公司簡介   產品資訊   客戶服務   安全資源   顧問服務   合作伙伴   臺銀共同供應契約 


 


TO SUBSCRIBE, UNSUBSCRIBE, OR CHANGE YOUR SUBSCRIPTION, go to:
http://www.dragonsoft.com/epaper/

DragonSoft (Chinese/English) Vulnerability and Threat Knowledge Base:
. Chinese Version: http://vdb.dragonsoft.com.tw/
. English Version: http://vdb.dragonsoft.com/

Contents:
* 7 Reported Vulnerabilities
* Sort by Risk

-------------------------------------------------
Date Reported: 2004/07/27
Name: Apache Mod_SSL Log Function Format String Vulnerability
Risk: High
Category: Web Servers
Affect OS: 95, 98, Windows NT4, 2000, XP, 2003
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1981
Description (English): http://vdb.dragonsoft.com/detail.php?id=1981

Date Reported: 2004/07/27
Name: Samba Web Administration Tool Base64 Decoder Buffer Overflow Vulnerability
Risk: High
Category: NetBIOS
Affect OS: UNIX
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1980
Description (English): http://vdb.dragonsoft.com/detail.php?id=1980

Date Reported: 2004/07/27
Name: Samba Filename Mangling Method Buffer Overrun Vulnerability
Risk: High
Category: NetBIOS
Affect OS: UNIX
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1979
Description (English): http://vdb.dragonsoft.com/detail.php?id=1979

Date Reported: 2004/08/03
Name: MS04-025:MS IE GIF File Double Free Vulnerability
Risk: High
Category: MS HotFix
Affect OS: 98, Windows NT4, 2000, XP, 2003
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1986
Description (English): http://vdb.dragonsoft.com/detail.php?id=1986

Date Reported: 2004/08/03
Name: MS04-025:MS IE BMP File Buffer Overrun Vulnerability
Risk: High
Category: MS HotFix
Affect OS: 98, Windows NT4, 2000, XP, 2003
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1985
Description (English): http://vdb.dragonsoft.com/detail.php?id=1985

Date Reported: 2004/08/11
Name: MS04-026:Exchange Server 5.5 Outlook Web Access Cross-Site Scripting Vulnerability
Risk: Medium
Category: Mail Servers
Affect OS: NT
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1987
Description (English): http://vdb.dragonsoft.com/detail.php?id=1987

Date Reported: 2004/07/27
Name: Microsoft SMS Remote DoS Vulnerability
Risk: Low
Category: DoS
Affect OS: 98, Windows NT4, 2000, XP, 2003
Description (Chinese): http://vdb.dragonsoft.com.tw/detail.php?id=1982
Description (English): http://vdb.dragonsoft.com/detail.php?id=1982


-------------------------------------------------

Risk:
  High: Allow immediate remote, or local access or immediate execution of code or commands,
          with unauthorized privileges, and bypassing security on firewalls.
  Medium: Potential of granting access or allowing code execution by means of complex or 
          lengthy exploit procedures. Examples are cross-site scripting, man-in-the-middle 
          attacks, SQL injection, denial of service, information disclosure.
  Low: deny service or provide non-system information that could be used to formulate 
         structured attacks on a target, but not directly gain unauthorized access.
-------------------------------------------------
Copyright (c) 2002 DragonSoft Security Associate, Inc. All rights reserved

Permission is hereby granted for the electronic redistribution of this document.
It is not to be edited or altered in any way without the express written consent
of the DragonSoft Security Associate. If you wish to reprint the whole or any
part of this document in any other medium excluding electronic media, please email
alert@dragonsoft.com for permission.

Disclaimer: The information in the database may change without notice.
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information, implied or otherwise, 
with regard to this information or its use. Any use of this information is at 
the user's risk. In no event shall the author/distributor be held liable for any 
damages whatsoever arising out of or in connection with the use or spread of this information.

Please send suggestions, updates, and comments to: DragonSoft 
vdb@dragonsoft.com of DragonSoft Security Associate, Inc.

DragonSoft Security Associate, Inc. http://www.dragonsoft.com/
Tel. +886-3-5630989
Fax. +886-3-5797758
6F, No. 30, Lane 607, Sec. 1, Guangfu Rd., Hsinchu, Taiwan 300
Certification & Awards

2006-02
2005 MIS Best Choice

2006-02
DragonSoft Vulnerability Database - CVE-Compatibility Certificate

2005-12
Small and Medium Enterprise Business Start-Up Award

2005-12
Small and Medium Enterprise Innovation Research Award

2005-11
Golden Torch Award

2005-04
National Quality Guarantee Golden Award

2005-03
Golden Peak Award

2004-11
DragonSoft Secure Scanner - CVE-Compatibility Certificate
  Copyright© DragonSoft Security Associates, Inc. All rights reserved..
  台灣總部:新竹市光復路一段 607 巷 30 號 5F   Tel: 03-563-0989 Fax: 03-579-7758
  台北業務處:中和市中山路二段 351 號 9 F   Tel: 02-8221-5408 Fax: 02-8221-5476