ESecurityGuy
USER: Visitor
PRINT PAGE
Home > Free Security Articles > Security Alerts November 19, 2008


Free Newsletter
Free Security Articles
Free Security Software
Free Security Tools

Security News

Feedback Form

Site Map


Username

Password

Click here to register.

Security Alerts for Non-Technical People

US-CERT Cyber Security Alerts

  • SA08-319A: Mozilla Updates for Multiple Vulnerabilities - Mozilla Updates for Multiple Vulnerabilities
  • SA08-316A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SA08-309A: Adobe Reader and Acrobat Vulnerabilities - Adobe Reader and Acrobat Vulnerabilities
  • SA08-297A: Microsoft Windows Server Service Vulnerability - Microsoft Windows Server Service Vulnerability
  • SA08-288A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SA08-260A: Apple Updates for Multiple Vulnerabilities - Apple Updates for Multiple Vulnerabilities
  • SA08-253A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SA08-225A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SA08-193A: Sun Updates for Multiple Vulnerabilities - Sun Updates for Multiple Vulnerabilities
  • SA08-190A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • Emergency Security Alerts

    US-CERT Technical Cyber Security Alerts

  • TA08-319A: Mozilla Updates for Multiple Vulnerabilities - Mozilla Updates for Multiple Vulnerabilities
  • TA08-316A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • TA08-309A: Adobe Reader and Acrobat Vulnerabilities - Adobe Reader and Acrobat Vulnerabilities
  • TA08-297A: Microsoft Windows Server Service RPC Vulnerability - Microsoft Windows Server Service RPC Vulnerability
  • TA08-288A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • TA08-260A: Apple Updates for Multiple Vulnerabilities - Apple Updates for Multiple Vulnerabilities
  • TA08-253A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • TA08-225A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • TA08-193A: Sun Java Updates for Multiple Vulnerabilities - Sun Java Updates for Multiple Vulnerabilities
  • TA08-190B: Multiple DNS implementations vulnerable to cache poisoning - Multiple DNS implementations vulnerable to cache poisoning
  • Overall Alerts

    US-CERT National Cyber Alert System

  • SB08-322: Vulnerability Summary for the Week of November 10, 2008 - Vulnerability Summary for the Week of November 10, 2008
  • SA08-319A: Mozilla Updates for Multiple Vulnerabilities - Mozilla Updates for Multiple Vulnerabilities
  • TA08-319A: Mozilla Updates for Multiple Vulnerabilities - Mozilla Updates for Multiple Vulnerabilities
  • TA08-316A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SA08-316A: Microsoft Updates for Multiple Vulnerabilities - Microsoft Updates for Multiple Vulnerabilities
  • SB08-315: Vulnerability Summary for the Week of November 3, 2008 - Vulnerability Summary for the Week of November 3, 2008
  • SA08-309A: Adobe Reader and Acrobat Vulnerabilities - Adobe Reader and Acrobat Vulnerabilities
  • TA08-309A: Adobe Reader and Acrobat Vulnerabilities - Adobe Reader and Acrobat Vulnerabilities
  • ST08-001: Using Caution with USB Drives - Using Caution with USB Drives
  • SB08-308: Vulnerability Summary for the Week of October 27, 2008 - Vulnerability Summary for the Week of October 27, 2008
  • Microsoft Security Bulletins

    Microsoft Security Bulletins

  • MS08-069 – Critical: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218) - Bulletin Severity Rating:Critical - This security update resolves several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • MS08-068 – Important: Vulnerability in SMB Could Allow Remote Code Execution (957097) - Bulletin Severity Rating:Important - This security update resolves a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. The vulnerability could allow remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • MS08-067 – Critical: Vulnerability in Server Service Could Allow Remote Code Execution (958644) - Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit. Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter.
  • MS08-066 – Important: Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803) - Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in the Microsoft Ancillary Function Driver. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
  • MS08-065 – Important: Vulnerability in Message Queuing Could Allow Remote Code Execution (951071) - Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in the Message Queuing Service (MSMQ) on Microsoft Windows 2000 systems. The vulnerability could allow remote code execution on Microsoft Windows 2000 systems with the MSMQ service enabled.
  • MS08-064 – Important: Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841) - Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Virtual Address Descriptor. The vulnerability could allow elevation of privilege if a user runs a specially crafted application. An authenticated attacker who successfully exploited this vulnerability could gain elevation of privilege on an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.
  • MS08-063 – Important: Vulnerability in SMB Could Allow Remote Code Execution (957095) - Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Microsoft Server Message Block (SMB) Protocol. The vulnerability could allow remote code execution on a server that is sharing files or folders. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
  • MS08-062 - Important: Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155) - Bulletin Severity Rating:Important - This update resolves a privately reported vulnerability in the Windows Internet Printing Service that could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
  • MS08-061 – Important: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211) - Bulletin Severity Rating:Important - This security update resolves one publicly disclosed and two privately reported vulnerabilities in the Windows kernel. A local attacker who successfully exploited these vulnerabilities could take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users.
  • MS08-060 – Critical: Vulnerability in Active Directory Could Allow Remote Code Execution (957280) - Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability could allow remote code execution if an attacker gains access to an affected network. This vulnerability only affects Microsoft Windows 2000 servers configured to be domain controllers. If a Microsoft Windows 2000 server has not been promoted to a domain controller, it will not be listening to Lightweight Directory Access Protocol (LDAP) or LDAP over SSL (LDAPS) queries, and will not be exposed to this vulnerability.


  • Free Computer Security Newsletter
    Your email address:

    Your name:

    Listen to Craig on ClearChannel radio every Saturday from 6 to 9am on WGIR, WGIP and WGIN. Visit WGIR

    © Copyright 2003- 2007 DGKL, Inc. PRINT PAGE