phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, click here to contact us.

Published: 2009-11-22,
Last Updated: 2009-11-22 03:58:31 UTC
by Marcus Sachs (Version: 3)
0 comment(s) Facebookacebook witter

According to VUPEN security:

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the "getElementsByTagName()" method, which could allow attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a malicious web page.

We have not verified this claim, but would like to know if any of our readers have.  Please use our contact form to reply, or add your comments below.

UPDATE 1:

Jack wrote to tell us that Symantec has verified the bug:

November 21, 2009 - "A new exploit targeting Internet Explorer was published to the BugTraq mailing list yesterday. Symantec has conducted further tests and confirmed that it affects Internet Explorer versions 6 and 7 as well. The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future... To minimize the chances of being affected by this issue, Internet Explorer users should ensure their antivirus definitions are up to date, disable JavaScript and only visit Web sites they trust until fixes are available from Microsoft."

Marcus H. Sachs
Director, SANS Internet Storm Center

Keywords: 0day ie6 ie7 zero day
0 comment(s) Facebookacebook witter

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2009-11-22Marcus Sachs IE7 and IE8 0-Day Reported
2009-11-21Mark Hofman What is making you vulnerable?
2009-11-19Joel Esler Fedora to allow the installation of packages, without root privileges?
2009-11-18Rob VandenBrink Using a Cisco Router as a “Remote Collector” for tcpdump or Wireshark
2009-11-17Guy Bruneau OpenVPN Fixed OpenSSL Session Renegotiation Issue
2009-11-17Guy Bruneau Metasploit Framework 3.3 Released
2009-11-16G. N. White Reports of a successful exploit of the SSL Renegotiation Vulnerability?
2009-11-14Adrien de Beaupre Microsoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-13Adrien de Beaupre TLS & SSLv3 renegotiation vulnerability explained
2009-11-13Adrien de Beaupre Flash Origin Policy Attack
Complete Archive
Search Diaries:

StormCast


last update 07 hrs 37 min ago.

Featured Event

Latest Reading Room Papers

Gathering Security Metrics and Reaping the Rewards
Hey Dude! I Can Do a Great Humphrey Bogart!
A Multi-Perspective View of PHP Remote File Include Attacks
Check Point Firewall Log Analysis In-Depth
Efficiently Deducing IDS False Positives Using System Profiling

Poll

I back up data on my home PCs...
daily, or whenever files change or get added
once a week
once a month
every now and then
other (please leave comment)

Trends

trends more details

World Map

Worldmap