<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Systech Solutions LTD. &#187; Microsoft and US-Cert Security Bulletins</title>
	<atom:link href="http://www.systechsolutions.info/blog/category/microsoft-security-bulletins/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.systechsolutions.info/blog</link>
	<description>Making the most out of your technology.</description>
	<lastBuildDate>Wed, 21 Oct 2009 13:44:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>US-CERT Current Activity &#8211; Adobe Flash Vulnerability Affecting Apple Snow Leopard</title>
		<link>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-adobe-flash-vulnerability-affecting-apple-snow-leopard/</link>
		<comments>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-adobe-flash-vulnerability-affecting-apple-snow-leopard/#comments</comments>
		<pubDate>Fri, 04 Sep 2009 21:18:39 +0000</pubDate>
		<dc:creator>lukeconaway</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=927</guid>
		<description><![CDATA[US-CERT Current Activity
 
Adobe Flash Vulnerability Affecting Apple Snow Leopard
 
Original release date: September 4, 2009 at 2:58 pm Last revised: September 4, 2009 at 2:58 pm
 
 
US-CERT is aware that Apple&#8217;s recently released version of Mac OS X, Snow Leopard, includes a version of the Flash Player that contains previously addressed vulnerabilities.
 
US-CERT encourages users and administrators to [...]]]></description>
			<content:encoded><![CDATA[<p>US-CERT Current Activity</p>
<p> </p>
<p>Adobe Flash Vulnerability Affecting Apple Snow Leopard</p>
<p> </p>
<p>Original release date: September 4, 2009 at 2:58 pm Last revised: September 4, 2009 at 2:58 pm</p>
<p> </p>
<p> </p>
<p>US-CERT is aware that Apple&#8217;s recently released version of Mac OS X, Snow Leopard, includes a version of the Flash Player that contains previously addressed vulnerabilities.</p>
<p> </p>
<p>US-CERT encourages users and administrators to upgrade to the latest version of Flash Player. Users and administrators can determine their version of Flash using the Version test for Adobe Flash Player.</p>
<p> </p>
<p>Relevant Url(s):</p>
<p>&lt;<a href="http://kb2.adobe.com/cps/155/tn_15507.html">http://kb2.adobe.com/cps/155/tn_15507.html</a>&gt;</p>
<p> </p>
<p>&lt;<a href="http://get.adobe.com/flashplayer/">http://get.adobe.com/flashplayer/</a>&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-adobe-flash-vulnerability-affecting-apple-snow-leopard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Current Activity &#8211; Microsoft Internet Information Services (IIS) FTP Service Vulnerability</title>
		<link>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-microsoft-internet-information-services-iis-ftp-service-vulnerability/</link>
		<comments>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-microsoft-internet-information-services-iis-ftp-service-vulnerability/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 13:49:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=923</guid>
		<description><![CDATA[Here are the latest in IIS vulenrability statements:
US-CERT Current Activity
 
Microsoft Internet Information Services (IIS) FTP Service Vulnerability
 
Original release date: August 31, 2009 at 4:27 pm Last revised: August 31, 2009 at 4:27 pm
 
 
Microsoft Internet Information Services (IIS) FTP Service Vulnerability
 
US-CERT is aware of a public report of a vulnerability affecting the Microsoft Internet Information Services [...]]]></description>
			<content:encoded><![CDATA[<p>Here are the latest in IIS vulenrability statements:</p>
<p>US-CERT Current Activity</p>
<p> </p>
<p>Microsoft Internet Information Services (IIS) FTP Service Vulnerability</p>
<p> </p>
<p>Original release date: August 31, 2009 at 4:27 pm Last revised: August 31, 2009 at 4:27 pm</p>
<p> </p>
<p> </p>
<p>Microsoft Internet Information Services (IIS) FTP Service Vulnerability</p>
<p> </p>
<p>US-CERT is aware of a public report of a vulnerability affecting the Microsoft Internet Information Services (IIS) FTP service. This vulnerability may allow a remote attacker to execute arbitrary code.</p>
<p> </p>
<p>US-CERT encourages administrators to disable anonymous write access to the FTP server to help mitigate the vulnerability, although a proper impact analysis should be performed prior to taking defensive measures.</p>
<p> </p>
<p>US-CERT will provide additional information as it becomes available.</p>
<p>====</p>
<p>This entry is available at</p>
<p><a href="http://www.us-cert.gov/current/index.html#microsoft_internet_information_services_iis1">http://www.us-cert.gov/current/index.html#microsoft_internet_information_services_iis1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/09/us-cert-current-activity-microsoft-internet-information-services-iis-ftp-service-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Current Activity &#8211; Autonomy KeyView SDK Vulnerability</title>
		<link>http://www.systechsolutions.info/blog/2009/08/us-cert-current-activity-autonomy-keyview-sdk-vulnerability-2/</link>
		<comments>http://www.systechsolutions.info/blog/2009/08/us-cert-current-activity-autonomy-keyview-sdk-vulnerability-2/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 14:43:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=915</guid>
		<description><![CDATA[I received the following notification regarding the Autonomy keyView SDK vulnerability.
US-CERT Current Activity
 
Autonomy KeyView SDK Vulnerability
 
Original release date: August 26, 2009 at 9:47 am Last revised: August 26, 2009 at 9:47 am
 
 
US-CERT is aware of reports of a vulnerability in the way the Autonomy KeyView SDK parses Excel files. The Autonomy KeyView SDK is used [...]]]></description>
			<content:encoded><![CDATA[<p>I received the following notification regarding the Autonomy keyView SDK vulnerability.</p>
<blockquote><p>US-CERT Current Activity</p>
<p> </p>
<p>Autonomy KeyView SDK Vulnerability</p>
<p> </p>
<p>Original release date: August 26, 2009 at 9:47 am Last revised: August 26, 2009 at 9:47 am</p>
<p> </p>
<p> </p>
<p>US-CERT is aware of reports of a vulnerability in the way the Autonomy KeyView SDK parses Excel files. The Autonomy KeyView SDK is used by certain products, including Lotus Notes and Symantec Mail Security, to support the handling of a number of different file formats. By supplying a specially crafted Excel spreadsheet to an application using the affected Autonomy KeyView SDK library, a remote attacker may be able to execute arbitrary code in the context of that application.</p>
<p> </p>
<p>US-CERT encourages users and administrators to do the following to help mitigate the risks:</p>
<p>  * IBM Lotus Notes users should review the IBM Flash Alert and</p>
<p>    implement the listed fixes or workarounds.</p>
<p>  * Symantec users should review Symantec Security Advisory SYM09-010</p>
<p>    and implement the listed fixes or workarounds.</p>
<p>  * The original reporters of the vulnerability state that users of</p>
<p>    other applications that use an affected version of the Autonomy</p>
<p>    KeyView SDK may wish to remove the xlssr.dll filter module or</p>
<p>    comment out the reference to xlssr.dll in the KeyView.ini file</p>
<p>    distributed with the affected application.</p>
<p> </p>
<p>Relevant Url(s):</p>
<p>&lt;<a href="http://www-01.ibm.com/support/docview.wss?rs=463&amp;uid=swg21396492">http://www-01.ibm.com/support/docview.wss?rs=463&amp;uid=swg21396492</a>&gt;</p>
<p> </p>
<p>&lt;<a href="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090825_00">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090825_00</a>&gt;</p>
<p> </p>
<p>====</p>
<p>This entry is available at</p>
<p><a href="http://www.us-cert.gov/current/index.html#autonomy_keyview_sdk_vulnerability1">http://www.us-cert.gov/current/index.html#autonomy_keyview_sdk_vulnerability1</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/08/us-cert-current-activity-autonomy-keyview-sdk-vulnerability-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Summary for the Week of August 17, 2009</title>
		<link>http://www.systechsolutions.info/blog/2009/08/vulnerability-summary-for-the-week-of-august-17-2009/</link>
		<comments>http://www.systechsolutions.info/blog/2009/08/vulnerability-summary-for-the-week-of-august-17-2009/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 19:52:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=913</guid>
		<description><![CDATA[National Cyber Alert System
Cyber Security Bulletin SB09-236 

Vulnerability Summary for the Week of August 17, 2009




The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of [...]]]></description>
			<content:encoded><![CDATA[<p><span>National Cyber Alert System</span><br />
<span>Cyber Security Bulletin SB09-236</span> <span id="cas_archiveLink"><a title="Current Activity Archive" href="http://www.systechsolutions.info/cas/bulletins/index.html"><img src="http://www.systechsolutions.info/images/archive.gif" border="0" alt="archive" /></a></span></p>
<div id="cas_copy">
<h2>Vulnerability Summary for the Week of August 17, 2009</h2>
<p><a name="top"></a></p>
<table border="0" align="center">
<tbody>
<tr>
<td>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the <a href="http://nvd.nist.gov/">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#high">High</a></strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</li>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#medium">Medium</a></strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</li>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#low">Low</a></strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</td>
</tr>
</tbody>
</table>
<p><a name="high"></a></p>
<div id="high_v">
<table border="1" align="center" summary="High Vulnerabilities">
<thead>
<tr>
<th id="high_v_title" colspan="5" scope="col">High Vulnerabilities</th>
</tr>
<tr>
<th style="width: 20%;" scope="col">Primary<br />
Vendor &#8212; Product</th>
<th style="width: 45%;" scope="col">Description</th>
<th style="width: 10%;" scope="col">Published</th>
<th style="width: 5%;" scope="col">CVSS Score</th>
<th style="width: 10%;" scope="col">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;" width="20%">2fly &#8212; gift_delivery_system</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2915&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2915">CVE-2009-2915</a><br />
<a href="http://secunia.com/advisories/36294" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0908-exploits/discuz60-sql.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">2kgames &#8212; vietcong2</td>
<td style="text-align: left;" width="45%">Format string vulnerability in the CNS_AddTxt function in logs.dll in 2K Games Vietcong 2 1.10 and earlier might allow remote attackers to execute arbitrary code via format string specifiers in the nickname.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2916&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2916">CVE-2009-2916</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52422" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/36301" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/57002" target="_blank">OSVDB</a><br />
<a href="http://aluigi.altervista.org/adv/vietcong2fs-adv.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">accellion &#8212; file_transfer_appliance_fta</td>
<td style="text-align: left;" width="45%">courier/1000@/api_error_email.html (aka &#8220;error reporting page&#8221;) in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7012&amp;vector=(AV:N/AC:L/Au:N/C:N/I:C/A:N)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7012">CVE-2008-7012</a><br />
<a href="http://zebux.free.fr/pub/Advisory/Advisory_Accellion_SPAM_Engine_Vulnerability_200808.txt" target="_blank">MISC</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45159" target="_blank">XF</a><br />
<a href="http://www.securitytracker.com/id?1020870" target="_blank">SECTRACK</a><br />
<a href="http://www.securityfocus.com/bid/31178" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/31848" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/48242" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">acer &#8212; lunchapp.aplunch</td>
<td style="text-align: left;" width="45%">The Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2627&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2627">CVE-2009-2627</a><br />
<a href="http://www.kb.cert.org/vuls/id/485961" target="_blank">CERT-VN</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2299" target="_blank">VUPEN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adium &#8212; adium<br />
pidgin &#8212; pidgin</td>
<td style="text-align: left;" width="45%">The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2694&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2694">CVE-2009-2694</a><br />
<a href="http://developer.pidgin.im/viewmtn/revision/info/6f7343166c673bf0496ecb1afec9b633c1d54a0e" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aj_square &#8212; aj_article</td>
<td style="text-align: left;" width="45%">AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7051&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7051">CVE-2008-7051</a><br />
<a href="http://www.vupen.com/english/advisories/2008/3097" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/32254" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/7081" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">artis.imag &#8212; basilic</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2881&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2881">CVE-2009-2881</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51992" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2005" target="_blank">VUPEN</a><br />
<a href="http://www.milw0rm.com/exploits/9246" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aruba_networks &#8212; aruba_mobility_controller<br />
arubanetworks &#8212; arubaos</td>
<td style="text-align: left;" width="45%">Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product&#8217;s security documentation.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7023&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7023">CVE-2008-7023</a><br />
<a href="http://www.securityfocus.com/bid/31336" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496622/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496604/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://osvdb.org/51731" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aves &#8212; rpg_board</td>
<td style="text-align: left;" width="45%">RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7028&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7028">CVE-2008-7028</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45501" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31466" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6591" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">chilkatsoft &#8212; chilkat_imap_activex_control</td>
<td style="text-align: left;" width="45%">Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7022&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7022">CVE-2008-7022</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45532" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/6600" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cisco &#8212; firewall_services_module</td>
<td style="text-align: left;" width="45%">The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 before 4.0(6) for Cisco Catalyst 6500 switches and Cisco 7600 routers allows remote attackers to cause a denial of service (traffic-handling outage) via a series of malformed ICMP messages.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-0638&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0638">CVE-2009-0638</a><br />
<a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af0d1d.shtml" target="_blank">CISCO</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">clone2009 &#8212; ebay_clone</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2894&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2894">CVE-2009-2894</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51956" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35952" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/clone2009-sql.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56268" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56266" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56265" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cmsbright &#8212; cmsbright</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL commands via the id_rub_page parameter.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6991&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6991">CVE-2008-6991</a><br />
<a href="http://www.securityfocus.com/bid/30946" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6343" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31669" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/47910" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">creative_mind &#8212; creator_cms</td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7001&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7001">CVE-2008-7001</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44982" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/6405" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">devalcms &#8212; devalcms</td>
<td style="text-align: left;" width="45%">modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6983&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6983">CVE-2008-6983</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44942" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31037" target="_blank">BID</a><br />
<a href="http://osvdb.org/47972" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">digitalspinners &#8212; ds_cms</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2927&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2927">CVE-2009-2927</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52486" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9440" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">djcalendar &#8212; djcalendar</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2925&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2925">CVE-2009-2925</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52463" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9140" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">elog &#8212; elog</td>
<td style="text-align: left;" width="45%">Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7004&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7004">CVE-2008-7004</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/39903" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2008/0265" target="_blank">VUPEN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">esqlanelapse &#8212; esqlanelapse</td>
<td style="text-align: left;" width="45%">Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7019&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7019">CVE-2008-7019</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45438" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31428" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6583" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ezonescripts &#8212; dating_website_script</td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6987&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6987">CVE-2008-6987</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44959" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31028" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ezphotogallery &#8212; ezphotogallery</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6989&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6989">CVE-2008-6989</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496220/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/48315" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/6428" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31774" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ezphotogallery &#8212; ezphotogallery</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6990&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6990">CVE-2008-6990</a><br />
<a href="http://www.osvdb.org/48315" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/31774" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">galore &#8212; com_simpleshop</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7033&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7033">CVE-2008-7033</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/40802" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/27977" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/488692" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/52094" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6994&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6994">CVE-2008-6994</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44935" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31029" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496042/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/6367" target="_blank">MILW0RM</a><br />
<a href="http://www.infoworld.com/d/security-central/critical-vulnerability-patched-in-googles-chrome-599" target="_blank">MISC</a><br />
<a href="http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/chrome/common/win_util.cc?r1=1757&amp;r2=1766&amp;pathrev=1766" target="_blank">CONFIRM</a><br />
<a href="http://securitytracker.com/id?1020823" target="_blank">SECTRACK</a><br />
<a href="http://security.bkis.vn/?p=119" target="_blank">MISC</a><br />
<a href="http://osvdb.org/48259" target="_blank">OSVDB</a><br />
<a href="http://code.google.com/p/chromium/issues/detail?id=1414" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6998&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6998">CVE-2008-6998</a><br />
<a href="http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/chrome/common/gfx/url_elider.cc?r1=1774&amp;r2=1797&amp;pathrev=1797" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">greensql &#8212; greensql_firewall</td>
<td style="text-align: left;" width="45%">GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as &#8220;x=y=z&#8221;, which is successfully parsed by MySQL.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6992&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6992">CVE-2008-6992</a><br />
<a href="http://www.greensql.net/node/98" target="_blank">MISC</a><br />
<a href="http://www.greensql.net/node/89" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">imtoo &#8212; mpeg_encoder</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2917&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2917">CVE-2009-2917</a><br />
<a href="http://www.milw0rm.com/exploits/9382" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">joshua_oliver &#8212; really_simple_cms</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2792&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2792">CVE-2009-2792</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52159" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9313" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">kde &#8212; kmplayer</td>
<td style="text-align: left;" width="45%">Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2896&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2896">CVE-2009-2896</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51882" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1959" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35745" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9220" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">libra_file_manager &#8212; php_filemanager</td>
<td style="text-align: left;" width="45%">Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7027&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7027">CVE-2008-7027</a><br />
<a href="http://www.securityfocus.com/bid/31422" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6579" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2692&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2692">CVE-2009-2692</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2272" target="_blank">VUPEN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer dereference.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2767&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2767">CVE-2009-2767</a><br />
<a href="http://lkml.org/lkml/2009/8/4/40" target="_blank">MLIST</a><br />
<a href="http://lkml.org/lkml/2009/8/4/28" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2844&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2844">CVE-2009-2844</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/17/2" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/17/1" target="_blank">MLIST</a><br />
<a href="http://jon.oberheide.org/files/cfg80211-remote-dos.c" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2846&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2846">CVE-2009-2846</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/18/6" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/10/1" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">minb &#8212; minb_is_not_a_blog</td>
<td style="text-align: left;" width="45%">include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit parameter. NOTE: this issue has been reported as an unrestricted file upload by some sources, but that is a potential consequence of code execution.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7005&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7005">CVE-2008-7005</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45054" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31127" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496234/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/6432" target="_blank">MILW0RM</a><br />
<a href="http://osvdb.org/51805" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mobilelib &#8212; mobilelib_gold</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php, (2) cid parameter to artcat.php, and (3) catid parameter to show.php.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2788&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2788">CVE-2009-2788</a><br />
<a href="http://www.securityfocus.com/bid/35910" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9327" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mocdesigns &#8212; php_news</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2921&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2921">CVE-2009-2921</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52231" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2161" target="_blank">VUPEN</a><br />
<a href="http://www.milw0rm.com/exploits/9353" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">nasa_goddard_space_flight_center &#8212; common_data_format</td>
<td style="text-align: left;" width="45%">Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4) CDFsel64, and other unspecified functions.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2850&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2850">CVE-2009-2850</a><br />
<a href="http://cdf.gsfc.nasa.gov/html/CDF_v330.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">natterchat &#8212; natterchat</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7049&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7049">CVE-2008-7049</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/46748" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/32385" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/7175" target="_blank">MILW0RM</a><br />
<a href="http://www.milw0rm.com/exploits/7172" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">permis &#8212; com_groups</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2789&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2789">CVE-2009-2789</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52142" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35849" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">php &#8212; php</td>
<td style="text-align: left;" width="45%">PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as &#8220;C:&#8221; drive notation.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7002&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7002">CVE-2008-7002</a><br />
<a href="http://www.securityfocus.com/bid/31064" target="_blank">BID</a><br />
<a href="http://downloads.securityfocus.com/vulnerabilities/exploits/31064.php" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">php-paid4mail &#8212; php-paid4mail</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2774&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2774">CVE-2009-2774</a><br />
<a href="http://www.milw0rm.com/exploits/9287" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35972" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpadultsite &#8212; phpadultsite_cms</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to execute arbitrary SQL commands via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6980&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6980">CVE-2008-6980</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44922" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496069/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.davidsopas.com/2008/09/phpadult-cms-exploit/" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/31793" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/47942" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpauction &#8212; phpauction</td>
<td style="text-align: left;" width="45%">PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7000&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7000">CVE-2008-7000</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44938" target="_blank">XF</a><br />
<a href="http://packetstorm.linuxsecurity.com/0809-exploits/phpauction32-rfi.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpcompet.free &#8212; php_competition_system</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2926&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2926">CVE-2009-2926</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52487" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9438" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; world&#8217;s_tallest_buildings</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in bios.php in PHP Scripts Now World&#8217;s Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2885&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2885">CVE-2009-2885</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51870" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56121" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35935" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/tallestbuildings-sql.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; president_bios</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2886&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2886">CVE-2009-2886</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51870" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35935" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/presidentbios-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; hangman</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2888&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2888">CVE-2009-2888</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51884" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56075" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35888" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/tophangman-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; riddles</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2891&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2891">CVE-2009-2891</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51872" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56123" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35932" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/riddledepot-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpsugar &#8212; ultimate_regnow_affiliate</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2895&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2895">CVE-2009-2895</a><br />
<a href="http://www.milw0rm.com/exploits/9263" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpversion &#8212; php_vx_guestbook</td>
<td style="text-align: left;" width="45%">Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7007&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7007">CVE-2008-7007</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45152" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31174" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6457" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31850" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/48155" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">piwigo &#8212; piwigo</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in comments.php in Piwigo before 2.0.3 allows remote attackers to execute arbitrary SQL commands via the items_number parameter.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2933&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2933">CVE-2009-2933</a><br />
<a href="http://www.senseofsecurity.com.au/advisories/SOS-09-007.pdf" target="_blank">MISC</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505801/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://secunia.com/advisories/36333" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">pixaria &#8212; pixaria_gallery</td>
<td style="text-align: left;" width="45%">Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2922&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2922">CVE-2009-2922</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51994" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35802" target="_blank">BID</a><br />
<a href="http://www.pixaria.com/news/article/234" target="_blank">CONFIRM</a><br />
<a href="http://www.milw0rm.com/exploits/9257" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">programmedintegration &#8212; pipl</td>
<td style="text-align: left;" width="45%">Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2934&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2934">CVE-2009-2934</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52440" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9428" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/36297" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/56996" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">reputation &#8212; reputation</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2786&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2786">CVE-2009-2786</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52088" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9289" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/36020" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/56612" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">scripteen &#8212; free_image_hosting_script</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2892&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2892">CVE-2009-2892</a><br />
<a href="http://www.scripteen.com/forum/news-announcements-f2-scripteen-free-image-hosting-script-v2-4-t766.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">shop-020 &#8212; php_paid_4_mail_script</td>
<td style="text-align: left;" width="45%">PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2773&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2773">CVE-2009-2773</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52015" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9269" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35972" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/56573" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">siemens &#8212; gigaset_wlan_camera</td>
<td style="text-align: left;" width="45%">Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6993&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6993">CVE-2008-6993</a><br />
<a href="http://www.securityfocus.com/bid/30973" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">site2nite &#8212; real_estate_web</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7030&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7030">CVE-2008-7030</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/40509" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/27779" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/488070/100/200/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/51076" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">skalinks &#8212; exchange_script</td>
<td style="text-align: left;" width="45%">Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7010&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7010">CVE-2008-7010</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45116" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31158" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6445" target="_blank">MILW0RM</a><br />
<a href="http://packetstormsecurity.org/0809-exploits/skalinks-editor.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">slideshowpro &#8212; director</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2931&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2931">CVE-2009-2931</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505534/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/56825" target="_blank">OSVDB</a><br />
<a href="http://www.clearskies.net/documents/css-advisory-css09001-sspdirector.pdf" target="_blank">MISC</a><br />
<a href="http://slideshowpro.net/news/archive/2009/07/director-139-fi.php" target="_blank">CONFIRM</a><br />
<a href="http://secunia.com/advisories/36197" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">snom &#8212; snom_300<br />
snom &#8212; snom_320<br />
snom &#8212; snom_360<br />
snom &#8212; snom_370</td>
<td style="text-align: left;" width="45%">The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1048&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1048">CVE-2009-1048</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52424" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505723/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/36293" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">softbiz &#8212; dating_script</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2790&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2790">CVE-2009-2790</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52158" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35896" target="_blank">BID</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/softbizdating-sql.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">tgs-cms &#8212; tgs_content_management</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters to cms/index.php; and the (12) cmd, (13) s_dir, (14) minutes, (15) s_mask, (16) test3_mp, (17) test15_file1, (18) submit, (19) brute_method, (20) ftp_server_port, (21) userfile14, (22) subj, (23) mysql_l, (24) action, and (25) userfile1 parameters to cms/frontpage_ception.php. NOTE: some of these parameters may be applicable only in nonstandard versions of the product, and cms/frontpage_ception.php may be cms/frontpage_caption.php in all released versions.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2929&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2929">CVE-2009-2929</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52468" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9434" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">the-rat-cms &#8212; the-rat-cms</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via the (1) user_id and (2) password parameter.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7003&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7003">CVE-2008-7003</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/47335" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/32845" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/7478" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">tikiwiki &#8212; tikiwiki</td>
<td style="text-align: left;" width="45%">TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer &#8220;Remember Me&#8221; feature. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2003-1574&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2003-1574">CVE-2003-1574</a><br />
<a href="http://www.securityfocus.com/bid/14170" target="_blank">BID</a><br />
<a href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=748739&amp;group_id=64258&amp;atid=506846" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">videosbroadcastyourself &#8212; videos_broadcast_yourself</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2924&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2924">CVE-2009-2924</a><br />
<a href="http://www.milw0rm.com/exploits/9453" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">webdynamite &#8212; projectbutler</td>
<td style="text-align: left;" width="45%">PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2791&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2791">CVE-2009-2791</a><br />
<a href="http://www.securityfocus.com/bid/35919" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9331" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wordpress &#8212; wordpress</td>
<td style="text-align: left;" width="45%">Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2853&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2853">CVE-2009-2853</a><br />
<a href="http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/" target="_blank">CONFIRM</a></td>
</tr>
</tbody>
<tfoot>
<tr>
<td colspan="5"><a href="http://www.systechsolutions.info/blog/wp-admin/#top">Back to top</a></td>
</tr>
</tfoot>
</table>
</div>
<p><a name="medium"></a></p>
<div id="medium_v">
<table border="1" align="center" summary="Medium Vulnerabilities">
<thead>
<tr>
<th id="medium_v_title" colspan="5" scope="col">Medium Vulnerabilities</th>
</tr>
<tr>
<th style="width: 20%;" scope="col">Primary<br />
Vendor &#8212; Product</th>
<th style="width: 45%;" scope="col">Description</th>
<th style="width: 10%;" scope="col">Published</th>
<th style="width: 5%;" scope="col">CVSS Score</th>
<th style="width: 10%;" scope="col">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;" width="20%"> </td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in usercp.php in AlilG Application AliBoard Beta allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in uploads/avatars/.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7029&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)">6.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7029">CVE-2008-7029</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/40276" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/27737" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/487921/100/200/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://osvdb.org/51183" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; coldfusion</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1872&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1872">CVE-2009-1872</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; jrun</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1873&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)">4.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1873">CVE-2009-1873</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; jrun</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1874&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1874">CVE-2009-1874</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; coldfusion</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1875&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1875">CVE-2009-1875</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; coldfusion</td>
<td style="text-align: left;" width="45%">Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a &#8220;double-encoded null character vulnerability.&#8221;</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1876&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1876">CVE-2009-1876</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; coldfusion</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1877&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1877">CVE-2009-1877</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; coldfusion</td>
<td style="text-align: left;" width="45%">Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1878&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1878">CVE-2009-1878</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">arabless &#8212; saphplesson</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2883&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2883">CVE-2009-2883</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51983" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35795" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9248" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">arzdev &#8212; gemini_lite<br />
arzdev &#8212; gemini_portal</td>
<td style="text-align: left;" width="45%">admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to &#8220;admin&#8221; and setting the name parameter to &#8220;users.&#8221;</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7024&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7024">CVE-2008-7024</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45439" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31429" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496761/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/6584" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/32057" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/48639" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">availscript &#8212; jobs_portal_script</td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7021&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)">6.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7021">CVE-2008-7021</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45335" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31297" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6514" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31810" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">baidu &#8212; baidu_hi_im</td>
<td style="text-align: left;" width="45%">NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7013&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7013">CVE-2008-7013</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496353/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://osvdb.org/51697" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bitmixsoft &#8212; php-lance</td>
<td style="text-align: left;" width="45%">Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2923&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2923">CVE-2009-2923</a><br />
<a href="http://www.milw0rm.com/exploits/9444" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bzip &#8212; compress-raw-bzip2</td>
<td style="text-align: left;" width="45%">Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1884&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1884">CVE-2009-1884</a><br />
<a href="https://bugs.gentoo.org/show_bug.cgi?id=281955" target="_blank">CONFIRM</a><br />
<a href="http://security.gentoo.org/glsa/glsa-200908-07.xml" target="_blank">GENTOO</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ca &#8212; host-based_intrusion_prevention_system</td>
<td style="text-align: left;" width="45%">kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2740&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2740">CVE-2009-2740</a><br />
<a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214665" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cacert &#8212; cacert</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7017&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7017">CVE-2008-7017</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45515" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31481" target="_blank">BID</a><br />
<a href="http://www.cynops.de/advisories/AKLINK-SA-2008-007.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">checkpoint &#8212; zonealarm</td>
<td style="text-align: left;" width="45%">Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7009&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)">6.9</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7009">CVE-2008-7009</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45082" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2008/2556" target="_blank">VUPEN</a><br />
<a href="http://www.securitytracker.com/id?1020859" target="_blank">SECTRACK</a><br />
<a href="http://www.securityfocus.com/bid/31124" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496226/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://secunia.com/advisories/31832" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/48097" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">checkpoint &#8212; zonealarm</td>
<td style="text-align: left;" width="45%">TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7025&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7025">CVE-2008-7025</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45480" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31431" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496764/100/0/threaded" target="_blank">BUGTRAQ</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cisco &#8212; ios_xr</td>
<td style="text-align: left;" width="45%">Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2055&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2055">CVE-2009-2055</a><br />
<a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml" target="_blank">CISCO</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">datingpro &#8212; matchmaking</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4) id parameter to services.php.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2882&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2882">CVE-2009-2882</a><br />
<a href="http://www.securityfocus.com/bid/35808" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/36004" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/pgmatchmaking-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">dd-wrt &#8212; dd-wrt</td>
<td style="text-align: left;" width="45%">Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a &#8220;weak &#8230; anti-CSRF fix&#8221; implemented in 24 sp2.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6975&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6975">CVE-2008-6975</a><br />
<a href="http://www.securityfocus.com/archive/1/499135" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/499119" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/499024" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9209" target="_blank">MILW0RM</a><br />
<a href="http://www.dd-wrt.com/phpBB2/viewtopic.php?t=55173" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">devalcms &#8212; devalcms</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6982&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6982">CVE-2008-6982</a><br />
<a href="http://sourceforge.net/projects/devalcms/files/devalcms/devalcms-1.4b/devalcms-1.4b.zip/download" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">digital_extreme &#8212; pariah<br />
epic_games &#8212; unreal_tournament<br />
groove_games &#8212; warpath<br />
human_head_studios &#8212; dead_mans_hand<br />
red_mercury &#8212; shadow_ops<br />
whiptail_interactive &#8212; postal</td>
<td style="text-align: left;" width="45%">The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man&#8217;s Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7011&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)">4.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7011">CVE-2008-7011</a><br />
<a href="http://www.securityfocus.com/bid/31205" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496399/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://osvdb.org/48293" target="_blank">OSVDB</a><br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0321.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">efrontlearning &#8212; efront</td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7026&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7026">CVE-2008-7026</a><br />
<a href="http://www.securityfocus.com/bid/31491" target="_blank">BID</a><br />
<a href="http://forum.efrontlearning.net/viewtopic.php?f=1&amp;t=271" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">elkagroup &#8212; elkapax_cms</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2930&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2930">CVE-2009-2930</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505725/100/0/threaded" target="_blank">BUGTRAQ</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">elvinbts &#8212; elvinbts</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to createaccount.php.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2920&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2920">CVE-2009-2920</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51671" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9342" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">epic_games &#8212; unreal_tournament<br />
frontlines &#8212; fuel_of_war</td>
<td style="text-align: left;" width="45%">Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7015&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7015">CVE-2008-7015</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45095" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31140" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496280/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://osvdb.org/48292" target="_blank">OSVDB</a><br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0189.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ezphotogallery &#8212; ezphotogallery</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters to show.php.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6988&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6988">CVE-2008-6988</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45050" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496220/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/48316" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/6428" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31774" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">fhttpd &#8212; fhttpd</td>
<td style="text-align: left;" width="45%">fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7014&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7014">CVE-2008-7014</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45278" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31265" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6493" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">fullrevolution &#8212; aspwebalbum</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6977&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6977">CVE-2008-6977</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44878" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/30996" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6420" target="_blank">MILW0RM</a><br />
<a href="http://www.milw0rm.com/exploits/6357" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31649" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">fullrevolution &#8212; aspwebalbum</td>
<td style="text-align: left;" width="45%">Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6978&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6978">CVE-2008-6978</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44876" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/30996" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6420" target="_blank">MILW0RM</a><br />
<a href="http://www.milw0rm.com/exploits/6357" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/31649" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/47913" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">garagesalesjunkie &#8212; garagesales_script</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2778&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2778">CVE-2009-2778</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52035" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2023" target="_blank">VUPEN</a><br />
<a href="http://www.milw0rm.com/exploits/9262" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/36017" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">gelatocms &#8212; gelatocms</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in admin/comments.php in Gelato CMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter in a comment. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7039&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7039">CVE-2008-7039</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/40264" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/27587" target="_blank">BID</a><br />
<a href="http://osvdb.org/ref/44/gelato-cms-xss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/44310" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a &#8220;%&#8221; (percent) character, which triggers a buffer over-read, as demonstrated using an &#8220;about:%&#8221; URI.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6995&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6995">CVE-2008-6995</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44899" target="_blank">XF</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the &#8220;ask where to save each file before downloading&#8221; setting.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6996&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6996">CVE-2008-6996</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44904" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31000" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496048/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/495987/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/495959/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/495954/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/495951/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/495942/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/496049" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/48261" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/6355" target="_blank">MILW0RM</a><br />
<a href="http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=1793" target="_blank">CONFIRM</a><br />
<a href="http://codereview.chromium.org/472/diff/1/2" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an &#8220;Inspect Element&#8221; action.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6997&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6997">CVE-2008-6997</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44941" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31038" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6386" target="_blank">MILW0RM</a><br />
<a href="http://osvdb.org/48260" target="_blank">OSVDB</a><br />
<a href="http://badzmanaois.blogspot.com/2008/09/google-chrome-inspect-element-denial-of.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">hp &#8212; insight_control_suite_for_linux</td>
<td style="text-align: left;" width="45%">Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2677&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2677">CVE-2009-2677</a><br />
<a href="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" target="_blank">HP</a><br />
<a href="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" target="_blank">HP</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">hyperstop &#8212; web_host_directory</td>
<td style="text-align: left;" width="45%">HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7008&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7008">CVE-2008-7008</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45241" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31249" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/31922" target="_blank">SECUNIA</a><br />
<a href="http://packetstorm.linuxsecurity.com/0809-exploits/webhost-database.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/48282" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ibm &#8212; db2</td>
<td style="text-align: left;" width="45%">Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2858&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2858">CVE-2009-2858</a><br />
