Welcome Guest. | Log In| Register | Membership Benefits

All Security News Feeds

SocialShield Releases the Top Social Networking Terms Kids Don't Want Their Parents To Know

    February 02, 2012

Yubico And CloudPassage Bring Easy, Secure Two-Factor Authentication To Cloud Servers

    February 02, 2012

CloudPassage Launches Network Security In The Cloud Inbox

    February 01, 2012

Vulnerabilities Reported In Mac Encryption Products

    February 01, 2012

Backupify Announces Security Best Practices, Adds Multiple Layers Of Protection To Cloud Application Data Backup

    February 01, 2012

New Survey: Two-Thirds Of Companies Interested In Switching Authentication Vendors

    January 31, 2012

Country With Most Online Fraud Attempts/How Much Fraud On Mobile Devices Revealed

    January 31, 2012

IBM Announces New Software to Manage And Secure The Influx Of Mobile Devices To The Workplace

    January 31, 2012

Baltimore-Based Security Provider Lookingglass Raises $5 Million In Funding

    January 30, 2012

Auto/Mate Launches Guard/Mate

    January 30, 2012

Wave Launches Cloud-Based Encryption Service

    January 30, 2012

Infoblox And CA Technologies Deliver Network Automation And Compliance Capabilities

    January 30, 2012

MetaFlows Announces Software-Based IDPS, Enables IDPS Hardware For 1/10 The Price

    January 30, 2012

Survey Of Security And Audit Pros, DBAs Reveals Responsibility Disconnect, Lack Of Management Commitment Impedes Database Security Efforts

    January 30, 2012

McAfee and Security & Defence Agenda Release Global Cyber Defense Report

    January 30, 2012

McAfee Announces Next Generation Of Mobile Security Software

    January 30, 2012

Vormetric Announces Record Revenues For 2011

    January 26, 2012

Symantec Reports Record Third Quarter Fiscal 2012 Results

    January 26, 2012

Mobile Marketing Association Releases Final Privacy Policy Guidelines For Mobile Apps

    January 25, 2012

Dome9 Unveils Industry First Multi-Cloud Security Groups

    January 25, 2012

Sophos Reveals Assessment On Threat Landscape In Security Threat Report 2012

    January 25, 2012

FireHost's European-Based Secure Cloud Hosting Services Go Live

    January 25, 2012

Fluke Rolls Out New Threat Signatures Released To Protect Against Wireless Attacks

    January 24, 2012

Packet Plus Introduces Interactive Networking Stack Debugger

    January 23, 2012

WatchDox Introduces Secure Annotation, Collaboration For iPad, iPhone

    January 23, 2012

BB&T Payment Solutions Offers Free Data Security Webinar For Small Business Owners

    January 23, 2012

Yubico Reports 2011 Record Growth, Outlook For 2012

    January 23, 2012

Sourcefire Rolls Out FireAMP For Blocking Advanced Malware Utilizing Big Data Analytics

    January 23, 2012

Alcatel-Lucent and Arbor Networks Team Up In The Fight Against 'Denial-Of-Service' Attacks

    January 20, 2012

NQ Mobile Launches Mobile Security V6.0 For Android

    January 20, 2012

Suits And Spooks Anti-Conference Aims to Redefine Security

    January 20, 2012

Prolexic Enhances Portal to Provide Customers With More Insight Into DDoS Threats And Mitigation

    January 20, 2012

SharePoint Users Develop Insecure Habits

    January 20, 2012

Trend Micro Marks 2011 "The Year Of Data Breaches"

    January 20, 2012

Qualys Launches New Freemium Web Security Service For SMBs

    January 20, 2012

F5 Announces Earnings For Q1 FY2012

    January 20, 2012

Avira Partners With Secure.me To Offer Facebook Protection

    January 20, 2012

Klocwork Insight 9.5 Creates New Benchmark For Developer-Friendly Source Code Analysis

    January 20, 2012

Version 8.3 Of Astaro Security Gateway Brings UTM To The Cloud

    January 20, 2012

Identropy Secures $4 Million In Series A Funding

    January 19, 2012

SITA First To Achieve PCI Security Compliance For Passenger Processing

    January 19, 2012

Metasploit Exploit Module Released For PLC SCADA Devices

    January 19, 2012

HBGary And HP Enterprise Security Partner To Deliver Advanced Threat Intelligence On The ArcSight Platform To Combat Targeted Attacks

    January 19, 2012

Webroot Engages Former Symantec Executive To Support Global Expansion Inbox

    January 19, 2012

GFI Software Enhances Dynamic Malware Analysis

    January 17, 2012

Cambridge company Launches Ultra-Secure 3rd Generation Networked SCADA System

    January 17, 2012

Facebook 'Koobface' Malware Gang Unmasked -- Sophos Releases Exclusive Research

    January 17, 2012

Symantec Announces Intelligent Information Governance To Mitigate Risks And Free Information

    January 17, 2012

Symplified Reports Major Growth In 2011

    January 13, 2012

SentryBay And NetSTAR Sign Strategic Technology Partnership

    January 12, 2012







Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)