<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns:sec="http://jvn.jp/rss/mod_sec/" xmlns:vrda="http://vrda.jpcert.or.jp/mod_vrda/" xml:lang="ja" xmlns="http://www.w3.org/2005/Atom">
  <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/atom.xml</id>
  <title>VRDA&#12501;&#12451;&#12540;&#12489;&#65306;&#33030;&#24369;&#24615;&#33029;&#23041;&#20998;&#26512;&#29992;&#24773;&#22577;&#12398;&#23450;&#22411;&#12487;&#12540;&#12479;&#37197;&#20449;</title>
  <subtitle>VRDA (Vulnerability Response Decision Assistance)&#12501;&#12451;&#12540;&#12489;&#12399;&#12289;&#32068;&#32340;&#12395;&#12362;&#12369;&#12427;&#12477;&#12501;&#12488;&#12454;&#12456;&#12450;&#31561;&#12398;&#33030;&#24369;&#24615;&#12510;&#12493;&#12472;&#12513;&#12531;&#12488;&#26989;&#21209;&#12398;&#21177;&#29575;&#21270;&#12539;&#30465;&#21147;&#21270;&#12434;&#25903;&#25588;&#12377;&#12427;&#12371;&#12392;&#12434;&#30446;&#30340;&#12392;&#12375;&#12390;&#12289;&#20844;&#38283;&#12373;&#12428;&#12390;&#12356;&#12427;&#33030;&#24369;&#24615;&#24773;&#22577;&#12395;&#38306;&#12377;&#12427;&#20998;&#26512;&#24773;&#22577;&#12434;&#12289;&#24773;&#22577;&#12398;&#20837;&#25163;&#12364;&#23481;&#26131;&#12391;&#21487;&#35501;&#24615;&#12398;&#39640;&#12356; HTML &#12501;&#12457;&#12540;&#12510;&#12483;&#12488;&#12392;&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#31561;&#12395;&#12424;&#12427;&#27231;&#26800;&#20966;&#29702;&#12395;&#21521;&#12356;&#12383; XML &#12501;&#12457;&#12540;&#12510;&#12483;&#12488;&#12391;&#37197;&#20449;&#12375;&#12390;&#12356;&#12414;&#12377;&#12290;</subtitle>
  <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/atom.xml" rel="self" type="application/atom+xml"/>
  <link href="http://vrda.jpcert.or.jp/feed_obsolete/en/atom.xml" rel="alternate" hreflang="en" type="application/atom+xml"/>
  <updated>2010-03-29T18:14:13+09:00</updated>
  <author>
    <name>JPCERT Coordination Center</name>
    <email>kengine@jpcert.or.jp</email>
    <uri>http://www.jpcert.or.jp/</uri>
  </author>
  <vrda:entrycount>376</vrda:entrycount>
  <vrda:startentryno>1</vrda:startentryno>
  <entry>
    <title>VRDA-100329-001:OpenSSL TLS &#25509;&#32154;&#12398;&#12524;&#12467;&#12540;&#12489;&#24773;&#22577;&#21462;&#25201;&#12356;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100329-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100329-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100329-001_AD_1.html</id>
    <published>2010-03-29T18:08:00+09:00</published>
    <updated>2010-03-29T18:08:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
In TLS connections, certain incorrectly formatted records can cause an OpenSSL
client or server to crash due to a read attempt at NULL.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100329-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openssl:openssl"/>
    <sec:identifier>VRDA-100329-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100325-001:Cisco IOS &#12398; SIP(Session Initiation Protocol) &#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100325-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100325-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100325-001_AD_1.html</id>
    <published>2010-03-25T14:25:00+09:00</published>
    <updated>2010-03-25T14:25:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS® Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100325-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:cisco:ios"/>
    <sec:identifier>VRDA-100325-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100323-001:Firefox WOFF &#12487;&#12467;&#12540;&#12480;&#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12395;&#12424;&#12427;&#12498;&#12540;&#12503;&#30772;&#25613;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100323-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100323-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100323-001_AD_1.html</id>
    <published>2010-03-23T16:46:00+09:00</published>
    <updated>2010-03-23T16:46:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
WOFF デコーダの圧縮フォント展開処理に整数オーバーフローが含まれていることが、Intevydis のセキュリティ研究者 Evgeny Legerov 氏によって報告されました。この問題によって、ダウンロードフォントの保存に割り当てられるメモリバッファが不足する状況が発生します。攻撃者はこの脆弱性を悪用して被害者のブラウザをクラッシュさせ、そのシステム上で任意のコードを実行することが可能でした。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100323-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:3.6"/>
    <sec:identifier>VRDA-100323-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100318-001:Google Chrome &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#12289;&#12362;&#12424;&#12403;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100318-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100318-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100318-001_AD_1.html</id>
    <published>2010-03-19T14:54:00+09:00</published>
    <updated>2010-03-19T14:54:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The stable channel has been updated to 4.1.249.1036 for Windows, and includes the following features and security fixes (since 4.0):&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100318-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:google:chrome"/>
    <sec:identifier>VRDA-100318-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100317-001:Safari &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100317-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100317-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100317-001_AD_1.html</id>
    <published>2010-03-17T15:56:00+09:00</published>
    <updated>2010-03-17T15:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
この記事では Safari 4.0.5 のセキュリティコンテンツについて説明します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100317-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:safari"/>
    <sec:identifier>VRDA-100317-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100316-001:Adobe Flash Media Server &#12395;&#12362;&#12369;&#12427; Apache HTTP Server &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100316-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100316-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100316-001_AD_1.html</id>
    <published>2010-03-16T16:10:00+09:00</published>
    <updated>2010-03-16T16:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
An important  vulnerability was recently identified  in Apache HTTP Server version 2.2.14 and earlier (CVE-2010-0425: mod_isapi module unload flaw). The flaw in mod_isapi could result in an attempt to unload the ISAPI dll when encountering various error states. This could leave the callbacks in an undefined state and result in a segfault. On Windows platforms using mod_isapi, a remote attacker could send a malicious request to trigger this issue, and as win32 MPM runs only one process, this would result in a denial of service, and potentially allow arbitrary code execution. This vulnerability has been fixed in Apache httpd 2.2.15.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100316-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:adobe:flash_media_server"/>
    <sec:identifier>VRDA-100316-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100315-001:Samba &#12398; CAP_DAC_OVERRIDE &#12501;&#12521;&#12464;&#12395;&#12362;&#12369;&#12427;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100315-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100315-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100315-001_AD_1.html</id>
    <published>2010-03-15T18:14:00+09:00</published>
    <updated>2010-03-15T18:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This flaw caused all smbd processes to inherit CAP_DAC_OVERRIDE capabilities, allowing all file system access to be allowed even when permissions should have denied access.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100315-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:samba:samba"/>
    <sec:identifier>VRDA-100315-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100311-001:Internet Explorer &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100311-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100311-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100311-001_AD_1.html</id>
    <published>2010-03-11T14:04:00+09:00</published>
    <updated>2010-03-11T14:04:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Internet Explorer 6 および Internet Explorer 7 に存在する新たな脆弱性が報告され、マイクロソフトはその報告を現在調査中です。マイクロソフトの調査で、最新バージョンのブラウザーである Internet Explorer 8 は影響を受けないことを確認しています。この脆弱性の主な影響はリモートでのコードの実行です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100311-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:ie:6"/>
    <category term="cpe:/a:microsoft:ie:7"/>
    <sec:identifier>VRDA-100311-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100310-001:Microsoft &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100310-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100310-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100310-001_AD_1.html</id>
    <published>2010-03-10T15:39:00+09:00</published>
    <updated>2010-03-10T15:39:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ情報は 2010 年 3 月に公開したセキュリティ情報の一覧です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100310-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:excel_viewer"/>
    <category term="cpe:/a:microsoft:office:2003"/>
    <category term="cpe:/a:microsoft:office:2007"/>
    <category term="cpe:/a:microsoft:office:xp"/>
    <category term="cpe:/a:microsoft:producer"/>
    <category term="cpe:/a:microsoft:sharepoint_server:2007"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-100310-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100308-001:Autonomy KeyView &#12398; OLE &#12489;&#12461;&#12517;&#12513;&#12531;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100308-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100308-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100308-001_AD_1.html</id>
    <published>2010-03-08T14:31:00+09:00</published>
    <updated>2010-03-08T14:31:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Autonomy KeyView SDK is a commercial SDK that provides many file format parsing libraries. It supports a large number of different document formats. KeyView is used by several popular vendors for processing documents.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100308-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:autonomy:keyview"/>
    <sec:identifier>VRDA-100308-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100305-001:Cisco Unified Communications Manager &#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100305-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100305-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100305-001_AD_1.html</id>
    <published>2010-03-05T15:44:00+09:00</published>
    <updated>2010-03-05T15:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco Unified Communications Manager (formerly Cisco CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption of voice services. The Session Initiation Protocol (SIP), Skinny Client Control Protocol (SCCP) and Computer Telephony Integration (CTI) Manager services are affected by these vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100305-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:unified_communications_manager"/>
    <sec:identifier>VRDA-100305-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#06874657:OpenPNE &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06874657_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06874657_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06874657_AD_1.html</id>
    <published>2010-03-05T15:32:00+09:00</published>
    <updated>2010-03-05T15:32:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
OpenPNE には、アクセス制限回避が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06874657_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:openpne:openpne"/>
    <sec:identifier>JVN#06874657</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100304-001:Apache HTTP &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100304-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100304-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100304-001_AD_1.html</id>
    <published>2010-03-04T15:55:00+09:00</published>
    <updated>2010-03-04T15:55:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Fixed in Apache httpd 2.2.15-dev *low: Request header information leak CVE-2010-0434 *moderate: mod_proxy_ajp DoS CVE-2010-0408&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100304-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:http_server"/>
    <sec:identifier>VRDA-100304-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100303-001:Lotus iNotes ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100303-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100303-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100303-001_AD_1.html</id>
    <published>2010-03-03T15:30:00+09:00</published>
    <updated>2010-03-03T15:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
iDefense Labs contacted IBM Lotus to report a potential buffer overflow vulnerability with the ActiveX control used by Lotus iNotes (formerly Lotus Domino Web Access).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100303-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:lotus_domino_inotes_client"/>
    <category term="cpe:/a:ibm:lotus_domino_web_access"/>
    <sec:identifier>VRDA-100303-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100302-001:VBScript &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100302-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100302-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100302-001_AD_1.html</id>
    <published>2010-03-02T15:34:00+09:00</published>
    <updated>2010-03-02T15:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは、サポートされるバージョンの Windows 2000、Windows XP および Windows Server 2003 の Internet Explorer に影響する、新たに一般公開された VBScript に存在する脆弱性の報告を現在調査中です。これまでのマイクロソフトの調査では、Windows 7、Windows Server 2008 R2、Windows Vista および Windows Server 2008 ではこの脆弱性が悪用される可能性はないと考えられます。主な脆弱性の影響は、「リモートでコードが実行される」です。マイクロソフトは現時点で、この報告された脆弱性を悪用しようとする攻撃を認識しておらず、またお客様が影響を受けたという報告は受けていません。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100302-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_2003_server"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <sec:identifier>VRDA-100302-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100301-001:PHP &#12395;&#12362;&#12369;&#12427;2&#12388;&#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100301-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100301-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100301-001_AD_1.html</id>
    <published>2010-03-01T15:15:00+09:00</published>
    <updated>2010-03-01T15:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen). Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100301-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php"/>
    <sec:identifier>VRDA-100301-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100226-001:IBM WebSphere Portal &#12398;&#12509;&#12540;&#12488;&#12524;&#12483;&#12488;&#12539;&#12497;&#12524;&#12483;&#12488;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100226-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100226-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100226-001_AD_1.html</id>
    <published>2010-02-26T16:34:00+09:00</published>
    <updated>2010-02-26T16:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The search field within the Portlet Palette of IBM WebSphere Portal is vulnerable to Cross-Site Scripting (XSS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100226-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:ibm:websphere_portal"/>
    <sec:identifier>VRDA-100226-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#73331060:tDiary &#20184;&#23646;&#12398;&#12503;&#12521;&#12464;&#12452;&#12531; tb-send.rb &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73331060_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73331060_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73331060_AD_1.html</id>
    <published>2010-02-25T15:28:00+09:00</published>
    <updated>2010-02-25T15:28:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
tDiary 付属のプラグイン tb-send.rb には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73331060_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:tdiary:tdiary"/>
    <sec:identifier>JVN#73331060</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100225-001:Adobe Download Manager &#12395;&#12362;&#12369;&#12427;&#35469;&#21487;&#12375;&#12390;&#12356;&#12394;&#12356;&#12477;&#12501;&#12488;&#12454;&#12455;&#12450;&#12434;&#12452;&#12531;&#12473;&#12488;&#12540;&#12523;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100225-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100225-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100225-001_AD_1.html</id>
    <published>2010-02-25T09:40:00+09:00</published>
    <updated>2010-02-25T09:40:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A critical  vulnerability has been identified in the Adobe Download Manager. This vulnerability (CVE-2010-0189) could potentially allow an attacker to download and install unauthorized software onto a user's system. References:CVE-2010-0189&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100225-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:download_manager"/>
    <sec:identifier>VRDA-100225-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100223-001:Cisco Security Agent &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100223-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100223-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100223-001_AD_1.html</id>
    <published>2010-02-23T16:15:00+09:00</published>
    <updated>2010-02-23T16:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated attacker to execute SQL statements that can cause instability of the product or changes in the configuration.
Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated exploitation could result in a sustained DoS condition.
These vulnerabilities are independent of each other.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100223-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:security_agent"/>
    <sec:identifier>VRDA-100223-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100222-001:Cisco ASA 5500 &#12471;&#12522;&#12540;&#12474; &#36969;&#24540;&#22411;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451; &#12450;&#12503;&#12521;&#12452;&#12450;&#12531;&#12473;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100222-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100222-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100222-001_AD_1.html</id>
    <published>2010-02-22T13:49:00+09:00</published>
    <updated>2010-02-22T13:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100222-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:cisco:asa_5500"/>
    <sec:identifier>VRDA-100222-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100219-002:Firefox &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-002_AD_1.html</id>
    <published>2010-02-19T15:35:00+09:00</published>
    <updated>2010-02-19T15:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.5.8 で修正済み。MFSA 2010-05：SVG ドキュメントとバイナリ Content-Type の使用による XSS。MFSA 2010-04：window.dialogArguments がクロスドメインで読み取り可能なことによる XSS。MFSA 2010-03：HTML パーサの誤ったメモリ解放によるクラッシュ。MFSA 2010-02：Web ワーカーの配列処理におけるヒープ破損。MFSA 2010-01：メモリ破壊の形跡があるクラッシュ (rv:1.9.1.8/1.9.0.18)&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>VRDA-100219-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100219-001:&#12471;&#12510;&#12531;&#12486;&#12483;&#12463;&#12463;&#12521;&#12452;&#12450;&#12531;&#12488;&#12503;&#12525;&#12461;&#12471;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-001_AD_1.html</id>
    <published>2010-02-19T15:23:00+09:00</published>
    <updated>2010-02-19T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Symantec Client Proxy integrated into older versions of Symantec AntiVirus and Symantec Client Security is vulnerable to a buffer overflow.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100219-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:client_security"/>
    <category term="lapt:/a:symantec:antivirus_corporate_edition"/>
    <sec:identifier>VRDA-100219-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100217-001:Adobe Reader, Acrobat &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#12362;&#12424;&#12403;&#12463;&#12525;&#12473;&#12489;&#12513;&#12452;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100217-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100217-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100217-001_AD_1.html</id>
    <published>2010-02-17T14:42:00+09:00</published>
    <updated>2010-02-17T14:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A critical vulnerability has been identified in Adobe Reader 9.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3 for Windows and Macintosh, and Adobe Reader 8.2 and Acrobat 8.2 for Windows and Macintosh. As described in Security Bulletin APSB10-06, this vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests. In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100217-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <sec:identifier>VRDA-100217-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100216-001:Squid &#12398; HTCP &#12497;&#12465;&#12483;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100216-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100216-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100216-001_AD_1.html</id>
    <published>2010-02-16T15:56:00+09:00</published>
    <updated>2010-02-16T15:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Due to incorrect processing Squid is vulnerable to a denial of service attack when receiving specially crafted HTCP packets.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100216-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:squid-cache.org:squid"/>
    <sec:identifier>VRDA-100216-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100215-002:OpenOffice.org &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-002_AD_1.html</id>
    <published>2010-02-15T15:42:00+09:00</published>
    <updated>2010-02-15T15:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
These notes contain changes between DEV300_m41 and DEV300_m60 + OOO320_m1 and OOO320_m12.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:openoffice.org:openoffice"/>
    <sec:identifier>VRDA-100215-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100215-001:Google Chrome &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#12362;&#12424;&#12403;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-001_AD_1.html</id>
    <published>2010-02-15T15:23:00+09:00</published>
    <updated>2010-02-15T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The stable channel has been updated to 4.0.249.89 for Windows.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100215-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:google:chrome"/>
    <sec:identifier>VRDA-100215-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#869993:Panda Security ActiveScan &#12395;&#12362;&#12369;&#12427;&#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12398;&#12487;&#12472;&#12479;&#12523;&#32626;&#21517;&#12434;&#26908;&#35388;&#12375;&#12394;&#12356;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU869993_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU869993_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU869993_AD_1.html</id>
    <published>2010-02-12T17:45:00+09:00</published>
    <updated>2010-02-12T17:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Panda ActiveScan のインストーラコンポーネントには、ダウンロードされたソフトウェアコンポーネントのデジタル署名を検証しない問題が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU869993_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:panda_security:activescan"/>
    <sec:identifier>JVNVU#869993</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100212-002:HP Network Node Manager (NNM) &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12510;&#12531;&#12489;&#23455;&#34892;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-002_AD_1.html</id>
    <published>2010-02-12T14:49:00+09:00</published>
    <updated>2010-02-12T14:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential security vulnerability has been identified with HP Network Node Manager (NNM). The vulnerability could be exploited remotely to execute arbitrary commands.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:network_node_manager"/>
    <sec:identifier>VRDA-100212-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100212-001:Adobe Flash Player &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12489;&#12513;&#12452;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-001_AD_1.html</id>
    <published>2010-02-12T14:32:00+09:00</published>
    <updated>2010-02-12T14:32:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A critical vulnerability has been identified in Adobe Flash Player version 10.0.42.34 and earlier. This vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100212-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:adobe_air"/>
    <category term="cpe:/a:adobe:flash_player"/>
    <sec:identifier>VRDA-100212-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100210-001:Microsoft &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100210-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100210-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100210-001_AD_1.html</id>
    <published>2010-02-10T14:27:00+09:00</published>
    <updated>2010-02-10T14:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ情報は 2010 年 2 月に公開したセキュリティ情報の一覧です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100210-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:office:2003"/>
    <category term="cpe:/a:microsoft:office:2007"/>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-100210-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100209-001:Samba &#12398;&#12471;&#12531;&#12508;&#12522;&#12483;&#12463;&#12522;&#12531;&#12463;&#12501;&#12449;&#12452;&#12523;&#20966;&#29702;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100209-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100209-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100209-001_AD_1.html</id>
    <published>2010-02-09T17:48:00+09:00</published>
