New User, Welcome!     Login

Next Page >>

Internet security

CA20090818-02: Security Notice for CA Internet Security Suite

CA20090818-02: Security Notice for CA Internet Security Suite

Issued: August 18, 2009

CA's technical support is alerting customers to a security risk with
CA Internet Security Suite. A vulnerability exists that can allow a
local attacker to cause a denial of service. CA has issued updates
to address the vulnerability.

The vulnerability, CVE-2009-0682, is due to insufficient verification

KHOBE - 8.0 earthquake for Windows desktop security software

Vulnerable software:

    * 3D EQSecure Professional Edition 4.2
    * avast! Internet Security 5.0.462
    * AVG Internet Security 9.0.791
    * Avira Premium Security Suite 10.0.0.536
    * BitDefender Total Security 2010 13.0.20.347
    * Blink Professional 4.6.1
    * CA Internet Security Suite Plus 2010 6.0.0.272

[PT-2009-05] CA Internet Security Suite Denial of Service Vulnerability

----------------------------------------------------------------------

         (PT-2009-05) Positive Technologies Security Advisory

      CA Internet Security Suite Denial of Service Vulnerability

----------------------------------------------------------------------

---[ Affected Software ]


[UPDATE] NSOADV-2010-001: Panda Security Local Privilege Escalation

  Affected Products:      (Self tested)
                          -Panda Security for Business 4.04.10
                          -Panda Security for Business with Exchange
                           4.04.10
                          -Panda Security for Enterprise 4.04.10
                          -Panda Internet Security 2010 (15.01.00)
                          -Panda Global Protection 2010 (3.01.00)
                          -Panda Antivirus Pro 2010 (9.01.00)
                          -Panda Antivirus for Netbooks (9.01.00)

                          (Provided by Panda)

NSOADV-2010-001: Panda Security Local Privilege Escalation

  Affected Products:      (Self tested)
                          -Panda Security for Business 4.04.10
                          -Panda Security for Business with Exchange
                           4.04.10
                          -Panda Security for Enterprise 4.04.10
                          -Panda Internet Security 2010 (15.01.00)
                          -Panda Global Protection 2010 (3.01.00)
                          -Panda Antivirus Pro 2010 (9.01.00)
                          -Panda Antivirus for Netbooks (9.01.00)

                          (Provided by Panda)

Re: [Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking

CISA, CISSP, ITIL
CEH Instructor, ECSP Instructor, CSSLP, OPSA, OPST
OWASP Spain Chapter Leader
vaguilera@isecauditors.com

Internet Security Auditors
www.isecauditors.com

c. Santander, 101. Edif. A. 2º
E-08030 Barcelona (Spain)
Tel: +34 93 305 13 18

iDefense Security Advisory 06.04.08: Kaspersky Internet Security IOCTL Stack Based Buffer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Jun 04, 2008

I. BACKGROUND

aspersky Internet Security Suite is a combination of Kaspersky
anti-virus, anti-spam, and personal firewall in one product. For more
information see the vendor's website at the following URL.

http://www.kaspersky.com/


iDefense Security Advisory 06.04.08: Kaspersky Internet Security IOCTL Stack Based Buffer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Jun 04, 2008

I. BACKGROUND

aspersky Internet Security Suite is a combination of Kaspersky
anti-virus, anti-spam, and personal firewall in one product. For more
information see the vendor's website at the following URL.

http://www.kaspersky.com/


CA20110223-01: Security Notice for CA Host-Based Intrusion Prevention System

Windows


Affected Products 
CA Host-Based Intrusion Prevention System (HIPS) r8.1
CA Internet Security Suite (ISS) 2010
CA Internet Security Suite (ISS) 2011


How to determine if the installation is affected 
HIPS Management Server is vulnerable if the version number is less than 

[Positive Technologies SA 2009-09] Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities

----------------------------------------------------------------------

         (PT-2009-09) Positive Technologies Security Advisory

       Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege 
Escalation Vulnerabilities

----------------------------------------------------------------------

---[ Affected Software ]

Malware detection evasion in antivirus software

  ESET NOD32 Antivirus 5.0.93.0, 5.0.94.0 and earlier
    4.2.71.2 and earlier
    4.0.x

