Current Activity Calendar
| August 06, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Apple Releases Update for iPhoneadded August 1, 2007 at 10:20 am
Apple has released an update to address several vulnerabilities in the iPhone. These vulnerabilities may allow an attacker to execute arbitrary code or conduct cross-site scripting attacks on an affected device. US-CERT Warns Public of Fraudulent Phishing Emailadded August 1, 2007 at 08:39 am
US-CERT is aware of a recent surge in fraudulent phishing e-mail messages. The messages, claiming to be from the United States National Medical Association, contain a subject line that reads "The United States National Medical Association" and a link that, when followed, will direct the user to a malicious website. These messages are not from any United States government agency. Mozilla Releases Update to Address URI Sanitization Vulnerabilityadded July 31, 2007 at 03:07 pm
Mozilla has released an update for the Firefox browser to address two vulnerabilities with URI sanitization. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code on an affected system.
Microsoft Windows URI Protocol Handling Vulnerabilityadded July 27, 2007 at 03:21 pm
US-CERT is aware of a vulnerability in the way Microsoft Windows determines how to handle URIs, which may be be leveraged by a remote attacker to execute arbitrary commands on an affected system. Public reports demonstrate that Mozilla Firefox can be used to pass malicious URIs to Windows, but other applications may also act as attack vectors for this vulnerability. Mozilla Firefox URI Sanitization Vulnerabilityadded July 26, 2007 at 04:21 pm | updated July 27, 2007 at 03:02 pm
US-CERT is aware of a vulnerability (VU#783400) in the way Mozilla Firefox passes URIs to registered protocol handlers in Microsoft Windows. Due to a separate vulnerability (VU#403150) in the way Windows determines how to execute URIs, Firefox could be used as an attack vector to execute arbitrary commands. Panda Antivirus Buffer Overflow Vulnerabilityadded July 26, 2007 at 01:36 pm
US-CERT is aware of a buffer overflow vulnerability in Panda Antivirus. This vulnerability may allow an attacker to execute arbitrary code on a vulnerable system by passing a crafted ".EXE" file to the Panda Antivirus file parsing engine. CA Releases Updates to Address Vulnerabilities in Several Productsadded July 26, 2007 at 01:04 pm Computer Associates has released updates to address vulnerabilities in CA Message Queuing, eTrust Intrusion Detection, and several products that implement the "Arclib" library. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition on a vulnerable system.
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
