Friday, September 5, 2008

F-Secure Internet Security 2009 - PC Magazine

F-Secure Internet Security 2009 - PC Magazine

Oracle WebLogic Server Apache Connector Remote Code Execution
Oracle WebLogic Server (formerly known as BEA WebLogic Server) is vulnerable to a buffer overflow, which would cause a denial of service and potentially remote code execution.

Microsoft Dynamics GP Multiple (4) Buffer Overflows
The Microsoft Dynamics GP is vulnerable to four heap and stack-based buffer overflows. A remote attacker could overflow the buffer and execute arbitrary code or gain control of the affected system by sending malicious queries to the Distributed Process Server or Distributed Process Manager.

Do-It-Yourself Security Suites for Free
There are a variety of threats attempting to compromise your computer and it takes a variety of tools to protect against them. Many vendors sell security suites, but many people...

Breaking Down Blog Spam Malware
Jesper Johansson, co-author of Windows Vista Security: Securing Vista Against Malicious Attacks, recently wrote an article in The Register which dissects a new type of threat. Anyone with a blog...

ID Theft Protection Not Worth It
Back in April I wrote a blog post where I stated that in my opinion nothing in the world of digital data is unbreakable or impenetrable and that LifeLock, an...

IE8 Works to Prevent Cross-Site Scripting Attacks
One of the most prevalent threats for Web surfers is the cross-site scripting attack. With cross-site scripting, an attacker is able to insert malicious code into otherwise legitimate web pages....

Multiple Vendors Vulnerable to DNS Cache Poisoning
Multiple vendor DNS protocol implementations could allow a remote attacker to poison the DNS cache.  Patches that resolve the vulnerability on the DNS may be rendered ineffective if the DNS is behind a NAT device that does not randomize ports. Public exploit code was made available on July 24, 2008.  At the time of this update, neither X-Force nor IBM MSS has witness any active exploitation nor the integration of this exploit into any exploit toolkits.

Microsoft Windows DirectX SAMI Code Execution
Microsoft Windows DirectX could allow a remote attacker to execute arbitrary code on the system.

No comments: