Current Activity Calendar
| June 04, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.HP Instant Support ActiveX Control Vulnerabilitiesadded June 4, 2008 at 02:37 pm
HP has released a support document to address multiple vulnerabilities in the Instant Support ActiveX control (HPISDataManager.dll). These vulnerabilities may allow a remote attacker to execute arbitrary code. Sun Releases Java ASP Server 4.0.3added June 4, 2008 at 02:12 pm
Sun has released Java ASP Server 4.0.3 to address multiple vulnerabilities. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the root user or the user running the Sun Java ASP server, obtain sensitive information, or bypass security restrictions. United States Tax Court Phishing Attackadded May 15, 2008 at 03:15 pm | updated June 4, 2008 at 01:10 pm
US-CERT is aware of public reports of a phishing attack circulating via email messages that claim to be petitions from the US Tax Court. These messages appear to be legitimate because they may contain very specific information about the message recipient. The message requests that the user follow a link to download additional information or documents. If a user clicks on this link, the website attempts to use JavaScript to install a bogus root certificate that is supposedly issued by "VeriSign Trust Network." The user will normally receive several warnings when the JavaScript code attempts to install the certificate.
Microsoft Releases Security Advisoryadded June 2, 2008 at 11:47 am
Microsoft has released Security Advisory 953818 to address reports of a blended threat that affects Windows users who have installed Apple's Safari web browser. According to the advisory, by convincing a user to visit a specially crafted website, an attacker may be able to execute arbitrary code on an affected system due to Safari's default file downloading behavior and the way that Windows Internet Explorer handles the downloaded files. VMware Releases Security Advisoryadded June 2, 2008 at 09:46 am
VMware has released a security advisory indicating that updates are available for VMware Workstation, VMware Player, VMware ACE, and VMware Fusion. These updates address multiple vulnerabilities that may allow an attacker to execute arbitrary code in the context of the "vmx" process on the host system or to bypass security restrictions. Samba Releases Version 3.0.30added May 29, 2008 at 09:26 am
Samba has released version 3.0.30 to address a vulnerability. This vulnerability is due to a heap-based buffer overflow condition in the receive_smb_raw() routine. By sending a specially crafted SMB response, an attacker may be able to execute arbitrary code on the affected system. Apple Releases Security Updatesadded May 29, 2008 at 07:43 am
Apple has released Mac OS X v10.5.3 and Security Update 2008-003 to address multiple vulnerabilities. These vulnerabilities affect a number of applications, libraries and the kernel. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, access the system with escalated privileges, obtain sensitive information, conduct cross-site scripting attacks or cause a denial-of-service condition. Adobe Flash Player Vulnerabilityadded May 27, 2008 at 06:44 pm | updated May 28, 2008 at 06:03 pm
US-CERT is aware of public reports of active exploitation of a vulnerability in Adobe Flash Player. By convincing a user to open a specially crafted Flash file, which may be embedded in a compromised website, a remote, unauthenticated attacker may be able to execute arbitrary code.
Cisco Releases Security Advisoryadded May 28, 2008 at 01:24 pm
Cisco has released a Security Advisory to address a vulnerability in CiscoWorks Common Services. This vulnerability may allow a remote attacker to execute arbitrary code. IBM Lotus Sametime Vulnerabilityadded May 22, 2008 at 10:23 am
IBM has released a Technote to address a vulnerability in Lotus Sametime. This vulnerability is due to an error in the way long URLs are processed within the Community Services Multiplexer (StMux.exe). By sending a specially crafted URL, an attacker may be able to cause a stack-based buffer overflow and execute arbitrary code. |
||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
