ISC DHCP Server Host Definition Remote Denial Of Service Vulnerability
Read more »Vuln: ISC DHCP Server Host Definition Remote Denial Of Service Vulnerability
Vuln: Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Read more »Oracle issues quarterly patches, fixes database flaws
The database giant repaired critical flaws in Oracle Database, BEA WebLogic and Oracle E-Business Suite.
Read more »Vuln: Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerability
Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerability
Read more »Vuln: Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnerability
Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnerability
Read more »Bugtraq: [USN-803-1] dhcp vulnerability
[USN-803-1] dhcp vulnerability
Read more »Mozilla warns of critical Firefox JavaScript vulnerability
Attackers could exploit the flaw by tricking a user into viewing a website with the malicious code.
Read more »Microsoft Patches Nine Security Flaws
Microsoft Corp. today issued software updates to plug at least nine different security holes in its various Windows operating systems and other software. Today's patch batch includes fixes for two very serious flaws that are actively being exploited by attackers to break into vulnerable PCs. Redmond issued patches to fix the vulnerability in itsVideo ActiveX Control for Internet Explorer, as well as the DirectShow flaw in Windows. Criminals currently are using both security holes to plant rogue software on PCs when users visit certain hacked or malicious Web sites. Contrary to what Microsoft itself said, the company did not release an official patch to plug the other ActiveX flaw hackers are actively exploiting -- which I first wrote about yesterday. Instead, it has released an interim workaround to blunt the threat from that weakness. Unfortunately, someone at Redmond seems to be a little confused about this point. In its advisory,
Vuln: Hitachi Web Server Client SSL Certificate Handling Unspecified Vulnerability
Hitachi Web Server Client SSL Certificate Handling Unspecified Vulnerability
Read more »Vuln: Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability
Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability
Read more »Bugtraq: [SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution
[SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution
Read more »Bugtraq: TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability
TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability
Read more »Bugtraq: ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability
ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability
Read more »Microsoft repairs critical DirectShow, Video ActiveX vulnerabilities
The software giant issued six updates this week as part of its Patch Tuesday updates. Three bulletins were rated critical.
Read more »Vuln: Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
Read more »Bugtraq: [ GLSA 200907-12 ] ISC DHCP: dhcpclient Remote execution of arbitrary code
[ GLSA 200907-12 ] ISC DHCP: dhcpclient Remote execution of arbitrary code
Read more »U.S. And S. Korea Attacks: "Source Located In United Kingdom"
When the U.S. and South Korea became victims of cyber attacks last week, logic and not a little evidence pointed to North Korea as the culprit. However, a new report traces the attacks to the U.K., instead.
U.S. And S. Korea Attacks: Source Located In U.K.
Bkis, a Vietnam-based security company, stated on its corporate blog, "In order to locate the source of the attacks, we have fought against C&C servers and have gained control of 2 in 8 of them. After analyzing the logs of these 2 servers, we discovered the IP address of the master server, which is 195.90.118.xxx. This IP is located in UK."
Bkis then sprung another surprise by painting the attacks as being far more powerful than experts first thought.
The blog post continued, "During the past few days, the number of zombies has been estimated to be 50,000 by Symantec and about 20,000 by Government of South Korea. But, by taking control of two C&C servers and analyzing logs on these servers, we count the exact number of zombies that have been querying C&C servers to receive commands. . . . [T]here have been 166,908 zombies from 74 countries around the world that have been used for the attacks."
Read more »Vuln: Mozilla Firefox 3.5 Remote Code Execution Vulnerability
Mozilla Firefox 3.5 Remote Code Execution Vulnerability
Read more »Vuln: Novell eDirectory Multiple Vulnerabilities
Novell eDirectory Multiple Vulnerabilities
Read more »Vuln: Wyse Thin Client 'hagent.exe' Unspecified Buffer Overflow Vulnerability
Wyse Thin Client 'hagent.exe' Unspecified Buffer Overflow Vulnerability
Read more »