More article whitepapers
Remote Data Replication: Combat Disasters And Optimize Business Operations
Metzler: The 2013 Application and Service Delivery Handbook
Evaluating the Performance of Shared WAN Links for Data Center Backup and Disaster Recovery
Riverbed vs Silver Peak: WAN Optimization Vendors Put to the Test
Improving SQL Availability and Performance: 6 Key Questions to Consider Before You Scale Up
Policy Control & SDN: A Perfect Match? - by Heavy Reading
Storage Infrastructure as a Service The Best of Cloud and On-premises Storage
Putting Metaswitch's SBC Software to the Test
Altair Speeds Complex Simulation and Workload Management with the Intel' Xeon Phi Coprocessor
Check Point 2013 Internet Security Report
Unified Communications Buyer's Guide
Demystifying Unified Communications
Secrets Revealed: Brilliant Simplicity and Lower TCO
Comparison of Cisco and ShoreTel Unified Communication Solutions
Comparison of Avaya and ShoreTel Unified Communication Solutions
Don't Get Stuck on Your Virtualization Journey: Where to Focus Next
How Virtualization is Key to Managing Risk
Top 10 Considerations for Getting Started with VMware Virtualization
Crash Insurance: Protect Your Business with Virtualization
Beyond Cost Savings: Four Compelling Reasons To Virtualize Your IT Environment
When It Makes Sense to Move to Desktop Virtualization: Seven Key Indicators
Top 10 Tech Tips: vSphere with Operations Management
Taneja Group: Overview of Virtualization and Cloud Market Vendor Landscape for SMBs
Real World Considerations for Implementing Desktop Virtualization eBook
Websense 2013 Threat Report
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3927
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.
CVE-2013-3647
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. NOTE: this vulnerability exists because of a CVE-2012-4009 regression.
CVE-2013-3646
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
CVE-2013-3644
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.
CVE-2013-4616 (iphone_os)
The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.



