- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: eCryptfs 'parse_tag_3_packet()' Packet Heap Based Buffer Overflow Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Search
Search Result
-
Best of Application Security (Friday, Nov. 20)
Category: Network Security & Hacking News/Latest Security News
... Reversing JavaScript Shellcode: A Step By Step How-To Brute-Forcing Compatibility Preventing Security Development Errors: Lessons Learned at Windows Live by Using ASP.NET MVC OWASP Board - Election Results ...Friday, 20 November 2009 -
Curiosity as a Malicious PDF
Category: Network Security & Hacking News/Global Security News
... about piracy off the coast of East Africa. But behind the scenes, sinister things occur. The malicious PDF runs some JavaScript that exploits the Adobe Collab overflow (CVE-2007-5659) and Adobe getIcon ...Friday, 20 November 2009 -
Malicious Java Applet Poses as Carrie Prejean Video
Category: Network Security & Hacking News/Global Security News
... of the tape became common knowledge. Source: Google Trends Java applets provide everything from interactive features to web applications to advertisements. Since the birth McAfee Labs has observed ...Thursday, 19 November 2009 -
Fake Blogs Lead to FAKEAV
Category: Network Security & Hacking News/Latest Security News
... as TROJ_FAKEAV.FFGZ. The JavaScript file that is used by the fake blogs is detected as JS_FRAUDLOAD.AP. The domains or actual FAKEAV drop sites involved in this attack are already blocked ...Wednesday, 18 November 2009 -
Learn Objective-C for Java Developers (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
Learn Objective-C for Java Developers (Paperback) By James Bucanek Buy new: $26.39 30 used and new from $20.99 Customer Rating: First tagged "programming" by ...Wednesday, 18 November 2009 -
Learn Objective-C for Java Developers (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
Learn Objective-C for Java Developers (Paperback) By James Bucanek Buy new: $26.39 30 used and new from $20.99 Customer Rating: First tagged "programming" by ...Wednesday, 18 November 2009 -
Java(TM) EE 5 Tutorial, The (3rd Edition) (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
Java(TM) EE 5 Tutorial, The (3rd Edition) (Paperback) By Eric Jendrock Buy new: $40.94 50 used and new from $28.36 Customer Rating: First tagged "programming" ...Wednesday, 18 November 2009 -
Tips For Independent Computer Consultants: Find Projects Faster - Earn Higher Billing Rates (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
... Eric Kay Customer tags: computer consultant, it job, consulting, job search, java, cobol, oracle, freelance, programming, contractor Read Full Article ...Wednesday, 18 November 2009 -
Grails 1.1 Web Application Development (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
... Customer tags: software development(2), web programming(2), java(2), grails(2), web development(2), groovy, programming, j2ee, gorm Read Full Article ...Tuesday, 17 November 2009 -
Interesting Information Security Bits for 11/17/2009
Category: Network Security & Hacking News/Latest Security News
... some Javascript shellcode. Good stuff! Paul Melson’s Blog: Reversing JavaScript Shellcode: A Step By Step How-To Tags: ( reverse-engineering javascript shellcode ) The Offensive Security Exploit ...Tuesday, 17 November 2009 -
Vuln: Sun Java Runtime Environment Multiple Unspecified Same Origin Policy Violation Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment Multiple Unspecified Same Origin Policy Violation Vulnerabilities Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Runtime Environment Virtual Machine Privilege Escalation Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment Virtual Machine Privilege Escalation Vulnerability Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java SE Java Management Extensions (JMX) Unspecified Unauthorized Access Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java SE Java Management Extensions (JMX) Unspecified Unauthorized Access Vulnerability Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Runtime Environment XML Data Processing Multiple Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment XML Data Processing Multiple Vulnerabilities Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Runtime Environment Multiple Security Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment Multiple Security Vulnerabilities Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Web Start Multiple Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Web Start Multiple Vulnerabilities Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java Runtime Environment Font Processing Buffer Overflow Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment Font Processing Buffer Overflow Vulnerability Read Full Article ...Tuesday, 17 November 2009 -
Vuln: Sun Java SE Secure Static Versioning Applet Execution Weakness
