exploits and vulnerabilities

  • Developer finds major coding errors in Facebook, MySpace 06/11/2009 08:29:00

    The simple problems may have exposed users' data for an unknown length of time
    Social-networking sites MySpace and Facebook have apparently fixed coding errors that could have allowed an attacker access to all of their users' data and photos.
  • Java, BlackBerry desktop get security bug fixes 05/11/2009 09:25:00

    Sun releases critical update to Java Runtime Environment
    Sun Microsystems and Research In Motion have issued critical bug fixes for security issues with their products.
  • Botnet authors crash WordPress sites with buggy code 05/11/2009 08:58:00

    Other sites that use complex PHP are also affected
    Webmasters who find an annoying error message on their sites may have caught a big break, thanks to a slip-up by the authors of the Gumblar botnet.
  • Mozilla blocks Microsoft's buggy Firefox plugin 18/10/2009 05:05:00

    Microsoft silently installed the .Net plugin earlier this year
    Mozilla developers have blocked a Firefox plugin that was quietly pushed out by Microsoft, saying that it presents a security risk.
  • Programmer slip-up produces critical bug, Microsoft admits 17/10/2009 04:18:00

    Missed SMB 2 vulnerability in Vista, but found it in time to fix Windows 7
    Microsoft acknowledged Thursday that one of the critical network vulnerabilities it patched earlier in the week was due to a programming error on its part.
  • Microsoft delivers massive Patch Tuesday, fixes 34 flaws 14/10/2009 06:09:00

    Unlucky 13 updates plug multiple 'zero-day' holes, including one Microsoft had kept secret until now
    Microsoft today delivered a record 13 security updates that patched 34 vulnerabilities in every version of Windows, including the not-yet-for-sale Windows 7, as well as in Internet Explorer (IE), Office, SQL Server and other parts of its software portfolio.
  • Cisco patches a dozen router bugs 24/09/2009 07:19:00

    12 security flaws are fixed in the semi-annual update
    Cisco Systems has released its twice-yearly set of security patches for its router firmware, fixing 12 security flaws in the products.
  • Microsoft unveils tool for Windows flaw as attack code looms 21/09/2009 23:35:00

    Company urges users to run single-click tool before hackers exploit "decently wormable" flaw
    With attack code that exploits a critical unpatched bug in Windows likely to go public soon, Microsoft wants users to run an automated tool that disables the vulnerable component.
  • Mozilla patches 10 Firefox 3.5 vulnerabilities 11/09/2009 06:39:00

    Also quashes 11 bugs in older 3.0 browser, debuts Flash Player version check
    Mozilla on Wednesday patched 10 security vulnerabilities in Firefox 3.5, all but one ranked critical, as it delivered the first update that automatically checks for outdated versions of the popular Flash Player plug-in.
  • Microsoft confirms critical unpatched Vista, Windows 7 RC bug 10/09/2009 06:35:00

    Doesn't affect Windows 7 or Server 2008 R2 RTMs, or older versions like 2000 and XP
    Microsoft late Tuesday confirmed that a bug in Windows Vista, Windows Server 2008, and the release candidates of Windows 7 and Windows Server 2008 R2, could be used to hijack PCs.
  • Microsoft: Patching Windows 2000 'infeasible' 09/09/2009 07:31:00

    Skips fix for critical flaw disclosed today in older, but still-supported, OS
    Microsoft took the unusual step today and skipped patching one of the vulnerabilities addressed in its monthly security update, saying that crafting a fix was "infeasible."
  • Microsoft: Cyber-crooks exploiting unpatched IIS bug 07/09/2009 07:08:00

    The flaw could allow an attacker to take control of an older ISS server or launch a DoS attack
    Microsoft says that cyber-criminals are starting to exploit an unpatched bug in its IIS server software that was made public earlier this week.
  • Apple ships vulnerable Flash version with new Mac OS 04/09/2009 04:28:00

    Snow Leopard leaps out of the box but forgets to bring an update to Adobe's multimedia program
    Mac users may be surprised that versions of Apple's latest operating system, Snow Leopard, also installs an older version of Adobe System's Flash player, potentially putting them at a higher security risk.
  • Unpatched flaw could take down Microsoft's IIS server 02/09/2009 05:59:00

    A hacker has posted code that could be used to install unauthorized software on some versions of the server
    A hacker has posted code that could be used to take over a system running Microsoft IIS (Internet Information Services) server.
  • Cisco downplays WLAN vulnerability 26/08/2009 04:47:00

    AirMagnet, the security company that discovered the issue, said the hole could still create problems
    Cisco Systems downplayed a vulnerability in some of its wireless access points, reporting Tuesday that there is no risk of data loss or interception.
More >
Syndicate content
 
Gift Guide
Samsung

CXO Latest

LED Advisor
 

Colour your world with Samsung

A chance to win with every
Samsung Consumable purchase*