CERT Vulnerability Note VU#250635 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum2 transaction http://www.kb.cert.org/vuls/id/250635
CERT Vulnerability Note VU#342243 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetShareEnum transaction http://www.kb.cert.org/vuls/id/342243
CERT/CC Vulnerability Note VU#311619 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum3 transaction http://www.kb.cert.org/vuls/id/311619
CERT/CC Vulnerability Note VU#250635 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum2 transaction http://www.kb.cert.org/vuls/id/250635
CERT/CC Vulnerability Note 2002/08/27 追加 VU#342243 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetShareEnum transaction http://www.kb.cert.org/vuls/id/342243
CERT 2002/08/27 追加 Microsoft Office Web Components allows reading of local files via "LoadText" method by using URL redirection http://www.kb.cert.org/vuls/id/355707
ISS X-Force Database Results 2002/08/29 追加 ie-local-resource-xss (9938) Microsoft Internet Explorer "Local HTML Resource" cross-site scripting variant http://www.iss.net/security_center/static/9938.php
CERT 2002/08/28 追加 Microsoft Windows Terminal Services Advanced Client (TSAC) contains buffer overflow in process that handles input parameters http://www.kb.cert.org/vuls/id/276321
▽ KDE KDEに二つの脆弱性が発見された。 一つ目は、クロスサイトスクリプティングの脆弱性で、HTML内に含まれた不正なJavaスクリプトが実行される可能性がある。 二つ目は、HTML内に含まれているSecureフラグを検出しない状態で、Cookie情報をサイトに送信してしまう問題。この問題により、悪意のあるページを利用しセッション情報を奪取することができる。
ISS X-Force Database cisco-vpn-banner-information (10020) Cisco VPN 3000 series concentrators disclose sensitive information in application layer banners http://www.iss.net/security_center/static/10020.php
ISS X-Force Database cisco-vpn-certificate-mitm (10045) Cisco VPN Client improper verification of certificate DN fields could allow a man-in-the-middle attack http://www.iss.net/security_center/static/10045.php