Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

February 2010

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Mozilla Organization
Mozilla Thunderbird Multiple Vulnerabilities
27/02/10
Red Hat
Red Hat update for sudo
27/02/10
Sun Microsystems
Sun Solaris FreeType Multiple Vulnerabilities
27/02/10
Red Hat
Fedora update for mingw32-libltdl
26/02/10
GNU Project
GNU M4 "make dist" Insecure Directory Permissions
26/02/10
Sun Microsystems
Sun Java System Directory Server LDAP Search Request Denial of Service
26/02/10
IBM
IBM Products "login" Page Cross-Site Scripting Vulnerability
25/02/10
Canonical Ltd.
Ubuntu update for squid
25/02/10
Red Hat
Fedora update for cronie
25/02/10
Canonical Ltd.
Ubuntu update for openoffice.org
25/02/10
Avaya
Avaya CMS Solaris Python Multiple Vulnerabilities
25/02/10
Avaya
Avaya Products Multiple Vulnerabilities
25/02/10
Blue Coat Systems
Blue Coat Products TLS Session Renegotiation Plaintext Injection
25/02/10
Computer Associates (CA)
CA eHealth Performance Manager Cross-Site Scripting Weakness
24/02/10
Red Hat
Red Hat update for JBoss Enterprise Web Server
24/02/10
Google
Google Picasa JPEG Processing Integer Overflow Vulnerability
24/02/10
SuSE
SUSE Update for Multiple Packages
24/02/10
Computer Associates (CA)
CA Service Desk Tomcat Cross-Site Scripting Vulnerability
24/02/10
Debian
Debian update for linux-2.6
24/02/10
IBM
IBM WebSphere Portal Portlet Palette Cross-Site Scripting Vulnerability
23/02/10
Canonical Ltd.
Ubuntu update for pidgin
23/02/10
Red Hat
Fedora update for pdfedit
22/02/10
Red Hat
Fedora update for konversation
22/02/10
Red Hat
Fedora update for firefox and xulrunner
22/02/10
Debian
Debian update for php5
22/02/10
Debian
Debian update for polipo
22/02/10
Red Hat
Fedora update for pidgin
22/02/10
Red Hat
Fedora update for seamonkey
22/02/10
Red Hat
Fedora update for moin
22/02/10
Red Hat
Fedora update for bltk
19/02/10
Red Hat
Red Hat update for pidgin
19/02/10
Red Hat
Red Hat update for acroread
19/02/10
Canonical Ltd.
Ubuntu update for xmlrpc-c
19/02/10
Debian
Debian update for ffmpeg
19/02/10
Debian
Debian update for xulrunner
19/02/10
Symantec
Symantec IM Manager Script Insertion Vulnerability
19/02/10
Red Hat
Fedora update for systemtap
19/02/10
SuSE
SUSE update for kernel
19/02/10
Red Hat
Fedora update for krb5
19/02/10
IBM
IBM Cognos Express Tomcat Manager Hidden Default Account
19/02/10
IBM
IBM Lotus Notes Unspecified Buffer Overflow Vulnerability
19/02/10
Mozilla Organization
Mozilla Firefox Unspecified Code Execution Vulnerability
19/02/10
IBM
IBM Lotus Domino Buffer Overflow Vulnerability
19/02/10
Google
Google Gadget ActiveX Control ATL Templates Vulnerability
19/02/10
Novell
Novell Products Kerberos KDC Integer Underflow Vulnerabilities
19/02/10
Cisco
Cisco Security Agent Multiple Vulnerabilities
19/02/10
Symantec
Symantec Products "SYMLTCOM.dll" ActiveX Control Buffer Overflow
18/02/10
Symantec
Symantec Products Scanning Bypass Weakness
18/02/10
Cisco
Cisco PIX 500 Series Multiple Vulnerabilities
18/02/10
Cisco
Cisco ASA 5500 Series Multiple Vulnerabilities
18/02/10
Cisco
Cisco Firewall Services Module Denial of Service Vulnerability
18/02/10
Canonical Ltd.
Ubuntu update for firefox and xulrunner
18/02/10
Canonical Ltd.
Ubuntu update for firefox and xulrunner
18/02/10
Red Hat
Red Hat update for seamonkey
18/02/10
Symantec
Symantec Products Client Proxy ActiveX Control Buffer Overflow
18/02/10
Red Hat
Red Hat update for firefox
18/02/10
Debian
Debian update for kdelibs
18/02/10
Mozilla Organization
Mozilla Firefox Multiple Vulnerabilities
18/02/10
Mozilla Organization
Mozilla Thunderbird Multiple Vulnerabilities
18/02/10
Mozilla Organization
Mozilla SeaMonkey Multiple Vulnerabilities
18/02/10
Canonical Ltd.
Ubuntu update for ruby1.9
17/02/10
Canonical Ltd.
