA-2009:1138-1: Important: openswan security update


Red Hat Enterprise Linux: Updated openswan packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. CVE-2009-2185


IT Security Dot 

RHSA-2009:1139-1: Moderate: pidgin security and bug fix update


Red Hat Enterprise Linux: Updated pidgin packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. CVE-2009-1889


IT Security Dot 

RHSA-2009:1140-2: Moderate: ruby security update


Red Hat Enterprise Linux: Updated ruby packages that fix multiple security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. CVE-2007-1558, CVE-2009-0642, CVE-2009-1904


IT Security Dot 

RHSA-2009:1141-1: Important: nagios security update


Red Hat Enterprise Linux: Updated nagios packages that fix one security issue are now available for the Red Hat HPC Solution. This update has been rated as having important security impact by the Red Hat Security Response Team. CVE-2009-2288


IT Security Dot 

RHBA-2009:1133-2: kernel bug fix update


Red Hat Enterprise Linux: Updated kernel packages that fix several bugs are now available for Red Hat Enterprise Linux 5.


IT Security Dot 

RHBA-2009:1135-1: kernel bug fix update


Red Hat Enterprise Linux: Updated kernel packages that fix a bug are now available for Red Hat Enterprise Linux 5.


IT Security Dot 

RHSA-2009:1132-1: Important: kernel security and bug fix update


Red Hat Enterprise Linux: Updated kernel packages that fix several security issues and various bugs are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team. CVE-2009-1072, CVE-2009-1192, CVE-2009-1385, CVE-2009-1630, CVE-2009-1758


Secunia Vulnerabilities:

[CaRP] XML error: syntax error at line 1
CERT Vulnerabilities:
IT Security Dot 

TA09-160A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-161A: Adobe Acrobat and Reader Vulnerabilities


Adobe Acrobat and Reader Vulnerabilities


IT Security Dot 

TA09-133B: Adobe Reader and Acrobat JavaScript Vulnerabilities


Adobe Reader and Acrobat JavaScript Vulnerabilities


IT Security Dot 

TA09-133A: Apple Updates for Multiple Vulnerabilities


Apple Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-132A: Microsoft PowerPoint Multiple Vulnerabilities


Microsoft PowerPoint Multiple Vulnerabilities


IT Security Dot 

TA09-105A: Oracle Updates for Multiple Vulnerabilities


Oracle Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-104A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-088A: Conficker Worm Targets Microsoft Windows Systems


Conficker Worm Targets Microsoft Windows Systems


IT Security Dot 

TA09-069A: Microsoft Updates for Multiple Vulnerabilities


Microsoft Updates for Multiple Vulnerabilities


IT Security Dot 

TA09-051A: Adobe Acrobat and Reader Vulnerability


Adobe Acrobat and Reader Vulnerability


IGX Vulnerabilities:

[CaRP] Connection timed out (110)

[CaRP] XML error: mismatched tag at line 10


This page is created dynamically and was last updated : 03 July, 2009 GMT


 
Home | Services | Research | Sales | Hosting | Contacts | Hot line | Site map | Adult | Links | Penetration Testing
Copyright © 2009. Station X Ltd. All rights reserved. Legal Notices Privacy Policy
seduction sex tips