    <updated>2010-02-09T17:48:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Claimed Zero Day exploit in Samba.A user named &quot;kcopedarookie&quot; posted what they claim to be a video of a zero-day exploit in Samba on youtube yesterday.The video shows modifications to smbclient allowing /etc/passwd to be downloaded from a remote server.The issue is actually a default insecure configuration in Samba.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100209-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:samba:samba"/>
    <sec:identifier>VRDA-100209-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100208-001:Oracle WebLogic Server &#12398; Node Manager &#12364;&#35469;&#35388;&#27231;&#27083;&#12434;&#20351;&#29992;&#12375;&#12390;&#12356;&#12394;&#12356;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100208-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100208-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100208-001_AD_1.html</id>
    <published>2010-02-08T14:52:00+09:00</published>
    <updated>2010-02-08T14:52:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This Security Alert addresses security issue CVE-2010-0073, a vulnerability in the Node Manager component of Oracle WebLogic Server. This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password. A knowledgeable and malicious remote user can exploit this vulnerability which can result in impacting the availability, integrity and confidentiality of the targeted system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100208-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:oracle:weblogic_server"/>
    <sec:identifier>VRDA-100208-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100205-001:Novell NetStorage &#12395;&#12362;&#12369;&#12427;&#12467;&#12540;&#12489;&#23455;&#34892;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100205-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100205-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100205-001_AD_1.html</id>
    <published>2010-02-05T18:07:00+09:00</published>
    <updated>2010-02-05T18:07:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
There may be a potential security vulnerability with NetStorage that may allow remote attackers to execute arbitrary code on vulnerable installations of Novell NetStorage. Authentication is not required to exploit this vulnerability.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100205-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:novell:netstorage"/>
    <sec:identifier>VRDA-100205-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100204-001:Internet Explorer &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#24773;&#22577;&#28431;&#12360;&#12356;&#12364;&#36215;&#12371;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100204-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100204-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100204-001_AD_1.html</id>
    <published>2010-02-04T15:19:00+09:00</published>
    <updated>2010-02-04T15:19:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは Windows XP を実行しているお客様、または Internet Explorer の保護モードを無効にしているお客様についての一般に公開された Internet Explorer に存在する脆弱性の報告を現在調査中です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100204-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:ie"/>
    <sec:identifier>VRDA-100204-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100203-001:Squid &#12398; DNS &#12497;&#12465;&#12483;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100203-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100203-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100203-001_AD_1.html</id>
    <published>2010-02-03T17:33:00+09:00</published>
    <updated>2010-02-03T17:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Due to incorrect data validation Squid is vulnerable to a denial of service attack when processing specially crafted DNS packets.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100203-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:squid-cache.org:squid"/>
    <sec:identifier>VRDA-100203-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100202-002:VMware &#35069;&#21697;&#12398; Java JRE &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-002_AD_1.html</id>
    <published>2010-02-02T15:21:00+09:00</published>
    <updated>2010-02-02T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Updated Java JRE packages address several security issues.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <category term="lapt:/a:vmware:vcenter"/>
    <category term="lapt:/a:vmware:virtualcenter"/>
    <category term="lapt:/a:vmware:vma"/>
    <sec:identifier>VRDA-100202-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100202-001:Adobe ColdFusion &#12398; Solr Collections &#12395;&#12362;&#12369;&#12427;&#24773;&#22577;&#28431;&#27945;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-001_AD_1.html</id>
    <published>2010-02-02T15:16:00+09:00</published>
    <updated>2010-02-02T15:16:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
An important vulnerability (CVE-2010-0185) has been identified in ColdFusion 9.0, which could allow access to collections created by the Solr Service to be accessed from any external machine using a specific URL. Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installations using the instructions provided below.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100202-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:coldfusion"/>
    <sec:identifier>VRDA-100202-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100201-001:Cisco Unified MeetingPlace &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100201-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100201-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100201-001_AD_1.html</id>
    <published>2010-02-01T18:36:00+09:00</published>
    <updated>2010-02-01T18:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:Insufficient validation of SQL commands, Unauthorized account creation, User and password enumeration in Cisco MeetingTime, Privilege escalation in Cisco MeetingTime. Workarounds are not available for these vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100201-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:meetingplace"/>
    <sec:identifier>VRDA-100201-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100129-002:Apache mod_proxy "ap_proxy_send_fb()" &#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-002_AD_1.html</id>
    <published>2010-01-29T18:20:00+09:00</published>
    <updated>2010-01-29T18:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SECURITY: CVE-2010-0010 (cve.mitre.org) mod_proxy: Prevent chunk-size integer overflow on platforms where sizeof(int) &lt; sizeof(long). Reported by Adam Zabrocki.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:http_server"/>
    <sec:identifier>VRDA-100129-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100129-001:Wireshark LWRES &#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-001_AD_1.html</id>
    <published>2010-01-29T13:41:00+09:00</published>
    <updated>2010-01-29T13:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The following vulnerabilities have been fixed. See the security advisory for details and a workaround. Babi discovered several buffer overflows in the LWRES dissector. Versions affected: 0.9.15 to 1.0.10, 1.2.0 to 1.2.5&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100129-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wireshark:wireshark"/>
    <sec:identifier>VRDA-100129-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#571860:Linux &#12459;&#12540;&#12493;&#12523;&#12398; IPv6 jumbogram &#20966;&#29702;&#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU571860_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU571860_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU571860_AD_1.html</id>
    <published>2010-01-29T11:55:00+09:00</published>
    <updated>2010-01-29T11:55:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Linux カーネルには、IPv6 jumbogram の処理に脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU571860_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:linux:linux_kernel"/>
    <sec:identifier>JVNVU#571860</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100128-001:Sun Java System Web Server &#12362;&#12424;&#12403; Sun Java System Web Proxy Server &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100128-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100128-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100128-001_AD_1.html</id>
    <published>2010-01-28T18:19:00+09:00</published>
    <updated>2010-01-28T18:19:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The following security vulnerabilities have been reported in the Sun Java System Web Server and the Sun Java System Web Proxy Server.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100128-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:java_system_web_proxy_server"/>
    <category term="cpe:/a:sun:java_system_web_server"/>
    <sec:identifier>VRDA-100128-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100127-002:Google Chrome &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-002_AD_1.html</id>
    <published>2010-01-27T13:53:00+09:00</published>
    <updated>2010-01-27T13:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The stable channel has been updated to 4.0.249.78 for Windows, and includes the following features and security fixes (since 3.0):&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:google:chrome"/>
    <sec:identifier>VRDA-100127-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100127-001:&#12488;&#12524;&#12531;&#12489;&#12510;&#12452;&#12463;&#12525; URL&#12501;&#12451;&#12523;&#12479;&#12522;&#12531;&#12464;&#12456;&#12531;&#12472;&#12531;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-001_AD_1.html</id>
    <published>2010-01-27T13:30:00+09:00</published>
    <updated>2010-01-27T13:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
弊社製品において、次の脆弱性の存在が確認されました。URLフィルタエンジンでバッファのオーバフローが発生する可能性があります。これにより、一般保護違反 (GPF) または製品でクラッシュが発生する可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100127-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:trend_micro:internet_security"/>
    <category term="lapt:/a:trend_micro:interscan_for_microsoft_exchange"/>
    <category term="lapt:/a:trend_micro:interscan_gateway_security"/>
    <category term="lapt:/a:trend_micro:interscan_viruswall"/>
    <category term="lapt:/a:trend_micro:interscan_web_security"/>
    <category term="lapt:/a:trend_micro:trend_micro_business_security"/>
    <category term="lapt:/a:trend_micro:trend_micro_threat_discovery"/>
    <sec:identifier>VRDA-100127-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100126-001:Apache Tomcat &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12362;&#12424;&#12403;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100126-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100126-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100126-001_AD_1.html</id>
    <published>2010-01-26T17:58:00+09:00</published>
    <updated>2010-01-26T17:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
These issues were fixed in Apache Tomcat 6.0.21 but the release votes for the 6.0.21, 6.0.22 and 6.0.23 release candidates did not pass. Therefore, although users must download 6.0.24 to obtain a version that includes fixes for these issues, versions 6.0.21 onwards are not included in the list of affected versions.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100126-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <sec:identifier>VRDA-100126-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100125-004:Cisco IOS XR &#12398; SSH &#12496;&#12540;&#12472;&#12519;&#12531; 2 &#12497;&#12465;&#12483;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-004_AD_1.html</id>
    <published>2010-01-25T10:24:00+09:00</published>
    <updated>2010-01-25T10:24:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The SSH server implementation in Cisco IOS XR Software contains a vulnerability that an unauthenticated, remote user could exploit to cause a denial of service condition.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:cisco:ios_xr"/>
    <sec:identifier>VRDA-100125-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100125-003:RealPlayer &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-003_AD_1.html</id>
    <published>2010-01-25T09:51:00+09:00</published>
    <updated>2010-01-25T09:51:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
RealNetworks は、セキュリティ バグ フィックスを含む製品アップグレードの提供を開始します。これまでのところ、今回修正された脆弱性により、実際にマシンに障害が発生したという報告はありません。RealNetworks は、セキュリティの脆弱性を回避するために、お使いの製品を常に最新のバージョンにアップグレードすることをお勧めします。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:real:realplayer"/>
    <sec:identifier>VRDA-100125-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100125-002:Windows &#12459;&#12540;&#12493;&#12523;&#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#26119;&#26684;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-002_AD_1.html</id>
    <published>2010-01-25T09:44:00+09:00</published>
    <updated>2010-01-25T09:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは、一般で報告された Windows カーネルに存在する脆弱性について、現在調査中です。マイクロソフトは現時点で、この報告された脆弱性を悪用しようとする攻撃を認識しておらず、またお客様が影響を受けたという報告は受けていません。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-100125-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VU#144233:Rockwell Automation Allen-Bradley MicroLogix PLC authentication and authorization vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU144233_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU144233_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU144233_AD_1.html</id>
    <published>2010-01-25T09:34:00+09:00</published>
    <updated>2010-01-25T09:34:00+09:00</updated>
    <author>
      <name>CERT/CC</name>
    </author>
    <content type="html">
Rockwell Automation Allen-Bradley MicroLogix programmable logic controllers (PLCs) do not adequately authenticate or authorize remote connections or commands. An attacker with network access can obtain the management password or issue commands that bypass the authentication mechanism.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU144233_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:rockwell_automation:allen_bradley_micrologix"/>
    <sec:identifier>VU#144233</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100125-001:Adobe Shockwave Player &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-001_AD_1.html</id>
    <published>2010-01-25T09:33:00+09:00</published>
    <updated>2010-01-25T09:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Macintosh operating systems. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations to the latest version using the instructions provided below.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100125-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:shockwave_player"/>
    <sec:identifier>VRDA-100125-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100121-001:Mac OS X &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100121-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100121-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100121-001_AD_1.html</id>
    <published>2010-01-21T09:14:00+09:00</published>
    <updated>2010-01-21T09:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ここでは、セキュリティアップデート 2010-001 について説明します。このアップデートは、ソフトウェア・アップデート 環境設定、または サポートダウンロード からダウンロードしてインストールできます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100121-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:apple:mac_os_x"/>
    <sec:identifier>VRDA-100121-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#360341:BIND 9 &#12398; DNSSEC &#26908;&#35388;&#12467;&#12540;&#12489;&#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU360341_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU360341_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU360341_AD_1.html</id>
    <published>2010-01-20T16:14:00+09:00</published>
    <updated>2010-01-20T16:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
BIND 9 に含まれている DNSSEC の検証コードに脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU360341_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:isc:bind"/>
    <sec:identifier>JVNVU#360341</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100119-001:Zeus Web Server &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100119-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100119-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100119-001_AD_1.html</id>
    <published>2010-01-19T16:41:00+09:00</published>
    <updated>2010-01-19T16:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Fixed crash caused by certain invalid SSL data. Thanks go to Evgeny Legerov, Intevydis, for his assistance in locating this problem.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100119-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:zeus:zeus_web_server"/>
    <sec:identifier>VRDA-100119-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100118-001:OpenSSL &#12398; "CRYPTO_free_all_ex_data()" &#12395;&#12362;&#12369;&#12427;&#12513;&#12514;&#12522;&#12522;&#12540;&#12463;&#12398;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100118-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100118-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100118-001_AD_1.html</id>
    <published>2010-01-18T14:23:00+09:00</published>
    <updated>2010-01-18T14:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Modify compression code so it frees up structures without using the ex_data callbacks. This works around a problem where some applications call CRYPTO_free_all_ex_data() before application exit (e.g. when restarting) then use compression (e.g. SSL with compression) later. This results in significant per-connection memory leaks and has caused some security issues including CVE-2008-1678 and CVE-2009-4355.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100118-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openssl:openssl"/>
    <sec:identifier>VRDA-100118-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#492515:Microsoft Internet Explorer &#12395;&#12362;&#12356;&#12390;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU492515_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU492515_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU492515_AD_1.html</id>
    <published>2010-01-15T14:43:00+09:00</published>
    <updated>2010-01-15T14:43:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Internet Explorer には、任意のコードが実行される脆弱性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU492515_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:ie"/>
    <sec:identifier>JVNVU#492515</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100114-002:Kerberos KDC RC4 &#12362;&#12424;&#12403; AES &#35299;&#35501;&#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12450;&#12531;&#12480;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-002_AD_1.html</id>
    <published>2010-01-14T16:58:00+09:00</published>
    <updated>2010-01-14T16:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Integer underflow bugs in the AES and RC4 decryption operations of the
crypto library of the MIT Kerberos software can cause crashes, heap corruption, or, under extraordinarily unlikely conditions, arbitrary code execution.  Only releases krb5-1.3 and later are vulnerable, as earlier releases did not contain the functionality implemented by the vulnerable code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mit:kerberos"/>
    <sec:identifier>VRDA-100114-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100114-001:Microsoft &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-001_AD_1.html</id>
    <published>2010-01-14T13:37:00+09:00</published>
    <updated>2010-01-14T13:37:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ情報は 2010 年 1 月 13 日に公開したセキュリティ情報の一覧です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100114-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-100114-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100113-001:Oracle &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100113-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100113-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100113-001_AD_1.html</id>
    <published>2010-01-13T17:20:00+09:00</published>
    <updated>2010-01-13T17:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A Critical Patch Update is a collection of patches for multiple security vulnerabilities. It also includes non-security fixes that are required (because of interdependencies) by those security patches. Critical Patch Updates are cumulative, except as noted below, but each advisory describes only the security fixes added since the previous Critical Patch Update. Thus, prior Critical Patch Update Advisories should be reviewed for information regarding earlier accumulated security fixes.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100113-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:oracle:application_server"/>
    <category term="cpe:/a:oracle:database_server"/>
    <category term="cpe:/a:oracle:e-business_suite"/>
    <category term="lapt:/a:oracle:oracle_access_manager"/>
    <category term="lapt:/a:oracle:oracle_jrockit"/>
    <category term="lapt:/a:oracle:peoplesoft_enterprise_hcm"/>
    <category term="lapt:/a:oracle:primavera_p6_enterprise_project_portfolio_management"/>
    <category term="lapt:/a:oracle:primavera_p6_web_services"/>
    <category term="lapt:/a:oracle:weblogic_server"/>
    <sec:identifier>VRDA-100113-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#22247093:WebCalenderC3 &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN22247093_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN22247093_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN22247093_AD_1.html</id>
    <published>2010-01-12T15:49:00+09:00</published>
    <updated>2010-01-12T15:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
有限会社シースリーが提供する WebCalenderC3 には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN22247093_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:c3:webcalenderc3"/>
    <sec:identifier>JVN#22247093</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#33977065:WebCalenderC3 &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33977065_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33977065_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33977065_AD_1.html</id>
    <published>2010-01-12T15:42:00+09:00</published>
    <updated>2010-01-12T15:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
有限会社シースリーが提供する WebCalenderC3 には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33977065_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:c3:webcalenderc3"/>
    <sec:identifier>JVN#33977065</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100112-002:Juniper JUNOS &#12398; TCP &#12497;&#12465;&#12483;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-002_AD_1.html</id>
    <published>2010-01-12T13:25:00+09:00</published>
    <updated>2010-01-12T13:25:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
I personally don't have access to the full vendor bulletin, but word is out that Juniper JUNOS routers can be crashed or made to reboot with easily spoofed malformed packets.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:juniper:junos"/>
    <sec:identifier>VRDA-100112-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100112-001:VMware ESX &#12362;&#12424;&#12403; vMA &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-001_AD_1.html</id>
    <published>2010-01-12T12:09:00+09:00</published>
    <updated>2010-01-12T12:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ervice console packages for Network Security Services (NSS) and NetScape Portable Runtime (NSPR) are updated to versions nss-3.12.3.99.3-1.2157 and nspr-4.7.6-1.2213 respectively. This patch fixes several security issues in the service console packages for NSS and NSPR.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100112-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <category term="lapt:/a:vmware:vma"/>
    <sec:identifier>VRDA-100112-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100107-001:Novell NetWare &#12398; AFP &#12497;&#12465;&#12483;&#12488;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100107-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100107-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100107-001_OT_1.html</id>
    <published>2010-01-07T14:44:00+09:00</published>
    <updated>2010-01-07T14:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The CIFS and AFP protocols have a memory consumption problem when their received lot's of malformed arbitrary requests on their respective services. Sending arbitrary crafted requests to these services will consumme all the memory available,create multiples abends and finally crash the whole server.... It could take couple of minutes to hours (Depend of the memory available on the server ).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100107-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/o:novell:netware"/>
    <sec:identifier>VRDA-100107-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#09872874:Movable Type &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN09872874_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN09872874_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN09872874_AD_1.html</id>
    <published>2010-01-06T17:06:00+09:00</published>
    <updated>2010-01-06T17:06:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type には、アクセス制限回避が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN09872874_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#09872874</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100105-001:PDF-XChange Viewer &#12395;&#12362;&#12369;&#12427;&#12513;&#12514;&#12522;&#30772;&#22730;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100105-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100105-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100105-001_AD_1.html</id>
    <published>2010-01-05T16:02:00+09:00</published>
    <updated>2010-01-05T16:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Secunia Research has discovered a vulnerability in PDF-XChange Viewer, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an input validation error in PDFXCview.exe when parsing certain content and can be exploited to corrupt memory via a specially crafted PDF file.
