Current Security Information
The following is a list of links to current security threats, vulnerabilities and advisories from Secunia, SANS and Microsoft.
The The Consensus Security Alert from SANS lists vulnerabilities detected in a variety of software including Open Source applications, device firmware and proprietary code. These are vulnerabilities that may or may not have been fixed, please see each announcement for more information. To establish whether a vulnerability has been fixed see the application vendor's website.
The Microsoft security bulletins are announcements that updates addressing reported or unreported vulnerabilities have been issued. Each bulletin may cover one or more updates and discusses the vulnerability fixed. It is not a comprehensive announcement of vulnerabilities, and vulnerabilities may exist that are not listed and have not been disclosed.
The Virus alerts from Secunia list current viral threats of varying severity.
- The Consensus Security Alert from SANS
- Current Microsoft Security Bulletins
- Current Virus Alerts from Secunia
The Consensus Security Alert from SANS
- SANS 2009
- (1) HIGH: IBM Lotus iNotes ActiveX Control Buffer Overflow Vulnerability
- (2) HIGH: IBM Informix Multiple Buffer Overflow Vulnerabilities
- (3) HIGH: Multiple Vendor "librpc.dll" Signedness Error Code Execution Vulnerability
- (4) MODERATE: Microsoft Internet Explorer VBScript Windows Help Code Execution Vulnerability
- (5) MODERATE: Modo 401 LXO Processing Integer Overflow Vulnerability
- 10.10.13 IBM AIX LDAP Login Local Denial of Service
- 10.10.14 WebKit Image Decoder Memory Allocation Remote Code Execution
- 10.10.15 EMC HomeBase Server Directory Traversal Remote Code Execution
- 10.10.16 MochaSoft FTPDisc "get" Request Remote Denial of Service
- 10.10.17 cronie "crontab" Symbolic Link Local Privilege Escalation
- 10.10.18 Zhang Boyang FTP Server Remote Denial of Service
- 10.10.19 Kojoney "urllib.urlopen()" Remote Denial of Service
- 10.10.20 TIBCO Administrator
- 10.10.21 Weekly Archive by Node Type Module Weekly Summary Security Bypass
- 10.10.22 Apple Safari Style Tag Remote Memory Corruption
- 10.10.23 Symantec Altiris Deployment Solution "dbmanager.exe" Denial of Service
- 10.10.24 VKPlayer ".mid" File Processing Buffer Overflow
- 10.10.25 Asterisk CIDR Notation in Access Rule Remote Security Bypass
- 10.10.26 XMail Insecure Temporary File Creation
- 10.10.27 Hitachi JP1/Cm2/Network Node Manager Insecure File Permissions
- 10.10.28 PHP LCG entropy Unspecified Security
- 10.10.29 PHP "tempnam()" "safe_mode" Validation Restriction Bypass
- 10.10.30 Todd Miller Sudo "runas_default" Local Privilege Escalation
- 10.10.31 FileExecutive Multiple Remote Vulnerabilities
- 10.10.32 Apple Safari "background" attribute Remote Denial of Service
- 10.10.33 IBM Domino Web Access Prior to 229.281 Unspecified Security Vulnerabilities
- 10.10.34 IBM Informix Dynamic Server "librpc.dll" Multiple Buffer Overflow Vulnerabilities
- 10.10.35 Reductive Labs Puppet "/tmp" Insecure File Permissions Vulnerabilities
- 10.10.36 MochaSoft FTPDisc Multiple Remote Denial of Service Vulnerabilities
- 10.10.37 Libpng "png_decompress_chunk()" Function Denial of Service
- 10.10.9 Linux Kernel TSB I-TLB Load Local Privilege Escalation
- 10.10.10 Linux Kernel "devtmpfs" Insecure Root Directory Permission
- 10.10.11 Linux Kernel KVM Segment Selector Loading Local Privilege Escalation
- 10.10.12 Linux Kernel "dvb_net_ule()" Remote Denial of Service
- 10.10.96 TrendNet TV-IP110W Missing Authentication Check Security Bypass
- 10.10.2 Microsoft Internet Explorer "winhlp32.exe" "MsgBox()" Stack-Based Buffer Overflow
- 10.10.3 Google Picasa JPEG Image Processing Integer Overflow
- 10.10.4 MediaCoder ".m3u" File Remote Buffer Overflow
- 10.10.5 DateV "DVBSExeCall.ocx" ActiveX Control Remote Command Execution
- 10.10.6 Domino Web Access ActiveX Control Unspecified Buffer Overflow
- 10.10.7 Multiple Vendor "librpc.dll" Stack Buffer Overflow
- 10.10.8 ProSSHD "scp_get()" Buffer Overflow
- 10.10.75 WikyBlog Multiple Remote Input Validation Vulnerabilities
- 10.10.76 SilverStripe Multiple Remote Vulnerabilities
- 10.10.77 PHP F1 Max's Photo Album "admin.php" Arbitrary File Upload
- 10.10.78 OpenInferno OI.Blogs Multiple Local File Include Vulnerabilities
- 10.10.79 Facebook-style Statuses Module User Status Security Bypass
- 10.10.80 PBoard "upload/index.php" Remote File Upload
- 10.10.81 Article Friendly Security Bypass
- 10.10.82 Newbie CMS Insecure Cookie Authentication Bypass
- 10.10.83 Arab Cart "showimg.php" Cross-Site Scripting and SQL Injection Vulnerabilities
- 10.10.84 Ceondo InDefero Unauthorized Access
- 10.10.85 Website Baker "framework/class.wb.php" Security Bypass
- 10.10.86 TYPO3 OpenID Module Backend User Account Security Bypass
- 10.10.87 Crawlability vBSEO "vbseo.php" Local File Include
- 10.10.88 Orbital Viewer ".orb" File Stack-Based Buffer Overflow
- 10.10.89 Nemo Multiple File Attachments Mail Form "upload.php" Arbitrary File Upload
- 10.10.90 Open Educational System "CONF_INCLUDE_PATH" Parameter Multiple Remote File Include Vulnerabilities
- 10.10.91 SLAED CMS Remote File Upload
- 10.10.92 SLAED CMS Multiple Remote File Include Vulnerabilities
- 10.10.93 SLAED CMS Installation Script Unauthorized Access
- 10.10.94 Article Friendly "filename" Parameter Local File Include
- 10.10.95 DeDeCMS
- 10.10.38 TRUC "login_reset_password_page.php" Cross-Site Scripting
- 10.10.39 WebKit "window.open()" method Cross-Domain Scripting
- 10.10.40 Computer Associates eHealth Performance Manager Web Interface Cross-Site Scripting
- 10.10.41 Softbiz Jobs "sbad_type" Parameter Cross-Site Scripting
- 10.10.42 MySmartBB Multiple Cross-Site Scripting Vulnerabilities
- 10.10.43 Sawmill Unspecified Cross-Site Scripting
- 10.10.44 Multiple IBM Products Login Page Cross-Site Scripting
- 10.10.45 tDiary TrackBack Transmission Plugin Cross-Site Scripting
- 10.10.46 Hitachi Multiple Products Unspecified Cross-Site Scripting
- 10.10.47 ARISg "wflogin.jsp" Cross-Site Scripting
- 10.10.48 Oracle Siebel "loyalty_enu/start.swe" Cross-Site Scripting
- 10.10.49 ExtCalendar "upgrade.php" Cross-Site Scripting
- 10.10.50 MarketGate Package for Eshbel Priority ERP "Referer" Parameter Cross-Site Scripting
- 10.10.51 Discuz! "uid" Parameter Cross-Site Scripting
- 10.10.52 Sparta Systems TrackWise EQMS Multiple Cross-Site Scripting Vulnerabilities
- 10.10.53 Pre Multi-Vendor E-Commerce Solution "detail.php" SQL Injection
- 10.10.54 MASA2EL Music City "index.php" Multiple SQL Injection Vulnerabilities
- 10.10.55 Softbiz Jobs "moredetails.php" SQL Injection
- 10.10.56 Bispage Content Manager Admin Page SQL Injection
- 10.10.57 Softbiz Auktios Multiple SQL Injection Vulnerabilities
- 10.10.58 HD FLV Player Component for Joomla! "id" Parameter SQL Injection
- 10.10.59 shortCMS "printview.php" SQL Injection
- 10.10.60 Softbiz Classifieds PLUS Script Multiple SQL Injection Vulnerabilities
- 10.10.61 GameScript "index.php" SQL Injection
- 10.10.62 JSK Internet WebAdministrator "download.php" SQL Injection
- 10.10.63 Softbiz Recipes Portal and Link Directory Script "showcats.php" SQL Injection
- 10.10.64 Entry Level CMS "index.php" SQL Injection
- 10.10.65 Pre Classified Listings "signup.asp" SQL Injection
- 10.10.66 SLAED CMS SQL Injection
- 10.10.67 Joomla! "com_yanc" Component "listid" Parameter SQL Injection
- 10.10.68 Uiga Fan Club and Personal Portal "id" Parameter SQL Injection
- 10.10.69 Blax Blog "girisyap.php" SQL Injection
- 10.10.70 Uiga Fan Club Login Multiple SQL Injection Vulnerabilities
- 10.10.71 Scriptsfeed Business Directory Software
- 10.10.72 1024 CMS "id" Parameter SQL Injection
- 10.10.73 My Little Forum "contact.php" SQL Injection
- 10.10.74 Phptroubleticket "vedi_faq.php" SQL Injection
- 10.10.1 Microsoft Windows Unspecified Denial of Service
Current Security Bulletins from Microsoft
- MS10-017 - Important: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
- MS10-016 - Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)
- MS10-015 - Important: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)
- MS10-014 - Important: Vulnerability in Kerberos Could Allow Denial of Service (977290)
- MS10-013 - Critical: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)
- MS10-012 - Important: Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)
- MS10-011 - Important: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)
- MS10-010 - Important: Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (977894)
- MS10-009 - Critical: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145)
- MS10-008 - Critical: Cumulative Security Update of ActiveX Kill Bits (978262)
- MS10-007 - Critical: Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)
- MS10-006 - Critical: Vulnerabilities in SMB Client Could Allow Remote Code Execution (978251)
- MS10-005 - Moderate: Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)
- MS10-004 - Important: Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)
- MS10-003 - Important: Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)
- MS10-002 - Critical: Cumulative Security Update for Internet Explorer (978207)
- MS10-001 - Critical: Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)
- MS09-074 - Critical: Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)
- MS09-073 - Important: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
- MS09-072 - Critical: Cumulative Security Update for Internet Explorer (976325)
- MS09-071 - Critical: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
- MS09-070 - Important: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)
- MS09-069 - Important: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)
- MS09-068 - Important: Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)
- MS09-067 - Important: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
Current Virus Alerts from Secunia
- Error: It's not possible to reach RSS file...




© “The