Current Activity Calendar
| May 06, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
PHP 5.2.6 Releasedadded May 6, 2008 at 09:03 am
PHP has released version 5.2.6 to address multiple vulnerabilities. These vulnerabilities include
US-CERT encourages users to review the PHP 5.2.6 Release Announcement and update to version 5.2.6. Common Data Format Buffer Overflow Vulnerabilityadded May 5, 2008 at 04:04 pm
NASA has issued an advisory regarding a vulnerability in Common Data Format (CDF) version 3.2 and earlier. This vulnerability is due to a buffer overflow condition in the handling of specially-crafted CDF files. Exploitation of this vulnerability may allow an attacker to execute arbitrary code. WordPress Vulnerabilitiesadded April 28, 2008 at 01:50 pm
WordPress has released version 2.5.1 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to bypass security restrictions or conduct a cross-site scripting attack. Compromised Websites Hosting Malicious JavaScriptadded April 25, 2008 at 04:45 pm
US-CERT is following reports of SQL injection attacks that have compromised a large number of legitimate websites. The compromised websites contain injected JavaScript that attempts to exploit multiple, known vulnerabilities. Users who visit a compromised website may unknowingly execute malicious code.
US-CERT will provide more information as it becomes available. HP Software Update Vulnerabilitiesadded April 25, 2008 at 10:44 am
US-CERT is aware of reports of multiple vulnerabilities affecting HP Software Update. These vulnerabilities are due to insecure methods in multiple ActiveX controls. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code or view or modify sensitive information.
IRS Rebate Phishing Scamadded April 24, 2008 at 09:31 am
US-CERT is aware of a public report indicating that a phishing scam is circulating. This scam is related to the U.S. Internal Revenue Service economic stimulus rebate and arrives via email messages that appear to be from the IRS. The messages include text that attempts to convince users to follow a link to a website before a deadline to expedite the rebate process. This website requests that the user provide bank account information.
Apple QuickTime Vulnerability Reportadded April 23, 2008 at 06:33 pm
US-CERT is aware of a public report of a new vulnerability in Apple QuickTime. The report indicates that if a user opens a specially crafted QuickTime file, an attacker may be able to execute arbitrary code. This vulnerability may have several attack vectors, such as visiting a malicious or compromised website. US-CERT is currently investigating this report and will provide additional details as needed. ICQ Vulnerabilityadded April 22, 2008 at 01:10 pm
US-CERT is aware of public reports of a vulnerability in ICQ 6. This vulnerability is due to a heap buffer overflow condition in the "Personal Status Manager" feature that occurs when processing specially crafted status messages. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. Microsoft Releases Security Advisory (951306)added April 18, 2008 at 01:30 pm
Microsoft has released a Security Advisory to address a vulnerability in Windows. This vulnerability may allow an authenticated attacker to execute code with LocalSystem privileges. Apple Releases Safari 3.1.1added April 17, 2008 at 08:57 am
Apple has released Safari 3.1.1 to address multiple vulnerabilities in Safari and WebKit. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct cross-site scripting attacks, or spoof the contents of the browser address bar. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