<a href="http://www-01.ibm.com/support/docview.wss?uid=swg24024075" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ibm &#8212; db2</td>
<td style="text-align: left;" width="45%">IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2859&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)">4.6</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2859">CVE-2009-2859</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2293" target="_blank">VUPEN</a><br />
<a href="http://www-01.ibm.com/support/docview.wss?uid=swg24024075" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ibm &#8212; db2</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via &#8220;malicious packets.&#8221;</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2860&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2860">CVE-2009-2860</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2293" target="_blank">VUPEN</a><br />
<a href="http://www-01.ibm.com/support/docview.wss?uid=swg24024075" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by executing a shared flat binary, which triggers an access of an &#8220;uninitialized cred pointer.&#8221;</td>
<td style="text-align: center;" width="10%">2009-08-14</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2768&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)">4.9</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2768">CVE-2009-2768</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/13/1" target="_blank">MLIST</a><br />
<a href="http://thread.gmane.org/gmane.linux.hardware.blackfin.kernel.devel/1905" target="_blank">CONFIRM</a><br />
<a href="http://lkml.org/lkml/2009/6/22/91" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The do_sigaltstack function in kernel/signal.c in Linux kernel 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2847&amp;vector=(AV:L/AC:L/Au:N/C:C/I:N/A:N)">4.9</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2847">CVE-2009-2847</a><br />
<a href="https://bugzilla.redhat.com/show_bug.cgi?id=515392" target="_blank">CONFIRM</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/05/1" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/04/1" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-&gt;clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2848&amp;vector=(AV:L/AC:M/Au:N/C:N/I:N/A:C)">4.7</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2848">CVE-2009-2848</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/05/10" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/04/2" target="_blank">MLIST</a><br />
<a href="http://article.gmane.org/gmane.linux.kernel/871942" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel</td>
<td style="text-align: left;" width="45%">The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to &#8220;suspend_* sysfs attributes&#8221; and the (1) suspend_lo_store or (2) suspend_hi_store functions. NOTE: this is only a vulnerability when sysfs is writable by an attacker.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2849&amp;vector=(AV:L/AC:M/Au:N/C:N/I:N/A:C)">4.7</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2849">CVE-2009-2849</a><br />
<a href="http://xorl.wordpress.com/2009/07/21/linux-kernel-md-driver-null-pointer-dereference/" target="_blank">MISC</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/07/26/1" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/07/24/1" target="_blank">MLIST</a><br />
<a href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.2" target="_blank">CONFIRM</a><br />
<a href="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.30.y.git;a=commit;h=3c92900d9a4afb176d3de335dc0da0198660a244" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">luke_mewburn &#8212; tnftpd</td>
<td style="text-align: left;" width="45%">tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7016&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7016">CVE-2008-7016</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45534" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/31958" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/48637" target="_blank">OSVDB</a><br />
<a href="http://freshmeat.net/projects/tnftpd/?branch_id=14355&amp;release_id=285654#" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">microtik &#8212; routeros</td>
<td style="text-align: left;" width="45%">MicroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6976&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)">6.4</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6976">CVE-2008-6976</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44944" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31025" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/6366" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">nashtech &#8212; easy_php_calendar</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7018&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7018">CVE-2008-7018</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45517" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31478" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/496796" target="_blank">BUGTRAQ</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">natterchat &#8212; natterchat</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in NatterChat 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) txtUsername parameter to registerDo.asp, as invoked from register.asp, or (2) txtRoomName parameter to room_new.asp. NOTE: these issues might be resultant from XSS in SQL error messages.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7048&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7048">CVE-2008-7048</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/46768" target="_blank">XF</a><br />
<a href="http://osvdb.org/51985" target="_blank">OSVDB</a><br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2008-11/0461.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">neon &#8212; neon</td>
<td style="text-align: left;" width="45%">neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2473&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2473">CVE-2009-2473</a><br />
<a href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00945.html" target="_blank">FEDORA</a><br />
<a href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00924.html" target="_blank">FEDORA</a><br />
<a href="http://secunia.com/advisories/36371" target="_blank">SECUNIA</a><br />
<a href="http://lists.manyfish.co.uk/pipermail/neon/2009-August/001045.html" target="_blank">MLIST</a><br />
<a href="http://lists.manyfish.co.uk/pipermail/neon/2009-August/001044.html" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">neon &#8212; neon</td>
<td style="text-align: left;" width="45%">neon before 0.28.6, when OpenSSL is used, does not properly handle a &#8216;\0&#8242; character in a domain name in the subject&#8217;s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2474&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2474">CVE-2009-2474</a><br />
<a href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00945.html" target="_blank">FEDORA</a><br />
<a href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00924.html" target="_blank">FEDORA</a><br />
<a href="http://secunia.com/advisories/36371" target="_blank">SECUNIA</a><br />
<a href="http://lists.manyfish.co.uk/pipermail/neon/2009-August/001046.html" target="_blank">MLIST</a><br />
<a href="http://lists.manyfish.co.uk/pipermail/neon/2009-August/001044.html" target="_blank">MLIST</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ntop &#8212; ntop</td>
<td style="text-align: left;" width="45%">The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2732&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2732">CVE-2009-2732</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2317" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505876/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505862/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://secunia.com/advisories/36403" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">parallels &#8212; plesk</td>
<td style="text-align: left;" width="45%">Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6984&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)">5.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6984">CVE-2008-6984</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44856" target="_blank">XF</a><br />
<a href="http://www.securitytracker.com/id?1020801" target="_blank">SECTRACK</a><br />
<a href="http://www.securityfocus.com/bid/30956" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/495881" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/51652" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpadultsite &#8212; phpadultsite_cms</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6979&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6979">CVE-2008-6979</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44923" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/31057" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496069/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.davidsopas.com/2008/09/phpadult-cms-exploit/" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/31793" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/47943" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpadultsite &#8212; phpadultsite_cms</td>
<td style="text-align: left;" width="45%">index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6981&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6981">CVE-2008-6981</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44924" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496069/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.davidsopas.com/2008/09/phpadult-cms-exploit/" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpauction &#8212; phpauction</td>
<td style="text-align: left;" width="45%">phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6999&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6999">CVE-2008-6999</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/44936" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/31803" target="_blank">SECUNIA</a><br />
<a href="http://packetstorm.linuxsecurity.com/0809-exploits/phpauction32-rfi.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/47939" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; world&#8217;s_tallest_buildings</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World&#8217;s Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2884&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2884">CVE-2009-2884</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51871" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56122" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35935" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/tallestbuildings-sql.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; president_bios</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2887&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2887">CVE-2009-2887</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51871" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35935" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/presidentbios-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; hangman</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2889&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2889">CVE-2009-2889</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51883" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56074" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35888" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/tophangman-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpscriptsnow &#8212; riddles</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2890&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2890">CVE-2009-2890</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51874" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56124" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35932" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/riddledepot-sqlxss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpversion &#8212; php_vx_guestbook</td>
<td style="text-align: left;" width="45%">Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7006&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7006">CVE-2008-7006</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45150" target="_blank">XF</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">reputation &#8212; reputation</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.</td>
<td style="text-align: center;" width="10%">2009-08-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2787&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2787">CVE-2009-2787</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52138" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9315" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/36020" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/punbbrep-lfi.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56613" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ryan.mcgeary &#8212; wp-syntax</td>
<td style="text-align: left;" width="45%">WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2852&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2852">CVE-2009-2852</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52457" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/36040" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9431" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sap &#8212; netweaver</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2932&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2932">CVE-2009-2932</a><br />
<a href="https://service.sap.com/sap/support/notes/1322098" target="_blank">MISC</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52429" target="_blank">XF</a><br />
<a href="http://www.securitytracker.com/id?1022731" target="_blank">SECTRACK</a><br />
<a href="http://www.securityfocus.com/bid/36034" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505697/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.dsecrg.com/pages/vul/show.php?id=133" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/36228" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/57000" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">simple_machines &#8212; phpraider</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7035&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7035">CVE-2008-7035</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/40849" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/27976" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">squid-cache &#8212; squid</td>
<td style="text-align: left;" width="45%">The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2855&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2855">CVE-2009-2855</a><br />
<a href="http://www.squid-cache.org/bugs/show_bug.cgi?id=2704" target="_blank">MISC</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/04/6" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/08/03/3" target="_blank">MLIST</a><br />
<a href="http://www.openwall.com/lists/oss-security/2009/07/20/10" target="_blank">MLIST</a><br />
<a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=31;filename=diff;att=1;bug=534982" target="_blank">MISC</a><br />
<a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534982" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sun &#8212; opensolaris<br />
sun &#8212; solaris</td>
<td style="text-align: left;" width="45%">The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2857&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)">4.9</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2857">CVE-2009-2857</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-257848-1" target="_blank">SUNALERT</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-127721-02-1" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sun &#8212; opensolaris<br />
sun &#8212; solaris</td>
<td style="text-align: left;" width="45%">The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2912&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)">4.9</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2912">CVE-2009-2912</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-258588-1" target="_blank">SUNALERT</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-127721-02-1" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">tgs-cms &#8212; tgs_content_management</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2928&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2928">CVE-2009-2928</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/52481" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9434" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wordpress &#8212; wordpress</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2851&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2851">CVE-2009-2851</a><br />
<a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wordpress &#8212; wordpress</td>
<td style="text-align: left;" width="45%">Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2854&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)">6.4</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2854">CVE-2009-2854</a><br />
<a href="http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">xzeroscripts &#8212; xzero_community_classifieds</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.</td>
<td style="text-align: center;" width="10%">2009-08-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2893&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2893">CVE-2009-2893</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2010" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35809" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35996" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/xzero-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">xzeroscripts &#8212; xzero_community_classifieds</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2913&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2913">CVE-2009-2913</a><br />
<a href="http://secunia.com/advisories/35996" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">xzeroscripts &#8212; xzero_community_classifieds</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2914&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2914">CVE-2009-2914</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2010" target="_blank">VUPEN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">zen-cart &#8212; zen_cart<br />
zen_cart &#8212; zen_cart</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6985&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6985">CVE-2008-6985</a><br />
<a href="http://www.zen-cart.com/forum/showthread.php?p=604473" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/bid/31023" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496032/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496002/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/48346" target="_blank">OSVDB</a><br />
<a href="http://www.gulftech.org/?node=research&amp;article_id=00129-09042008" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/31758" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">zen-cart &#8212; zen_cart</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the products_id array parameter in a multiple_products_add_product action, a different vulnerability than CVE-2008-6985.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6986&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6986">CVE-2008-6986</a><br />
<a href="http://www.zen-cart.com/forum/showthread.php?p=604473" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/bid/31023" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496032/100/100/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/496002/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.osvdb.org/48347" target="_blank">OSVDB</a><br />
<a href="http://www.gulftech.org/?node=research&amp;article_id=00129-09042008" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/31758" target="_blank">SECUNIA</a></td>
</tr>
</tbody>
<tfoot>
<tr>
<td colspan="5"><a href="http://www.systechsolutions.info/blog/wp-admin/#top">Back to top</a></td>
</tr>
</tfoot>
</table>
</div>
<p><a name="low"></a></p>
<div id="low_v">
<table border="1" align="center" summary="Low Vulnerabilities">
<thead>
<tr>
<th id="low_v_title" colspan="5" scope="col">Low Vulnerabilities</th>
</tr>
<tr>
<th style="width: 20%;" scope="col">Primary<br />
Vendor &#8212; Product</th>
<th style="width: 45%;" scope="col">Description</th>
<th style="width: 10%;" scope="col">Published</th>
<th style="width: 5%;" scope="col">CVSS Score</th>
<th style="width: 10%;" scope="col">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; flex</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1879&amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)">2.6</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1879">CVE-2009-1879</a><br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-13.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">boonex &#8212; orca</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2919&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)">3.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2919">CVE-2009-2919</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/48434" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/33545" target="_blank">BID</a><br />
<a href="http://securityreason.com/exploitalert/5644" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ca &#8212; internet_security_suite</td>
<td style="text-align: left;" width="45%">vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.</td>
<td style="text-align: center;" width="10%">2009-08-19</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-0682&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:P)">2.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0682">CVE-2009-0682</a><br />
<a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214673" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505880/100/0/threaded" target="_blank">BUGTRAQ</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cisco &#8212; ios_xr</td>
<td style="text-align: left;" width="45%">Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1154&amp;vector=(AV:N/AC:L/Au:M/C:N/I:N/A:P)">3.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1154">CVE-2009-1154</a><br />
<a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml" target="_blank">CISCO</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">cisco &#8212; ios_xr</td>
<td style="text-align: left;" width="45%">Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2056&amp;vector=(AV:N/AC:L/Au:M/C:N/I:N/A:P)">3.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2056">CVE-2009-2056</a><br />
<a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml" target="_blank">CISCO</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mcafee &#8212; safeboot_device_encryption</td>
<td style="text-align: left;" width="45%">McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-7020&amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)">2.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7020">CVE-2008-7020</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/45275" target="_blank">XF</a><br />
<a href="http://www.ivizsecurity.com/security-advisory-iviz-sr-08010.html" target="_blank">MISC</a><br />
<a href="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf" target="_blank">MISC</a><br />
<a href="http://secunia.com/advisories/31903" target="_blank">SECUNIA</a><br />
<a href="http://seclists.org/fulldisclosure/2008/Sep/0378.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sun &#8212; virtual_desktop_infrastructure</td>
<td style="text-align: left;" width="45%">Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client&#8217;s attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.</td>
<td style="text-align: center;" width="10%">2009-08-18</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2856&amp;vector=(AV:N/AC:M/Au:S/C:P/I:N/A:N)">3.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2856">CVE-2009-2856</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2282" target="_blank">VUPEN</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-265488-1" target="_blank">SUNALERT</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-02-1" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">thegreenbow &#8212; thegreenbow_vpn_client</td>
<td style="text-align: left;" width="45%">The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0&#215;80000034 IOCTL, probably involving an input or output buffer size of 0.</td>
<td style="text-align: center;" width="10%">2009-08-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2918&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:P)">2.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2918">CVE-2009-2918</a><br />
<a href="https://www.evilfingers.com/advisory/Advisory/TheGreenBow_VPN_Client_tgbvpn.sys_DoS.php" target="_blank">MISC</a><br />
<a href="http://www.vupen.com/english/advisories/2009/2294" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505816/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://secunia.com/advisories/36332" target="_blank">SECUNIA</a></td>
</tr>
</tbody>
<tfoot>
<tr>
<td colspan="5"><a href="http://www.systechsolutions.info/blog/wp-admin/#top">Back to top</a></td>
</tr>
</tfoot>
</table>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/08/vulnerability-summary-for-the-week-of-august-17-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Cyber Security Tip ST04-007 &#8212; Reducing Spam</title>
		<link>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-tip-st04-007-reducing-spam/</link>
		<comments>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-tip-st04-007-reducing-spam/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 22:43:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=903</guid>
		<description><![CDATA[The latest US-Cert Cyber Security Tip came today, it&#8217;s an introduction to spam for those who are new to email, and the associated security issues:

