NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Search NIST IT Security
Search For:   Enhanced Query Form
Search In:
 
Results 1 - 1 of 1 in Content
bullet Lotus Notes vulnerable to MS Windows graphics rendering engine bug
IBM's Lotus Notes uses the same vulnerable shimgvw.dll graphics rendering engine file implicated in the Microsoft Security Advisory 912840 to view ima...
Posted on Monday 02 January 2006 - 22:00:00 in Vulnerabilities

bullet XSS Hall of Shame
...list is no longer being regularly maintained. XSS vulnerabilities come and go so quickly it is impossible to keep up. This page will remain for educat...
Posted on Tuesday 31 March 2009 - 00:00:00 in General IT Security

bullet Microsoft’s Zero Day Event
... it involves Microsoft, and like many such recent vulnerabilities the problem is with Internet Explorer Microsoft’s Zero Day Event A Zero Day ...
Posted on Sunday 04 December 2005 - 23:33:18 in Security

bullet Vulnerabilities
Vulnerabilities that have long lasting IT Security affects for a large number of systems.
Posted on Friday 20 January 2006 - 22:27:21 in General IT Security

bullet NIST SP 800-40 v2 Creating a Patch and Vulnerability Management Program
Patch and vulnerability management is a security practice designed to proactively prevent the exploitation of IT vulnerabilities that exist within an ...
Posted on Saturday 21 January 2006 - 22:00:00 in Special Publications - SP 800 series

bullet Non-Encrypted Hall of Shame
...ed is meaningless, without encryption the data is vulnerable. August 5, 2006 – Denver Business Journal Matrix Bancorp Inc. – Two laptops...
Posted on Wednesday 10 October 2007 - 19:55:58 in Non-Encrypted Hall of Shame

bullet NIST SP 800-48 Wireless Network Security
...acks on other networks. Specific threats and vulnerabilities to wireless networks and handheld devices include the following: *All the vuln...
Posted on Tuesday 17 January 2006 - 22:00:00 in Special Publications - SP 800 series

bullet "Drop My Rights" - method to reduce harm while web surfing
...here, though. The past six months have seen major vulnerabilities in Firefox too, and its adoption has slowed. Some people are beginning to question t...
Posted on Sunday 04 December 2005 - 23:50:12 in Security

Results 1 - 1 of 1 in Links
bullet Vulnerabiity Alerts | Secunia.com
Perhaps the best source of information on current vulnerabilities. They've also been spot on many times on their risk ratings.
http://secunia.com/advisories/

Results 1 - 10 of 155 in News
bullet Month of PHP Bugs part 2 – Bug Opens Thousands more Servers to XSS Vulnerabilities
...info, cross, site, scripting, xss, google, inurl, vulnerabilities, http, headers, ha, ckers, org, recon, mysql, regression, Stefan, Esser@@@ To ...
Posted on Tuesday 06 March 2007 - 15:54:53

bullet Firefox 3.0 Vulnerabilities, 2.0.x Also Vulnerable
... firewalls are likely to soon detect and stop any exploits. The Neohapsis Full-Disclosure security mailing list is reporting a separate FF3 vulne...
Posted on Saturday 21 June 2008 - 10:27:49

bullet Highly Critical and Extremely Critical Vulnerabilities in Lotus Notes and Apple Quicktime
...me, lotus 123, extremely critical, vulnerability, vulnerabilities, viewer, worksheet, ibm, secunia, frsirt, rtsp, buffer overflow, content-type, explo...
Posted on Thursday 29 November 2007 - 04:35:47

bullet Zero-Day MS Office Exploit in the wild, Excel files currently being used.
...y, cve, 2007, 0671, excel, code, windows, server, vulnerabilities, nist, security, bulletin, patch, sans, org, vu, 166700@@@ From the Microsoft ...
Posted on Sunday 04 February 2007 - 21:53:09

bullet Critical Vulnerabilities in Adobe Reader and MS Word
Adobe Reader and Microsoft Word have announced critical vulnerabilities that can lead to allow execution of arbitrary executable code. // @@@micr...
Posted on Thursday 07 December 2006 - 14:48:20

bullet Google Search Appliance Vulnerable to Cross-Site Scripting (XSS)
...ode, vulnerable, phishing, phish, ha, ckers, org, vulnerabilities, nist, box, security, gov, cuna, mutual, fda, us, cert, bulletin, patch, advisory, p...
Posted on Sunday 26 November 2006 - 20:07:29

bullet Yet another PowerPoint 0day Exploit (9-27-06)
... office, 0day, zero, day, exploit, code, windows, vulnerabilities, nist, security, mcafee, bulletin, patch, microsoft, blog, advisory, 2000, xp, 2003,...
Posted on Thursday 28 September 2006 - 03:50:10

bullet More OS X Vulnerabilities and Exploits
Several new Mac OS X vulnerabilities are being reported. Some have PoC exploit code available on the web. The vulnerabilities include Denial of Servi...
Posted on Saturday 22 April 2006 - 10:24:19

bullet 0day PowerPoint Exploit Released
..., point, exploit, MS, microsoft, office, windows, vulnerabilities, nist, security, bulletin, patch, advisory, excel, IDS, IPS, hacked@@@ Last mo...
Posted on Friday 14 July 2006 - 04:11:50

bullet Cross-Site Scripting (XSS) - The Internet is Definitely a More Dangerous Place
..., scripting, exploit, code, security, javascript, vulnerabilities, vulnerable, server, exploited, reflected, hackers, forms, fix, programming, jeremia...
Posted on Monday 09 October 2006 - 15:35:01

Go to page       >>  
Results 1 - 9 of 9 in Forum
bullet As part of thread: WMF---Still vulnerable?
The Microsoft patch for the WMF vulnerability has now been out there for more than 10 days. However, we believe that most of the vulnerable Windows ma...
Posted by Meehowski on Monday 16 January 2006 - 14:33:48

bullet As part of thread: Microsoft's 0day "window()" Arbitrary Code Execution Vulnerability
... it involves Microsoft, and like many such recent vulnerabilities the problem is with Internet Explorer Microsoft’s Zero Day Event A Zero ...
Posted by NIST.org on Tuesday 06 December 2005 - 16:18:17

bullet As part of thread: Adding application POA&M Vulnerabilities?
One thing I'm still trying to figure out is how we're doing our POA&M's? We're GSS and host a ton of applications, all of which have their ...
Posted by Mathurin on Tuesday 10 April 2007 - 16:39:54

bullet As part of thread: The Twenty Most Critical Internet Security Vulnerabilities (Updated) ~ The Experts Consensus
http://www.sans.org/top20/
Posted by Meehowski on Wednesday 25 January 2006 - 13:26:58

bullet As part of thread: Encryption Solutions - Whole Disk
... it. Besides being more work it also is much more vulnerable. Unencrypting inevitably leaves unencrypted remnants behind, either in deleted file space...
Posted by NIST.org on Monday 12 June 2006 - 20:23:32

bullet As part of thread: WMF---Still vulnerable?
Steve Gibson at GRC.COM is reporting that he now believes that no Windows 9x computer is vulnerable to having this WMF vulnerability exploited. ...
Posted by Meehowski on Monday 23 January 2006 - 02:35:01

bullet As part of thread: WMF---Still vulnerable?
Steve Gibson at GRC.COM is reporting that he now believes that no Windows 9x computer is vulnerable to having this WMF vulnerability exploited. ...
Posted by NIST.org on Saturday 21 January 2006 - 18:03:31

bullet As part of thread: Microsoft's 0day "window()" Arbitrary Code Execution Vulnerability
Marco, I wish I knew. The reports I've received indicate that Lotus Notes uses the vulnerable shimgwv.dll file to get image information, but not to ...
Posted by NIST.org on Wednesday 04 January 2006 - 17:07:31

bullet As part of thread: Microsoft's 0day "window()" Arbitrary Code Execution Vulnerability
...LN is able to show the WMF image also without the vulnerable DLL. The question is : Is Lotus Notes using the vulnerable DLL in a way that can t...
Posted by VALVAGIO on Wednesday 04 January 2006 - 11:15:03

Results 1 - 9 of 9 in Comments
bullet Posted in reply to news item: $8,000 bounty for Vista and IE7 Vulnerabilities, plus bonuses.
...ctions are complete." But apparently there is a bidding war starting over Vista and IE7 zeroday exploits. < edited 1168991550 >
Posted by NIST.org on Tuesday 16 January 2007 - 15:57:11

bullet Posted in reply to item: Lotus Notes vulnerable to MS Windows graphics rendering engine bug
...hich the exploit code tries to invoke. YMMV - but my 6.5.3 is not vulnerable !! Hope IBM will soon verify/deny this vulnerability!
Posted by deros68 on Thursday 05 January 2006 - 10:27:06

bullet Posted in reply to news item: Extremely Critical New zero-day Windows vulnerability being exploited.
...gs such as canceling print jobs, etc. The current exploits are using the Escape() WMF routine but experts say other routines could also be vulnerable....
Posted by NIST.org on Monday 02 January 2006 - 16:40:15

bullet Posted in reply to news item: RealVNC 4 Exploit Bypasses Authentication - Update: Fix Available
Having grabbed a copy of this exploit for internal testing I was amazed to see how easy it was to take complete control of the target system. If you ...
Posted by minshaw on Tuesday 23 May 2006 - 02:17:14

bullet Posted in reply to news item: Spyware Makers Targeting Enterprises Users
...s attempted to hijack the computers of more than 70 named individuals at the UK Parliament using the recent WMF Exploit. < edited 1138256123 >
Posted by NIST.org on Wednesday 25 January 2006 - 23:14:44

bullet Posted in reply to item: Lotus Notes vulnerable to MS Windows graphics rendering engine bug
Hi John I have performed another test. 1) I have disabled using regsvr32 the vulnerable dll %windir%system32shimgvw.dllshimgvw.dll 2) u...
Posted by VALVAGIO on Thursday 05 January 2006 - 04:15:26

bullet Posted in reply to item: Lotus Notes vulnerable to MS Windows graphics rendering engine bug
... is able to show the WMF image also "without" the vulnerable DLL. The question is : Is Lotus Notes using the vulnerable DLL in a way that can t...
Posted by VALVAGIO on Thursday 05 January 2006 - 02:15:01

bullet Posted in reply to news item: Extremely Critical New zero-day Windows vulnerability being exploited.
From SANS.org "The main vector that the bad guys use to exploit this is still by posting it on web sites." I've been wondering about public forum / b...
Posted by NIST.org on Wednesday 04 January 2006 - 23:06:46

bullet Posted in reply to news item: Extremely Critical New zero-day Windows vulnerability being exploited.
It turns out that Microsoft has had a fix ready for the WMF exploit since 12/28 and has been sitting on it testing it all this time. Steve Gibson at ...
Posted by NIST.org on Wednesday 04 January 2006 - 19:22:14

Results in Other Pages
No matches found
Results in Bugtracker2
No matches found
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Headlines

»Experts to Discuss Botnet Challenges, Steps for Prevention at May 30 Workshop
»A User-Centered Approach to Designing Electronic Health Records
»Comments Requested on Strategies to Mitigate Risk in the Federal ICT Supply Chain
»No Strings Attached: NIST Protocol Helps Communicate Biometrics from Anywhere
»Cloud Computing Forum amp Workshop V Meets June 5-7 at the Department of Commerce
»Creating Usable Electronic Health Records (EHRs): A User-Centered Design Best Practices Workshop
»Iris Recognition Report Evaluates Needle in Haystack Search Capability
»Fifth Annual Health Information Security Conference Runs June 6-7
»NIST Proposes Update to Digital Signature Standard
»April Workshop Focuses on Cybersecurity for Cyber-Physical Systems and Industrial Controls
»New Industry Commitments to Give 15 Million Households Tools to Shrink Their Energy Bills
»NIST Releases Technical Guidance for Evaluating Electronic Health Records
»NIST Announces Funding to Form Steering Group to Support Trusted Identities in Cyberspace
»NSTIC Steering Group FFO Proposers' Webinar
»Guidance on Wireless Local Area Network Security is Close at Hand