Successful exploitation allows execution of arbitrary code when a user views a malicious PDF document.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100105-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:tracker_software_products:pdf-xchange"/>
    <category term="lapt:/a:tracker_software_products:pdf-xchange_viewer"/>
    <sec:identifier>VRDA-100105-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100104-002:Sendmail SSL &#35388;&#26126;&#26360;&#12395;&#12362;&#12369;&#12427;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#36802;&#22238;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-002_AD_1.html</id>
    <published>2010-01-04T17:59:00+09:00</published>
    <updated>2010-01-04T17:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Sendmail, Inc., and the Sendmail Consortium announce the availability of sendmail 8.14.4. This version fixes some problems:
* some certificate authorities do not properly check the requests they are signing and hence allow spoofing via an embedded NUL in the CN entry. Some checks have been added to deal with &quot;bogus&quot; CNs (see below and doc/op/op.*).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sendmail:sendmail"/>
    <sec:identifier>VRDA-100104-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-100104-001:Kerberos KDC &#12398;&#12524;&#12523;&#12512;&#27178;&#26029;&#35469;&#35388;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-001_AD_1.html</id>
    <published>2010-01-04T17:44:00+09:00</published>
    <updated>2010-01-04T17:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A null pointer dereference can occur in an error condition in the KDC cross-realm referral processing code in MIT krb5-1.7.  This can cause the KDC to crash.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-100104-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mit:kerberos"/>
    <sec:identifier>VRDA-100104-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091225-001:Microsoft IIS &#12398;&#12501;&#12449;&#12452;&#12523;&#25313;&#24373;&#23376;&#12398;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091225-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091225-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091225-001_OT_1.html</id>
    <published>2009-12-25T13:53:00+09:00</published>
    <updated>2009-12-25T13:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Microsoft Internet Information Services (IIS), which could be exploited by attackers to compromise a vulnerable system. This issue is caused due to the server handling files with multiple extensions separated by the &quot;;&quot; character e.g. &quot;malicious.asp;.jpg&quot; as ASP pages, which could allow attackers to execute arbitrary code on a vulnerable web server by uploading a malicious file bypassing file extension protections and restrictions.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091225-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:microsoft:internet_information_server"/>
    <sec:identifier>VRDA-091225-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091224-001:F5 BIG-IP ASM &#12362;&#12424;&#12403; PSM &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091224-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091224-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091224-001_AD_1.html</id>
    <published>2009-12-24T18:33:00+09:00</published>
    <updated>2009-12-24T18:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The BIG-IP Application Security Manager (ASM) and Protocol Security Manager (PSM) &quot;bd&quot; daemon is vulnerable to a remote buffer overflow which could be exploited by remote attackers to cause a denial of service and may cause the system to crash and dump core.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091224-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:f5:big-ip"/>
    <sec:identifier>VRDA-091224-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091222-001:Adobe Flash Media Server &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12362;&#12424;&#12403;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091222-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091222-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091222-001_AD_1.html</id>
    <published>2009-12-22T16:36:00+09:00</published>
    <updated>2009-12-22T16:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Critical vulnerabilities have been identified in Adobe Flash Media Server (FMS) 3.5.2 and earlier versions. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091222-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:macromedia:flash_media_server"/>
    <sec:identifier>VRDA-091222-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091221-002:Wireshark &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12362;&#12424;&#12403;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-002_AD_1.html</id>
    <published>2009-12-21T17:45:00+09:00</published>
    <updated>2009-12-21T17:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Vulnerabilities have been fixed. See the security advisory for details and a workaround.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wireshark:wireshark"/>
    <sec:identifier>VRDA-091221-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091221-001:Solaris &#12398; Adobe Flash Player &#12395; &#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-001_AD_1.html</id>
    <published>2009-12-21T17:41:00+09:00</published>
    <updated>2009-12-21T17:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091221-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:flash_player"/>
    <category term="cpe:/o:sun:solaris"/>
    <sec:identifier>VRDA-091221-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091218-002:Cisco WebEx WRF Player &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-002_AD_1.html</id>
    <published>2009-12-18T18:28:00+09:00</published>
    <updated>2009-12-18T18:28:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cisco:webex_wrf_player"/>
    <sec:identifier>VRDA-091218-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091218-001:PHP &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-001_AD_1.html</id>
    <published>2009-12-18T18:18:00+09:00</published>
    <updated>2009-12-18T18:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091218-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php"/>
    <sec:identifier>VRDA-091218-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091217-004:PostgreSQL &#12395;&#12362;&#12369;&#12427; &#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#36802;&#22238;&#12362;&#12424;&#12403;&#27177;&#38480;&#26119;&#26684;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-004_AD_1.html</id>
    <published>2009-12-17T15:49:00+09:00</published>
    <updated>2009-12-17T15:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The PostgreSQL Project today released minor versions updating all active branches of the PostgreSQL object-relational database system, including versions 8.4.2, 8.3.9, 8.2.15, 8.1.19, 8.0.23, and 7.4.27. This release fixes one moderate-risk and one low-risk security issue: an SSL authentication issue, and a privilege escalation issue with expression indexes. All PostgreSQL database administrators are urged to update your version of PostgreSQL at the earliest opportunity.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:postgresql:postgresql"/>
    <sec:identifier>VRDA-091217-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091217-003:HP-UX &#12398; sendmail &#12395;&#12362;&#12369;&#12427; &#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475;&#65288;DoS&#65289;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-003_AD_1.html</id>
    <published>2009-12-17T15:41:00+09:00</published>
    <updated>2009-12-17T15:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential security vulnerability has been identified with HP-UX running sendmail. This vulnerability could allow a remote user to cause a Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:sendmail"/>
    <sec:identifier>VRDA-091217-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091217-002:VMware vCenter, ESX patch, vCenter Lab Manager &#12395;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-002_AD_1.html</id>
    <published>2009-12-17T15:31:00+09:00</published>
    <updated>2009-12-17T15:31:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
VMware vCenter and ESX update releases address cross-site scripting issues in the Help functionality of WebAccess. A vCenter Lab Manager release addresses the same issues which are present in the online Help functionality of Lab Manager and Stage Manager.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <category term="cpe:/a:vmware:server"/>
    <category term="lapt:/a:vmware:vcenter_server"/>
    <category term="lapt:/a:vmware:vma"/>
    <sec:identifier>VRDA-091217-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091217-001:Firefox &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-001_AD_1.html</id>
    <published>2009-12-17T15:11:00+09:00</published>
    <updated>2009-12-17T15:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.5.6 では、以下の問題が修正されています。いくつかのセキュリティ問題 が修正されました。いくつかの安定性に関する問題が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091217-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-091217-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#508357:Adobe Reader &#12362;&#12424;&#12403; Acrobat &#12395;&#12362;&#12369;&#12427;&#35299;&#25918;&#28168;&#12415;&#12513;&#12514;&#12522;&#12434;&#20351;&#29992;&#12377;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU508357_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU508357_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU508357_AD_1.html</id>
    <published>2009-12-16T15:03:00+09:00</published>
    <updated>2009-12-16T15:03:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Adobe Reader および Acrobat の Doc.media.newPlayer メソッドには、解放済みメモリを使用する (use-after-free) 脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU508357_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="lapt:/a:adobe:reader"/>
    <sec:identifier>JVNVU#508357</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#00152874:P forum &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00152874_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00152874_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00152874_AD_1.html</id>
    <published>2009-12-15T15:51:00+09:00</published>
    <updated>2009-12-15T15:51:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Rocomotion が提供する P forum には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00152874_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:rocomotion:p_forum"/>
    <sec:identifier>JVN#00152874</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#228561:Indeo &#12467;&#12540;&#12487;&#12483;&#12463;&#12395;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU228561_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU228561_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU228561_AD_1.html</id>
    <published>2009-12-15T15:40:00+09:00</published>
    <updated>2009-12-15T15:40:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Windows に含まれている Indeo コーデックには、複数の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU228561_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <sec:identifier>JVNVU#228561</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091215-001:Mozilla Thunderbird &#12395;&#12362;&#12369;&#12427;&#28014;&#21205;&#23567;&#25968;&#28857;&#25968;&#20966;&#29702;&#26178;&#12398;&#12513;&#12514;&#12522;&#30772;&#22730;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091215-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091215-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091215-001_OT_1.html</id>
    <published>2009-12-15T14:53:00+09:00</published>
    <updated>2009-12-15T14:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Mozilla Thunderbird, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing floating point numbers e.g. via the Lightning or Thunderbrowse Add-ons, which could allow remote attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious ICS file or visiting a specially crafted web page.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091215-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>VRDA-091215-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091214-001:InterSystems Cache &#12362;&#12424;&#12403; Ensemble &#12398; CSP Gateway &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091214-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091214-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091214-001_AD_1.html</id>
    <published>2009-12-14T14:27:00+09:00</published>
    <updated>2009-12-14T14:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
InterSystems has corrected a security defect that an attacker could exploit to gain complete control of a system through the CSP Gateway.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091214-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:intersystems:cache"/>
    <category term="lapt:/a:intersystems:ensemble"/>
    <sec:identifier>VRDA-091214-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091211-002:&#12488;&#12524;&#12531;&#12489;&#12510;&#12452;&#12463;&#12525; URL &#12501;&#12451;&#12523;&#12479;&#12522;&#12531;&#12464;&#12456;&#12531;&#12472;&#12531;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-002_AD_1.html</id>
    <published>2009-12-11T18:14:00+09:00</published>
    <updated>2009-12-11T18:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
トレンドマイクロURLフィルタリングエンジンはURLを評価する際、URLの標準化を行います。
非常に長いURL (最大長2319文字付近) を処理して標準化されたURLの文字数が定義済み最大数を超える場合、
無効なメモリアドレスにアクセスしようとしてバッファオーバーフローが発生し、
結果としてプログラムがクラッシュする可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:trend_micro:internet_security"/>
    <sec:identifier>VRDA-091211-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091211-001:&#12471;&#12510;&#12531;&#12486;&#12483;&#12463; Veritas VRTSweb &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-001_AD_1.html</id>
    <published>2009-12-11T14:30:00+09:00</published>
    <updated>2009-12-11T14:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Symantec VRTSweb, a shared component shipped with many Symantec Veritas products, is susceptible to a remote code execution vulnerability.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091211-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:veritas_storage_foundation"/>
    <category term="lapt:/a:symantec:backup_exec_continuous_protection_server"/>
    <category term="lapt:/a:symantec:veritas_application_director"/>
    <category term="lapt:/a:symantec:veritas_backup_reporter"/>
    <category term="lapt:/a:symantec:veritas_cluster_server"/>
    <category term="lapt:/a:symantec:veritas_cluster_server_management_console"/>
    <category term="lapt:/a:symantec:veritas_cluster_server_one"/>
    <category term="lapt:/a:symantec:veritas_command_central_enterprise_reporter"/>
    <category term="lapt:/a:symantec:veritas_command_central_storage"/>
    <category term="lapt:/a:symantec:veritas_command_central_storage_change_manager"/>
    <category term="lapt:/a:symantec:veritas_micromeasure"/>
    <category term="lapt:/a:symantec:veritas_netbackup_operations_manager"/>
    <category term="lapt:/a:symantec:veritas_storage_foundation_cluster_file_system"/>
    <category term="lapt:/a:symantec:veritas_storage_foundation_manager"/>
    <sec:identifier>VRDA-091211-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091210-003:HP OpenView Network Node Manager (OV NNM) &#12395;&#12362;&#12369;&#12427;&#12522;&#12514;&#12540;&#12488;&#12363;&#12425;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-003_AD_1.html</id>
    <published>2009-12-10T17:45:00+09:00</published>
    <updated>2009-12-10T17:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:openview_network_node_manager"/>
    <sec:identifier>VRDA-091210-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091210-002:Adobe Flash Player &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-002_AD_1.html</id>
    <published>2009-12-10T14:37:00+09:00</published>
    <updated>2009-12-10T14:37:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Critical vulnerabilities have been identified in Adobe Flash Player version 10.0.32.18 and earlier.  These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:adobe_air"/>
    <category term="cpe:/a:adobe:flash_player"/>
    <category term="lapt:/a:adobe:flash:cs3::pro"/>
    <category term="lapt:/a:adobe:flash:cs4::pro"/>
    <category term="lapt:/a:adobe:flex"/>
    <sec:identifier>VRDA-091210-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091210-001:Ruby &#12395;&#12362;&#12369;&#12427; String &#12463;&#12521;&#12473;&#12398;&#35079;&#25968;&#12398;&#12513;&#12477;&#12483;&#12489;&#12395;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-001_AD_1.html</id>
    <published>2009-12-10T14:30:00+09:00</published>
    <updated>2009-12-10T14:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
String#ljust, String#centerおよびString#rjustにヒープオーバーフローが発見されました。これはある稀なケースにおいて攻撃者に任意のコードの実行を許します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091210-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:ruby:ruby"/>
    <sec:identifier>VRDA-091210-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091209-005:Novell iPrint Client for Windows &#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-005_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-005_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-005_AD_1.html</id>
    <published>2009-12-09T17:21:00+09:00</published>
    <updated>2009-12-09T17:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CVE-2009-1569 found by Carsten Eiram, Secunia Research. Novell iPrint Client &quot;target-frame&quot; Buffer Overflowgs()&quot; function and Novell iPrint Client boundary error in the parsing of certain time information&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-005_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:novell:iprint"/>
    <sec:identifier>VRDA-091209-005</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#568372:NTP &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU568372_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU568372_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU568372_AD_1.html</id>
    <published>2009-12-09T17:09:00+09:00</published>
    <updated>2009-12-09T17:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
NTP には、mode 7 パケットの処理に起因する脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU568372_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:network_time_protocol_project:ntp"/>
    <sec:identifier>JVNVU#568372</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#49602378:SEIL/B1 &#12398;&#35469;&#35388;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49602378_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49602378_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49602378_AD_1.html</id>
    <published>2009-12-09T15:17:00+09:00</published>
    <updated>2009-12-09T15:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SEIL/B1 には、PPP アクセスコンセントレータ (PPPAC) 機能の実装上の問題により、認証が適切に行われない可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49602378_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:internet_initiative_japan:seil_b1"/>
    <sec:identifier>JVN#49602378</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091209-004:Microsoft &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-004_AD_1.html</id>
    <published>2009-12-09T14:56:00+09:00</published>
    <updated>2009-12-09T14:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ情報は 2009 年 12 月 9 日に公開したセキュリティ情報の一覧です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:office:2003"/>
    <category term="cpe:/a:microsoft:office:xp"/>
    <category term="cpe:/a:microsoft:project:2000"/>
    <category term="cpe:/a:microsoft:project:2002"/>
    <category term="cpe:/a:microsoft:project:2003"/>
    <category term="cpe:/a:microsoft:works"/>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-091209-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091209-003:Java for Mac OS X 10.6 Update 1 &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#12362;&#12424;&#12403;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#36802;&#22238;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-003_AD_1.html</id>
    <published>2009-12-09T14:08:00+09:00</published>
    <updated>2009-12-09T14:08:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ここでは、Java for Mac OS X 10.6 Release 1 のセキュリティコンテンツについて説明します。これは、ソフトウェア・アップデート の環境設定、または サポートダウンロード からダウンロードしてインストールできます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:mac_os_runtime_for_java"/>
    <sec:identifier>VRDA-091209-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091209-002:Java for Mac OS X 10.5 Update 6 &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#12362;&#12424;&#12403;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#21046;&#38480;&#36802;&#22238;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-002_AD_1.html</id>
    <published>2009-12-09T14:02:00+09:00</published>
    <updated>2009-12-09T14:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ここでは、Java for Mac OS X 10.5 Release 6 のセキュリティコンテンツについて説明します。これは、ソフトウェア・アップデート の環境設定、または サポートダウンロード からダウンロードしてインストールできます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:mac_os_runtime_for_java"/>
    <sec:identifier>VRDA-091209-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091209-001:Solaris &#12398; Python &#12395;&#35079;&#25968;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-001_AD_1.html</id>
    <published>2009-12-09T09:36:00+09:00</published>
    <updated>2009-12-09T09:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple buffer and integer overflow vulnerabilities in Python (see python(1)) may allow a local or remote unprivileged user to execute arbitrary code with the privileges of the Python application or crash a Python application resulting in a Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091209-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <category term="lapt:/a:python:python"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-091209-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091208-002:Linux &#12459;&#12540;&#12493;&#12523;&#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#26119;&#26684;&#12362;&#12424;&#12403;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475;&#65288;DoS&#65289;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-002_AD_1.html</id>
    <published>2009-12-08T17:56:00+09:00</published>
    <updated>2009-12-08T17:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Two vulnerabilities have been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service or gain elevated privileges.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:linux:linux_kernel"/>
    <sec:identifier>VRDA-091208-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091208-001:AROUNDMe &#12395;&#12362;&#12369;&#12427;&#12522;&#12514;&#12540;&#12488;&#12501;&#12449;&#12452;&#12523;&#12452;&#12531;&#12463;&#12523;&#12540;&#12489;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-001_OT_1.html</id>
    <published>2009-12-08T17:31:00+09:00</published>
    <updated>2009-12-08T17:31:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Input passed to the &quot;language_path&quot; parameter in components/core/connect.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091208-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="lapt:/a:barnraiser:aroundme"/>
    <sec:identifier>VRDA-091208-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#36207497:Active! mail 2003 &#12395;&#12362;&#12369;&#12427; Cookie &#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36207497_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36207497_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36207497_AD_1.html</id>
    <published>2009-12-08T17:04:00+09:00</published>
    <updated>2009-12-08T17:04:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
トランスウエアが提供する Active! mail 2003 には、Cookie が漏えいする脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36207497_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:transware:active_mail"/>
    <sec:identifier>JVN#36207497</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#85821104:Active! mail 2003 &#12395;&#12362;&#12369;&#12427;&#12475;&#12483;&#12471;&#12519;&#12531; ID &#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN85821104_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN85821104_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN85821104_AD_1.html</id>
    <published>2009-12-08T16:45:00+09:00</published>
    <updated>2009-12-08T16:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
トランスウエアが提供する Active! mail 2003 には、セッション ID が漏えいする脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN85821104_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:transware:active_mail"/>
    <sec:identifier>JVN#85821104</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#49083120:Active! mail 2003 &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49083120_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49083120_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49083120_AD_1.html</id>
    <published>2009-12-08T15:21:00+09:00</published>
    <updated>2009-12-08T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
トランスウエアが提供する Active! mail 2003 には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN49083120_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:transware:active_mail"/>
    <sec:identifier>JVN#49083120</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091207-001:Jasc Paint Shop Pro &#12398; PNG &#12501;&#12449;&#12452;&#12523;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091207-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091207-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091207-001_OT_1.html</id>
    <published>2009-12-07T16:58:00+09:00</published>
    <updated>2009-12-07T16:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The vulnerability is caused due to a boundary error in the processing of PNG files. This can be exploited to cause a stack-based buffer overflow when a PNG file with e.g. a specially crafted &quot;pHYs&quot; chunk is opened.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091207-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:corel:paint_shop_pro"/>
    <sec:identifier>VRDA-091207-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#79762947:EC-CUBE &#12395;&#12362;&#12369;&#12427;&#24773;&#22577;&#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN79762947_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN79762947_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN79762947_AD_1.html</id>
    <published>2009-12-07T11:16:00+09:00</published>
    <updated>2009-12-07T11:16:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
株式会社ロックオンが提供する EC-CUBE には、情報漏えいの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN79762947_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:lockon:ec-cube"/>
    <sec:identifier>JVN#79762947</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091204-002:Sun Java System Portal &#12469;&#12540;&#12496; &#12398; Gateway &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-002_AD_1.html</id>
    <published>2009-12-04T18:44:00+09:00</published>
    <updated>2009-12-04T18:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple Cross-Site Scripting (XSS) security vulnerabilities exist in Sun Java System Portal Server's Gateway that may allow remote users to execute arbitrary JavaScript code in a user's web browser.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:java_system_portal_server"/>
    <sec:identifier>VRDA-091204-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091204-001:Adobe Illustrator &#12398; EPS &#12501;&#12449;&#12452;&#12523;&#20966;&#29702;&#12395;&#12498;&#12540;&#12503;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-001_OT_1.html</id>
    <published>2009-12-04T18:27:00+09:00</published>
    <updated>2009-12-04T18:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Adobe Illustrator, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error when processing Encapsulated Postscript (.eps) files containing overly long data, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091204-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="lapt:/a:adobe:illustrator"/>
    <sec:identifier>VRDA-091204-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091203-003:HP NonStop &#12469;&#12540;&#12496;&#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#26119;&#26684;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-003_AD_1.html</id>
    <published>2009-12-03T16:24:00+09:00</published>
    <updated>2009-12-03T16:24:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential vulnerability has been identified with the HP NonStop Servers. The vulnerability could be exploited locally resulting in an unauthorized access to data, Denial of Service (DoS), or execution of arbitrary code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:hp:nonstop_server"/>
    <sec:identifier>VRDA-091203-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091203-002:Novell eDirectory &#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-002_AD_1.html</id>
    <published>2009-12-03T15:23:00+09:00</published>
    <updated>2009-12-03T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Novell eDirectory permits unauthenticated users to query the server for information about specific objects.  The user can send a service request (NDS Verb 0x1) that has integer used in a memory allocation. A large integer can result in an integer wrap and a subsequent allocation returning an insufficient buffer, resulting in a heap-based buffer overflow.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:novell:edirectory"/>
    <sec:identifier>VRDA-091203-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091203-001:BlackBerry &#12398; PDF &#34920;&#31034;&#12434;&#12469;&#12509;&#12540;&#12488;&#12377;&#12427; BlackBerry Ecnterprise Server &#12398; BlackBerry Attachment Service &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-001_AD_1.html</id>
    <published>2009-12-03T15:23:00+09:00</published>
    <updated>2009-12-03T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This advisory describes security issues that the BlackBerry Attachment Service component of the BlackBerry Enterprise Server is susceptible to. The issues relate to the handling of malformed and possibly malicious PDF files.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091203-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:rim:blackberry_enterprise_server"/>
    <category term="lapt:/a:rim:blackberry_professional"/>
    <sec:identifier>VRDA-091203-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091202-001:IBM WebSphere Portal &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091202-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091202-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091202-001_AD_1.html</id>
    <published>2009-12-02T16:48:00+09:00</published>
    <updated>2009-12-02T16:48:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
IBM WebSphere Portal and IBM Lotus Web Content Management (WCM) periodically provides service releases integrating code fixes for the product.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091202-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:ibm:websphere_portal"/>
    <sec:identifier>VRDA-091202-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091201-002:FreeBSD &#12398; Run-Time Link-Editor &#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#26119;&#26684;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-002_AD_1.html</id>
    <published>2009-12-01T18:11:00+09:00</published>
    <updated>2009-12-01T18:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A short time ago a &quot;local root&quot; exploit was posted to the full-disclosure mailing list; as the name suggests, this allows a local user to execute arbitrary code as root.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:freebsd:freebsd"/>
    <sec:identifier>VRDA-091201-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091201-001:Ruby on Rails &#12398; "strip_tags" &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-001_AD_1.html</id>
    <published>2009-12-01T18:05:00+09:00</published>
    <updated>2009-12-01T18:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Rails 2.3.5 was released over the weekend which provides several bug-fixes and one security fix. It should be fully compatible with all prior 2.3.x releases and can be easily upgraded to with “gem update rails”. The most interesting bits can be summarized in three points.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091201-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:david_heinemeier_hansson:ruby_on_rails"/>
