eWeek Security Watch
Advertisement
Advertisement

Patches Archive

December 17, 2008

Wednesday, December 17, 2008 5:10 PM/EST

Attackers Hammering New IE Flaw via SQL Injection

Symantec reported tha it is seeing quite a bit of malware activity related to the newly-reported IE memory corruption flaw, with attacks centered in Asia.

Read more... | Comment | del.icio.us | digg.com | View all of Microsoft Windows

December 8, 2008

Monday, December 08, 2008 5:15 PM/EST

Research Shows Almost No PCs Fully Patched

Secunia reports that based on a free scanning application that it has distributed to end users over the last year, less than 2 percent of PCs are fully updated with patched software.

Read more... | Comment | del.icio.us | digg.com | View all of Patches

May 6, 2008

Tuesday, May 06, 2008 11:18 AM/EST

Big Vendors Still Very Tardy on Fixing Security Flaws

Some of the biggest names in the IT software business still are very lax when it comes to fixing security holes reported by third-party brokers. According to a list maintained by TippingPoint's Zero Day Initiative, Microsoft, Novell, Oracle, Computer Associates...

Read more... | Comment | del.icio.us | digg.com | View all of Patches

April 22, 2008

Tuesday, April 22, 2008 3:43 PM/EST

High-Profile OLPC Defections Bad for Security

There's a serious brain drain affecting the OLPC (One Laptop Per Child) initiative and it's not a good sign for security. The latest high-profile defector from the nonprofit organization is Walter Bender, a former MIT Media Lab executive who...

Read more... | Comment | del.icio.us | digg.com | View all of Open Source
Tuesday, April 22, 2008 2:55 PM/EST

QuickTime Zero-Day Hits Windows XP, Vista

Security researcher Petko D. Petkov (aka pdp) has discovered a gaping hole in fully patched versions of Apple's QuickTime for Windows Media Player. The zero-day vulnerability allows an attacker to use rigged movie (.mov) files to take full control of...

Read more... | Comment | del.icio.us | digg.com | View all of Apple
Tuesday, April 22, 2008 10:12 AM/EST

Adobe Issues Warning for Unpatched Photoshop Flaw

Adobe has issued a prepatch advisory for a critical vulnerability in Photoshop Album Starter Edition 3.2, its free image-manipulation software product. The flaw, which affects Windows users, could be exploited to launch code execution attacks if the target is...

Read more... | Comment | del.icio.us | digg.com | View all of Flaws

April 21, 2008

Monday, April 21, 2008 4:44 PM/EST

Windows XP SP3: NAP Among Security Goodies

Microsoft's Windows XP SP3 (Service Pack 3) is finally here, offering several subtle security goodies alongside thousands of bug fixes. The biggest security feature in this service pack is the inclusion of NAP (Network Access Protection) to help organizations...

Read more... | Comment | del.icio.us | digg.com | View all of Microsoft Windows

April 19, 2008

Saturday, April 19, 2008 6:40 PM/EST

OpenOffice Bitten by Code Execution Bugs

OpenOffice has issued a high-priority update to fix at least six vulnerabilities affecting users of its free desktop productivity suite. The open-source group said the critical vulnerabilities affect OpenOffice.org suite versions prior to 2.4. An alert from Symantec's DeepSight...

Read more... | Comment | del.icio.us | digg.com | View all of Open Source

April 18, 2008

Friday, April 18, 2008 12:36 PM/EST

Microsoft (Belatedly) Admits to Windows Server 2008 Token Kidnapping

[[ UPDATE: Here are the slides from Cerrudo's HiTB talk (.pdf) that prompted Microsoft's advisory. At the company's request, Cerrudo has opted not to release exploit code. ]] Last month, when I wrote about hacker Cesar Cerrudo's (left) plans to...

Read more... | Comment | del.icio.us | digg.com | View all of Flaws

March 28, 2008

Friday, March 28, 2008 10:43 PM/EST

Vista Hacked with Adobe Flash Vulnerability

Using a zero-day vulnerability in Adobe's ubiquitous Flash Player, hacker Shane Macaulay hacked into a Windows Vista laptop to win a $5,000 cash prize at this year's CanSecWest Pwn2Own challenge. Macaulay, who uses the "K2" hacker moniker, also won...

Read more... | Comment | del.icio.us | digg.com | View all of Exploits and Attacks
Previous Viewing articles: 10 - 20 Next
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise