Current Activity Calendar
| October 10, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Microsoft Updates Security Bulletin MS05-004added October 10, 2007 at 01:33 pm
Microsoft has released an update to Security Bulletin MS05-004 adding Windows Server 2003 Service Pack 2 and Windows Vista to the affected software. This ASP .NET path validation vulnerability may allow a remote, unauthenticated attacker to gain access to secure website content by using a specially crafted URL. Adobe Acrobat and Adobe Reader Vulnerabilityadded October 9, 2007 at 03:31 pm
Adobe has issued a Security Advisory to address a vulnerability in Adobe Acrobat and Adobe Reader. By convincing a user to open a specially crafted pdf file in Microsoft Internet Explorer 7, an attacker may be able to execute arbitrary code. Microsoft Releases October Security Bulletinsadded October 9, 2007 at 03:15 pm
Microsoft has released updates to address
vulnerabilities in Windows, Outlook Express, Windows Mail, Internet Explorer, and Office as part of the Microsoft Security Bulletin Summary for October 2007. Microsoft Releases Advance Notification for October Security Bulletinsadded October 4, 2007 at 02:26 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its October release cycle will contain seven bulletins, of which four have a maximum severity rating of Critical. The notification further states that the bulletins are for Windows, Outlook Express, Windows Mail, Internet Explorer, and Office. The release is scheduled for Tuesday, October 9, 2007. Apple QuickTime Security Updateadded October 4, 2007 at 09:31 am
Apple has released a Security Update to address a vulnerability in QuickTime 7.2 for Microsoft Windows. This vulnerability may allow an attacker to execute applications with arbitrary command line arguments by enticing a user to open a crafted QTL file. Axis IP Camera Vulnerabilitiesadded October 3, 2007 at 03:13 pm
US-CERT is aware of several publicly reported cross-site scripting and cross-site request forgery vulnerabilities in Axis IP cameras. Currently, these vulnerabilities have not been confirmed by US-CERT.
Google's Gmail XSRF Vulnerabilityadded October 2, 2007 at 09:10 am | updated October 2, 2007 at 09:11 am
US-CERT is aware of a publicly reported cross-site request forgery vulnerability in Google's Gmail. A cross-site request forgery vulnerability may allow a request from an attacker to be interpreted as originating from an authenticated user. Public reports indicate that this vulnerability may allow an attacker to create arbitrary filters for a user's Gmail account. |
||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
