Big Blog

Arts & Culture
Biological Science
Blog Watch
Computer Games
Computer Security
Cricket
Data Privacy
Developer
Domain Names
E-commerce
Gadgets
General Science
Handhelds
IP & Patents
Java
Linux
MP3
Nanotech
Online Auctions
Online Legal Issues
Open Source
Personal Finance
Photography
Quirky
Robotics
Search Engines
Space Science
Top Internet
Top Stories
Top Tech
Video Games
Web Developer
Webmaster Tips
XML & Metadata
{Home}



vulnerability: search

Firefox 3 Vulnerability Rains on Mozilla Download Parade

A security vulnerability in Mozilla's Firefox 3 was found within hours of the open-source browser's release. Tipping Point received a tip about the Firefox 3 vulnerability, which said the problem could allow an attacker to execute arbitrary code. Tipping Point also questioned the tip it received, suggesting the "researcher" waited for the release.

Apple Fixes Safari "Carpet Bomb" Windows Vulnerability

Titoxd writes "Apple has released a new version of Safari that fixes the carpet bomb vulnerability in Safari 3.1 for Windows. This comes in the heels of Microsoft recommending against using Safari in Windows, as well as the release of code exploiting this vulnerability."

Venafi Automates Cert Replacement to Address Debian Linux Vulnerability

SALT LAKE CITY --(Business Wire)-- Organizations relying on encryption within their most mission-critical business systems must take steps to ensure they can address vulnerabilities like the recently reported Debian Linux flaw when-not if-they happen again, according to Venafi, inventor of systems management for encryption. Such preparations should include automating the management of encryption certificates and keys, to enable rapid identification and replacement. A guide outlining specifically how organizations can address issues and vulnerabilities like the Debian vulnerability using the Venafi encryption management platform and help from a team of expert consultants at Venafi, is available at www.venafi.com/disaster_recovery/linux-debian-openssl-vulnerability.

Venafi Automates Cert Replacement to Address Debian Linux Vulnerability

SALT LAKE CITY (Business Wire) -- Organizations relying on encryption within their most mission-critical business systems must take steps to ensure they can address vulnerabilities like the recently reported Debian Linux flaw when-not if-they happen again, according to Venafi, inventor of systems management for encryption. Such preparations should include automating the management of encryption certificates and keys, to enable rapid identification and replacement. A guide outlining specifically how organizations can address issues and vulnerabilities like the Debian vulnerability using the Venafi encryption management platform and help from a team of expert consultants at Venafi, is available at www.venafi.com/disaster_recovery/linux-debian-openssl-vulnerability.

Venafi Automates Cert Replacement to Address Debian Linux Vulnerability

SALT LAKE CITY--(BUSINESS WIRE)--May 23, 2008--Organizations relying on encryption within their most mission-critical business systems must take steps to ensure they can address vulnerabilities like the recently reported Debian Linux flaw when–not if–they happen again, according to Venafi, inventor of systems management for encryption. Such preparations should include automating the management of encryption certificates and keys, to enable rapid identification and replacement. A guide outlining specifically how organizations can address issues and vulnerabilities like the Debian vulnerability using the Venafi encryption management platform and help from a team of expert consultants at Venafi, is available at www.venafi.com/disaster-recovery/linux-debian-openssl-vulnerability.

Vulnerability Found in New Firefox Browser

It took only five hours from the release of Firefox version 3.0 for a researcher to report a critical vulnerability in the open source browser.

Multiple Vendor HTML Form Protocol Vulnerability

This vulnerability was submitted to BugTraq on August 15th by Jochen Topf . Additional techniques for exploitation were published by Obscure .

Linksys WRH54G Denial of Service Vulnerability

A vulnerability has been reported in Linksys WRH54G, which can be exploited by malicious people to cause a DoS (Denial of Service).

Apache Tomcat Invoker Servlet File Disclosure Vulnerability

This vulnerability was reported by the Tomcat development team.