Cyber Security Tip ST04-007
                                Reducing Spam
 
   Spam is a common, and often frustrating, side effect to having an email
   account. Although you will probably not be able to eliminate it, there [...]]]></description>
			<content:encoded><![CDATA[<p>The latest US-Cert Cyber Security Tip came today, it&#8217;s an introduction to spam for those who are new to email, and the associated security issues:</p>
<blockquote>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Cyber Security Tip ST04-007</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">                                </span>Reducing Spam</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Spam is a common, and often frustrating, side effect to having an email</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>account. Although you will probably not be able to eliminate it, there are</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>ways to reduce it.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">What is spam?</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Spam is the electronic version of &#8220;junk mail.&#8221; The term spam refers to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>unsolicited, often unwanted, email messages. Spam does not necessarily</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>contain virusesâ€”valid messages from legitimate sources could fall into this</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>category.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">How can you reduce the amount of spam?</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>There are some steps you can take to significantly reduce the amount of spam</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>you receive:</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Don&#8217;t give your email address out arbitrarily &#8211; Email addresses have</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>become so common that a space for them is often included on any form</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>that asks for your addressâ€”even comment cards at restaurants. It seems</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>harmless,<span style="mso-spacerun: yes;">  </span>so many people write them in the space provided without</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>realizing what could happen to that information. For example, companies</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>often enter the addresses into a database so that they can keep track of</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>their customers and the customers&#8217; preferences. Sometimes these lists</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>are<span style="mso-spacerun: yes;">  </span>sold<span style="mso-spacerun: yes;">  </span>to or shared with other companies, and suddenly you are</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>receiving email that you didn&#8217;t request.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Check privacy policies &#8211; Before submitting your email address online,</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>look for a privacy policy. Most reputable sites will have a link to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>their privacy policy from any form where you&#8217;re asked to submit personal</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>data. You should read this policy before submitting your email address</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>or any other personal information so that you know what the owners of</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>the site plan to do with the information (see Protecting Your Privacy</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>for more information).</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Be aware of options selected by default &#8211; When you sign up for some</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>online accounts or services, there may be a section that provides you</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>with the option to receive email about other products and services.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Sometimes<span style="mso-spacerun: yes;">  </span>there are options selected by default, so if you do not</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>deselect them, you could begin to receive email from lists those lists</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>as well.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Use filters &#8211; Many email programs offer filtering capabilities that</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>allow<span style="mso-spacerun: yes;">  </span>you<span style="mso-spacerun: yes;">  </span>to block certain addresses or to only allow email from</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>addresses<span style="mso-spacerun: yes;">  </span>on your contact list. Some ISPs offer spam &#8220;tagging&#8221; or</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>filtering services, but legitimate messages misclassified as spam might</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>be dropped before reaching your inbox. However, many ISPs that offer</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>filtering services also provide options for tagging suspected spam</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>messages so the end user can more easily identify them. This can be</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>useful in conjunction with filtering capabilities provided by many email</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>programs.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Report messages as spam &#8211; Most email clients offer an option to report a</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">    </span><span style="mso-spacerun: yes;">   </span>message as spam or junk. If your has that option, take advantage of it.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Reporting messages as spam or junk helps to train the mail filter so</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>that the messages aren&#8217;t delivered to your inbox. However, check your</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>junk or spam folders occasionally to look for legitimate messages that</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>were incorrectly classified as spam.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Don&#8217;t follow links in spam messages &#8211; Some spam relies on generators</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>that try variations of email addresses at certain domains. If you click</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>a link within an email message or reply to a certain address, you are</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>just confirming that your email address is valid. Unwanted messages that</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>offer an &#8220;unsubscribe&#8221; option are particularly tempting, but this is</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>often just a method for collecting valid addresses that are then sent</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>other spam.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Disable<span style="mso-spacerun: yes;">  </span>the automatic downloading of graphics in HTML mail &#8211; Many</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>spammers send HTML mail with a linked graphic file that is then used to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>track who opens the mail messageâ€”when your mail client downloads the</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>graphic from their web server, they know you&#8217;ve opened the message.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Disabling HTML mail entirely and viewing messages in plain text also</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>prevents this problem.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Consider opening an additional email account &#8211; Many domains offer free</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>email accounts. If you frequently submit your email address (for online</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>shopping, signing up for services, or including it on something like a</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>comment card), you may want to have a secondary email account to protect</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>your primary email account from any spam that could be generated. You</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>could also use this secondary account when posting to public mailing</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>lists, social networking sites, blogs, and web forums. If the account</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>start to fill up with spam, you can get rid of it and open a different</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>one.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Use privacy settings on social networking sites &#8211; Social networking</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>sites typically allow you to choose who has access to see your email</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>address. Consider hiding your email account or changing the settings so</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>that only a small group of people that you trust are able to see your</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>address (see Staying Safe on Social Network Sites for more information).</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Also, when you use applications on these sites, you may be granting</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>permission for them to access your personal information. Be cautious</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>about which applications you choose to use.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Don&#8217;t spam other people &#8211; Be a responsible and considerate user. Some</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>people consider email forwards a type of spam, so be selective with the</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>messages you redistribute. Don&#8217;t forward every message to everyone in</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>your address book, and if someone asks that you not forward messages to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>them, respect their request.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>_________________________________________________________________</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Authors: Mindi McDowell, Allen Householder</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>_________________________________________________________________</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Produced 2004 by US-CERT, a government organization.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">  </span><span style="mso-spacerun: yes;">   </span>Last updated July 29, 2009</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Note: This tip was previously published and is being re-distributed to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>increase awareness.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Terms of use</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>http//www.us-cert.gov/legal.html</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>This document can also be found at</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>http//www.us-cert.gov/cas/tips/ST04-007.html</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p> </p></blockquote>
<blockquote><p> </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-tip-st04-007-reducing-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Cyber Security Bulletin SB09-208 &#8212; Vulnerability Summary for the Week of July 20, 2009</title>
		<link>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-bulletin-sb09-208-vulnerability-summary-for-the-week-of-july-20-2009/</link>
		<comments>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-bulletin-sb09-208-vulnerability-summary-for-the-week-of-july-20-2009/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 14:25:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=887</guid>
		<description><![CDATA[I received another monthly report from NIST and posted both the update, and the full vulnerability listing below:
Vulnerability Summary for the Week of July 20, 2009
 
This bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) the week of July 20, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small; font-family: Consolas;">I received another monthly report from NIST and posted both the update, and the full vulnerability listing below:</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Vulnerability Summary for the Week of July 20, 2009</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">This bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) the week of July 20, 2009. It is available here:</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Consolas;">    </span></span><a href="http://www.us-cert.gov/cas/bulletins/SB09-208.html"><span style="font-size: small; font-family: Consolas;">http://www.us-cert.gov/cas/bulletins/SB09-208.html</span></a></p>
<p><span class="cas_title">National Cyber Alert System</span><br />
<span class="cas_alert_info">Cyber Security Bulletin SB09-208</span> <span id="cas_archiveLink"><a title="Current Activity Archive" href="http://www.systechsolutions.info/cas/bulletins/index.html"><img src="http://www.systechsolutions.info/images/archive.gif" border="0" alt="archive" /></a></span></p>
<div id="cas_copy">
<h2>Vulnerability Summary for the Week of July 20, 2009</h2>
<p><a name="top"></a></p>
<table border="0" align="center">
<tbody>
<tr>
<td>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the <a href="http://nvd.nist.gov/">NVD</a>, which contains historical vulnerability information.The vulnerabilities are based on the <a href="http://cve.mitre.org/">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#high">High</a></strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</li>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#medium">Medium</a></strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</li>
<li><strong><a href="http://www.systechsolutions.info/blog/wp-admin/#low">Low</a></strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</td>
</tr>
</tbody>
</table>
<p><a name="high"></a></p>
<div id="high_v">
<table class="vul_tables" border="1" align="center" summary="High Vulnerabilities">
<thead>
<tr>
<th id="high_v_title" class="titles" colspan="5" scope="col">High Vulnerabilities</th>
</tr>
<tr>
<th class="headers" style="width: 20%;" scope="col">Primary<br />
Vendor &#8212; Product</th>
<th class="headers" style="width: 45%;" scope="col">Description</th>
<th class="headers" style="width: 10%;" scope="col">Published</th>
<th class="headers" style="width: 5%;" scope="col">CVSS Score</th>
<th class="headers" style="width: 10%;" scope="col">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;" width="20%">activewebsoftwares &#8212; active_web_mail</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6873&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6873">CVE-2008-6873</a><br />
<a href="http://www.vupen.com/english/advisories/2008/3303" target="_blank">VUPEN</a><br />
<a href="http://www.milw0rm.com/exploits/7288" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adminnewstools &#8212; admin_news_tools</td>
<td style="text-align: left;" width="45%">system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2558&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2558">CVE-2009-2558</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51780" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9161" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35842" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; acrobat_reader<br />
nos_microsystems &#8212; getplus_download_manager</td>
<td style="text-align: left;" width="45%">NOS Microsystems getPlus Download Manager for Adobe 1.6.2.36, and possibly other versions, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2564&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2564">CVE-2009-2564</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1969" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35740" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505095/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9199" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35930" target="_blank">SECUNIA</a><br />
<a href="http://retrogod.altervista.org/9sg_adobe_local.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; acrobat<br />
adobe &#8212; acrobat_reader<br />
adobe &#8212; flash_player</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2 and Adobe Flash Player 9 and 10 allows remote attackers to execute arbitrary code via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, as exploited in the wild in July 2009.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2580&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2580">CVE-2009-2580</a><br />
<a href="http://www.kb.cert.org/vuls/id/259425" target="_blank">CERT-VN</a><br />
<a href="http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability" target="_blank">MISC</a><br />
<a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99" target="_blank">MISC</a><br />
<a href="http://www.securityfocus.com/bid/35759" target="_blank">BID</a><br />
<a href="http://news.cnet.com/8301-27080_3-10293389-245.html" target="_blank">MISC</a><br />
<a href="http://isc.sans.org/diary.html?storyid=6847" target="_blank">MISC</a><br />
<a href="http://bugs.adobe.com/jira/browse/FP-1265" target="_blank">MISC</a><br />
<a href="http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">adobe &#8212; acrobat<br />
adobe &#8212; acrobat_reader<br />
adobe &#8212; flash_player</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1862&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1862">CVE-2009-1862</a><br />
<a href="http://www.kb.cert.org/vuls/id/259425" target="_blank">CERT-VN</a><br />
<a href="http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability" target="_blank">MISC</a><br />
<a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99" target="_blank">MISC</a><br />
<a href="http://www.securityfocus.com/bid/35759" target="_blank">BID</a><br />
<a href="http://news.cnet.com/8301-27080_3-10293389-245.html" target="_blank">MISC</a><br />
<a href="http://isc.sans.org/diary.html?storyid=6847" target="_blank">MISC</a><br />
<a href="http://bugs.adobe.com/jira/browse/FP-1265" target="_blank">MISC</a><br />
<a href="http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aigo &#8212; aigo_md_p8860</td>
<td style="text-align: left;" width="45%">The Aigo P8860 allows remote attackers to cause a denial of service (memory consumption and browser hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2539&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2539">CVE-2009-2539</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">akamai_technologies &#8212; download_manager</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2582&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2582">CVE-2009-2582</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1985" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35778" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505187/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=813" target="_blank">IDEFENSE</a><br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0351.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">almondsoft &#8212; almond_classifieds</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2567&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2567">CVE-2009-2567</a><br />
<a href="http://www.securityfocus.com/bid/34843" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/8619" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aspsiteware &#8212; autodealer</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6874&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6874">CVE-2008-6874</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/47365" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/32812" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/7463" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/23572" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bistudio &#8212; arma<br />
bistudio &#8212; arma_2</td>
<td style="text-align: left;" width="45%">Format string vulnerability in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) nickname and (2) datafile fields in a join request, which is not properly handled when logging an error message.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2548&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2548">CVE-2009-2548</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1951" target="_blank">VUPEN</a><br />
<a href="http://aluigi.altervista.org/adv/armazzofs-adv.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">censura &#8212; censura</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2593&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2593">CVE-2009-2593</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51663" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35637" target="_blank">BID</a><br />
<a href="http://www.osvdb.org/55790" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/9129" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35787" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome<br />
google &#8212; v8</td>
<td style="text-align: left;" width="45%">Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2555&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2555">CVE-2009-2555</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51801" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1924" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35722" target="_blank">BID</a><br />
<a href="http://www.osvdb.org/55939" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35844" target="_blank">SECUNIA</a><br />
<a href="http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.html" target="_blank">CONFIRM</a><br />
<a href="http://codereview.chromium.org/141042/diff/6/1004" target="_blank">CONFIRM</a><br />
<a href="http://codereview.chromium.org/141042" target="_blank">CONFIRM</a><br />
<a href="http://code.google.com/p/chromium/issues/detail?id=14719" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2556&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2556">CVE-2009-2556</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51802" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1924" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35723" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35844" target="_blank">SECUNIA</a><br />
<a href="http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">humayun_shabbir_bhutta &#8212; asp_product_catalog</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6875&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6875">CVE-2008-6875</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/36894" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2007/3345" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/25884" target="_blank">BID</a><br />
<a href="http://osvdb.org/51976" target="_blank">OSVDB</a><br />
<a href="http://marc.info/?l=bugtraq&amp;m=122901307932738&amp;w=2" target="_blank">BUGTRAQ</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ibm &#8212; proventia_desktop_endpoint_security<br />
ibm &#8212; proventia_network_mail_security_system<br />
ibm &#8212; proventia_network_mail_security_system_vitual_appliance<br />
ibm &#8212; proventia_network_multi-function_security</td>
<td style="text-align: left;" width="45%">Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass detection of malware via a modified (1) ZIP or (2) CAB archive, a related issue to CVE-2009-1240.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2543&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2543">CVE-2009-2543</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504995/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504992/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504987/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">linux &#8212; kernel<br />
linux &#8212; linux_kernel</td>
<td style="text-align: left;" width="45%">Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2584&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2584">CVE-2009-2584</a><br />
<a href="http://xorl.wordpress.com/2009/07/21/linux-kernel-sgi-gru-driver-off-by-one-overwrite/" target="_blank">MISC</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51887" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35753" target="_blank">BID</a><br />
<a href="http://lkml.org/lkml/2009/7/20/362" target="_blank">MLIST</a><br />
<a href="http://lkml.org/lkml/2009/7/20/348" target="_blank">MLIST</a><br />
<a href="http://grsecurity.net/~spender/exploit_demo.c" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mlffat &#8212; mlffat</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2585&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2585">CVE-2009-2585</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51623" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/55826" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/9091" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35728" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2462&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2462">CVE-2009-2462</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://www.mozilla.org/security/announce/2009/mfsa2009-34.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">Integer overflow in a base64 decoding function in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2463&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2463">CVE-2009-2463</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; seamonkey<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2464&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2464">CVE-2009-2464</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://www.mozilla.org/security/announce/2009/mfsa2009-34.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2465&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2465">CVE-2009-2465</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://www.mozilla.org/security/announce/2009/mfsa2009-34.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2466&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2466">CVE-2009-2466</a><br />
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=493281" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35944" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox</td>
<td style="text-align: left;" width="45%">Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2467&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2467">CVE-2009-2467</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35944" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox</td>
<td style="text-align: left;" width="45%">Integer overflow in CoreGraphics in Apple Mac OS X, as used in Mozilla Firefox before 3.0.12, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2468&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2468">CVE-2009-2468</a><br />
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=480134" target="_blank">CONFIRM</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://www.mozilla.org/security/announce/2009/mfsa2009-36.html" target="_blank">CONFIRM</a><br />
<a href="http://secunia.com/advisories/35914" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox</td>
<td style="text-align: left;" width="45%">Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2469&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2469">CVE-2009-2469</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox</td>
<td style="text-align: left;" width="45%">The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2471&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2471">CVE-2009-2471</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35944" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">nokia &#8212; n810_internet_tablet<br />
nokia &#8212; n82<br />
nokia &#8212; symbian</td>
<td style="text-align: left;" width="45%">The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2538&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)">7.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2538">CVE-2009-2538</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ondanera.net &#8212; hamster_audio_player</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl playlist file.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2550&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2550">CVE-2009-2550</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51732" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9172" target="_blank">MILW0RM</a><br />
<a href="http://www.milw0rm.com/exploits/9157" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35825" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/55871" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">phpjunkyard &#8212; gbook</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in guestbook.php in PHPJunkYard GBook 1.6 allows remote attackers to execute arbitrary SQL commands via the mes_id parameter.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2592&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2592">CVE-2009-2592</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51827" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9197" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">pulseaudio &#8212; pulseaudio</td>
<td style="text-align: left;" width="45%">Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.</td>
<td style="text-align: center;" width="10%">2009-07-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1894&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)">7.2</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1894">CVE-2009-1894</a><br />
<a href="https://bugzilla.redhat.com/show_bug.cgi?id=510071" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/bid/35721" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">resalecode &#8212; hutscripts_php_website_script</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2590&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2590">CVE-2009-2590</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51913" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1978" target="_blank">VUPEN</a><br />
<a href="http://secunia.com/advisories/35893" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/hutscript-sqlxss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56175" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">rim &#8212; blackberry_8800</td>
<td style="text-align: left;" width="45%">The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption and browser crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2575&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)">7.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2575">CVE-2009-2575</a><br />
<a href="http://lists.grok.org.uk/pipermail/full-disclosure/2009-July/069772.html" target="_blank">FULLDISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">runcms &#8212; myannonces</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2591&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)">7.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2591">CVE-2009-2591</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51852" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35744" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9217" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sony &#8212; playstation_3</td>
<td style="text-align: left;" width="45%">The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2541&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)">7.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2541">CVE-2009-2541</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">sorinara &#8212; streaming_audio_player</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2568&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2568">CVE-2009-2568</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/50339" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/34842" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/8620" target="_blank">MILW0RM</a><br />
<a href="http://www.milw0rm.com/exploits/8617" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">symantec &#8212; winfax_pro</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2570&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)">10.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2570">CVE-2009-2570</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1221" target="_blank">VUPEN</a><br />
<a href="http://www.securitytracker.com/id?1022147" target="_blank">SECTRACK</a><br />
<a href="http://www.securityfocus.com/bid/34766" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/503163/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/503086/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/503074/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://secunia.com/advisories/34925" target="_blank">SECUNIA</a><br />
<a href="http://retrogod.altervista.org/9sg_symantec_win_fuck_pro.html" target="_blank">MISC</a><br />
<a href="http://osvdb.org/54137" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">tfm &#8212; mmplayer</td>
<td style="text-align: left;" width="45%">Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2566&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)">9.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2566">CVE-2009-2566</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51442" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9047" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35605" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wireshark &#8212; wireshark</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2563&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)">7.1</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2563">CVE-2009-2563</a><br />
<a href="http://www.wireshark.org/security/wnpa-sec-2009-04.html" target="_blank">CONFIRM</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1970" target="_blank">VUPEN</a></td>
</tr>
</tbody>
<tfoot>
<tr>
<td colspan="5"><a href="http://www.systechsolutions.info/blog/wp-admin/#top">Back to top</a></td>
</tr>
</tfoot>
</table>
</div>
<p><a name="medium"></a></p>
<div id="medium_v">
<table class="vul_tables" border="1" align="center" summary="Medium Vulnerabilities">
<thead>
<tr>
<th id="medium_v_title" class="titles" colspan="5" scope="col">Medium Vulnerabilities</th>
</tr>
<tr>
<th class="headers" style="width: 20%;" scope="col">Primary<br />
Vendor &#8212; Product</th>
<th class="headers" style="width: 45%;" scope="col">Description</th>
<th class="headers" style="width: 10%;" scope="col">Published</th>
<th class="headers" style="width: 5%;" scope="col">CVSS Score</th>
<th class="headers" style="width: 10%;" scope="col">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;" width="20%">adminnewstools &#8212; admin_news_tools</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2557&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2557">CVE-2009-2557</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504949/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9153" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35842" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/55856" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">anelectron &#8212; advanced_electron_forum</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2545&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2545">CVE-2009-2545</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51775" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35646" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/55925" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">anelectron &#8212; advanced_electron_forum</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2546&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2546">CVE-2009-2546</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51776" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35646" target="_blank">SECUNIA</a><br />
<a href="http://osvdb.org/55926" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">aspthai.net &#8212; aspthai_forums</td>