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java SE Secure Static Versioning Applet Execution Weakness Read Full Article ...Tuesday, 17 November 2009 -
Aster Data announces version 4.0, for ultra-fast analysis of Big Data
Category: Network Security & Hacking News/Latest Security News
... Companies can take their existing Java, C, C++, C#, .NET, Perl and Python applications, MapReduce-enable them and push them down into the data. • Application Process management: Parallelized applications ...Monday, 16 November 2009 -
Weekly Intelligence Summary: 2009 – 11 – 06
Category: Network Security & Hacking News/Latest Security News
The most risk significant development this week was Microsoft's Advance Notification for release of six security bulletins on 2009-11-10. Sun released an update to Java addressing seventeen vulnerabilities, ...Monday, 09 November 2009 -
Updates for Adobe's Shockwave, Sun's Java
Category: Network Security & Hacking News/Latest Security News
Sun Microsystems has issued an update to its Java software that fixes at least one security vulnerability. Separately, Adobe is pushing out a patch to plug four security holes in its Shockwave Player. ...Thursday, 05 November 2009 -
Vulnerability in TLS Protocol during Renegotiation [CVE-2009-3555]
Category: Network Security & Hacking News/Global Security News
... which use Network Security Services (NSS), Java Secure Socket Extensions (JSSE), OpenSSL or GnuTLS libraries may be affected. Sun is evaluating the impact of the issue on various products which make ...Thursday, 05 November 2009 -
Vuln: Prototype JavaScript Framework Cross-Site Ajax Request Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Prototype JavaScript Framework Cross-Site Ajax Request Vulnerability Read Full Article ...Wednesday, 04 November 2009 -
Java 6 Update 17 fixes multiple security vulnerabilities
Category: Network Security & Hacking News/Latest Security News
Various buffer and integer overflows triggered by crafted audio and image files allow Java applets and 'Java Web Start' applications to escalate their privileges Various buffer and integer overflows ...Tuesday, 03 November 2009 -
Python Pocket Reference (Python in Your Pocket) (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
... by K. Langer "Java Lover" Customer tags: programming, python reference Read Full Article ...Tuesday, 03 November 2009 -
Sun Alert 269868 The Java Update Mechanism on Non-English Versions Does Not Update the JRE When a New Version is Available
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) The Java Runtime Environment (JRE) Java Update mechanism running on non-English versions of the Windows operating system does not update the JRE when ...Monday, 02 November 2009 -
Sun Alert 270475 A Security Vulnerability in the Java Runtime Environment With Verifying HMAC Digests may Allow Authentication to be Bypassed
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) A security vulnerability in the Java Runtime Environment with verifying HMAC digests may allow authentication to be bypassed. This could allow a user ...Monday, 02 November 2009 -
Sun Alert 269870 Security Vulnerability in the Java Web Start Installer May be Leveraged to Allow Untrusted Java Web Start Application to Run As Trusted Application
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) A security vulnerability in the Java Web Start Installer may be leveraged to allow an untrusted Java Web Start application to run as a trusted application ...Monday, 02 November 2009 -
Sun Alert 269869 Command Execution Vulnerability in the Java Runtime Environment Deployment Toolkit May be Leveraged to Execute Arbitrary Code
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) A command execution vulnerability in the Java Runtime Environment Deployment Toolkit may be leveraged to execute arbitrary code. This may occur as the ...Monday, 02 November 2009 -
Sun Alert 270474 Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment With Processing Audio and Image Files May Allow Privileges to be Escalated
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) Multiple buffer and integer overflow vulnerabilities in the Java Runtime Environment with processing audio and image files may allow an untrusted applet ...Monday, 02 November 2009 -
Sun Alert 270476 Two Security Vulnerabilities in the Java Runtime Environment With Decoding DER Encoded Data and Parsing HTTP Headers may Result in a Denial of Service (DoS)
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) Two vulnerabilities in the Java Runtime Environment with decoding DER encoded data and parsing HTTP headers may separately allow a remote client to cause ...Monday, 02 November 2009 -
Weekly Intelligence Summary: 2009 – 10 – 30
Category: Network Security & Hacking News/Latest Security News
... with the primary goal of stealing bank account information. Sun issued advance notification to patch at least six vulnerabilities in Java on Tuesday, 2009-11-03. There is also an Most of the threat ...Monday, 02 November 2009 -
