Sunday, August 17, 2008

The future of security - Computerworld

The future of security - Computerworld

McCain Promotes Online Security, Privacy Policies - PC World

Microsoft Windows MJPEG Codec Multiple Overflows
The Microsoft MJPEG codec is vulnerable to multiple stack-based buffer overflows when parsing specially crafted files. A remote attacker could overflow the buffer and execute arbitary code within the context of the user viewing the malicious file.

What is ASLR?
Windows Vista includes a variety of security features not found in previous operating systems such as Windows XP. One of these features is ASLR. ASLR is like a shell game...

Oracle WebLogic Server Apache Connector Remote Code Execution
Oracle WebLogic Server (formerly known as BEA WebLogic Server) is vulnerable to a buffer overflow, which would cause a denial of service and potentially remote code execution.

Microsoft Windows DirectX SAMI Code Execution
Microsoft Windows DirectX could allow a remote attacker to execute arbitrary code on the system.

Security Expert Finds A Wrench In The Internet - NPR

Microsoft ActiveX Snapshot Viewer for Microsoft Access RCE
Microsoft ActiveX Snapshot Viewer for Microsoft Access could allow a remote attacker to execute arbitrary code on the system.  Targeted exploitation was reported on July 7, but X-Force has been monitoring toolkit-related mass exploitation since July 10.  As of July 24, exploitation has continued to escalate.  See technical description for more details.

Research fingers ActiveX, QuickTime as buggiest browser plug-ins - Computerworld

Microsoft Dynamics GP Multiple (4) Buffer Overflows
The Microsoft Dynamics GP is vulnerable to four heap and stack-based buffer overflows. A remote attacker could overflow the buffer and execute arbitrary code or gain control of the affected system by sending malicious queries to the Distributed Process Server or Distributed Process Manager.

No comments: