Sponsored White Papers, Webcasts, and Downloads
ZDNet Dictionary Definition
- Vulnerability
- A security exposure in an operating system or other system software or application software component. Before the Internet became mainstream and exposed every organization in the world to every...
- Full Vulnerability Definition >>
ZDNet Resources
- Mozilla tackles XSS vulnerabilities with new technology
- Mozilla's security engineers are working on new technology that promises to mitigate a large class of Web application vulnerabilities, especially the cross-site scripting XSS plague against modern Web browsers. The project, called Content Security Policy, is designed to shut down XSS attacks by providing a mechanism for...
- Tags: Vulnerability, XSS, Web Browser, Mozilla Corp., Web Browsers, Internet, Ryan Naraine
- Blog posts 2009-06-22
- Apple iPhone OS 3.0 update plugs 46 security holes
- Apple's latest iPhone OS 3.0 software updates includes patches for multiple vulnerabilities, some with serious security implications. The update, which is only available for download via iTunes, covers a total of 46 documented vulnerabilities, including several that allows malicious code execution if a user simply visits a...
- Tags: Apple iPhone, Malicious Code, Vulnerability, Apple Inc., Security, IPSec, Viruses And Worms, Networking, Ryan Naraine
- Blog posts 2009-06-17
- Apple finally patches musty old Java for Mac vulnerabilities
- Apple finally patches musty old Java for Mac vulnerabilitiesDisgusting behaviour by AppleBy not updating Java, they have not only left millions of users exposed, but they have left users dependent on Java unable to access certain web pages. They should, absolutely, let Sun maintain the Java updates.I say this...
- Tags: Programming languages, patch management, Java, Apple Inc., response time, Apple Macintosh
- Discussion threads 2009-06-15
- Apple finally patches musty old Java for Mac vulnerabilities
- Apple has finally released a Java for Mac update to fix multiple security flaws that were patched upstream more than six months ago. The fix comes three weeks after developers released proof-of-concept code to demonstrate the severity of the flaw and to nudge embarrass Apple into shipping...
- Tags: Apple Macintosh, Vulnerability, Patch Management, Apple Inc., Programming Languages, Java, Software Development, Software/Web Development, Ryan Naraine
- Blog posts 2009-06-15
- Coming in July: Month of Twitter Bugs
- A well-known security researcher plans to use the month of July to expose serious vulnerabilities in the Twitter ecosystem. The Month of Twitter Bugs, a project which launches on July 1, is the handiwork of Aviv Raff left, a researcher known for his work on Web-based security...
- Tags: Vulnerability, Twitter, Aviv Raff, Web 2.0, Security, Internet, Ryan Naraine
- Blog posts 2009-06-15
- Windows 7 UAC flaw: "Pandora's box of all vulnerabilities"
- The UAC flaw, a serious issue bubbling away underneath the surface of Microsoft's next operating system, has been described as the "Pandora's box of security vulnerabilities". But what is it exactly? Where did it all start from, what is the vulnerability and where do we go from here? Hopefully this...
- Tags: Standard User, Microsoft Windows 7, Flaw, Vulnerability, Malware, UAC, Microsoft Windows, Security, Operating Systems, Software, Zack Whittaker
- Blog posts 2009-06-12
- Security flaws galore: Researchers dissect China's Green Dam censorware
- A team of researchers at the University of Michigan has found a bevy of exploitable vulnerabilities in Green Dam, censorship software that the Chinese government wants to bundle on every PC. This week, the Wall Street Journal reported that China wanted to require PC makers to bundle...
- Tags: Software, China, Flaw, Vulnerability, Programming, Government, Tools & Techniques, Security, Development Tools, Management, Software Development, Software/Web Development, Larry Dignan
- Blog posts 2009-06-12
- Adobe patches 13 critical Reader, Acrobat vulnerabilities
- Adobe has issued its first ever scheduled quarterly update for its Reader/Acrobat product line, a mega-patch covering 13 documented security vulnerabilities. The patches address "critical vulnerabilities" in Adobe Reader 9.1.1 and Acrobat 9.1.1 and earlier versions. "These vulnerabilities would cause the application to crash and could potentially...
- Tags: Adobe Systems Inc., Adobe Acrobat, Vulnerability, Update, Arbitrary Code Execution, Memory Corruption Vulnerability, Security, Ryan Naraine
- Blog posts 2009-06-09
- Microsoft patches 31 Windows, IE, Office security holes
- Microsoft's batch of patches this month is a big one: 10 bulletins covering a total of 31 documented vulnerabilities affecting the Windows OS, the Internet Explorer browser and the Microsoft Office productivity suite (Word, Works and Excel). Five of the 10 bulletins are rated "critical," Microsoft's highest...
- Tags: Microsoft Word, Microsoft Windows Server, Window, Vulnerability, Microsoft Internet Explorer, Microsoft Corp., Microsoft Windows Server 2003, Microsoft Windows, Security, Microsoft Office, Operating Systems, Software, Office Suites, Ryan Naraine
- Blog posts 2009-06-09
- Apple Safari jumbo patch: 50 vulnerabilities fixed
- Apple Safari jumbo patch: 50 vulnerabilities fixedOf interestAdvisory here:http://support.apple.com/kb/HT3613TippingPoint's Zero Day Initiative credited with three CVE's.The big headline one exploiting SVG animation elements:CVE-ID: CVE-2009-1709Anyone want to beton which vendor will take the top spot of most vulnerable 2009? With this speed Apple is clearly going for the gold.The most...
- Tags: vulnerability, Apple Inc., Apple Safari
- Discussion threads 2009-06-08
- Apple Safari jumbo patch: 50+ vulnerabilities fixed
- Apple has shipped a whopper of a Safari browser update to fix more than 50 vulnerabilities, some rated extremely critical. The latest fixes, available in the new Safari 4.0, corrects a wide range of code execution and denial-of-service vulnerabilities and even comes with a fix for the...