  AVAST 6.0.1289 Internet Security , engine 111011-2 and earlier

  F-Prot Antivirus 6.0.9.5 , Scanning Engine 4.6.2

  G-Data AntiVirus 2012 22.0.2.38, 22.0.9.1


ASPR #2011-01-11-1: Remote Binary Planting in Multiple F-Secure Products

ASPR #2011-01-11-1: Remote Binary Planting in Multiple F-Secure Products
=======================================================================

Document ID:     ASPR #2011-01-11-1-PUB
Vendor:          F-Secure Corp. (http://www.f-secure.com)
Target:          F-Secure Internet Security 2010 and 2011
                 F-Secure Anti-Virus 2010 and 2011
                 (and multiple other F-Secure products) 
Impact:          Remote execution of arbitrary code
Severity:        Very high
Status:          Official patch available, workarounds available

Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability

Kaspersky Anti-Virus 6.0 for Windows Workstations (6.0.3.837)
Kaspersky Anti-Virus 6.0 for Windows File Servers (6.0.3.837)
Kaspersky Anti-Virus 7 (7.0.1.325)
Kaspersky Anti-Virus 2009 (8.0.0.x)
Kaspersky Anti-Virus 2010 (9.0.0.463)
Kaspersky Internet Security 7 (7.0.1.325)
Kaspersky Internet Security 2009 (8.0.0.x)
Kaspersky Internet Security 2010 (9.0.0.463)

Prior versions may also be affected.


AhnLab AntiVirus Remote Kernel Memory Corruption

AhnLab Inc.


Affected:

AhnLab Antivirus V3 Internet Security 2008
The other version maybe vulnerable too.

This vulnerability has been confirmed on AhnLab V3 Internet Security
2008 Platinum.


iDefense Security Advisory 04.02.08: Symantec Internet Security 2008 ActiveDataInfo.LaunchProcess Design Error Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Apr 02, 2008

I. BACKGROUND

Norton Internet Security 2008 is a system security suite that offers
protection from spyware, viruses, identity theft, spam, and malicious
network traffic. More information can be found on the vendor's site at
the following URL.

http://www.symantec.com/home_homeoffice/products/overview.jsp?pcid=is&pvid=nis2008

CA20091008-01: Security Notice for CA Anti-Virus Engine

CA Anti-Virus 2007 (v8)
CA Anti-Virus 2008
CA Anti-Virus 2009
CA Anti-Virus Plus 2009
eTrust EZ Antivirus r7.1
CA Internet Security Suite 2007 (v3)
CA Internet Security Suite 2008
CA Internet Security Suite Plus 2008
CA Internet Security Suite Plus 2009
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) r8

[ISecAuditors Security Advisories] Insecure Direct Object Reference in tuenti.com allow to read of any message user

=============================================
INTERNET SECURITY AUDITORS ALERT 2010-008
- Original release date: August 30th, 2010
- Last revised: September 21st, 2010
- Discovered by: Vicente Aguilera Diaz
- Severity: 4/10 (CVSSv2 Base Scored)
=============================================

I. VULNERABILITY
-------------------------

[TZO-17-2009]Trendmicro multiple bypass/evasions

   -ServerProtect for EMC Celerra
   -ServerProtect for NetApp
   -Server Protect for Linux
   -ServerProtect for Network Appliance Filers
   
3. Trend Micro Internet Security product suites 
   (Internet Security Pro, Internet Security, Antivirus+AntiSpyware)
4. Client / Server / Messaging Suite ( The OfficeScan component )
5. Worry Free Business Security - Standard 
6. Worry Free Business Security - Advanced ( The security agent component )
7. Worry Free Business Security Hosted 

[ISecAuditors Security Advisories] SQL Injection and XSS in Motorito < v2.0 Ni 483

=============================================
INTERNET SECURITY AUDITORS ALERT 2010-005
- Original release date: March 30th, 2010
- Last revised: September 23th, 2010
- Discovered by: Mario Diaz Caldera
- Severity: 5.5/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
-------------------------

[ISecAuditors Security Advisories] Reflected XSS in Atmail WebMail < v6.2.0

=============================================
INTERNET SECURITY AUDITORS ALERT 2010-009
- Original release date: August 30th, 2010
- Last revised:  September 21st, 2010
- Discovered by: Vicente Aguilera Diaz
- Severity: 4.3/10 (CVSSv2 Base Scored)
=============================================