Date published: not known
Details

»Apple Releases QuickTime 7.7.2
»Google Releases Google Chrome 19
»Apple Releases Flashback Malware Security Updates
»Apple Releases Multiple Security Updates
»Adobe Releases Security Bulletins for Multiple Products
»Apple Releases iOS 5.1.1
»Microsoft Releases May Security Bulletin
»Microsoft Releases Advanced Notification for May Security Bulletin
»Adobe Releases Security Advisory for Adobe Flash Player
»Google Releases Chrome 18.0.1025.168
»RuggedCom Rugged Operating System Vulnerability
»DNSChanger Malware
»Oracle Releases Critical Patch Update for April 2012
»HP ProCurve 5400 zl Switches Security Bulletin
»Samba Releases Updates for 3.0.x - 3.6.3
»Microsoft Releases April Security Bulletin
»Adobe Releases Security Bulletin for Adobe Reader and Acrobat
»Google Releases Google Chrome 18.0.1025.151
»Cisco Releases Security Advisory for WebEx Player
»Apple Update for Java for OS X Lion and Mac OS X
»Google Releases Google Chrome 18.0.1025.142
»Cisco Releases Multiple Security Advisories
»Adobe Releases Security Advisory for Adobe Flash Player
»Google Releases Google Chrome 17.0.963.83
»Cisco Releases Multiple Security Advisories
»Mozilla Releases Multiple Updates
»Microsoft Releases March Security Bulletin
»Apple Releases Safari 5.1.4
»Google Releases Chrome 17.0.963.79
»Apple Releases Multiple Security Updates


Date published: not known
Details

»U-170: Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code
Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code
»U-169: Sympa Multiple Security Bypass Vulnerabilities
Sympa Multiple Security Bypass Vulnerabilities
»U-168: EMC Documentum Information Rights Management Server Bugs Let Remote Authenticated Users Deny Service
EMC Documentum Information Rights Management Server Bugs Let Remote Authenticated Users Deny Service
»U-167: OpenSSL Invalid TLS/DTLS Record Processing Lets Remote Users Deny Service
OpenSSL Invalid TLS/DTLS Record Processing Lets Remote Users Deny Service
»U-166: Adobe Shockwave Player Memory Corruption Flaws Let Remote Users Execute Arbitrary Code
Adobe Shockwave Player Memory Corruption Flaws Let Remote Users Execute Arbitrary Code
»U-165: Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Spoof Address Bar URLs
Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Spoof Address Bar URLs
»U-164: Microsoft Security Bulletin Advance Notification for May 2012
Microsoft Security Bulletin Advance Notification for May 2012
»U-163: PHP Command Parameter Bug Lets Remote Users Obtain Potentially Sensitive Information and Execute Arbitrary Code
PHP Command Parameter Bug Lets Remote Users Obtain Potentially Sensitive Information and Execute Arb ...
»U-162: Drupal Multiple Vulnerabilities
Drupal Multiple Vulnerabilities
»U-161: Citrix Provisioning Services Unspecified Flaw Lets Remote Users Execute Arbitrary Code
Citrix Provisioning Services Unspecified Flaw Lets Remote Users Execute Arbitrary Code
»U-160: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
»U-159: Red Hat Enterprise MRG Messaging Qpid Bug Lets Certain Remote Users Bypass Authentication
Red Hat Enterprise MRG Messaging Qpid Bug Lets Certain Remote Users Bypass Authentication
»U-158: HP NonStop Server Java Multiple Vulnerabilities
HP NonStop Server Java Multiple Vulnerabilities
»U-157: Ruby Mail Gem Directory Traversal and Shell Command Injection Vulnerabilities
Ruby Mail Gem Directory Traversal and Shell Command Injection Vulnerabilities
»U-156: Red Hat update for JBoss Enterprise Portal Platform
Red Hat update for JBoss Enterprise Portal Platform


Date published: not known
Details

»FBI warns against malware installed via hotel networks
Malware poses as fake update of popular software.
»May issue of VB published
The May issue of Virus Bulletin is now available for subscribers to download.
»Android malware served via compromised websites
Malware downloaded automatically, but requires user permission to be installed.
»PayPal spam leads to exploit kit
Clicking on links leads to Blackhole rather than phishing site.
»Significant rise in malicious spam and phishing
Over one quarter of malicious emails contain eight-year-old malware.
»Researchers find many popular sites serving drive-by downloads
10 million people exposed to malware served by 25,000 most visited sites alone.
»Android malware hides inside JPG image
New LeNa variant no longer depends on rooted devices.
»April issue of VB published
The April issue of Virus Bulletin is now available for subscribers to download.
»Microsoft Word for Mac exploit used in targeted attacks
Tibetan NGOs targeted.


