BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks

 

Widespread P2P Data Breaches

The Federal Trade Commission has notified almost 100 organizations that personal information, including sensitive data about customers and/or employees, has been shared from the organizations’ computer networks and is available on peer-to-peer (P2P) file-sharing networks to any users of those networks, who could use it to commit identity theft or fraud. The agency also has [...]

Read More About - Widespread P2P Data Breaches »

Microsoft Security Bulletin

Microsoft has released an update to address vulnerabilities in Microsoft Windows, Office, and Internet Explorer as part of the Microsoft Security Bulletin Summary for June 2009. These vulnerabilities may allow an attacker to execute arbitrary code, operate with elevated privileges, or obtain sensitive information.

Read More About - Microsoft Security Bulletin »

Apple Safari Vulnerabilities

Apple has released Safari 4.0 for Windows and Mac OS X to address multiple vulnerabilities in CFNetwork, CoreGraphics, ImageIO, International Components for Unicode, libxml, Safari, Safari Windows Installer, and WebKit. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, bypass security restrictions, or conduct cross-site scripting [...]

Read More About - Apple Safari Vulnerabilities »

Apple QuickTime Updates for Multiple Vulnerabilities

National Cyber Alert System
Technical Cyber Security Alert TA09-022A
Apple QuickTime Updates for Multiple Vulnerabilities
Original release date: January 22, 2009
Source: US-CERT
Systems Affected
Apple QuickTime 7.5 for Windows and Mac OS X
Overview
Apple has released QuickTime 7.6 to correct multiple vulnerabilities affecting QuickTime for Mac OS X and Windows. Attackers may be able to exploit these vulnerabilities to execute arbitrary [...]

Read More About - Apple QuickTime Updates for Multiple Vulnerabilities »

Microsoft Windows Does Not Disable AutoRun Properly

National Cyber Alert System
Technical Cyber Security Alert TA09-020A
Microsoft Windows Does Not Disable AutoRun Properly
Source: US-CERT
Systems Affected
Microsoft Windows
Overview
Disabling AutoRun on Microsoft Windows systems can help prevent the spread of malicious code. However, Microsoft’s guidelines for disabling AutoRun are not fully effective, which could be considered a vulnerability.
I. Description
Microsoft Windows includes an AutoRun feature, which can automatically [...]

Read More About - Microsoft Windows Does Not Disable AutoRun Properly »

Oracle National Cyber Alert System

Oracle Updates for Multiple Vulnerabilities
Original release date: January 15, 2009
Source: US-CERT
Overview
Oracle products and components are affected by multiple vulnerabilities. The impacts of these vulnerabilities include remote execution of arbitrary code, information disclosure, and denial of service.
I. Description
The Oracle Critical Patch Update – January 2009 addresses 41 vulnerabilities in different Oracle products and components. The document [...]

Read More About - Oracle National Cyber Alert System »

RSS BugTraq

  • ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnerability
    Posted by ZDI Disclosures on Mar 12ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-027 March 11, 2010 -- Affected Vendors: Skype -- Affected Products: Skype -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against t […]
  • ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability
    Posted by ZDI Disclosures on Mar 12ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-028 March 11, 2010 -- Affected Vendors: Skype -- Affected Products: Skype -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against this vulnerability by Dig […]
  • [SECURITY] [DSA 2012-1] New Linux 2.6.26 packages fix several issues
    Posted by dann frazier on Mar 12---------------------------------------------------------------------- Debian Security Advisory DSA-2012-1 security () debian org http://www.debian.org/security/ dann frazier March 11, 2010 http://www.debian.org/security/faq ---------------------------------------------------------------------- Package : linux-2.6 Vulnerabilit […]
  • VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability
    Posted by VUPEN Security Research on Mar 12VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND --------------------- "Safari is a web browser developed by Apple. As of February 2010, Safari was the fourth most widely used browser, with 4.45% of the worldwide usag […]
  • [XSS] I found a xss in phpmyadmin 3.3.0 when we create new database in interface!
    Posted by lis cker on Mar 12there is a xss in phpmyadmin 3.3.0 when we create new database in interface, the "new_db" parameter do not filter characters when users enter. attacker can enter malicious code, like "alert(/liscker/);". it also can be true in post and get. but in post, we can not encode xss code, or , the xss will faild. For e […]