Risk
2/28/2008
04:51 PM
Jake Widman
Jake Widman
Commentary
Connect Directly
RSS
E-Mail
50%
50%

VMware Welcomes Third-Party Security Applications

PCPro, The Register

In a move intended to improve the security of its virtualization platform, VMware has provided ways for third-party security vendors to integrate their applications into the platform.Basically, VMware has provided a set of application program interfaces (APIs) to such security companies as McAfee and Symantec. The APIs, collectively called VMsafe, give the security programs the access needed to monitor and protect the memory, CPU and disk operations, and I/O systems of virtual machines set up with the VMware hypervisor.

Upwards of 20 security companies have announced plans to producing products that will work with the APIs. One of them, McAfee, has already announced beta availability of its new Email and Web Security Virtual Appliance, "built from the ground up for the VMware platform."PCPro, The Register

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5142
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the src parameter.

CVE-2010-5302
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

CVE-2010-5303
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.

CVE-2014-0965
Published: 2014-08-21
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.

CVE-2014-3022
Published: 2014-08-21
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.