Date published: not known
Details

»SCADA/Smart-Grid Vendor Adopts Microsoft's Secure Software Development Program
Meanwhile, utilities lag when it comes to cyberattack preparedness and risk management at the execut ...
»Delete Data To Delete Risk
Smart data-retention policies allow an organization to rid itself of risky data when there's no need ...
»New Fraud Campaign Targets Facebook, Gmail, Hotmail, Yahoo Users
What the attacks share in common, besides being scams, is their use of a specific variant of Zeus
»Time To Deploy The FUD Weapon?
When suffering from compliance fatigue, you may have only one option to getting the funding you need ...
»5 Ways To Lose A Malicious Insider Lawsuit
Making the case against an insider takes preparation and proactive work with HR and legal
»What A DDoS Can Cost
Around 65 percent of IT pros say a DDoS costs their organizations $240,000 in lost revenue per day o ...
»Cyberspies Target Victims Via 'Strategic' Drive-by Website Attacks
Cyberespionage attackers more and more are injecting specific, legitimate websites with malware in h ...
»Number Of Software Pirates On The Rise
Fifty-seven percent of respondents said they've pirated software, according to Business Software All ...
»Network Security Technology Evolving Rapidly, Forrester Says
Review of 17 product categories shows next-generation firewalls on the rise, stand-alone NAC on the ...


Date published: not known
Details
Main Menu
· Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» ISC StormCast for Thursday, May 17th 2012 http://isc.sans.edu/podcastdetail.html?id=2542, (Thu, May 17th)
[16 May 2012 09:03pm]

» Reserved IP Address Space Reminder, (Wed, May 16th)
[16 May 2012 08:58pm]

» Avira Antivirus false positives http://forum.avira.com/wbb/index.php?page=Thread&threadID=144875, (Wed, May 16th)
[16 May 2012 11:02am]

» New Version of Google Chrome released (19.0.1084.46) , (Wed, May 16th)
[16 May 2012 09:00am]

» Microsoft released an update for its Enhanced Mitigation Experience Tool (EMET) http://blogs.technet.com/b/srd/archive/2012/05/15/introducing-emet-v3.aspx, (Wed, May 16th)
[16 May 2012 05:48am]

» Got Packets? Odd duplicate DNS replies from 10.x IP Addresses, (Wed, May 16th)
[16 May 2012 05:48am]

» ISC StormCast for Wednesday, May 16th 2012 http://isc.sans.edu/podcastdetail.html?id=2536, (Wed, May 16th)
[15 May 2012 08:23pm]

» Odd DNS replies from 10 nets and RFC1323 impacting firewalls, (Tue, May 15th)
[15 May 2012 07:21pm]

***
CNET News.com

» Euclid downplays privacy concerns about Wi-Fi tracking
[16 May 2012 06:36pm]

» Flashback makers missed out on their payday, Symantec says
[16 May 2012 05:06pm]

» Facebook IPO doesn't mean the end of privacy
[16 May 2012 04:51pm]

» Microsoft readies NUads: They watch you watching them
[15 May 2012 06:54pm]

» Apple QuickTime update for Windows only; Macs already secure
[15 May 2012 05:50pm]

» Avira update blocked Windows applications
[15 May 2012 03:21pm]

» Bots dominate small Web site traffic, research shows
[15 May 2012 07:00am]

» Rebekah Brooks charged in phone-hacking scandal
[15 May 2012 06:55am]

» Facebook attempts to clear up privacy questions
[14 May 2012 12:47pm]

» After a decade of Windows malware, feel any safer?
[14 May 2012 11:52am]

» After a decade of Windows malware, do you feel any safer?
[14 May 2012 11:52am]

» Kaspersky: Apple needs to face up to Mac threats
[14 May 2012 10:09am]

» Kaspersky probe: Apple working with us on new vulnerabilities, malware
[14 May 2012 10:09am]

» Kaspersky probe: Apple doesn't take security seriously enough
[14 May 2012 10:09am]

» Adobe will issue free security fixes for CS5 apps after all
[12 May 2012 12:55pm]

***
Computerworld Security News

» Smartphone security is heading for 'apocalypse'
[16 May 2012 07:11pm]

» Disaster recovery is a success just waiting to happen
[16 May 2012 06:28pm]

» Utah CTO takes fall for data breach
[16 May 2012 02:00pm]

» Zeus variant tricks Facebook users into exposing card data
[15 May 2012 02:17pm]

» Privacy advocates fear CISPA
[15 May 2012 01:23pm]

» Voyager postpones mobile service launch, citing Web attack
[15 May 2012 01:10pm]

» More Security News

***


***


More IT Security
News Feeds
More Sponsors

Advertise on this site
NIST - Books You Need

NIST Bookstore
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News
Welcome
Username:

Password:


Remember me

[ ]
[ ]
[ ]

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}