Ubuntu update for squid
17/02/10
Red Hat
Red Hat update for mysql
17/02/10
Red Hat
Red Hat update for mysql
17/02/10
Novell
SUSE update for postfix
17/02/10
Adobe Systems
Adobe Reader/Acrobat Two Vulnerabilities
17/02/10
VMware
VMware ESX Server update for net-snmp
17/02/10
Red Hat
Red Hat update for kernel
17/02/10
Red Hat
Red Hat update for NetworkManager
17/02/10
Red Hat
Fedora update for gnome-screensaver
17/02/10
SuSE
SUSE Update for Multiple Packages
17/02/10
Red Hat
Fedora update for mod_security
17/02/10
Red Hat
Fedora update for maildrop
17/02/10
Red Hat
Fedora update for openoffice.org
17/02/10
Red Hat
Fedora update for kernel
17/02/10
Red Hat
Fedora update for gambas
17/02/10
Red Hat
Fedora update for fwbuilder and libfwbuilder
17/02/10
SAP
SAP JAVA CORE Unspecified Phishing Vulnerability
17/02/10
SAP
SAP NetWeaver WebDynpro Runtime Cross-Site Scripting Vulnerability
17/02/10
Novell
Novell NetStorage Unspecified Code Execution Vulnerability
17/02/10
Novell
SUSE update for kernel
16/02/10
Novell
SUSE update for postfix
16/02/10
Juniper Networks
Juniper Networks Installer Service Buffer Overflow Vulnerability
16/02/10
Sun Microsystems
Sun Java System Products TLS Session Renegotiation Plaintext Injection
16/02/10
Red Hat
Fedora update for gnash
16/02/10
Debian
Debian update for linux-2.6
16/02/10
Debian
Debian update for mysql-dfsg-5.0
16/02/10
Red Hat
Red Hat update for openoffice.org
16/02/10
Debian
Debian update for openoffice.org
16/02/10
Red Hat
Red Hat update for flash-plugin
16/02/10
OpenOffice.org
OpenOffice.org 3 Multiple Vulnerabilities
16/02/10
OpenOffice.org
OpenOffice.org 2 Multiple Vulnerabilities
16/02/10
Adobe Systems
Adobe Products XML Processing Information Disclosure
16/02/10
Red Hat
Fedora update for kernel
16/02/10
SuSE
SUSE update for Multiple Packages
16/02/10
Sun Microsystems
Sun Solaris 9 Samba Information Disclosure and Denial of Service
16/02/10
Adobe Systems
Adobe Reader/Acrobat Domain Sandbox Bypass Vulnerability
16/02/10
HP
HP ProLiant Support Pack Visual C++ Redistributable Vulnerabilities
16/02/10
Adobe Systems
Adobe Flash Player Domain Sandbox Bypass Vulnerability
16/02/10
HP
HP DreamScreen Information Disclosure Vulnerability
16/02/10
Debian
Debian update for ajaxterm
16/02/10
Canonical Ltd.
Ubuntu update for tomcat6
16/02/10
Opera Software
Opera TLS Session Renegotiation Plaintext Injection Vulnerability
16/02/10
Cisco
Cisco IronPort Multiple Vulnerabilities
16/02/10
Google
Google Chrome Multiple Vulnerabilities
16/02/10
Canonical Ltd.
Ubuntu update for gnome-screensaver
16/02/10
Debian
Debian update for otrs2
16/02/10
HP
HP OpenView Network Node Manager Java JDK / JRE Multiple Vulnerabilities
16/02/10
HP
HP Network Node Manager Arbitrary Command Execution Vulnerability
16/02/10
Canonical Ltd.
Ubuntu update for mysql-dfsg-5 and mysql-dfsg-5.1
16/02/10
Microsoft
Microsoft Windows SMB Server Multiple Vulnerabilities
10/02/10
MySQL
MySQL yaSSL Certificate Processing Buffer Overflow Vulnerability
09/02/10
Oracle
Oracle Database Two Security Issues
09/02/10
Samba Team
Samba Insecure "wide links" Default Configuration Weakness
09/02/10
Oracle
Oracle WebLogic Server Node Manager Unspecified Vulnerability
08/02/10
Red Hat
Fedora update for chrony
08/02/10
IBM
WebSphere Application Server "Requires SSL" Option Security Issue
06/02/10
Mozilla Organization
Network Security Services (NSS) TLS Session Renegotiation Vulnerability
06/02/10
Red Hat
Fedora update for nss
06/02/10
IBM
IBM WebSphere Application Server TLS Session Renegotiation Plaintext Injection
06/02/10
SuSE
SUSE update for kernel
06/02/10
Debian
Debian update for chrony
05/02/10
Avaya
Avaya CMS Solaris NTP Mode 7 Request Denial of Service
05/02/10
Canonical Ltd.
Ubuntu update for kernel
05/02/10
F5 Networks
F5 Products TCP Implementation Denial of Service
05/02/10
F5 Networks
F5 BIG-IP TCP Implementation Denial of Service
05/02/10
Samba Team
Samba Symlink Handling Directory Traversal Vulnerability
05/02/10
Red Hat
Fedora update for dokuwiki
05/02/10
Red Hat
Fedora update for ejabberd
05/02/10
Red Hat
Fedora update for gmime22
05/02/10
Red Hat
Fedora update for kernel
05/02/10
Debian
Debian update for trac-git
05/02/10
Debian
Debian update for squid and squid3
05/02/10
IBM
IBM DB2 Multiple Vulnerabilities
05/02/10
IBM
IBM DB2 Multiple Vulnerabilities
05/02/10
Novell
Novell NetStorage Unspecified Code Execution Vulnerability
05/02/10
Apple
iPhone Configuration Profiles Spoofing Security Issue
05/02/10
HP
HP System Management Homepage Cross-Site Scripting Vulnerability
04/02/10
Debian
Debian update for trac-git
04/02/10
IBM
IBM Cognos Express Tomcat Manager Hardcoded Credentials
04/02/10
Trend Micro
Trend Micro OfficeScan URL Filtering Engine Buffer Overflow
04/02/10