    <sec:identifier>VRDA-091201-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#261869:&#35079;&#25968;&#12398; SSL VPN (Web VPN) &#35069;&#21697;&#12395;&#12362;&#12356;&#12390;&#12454;&#12455;&#12502;&#12502;&#12521;&#12454;&#12470;&#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12364;&#36802;&#22238;&#12373;&#12428;&#12427;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU261869_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU261869_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU261869_AD_1.html</id>
    <published>2009-12-01T17:18:00+09:00</published>
    <updated>2009-12-01T17:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
複数の SSL VPN (Web VPN) 製品には、ウェブブラウザのセキュリティメカニズムを迂回可能な問題が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU261869_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/t::ssl_vpn"/>
    <sec:identifier>JVNVU#261869</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091130-002:Solaris &#12398; BIND &#12395;&#12362;&#12369;&#12427; DNS &#12461;&#12515;&#12483;&#12471;&#12517;&#27738;&#26579;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-002_AD_1.html</id>
    <published>2009-11-30T15:41:00+09:00</published>
    <updated>2009-11-30T15:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A security vulnerability in the BIND DNS software shipped with Solaris may allow a remote user who is able to perform recursive queries to cause a server that is configured to support DNSSEC validation and recursive client queries to return incorrect addresses for Internet hosts, thereby redirecting end users to unintended hosts or services.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:isc:bind"/>
    <category term="cpe:/o:sun:solaris"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-091130-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091130-001:HP-UX OpenSSL &#12395;&#12362;&#12369;&#12427;&#12487;&#12540;&#12479;&#25407;&#20837;&#12289;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-001_AD_1.html</id>
    <published>2009-11-30T09:14:00+09:00</published>
    <updated>2009-11-30T09:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential security vulnerability has been identified with HP-UX OpenSSL. The vulnerability could be exploited remotely to inject unauthorized data or to create a Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091130-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openssl:openssl"/>
    <category term="cpe:/o:hp:hp-ux"/>
    <sec:identifier>VRDA-091130-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091127-001:IBM DB2 "DASAUTO" &#12467;&#12510;&#12531;&#12489;&#12395;&#12424;&#12427;&#27177;&#38480;&#26119;&#26684;&#12398;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091127-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091127-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091127-001_AD_1.html</id>
    <published>2009-11-27T17:42:00+09:00</published>
    <updated>2009-11-27T17:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
DASAUTO COMMAND CAN BE RUN BY NON-PRIVILEGED USERS&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091127-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:db2"/>
    <sec:identifier>VRDA-091127-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091126-003:Symantec&#8217;s Altiris Deployment and Notification Management Web Console RunCmd Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-003_AD_1.html</id>
    <published>2009-11-26T17:52:00+09:00</published>
    <updated>2009-11-26T17:52:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Symantec’s Altiris Deployment Solution, Notification Server and Symantec Management Platform web consoles install a vulnerable ActiveX control. Exploitation of one of the methods used by this control could possibly lead to unauthorized information disclosure, system information corruption or potentially allow arbitrary code execution in the context of the user’s browser. Successful exploitation would require user interaction to download malicious code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:altiris_deployment_solution"/>
    <category term="lapt:/a:symantec:altiris_notification_server"/>
    <category term="lapt:/a:symantec:management_platform"/>
    <sec:identifier>VRDA-091126-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091126-002:Security Vulnerability in the Timeout Mechanism of Solaris sshd(1M) may Lead to a Denial of Service (DoS)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-002_AD_1.html</id>
    <published>2009-11-26T17:06:00+09:00</published>
    <updated>2009-11-26T17:06:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A security vulnerability in the timeout mechanism of Solaris sshd(1M) may allow a remote unprivileged user to cause a Denial of Service (DoS) condition. If this issue is exploited, the sshd(1M) daemon will stop accepting new ssh(1) connections.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openbsd:openssh"/>
    <category term="cpe:/o:sun:solaris:10"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-091126-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091126-001:VMware Products Multiple Code Execution and Security Bypass Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-001_AD_1.html</id>
    <published>2009-11-26T17:01:00+09:00</published>
    <updated>2009-11-26T17:01:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Updated Java JRE packages and Tomcat packages address several security issues. Updates for the ESX Service Console and vMA include kernel, ntp, Python, bind libxml, libxml2, curl and gnutil packages. ntp is also updated for ESXi userworlds.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091126-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <category term="cpe:/a:vmware:server"/>
    <category term="lapt:/a:vmware:esxi"/>
    <category term="lapt:/a:vmware:vcenter_server"/>
    <category term="lapt:/a:vmware:vma"/>
    <sec:identifier>VRDA-091126-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091125-003:HP Operations Manager for Windows, Remote Unauthorized Access</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-003_AD_1.html</id>
    <published>2009-11-25T14:44:00+09:00</published>
    <updated>2009-11-25T14:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential security vulnerability has been identified with HP Operations Manager for Windows. The vulnerability could be exploited remotely to gain unauthorized access.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:openview_operations"/>
    <category term="lapt:/a:hp:hp_operations_manager"/>
    <sec:identifier>VRDA-091125-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091125-002:PHP Security Bypass and DoS Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-002_AD_1.html</id>
    <published>2009-11-25T14:03:00+09:00</published>
    <updated>2009-11-25T14:03:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Added &quot;max_file_uploads&quot; INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion. Added missing sanity checks around exif processing. Fixed a safe_mode bypass in tempnam(). Fixed a open_basedir bypass in posix_mkfifo(). Fixed bug #50063 (safe_mode_include_dir fails). Fixed bug #44683 (popen crashes when an invalid mode is passed).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php"/>
    <sec:identifier>VRDA-091125-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091125-001:ISC BIND 9 DNSSEC Cache Poisoning Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-001_AD_1.html</id>
    <published>2009-11-25T13:38:00+09:00</published>
    <updated>2009-11-25T13:38:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A nameserver with DNSSEC validation enabled may incorrectly add records to its cache from the additional section of responses received during resolution of a recursive client query. This behavior only occurs when processing client queries with checking disabled (CD) at the same time as requesting DNSSEC records (DO).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091125-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:isc:bind"/>
    <sec:identifier>VRDA-091125-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091124-003:&#12510;&#12452;&#12463;&#12525;&#12477;&#12501;&#12488; &#12475;&#12461;&#12517;&#12522;&#12486;&#12451; &#12450;&#12489;&#12496;&#12452;&#12470;&#12522;(977981) Internet Explorer &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-003_AD_1.html</id>
    <published>2009-11-24T16:49:00+09:00</published>
    <updated>2009-11-24T16:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
この脆弱性は Internet Explorer の無効なポインター参照が原因で起こります。CSS/Style オブジェクトが削除された後でも、特定の状況でそのオブジェクトにアクセスすることができる可能性があります。特別な細工がされた攻撃で、解放されたオブジェクトにアクセスしようとしている Internet Explorer が攻撃者が提供したコードを実行する可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:ie"/>
    <sec:identifier>VRDA-091124-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091124-002:CubeCart "productId" Parameter Remote SQL Injection Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-002_AD_1.html</id>
    <published>2009-11-24T09:50:00+09:00</published>
    <updated>2009-11-24T09:50:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in CubeCart, which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error in the &quot;includes/content/viewProd.inc.php&quot; script when processing the &quot;productId&quot; parameter, which could be exploited by malicious people to conduct SQL injection attacks.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:devellion:cubecart"/>
    <sec:identifier>VRDA-091124-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091124-001:Two Security Vulnerabilities in SAMBA(7) May Allow Unauthorized Access to the Remote Root Filesystem or May Lead to a Denial of Service Condition</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-001_AD_1.html</id>
    <published>2009-11-24T09:35:00+09:00</published>
    <updated>2009-11-24T09:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Two Security Vulnerabilities in SAMBA(7) May Allow Unauthorized Access to the Remote Root Filesystem or May Lead to a Denial of Service (DoS) Condition&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091124-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <category term="cpe:/o:sun:solaris:9"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-091124-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091119-002:Serv-U TEA Decoding Remote Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-002_AD_1.html</id>
    <published>2009-11-19T17:52:00+09:00</published>
    <updated>2009-11-19T17:52:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Serv-U, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing a hexadecimal hepresentation of a string using a TEA decoding algorithm, which could allow remote attackers to crash an affected server or execute arbitrary code via a specially crafted request.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:rhino_software:serv-u"/>
    <sec:identifier>VRDA-091119-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091119-001:OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-001_AD_1.html</id>
    <published>2009-11-19T17:48:00+09:00</published>
    <updated>2009-11-19T17:48:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to create a Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091119-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:openview_network_node_manager"/>
    <sec:identifier>VRDA-091119-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#01245481:Redmine &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01245481_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01245481_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01245481_AD_1.html</id>
    <published>2009-11-19T16:37:00+09:00</published>
    <updated>2009-11-19T16:37:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Redmine には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01245481_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:redmine:redmine"/>
    <sec:identifier>JVN#01245481</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#87341298:Redmine &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87341298_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87341298_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87341298_AD_1.html</id>
    <published>2009-11-19T16:27:00+09:00</published>
    <updated>2009-11-19T16:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Redmine には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87341298_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:redmine:redmine"/>
    <sec:identifier>JVN#87341298</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091118-002:Wikipedia Toolbar for Firefox Cross-Context Scripting Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-002_AD_1.html</id>
    <published>2009-11-18T17:32:00+09:00</published>
    <updated>2009-11-18T17:32:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Fixed a security vulnerability (carried over from unreleased version 0.5.9.1)&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a::wikipedia_toolbar"/>
    <sec:identifier>VRDA-091118-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091118-001:Gimp PSD Image Parsing Integer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-001_AD_1.html</id>
    <published>2009-11-18T17:29:00+09:00</published>
    <updated>2009-11-18T17:29:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Secunia Research has discovered a vulnerability in Gimp, which can be 
exploited by malicious people to potentially compromise a user's
system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091118-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:gnu:gimp"/>
    <sec:identifier>VRDA-091118-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091117-002:ToutVirtual VirtualIQ Remote Code Execution Vulnerability and Infomation Disclusure.</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-002_AD_1.html</id>
    <published>2009-11-17T18:27:00+09:00</published>
    <updated>2009-11-17T18:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities have been identified in ToutVirtual VirtualIQ Pro, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information, manipulate data, or compromise a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:toutvirtual:virtualiq_pro"/>
    <sec:identifier>VRDA-091117-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091117-001:XOOPS Profiles Activation Security Bypass Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-001_AD_1.html</id>
    <published>2009-11-17T18:17:00+09:00</published>
    <updated>2009-11-17T18:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The problem is that any user not activated may request and receive their activation code via email by using the activation resend function. For those sites that require administrative approval, this is a bypass of the approval process and the administrator isn't even notified it occurred.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091117-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:xoops:xoops"/>
    <sec:identifier>VRDA-091117-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091116-003:libexif "exif_entry_fix()" Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-003_AD_1.html</id>
    <published>2009-11-16T18:12:00+09:00</published>
    <updated>2009-11-16T18:12:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Fixed a heap buffer overflow during tag format conversion&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a::libexif"/>
    <sec:identifier>VRDA-091116-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091116-002:IBM WebSphere Application Server Administration Console cross-site scripting</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-002_AD_1.html</id>
    <published>2009-11-16T13:19:00+09:00</published>
    <updated>2009-11-16T13:19:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
IBM WebSphere Application Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input in the Administration Console. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:websphere_application_server"/>
    <sec:identifier>VRDA-091116-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091116-001:&#12510;&#12452;&#12463;&#12525;&#12477;&#12501;&#12488; &#12475;&#12461;&#12517;&#12522;&#12486;&#12451; &#12450;&#12489;&#12496;&#12452;&#12470;&#12522; (977544) SMB &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12469;&#12540;&#12499;&#12473;&#25298;&#21542;&#12364;&#36215;&#12371;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-001_AD_1.html</id>
    <published>2009-11-16T13:11:00+09:00</published>
    <updated>2009-11-16T13:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Server Message Block (SMB) プロトコルに存在する可能性のあるサービス拒否の脆弱性が新たに一般で報告され、マイクロソフトが現在調査中です。この脆弱性は、ユーザーのシステムが制御されたり、ユーザーのシステム上に悪意のあるソフトウェアがインストールされるようなものではありません。マイクロソフトはこの脆弱性に対する詳細な悪用コードが一般に公開されていることを認識しています。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091116-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_server_2008:-"/>
    <category term="lapt:/o:microsoft:windows_7"/>
    <sec:identifier>VRDA-091116-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091113-003:GIMP "ReadImage()" BMP Image Parsing Integer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-003_AD_1.html</id>
    <published>2009-11-13T17:32:00+09:00</published>
    <updated>2009-11-13T17:32:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in GIMP, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an integer overflow error in the &quot;ReadImage()&quot; [plug-ins/file-bmp/bmp-read.c] function when processing malformed BMP images, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted image file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:gnu:gimp"/>
    <sec:identifier>VRDA-091113-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091113-002:WordPress&#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-002_AD_1.html</id>
    <published>2009-11-13T17:28:00+09:00</published>
    <updated>2009-11-13T17:28:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wordpress:wordpress"/>
    <sec:identifier>VRDA-091113-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091113-001:safari &#12395;&#12362;&#12369;&#12427;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-001_AD_1.html</id>
    <published>2009-11-13T09:45:00+09:00</published>
    <updated>2009-11-13T09:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This document describes the security content of Safari 4.0.4.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091113-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:safari"/>
    <sec:identifier>VRDA-091113-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091112-001:Workaround available for potential Photoshop Elements privilege escalation issue</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091112-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091112-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091112-001_AD_1.html</id>
    <published>2009-11-12T17:09:00+09:00</published>
    <updated>2009-11-12T17:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A moderate vulnerability has been identified in Adobe Photoshop Elements versions 8.0 and 7.0. The vulnerability could allow a user with valid login credentials and/or physical access, who successfully exploits the vulnerability, to execute arbitrary commands with elevated privileges.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091112-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:photoshop_elements"/>
    <sec:identifier>VRDA-091112-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091111-003:2009 &#24180; 11 &#26376;&#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#24773;&#22577;(Microsoft)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-003_AD_1.html</id>
    <published>2009-11-11T16:00:00+09:00</published>
    <updated>2009-11-11T16:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ情報は 2009 年 11 月 6 日に公開したセキュリティ情報の一覧です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:excel_viewer"/>
    <category term="cpe:/a:microsoft:excel_viewer:2003"/>
    <category term="cpe:/a:microsoft:office:2003"/>
    <category term="cpe:/a:microsoft:office:2007"/>
    <category term="cpe:/a:microsoft:office:xp"/>
    <category term="cpe:/a:microsoft:word_viewer"/>
    <category term="cpe:/a:microsoft:word_viewer:2003"/>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <sec:identifier>VRDA-091111-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091111-002:HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-002_AD_1.html</id>
    <published>2009-11-11T15:53:00+09:00</published>
    <updated>2009-11-11T15:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Potential security vulnerabilities have been identified in Java Runtime Environment (JRE) and Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote unauthorized access, privilege escalation, and Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:java_jre-jdk"/>
    <category term="cpe:/o:hp:hp-ux"/>
    <sec:identifier>VRDA-091111-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091111-001:&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488; 2009-006 / Mac OS X v10.6.2 &#12395;&#12388;&#12356;&#12390;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-001_AD_1.html</id>
    <published>2009-11-11T10:28:00+09:00</published>
    <updated>2009-11-11T10:28:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
セキュリティアップデート 2009-006 / Mac OS X v10.6.2 のセキュリティコンテンツについて説明します。これらは、Mac のシステム環境設定の「ソフトウェアアップデート」、または「サポートダウンロード」のページからダウンロードしてインストールできます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091111-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:apple:mac_os_x"/>
    <category term="cpe:/o:apple:mac_os_x_server"/>
    <sec:identifier>VRDA-091111-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091110-003:Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to DoS Unauthorized Access to Data</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-003_AD_1.html</id>
    <published>2009-11-10T16:00:00+09:00</published>
    <updated>2009-11-10T16:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Two security vulnerabilities exist in the Apache 2 mod_perl2(3) module
components which affect the Apache 2.0 web server bundled with Solaris
10 and the Apache 2.2 web server bundled with OpenSolaris.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10.0"/>
    <category term="lapt:/a:sun:apache"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-091110-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091110-002:openssl - Check-in [18790]</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-002_AD_1.html</id>
    <published>2009-11-10T15:27:00+09:00</published>
    <updated>2009-11-10T15:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Disable renegotiation completely - this fixes a severe security problem at the cost of breaking all renegotiation.Renegotiation can be re-enabled by setting OPENSSL_ENABLE_UNSAFE_LEGACY_SESSION_RENEGOTATION at compile-time. This is really not recommended.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openssl:openssl"/>
    <sec:identifier>VRDA-091110-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091110-001:Vulnerability in Citrix NetScaler, Citrix NetScaler Application Firewall and Citrix Access Gateway Enterprise Edition could result in DoS.</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-001_AD_1.html</id>
    <published>2009-11-10T14:30:00+09:00</published>
    <updated>2009-11-10T14:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in components of the Citrix NetScaler, NetScaler Application Firewall and Access Gateway Enterprise Edition that, when triggered, results in a denial of service.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091110-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:citrix:access_gateway"/>
    <category term="cpe:/a:citrix:netscaler"/>
    <category term="lapt:/a:citrix:netscaler_application_firewall"/>
    <sec:identifier>VRDA-091110-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091106-003:A Security Vulnerability in Solaris Sockets Direct Protocol (SDP) Driver (sdp(7D)) may Allow Users to Exhaust Kernel Memory</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-003_AD_1.html</id>
    <published>2009-11-06T17:57:00+09:00</published>
    <updated>2009-11-06T17:57:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A security vulnerability in Solaris Sockets Direct Protocol (SDP) driver (sdp(7D)) may allow a local or remote unprivileged user to exhaust all kernel memory.  This is a type of Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <sec:identifier>VRDA-091106-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091106-002:HP Power Manager, Remote Execution of Arbitrary Code</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-002_AD_1.html</id>
    <published>2009-11-06T17:49:00+09:00</published>
    <updated>2009-11-06T17:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential security vulnerability has been identified with HP Power Manager. The vulnerability could be exploited remotely to execute arbitrary code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:hp:power_manager"/>
    <sec:identifier>VRDA-091106-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091106-001:Advance notification of Security Updates for Java SE</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-001_AD_1.html</id>
    <published>2009-11-06T17:38:00+09:00</published>
    <updated>2009-11-06T17:38:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
On November 3, 2009, Sun will release the following security updates:
JDK and JRE 6 Update 17,JDK and JRE 5.0 Update 22,SDK and JRE 1.4.2_24,SDK and JRE 1.3.1_27&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091106-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <category term="cpe:/a:sun:sdk"/>
    <sec:identifier>VRDA-091106-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091105-001:APSB09-16 Security updates available for Shockwave Player</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091105-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091105-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091105-001_AD_1.html</id>
    <published>2009-11-05T16:06:00+09:00</published>
    <updated>2009-11-05T16:06:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.1.601 and earlier versions. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations using the instructions provided below.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091105-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:shockwave_player"/>
    <sec:identifier>VRDA-091105-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#75694913:Roundcube Webmail &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75694913_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75694913_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75694913_AD_1.html</id>
    <published>2009-11-04T16:03:00+09:00</published>
    <updated>2009-11-04T16:03:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Roundcube Webmail Project が提供する Roundcube Webmail には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75694913_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:roundcube:webmail"/>
    <sec:identifier>JVN#75694913</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#72974205:Roundcube Webmail &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72974205_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72974205_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72974205_AD_1.html</id>
    <published>2009-11-04T15:54:00+09:00</published>
    <updated>2009-11-04T15:54:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Roundcube Webmail Project が提供する Roundcube Webmail には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72974205_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:roundcube:webmail"/>
    <sec:identifier>JVN#72974205</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091104-003:Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-003_AD_1.html</id>
    <published>2009-11-04T14:36:00+09:00</published>
    <updated>2009-11-04T14:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple security vulnerabilities in Adobe Reader versions 9.x before 9.1.4, 8.x before 8.1.7 and 7.x before 7.1.4 may allow remote unprivileged users to execute arbitrary code or crash the Adobe Reader application, thereby causing a Denial of Service (DoS) condition. These vulnerabilities may be exploited via specially crafted PDF files.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <category term="cpe:/o:sun:solaris"/>
    <sec:identifier>VRDA-091104-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091104-002:Joomla Jumi Component Backdoor Security Issue</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-002_AD_1.html</id>
    <published>2009-11-04T14:19:00+09:00</published>
    <updated>2009-11-04T14:19:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A security issue has been reported in the Jumi component for Joomla!, which can be exploited by malicious people to potentially compromise a vulnerable system.
The security issue is caused due to a backdoor in the application and can be exploited to potentially execute arbitrary PHP code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:jumi:jumi"/>
    <sec:identifier>VRDA-091104-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091104-001:Symantec Altiris Deployment Solution and Notification Server Management Web Console Browse and Save File ActiveX Overflow</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-001_AD_1.html</id>
    <published>2009-11-04T14:07:00+09:00</published>
    <updated>2009-11-04T14:07:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Symantec’s Altiris Deployment Solution and Notification Server web consoles install a vulnerable ActiveX control. Exploitation of this issue could possibly lead to unauthorized information disclosure, system information corruption or potentially allow arbitrary code execution in the context of the user’s browser. Successful exploitation requires user interaction.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091104-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:altiris_deployment_solution"/>
    <category term="lapt:/a:symantec:altiris_notification_server"/>
    <category term="lapt:/a:symantec:management_platform"/>
    <sec:identifier>VRDA-091104-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VU#180065:Nginx ngx_http_parse_complex_uri() buffer underflow vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU180065_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU180065_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU180065_AD_1.html</id>
    <published>2009-11-04T09:27:00+09:00</published>
    <updated>2009-11-04T09:27:00+09:00</updated>
    <author>
      <name>CERT/CC</name>
    </author>
    <content type="html">
A vulnerability in the nginx web server may allow remote attackers to execute arbitrary code on an affected system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/CERTCC_VU180065_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:igor_sysoev:nginx"/>
    <sec:identifier>VU#180065</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091030-001:VMware hosted products and ESX patches resolve two security issues</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091030-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091030-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091030-001_AD_1.html</id>
    <published>2009-10-30T17:34:00+09:00</published>
    <updated>2009-10-30T17:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
VMware hosted products and ESX patches resolve two security issues.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091030-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:ace"/>
    <category term="cpe:/a:vmware:esx_server"/>
    <category term="cpe:/a:vmware:player"/>
    <category term="cpe:/a:vmware:server"/>
    <category term="cpe:/a:vmware:workstation"/>
    <category term="lapt:/a:vmware:esxi"/>
    <category term="lapt:/a:vmware:fusion"/>
    <sec:identifier>VRDA-091030-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091029-004:Wireshark :: wnpa-sec-2009-08</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-004_AD_1.html</id>
    <published>2009-10-29T15:01:00+09:00</published>
    <updated>2009-10-29T15:01:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Wireshark 1.0.10 fixes the following vulnerabilities:
* The RADIUS dissector could crash.
* The DCERPC/NT dissector could crash.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wireshark:wireshark"/>
    <sec:identifier>VRDA-091029-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091029-003:Wireshark :: wnpa-sec-2009-07</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-003_AD_1.html</id>
    <published>2009-10-29T14:26:00+09:00</published>
    <updated>2009-10-29T14:26:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Wireshark 1.2.3 fixes the following vulnerabilities:
* The Paltalk dissector could crash on alignment-sensitive processors.
* The DCERPC/NT dissector could crash.