- Tags: Apple Safari, Vulnerability, Apple Inc., Web Site, Web Site Development, Web Technology, Security, Internet, Ryan Naraine
- Blog posts 2009-06-08
- Patch Tuesday heads-up: Critical Windows, IE fixes coming
- Patch Tuesday heads-up: Critical Windows, IE fixes comingOnly 4 bulletins for VistaPlease pay attention to the versions, don't generalize, newer Windows versions have less vulnerabilities: on June 2009 Microsoft will release 7 bulletins for XP and only 4 bulletins for Vista ===> yet another reason to use VistaBut one of...
- Tags: Microsoft Windows Vista (Longhorn), SECURITY, Patches, Microsoft Windows Vista, vulnerability, Microsoft Windows XP, Microsoft Windows
- Discussion threads 2009-06-04
- Patch Tuesday heads-up: Critical Windows, IE fixes coming
- Microsoft plans to ship 10 security bulletins next Tuesday (June 9, 2009) with fixes for a wide range of code execution vulnerabilities affecting Windows, Microsoft Office and Internet Explorer. Six of the ten bulletins will be rated "critical," Microsoft's highest severity rating. ...
- Tags: Vulnerability, Patch Management, Microsoft Internet Explorer, Microsoft Corp., Attack, Microsoft Windows, Patches, Operating Systems, Security, Software, Ryan Naraine
- Blog posts 2009-06-04
- U.S. Army servers breached by Turkish hackers
- U.S. Army servers breached by Turkish hackers A question that puzzles meWhy on Earth is an US Army's Ammunition Plant and an US Army Corps of Engineers running insecure software from M$, more precisely Microsoft SQL Server?Presumably there are many other critical US institutions running dangerous software from M$. The...
- Tags: Databases, SECURITY, Servers, server, SQL injection, Turkish Hackers, SQL, Microsoft SQL Server, Microsoft Corp., vulnerability, U.S. Army
- Discussion threads 2009-06-01
- Dangerous Microsoft DirectX vulnerability under attack
- Dangerous Microsoft DirectX vulnerability under attackOne of Us Misread the ArticleQuote1: "... to exploit an unpatched vulnerability in DirectShow, the APIs used by Windows programs for multimedia support."Quote2: "Also, we?ve verified that it is possible to direct calls to DirectShow specifically, even if Apple?s QuickTime which is not vulnerable is...
- Tags: Microsoft Windows Vista (Longhorn), Digital music, Web browsers, SECURITY, Microsoft Corp., sandbox, Apple QuickTime, Dangerous Microsoft DirectX vulnerability, Dangerous Microsoft DirectX, vulnerability, DirectShow, Microsoft Windows Vista, attack, Microsoft Internet
- Discussion threads 2009-05-28
- Dangerous Microsoft DirectX vulnerability under attack
- Microsoft today warned that hackers are using rigged QuickTime media files to exploit an unpatched vulnerability in DirectShow, the APIs used by Windows programs for multimedia support. The company has activated its security response process to deal with the zero-day attacks has issued a pre-patch advisory with...
- Tags: Apple QuickTime, Vulnerability, Microsoft Corp., Web Browser, Attack, Microsoft Windows, Operating Systems, Security, Software, Ryan Naraine
- Blog posts 2009-05-28
- My Privacy 4.0 (Windows)
- Analyze your privacy vulnerability! My Privacy - is a software application intended for probing the confidential information stored on your computer on its vulnerability to unauthorized access by hackers. Your computer may contain private information which you have long forgotten about. These may include your credit card information, login names,...
- Tags: Software, Vulnerability, Privacy, Microsoft Windows, Computer, Cookie, Smart PC Solutions, Productivity, Tools & Techniques, Security, Management
- Software downloads 2009-05-27
- Mac OS X vulnerable to 6-month old Java flaw
- Attention Mac OS X users:Â Turn Java off immediately or you could be at high risk of malicious code execution attacks. Tired of waiting for a patch from Apple for a Java flaw that was fixed upstream six months ago, Mac developer Landon Fuller (of Month of...
- Tags: Malicious Code, Apple Macintosh, Java Applet, Flaw, Vulnerability, Apple Inc., Applet, Landon Fuller, CVE-2008-5353, Apple Mac OS X, Apple Mac OS, Java, Programming Languages, Operating Systems, Security, Software, Software Development, Software/Web Development, Ryan Naraine
- Blog posts 2009-05-20
- Microsoft confirms server vulnerability warning
- Microsoft has activated its security response process to deal with the release of a exploit code targeting an unpatched vulnerability affecting IIS 5.0 through 6.0. The company released a formal pre-patch advisory to acknowledge the vulnerability and offer mitigation guidance for customers. ...
- Tags: Vulnerability, WebDAV, Server, Microsoft Corp., Microsoft IIS Server, Thierry Zoller, Security, Ryan Naraine
- Blog posts 2009-05-19
- Apple eliminates CanSecWest Pwn2Own flaws
- Apple eliminates CanSecWest Pwn2Own flawsFault EliminationI did see the SVG fix in your article on 10.5.7's release and your relaying of Apple's attribution of discovery to "Nils." Regarding the IE8 issue, this is difficult to research because the signal to noise ratio is real low, but it looks as though...
- Tags: SECURITY, Patches, OSX, IE8, Apple Inc., vulnerability
- Discussion threads 2009-05-14

Introducing SmartPlanet
-
-
Find thought-provoking progressive ideas on topics that intersect with technology, business and life.
Visit Today
-
-
Technology, perspective, and insights shaping the world
-
Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large.
Go to SmartPlanet
White Papers and Webcasts