Asterisk Addons "ooh323" Denial of Service Vulnerability

A vulnerability has been reported in Asterisk Addons, which can be exploited by malicious people to cause a DoS (Denial of Service).

Vulnerability disclosure gone awry: Inside the DNS debacle

Categories: Patch Watch, Hackers, Microsoft, Browsers, Vulnerability research, Responsible disclosure, Botnets, Exploit code, Data theft, Open source, Pen testing, Passwords, Arbitrary Code Execution, Complex Attacks

Adobe RoboHelp Server Help Errors Log SQL-Injection Vulnerability

The Vulnerability Research Team of Assurent Secure Technologies (a TELUS company) and Greg Patton of PropertyInfo Corporation

Critical vulnerability in Microsoft XML Core Services patched

Microsoft Security issued a patch today for a critical vulnerability affecting all supported editions of Windows 2000, Windows XP, Windows Vista, Microsoft Office 2003, and the 2007 Microsoft Office System. The hole is in Microsoft XML Core Services and could allow remote code execution if a user viewed a malicious Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Impact of the Debian OpenSSL vulnerability

A severe vulnerability was found in the random number generator (RNG) of the Debian OpenSSL package, starting with version 0.9.8c-1 (and similar packages in derived distributions such as Ubuntu). While this bug is not present in the OpenSSL packages provided by CentOS, it may still affect CentOS users. The bug barred the OpenSSL random number generator from gaining enough entropy required for generating unpredicatable keys. In fact it appearss that the only source for entropy was the process ID of the process generating a key, which is chosen from a very small range and is predictable. As such, all keys generated using the Debian OpenSSL library should be considered compromized. Programs that use OpenSSL include OpenSSH and OpenVPN. Note that GnuPG and GNU TLS do not use OpenSSL, so they are not affected.

Code execution vulnerability in Firefox 3.0

Categories: Patch Watch, Hackers, Browsers, Vulnerability research, Responsible disclosure, Botnets, Exploit code, Viruses and Worms, Mozilla, Firefox, Arbitrary Code Execution

Critical Linux vulnerability exposed

Security experts have warned of a suspected vulnerability in the Debian and Ubuntu Linux operating systems.

Firefox 3 vulnerability found

Tipping Point ranked the severity of Firefox 3's vulnerability as high, but said users would have to click on a link in an e-mail or visit a malicious Web page before being affected

Firefox 3 vulnerability found

Five hours after Mozilla officially released Firefox 3.0, researchers found a vulnerability in the new browser.

Digital Defense Releases Critical Vulnerability Check for the OpenSSL Implementation on Debian and Ubuntu Linux Distributions

TMCNet: Digital Defense Releases Critical Vulnerability Check for the OpenSSL Implementation on Debian and Ubuntu Linux Distributions

Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability

Discovery of this vulnerability has been credited to Aldrin Martoq.

PayPal XSS vulnerability affects EV SSL

A new attack on PayPal could have allowed users who thought they were on a trusted page to access a fraudulent page and possibly expose personal information. On Friday, Finnish researcher Harry Sintonen reported the vulnerability on an IRC chat room.

Security experts confirm Linux vulnerability

Security experts have confirmed a suspected vulnerability in the Debian and Ubuntu Linux operating systems.

Ruby "rb_ary_fill()" Denial of Service Vulnerability

Vincenzo "snagg" Iozzo has reported a vulnerability in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).

TorrentTrader 'msg' Parameter HTML Injection Vulnerability

Dominus is credited with discovering this vulnerability.

Digital Defense Rolls Out Critical Vulnerability Check for the OpenSSL Implementation on Debian and Ubuntu Linux Distributions

TMCNet: Digital Defense Rolls Out Critical Vulnerability Check for the OpenSSL Implementation on Debian and Ubuntu Linux Distributions


Search News:


Copyright © 2001-2008 Jonathan Hedley