* The SMB dissector could crash.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wireshark:wireshark"/>
    <sec:identifier>VRDA-091029-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091029-002:Opera 10.01 for Windows Changelog</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-002_AD_1.html</id>
    <published>2009-10-29T13:15:00+09:00</published>
    <updated>2009-10-29T13:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Opera 10.01 is a recommended security and stability upgrade. Opera highly recommends all users to upgrade to Opera 10.01 to take advantage of these improvements.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:opera:opera_browser"/>
    <sec:identifier>VRDA-091029-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091029-001:Firefox 3.5 &#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12450;&#12489;&#12496;&#12452;&#12470;&#12522;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-001_AD_1.html</id>
    <published>2009-10-29T09:43:00+09:00</published>
    <updated>2009-10-29T09:51:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.5.4 では、いくつかのセキュリティ問題 が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091029-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <sec:identifier>VRDA-091029-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091028-003:Sun Java System Web Server Unspecified Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-003_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-003_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-003_OT_1.html</id>
    <published>2009-10-28T17:05:00+09:00</published>
    <updated>2009-10-28T17:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Sun Java System Web Server, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable web server. This issue is caused by an unspecified buffer overflow error when processing user-supplied requests, which could allow remote attackers to crash an affected web server or execute arbitrary code via a specially crafted packet.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-003_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:sun:java_system_web_server"/>
    <sec:identifier>VRDA-091028-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#13011682:SEIL/X &#12471;&#12522;&#12540;&#12474;&#12362;&#12424;&#12403; SEIL/B1 &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN13011682_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN13011682_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN13011682_AD_1.html</id>
    <published>2009-10-28T15:59:00+09:00</published>
    <updated>2009-10-28T15:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SEIL/X シリーズおよび SEIL/B1 には、サービス運用妨害 (DoS) の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN13011682_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:internet_initiative_japan:seil_b1"/>
    <category term="lapt:/h:internet_initiative_japan:seil_x1"/>
    <category term="lapt:/h:internet_initiative_japan:seil_x2"/>
    <sec:identifier>JVN#13011682</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#06362164:SEIL/X &#12471;&#12522;&#12540;&#12474;&#12362;&#12424;&#12403; SEIL/B1 &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06362164_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06362164_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06362164_AD_1.html</id>
    <published>2009-10-28T15:35:00+09:00</published>
    <updated>2009-10-28T15:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SEIL/X シリーズおよび SEIL/B1 には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN06362164_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:internet_initiative_japan:seil_b1"/>
    <category term="lapt:/h:internet_initiative_japan:seil_x1"/>
    <category term="lapt:/h:internet_initiative_japan:seil_x2"/>
    <sec:identifier>JVN#06362164</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091028-002:Novell eDirectory HTTP Request Remote Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-002_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-002_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-002_OT_1.html</id>
    <published>2009-10-28T14:04:00+09:00</published>
    <updated>2009-10-28T14:04:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the &quot;dhost&quot; service when processing overly long HTTP requests, which could be exploited by remote attackers to crash a vulnerable server or execute arbitrary code via a specially crafted request.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-002_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:novell:edirectory"/>
    <sec:identifier>VRDA-091028-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091028-001:Invalid and tainted utf-8 char crashes perl 5.10.1 in regexp evaluation</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-001_AD_1.html</id>
    <published>2009-10-28T09:10:00+09:00</published>
    <updated>2009-10-28T09:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Tracking down a reason for crashes of a perl process while processing
certain obfuscated spam messages, it turns out that an utf-8 character
with a large (and invalid) codepoint is causing a perl 5.10.1 crash
while matching such string to a particular regular expression.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091028-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:perl:perl"/>
    <sec:identifier>VRDA-091028-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091027-004:Snort 2.8.5 Release</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-004_AD_1.html</id>
    <published>2009-10-27T10:59:00+09:00</published>
    <updated>2009-10-27T10:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Hot on the heels of the Snort 2.8.5 release, a new Snort tarball is now available that fixes a few issues:
* Fixed syslog output when running on Windows.
* Fixed potential segfault when printing IPv6 packets using the -v option. Thanks to Laurent Gaffie for reporting this issue.
* Fixed segfault when additional policies were added during a configuration reload.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:snort:snort"/>
    <sec:identifier>VRDA-091027-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091027-003:HPSBUX02466 SSRT090192 rev.1 - HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-003_AD_1.html</id>
    <published>2009-10-27T10:47:00+09:00</published>
    <updated>2009-10-27T10:47:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Potential security vulnerabilities have been identified with HP-UX running Tomcat-based Servlet Engine. The vulnerabilities could be exploited remotely to cause a Denial of Service (DoS) or unauthorized access. Tomcat-based Servlet Engine is contained in the Apache Web Server Suite.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <category term="cpe:/o:hp:hp-ux"/>
    <sec:identifier>VRDA-091027-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091027-002:About Hotfix 4 for Websense Email Security v7.1</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-002_AD_1.html</id>
    <published>2009-10-27T10:15:00+09:00</published>
    <updated>2009-10-27T10:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This hotfix also includes 2 important security fixes:
* A remote distributed Denial of Services (DoS) vulnerability allowed remote attackers to disable the Websense Email Security Web Administrator service. This vulnerability has been fixed.
* A cross-site scripting (XSS) vulnerability in the Websense Email Security Web Administrator has been fixed.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:websense:websense_email_security"/>
    <sec:identifier>VRDA-091027-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091027-001:WordPress 2.8.5: Hardening Release</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-001_AD_1.html</id>
    <published>2009-10-27T10:04:00+09:00</published>
    <updated>2009-10-27T10:04:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The headline changes in this release are:
* A fix for the Trackback Denial-of-Service attack that is currently being seen.
* Removal of areas within the code where php code in variables was evaluated.
* Switched the file upload functionality to be whitelisted for all users including Admins.
* Retiring of the two importers of Tag data from old plugins.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091027-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wordpress:wordpress"/>
    <sec:identifier>VRDA-091027-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#75368899:IPv6 &#12434;&#23455;&#35013;&#12375;&#12383;&#35079;&#25968;&#12398;&#35069;&#21697;&#12395;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75368899_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75368899_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75368899_AD_1.html</id>
    <published>2009-10-26T15:32:00+09:00</published>
    <updated>2009-10-26T15:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Internet Protocol version 6 (IPv6) を実装した複数の製品には、サービス運用妨害 (DoS) の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN75368899_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/t::ipv6"/>
    <sec:identifier>JVN#75368899</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091026-002:Oracle Critical Patch Update - October 2009</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-002_AD_1.html</id>
    <published>2009-10-26T10:10:00+09:00</published>
    <updated>2009-10-26T10:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This Critical Patch Update contains 38 new security fixes across all products.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:oracle:application_server"/>
    <category term="cpe:/a:oracle:database_server"/>
    <category term="cpe:/a:oracle:e-business_suite"/>
    <category term="cpe:/a:oracle:peoplesoft_enterprise_portal"/>
    <category term="lapt:/a:oracle:agile_engineering_data_management"/>
    <category term="lapt:/a:oracle:autovue"/>
    <category term="lapt:/a:oracle:jdedward_tools"/>
    <category term="lapt:/a:oracle:oracle_business_intelligence_enterprise_edition"/>
    <category term="lapt:/a:oracle:oracle_communications_order_and_service_management"/>
    <category term="lapt:/a:oracle:oracle_jrockit"/>
    <category term="lapt:/a:oracle:oracle_webLogic_portal"/>
    <category term="lapt:/a:oracle:peoplesoft_enterprise_hcm"/>
    <category term="lapt:/a:oracle:peoplesoft_peopletools"/>
    <category term="lapt:/a:oracle:weblogic_server"/>
    <sec:identifier>VRDA-091026-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091026-001:VMware ESX patches for DHCP, Service Console kernel, and JRE resolve multiple security issues</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-001_AD_1.html</id>
    <published>2009-10-26T09:10:00+09:00</published>
    <updated>2009-10-26T09:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Updated DHCP and Kernel packages for ESX 3.5 and ESX 3.0.3 and updated Java JRE packages for ESX 3.5 address several security issues.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091026-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <sec:identifier>VRDA-091026-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#33822756:&#12461;&#12516;&#12494;&#12531;IT&#12477;&#12522;&#12517;&#12540;&#12471;&#12519;&#12531;&#12474;&#35069; ACCESSGUARDIAN &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33822756_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33822756_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33822756_AD_1.html</id>
    <published>2009-10-21T09:13:00+09:00</published>
    <updated>2009-10-21T09:13:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
キヤノンITソリューションズが提供する ACCESSGUARDIAN には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33822756_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:canon:accessguardian"/>
    <sec:identifier>JVN#33822756</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#23108985:&#35079;&#25968;&#12398;&#12469;&#12452;&#12508;&#12454;&#12474;&#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23108985_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23108985_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23108985_AD_1.html</id>
    <published>2009-10-15T16:08:00+09:00</published>
    <updated>2009-10-15T16:08:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
サイボウズ株式会社が提供する複数の製品には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23108985_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cybozu:Mailwize"/>
    <category term="lapt:/a:cybozu:office"/>
    <sec:identifier>JVN#23108985</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#257117:Adobe Reader &#12362;&#12424;&#12403; Acrobat &#12398;&#35079;&#25968;&#12398; JavaScript &#12513;&#12477;&#12483;&#12489;&#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU257117_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU257117_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU257117_AD_1.html</id>
    <published>2009-10-14T17:03:00+09:00</published>
    <updated>2009-10-14T17:03:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Adobe Reader および Acrobat には、JavaScript メソッドの実行を制限する仕組みに脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU257117_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="lapt:/a:adobe:reader"/>
    <sec:identifier>JVNVU#257117</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091013-001:IBM AIX rpc.cmsd Stack Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091013-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091013-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091013-001_AD_1.html</id>
    <published>2009-10-13T10:00:00+09:00</published>
    <updated>2009-10-13T10:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of a stack based buffer overflow vulnerability in IBM Corp.'s AIX could allow an attacker to execute arbitrary code with the privileges of the affected service.
rpc.cmsd, more commonly known as the Calendar Manager Service Daemon, is an RPC application used to manage schedules and calendars. It operates over SUN RPC.
The vulnerability is triggered when handling a request for remote procedure 21. This function takes two arguments, both of which are XDR strings. When copying the first argument into a stack based buffer, the code does not properly verify its length. This results in a stack based buffer overflow vulnerability.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091013-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:ibm:aix"/>
    <category term="lapt:/o:ibm:VIOS"/>
    <sec:identifier>VRDA-091013-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-091008-001:Misconfigured /etc/passwd file may share folders unexpectedly</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091008-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091008-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091008-001_AD_1.html</id>
    <published>2009-10-08T18:00:00+09:00</published>
    <updated>2009-10-08T18:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
If a user in /etc/passwd is misconfigured to have an empty home
directory (::) and the automated [homes] share is enabled, or an
explicit share is created with that username, then any client connecting
to that share name will be able to access the whole filesystem from
root (/) on downwards, subject to local file system permissions
applied to the connecting user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-091008-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:samba:samba"/>
    <sec:identifier>VRDA-091008-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#676492:Wireshark &#12398; erf &#12501;&#12449;&#12452;&#12523;&#20966;&#29702;&#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU676492_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU676492_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU676492_AD_1.html</id>
    <published>2009-10-07T16:43:00+09:00</published>
    <updated>2009-10-07T16:43:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Wireshark には、細工された erf ファイルの処理に脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU676492_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wireshark:wireshark"/>
    <sec:identifier>JVNVU#676492</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#84396512:SugarCRM &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84396512_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84396512_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84396512_AD_1.html</id>
    <published>2009-10-02T15:15:00+09:00</published>
    <updated>2009-10-02T15:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SugarCRM Inc. が提供する SugarCRM には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84396512_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sugarcrm:sugar_community_editons"/>
    <category term="lapt:/a:sugarcrm:sugar_enterprise_editons"/>
    <category term="lapt:/a:sugarcrm:sugar_professional_editons"/>
    <sec:identifier>JVN#84396512</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090930-001:Security Vulnerabilities in Solaris Trusted Extensions Common Desktop Environment (CDE) may allow Privilege Escalation or Mandatory Access Control (MAC) Policy Violation</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090930-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090930-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090930-001_AD_1.html</id>
    <published>2009-09-30T14:23:00+09:00</published>
    <updated>2009-09-30T14:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Security Vulnerabilities in Solaris Trusted Extensions Common Desktop Environment (CDE)
may allow an unprivileged local user to easily execute arbitrary commands with root privileges
or to bypass Mandatory Access Control (MAC) policy.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090930-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <sec:identifier>VRDA-090930-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#65914253:&#35079;&#25968;&#12398; phpspot &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN65914253_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN65914253_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN65914253_AD_1.html</id>
    <published>2009-09-18T19:34:00+09:00</published>
    <updated>2009-09-18T19:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
phpspot が提供する複数の製品には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN65914253_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:phpspot:php_bbs"/>
    <category term="lapt:/a:phpspot:php_bbs_ce"/>
    <category term="lapt:/a:phpspot:php_css_bbs"/>
    <category term="lapt:/a:phpspot:php_monitor_capture_bbs"/>
    <category term="lapt:/a:phpspot:php_rss_builder"/>
    <category term="lapt:/a:phpspot:webshot"/>
    <sec:identifier>JVN#65914253</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#53591199:&#35079;&#25968;&#12398; phpspot &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN53591199_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN53591199_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN53591199_AD_1.html</id>
    <published>2009-09-18T18:38:00+09:00</published>
    <updated>2009-09-18T18:38:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
phpspot が提供する複数の製品には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN53591199_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:phpspot:php_bbs"/>
    <category term="lapt:/a:phpspot:php_bbs_ce"/>
    <category term="lapt:/a:phpspot:php_css_bbs"/>
    <category term="lapt:/a:phpspot:php_monitor_capture_bbs"/>
    <category term="lapt:/a:phpspot:php_rss_builder"/>
    <category term="lapt:/a:phpspot:webshot"/>
    <sec:identifier>JVN#53591199</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#00425482:XF-Section &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00425482_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00425482_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00425482_AD_1.html</id>
    <published>2009-09-17T15:11:00+09:00</published>
    <updated>2009-09-17T15:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
はっぴぃ・りなっくすが提供する XF-Section は、コンテンツのカテゴリ分け機能などを提供する、XOOPS 用モジュールです。XF-Section には、クロスサイトスクリプティングの脆弱性が存在します。

XF-Section の開発は終了しているため、使用を停止してください。同等の機能が実装された他製品に切り替えることをお勧めします。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN00425482_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:happy_linux:xf-section"/>
    <sec:identifier>JVN#00425482</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#39157969:Opera &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12489;&#12497;&#12540;&#12486;&#12451; Cookie &#12398;&#21462;&#12426;&#25201;&#12356;&#12395;&#38306;&#12377;&#12427;&#21839;&#38988;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN39157969_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN39157969_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN39157969_AD_1.html</id>
    <published>2009-09-17T15:05:00+09:00</published>
    <updated>2009-09-17T15:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Opera には、サードパーティ Cookie の取り扱いに問題が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN39157969_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:opera:opera_browser"/>
    <sec:identifier>JVN#39157969</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090917-001:Security Vulnerability in the w(1) Utility may Lead to Execution of Arbitrary Code</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090917-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090917-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090917-001_AD_1.html</id>
    <published>2009-09-17T10:37:00+09:00</published>
    <updated>2009-09-17T10:37:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A heap overflow vulnerability in the w(1) utility may allow a local unprivileged user to execute arbitrary code with root privileges.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090917-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <category term="cpe:/o:sun:solaris:8"/>
    <category term="cpe:/o:sun:solaris:9"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-090917-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#180065:Nginx ngx_http_parse_complex_uri() &#12395;&#12496;&#12483;&#12501;&#12449;&#12450;&#12531;&#12480;&#12540;&#12521;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU180065_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU180065_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU180065_AD_1.html</id>
    <published>2009-09-16T17:02:00+09:00</published>
    <updated>2009-09-16T17:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Nginx ウェブサーバには、バッファアンダーランの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU180065_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:igor_sysoev:nginx"/>
    <sec:identifier>JVNVU#180065</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090914-001:Apple Security Update 2009-005</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090914-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090914-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090914-001_AD_1.html</id>
    <published>2009-09-14T15:35:00+09:00</published>
    <updated>2009-09-14T15:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This document describes Security Update 2009-005, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090914-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:apple:mac_os_x"/>
    <category term="cpe:/o:apple:mac_os_x_server"/>
    <sec:identifier>VRDA-090914-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#135940:Windows SMB version 2 &#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU135940_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU135940_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU135940_AD_1.html</id>
    <published>2009-09-11T15:34:00+09:00</published>
    <updated>2009-09-11T15:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Windows Vista および Server 2008 には、Server Message Block version 2 (SMBv2) メッセージの解析に起因する脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU135940_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_server_2008:::itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:::x32"/>
    <category term="cpe:/o:microsoft:windows_server_2008:::x64"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_vista:::x64"/>
    <sec:identifier>JVNVU#135940</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#05857667:&#26666;&#24335;&#20250;&#31038;&#12487;&#12451;&#12540;&#12450;&#12452;&#12471;&#12540;&#35069; yoyaku_v41 &#12395;&#12362;&#12369;&#12427; OS &#12467;&#12510;&#12531;&#12489;&#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN05857667_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN05857667_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN05857667_AD_1.html</id>
    <published>2009-09-11T15:30:00+09:00</published>
    <updated>2009-09-11T15:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
株式会社ディーアイシーが提供する yoyaku_v41 には、OS コマンドインジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN05857667_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:dic:yoyaku_v41"/>
    <sec:identifier>JVN#05857667</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#336053:Cyrus IMAPd &#12395;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU336053_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU336053_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU336053_AD_1.html</id>
    <published>2009-09-10T17:36:00+09:00</published>
    <updated>2009-09-10T17:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cyrus IMAP サーバには、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU336053_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:project_cyrus:cyrus_imapd"/>
    <sec:identifier>JVNVU#336053</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090910-001:Firefox 3.5.3 &#12522;&#12522;&#12540;&#12473;&#12494;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090910-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090910-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090910-001_AD_1.html</id>
    <published>2009-09-10T16:14:00+09:00</published>
    <updated>2009-09-10T16:14:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.5.3 では、いくつかのセキュリティ問題 が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090910-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090910-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#62211338:Microsoft Windows &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62211338_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62211338_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62211338_AD_1.html</id>
    <published>2009-09-09T15:20:00+09:00</published>
    <updated>2009-09-09T15:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Windows の Windows Media Format Runtime には、特定のファイルの解析に起因するバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62211338_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2000"/>
    <category term="cpe:/o:microsoft:windows_server:2003"/>
    <category term="cpe:/o:microsoft:windows_server:2008"/>
    <category term="cpe:/o:microsoft:windows_server_2003:::x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008:::x64"/>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <category term="cpe:/o:microsoft:windows_vista:::x64"/>
    <category term="cpe:/o:microsoft:windows_xp"/>
    <category term="lapt:/o:microsoft:windows_xp:::professional_x64"/>
    <sec:identifier>JVN#62211338</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090909-002:Security Vulnerabilities in libxml2 Library Related to Parsing of Element Declarations, Notation and Enumeration Attribute Types may Lead to a Denial of Service (DoS)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-002_AD_1.html</id>
    <published>2009-09-09T13:58:00+09:00</published>
    <updated>2009-09-09T13:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Security Vulnerabilities in libxml2 Library Related to Parsing of Element Declarations, Notation and Enumeration Attribute Types may Lead to a Denial of Service (DoS)&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <category term="cpe:/o:sun:solaris:9"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-090909-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090909-001:CERT-FI Advisory on the Outpost24 TCP Issues</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-001_AD_1.html</id>
    <published>2009-09-09T13:38:00+09:00</published>
    <updated>2009-09-09T13:38:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The vulnerabilities described in this advisory can potentially affect systems and applications that run an implementation of TCP protocol (RFC793 et al.). The issues were found by the Sockstress tool developed by Outpost24.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090909-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/t::tcp"/>
    <sec:identifier>VRDA-090909-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090907-001:VMware Security Advisories (VMSAs) : VMSA-2009-0012</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090907-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090907-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090907-001_AD_1.html</id>
    <published>2009-09-07T15:21:00+09:00</published>
    <updated>2009-09-07T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Several security issues are resolved with the latest VMnc codec.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090907-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:ace"/>
    <category term="cpe:/a:vmware:player"/>
    <category term="cpe:/a:vmware:workstation"/>
    <category term="lapt:/a:vmware:workstation_movie_decoder_stand_alone"/>
    <sec:identifier>VRDA-090907-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090904-001:About the security content of Java for Mac OS X 10.5 Update 5</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090904-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090904-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090904-001_AD_1.html</id>
    <published>2009-09-04T14:30:00+09:00</published>
    <updated>2009-09-04T14:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This document describes the security content of Java for Mac OS X 10.5 Update 5.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090904-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:mac_os_x"/>
    <category term="lapt:/a:apple:java"/>
    <sec:identifier>VRDA-090904-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#57040664:ATOK &#12395;&#12362;&#12369;&#12427;&#12473;&#12463;&#12522;&#12540;&#12531;&#12525;&#12483;&#12463;&#12398;&#21046;&#38480;&#22238;&#36991;&#12364;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57040664_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57040664_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57040664_AD_1.html</id>
    <published>2009-09-02T15:21:00+09:00</published>
    <updated>2009-09-02T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ジャストシステムが提供する ATOK には、スクリーンロックの制限を回避可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57040664_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:justsystems:atok"/>
    <category term="lapt:/a:justsystems:atok_smile"/>