I. VULNERABILITY
-------------------------

[ISecAuditors Security Advisories] Simple PHP Blog <= 0.5.1 Local File Include vulnerability

=============================================
INTERNET SECURITY AUDITORS ALERT 2009-005
- Original release date: March 2nd, 2009
- Last revised:  December 18th, 2009
- Discovered by: Juan Galiana Lara
- Severity: 6.8/10 (CVSS scored)
=============================================

I. VULNERABILITY
-------------------------

[ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple XSS vulnerabilities in HTTP Headers

=============================================
INTERNET SECURITY AUDITORS ALERT 2009-007
- Original release date: June 30th, 2009
- Last revised:  July 2nd, 2009
- Discovered by: Juan Galiana Lara
- Severity: 6.8/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
-------------------------

[ISecAuditors Security Advisories] XSS in Oracle AS Portal 10g

=============================================
INTERNET SECURITY AUDITORS ALERT 2010-007
- Original release date: August 11th, 2010
- Last revised:  May 1st, 2011
- Discovered by: Vicente Aguilera Diaz
- Severity: 5.0/10 (CVSS Base Scored)
=============================================

I. VULNERABILITY
-------------------------

iDefense Security Advisory 04.02.08: Symantec Norton Internet Security 2008 ActiveX Control Buffer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Apr 02, 2008

I. BACKGROUND

Norton Internet Security 2008 is a system security suite that offers
protection from spyware, viruses, identity theft, spam, and malicious
network traffic. More information can be found on the vendor's site at
the following URL.

http://www.symantec.com/home_homeoffice/products/overview.jsp?pcid=is&pvid=nis2008

[G-SEC 46-2009] Computer Associates multiple products arbritary code execution

CA Anti-Virus 2007 (v8)
CA Anti-Virus 2008
CA Anti-Virus 2009
CA Anti-Virus Plus 2009
eTrust EZ Antivirus r7.1
CA Internet Security Suite 2007 (v3)
CA Internet Security Suite 2008
CA Internet Security Suite Plus 2008
CA Internet Security Suite Plus 2009
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) r8

Secunia Research: Trend Micro Network Security Component Vulnerabilities

Verification........................................................10

====================================================================== 
1) Affected Software 

* Trend Micro Internet Security 2007
* Trend Micro Internet Security 2008 17.0.1224
* Trend Micro OfficeScan 8.0 SP1 Patch 1

NOTE: Other versions may also be affected.


[ISecAuditors Security Advisories] WP-Forum <= 2.3 SQL Injection vulnerabilities

=============================================
INTERNET SECURITY AUDITORS ALERT 2009-010
- Original release date: September 28th, 2009
- Last revised: December 15th, 2009
- Discovered by: Juan Galiana Lara
- CVE ID: CVE-2009-3703
- Severity: 8.5/10 (CVSS Base Score)
=============================================

I. VULNERABILITY

[ISecAuditors Security Advisories] wwwstats is vulnerable to Persistent XSS

=============================================
INTERNET SECURITY AUDITORS ALERT 2007-004
- Original release date: November 7th, 2007
- Last revised:  December 7th, 2007
- Discovered by: Jesus Olmos Gonzalez
- Severity: 4/5
=============================================

I. VULNERABILITY
-------------------------

[TZO-20-2009] AVG ZIP evasion / bypass

Disclosure Policy : 
http://blog.zoller.lu/2008/09/notification-and-disclosure-policy.html

Affected products : 
- AVG Anti-Virus Network Edition (prior to engine build 8.5 323)
- AVG Internet Security Netzwerk Edition (prior to engine build 8.5 323)
- AVG Server Edition fr Linux/FreeBSD (prior to engine build 8.5 323)
- AVG eMail Server Edition (prior to engine build 8.5 323)
- AVG File Server Edition (prior to engine build 8.5 323)
- AVG Internet Security SBS Edition (prior to engine build 8.5 323)
- AVG Anti-Virus SBS Edition (prior to engine build 8.5 323)

[ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple Full Path Disclosure vulnerabilities

=============================================
INTERNET SECURITY AUDITORS ALERT 2009-009
- Original release date: July 21st, 2009
- Last revised:  July 23rd, 2009
- Discovered by: Juan Galiana Lara
- Severity: 5/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
-------------------------

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!