<td style="text-align: left;" width="45%">ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6872&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6872">CVE-2008-6872</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/46960" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2008/3301" target="_blank">VUPEN</a><br />
<a href="http://www.osvdb.org/50329" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/7292" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/32912" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bioscripts &#8212; minitwitter</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2573&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:P)">6.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2573">CVE-2009-2573</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/50282" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/34795" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/503155/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/8586" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bioscripts &#8212; minitwitter</td>
<td style="text-align: left;" width="45%">index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2574&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)">6.5</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2574">CVE-2009-2574</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/50283" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/34795" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/503157/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/8587" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bistudio &#8212; arma<br />
bistudio &#8212; arma_2</td>
<td style="text-align: left;" width="45%">Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) via a VoIP over Network (VON) packet to port 2305 with a negative packet_size value, which triggers a buffer over-read.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2547&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2547">CVE-2009-2547</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51820" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1951" target="_blank">VUPEN</a><br />
<a href="http://secunia.com/advisories/35900" target="_blank">SECUNIA</a><br />
<a href="http://aluigi.altervista.org/adv/armadioz-adv.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">bistudio &#8212; arma<br />
bistudio &#8212; arma_2</td>
<td style="text-align: left;" width="45%">Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service via a join packet with a final field whose value is (1) 0, which triggers a server crash related to memory allocation, or (2) 1, which triggers CPU/memory consumption and a NULL pointer dereference.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2549&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2549">CVE-2009-2549</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1951" target="_blank">VUPEN</a><br />
<a href="http://aluigi.altervista.org/adv/armazzo-adv.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">censura &#8212; censura</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2594&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2594">CVE-2009-2594</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51664" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35637" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9129" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35787" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">censura &#8212; censura</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2595&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2595">CVE-2009-2595</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51665" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/55791" target="_blank">OSVDB</a><br />
<a href="http://www.censura.info/forums/showthread.php?t=969" target="_blank">CONFIRM</a><br />
<a href="http://www.censura.info/forums/project.php?issueid=151" target="_blank">CONFIRM</a><br />
<a href="http://secunia.com/advisories/35795" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">dragdropcart &#8212; dragdropcart</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect parameter to login.php, and the (6) product parameter to productdetail.php.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2587&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2587">CVE-2009-2587</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51877" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/56071" target="_blank">OSVDB</a><br />
<a href="http://www.osvdb.org/56070" target="_blank">OSVDB</a><br />
<a href="http://www.osvdb.org/56069" target="_blank">OSVDB</a><br />
<a href="http://www.osvdb.org/56067" target="_blank">OSVDB</a><br />
<a href="http://www.osvdb.org/56066" target="_blank">OSVDB</a><br />
<a href="http://www.osvdb.org/56065" target="_blank">OSVDB</a><br />
<a href="http://secunia.com/advisories/35925" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/dragdopcart-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">edgephp &#8212; ezarticles</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2586&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2586">CVE-2009-2586</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51858" target="_blank">XF</a><br />
<a href="http://secunia.com/advisories/35924" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/ezarticles-xss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56002" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">editeurscripts &#8212; esbaseadmin</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in default/login.php in EditeurScripts EsBaseAdmin 2.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6868&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6868">CVE-2008-6868</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/49237" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/34112" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/34284" target="_blank">SECUNIA</a><br />
<a href="http://packetstorm.linuxsecurity.com/0903-exploits/editeurscripts-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">editeurscripts &#8212; esnews</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2581&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2581">CVE-2009-2581</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/49237" target="_blank">XF</a><br />
<a href="http://packetstorm.linuxsecurity.com/0903-exploits/editeurscripts-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">editeurscripts &#8212; espartenaires</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6876&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6876">CVE-2008-6876</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/49237" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/34112" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/34284" target="_blank">SECUNIA</a><br />
<a href="http://packetstorm.linuxsecurity.com/0903-exploits/editeurscripts-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">google &#8212; chrome</td>
<td style="text-align: left;" width="45%">Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2578&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2578">CVE-2009-2578</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505092/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://websecurity.com.ua/3338/" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">ibm &#8212; tivoli_identity_manager</td>
<td style="text-align: left;" width="45%">Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2583&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2583">CVE-2009-2583</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1990" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35779" target="_blank">BID</a><br />
<a href="http://www-01.ibm.com/support/docview.wss?uid=swg24023826" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">isc &#8212; dhcp</td>
<td style="text-align: left;" width="45%">dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.</td>
<td style="text-align: center;" width="10%">2009-07-17</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-1892&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1892">CVE-2009-1892</a><br />
<a href="http://www.securityfocus.com/bid/35669" target="_blank">BID</a><br />
<a href="http://www.debian.org/security/2009/dsa-1833" target="_blank">DEBIAN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">kde &#8212; konqueror</td>
<td style="text-align: left;" width="45%">KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2537&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2537">CVE-2009-2537</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">lullabot &#8212; fivestar_module_for_drupal</td>
<td style="text-align: left;" width="45%">Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2572&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2572">CVE-2009-2572</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1215" target="_blank">VUPEN</a><br />
<a href="http://drupal.org/node/449042" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">marcelo_costa &#8212; fileserver</td>
<td style="text-align: left;" width="45%">Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2544&amp;vector=(AV:N/AC:L/Au:S/C:C/I:N/A:N)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2544">CVE-2009-2544</a><br />
<a href="http://www.milw0rm.com/exploits/9093" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">merlix &#8212; educate_server</td>
<td style="text-align: left;" width="45%">Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6870&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6870">CVE-2008-6870</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/47107" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/7348" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">merlix &#8212; educate_server</td>
<td style="text-align: left;" width="45%">Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6871&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6871">CVE-2008-6871</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/47108" target="_blank">XF</a><br />
<a href="http://www.osvdb.org/50524" target="_blank">OSVDB</a><br />
<a href="http://www.milw0rm.com/exploits/7348" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/33018" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">microsoft &#8212; internet_explorer</td>
<td style="text-align: left;" width="45%">Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2536&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2536">CVE-2009-2536</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">microsoft &#8212; ie</td>
<td style="text-align: left;" width="45%">Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2576&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2576">CVE-2009-2576</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505122/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505120/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505092/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://websecurity.com.ua/3338/" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox<br />
mozilla &#8212; seamonkey<br />
mozilla &#8212; thunderbird</td>
<td style="text-align: left;" width="45%">Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2535&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2535">CVE-2009-2535</a><br />
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=460713" target="_blank">MISC</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">mozilla &#8212; firefox</td>
<td style="text-align: left;" width="45%">Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a &#8220;cross origin wrapper bypass.&#8221;</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2472&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2472">CVE-2009-2472</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1972" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35758" target="_blank">BID</a><br />
<a href="http://www.mozilla.org/security/announce/2009/mfsa2009-40.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">netscape &#8212; navigator</td>
<td style="text-align: left;" width="45%">Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2542&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2542">CVE-2009-2542</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">olle_johansson &#8212; jobline</td>
<td style="text-align: left;" width="45%">SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in a results action to index.php, which invokes the search method from the searchJobPostings function in jobline.php.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2554&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2554">CVE-2009-2554</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51811" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35728" target="_blank">BID</a><br />
<a href="http://www.milw0rm.com/exploits/9187" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35877" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">opera &#8212; opera_browser</td>
<td style="text-align: left;" width="45%">Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2540&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2540">CVE-2009-2540</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9160" target="_blank">MILW0RM</a><br />
<a href="http://www.g-sec.lu/one-bug-to-rule-them-all.html" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">opera &#8212; opera_browser</td>
<td style="text-align: left;" width="45%">Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application hang) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2577&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2577">CVE-2009-2577</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505092/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://websecurity.com.ua/3338/" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">oramon &#8212; oramon</td>
<td style="text-align: left;" width="45%">Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini.</td>
<td style="text-align: center;" width="10%">2009-07-23</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2008-6869&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6869">CVE-2008-6869</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/46967" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2008/3305" target="_blank">VUPEN</a><br />
<a href="http://www.milw0rm.com/exploits/7286" target="_blank">MILW0RM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">realnetworks &#8212; helix_server<br />
realnetworks &#8212; helix_server_mobile</td>
<td style="text-align: left;" width="45%">rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2533&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2533">CVE-2009-2533</a><br />
<a href="http://www.securityfocus.com/bid/35731" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505083/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9198" target="_blank">MILW0RM</a><br />
<a href="http://www.coresecurity.com/content/real-helix-dna" target="_blank">MISC</a><br />
<a href="http://docs.real.com/docs/security/SecurityUpdate071409HS.pdf" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">realnetworks &#8212; helix_server<br />
realnetworks &#8212; helix_server_mobile</td>
<td style="text-align: left;" width="45%">RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2534&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2534">CVE-2009-2534</a><br />
<a href="http://www.securityfocus.com/bid/35732" target="_blank">BID</a><br />
<a href="http://www.securityfocus.com/archive/1/archive/1/505083/100/0/threaded" target="_blank">BUGTRAQ</a><br />
<a href="http://www.milw0rm.com/exploits/9198" target="_blank">MILW0RM</a><br />
<a href="http://www.coresecurity.com/content/real-helix-dna" target="_blank">MISC</a><br />
<a href="http://docs.real.com/docs/security/SecurityUpdate071409HS.pdf" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">resalecode &#8212; hotscripts_type_php_clone_script</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2588&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2588">CVE-2009-2588</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51911" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1979" target="_blank">VUPEN</a><br />
<a href="http://secunia.com/advisories/35892" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/hotscriptsclone-xss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56169" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56168" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56167" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">resalecode &#8212; hutscripts_php_website_script</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.</td>
<td style="text-align: center;" width="10%">2009-07-24</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2589&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2589">CVE-2009-2589</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51912" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1978" target="_blank">VUPEN</a><br />
<a href="http://secunia.com/advisories/35893" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/hutscript-sqlxss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/56172" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56171" target="_blank">OSVDB</a><br />
<a href="http://osvdb.org/56170" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">scriptsez &#8212; easy_image_downloader</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2551&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2551">CVE-2009-2551</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51722" target="_blank">XF</a><br />
<a href="http://www.securityfocus.com/bid/35701" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/35838" target="_blank">SECUNIA</a><br />
<a href="http://packetstormsecurity.org/0907-exploits/eid-xss.txt" target="_blank">MISC</a><br />
<a href="http://osvdb.org/55862" target="_blank">OSVDB</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">supersimple &#8212; super_simple_blog_script</td>
<td style="text-align: left;" width="45%">Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2552&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2552">CVE-2009-2552</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51805" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9179" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35859" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">supersimple &#8212; super_simple_blog_script</td>
<td style="text-align: left;" width="45%">Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the entry parameter.</td>
<td style="text-align: center;" width="10%">2009-07-20</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2553&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)">6.8</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2553">CVE-2009-2553</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51806" target="_blank">XF</a><br />
<a href="http://www.milw0rm.com/exploits/9180" target="_blank">MILW0RM</a><br />
<a href="http://secunia.com/advisories/35859" target="_blank">SECUNIA</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">t-okada &#8212; shiromuku(fs6)diary</td>
<td style="text-align: left;" width="45%">Cross-site scripting (XSS) vulnerability in Perl CGI&#8217;s By Mrs. Shiromuku shiromuku(fs6)DIARY 2.40 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2565&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2565">CVE-2009-2565</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/51696" target="_blank">XF</a><br />
<a href="http://www.t-okada.com/cgi-bin/s_news/s_news.cgi?action=show_detail&amp;txtnumber=log&amp;mynum=345" target="_blank">CONFIRM</a><br />
<a href="http://secunia.com/advisories/35806" target="_blank">SECUNIA</a><br />
<a href="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000048.html" target="_blank">JVNDB</a><br />
<a href="http://jvn.jp/en/jp/JVN31110006/index.html" target="_blank">JVN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">verliadmin &#8212; verliadmin</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2571&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2571">CVE-2009-2571</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/50347" target="_blank">XF</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1265" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/34845" target="_blank">BID</a><br />
<a href="http://packetstormsecurity.org/0905-exploits/verliadmin-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">verlihub-project &#8212; verlihub_control_panel</td>
<td style="text-align: left;" width="45%">Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.</td>
<td style="text-align: center;" width="10%">2009-07-22</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2569&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)">4.3</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2569">CVE-2009-2569</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1264" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/34856" target="_blank">BID</a><br />
<a href="http://secunia.com/advisories/34941" target="_blank">SECUNIA</a><br />
<a href="http://packetstorm.linuxsecurity.com/0905-exploits/verlihub-xss.txt" target="_blank">MISC</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wireshark &#8212; wireshark</td>
<td style="text-align: left;" width="45%">Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2559&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2559">CVE-2009-2559</a><br />
<a href="http://www.wireshark.org/security/wnpa-sec-2009-04.html" target="_blank">CONFIRM</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1970" target="_blank">VUPEN</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wireshark &#8212; wireshark</td>
<td style="text-align: left;" width="45%">Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (crash) via unspecified vectors in the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissectors.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2560&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2560">CVE-2009-2560</a><br />
<a href="http://www.wireshark.org/security/wnpa-sec-2009-04.html" target="_blank">CONFIRM</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wireshark &#8212; wireshark</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2561&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2561">CVE-2009-2561</a><br />
<a href="http://www.wireshark.org/security/wnpa-sec-2009-04.html" target="_blank">CONFIRM</a><br />
<a href="http://www.vupen.com/english/advisories/2009/1970" target="_blank">VUPEN</a><br />
<a href="http://www.securityfocus.com/bid/35748" target="_blank">BID</a></td>
</tr>
<tr>
<td style="text-align: left;" width="20%">wireshark &#8212; wireshark</td>
<td style="text-align: left;" width="45%">Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.</td>
<td style="text-align: center;" width="10%">2009-07-21</td>
<td style="width: 5%; text-align: center;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-2562&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)">5.0</a></td>
<td width="10%"><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2562">CVE-2009-2562</a><br />
<a href="http://www.wireshark.org/security/wnpa-sec-2009-04.html" target="_blank">CONFIRM</a><br />
<a href="http://www.securityfocus.com/bid/35748" target="_blank">BID</a></td>
</tr>
</tbody>
</table>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/07/us-cert-cyber-security-bulletin-sb09-208-vulnerability-summary-for-the-week-of-july-20-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Current Activity &#8211; Cisco Releases Security Advisory for Vulnerabilities in Cisco Wireless LAN Controllers</title>
		<link>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-cisco-releases-security-advisory-for-vulnerabilities-in-cisco-wireless-lan-controllers/</link>
		<comments>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-cisco-releases-security-advisory-for-vulnerabilities-in-cisco-wireless-lan-controllers/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 14:14:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=884</guid>
		<description><![CDATA[Cisco releases notice of wireless lan controller exploits:

US-CERT Current Activity
 
Cisco Releases Security Advisory for Vulnerabilities in Cisco Wireless LAN Controllers
 
Original release date: July 27, 2009 at 2:59 pm Last revised: July 27, 2009 at 2:59 pm
 
 
Cisco has released a security advisory to address multiple vulnerabilities in Wireless LAN Controllers. The advisory addresses the following:
  * [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco releases notice of wireless lan controller exploits:</p>
<blockquote>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT Current Activity</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Cisco Releases Security Advisory for Vulnerabilities in Cisco Wireless LAN Controllers</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Original release date: July 27, 2009 at 2:59 pm Last revised: July 27, 2009 at 2:59 pm</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Cisco has released a security advisory to address multiple vulnerabilities in Wireless LAN Controllers. The advisory addresses the following:</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">  </span>* Malformed HTTP or HTTPS authentication response denial-of-service</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">    </span>vulnerability.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">  </span>* SSH connections denial-of-service vulnerability.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">  </span>* Crafted HTTP or HTTPS request denial-of-service vulnerability.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">  </span>* Crafted HTTP or HTTPS request unauthorized configuration</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">    </span>modification vulnerability.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Exploitation of these vulnerabilities may allow an attacker to cause a denial-of-service condition or gain full control over the Wireless LAN Controller.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT encourages users and administrators to review Cisco Security Advisory cisco-sa-20090727-wlc and apply any necessary updates or workarounds to help mitigate the risks.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Relevant Url(s):</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">&lt;</span><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml</span></a><span style="font-size: small; font-family: Consolas;">&gt;</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">====</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">This entry is available at</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><a href="http://www.us-cert.gov/current/index.html#cisco_releases_security_advisory_for11"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.us-cert.gov/current/index.html#cisco_releases_security_advisory_for11</span></a></p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-cisco-releases-security-advisory-for-vulnerabilities-in-cisco-wireless-lan-controllers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Current Activity &#8211; Microsoft Releases Advance Notification for July Security Bulletin</title>
		<link>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-microsoft-releases-advance-notification-for-july-security-bulletin/</link>
		<comments>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-microsoft-releases-advance-notification-for-july-security-bulletin/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 20:04:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=882</guid>
		<description><![CDATA[I got the following notification regarding the Microsoft July Security Bulletin:

US-CERT Current Activity
 
Microsoft Releases Advance Notification for July Security Bulletin
 
Original release date: July 9, 2009 at 1:58 pm Last revised: July 9, 2009 at 1:58 pm
 
 
Microsoft has issued a Security Bulletin Advance Notification indicating that the July release cycle will contain six bulletins, three of [...]]]></description>
			<content:encoded><![CDATA[<p>I got the following notification regarding the Microsoft July Security Bulletin:</p>
<blockquote>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT Current Activity</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Microsoft Releases Advance Notification for July Security Bulletin</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Original release date: July 9, 2009 at 1:58 pm Last revised: July 9, 2009 at 1:58 pm</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Microsoft has issued a Security Bulletin Advance Notification indicating that the July release cycle will contain six bulletins, three of which will have a severity rating of critical. The notification states that these critical bulletins are for Microsoft Windows. There will also be three important bulletins for Microsoft Office, Virtual PC and Virtual Server, and ISA Server. Release of these bulletins is scheduled for Tuesday, July 14.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT will provide additional information as it becomes available.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Relevant Url(s):</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">&lt;</span><a href="http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx</span></a><span style="font-size: small; font-family: Consolas;">&gt;</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">====</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">This entry is available at</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><a href="http://www.us-cert.gov/current/index.html#microsoft_releases_advance_notification_for23"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.us-cert.gov/current/index.html#microsoft_releases_advance_notification_for23</span></a></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/07/us-cert-current-activity-microsoft-releases-advance-notification-for-july-security-bulletin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US-CERT Current Activity &#8211; Apple Releases iPhone OS 3.0</title>
		<link>http://www.systechsolutions.info/blog/2009/06/us-cert-current-activity-apple-releases-iphone-os-30/</link>
		<comments>http://www.systechsolutions.info/blog/2009/06/us-cert-current-activity-apple-releases-iphone-os-30/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 14:02:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=870</guid>
		<description><![CDATA[US-CERT Current Activity
 
Apple Releases iPhone OS 3.0
 
Original release date: June 18, 2009 at 8:09 am Last revised: June 18, 2009 at 8:09 am
 
 
Apple has released iPhone OS 3.0 to address multiple vulnerabilities across many packages. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, bypass [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT Current Activity</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Apple Releases iPhone OS 3.0</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Original release date: June 18, 2009 at 8:09 am Last revised: June 18, 2009 at 8:09 am</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Apple has released iPhone OS 3.0 to address multiple vulnerabilities across many packages. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, bypass security restrictions, or conduct cross-site scripting attacks.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT encourages users to review Apple article HT3639 and upgrade to iPhone OS 3.0 to help mitigate the risks.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Relevant Url(s):</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">&lt;</span><a href="http://support.apple.com/kb/HT3639"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://support.apple.com/kb/HT3639</span></a><span style="font-size: small; font-family: Consolas;">&gt;</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">====</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">This entry is available at</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><a href="http://www.us-cert.gov/current/index.html#apple_releases_iphone_os_3"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.us-cert.gov/current/index.html#apple_releases_iphone_os_3</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/06/us-cert-current-activity-apple-releases-iphone-os-30/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>US-CERT Cyber Security Tip ST04-004 &#8212; Understanding Firewalls</title>
		<link>http://www.systechsolutions.info/blog/2009/06/us-cert-cyber-security-tip-st04-004-understanding-firewalls/</link>
		<comments>http://www.systechsolutions.info/blog/2009/06/us-cert-cyber-security-tip-st04-004-understanding-firewalls/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 20:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/blog/?p=854</guid>
		<description><![CDATA[Cyber Security Tip ST04-004
                          Understanding Firewalls
 
   When anyone or anything can access your computer at any time, your computer
   is more susceptible to being attacked. You can restrict outside access to
   your computer and the information on it with a firewall.
 
What do firewalls do?
 
   Firewalls provide protection against outside attackers by shielding your
   computer  or  [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Cyber Security Tip ST04-004</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">                          </span>Understanding Firewalls</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>When anyone or anything can access your computer at any time, your computer</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>is more susceptible to being attacked. You can restrict outside access to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>your computer and the information on it with a firewall.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">What do firewalls do?</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Firewalls provide protection against outside attackers by shielding your</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>computer<span style="mso-spacerun: yes;">  </span>or<span style="mso-spacerun: yes;">  </span>network<span style="mso-spacerun: yes;">  </span>from malicious or unnecessary Internet traffic.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Firewalls can be configured to block data from certain locations while</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>allowing<span style="mso-spacerun: yes;">  </span>the<span style="mso-spacerun: yes;">  </span>relevant<span style="mso-spacerun: yes;">  </span>and necessary data through (see Understanding</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Denial-of-Service Attacks and Understanding Hidden Threats: Rootkits and</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Botnets for more information). They are especially important for users who</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>rely on &#8220;always on&#8221; connections such as cable or DSL modems.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">What type of firewall is best?</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Firewalls<span style="mso-spacerun: yes;">  </span>are<span style="mso-spacerun: yes;">  </span>offered in two forms: hardware (external) and software</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>(internal). While both have their advantages and disadvantages, the decision</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>to use a firewall is far more important than deciding which type you use.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Hardware &#8211; Typically called network firewalls, these external devices</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>are positioned between your computer or network and your cable or DSL</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>modem. Many vendors and some Internet service providers (ISPs) offer</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>devices<span style="mso-spacerun: yes;">  </span>called<span style="mso-spacerun: yes;">  </span>&#8220;routers&#8221;<span style="mso-spacerun: yes;">  </span>that<span style="mso-spacerun: yes;">  </span>also<span style="mso-spacerun: yes;">  </span>include firewall features.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Hardware-based firewalls are particularly useful for protecting multiple</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>computers<span style="mso-spacerun: yes;">  </span>but also offer a high degree of protection for a single</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>computer. If you only have one computer behind the firewall, or if you</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>are certain that all of the other computers on the network are up to</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>date on patches and are free from viruses, worms, or other malicious</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>code, you may not need the extra protection of a software firewall.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>Hardware-based firewalls have the advantage of being separate devices</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>running their own operating systems, so they provide an additional line</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>of defense against attacks. Their major drawback is cost, but many</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>products are available for less than $100 (and there are even some for</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>less than $50).</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>* Software &#8211; Some operating systems include a built-in firewall; if yours</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>does, consider enabling it to add another layer of protection even if</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>you have an external firewall. If you don&#8217;t have a built-in firewall,</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>you can obtain a software firewall for relatively little or no cost from</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>your local computer store, software vendors, or ISP. Because of the</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>risks associated with downloading software from the Internet onto an</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>unprotected computer, it is best to install the firewall from a CD or</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>DVD. If you do download software from the Internet, make sure it is a</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>reputable, secure website (see Understanding Web Site Certificates for</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>more information). Although relying on a software firewall alone does</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>provide some protection, realize that having the firewall on the same</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>computer as the information you&#8217;re trying to protect may hinder the</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">       </span>firewall&#8217;s ability to catch malicious traffic before it enters your</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;">      </span>system.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">How do you know what configuration settings to apply?</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Most<span style="mso-spacerun: yes;">  </span>commercially<span style="mso-spacerun: yes;">  </span>available<span style="mso-spacerun: yes;">  </span>firewall<span style="mso-spacerun: yes;">  </span>products,<span style="mso-spacerun: yes;">  </span>both hardware- and</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>software-based, come configured in a manner that is acceptably secure for</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>most<span style="mso-spacerun: yes;">  </span>users. Since each firewall is different, you&#8217;ll need to read and</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>understand the documentation that comes with it to determine whether or not</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>the<span style="mso-spacerun: yes;">  </span>default<span style="mso-spacerun: yes;">  </span>settings on your firewall are sufficient for your needs.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Additional assistance may be available from your firewall vendor or your ISP</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>(either from tech support or a website). Also, alerts about current viruses</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>or<span style="mso-spacerun: yes;">  </span>worms<span style="mso-spacerun: yes;">  </span>(such as US-CERT&#8217;s Cyber Security Alerts) sometimes include</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>information about restrictions you can implement through your firewall.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Unfortunately, while properly configured firewalls may be effective at</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>blocking some attacks, don&#8217;t be lulled into a false sense of security.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>Although they do offer a certain amount of protection, firewalls do not</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>guarantee that your computer will not be attacked. In particular, a firewall</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>offers little to no protection against viruses that work by having you run</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>the infected program on your computer, as many email-borne viruses do.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>However, using a firewall in conjunction with other protective measures</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>(such as anti-virus software and &#8220;safe&#8221; computing practices) will strengthen</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>your resistance to attacks (see Understanding Anti-Virus Software and other</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">   </span>security tips for more information).</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>_________________________________________________________________</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Both the National Cyber Security Alliance and US-CERT have identified this</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>topic as one of the top tips for home users.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>_________________________________________________________________</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Authors: Mindi McDowell, Allen Householder</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>_________________________________________________________________</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Produced 2004 by US-CERT, a government organization.</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Note: This tip was previously published and is being re-distributed </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>to increase awareness. </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Consolas;">  </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>Terms of use</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Consolas;"> </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>&lt;</span></span><a href="http://www.us-cert.gov/legal.html"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.us-cert.gov/legal.html</span></a><span style="font-size: small; font-family: Consolas;">&gt;</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Consolas;">  </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>This document can also be found at</span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Consolas;"> </span></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="mso-spacerun: yes;">     </span>&lt;</span></span><a href="http://www.us-cert.gov/cas/tips/ST04-004.html"><span style="font-size: small; color: #0000ff; font-family: Consolas;">http://www.us-cert.gov/cas/tips/ST04-004.html</span></a><span style="font-size: small; font-family: Consolas;">&gt;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/06/us-cert-cyber-security-tip-st04-004-understanding-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