    <sec:identifier>JVN#57040664</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090902-001:OpenOffice.org Documents Parsing Code Execution Vulnerabilities / Exploit</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090902-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090902-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090902-001_AD_1.html</id>
    <published>2009-09-02T14:49:00+09:00</published>
    <updated>2009-09-02T14:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to compromise a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090902-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:openoffice.org:openoffice"/>
    <sec:identifier>VRDA-090902-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090901-001:Microsoft Internet Information Server (IIS) FTP server NLST stack buffer overflow</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090901-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090901-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090901-001_AD_1.html</id>
    <published>2009-09-01T13:02:00+09:00</published>
    <updated>2009-09-01T13:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Microsoft IIS FTP server contains a stack buffer overflow in the handling of directory names, which may allow a remote, authenticated attacker to execute arbitrary code on a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090901-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:iis:5.0"/>
    <category term="cpe:/a:microsoft:iis:5.1"/>
    <category term="cpe:/a:microsoft:iis:6.0"/>
    <sec:identifier>VRDA-090901-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#68640473:bingo!CMS core &#12362;&#12424;&#12403; bingo!CMS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN68640473_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN68640473_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN68640473_AD_1.html</id>
    <published>2009-08-27T15:20:00+09:00</published>
    <updated>2009-08-27T15:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
bingo!CMS core および bingo!CMS には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN68640473_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:itd:bingo_cms"/>
    <category term="lapt:/a:itd:bingo_cms_core"/>
    <sec:identifier>JVN#68640473</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090826-001:VMware Hosted products update libpng and Apache HTTP Server</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090826-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090826-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090826-001_OT_1.html</id>
    <published>2009-08-26T13:29:00+09:00</published>
    <updated>2009-08-26T13:29:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Updated VMware Hosted products address security issues in libpng and the Apace HTTP Server.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090826-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:vmware:ace"/>
    <category term="cpe:/a:vmware:player"/>
    <category term="cpe:/a:vmware:workstation"/>
    <sec:identifier>VRDA-090826-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#31035930:SugarCRM &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31035930_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31035930_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31035930_AD_1.html</id>
    <published>2009-08-26T13:20:00+09:00</published>
    <updated>2009-08-26T13:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SugarCRM Inc. が提供する SugarCRM には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31035930_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sugarcrm:sugar_community_editons"/>
    <category term="lapt:/a:sugarcrm:sugar_enterprise_editons"/>
    <category term="lapt:/a:sugarcrm:sugar_professional_editons"/>
    <sec:identifier>JVN#31035930</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#20478978:&#12469;&#12452;&#12488;&#12459;&#12524;&#12531;&#12480; mycaljp &#12395;&#12399;&#12289;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;&#12364;&#23384;&#22312;&#12375;&#12414;&#12377;&#12290;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20478978_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20478978_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20478978_AD_1.html</id>
    <published>2009-08-21T15:21:00+09:00</published>
    <updated>2009-08-21T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
サイトカレンダ mycaljp には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20478978_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:geeklog:mycaljp"/>
    <sec:identifier>JVN#20478978</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090821-001:Mozilla Thunderbird 2.0.0.23 &#12522;&#12522;&#12540;&#12473;&#12494;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090821-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090821-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090821-001_AD_1.html</id>
    <published>2009-08-21T15:17:00+09:00</published>
    <updated>2009-08-21T15:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SSL で保護された通信の情報漏えいの問題が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090821-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>VRDA-090821-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090820-002:Firewall Services Module Crafted ICMP Message</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-002_AD_1.html</id>
    <published>2009-08-20T14:02:00+09:00</published>
    <updated>2009-08-20T14:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability exists in the Cisco Firewall Services Module (FWSM) for the Catalyst 6500 Series Switches and Cisco 7600 Series Routers. The vulnerability may cause the FWSM to stop forwarding traffic and may be triggered while processing multiple, crafted ICMP messages.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:cisco:fwsm"/>
    <sec:identifier>VRDA-090820-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090820-001:Cisco IOS XR Software Border Gateway Protocol Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-001_AD_1.html</id>
    <published>2009-08-20T13:58:00+09:00</published>
    <updated>2009-08-20T13:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco IOS XR contains multiple vulnerabilities in the Border Gateway Protocol (BGP) feature.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090820-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:cisco:ios_xr"/>
    <sec:identifier>VRDA-090820-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#21388501:ColdFusion &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN21388501_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN21388501_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN21388501_AD_1.html</id>
    <published>2009-08-20T10:01:00+09:00</published>
    <updated>2009-08-20T10:01:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Adobe が提供する ColdFusion には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN21388501_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:coldfusion"/>
    <sec:identifier>JVN#21388501</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090814-004:Apple Security Update 2009-004</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-004_AD_1.html</id>
    <published>2009-08-17T10:18:00+09:00</published>
    <updated>2009-08-17T10:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This document describes the security content of Security Update 2009-004, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:apple:mac_os_x"/>
    <category term="cpe:/o:apple:mac_os_x_server"/>
    <sec:identifier>VRDA-090814-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090814-003:WordPress 2.8.4: &#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12522;&#12522;&#12540;&#12473;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-003_AD_1.html</id>
    <published>2009-08-17T10:11:00+09:00</published>
    <updated>2009-08-17T10:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
特別に作成された URL がリクエストされると、ユーザーがリクエストしたパスワードのリセットを確認するためのセキュリティチェックを攻撃者が回避できる可能性があります。その結果、データベースにキーを持たない最初のアカウント (通常は管理者アカウント) のパスワードがリセットされ、新しいパスワードがそのアカウントのメールアドレスに送られます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:wordpress:wordpress"/>
    <sec:identifier>VRDA-090814-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090814-002:Safari 4.0.3 &#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12467;&#12531;&#12486;&#12531;&#12484;&#12395;&#12388;&#12356;&#12390;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-002_AD_1.html</id>
    <published>2009-08-17T10:00:00+09:00</published>
    <updated>2009-08-17T10:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
本件では Safari 4.0.3 のセキュリティコンテンツについて説明します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:safari"/>
    <sec:identifier>VRDA-090814-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090814-001:Memcached Multiple Heap Based Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-001_AD_1.html</id>
    <published>2009-08-17T09:51:00+09:00</published>
    <updated>2009-08-17T09:51:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Memcached is a database-caching applications available for multiple operating systems.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090814-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:danga_interactive:memcached"/>
    <sec:identifier>VRDA-090814-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090806-001:About the security content of Security Update 2009-003 / Mac OS X v10.5.8</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090806-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090806-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090806-001_AD_1.html</id>
    <published>2009-08-06T17:30:00+09:00</published>
    <updated>2009-08-06T17:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
This document describes the security content of Security Update 2009-003 / Mac OS X v10.5.8, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090806-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:apple:mac_os_x"/>
    <sec:identifier>VRDA-090806-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#15267895:FreeNAS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN15267895_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN15267895_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN15267895_AD_1.html</id>
    <published>2009-08-05T15:45:00+09:00</published>
    <updated>2009-08-05T15:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
FreeNAS には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN15267895_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:freenas:freenas"/>
    <sec:identifier>JVN#15267895</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#89791790:FreeNAS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN89791790_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN89791790_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN89791790_AD_1.html</id>
    <published>2009-08-05T15:40:00+09:00</published>
    <updated>2009-08-05T15:40:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
FreeNAS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN89791790_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:freenas:freenas"/>
    <sec:identifier>JVN#89791790</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090804-003:Firefox 3.5.2 &#12522;&#12522;&#12540;&#12473;&#12494;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-003_AD_1.html</id>
    <published>2009-08-04T15:45:00+09:00</published>
    <updated>2009-08-04T15:45:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.5.2 では、いくつかのセキュリティ問題 が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090804-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090804-002:Firefox 3.0.13 &#12522;&#12522;&#12540;&#12473;&#12494;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-002_AD_1.html</id>
    <published>2009-08-04T15:42:00+09:00</published>
    <updated>2009-08-04T15:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.0.13 では、Firefox 3.0.12 で見つかったいくつかの問題が修正されています。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090804-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090804-001:Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-001_AD_1.html</id>
    <published>2009-08-04T15:11:00+09:00</published>
    <updated>2009-08-04T15:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Recent versions of Cisco IOS Software support RFC4893 (&quot;BGP Support for Four-octet AS Number Space&quot;) and contain two remote denial of service (DoS) vulnerabilities when handling specific Border Gateway Protocol (BGP) updates.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090804-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:cisco:ios"/>
    <sec:identifier>VRDA-090804-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#80436657:&#26666;&#24335;&#20250;&#31038;&#12487;&#12451;&#12540;&#12450;&#12452;&#12471;&#12540;&#35069; yoyaku_v41 &#12395;&#12362;&#12369;&#12427; OS &#12467;&#12510;&#12531;&#12489;&#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80436657_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80436657_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80436657_AD_1.html</id>
    <published>2009-07-31T16:36:00+09:00</published>
    <updated>2009-07-31T16:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
株式会社ディーアイシーが提供する yoyaku_v41 には、OS コマンドインジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80436657_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:dic:yoyaku_v41"/>
    <sec:identifier>JVN#80436657</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#59748723:MySQL Connector/J &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN59748723_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN59748723_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN59748723_AD_1.html</id>
    <published>2009-07-29T17:11:00+09:00</published>
    <updated>2009-07-29T17:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Sun Microsystems が提供する MySQL Connector/J には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN59748723_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sun:mysql_connector_j"/>
    <sec:identifier>JVN#59748723</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090729-002:Visual Studio &#12398; Active Template Library &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-002_AD_1.html</id>
    <published>2009-07-29T16:56:00+09:00</published>
    <updated>2009-07-29T16:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
このセキュリティ更新プログラムは、責任ある開示方法で報告された Visual Studio に含まれている、パブリック バージョンの Microsoft Active Template Library (ATL) のいくつかの脆弱性を解決します。このセキュリティ更新プログラムは、特にコンポーネントおよびコントロールの開発者に向けられたものです。ATL を使用してコンポーネントおよびコントロールを作成、配布する開発者はこのセキュリティ情報で提供している更新プログラムをインストールし、このセキュリティ情報で説明している脆弱性の影響を受けないコンポーネントおよびコントロールを作成するためのガイダンスに従い、お客様に配布する必要があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:visual_c%2B%2B"/>
    <category term="cpe:/a:microsoft:visual_studio"/>
    <sec:identifier>VRDA-090729-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090729-001:BIND Dynamic Update DoS</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-001_AD_1.html</id>
    <published>2009-07-29T15:42:00+09:00</published>
    <updated>2009-07-29T15:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090729-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:isc:bind"/>
    <sec:identifier>VRDA-090729-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090728-003:Squid HTTP Data Processing Remote Denial of Service Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-003_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-003_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-003_OT_1.html</id>
    <published>2009-07-28T18:02:00+09:00</published>
    <updated>2009-07-28T18:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities have been identified in Squid, which could be exploited by remote attackers to cause a denial of service.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-003_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="lapt:/a:squid-cache.org:squid"/>
    <sec:identifier>VRDA-090728-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090728-002:Multiple Vulnerabilities in Cisco Wireless LAN Controllers</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-002_AD_1.html</id>
    <published>2009-07-28T17:53:00+09:00</published>
    <updated>2009-07-28T17:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities exist in the Cisco Wireless LAN Controller (WLC) platforms. This security advisory outlines the details of the following vulnerabilities:

    * Malformed HTTP or HTTPS authentication response denial of service vulnerability
    * SSH connections denial of service vulnerability
    * Crafted HTTP or HTTPS request denial of service vulnerability
    * Crafted HTTP or HTTPS request unauthorized configuration modification vulnerability&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:wireless_lan_controllers"/>
    <sec:identifier>VRDA-090728-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090728-001:A Security Vulnerability in the Sun Java System Access Manager Policy Agent May Result in a Denial of Service (DoS) to Web Proxy Server 4.0</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-001_AD_1.html</id>
    <published>2009-07-28T14:18:00+09:00</published>
    <updated>2009-07-28T14:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A security vulnerability in the Sun Java System Access Manager Policy Agent may allow a local or remote unprivileged user to crash the Sun Java System Web Proxy Server, when this is the deployment container that the Agent is running in. This is a type of Denial of Service (DoS).&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090728-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sun:java_system_access_manager_policy_agents"/>
    <sec:identifier>VRDA-090728-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#29852698:futomi's CGI Cafe &#35069; RevoCounter CGI (&#12450;&#12491;&#12513;&#12540;&#12471;&#12519;&#12531;&#12459;&#12454;&#12531;&#12479;&#12540;) &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29852698_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29852698_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29852698_AD_1.html</id>
    <published>2009-07-24T16:53:00+09:00</published>
    <updated>2009-07-24T16:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する RevoCounter CGI (アニメーションカウンター) には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29852698_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:revocounter_cgi"/>
    <sec:identifier>JVN#29852698</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090723-002:Firefox 3.0 &#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12450;&#12489;&#12496;&#12452;&#12470;&#12522;&#65306;Firefox 3.0.12</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-002_AD_1.html</id>
    <published>2009-07-23T13:44:00+09:00</published>
    <updated>2009-07-23T13:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.0.12 において、SVG 要素上で watch と __defineSetter__ を利用したクラッシュとリモートコード実行できる等の脆弱性が修正されました。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090723-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090723-001:Adobe Flash Player vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-001_AD_1.html</id>
    <published>2009-07-23T10:08:00+09:00</published>
    <updated>2009-07-23T10:08:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Adobe Flash contains a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090723-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <category term="cpe:/a:adobe:flash_player"/>
    <sec:identifier>VRDA-090723-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090715-002:Microsoft Office Web &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-002_AD_1.html</id>
    <published>2009-07-15T17:48:00+09:00</published>
    <updated>2009-07-15T17:48:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは現在、Microsoft Office Web コンポーネントに存在する責任ある開示方法で報告された脆弱性を調査中です。攻撃者がこの脆弱性を悪用した場合、ローカルのユーザーと同じユーザー権限を取得する可能性があります。Internet Explorer を使用している場合、リモートでコードが実行され、ユーザーの操作を必要としない可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:office:2003:sp3"/>
    <category term="cpe:/a:microsoft:office:xp:sp3"/>
    <category term="lapt:/a:microsoft:isa_server:2004:sp3"/>
    <category term="lapt:/a:microsoft:isa_server:2006:sp1"/>
    <category term="lapt:/a:microsoft:office:2006::small_business"/>
    <sec:identifier>VRDA-090715-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#410676:ISC DHCP dhclient &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU410676_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU410676_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU410676_AD_1.html</id>
    <published>2009-07-15T17:33:00+09:00</published>
    <updated>2009-07-15T17:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ISC DHCP dhclient には、バッファオーバーフローの脆弱性が存在します。 
なお、ISC によると 3.0 系および 2.0 系はサポート対象外とのことです。詳しくは ISC が提供する情報をご確認ください。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU410676_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:isc:dhcp_client"/>
    <sec:identifier>JVNVU#410676</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090715-001:Critical JavaScript vulnerability in Firefox 3.5 at Mozilla Security Blog</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-001_OT_1.html</id>
    <published>2009-07-15T16:41:00+09:00</published>
    <updated>2009-07-15T16:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090715-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090715-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#31110006:shiromuku(fs6)DIARY &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31110006_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31110006_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31110006_AD_1.html</id>
    <published>2009-07-14T15:31:00+09:00</published>
    <updated>2009-07-14T15:31:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Perl CGI's By Mrs.Shiromuku が提供する shiromuku(fs6)DIARY には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN31110006_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:perl_cgis_by_mrs_shiromuku:shiromuku_fs6_diary"/>
    <sec:identifier>JVN#31110006</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090713-001:Security Vulnerabilities in Solaris Bundled Tomcat May Lead to Unauthorized Access to Data or Denial of Service (DoS)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090713-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090713-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090713-001_AD_1.html</id>
    <published>2009-07-13T15:44:00+09:00</published>
    <updated>2009-07-13T15:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
There are five security vulnerabilities in the Tomcat JSP/Servlet container that affect Tomcat 5.5 bundled in Solaris 9 and Solaris 10 and Tomcat 6 bundled in OpenSolaris.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090713-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:sun:solaris:8"/>
    <category term="cpe:/o:sun:solaris:9"/>
    <category term="lapt:/o:sun:opensolaris"/>
    <sec:identifier>VRDA-090713-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090709-001:About the security content of Safari 4.0.2</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090709-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090709-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090709-001_AD_1.html</id>
    <published>2009-07-09T14:35:00+09:00</published>
    <updated>2009-07-09T14:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
An issue in WebKit's handling of the parent and top objects may result in a cross-site scripting attack when visiting a maliciously crafted website. This update addresses the issue through improved handling of parent and top objects.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090709-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apple:safari"/>
    <sec:identifier>VRDA-090709-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090707-001:Microsoft Video ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090707-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090707-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090707-001_AD_1.html</id>
    <published>2009-07-07T13:37:00+09:00</published>
    <updated>2009-07-07T13:37:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは現在、Microsoft Video ActiveX コントロールに存在する非公開で報告された脆弱性を調査中です。攻撃者がこの脆弱性を悪用した場合、ローカルのユーザーと同じ権限を取得する可能性があります。Internet Explorer を使用している場合、リモートでコードが実行され、ユーザーの操作を必要としない可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090707-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_2003_server::sp2"/>
    <category term="cpe:/o:microsoft:windows_xp::sp3"/>
    <sec:identifier>VRDA-090707-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090706-003:&#12454;&#12452;&#12523;&#12473;&#12496;&#12473;&#12479;&#12540;&#12467;&#12540;&#12509;&#12524;&#12540;&#12488;&#12456;&#12487;&#12451;&#12471;&#12519;&#12531;&#12539;&#12454;&#12452;&#12523;&#12473;&#12496;&#12473;&#12479;&#12540;&#12499;&#12472;&#12493;&#12473;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#25298;&#21542; (DoS)&#25915;&#25731; &#12398;&#33030;&#24369;&#24615;&#12395;&#12388;&#12356;&#12390;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-003_AD_1.html</id>
    <published>2009-07-06T18:20:00+09:00</published>
    <updated>2009-07-06T18:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ウイルスバスターコーポレートエディションおよびウイルスバスタービジネスセキュリティクライアントにおいて、非常に長いパスの処理に問題があり、バッファオーバーフローが発生します。悪意あるリモート攻撃者が、この脆弱性を悪用し、該当クライアントのリアルタイム検索サービスを停止させる可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:trendmicro:virus_buster_business_security"/>
    <category term="lapt:/a:trendmicro:virus_buster_corporate_edition"/>
    <sec:identifier>VRDA-090706-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090706-002:Cold Fusion web sites getting compromised</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-002_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-002_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-002_OT_1.html</id>
    <published>2009-07-06T13:06:00+09:00</published>
    <updated>2009-07-06T13:06:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-002_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:adobe:coldfusion"/>
    <sec:identifier>VRDA-090706-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090706-001:ESX Service Console update for krb5</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-001_AD_1.html</id>
    <published>2009-07-06T10:40:00+09:00</published>
    <updated>2009-07-06T10:40:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
An input validation flaw in the asn1_decode_generaltime function in MIT Kerberos 5 before 1.6.4 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090706-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:vmware:esx_server"/>
    <sec:identifier>VRDA-090706-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090702-003:NetBSD update for ntp</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-003_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-003_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-003_OT_1.html</id>
    <published>2009-07-02T17:41:00+09:00</published>
    <updated>2009-07-02T17:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
NetBSD has issued an update for ntp. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-003_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/o:netbsd:netbsd"/>
    <sec:identifier>VRDA-090702-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090702-002:Sun Solaris Trusted Extensions UDP Handling Denial of Service</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-002_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-002_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-002_OT_1.html</id>
    <published>2009-07-02T15:10:00+09:00</published>
    <updated>2009-07-02T15:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-002_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <sec:identifier>VRDA-090702-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090702-001:Sun Solaris Network File System "nfs_portmon" Tunable Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-001_OT_1.html</id>
    <published>2009-07-02T15:05:00+09:00</published>
    <updated>2009-07-02T15:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090702-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/o:sun:solaris:10"/>
    <sec:identifier>VRDA-090702-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090701-001:HP-UX Web Server Suite Code Execution and DoS Vulnerabilities / Exploit (Security Advisories)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090701-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090701-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090701-001_AD_1.html</id>
    <published>2009-07-01T14:18:00+09:00</published>
    <updated>2009-07-01T14:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities have been identified in HP-UX, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in the Apache Web Server Suite.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090701-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:hp:hp-ux:11.11"/>
    <category term="cpe:/o:hp:hp-ux:11.23"/>
    <category term="cpe:/o:hp:hp-ux:11.31"/>
    <sec:identifier>VRDA-090701-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090630-001:HP OpenView Network Node Manager "rping" Buffer Overflow Vulnerability / Exploit (Security Advisories)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090630-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090630-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090630-001_OT_1.html</id>
    <published>2009-06-30T16:18:00+09:00</published>
    <updated>2009-06-30T16:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in HP OpenView Network Node Manager (OV NNM) for Linux, which could be exploited by remote attackers to compromise a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090630-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="lapt:/a:hp:openview_network_node_manager_for_linux"/>
    <sec:identifier>VRDA-090630-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#32788272:&#12524;&#12483;&#12484;PHP! &#35069; PHP-I-BOARD &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN32788272_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN32788272_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN32788272_AD_1.html</id>
    <published>2009-06-25T16:33:00+09:00</published>
    <updated>2009-06-25T16:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
レッツPHP! が提供する PHP-I-BOARD には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN32788272_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:letsphp:php-i-board"/>
    <sec:identifier>JVN#32788272</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#20219071:&#12524;&#12483;&#12484;PHP! &#35069; PHP-I-BOARD &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20219071_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20219071_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20219071_AD_1.html</id>
    <published>2009-06-25T16:30:00+09:00</published>
    <updated>2009-06-25T16:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
レッツPHP! が提供する PHP-I-BOARD には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20219071_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:letsphp:php-i-board"/>
