Welcome Guest. | Log In | Register | Membership Benefits

All Security News Analysis

5 Ways To Lose A Malicious Insider Lawsuit

    May 15, 2012

Cyberspies Target Victims Via 'Strategic' Driveby Website Attacks

    May 15, 2012

Number Of Software Pirates On The Rise

    May 15, 2012

Why Some SMBs Still Fear The Cloud

    May 14, 2012

Websites Select Security Services To Suppress DDoS, Other Attacks

    May 14, 2012

4 Ways To Identify The Real Threats To Your Organization

    May 14, 2012

Security Index Marks A Year Of Doing Business Dangerously

    May 11, 2012

New .secure Internet Domain On Tap

    May 10, 2012

FBI Warns Travelers Using Hotel Networks About New Attack

    May 10, 2012

Mass SQL Injections Spike Again

    May 09, 2012

Windows Gets Privacy Boost For DNS

    May 09, 2012

Targeted Attack Infiltrates At Least 20 Companies

    May 08, 2012

How To Better Measure Botnet Size

    May 08, 2012

Crypto In The Cloud Secures Data In Spite Of Providers

    May 07, 2012

10 Symptoms Of Check-Box Compliance

    May 07, 2012

IBM Profiles The New CSO, Security Exec

    May 04, 2012

5 Facebook Privacy Blind Spots

    May 04, 2012

Microsoft Fingers Chinese Firewall/IPS Vendor In Windows Exploit Leak

    May 03, 2012

6 Discoveries That Prove Mobile Malware's Mettle

    May 03, 2012

Slide Show: Security Gets Graphic

    May 03, 2012

7 Ways Oracle Puts Database Customers At Risk

    May 02, 2012

Microsoft Skype IP Leakage Not New, Report Contends

    May 02, 2012

Apple Mac Flashback Trojan Gang Still Making Money

    May 01, 2012

Picking Apart Malware In The Cloud

    April 30, 2012

Advanced Attacks Call For New Defenses

    April 30, 2012







Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)