BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks


BuyLow.com | Resources | Contact Us


 

Apple Safari And Firefox

Apple has released Safari 4.0.3 for Windows and Mac OS X to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof a website.
The Mozilla Foundation has released Firefox 3.0.13 and Firefox 3.5.2 to address multiple vulnerabilities. These vulnerabilities may allow an [...]

Read More About - Apple Safari And Firefox »

Apple Safari Vulnerabilities

Apple has released Safari 4.0 for Windows and Mac OS X to address multiple vulnerabilities in CFNetwork, CoreGraphics, ImageIO, International Components for Unicode, libxml, Safari, Safari Windows Installer, and WebKit. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, bypass security restrictions, or conduct cross-site scripting [...]

Read More About - Apple Safari Vulnerabilities »

Alert: Apple iTunes

Apple Releases iTunes 8.2 and QuickTime 7.6.2
Apple has released iTunes 8.2 and QuickTime 7.6.2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
US-CERT encourages users to review Apple articles HT3592 and HT3591 and apply any necessary updates to help mitigate the risks.
Available for: Mac [...]

Read More About - Alert: Apple iTunes »

Mac OS X and Java Alert

Mac OS X Includes Known Vulnerable Version of Java
Current releases of Mac OS X (version 10.5.7 and version 10.4.11 with security update 2009-002) include a version of Java Runtime Environment (JRE) containing known security vulnerabilities. US-CERT is aware of publicly available exploit code for one of these vulnerabilities. This vulnerability may allow untrusted applets to [...]

Read More About - Mac OS X and Java Alert »

Apple QuickTime Updates for Multiple Vulnerabilities

National Cyber Alert System
Technical Cyber Security Alert TA09-022A
Apple QuickTime Updates for Multiple Vulnerabilities
Original release date: January 22, 2009
Source: US-CERT
Systems Affected
Apple QuickTime 7.5 for Windows and Mac OS X
Overview
Apple has released QuickTime 7.6 to correct multiple vulnerabilities affecting QuickTime for Mac OS X and Windows. Attackers may be able to exploit these vulnerabilities to execute arbitrary [...]

Read More About - Apple QuickTime Updates for Multiple Vulnerabilities »

RSS BugTraq

  • QuickZip 0day detailed write-up
    Posted by Security on Mar 15In case some of you missed it - I published 2 articles on the Offensive Security Blog (last one was published a few hours ago), explaining the process of building a (not so typical) SEH based exploit for a QuickZip 0day vulnerability. Part 1 : http://www.offensive-security.com/blog/vulndev/quickzip-stack-bof-0day-a-box-of-chocolat […]
  • New vulnerabilities in Abton
    Posted by MustLive on Mar 15Hello Bugtraq! I want to warn you about new vulnerabilities in Abton. It's commercial Ukrainian CMS. ----------------------------- Advisory: New vulnerabilities in Abton ----------------------------- URL: http://websecurity.com.ua/3618/ ----------------------------- Timeline: 17.02.2009 - found the vulnerabilities. 23.10.2009 […]
  • ZDI-10-029: Apple WebKit innerHTML element Substitution Remote Code Execution Vulnerability
    Posted by ZDI Disclosures on Mar 15ZDI-10-029: Apple WebKit innerHTML element Substitution Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-029 March 15, 2010 -- CVE ID: CVE-2010-0050 -- Affected Vendors: Google Apple -- Affected Products: Google Chrome Apple WebKit Apple Safari -- TippingPoint(TM) IPS Customer Protectio […]
  • Multiple DOM-Based XSS in Dojo Toolkit SDK
    Posted by labs on Mar 15=========================================================== Multiple DOM-Based XSS in Dojo Toolkit SDK Public Release Date: 3/12/2010 Adam Bixby - Gotham Digital Science (labs () gdssecurity com) Affected Software: Dojo Toolkit SDK […]
  • ZoneAlarm 9 (ForceField) Security Disclosure
    Posted by Andrew Barkley on Mar 15Hi, This disclosure pertains to ZoneAlarm 9 (ForceField). ZoneAlarm have been informed. The following discusses similar issues as was previously disclosed regarding ZoneAlarm 8. ZoneAlarm 9 (ForceField) ZoneAlarm version:9.1.007.002 TrueVector version:9.1.007.002 Driver version:9.1.007.002 Introduction The following illustra […]