je.st
news
Tag: vulnerability
Microsoft patches critical vulnerability in Office 2011 for Mac
2013-06-12 19:24:50| CNET News.com
The latest update closes a hole that could allow arbitrary execution of code on an affected system. [Read more]
Tags: office
microsoft
critical
mac
ISC patches denial-of-service vulnerability affecting BIND 9
2013-06-06 14:15:24| InfoWorld: Top News
The Internet Systems Consortium (ISC), the organization that develops and maintains the widely used BIND DNS (Domain Name System) software, has patched a publicly disclosed vulnerability that can be used to remotely crash DNS servers running recent releases of BIND 9.
Tags: affecting
patches
bind
vulnerability
Hackers exploit Ruby on Rails vulnerability to compromise servers, create botnet
2013-05-29 14:25:25| InfoWorld: Top News
Hackers are actively exploiting a critical vulnerability in the Ruby on Rails Web application development framework in order to compromise Web servers and create a botnet. The Ruby on Rails development team released a security patch for the vulnerability, which is known as CVE-2013-0156, back in January. However, some server administrators haven't yet updated their Rails installations.
Tags: create
servers
ruby
compromise
Microsoft releases fix-it for Internet Explorer 8 vulnerability
2013-05-09 13:27:16| InfoWorld: Top News
Microsoft has released a temporary fix for a zero-day vulnerability in Internet Explorer 8, which was used by hackers in a prominent attack against the U.S. Department of Labor's website. The problem is particularly dangerous since it can allow an attacker to install malware merely by visiting a tampered web page. Microsoft is still working on a patch, wrote Dustin Childs, group manager for the company's Trustworthy Computing division.
Tags: internet
microsoft
releases
internet explorer
Highly critical vulnerability fixed in Nginx Web server software
2013-05-08 14:02:20| InfoWorld: Top News
The development team behind the popular Nginx open-source Web server software released security updates on Tuesday to address a highly critical vulnerability that could be exploited by remote attackers to execute arbitrary code on susceptible servers. Identified as CVE-2013-2028, the vulnerability is a stack-based buffer overflow and was first introduced in the Nginx 1.3.9 development version back in November 2012. The flaw is also present in the 1.4.0 stable version released last month.
Tags: web
software
server
highly
Sites : [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [25] [26] [27] [28] next »