Current Activity Calendar
| February 21, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
BEA Releases Security Advisories for Vulnerabilitiesadded February 21, 2008 at 02:51 pm
BEA has released multiple security advisories to address vulnerabilities in WebLogic, AquaLogic and Plumtree. These vulnerabilities may allow an attacker to execute arbitrary code, bypass security restrictions, elevate privileges, and obtain sensitive information. EMC RepliStor Vulnerabilitiesadded February 21, 2008 at 02:46 pm
US-CERT is aware of reports of multiple vulnerabilities affecting EMC RepliStor. Exploitation of these vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code on an affected system. Lunar Eclipse Email Attackadded February 21, 2008 at 12:56 pm
US-CERT is aware of an email attack circulating that is related to the recent lunar eclipse. The email contains a message indicating that there is a video of the lunar eclipse available and instructs users to follow a link to download the video. If a user clicks on this link, an executable file will be downloaded that contains a Trojan program. This Trojan program may allow an attacker to take control of an affected system.
Symantec Veritas Storage Foundation Updateadded February 21, 2008 at 12:55 pm
Symantec has released an update for Veritas Storage Foundation to address a vulnerability. This vulnerability is caused by packet handling errors in the Symantec VEA administrative service. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code, cause a denial-of-service condition, escalate privileges. Mozilla Firefox and Opera Vulnerabilityadded February 18, 2008 at 03:34 pm
US-CERT is aware of public reports of a vulnerability in Mozilla Firefox and Opera web browsers. This vulnerability is caused by improper handling of bitmap image files (.bmp). By sending a specially crafted bitmap image file to the browser, an attacker may be able to obtain sensitive information or cause a denial-of-service condition. Public Exploit Code for Microsoft Works Vulnerabilitiesadded February 15, 2008 at 08:37 am
US-CERT is aware of reports of publicly available exploit code for vulnerabilities in Microsoft Works 6 File Converter. By convincing a user to open a specially crafted Works file, an attacker may be able to execute arbitrary code on an affected system. This vulnerability was addressed in Microsoft Security Bulletin MS08-011. Email Attacks Circulatingadded February 14, 2008 at 03:27 pm
US-CERT is aware of reports of several email attacks circulating.
Public Exploit for Local Linux Kernel Vulnerabilityadded February 14, 2008 at 11:53 am
US-CERT has received information that public exploit information is available for a vulnerability affecting Linux kernels 2.6.17 to 2.6.24.1. These kernel versions contain a buffer overflow vulnerability in the get_user_pages function which may allow an unprivileged local attacker to gain root privileges. Adobe Flash Media Server Vulnerabilitiesadded February 14, 2008 at 09:33 am
Adobe has released Flash Media Server 2.0.5 to address multiple vulnerabilities. These vulnerabilities may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. Cisco Releases Security Advisories for Vulnerabilitiesadded February 13, 2008 at 03:17 pm
Cisco has released security advisories in response to multiple vulnerabilities.
More information will be provided as it becomes available. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
