Current Activity Calendar
| October 03, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
Axis IP Camera Vulnerabilitiesadded October 3, 2007 at 03:13 pm
US-CERT is aware of several publicly reported cross-site scripting and cross-site request forgery vulnerabilities in Axis IP cameras. Currently, these vulnerabilities have not been confirmed by US-CERT.
Google's Gmail XSRF Vulnerabilityadded October 2, 2007 at 09:10 am | updated October 2, 2007 at 09:11 am
US-CERT is aware of a publicly reported cross-site request forgery vulnerability in Google's Gmail. A cross-site request forgery vulnerability may allow a request from an attacker to be interpreted as originating from an authenticated user. Public reports indicate that this vulnerability may allow an attacker to create arbitrary filters for a user's Gmail account. Apple Releases Update for iPhoneadded September 27, 2007 at 03:29 pm
Apple has released an update to address several vulnerabilities in the iPhone. These vulnerabilities may allow an attacker to execute arbitrary code or commands, cause a denial-of-service condition, or conduct cross-site scripting attacks on an affected device. CA BrightStor Hierarchical Storage Manager Vulnerabilitiesadded September 27, 2007 at 09:55 am
US-CERT is aware of several vulnerabilities that affect the CA BrightStor Hierarchical Storage Manager version r11.5. These vulnerabilities may allow an attacker to execute arbitrary code or gain control of the system. Cisco Products Loopback Vulnerabilityadded September 27, 2007 at 09:25 am
Cisco has released a Security Response regarding a vulnerability in the way that Cisco Catalyst 6500 and Cisco 7600 series devices use addresses from the loopback range. Cisco reports that an attacker can exploit this to bypass access control lists. CA ARCserve Backup for Laptops and Desktops contains multiple vulnerabilitiesadded September 24, 2007 at 03:02 pm
US-CERT is aware of several vulnerabilities that affect the CA ARCserve Backup for Laptops and Desktops product. These vulnerabilities may allow an attacker to execute arbitrary code, bypass authentication, or cause a denial-of-service condition. Google Search Appliance Vulnerabilityadded September 24, 2007 at 12:28 pm
US-CERT is aware of a publicly reported cross-site scripting (XSS) vulnerability in Google's search appliance. Cross-site scripting vulnerabilities may allow a remote, unauthenticated attacker to inject malicious script into a web page. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
