FAQ

US-CERT

Emite conţinut
US-CERT publishes information on a wide variety of vulnerabilities. Descriptions of these vulnerabilities are available from this web page in a searchable database format, and are published as "US-CERT Vulnerability Notes". The notes are very similar to alerts, but they may have less complete information. In particular, solutions may not be available for all the vulnerabilities in this database.
Updated: în urmă cu 28 minute 57 sec

VU#204055: Blackboard Transact database credentials disclosure

Mie, 01/09/2010 - 23:22
The Blackboard Transact application contains two vulnerabilities that allow an unauthorized user to access the database credentials.
Categories: US-CERT

VU#707943: Microsoft Windows based applications may insecurely load dynamic libraries

Mie, 25/08/2010 - 16:40
Some applications for Microsoft Windows may use unsafe methods for determining how to load DLLs. As a result,these applications can be forced to load a DLL from an attacker-controlled source rather than a trusted location.
Categories: US-CERT

VU#278785: DevonIT weak authentication and buffer overflow in /usr/bin/tm-console-bin

Mar, 24/08/2010 - 21:54
The DevonIT management tool for thin clients uses a shared secret that is transmitted over the network in the clear. The/usr/bin/tm-console-bin application contains a buffer overflow,which may allow an attacker to execute arbitrary code.
Categories: US-CERT

VU#644319: Ghostscript Heap Corruption in TrueType bytecode interpreter

Mar, 24/08/2010 - 16:51
The TrueType bytecode interpreter which is a part of Ghostscript is prone to heap corruption.
Categories: US-CERT

VU#320233: Wyse ThinOS LPD service buffer overflow vulnerability

Lun, 16/08/2010 - 21:38
Wyse ThinOS HF 4.4.079i has a buffer overflow vulnerability in the LPD service(515/tcp).
Categories: US-CERT

VU#660993: Adobe Flash 10.1 ActionScript AVM1 ActionPush vulnerability

Mar, 10/08/2010 - 18:39
Adobe Flash contains a vulnerability in the handling of the ActionScript,AVM1 ActionPush command,which can allow a remote,unauthenticated attacker to execute arbitrary code.
Categories: US-CERT

VU#275247: FreeType 2 CFF font stack corruption vulnerability

Joi, 05/08/2010 - 16:48
FreeType 2 contains a vulnerability in the processing of CFF fonts,which may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT

VU#174089: Oracle Siebel Option Pack for IE ActiveX control memory initialization vulnerability

Joi, 05/08/2010 - 16:01
The Oracle Siebel Option Pack for IE ActiveX control fails to properly initialize memory,which may allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system.
Categories: US-CERT

VU#703189: Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control stack buffer overflow

Mie, 04/08/2010 - 20:04
The Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control contains a stack buffer overflow that could allow a remote attacker to execute arbitrary code on an affected system
Categories: US-CERT

VU#840249: Wind River Systems VxWorks weak default hashing algorithm in standard authentication API (loginLib)

Lun, 02/08/2010 - 18:36
The hashing algorithm that is used in the standard authentication API for VxWorks is susceptible to collisions. An attacker can brute force a password by guessing a string that produces the same hash as a legitimate password.
Categories: US-CERT

VU#362332: Wind River Systems VxWorks debug service enabled by default

Lun, 02/08/2010 - 18:36
Some products based on VxWorks have the WDB target agent debug service enabled by default. This service provides read/write access to the device's memory and allows functions to be called.
Categories: US-CERT

VU#940193: Microsoft Windows automatically executes code specified in shortcut files

Joi, 15/07/2010 - 21:21
Microsoft Windows automatically executes code specified in shortcut(LNK and PIF)files.
Categories: US-CERT

VU#541921: ISC DHCP server fails to handle zero-length client identifier

Mie, 14/07/2010 - 21:06
A vulnerability in ISC DHCP could allow a remote attacker to cause the DHCP server to exit,resulting in a denial of service.
Categories: US-CERT

VU#732671: Cisco Industrial Ethernet 3000 Series switches have hardcoded SNMP community strings

Lun, 12/07/2010 - 22:34
Cisco Industrial Ethernet 3000(IE 3000)Series switches running Cisco IOS Software releases 12.2(52)SE or 12.2(52)SE1,contain well-known,hard-coded read and write SNMP community strings. An remote attacker could take full control of a vulnerable device.
Categories: US-CERT

VU#643615: libpng fails to limit number of rows in header

Vin, 02/07/2010 - 22:34
Libpng contains a vulnerability in the way it handles images containing an extra row of image data beyond the height reported in the image header.
Categories: US-CERT

VU#173009: Snare Agent web interface cross-site request forgery vulnerabilities

Mar, 29/06/2010 - 22:24
The Snare Agent web interface is susceptible to cross-site request forgery attacks.
Categories: US-CERT

VU#251133: S2 NetBox allows unauthenticated HTTP access to node logs, backups, and employee photographs

Joi, 24/06/2010 - 22:33
S2 NetBox and related products do not adequately restrict access to node logs,backups,and employee photographs. A remote,unauthenticated attacker could use information obtained from a vulnerable system to aid in further attacks.
Categories: US-CERT

VU#221257: Symantec AppStream and Workspace Streaming vulnerable to arbitrary code download and execution

Joi, 17/06/2010 - 16:09
The Symantec AppStream and Workspace Streaming clients fail to properly validate downloads,which can allow a remote,unauthenticated attacker to download and execute arbitrary code on a vulnerable system.
Categories: US-CERT

VU#578319: Microsoft Windows Help and Support Center URI processing vulnerability

Joi, 10/06/2010 - 23:46
The Microsoft Windows Help and Support Center application fails to properly sanitize hcp://URIs,which can allow a remote,unauthenticated attacker to execute arbitrary commands.
Categories: US-CERT

VU#486225: Adobe Flash ActionScript AVM2 newfunction vulnerability

Lun, 07/06/2010 - 23:46
Adobe Flash contains a vulnerability in the handling of the ActionScript newfunction instruction,which can allow a remote,unauthenticated attacker to execute arbitrary code.
Categories: US-CERT

Calendar

M T W T F S S
 
 
1
 
2
 
3
 
4
 
5
 
6
 
7
 
8
 
9
 
10
 
11
 
12
 
13
 
14
 
15
 
16
 
17
 
18
 
19
 
20
 
21
 
22
 
23
 
24
 
25
 
26
 
27
 
28
 
29
 
30
 
 
 
 
Add to calendar