    <sec:identifier>JVN#20219071</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#93827000:&#12524;&#12483;&#12484;PHP! &#35069; Tree BBS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93827000_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93827000_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93827000_AD_1.html</id>
    <published>2009-06-25T16:27:00+09:00</published>
    <updated>2009-06-25T16:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
レッツPHP! が提供する Tree BBS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93827000_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:letsphp:tree_bbs"/>
    <sec:identifier>JVN#93827000</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#08369659:Movable Type &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#21046;&#38480;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN08369659_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN08369659_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN08369659_AD_1.html</id>
    <published>2009-06-24T16:16:00+09:00</published>
    <updated>2009-06-24T16:16:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type には、アクセス制限回避が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN08369659_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#08369659</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#86472161:Movable Type &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86472161_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86472161_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86472161_AD_1.html</id>
    <published>2009-06-24T16:10:00+09:00</published>
    <updated>2009-06-24T16:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86472161_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#86472161</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#12244807:XOOPS &#12510;&#12491;&#12450;&#35069; PukiWikiMod &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN12244807_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN12244807_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN12244807_AD_1.html</id>
    <published>2009-06-22T19:27:00+09:00</published>
    <updated>2009-06-22T19:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
XOOPS マニアが提供する PukiWikiMod には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN12244807_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:xoops_mania:pukiwikimod"/>
    <sec:identifier>JVN#12244807</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#87239696:iPhone OS &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87239696_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87239696_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87239696_AD_1.html</id>
    <published>2009-06-18T15:47:00+09:00</published>
    <updated>2009-06-18T15:47:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Apple が提供する iPhone OS には、サービス運用妨害 (DoS) の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87239696_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/o:apple:iphone_os"/>
    <category term="lapt:/o:apple:iphone_os_for_ipod_touch"/>
    <sec:identifier>JVN#87239696</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090612-002:Mozilla Japan - Firefox 3.0.11 &#12522;&#12522;&#12540;&#12473;&#12494;&#12540;&#12488;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-002_AD_1.html</id>
    <published>2009-06-12T13:28:00+09:00</published>
    <updated>2009-06-12T13:28:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Firefox 3.0.11 では、Firefox 3.0.10 で見つかったいくつかの問題が修正されています。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090612-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090612-001:Ruby:BigDecimal &#12398; DoS &#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-001_AD_1.html</id>
    <published>2009-06-12T13:20:00+09:00</published>
    <updated>2009-06-12T13:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Ruby標準ライブラリの一つであるBigDecimalに、DoS(Denial Of Service)状態を引き起こしてしまう脆弱性が存在することが発見されました。 BigDecimalオブジェクトから浮動小数点数(Float)への変換に問題があり、攻撃者はsegmentation faultsを引き起こすことができます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090612-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:ruby:ruby"/>
    <sec:identifier>VRDA-090612-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#63832775:Apache Tomcat &#12395;&#12362;&#12369;&#12427;&#24773;&#22577;&#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63832775_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63832775_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63832775_AD_1.html</id>
    <published>2009-06-09T15:15:00+09:00</published>
    <updated>2009-06-09T15:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Apache Software Foundation が提供する Apache Tomcat には、情報漏えいの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63832775_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <sec:identifier>JVN#63832775</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#87272440:Apache Tomcat &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475;&#65288;DoS&#65289;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87272440_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87272440_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87272440_AD_1.html</id>
    <published>2009-06-09T15:10:00+09:00</published>
    <updated>2009-06-09T15:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Apache Software Foundation が提供する Apache Tomcat には、サービス運用妨害（DoS）の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN87272440_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <sec:identifier>JVN#87272440</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#20689557:Serene Bach &#12395;&#12362;&#12369;&#12427;&#12475;&#12483;&#12471;&#12519;&#12531; ID &#12364;&#25512;&#28204;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20689557_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20689557_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20689557_AD_1.html</id>
    <published>2009-06-08T15:12:00+09:00</published>
    <updated>2009-06-08T15:12:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SerendipityNZ Limited が提供する Serene Bach には、セッション ID が推測可能である脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN20689557_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:serendipitynz_limited:serene_bach"/>
    <sec:identifier>JVN#20689557</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090604-001:Apache Tomcat denial of service vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090604-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090604-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090604-001_OT_1.html</id>
    <published>2009-06-04T16:41:00+09:00</published>
    <updated>2009-06-04T16:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
If Tomcat receives a request with invalid headers via the Java AJP connector, it does not return an error and instead closes the AJP connection.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090604-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <sec:identifier>VRDA-090604-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#01115659:MT312 &#35069;&#25658;&#24111;&#23550;&#24540;&#25522;&#31034;&#26495; REP-BBS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01115659_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01115659_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01115659_AD_1.html</id>
    <published>2009-05-29T15:56:00+09:00</published>
    <updated>2009-05-29T15:56:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
MT312 が提供する携帯対応掲示板 REP-BBS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN01115659_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:mt312:rep-bbs"/>
    <sec:identifier>JVN#01115659</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#70836284:MT312 &#35069;&#20889;&#12513;&#12540;&#12523;&#25522;&#31034;&#26495; IMG-BBS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70836284_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70836284_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70836284_AD_1.html</id>
    <published>2009-05-29T15:53:00+09:00</published>
    <updated>2009-05-29T15:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
MT312 が提供する写メール掲示板 IMG-BBS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70836284_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:mt312:img-bbs"/>
    <sec:identifier>JVN#70836284</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#62527913:&#35079;&#25968;&#12398; Cisco Systems &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62527913_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62527913_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62527913_AD_1.html</id>
    <published>2009-05-29T15:42:00+09:00</published>
    <updated>2009-05-29T15:42:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco Systems が提供する複数の製品には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN62527913_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:ciscoworks_common_services"/>
    <sec:identifier>JVN#62527913</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090529-001:&#12510;&#12452;&#12463;&#12525;&#12477;&#12501;&#12488; &#12475;&#12461;&#12517;&#12522;&#12486;&#12451; &#12450;&#12489;&#12496;&#12452;&#12470;&#12522; (971778): Microsoft DirectShow &#12398;&#33030;&#24369;&#24615;&#12395;&#12424;&#12426;&#12289;&#12522;&#12514;&#12540;&#12488;&#12391;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090529-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090529-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090529-001_AD_1.html</id>
    <published>2009-05-29T11:09:00+09:00</published>
    <updated>2009-05-29T11:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトは、Microsoft DirectX に存在する脆弱性に関する新たに公開された報告を現在調査中です。この脆弱性で、特別な細工がされた QuickTime メディアファイルをユーザーが開いた場合、リモートでコードが実行される可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090529-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:directx:7.0"/>
    <category term="cpe:/a:microsoft:directx:8.1"/>
    <category term="cpe:/a:microsoft:directx:9.0a"/>
    <category term="cpe:/a:microsoft:directx:9.0b"/>
    <category term="cpe:/a:microsoft:directx:9.0c"/>
    <sec:identifier>VRDA-090529-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090526-001:VUPEN Security - Apple QuickTime PICT 0x77 Tag Parsing Heap Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090526-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090526-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090526-001_OT_1.html</id>
    <published>2009-05-26T11:02:00+09:00</published>
    <updated>2009-05-26T11:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A vulnerability has been identified in Apple QuickTime, which could be exploited by remote
attackers to cause a denial of service or compromise a vulnerable system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090526-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:apple:quicktime"/>
    <sec:identifier>VRDA-090526-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#710316:NSD &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU710316_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU710316_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU710316_AD_1.html</id>
    <published>2009-05-22T17:15:00+09:00</published>
    <updated>2009-05-22T17:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
NSD にはバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU710316_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:nlnetlabs:nsd"/>
    <sec:identifier>JVNVU#710316</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#57036470:&#12450;&#12489;&#12471;&#12473;&#12486;&#12512;&#12474;&#35069;&#65335;&#65349;&#65346;&#20250;&#35696;&#23460;&#20104;&#32004; &#12501;&#12522;&#12540;&#65288;&#28961;&#26009;&#65289;&#29256; leger &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57036470_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57036470_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57036470_AD_1.html</id>
    <published>2009-05-22T15:27:00+09:00</published>
    <updated>2009-05-22T15:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
有限会社アドシステムズが提供するＷｅｂ会議室予約 フリー（無料）版 leger には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN57036470_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:adsystems:leger"/>
    <sec:identifier>JVN#57036470</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#42927215:&#12450;&#12483;&#12503;&#12523;&#12483;&#12503;&#12523;&#35069; a-News &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN42927215_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN42927215_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN42927215_AD_1.html</id>
    <published>2009-05-21T15:17:00+09:00</published>
    <updated>2009-05-21T15:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
有限会社アップルップルが提供する a-News には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN42927215_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:appleple:a-news"/>
    <sec:identifier>JVN#42927215</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#787932:Microsoft IIS 6.0 WebDAV &#12395;&#12362;&#12369;&#12427;&#35469;&#35388;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU787932_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU787932_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU787932_AD_1.html</id>
    <published>2009-05-21T14:59:00+09:00</published>
    <updated>2009-05-21T14:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft Internet Information Services (IIS) には認証回避の脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU787932_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:iis:5.0"/>
    <category term="cpe:/a:microsoft:iis:5.1"/>
    <category term="cpe:/a:microsoft:iis:6.0"/>
    <sec:identifier>JVNVU#787932</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#02331156:HP System Management Homepage &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02331156_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02331156_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02331156_AD_1.html</id>
    <published>2009-05-20T15:12:00+09:00</published>
    <updated>2009-05-20T15:12:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Hewlett-Packard が提供する HP System Management Homepage (SMH) には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02331156_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:system_management_homepage"/>
    <sec:identifier>JVN#02331156</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#853097:ntpd autokey &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU853097_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU853097_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU853097_AD_1.html</id>
    <published>2009-05-19T17:09:00+09:00</published>
    <updated>2009-05-19T17:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ntpd にはバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU853097_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/t::ntp"/>
    <sec:identifier>JVNVU#853097</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#28521500:CGI RESCUE &#35069; Trees &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28521500_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28521500_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28521500_AD_1.html</id>
    <published>2009-05-18T15:11:00+09:00</published>
    <updated>2009-05-18T15:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供する Trees には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28521500_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:trees"/>
    <sec:identifier>JVN#28521500</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090518-001:IIS6.0 WebDav Remote Auth Bypass</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090518-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090518-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090518-001_OT_1.html</id>
    <published>2009-05-18T13:47:00+09:00</published>
    <updated>2009-05-18T13:47:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
If you're in the security business long enough, this one will sound extremely familiar:  Apparently, adding certain Unicode characters to an URL makes it possible to bypass authentication in Microsoft IIS6 with WebDav and access or even upload files in folders which are supposed to be password protected.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090518-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:microsoft:iis:6.0"/>
    <sec:identifier>VRDA-090518-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090515-001:Sun Java Runtime Environment ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090515-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090515-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090515-001_OT_1.html</id>
    <published>2009-05-15T14:09:00+09:00</published>
    <updated>2009-05-15T14:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Sun Java Runtime Environment is prone to multiple remote buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090515-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:sun:jre"/>
    <sec:identifier>VRDA-090515-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#73653977:Sun GlassFish Enterprise Server &#12362;&#12424;&#12403; Sun Java System Application Server &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73653977_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73653977_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73653977_AD_1.html</id>
    <published>2009-05-13T15:11:00+09:00</published>
    <updated>2009-05-13T15:11:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Sun Microsystems が提供する Sun GlassFish Enterprise Server および Sun Java System Application Server には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN73653977_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:java_system_application_server:9.1"/>
    <category term="lapt:/a:sun:glassfish_enterprise_server"/>
    <sec:identifier>JVN#73653977</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#43233160:SKIP&#12518;&#12540;&#12470;&#12464;&#12523;&#12540;&#12503;&#35069; SKIP &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN43233160_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN43233160_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN43233160_AD_1.html</id>
    <published>2009-05-11T15:27:00+09:00</published>
    <updated>2009-05-11T15:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SKIPユーザグループが提供する SKIP には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN43233160_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:skip_user_group:skip"/>
    <sec:identifier>JVN#43233160</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#03114223:SKIP&#12518;&#12540;&#12470;&#12464;&#12523;&#12540;&#12503;&#35069; SKIP &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN03114223_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN03114223_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN03114223_AD_1.html</id>
    <published>2009-05-11T15:15:00+09:00</published>
    <updated>2009-05-11T15:15:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
SKIPユーザグループが提供する SKIP には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN03114223_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:skip_user_group:skip"/>
    <sec:identifier>JVN#03114223</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090501-001:Security Advisories Relating to Symantec Products - Symantec Alert Management System 2 multiple vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090501-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090501-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090501-001_AD_1.html</id>
    <published>2009-05-01T10:58:00+09:00</published>
    <updated>2009-05-01T10:58:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The version of Alert Management System 2 (AMS2) used by some versions of Symantec System Center, Symantec Antivirus Server, and Symantec AntiVirus Central Quarantine Server contains four vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090501-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:client_security"/>
    <category term="lapt:/a:symantec:antivirus_corporate_edition"/>
    <category term="lapt:/a:symantec:endpoint_protection"/>
    <sec:identifier>VRDA-090501-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#970180:Adobe Reader &#12362;&#12424;&#12403; Acrobat &#12395;&#12362;&#12369;&#12427; customDictionaryOpen() &#12392; getAnnots() &#12395;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU970180_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU970180_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU970180_AD_1.html</id>
    <published>2009-04-30T16:22:00+09:00</published>
    <updated>2009-04-30T16:22:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Adobe Reader および Acrobat には JavaScript メソッドである customDictionaryOpen() と getAnnots() に脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU970180_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <sec:identifier>JVNVU#970180</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090427-003:Debian Bug report logs - #433091 ignores expiry of archive keys</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-003_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-003_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-003_OT_1.html</id>
    <published>2009-04-27T16:27:00+09:00</published>
    <updated>2009-04-27T16:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Debian aptが取得したパッケージのPGP署名を検証するが、期限切れの鍵で署名されていても処理を続行してしまうという脆弱性。 debian/ubuntuではgpgvという専用コマンドをつかっているがそのコマンドがそもそも期限切れを警告しない。aptの0.7.21で修正が施された&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-003_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="lapt:/a:debian:apt"/>
    <sec:identifier>VRDA-090427-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#28020230:CGI RESCUE &#35069;WEB&#12513;&#12540;&#12521;&#12540;&#12395;&#12362;&#12369;&#12427;HTTP&#12504;&#12483;&#12480;&#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28020230_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28020230_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28020230_AD_1.html</id>
    <published>2009-04-27T15:57:00+09:00</published>
    <updated>2009-04-27T15:57:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供する Webメーラーには、HTTP ヘッダインジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28020230_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:webmailer"/>
    <sec:identifier>JVN#28020230</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#76370393:CGI RESCUE &#35069;&#12501;&#12457;&#12540;&#12512;&#12513;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#12513;&#12540;&#12523;&#12398;&#19981;&#27491;&#36865;&#20449;&#12364;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN76370393_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN76370393_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN76370393_AD_1.html</id>
    <published>2009-04-27T15:53:00+09:00</published>
    <updated>2009-04-27T15:53:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供するフォームメールには、管理者の設定とは異なる内容でメールの送信が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN76370393_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:form2mail"/>
    <sec:identifier>JVN#76370393</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#36982346:CGI RESCUE &#35069;&#31777;&#26131;BBS22 &#12395;&#12362;&#12369;&#12427;&#12513;&#12540;&#12523;&#12398;&#19981;&#27491;&#36865;&#20449;&#12364;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36982346_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36982346_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36982346_AD_1.html</id>
    <published>2009-04-27T15:49:00+09:00</published>
    <updated>2009-04-27T15:49:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供する簡易BBS22 は、電子掲示板スクリプトです。簡易BBS22 には、管理者の設定とは異なる内容でメールの送信が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36982346_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:kannibbs22"/>
    <sec:identifier>JVN#36982346</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#11396739:CGI RESCUE &#35069;&#31777;&#26131;BBS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN11396739_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN11396739_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN11396739_AD_1.html</id>
    <published>2009-04-27T15:21:00+09:00</published>
    <updated>2009-04-27T15:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供する簡易BBS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN11396739_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:kannibbs"/>
    <sec:identifier>JVN#11396739</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090427-002:Mozilla Thunderbird Multiple Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-002_AD_1.html</id>
    <published>2009-04-27T13:36:00+09:00</published>
    <updated>2009-04-27T13:36:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and cross-site request forgery attacks, and potentially to compromise a user's system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>VRDA-090427-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090427-001:Mozilla Firefox Multiple Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-001_AD_1.html</id>
    <published>2009-04-27T13:10:00+09:00</published>
    <updated>2009-04-27T13:10:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Some vulnerabilities, security issues, and a weakness have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, conduct cross-site scripting and cross-site request forgery attacks, and potentially compromise a user's system.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090427-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <sec:identifier>VRDA-090427-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#97248625:Movable Type &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN97248625_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN97248625_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN97248625_AD_1.html</id>
    <published>2009-04-24T15:27:00+09:00</published>
    <updated>2009-04-24T15:27:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN97248625_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#97248625</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#82744714:LovPop.net &#35069; apricot.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN82744714_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN82744714_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN82744714_AD_1.html</id>
    <published>2009-04-16T15:22:00+09:00</published>
    <updated>2009-04-16T15:22:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
LovPop.net が提供する apricot.php は、ウェブページのアクセスログ解析を行うためのソフトウェアです。apricot.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN82744714_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:lovpop.net:apricot.php"/>
    <sec:identifier>JVN#82744714</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090415-001:Oracle Critical Patch Update Advisory - April 2009</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090415-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090415-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090415-001_AD_1.html</id>
    <published>2009-04-15T16:59:00+09:00</published>
    <updated>2009-04-15T16:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A Critical Patch Update is a collection of patches for multiple security vulnerabilities. It also includes non-security fixes that are required (because of interdependencies) by those security patches.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090415-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:oracle:application_server"/>
    <category term="cpe:/a:oracle:e-business_suite"/>
    <category term="cpe:/a:oracle:peoplesoft_enterprise"/>
    <category term="lapt:/a:oracle:database"/>
    <category term="lapt:/a:oracle:weblogic_server"/>
    <sec:identifier>VRDA-090415-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#33846134:&#19968;&#22826;&#37070;&#12471;&#12522;&#12540;&#12474;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33846134_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33846134_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33846134_AD_1.html</id>
    <published>2009-04-08T14:08:00+09:00</published>
    <updated>2009-04-08T14:08:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ジャストシステムが提供する一太郎シリーズはワープロソフトです。この一太郎シリーズには、リッチテキストファイルの読込み処理に問題があり、バッファオーバーフローを起こす脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN33846134_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:justsystems:ichitaro"/>
    <sec:identifier>JVN#33846134</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#74747784:XOOPS Cube Legacy &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN74747784_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN74747784_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN74747784_AD_1.html</id>
    <published>2009-04-02T15:41:00+09:00</published>
    <updated>2009-04-02T15:41:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
XOOPS Cube Project が提供する XOOPS Cube Legacy には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN74747784_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:xoops_cube_project:xoops_cube_legacy"/>
    <sec:identifier>JVN#74747784</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090402-001:JP1/VERITAS NetBackup &#12398; Communications Setup &#12395;&#29305;&#27177;&#26119;&#26684;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090402-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090402-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090402-001_AD_1.html</id>
    <published>2009-04-02T14:51:00+09:00</published>
    <updated>2009-04-02T14:51:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
JP1/VERITAS NetBackupのCommunications Setupに特権昇格の脆弱性が存在します。本脆弱性を悪用することで，非特権の正当なシステムユーザがVeritas Network Daemonを使用することにより，そのシステム上で特権の昇格が行えます。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090402-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:symantec:veritas_netbackup_enterprise_server"/>
    <category term="cpe:/a:symantec:veritas_netbackup_server"/>
    <category term="lapt:/a:hitachi:jp1_veritas_netbackup"/>
    <sec:identifier>VRDA-090402-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#63511247:futomi's CGI Cafe &#35069;&#39640;&#27231;&#33021;&#12450;&#12463;&#12475;&#12473;&#35299;&#26512;CGI Professional &#29256;&#12395;&#12362;&#12369;&#12427;&#31649;&#29702;&#32773;&#27177;&#38480;&#22890;&#21462;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63511247_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63511247_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63511247_AD_1.html</id>
    <published>2009-03-31T15:23:00+09:00</published>
    <updated>2009-03-31T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する高機能アクセス解析CGI Professional 版には、管理者権限が奪取可能である脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN63511247_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:cgi_cafe"/>
    <sec:identifier>JVN#63511247</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090330-005:Sun Java Runtime Environment (JRE) Pack200 Decompression Integer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-005_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-005_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-005_AD_1.html</id>