Vuln: Sun Java SE Advance Notification of Multiple Security Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java SE Advance Notification of Multiple Security Vulnerabilities Read Full Article ...Sunday, 01 November 2009 -
Object-Oriented JavaScript: Create scalable, reusable high-quality JavaScript applications and libraries (Paperback) newly tagged "programming"
Category: Network Security & Hacking Products/Programming
Object-Oriented JavaScript: Create scalable, reusable high-quality JavaScript applications and libraries (Paperback) By Stoyan Stefanov Buy new: $31.64 Customer Rating: ...Sunday, 01 November 2009 -
Advance notification of Security Updates for Java SE
Category: Network Security & Hacking News/Global Security News
On November 3, 2009, Sun will release the following security updates: JDK and JRE 6 Update 17 JDK and JRE 5.0 Update 22 SDK and JRE 1.4.2_24 SDK and JRE 1.3.1_27 The following Sun Alerts corresponding ...Thursday, 29 October 2009 -
Mozilla update repairs Firefox buffer overflow vulnerabilities
Category: Network Security & Hacking News/Latest Security News
... in a variety of browser functions. Mozilla repaired four critical memory corruption errors affecting the browser engine and the JavaScript engine. In its advisory, Mozilla said some of the errors could ...Thursday, 29 October 2009 -
Hack-o-Lantern
Category: Network Security & Hacking News/Latest Security News
... cool to me on many levels. Here's a java implementation of Life for you to tinker with. Let's see your pumpkins!HiR Information Report is brought you you by Edgeos, Your Network Security Platform. We ...Wednesday, 28 October 2009 -
Vuln: Mozilla Firefox JavaScript Web-Workers Remote Code Execution Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Mozilla Firefox JavaScript Web-Workers Remote Code Execution Vulnerability Read Full Article ...Tuesday, 27 October 2009 -
Review of Hacking Exposed: Web 2.0 Posted
Category: Network Security & Hacking News/Latest Security News
... when I was already reading snippets mentioning JavaScript arrays in the introduction. That set the tone for the book: compressed, probably rushed, mixing material of differing levels of difficulty. For ...Monday, 26 October 2009 -
Giving OpenSolaris another shot
Category: Network Security & Hacking News/Latest Security News
... desktop environment within OpenSolaris is familiar, with a very Ubuntu-inspired default configuration. It's certainly much different than my Solaris 10 "Java Desktop" interface at the office. The default ...Monday, 26 October 2009 -
Alleged critical vulnerability in Sun Java System Web Server
Category: Network Security & Hacking News/Latest Security News
A commercial exploit package allegedly contains a zero day exploit for Sun's web platform A commercial exploit package allegedly contains a zero day exploit for Sun's web platform Read Full Article ...Monday, 26 October 2009 -
Vuln: Sun Java System Web Server Unspecified Remote Buffer Overflow Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java System Web Server Unspecified Remote Buffer Overflow Vulnerability Read Full Article ...Sunday, 25 October 2009 -
Vuln: Adobe Reader and Acrobat JavaScript Memory Corruption Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Adobe Reader and Acrobat JavaScript Memory Corruption Vulnerability Read Full Article ...Sunday, 25 October 2009 -
Oracle Database 10g DBA Handbook (Paperback) newly tagged "databases"
Category: Network Security & Hacking Products/Databases
... Customer tags: oracle(5), oracle 10g(3), dba(2), relational databases, sql, javan, databases, oracle tuning, database management systems, database, kevin loney Read Full Article ...Saturday, 24 October 2009 -
Metasploit JSP Shells
Category: Network Security & Hacking News/Latest Security News
Stephen Fewer has pushed up a jsp reverse and jsp bind shell. http://dev.metasploit.com/redmine/projects/framework/repository/show/modules/payloads/singles/java I'm not sure of all the ways to use them ...Thursday, 22 October 2009 -
VanMorrison.com Iframe
Category: Network Security & Hacking News/Latest Security News
... up. I haven't yet learned javascript deobfuscation but that didn't look like good stuff was happening. So I took a sacrificial lamb system. (still dangerous don't try this at home). And went ...Wednesday, 21 October 2009 -
JAVA ENTERPRISE COMPUTING: Enabling Breakaway Business Strategies (Hardcover) newly tagged "operating systems"
Category: Network Security & Hacking Products/Operating Systems
JAVA ENTERPRISE COMPUTING: Enabling Breakaway Business Strategies (Hardcover) By Sun Microsystems. 14 used and new from $2.39 First tagged "operating systems" ...Wednesday, 21 October 2009 -
Vuln: Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities Read Full Article ...Thursday, 15 October 2009