    <published>2009-03-30T15:07:00+09:00</published>
    <updated>2009-03-30T15:07:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of an integer overflow vulnerability in Sun Microsystems Inc.'s Java Runtime Environment (JRE) could allow an attacker to execute arbitrary code with the privileges of the current user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-005_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <sec:identifier>VRDA-090330-005</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090330-004:Sun Java Web Start (JWS ) PNG Decoding Integer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-004_AD_1.html</id>
    <published>2009-03-30T15:02:00+09:00</published>
    <updated>2009-03-30T15:02:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of an integer overflow vulnerability in Sun Microsystems Inc.'s Java Web Start could allow an attacker to execute arbitrary code with privileges of the current user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:java_web_start"/>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <sec:identifier>VRDA-090330-004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090330-003:Sun Java Runtine Environment (JRE) GIF Decoding Heap Corruption Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-003_AD_1.html</id>
    <published>2009-03-30T14:56:00+09:00</published>
    <updated>2009-03-30T14:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of a heap corruption vulnerability in Sun Microsystems Inc.'s Java JRE could allow an attacker to execute arbitrary code with the privileges of the current user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <sec:identifier>VRDA-090330-003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090330-002:Sun Java Web Start (JWS) GIF Decoding Heap Corruption Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-002_AD_1.html</id>
    <published>2009-03-30T14:50:00+09:00</published>
    <updated>2009-03-30T14:57:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of a heap corruption vulnerability in Sun Microsystems Inc.'s Java Web Start could allow an attacker to execute arbitrary code with privileges of the current user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:java_web_start"/>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <category term="cpe:/a:sun:sdk"/>
    <sec:identifier>VRDA-090330-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090330-001:Sun Java Runtine Environment (JRE) Type1 Font Parsing Integer Signedness Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-001_AD_1.html</id>
    <published>2009-03-30T14:39:00+09:00</published>
    <updated>2009-03-30T14:39:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Remote exploitation of an integer signedness vulnerability in Sun Microsystems Inc.'s Java JRE could allow an attacker to execute arbitrary code with the privileges of the current user.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090330-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sun:jdk"/>
    <category term="cpe:/a:sun:jre"/>
    <sec:identifier>VRDA-090330-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090319-001:IBM - Potential Security Issue with Lotus Notes File Viewer for WordPerfect</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090319-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090319-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090319-001_AD_1.html</id>
    <published>2009-03-19T15:05:00+09:00</published>
    <updated>2009-03-19T15:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
iDefense Labs contacted IBM Lotus to report a potential keyview buffer overflow vulnerability in Lotus Notes. In specific situations it was found that there is the possibility to execute arbitrary code.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090319-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:lotus_notes"/>
    <sec:identifier>VRDA-090319-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#23558374:futomi's CGI Cafe &#35069;&#39640;&#27231;&#33021;&#12450;&#12463;&#12475;&#12473;&#35299;&#26512;CGI Standard &#29256; (Ver. 3.x &#31995;) &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23558374_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23558374_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23558374_AD_1.html</id>
    <published>2009-03-16T15:13:00+09:00</published>
    <updated>2009-03-16T15:13:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する高機能アクセス解析CGI Standard 版 (Ver. 3.x 系) にはクロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN23558374_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:cgi_cafe"/>
    <sec:identifier>JVN#23558374</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090316-001:&#19968;&#22826;&#37070;&#12398;&#33030;&#24369;&#24615;&#12434;&#24746;&#29992;&#12375;&#12383;&#19981;&#27491;&#12394;&#12503;&#12525;&#12464;&#12521;&#12512;&#12398;&#23455;&#34892;&#21361;&#38522;&#24615;&#12395;&#12388;&#12356;&#12390;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090316-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090316-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090316-001_AD_1.html</id>
    <published>2009-03-16T14:29:00+09:00</published>
    <updated>2009-03-16T14:29:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
2009年3月11日、弊社の一部製品に脆弱性の存在を確認いたしました。この脆弱性が悪用されると任意のコードが実行され、パソコンが不正に操作される危険性があります。弊社ではこの問題を調査中です。なお、2009年3月16日現在におきまして、本件に起因する実際の被害は確認しておりません。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090316-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:justsystems:ichitaro"/>
    <sec:identifier>VRDA-090316-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090311-001:Adobe - Security Advisories : APSB09-03 - Security Updates available for Adobe Reader 9 and Acrobat 9</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090311-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090311-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090311-001_AD_1.html</id>
    <published>2009-03-11T15:23:00+09:00</published>
    <updated>2009-03-11T15:23:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090311-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <sec:identifier>VRDA-090311-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#84899898:futomi's CGI Cafe &#35069; MP Form Mail CGI &#12395;&#12362;&#12369;&#12427;&#31649;&#29702;&#32773;&#27177;&#38480;&#22890;&#21462;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84899898_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84899898_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84899898_AD_1.html</id>
    <published>2009-03-10T15:31:00+09:00</published>
    <updated>2009-03-10T15:31:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する MP Form Mail CGI には、管理者権限が奪取可能である脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN84899898_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:cgi_cafe"/>
    <sec:identifier>JVN#84899898</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#649212:libpng &#12364;&#36969;&#20999;&#12395;&#12456;&#12524;&#12513;&#12531;&#12488;&#12509;&#12452;&#12531;&#12479;&#12434;&#21021;&#26399;&#21270;&#12375;&#12394;&#12356;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU649212_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU649212_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU649212_AD_1.html</id>
    <published>2009-03-04T17:30:00+09:00</published>
    <updated>2009-03-04T17:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
libpng にはエレメントポインタが適切に初期化されない脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU649212_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:libpng:libpng"/>
    <sec:identifier>JVNVU#649212</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090303-002:Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-002_AD_1.html</id>
    <published>2009-03-03T10:44:00+09:00</published>
    <updated>2009-03-03T10:44:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Cisco ACE Module and Cisco ACE 4710 Application Control Engine contain multiple vulnerabilities.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cisco:anm_4710_application_control_engine"/>
    <sec:identifier>VRDA-090303-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090303-001:Cisco Security Advisory: Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-001_AD_1.html</id>
    <published>2009-03-03T10:13:00+09:00</published>
    <updated>2009-03-03T10:13:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Multiple vulnerabilities exist in the Cisco Application Networking Manager (ANM) and Cisco Application Control Engine (ACE) Device Manager applications. These vulnerabilities are independent of each other. Successful exploitation of these vulnerabilities may result in unauthorized system or host operating system access.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090303-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cisco:ace_application_control_engine_device_manager"/>
    <category term="lapt:/a:cisco:anm_application_networking_manager"/>
    <sec:identifier>VRDA-090303-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090302-001:Cisco Security Advisory: Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090302-001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090302-001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090302-001_AD_1.html</id>
    <published>2009-03-02T17:54:00+09:00</published>
    <updated>2009-03-02T17:54:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco Unified MeetingPlace Web Conferencing servers may contain an authentication bypass vulnerability that could allow an unauthenticated user to gain administrative access to the MeetingPlace application. Cisco has released free software updates that address this vulnerability.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090302-001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cisco:unified_meetingplace"/>
    <sec:identifier>VRDA-090302-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#66905322:Apache Tomcat &#12395;&#12362;&#12369;&#12427;&#24773;&#22577;&#28431;&#12360;&#12356;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66905322_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66905322_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66905322_AD_1.html</id>
    <published>2009-03-02T17:39:00+09:00</published>
    <updated>2009-03-02T17:39:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
The Apache Software Foundation が提供する Apache Tomcat には、情報漏えいの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66905322_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat"/>
    <sec:identifier>JVN#66905322</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090225-001:Adobe - Security Advisories : APSB09-01 - Flash Player update available to address security vulnerabilities</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090225-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090225-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090225-001_OT_1.html</id>
    <published>2009-02-25T17:33:00+09:00</published>
    <updated>2009-02-25T17:33:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
A potential vulnerability has been identified in Adobe Flash Player 10.0.12.36 and earlier that could allow an attacker who successfully exploits this potential vulnerability to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit this potential vulnerability. Additional vulnerabilities have been addressed in this update. Adobe recommends users update to the most current version of Flash Player available for their platform.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090225-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:adobe:flash_player"/>
    <sec:identifier>VRDA-090225-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#91591874:PEAK XOOPS &#35069; piCal &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN91591874_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN91591874_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN91591874_AD_1.html</id>
    <published>2009-02-25T15:17:00+09:00</published>
    <updated>2009-02-25T15:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
PEAK XOOPS が提供する piCal には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN91591874_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:peak_xoops:peak_xoops-pical"/>
    <sec:identifier>JVN#91591874</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090224-002:APSA09-01 - Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and Acrobat</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-002_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-002_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-002_OT_1.html</id>
    <published>2009-02-24T17:30:00+09:00</published>
    <updated>2009-02-24T17:30:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-002_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:adobe:acrobat"/>
    <category term="cpe:/a:adobe:acrobat_reader"/>
    <sec:identifier>VRDA-090224-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090224-001:New Excel 0-day being exploited - Computerworld Blogs</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-001_OT_1.html</id>
    <published>2009-02-24T16:59:00+09:00</published>
    <updated>2009-02-24T16:59:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090224-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:microsoft:excel:2000:sp3"/>
    <category term="cpe:/a:microsoft:excel:2002:sp3"/>
    <category term="cpe:/a:microsoft:excel_viewer"/>
    <category term="cpe:/a:microsoft:excel_viewer:2003"/>
    <category term="lapt:/a:microsoft:excel:2003:sp3"/>
    <category term="lapt:/a:microsoft:excel:2007:sp1"/>
    <category term="lapt:/a:microsoft:excel_for_mac:2004"/>
    <category term="lapt:/a:microsoft:excel_for_mac:2008"/>
    <category term="lapt:/a:microsoft:excel_viewer:2003:sp3"/>
    <sec:identifier>VRDA-090224-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#16767117:&#12477;&#12491;&#12540;&#35069;&#12493;&#12483;&#12488;&#12527;&#12540;&#12463;&#12459;&#12513;&#12521; SNC &#12471;&#12522;&#12540;&#12474;&#12398; ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN16767117_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN16767117_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN16767117_AD_1.html</id>
    <published>2009-02-23T16:05:00+09:00</published>
    <updated>2009-02-23T16:05:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ソニー製ネットワークカメラ SNC シリーズの ActiveX コントロールは、ネットワーク経由でブラウザ上から映像をモニタリングするためのソフトウェアです。この ActiveXコントロールには、設定変数の一部の処理が適切に行われないため、ヒープバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN16767117_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:sony:sony_network_camera_snc"/>
    <sec:identifier>JVN#16767117</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#29641290:Becky! Internet Mail &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29641290_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29641290_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29641290_AD_1.html</id>
    <published>2009-02-12T17:39:00+09:00</published>
    <updated>2009-02-12T17:39:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Becky! Internet Mail はメールクライアントソフトです。Becky! Internet Mail には、メールを閲覧した際の開封確認の処理に問題があり、バッファオーバーフローを起こす脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN29641290_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:rimarts:becky"/>
    <sec:identifier>JVN#29641290</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#45184501:FAST ESP &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN45184501_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN45184501_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN45184501_AD_1.html</id>
    <published>2009-02-10T15:47:00+09:00</published>
    <updated>2009-02-10T15:47:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
マイクロソフトが提供する検索プラットフォームである FAST ESP には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN45184501_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:microsoft:fast_esp"/>
    <sec:identifier>JVN#45184501</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#80771386:futomi's CGI Cafe &#35069;&#20840;&#25991;&#26908;&#32034;CGI &#12395;&#12362;&#12369;&#12427;&#31649;&#29702;&#32773;&#27177;&#38480;&#22890;&#21462;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80771386_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80771386_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80771386_AD_1.html</id>
    <published>2009-01-27T15:48:00+09:00</published>
    <updated>2009-01-27T15:48:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する全文検索CGI には管理者権限が奪取可能である脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN80771386_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:cgi_cafe"/>
    <sec:identifier>JVN#80771386</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-090122-001:About the security content of QuickTime 7.6</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090122-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090122-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090122-001_OT_1.html</id>
    <published>2009-01-22T10:50:00+09:00</published>
    <updated>2009-01-22T10:50:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-090122-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:apple:quicktime"/>
    <sec:identifier>VRDA-090122-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#93431860:Oracle WebLogic Server &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93431860_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93431860_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93431860_AD_1.html</id>
    <published>2009-01-20T18:19:00+09:00</published>
    <updated>2009-01-20T18:19:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Oracle（旧 BEA Systems, Inc.）が提供する Oracle WebLogic Server には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN93431860_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:bea:weblogic_server"/>
    <category term="lapt:/a:oracle:weblogic_server"/>
    <sec:identifier>JVN#93431860</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#28344798:Cisco IOS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28344798_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28344798_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28344798_AD_1.html</id>
    <published>2009-01-15T15:25:00+09:00</published>
    <updated>2009-01-15T15:25:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Cisco IOS に含まれるウェブ管理インターフェースには、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN28344798_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:cisco:ios"/>
    <sec:identifier>JVN#28344798</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#72630020:MODx &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72630020_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72630020_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72630020_AD_1.html</id>
    <published>2009-01-09T16:24:00+09:00</published>
    <updated>2009-01-09T16:24:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
オープンソースのコンテンツ管理システムである MODx には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN72630020_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:modx:modx"/>
    <sec:identifier>JVN#72630020</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#66828183:MODx &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66828183_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66828183_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66828183_AD_1.html</id>
    <published>2009-01-09T16:18:00+09:00</published>
    <updated>2009-01-09T16:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
オープンソースのコンテンツ管理システムである MODx には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN66828183_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:modx:modx"/>
    <sec:identifier>JVN#66828183</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#10170564:MODx &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN10170564_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN10170564_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN10170564_AD_1.html</id>
    <published>2009-01-09T16:12:00+09:00</published>
    <updated>2009-01-09T16:12:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
オープンソースのコンテンツ管理システムである MODx には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN10170564_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:modx:modx"/>
    <sec:identifier>JVN#10170564</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#71945722:Movable Type Enterprise &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN71945722_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN71945722_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN71945722_AD_1.html</id>
    <published>2009-01-08T15:26:00+09:00</published>
    <updated>2009-01-08T15:26:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type Enterprise には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN71945722_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#71945722</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#36802959:MyNETS &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36802959_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36802959_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36802959_AD_1.html</id>
    <published>2009-01-07T17:29:00+09:00</published>
    <updated>2009-01-07T17:29:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
オープンソースの SNS ソフトウェアである MyNETS には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN36802959_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:usagi_project:mynets"/>
    <sec:identifier>JVN#36802959</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#17298485:Mayaa &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN17298485_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN17298485_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN17298485_AD_1.html</id>
    <published>2008-12-25T19:32:00+09:00</published>
    <updated>2008-12-25T19:32:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Seasar プロジェクトが提供する Java 用テンプレートエンジンである Mayaa には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN17298485_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:seasar_project:mayaa"/>
    <sec:identifier>JVN#17298485</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#98063934:BlackJumboDog &#12395;&#12362;&#12369;&#12427;&#35469;&#35388;&#22238;&#36991;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN98063934_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN98063934_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN98063934_AD_1.html</id>
    <published>2008-12-25T19:20:00+09:00</published>
    <updated>2008-12-25T19:20:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
サッポロワークスが提供する BlackJumboDog には、認証回避が可能な脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN98063934_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sapporoworks:blackjumbodog"/>
    <sec:identifier>JVN#98063934</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#696644:Microsoft SQL Server &#12398; sp_replwritetovarbin &#25313;&#24373;&#12473;&#12488;&#12450;&#12489; &#12503;&#12525;&#12471;&#12540;&#12472;&#12515;&#12398;&#20966;&#29702;&#12395;&#12362;&#12369;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU696644_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU696644_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU696644_AD_1.html</id>
    <published>2008-12-25T12:04:00+09:00</published>
    <updated>2008-12-25T12:04:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Microsoft SQL Server の sp_replwritetovarbin 拡張ストアド プロシージャのパラメータ処理に脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU696644_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:sql_server:2000"/>
    <category term="cpe:/a:microsoft:sql_server:2005"/>
    <sec:identifier>JVNVU#696644</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#50327700:PHP &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN50327700_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN50327700_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN50327700_AD_1.html</id>
    <published>2008-12-19T15:55:00+09:00</published>
    <updated>2008-12-19T15:55:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
PHP には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN50327700_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php"/>
    <sec:identifier>JVN#50327700</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-081218-002:&#12510;&#12452;&#12463;&#12525;&#12477;&#12501;&#12488; &#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#24773;&#22577; MS08-078 - &#32202;&#24613; : Internet Explorer &#29992;&#12398;&#12475;&#12461;&#12517;&#12522;&#12486;&#12451;&#26356;&#26032;&#12503;&#12525;&#12464;&#12521;&#12512; (960714)</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-002_AD_1.html</id>
    <published>2008-12-18T17:17:00+09:00</published>
    <updated>2008-12-18T17:17:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:microsoft:ie"/>
    <category term="cpe:/a:microsoft:outlook_express"/>
    <sec:identifier>VRDA-081218-002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-081218-001:Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-001_OT_1.html</id>
    <published>2008-12-18T17:09:00+09:00</published>
    <updated>2008-12-18T17:09:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081218-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/a:microsoft:sql_server:2000"/>
    <category term="cpe:/a:microsoft:sql_server:2005"/>
    <sec:identifier>VRDA-081218-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#07468800:futomi's CGI Cafe &#35069;&#39640;&#27231;&#33021;&#12450;&#12463;&#12475;&#12473;&#35299;&#26512;CGI &#12395;&#12362;&#12369;&#12427;&#12475;&#12483;&#12471;&#12519;&#12531; ID &#12364;&#25512;&#28204;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN07468800_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN07468800_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN07468800_AD_1.html</id>
    <published>2008-12-12T00:00:00+09:00</published>
    <updated>2008-12-12T00:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
futomi's CGI Cafe が提供する高機能アクセス解析CGI には、セッション ID が推測可能である脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN07468800_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:futomi:cgi_cafe"/>
    <sec:identifier>JVN#07468800</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNVU#926676:Microsoft &#12527;&#12540;&#12489;&#12497;&#12483;&#12489;&#12398;&#12486;&#12461;&#12473;&#12488;&#12467;&#12531;&#12496;&#12540;&#12479;&#12395;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU926676_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU926676_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU926676_AD_1.html</id>
    <published>2008-12-12T00:00:00+09:00</published>
    <updated>2008-12-12T00:00:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Word 97 ファイル形式用のワードパッドテキストコンバータの処理に問題があり、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVNVU926676_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:microsoft:wordpad"/>
    <sec:identifier>JVNVU#926676</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#02216739:Movable Type Enterprise &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02216739_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02216739_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02216739_AD_1.html</id>
    <published>2008-12-03T16:12:00+09:00</published>
    <updated>2008-12-03T16:12:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
Movable Type Enterprise には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN02216739_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:sixapart:movable_type"/>
    <sec:identifier>JVN#02216739</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#70599814:&#12450;&#12452;&#12539;&#12458;&#12540;&#12539;&#12487;&#12540;&#12479;&#35069; HDL-F &#12471;&#12522;&#12540;&#12474;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70599814_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70599814_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70599814_AD_1.html</id>
    <published>2008-11-26T17:35:00+09:00</published>
    <updated>2008-11-26T17:35:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
アイ・オー・データ製 LAN 接続型ハードディスクである HDL-F シリーズのウェブ管理画面には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN70599814_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/h:iodata:hdl-f"/>
    <sec:identifier>JVN#70599814</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VRDA-081121-001:Microsoft Windows Vista 'iphlpapi.dll' Local Kernel Buffer Overflow Vulnerability</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081121-001_OT_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081121-001_OT_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081121-001_OT_1.html</id>
    <published>2008-11-21T15:34:00+09:00</published>
    <updated>2008-11-21T15:34:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VRDA-081121-001_OT_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Other    </content>
    <category term="cpe:/o:microsoft:windows_vista"/>
    <sec:identifier>VRDA-081121-001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Other</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#86833991:CGI RESCUE &#35069;&#31777;&#26131;BBS2000 &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86833991_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86833991_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86833991_AD_1.html</id>
    <published>2008-11-21T15:18:00+09:00</published>
    <updated>2008-11-21T15:18:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
CGI RESCUE が提供する簡易BBS2000 には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN86833991_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:cgi_rescue:bbs2000"/>
    <sec:identifier>JVN#86833991</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVN#47875752:&#12460;&#12531;&#12507;&#12540;&#35069; LoadPrgAx &#12395;&#12362;&#12356;&#12390;&#20219;&#24847;&#12398; Java &#12503;&#12525;&#12464;&#12521;&#12512;&#12364;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN47875752_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN47875752_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN47875752_AD_1.html</id>
    <published>2008-11-17T17:21:00+09:00</published>
    <updated>2008-11-17T17:21:00+09:00</updated>
    <author>
      <name>JPCERT/CC</name>
    </author>
    <content type="html">
ガンホー・オンライン・エンターテイメント株式会社が提供する LoadPrgAx ActiveX コントロールには、任意の Java プログラムが実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_JVN47875752_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="lapt:/a:gungho:loadprgax"/>
    <sec:identifier>JVN#47875752</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>VU#277313:SAP AG SAPgui MDrmSap ActiveX control &#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#23455;&#34892;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VU277313_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VU277313_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed_obsolete/ja/JPCERTCC_VU277313_AD_1.html</id>
    <published>2008-1
