<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CVE : Nchovy &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</title>
  <link type="text/html" href="http://nchovy.kr/security/cve" rel="alternate"/>
  <author>
    <name>NCHOVY &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</name>
    <email>xeraph@nchovy.kr</email>
  </author>
  <entry>
    <title>CVE-2010-3197</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3197</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3197" rel="alternate"/>
    <content>IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3196</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3196</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3196" rel="alternate"/>
    <content>IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3195</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3195</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3195" rel="alternate"/>
    <content>Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3194</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3194</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3194" rel="alternate"/>
    <content>The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3191</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3191</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3191" rel="alternate"/>
    <content>Per: http://cwe.mitre.org/data/definitions/426.html

CWE-426: Untrusted Search Path</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3190</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3190</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3190" rel="alternate"/>
    <content>Untrusted search path vulnerability in ATL MFC Trace Tool (AtlTraceTool8.exe), as used in Microsoft Visual Studio, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a TRC, cur, rs, rct, or res file.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3189</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3189</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3189" rel="alternate"/>
    <content>The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-3188</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-3188</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-3188" rel="alternate"/>
    <content>SQL injection vulnerability in search.aspx in BugTracker.NET 3.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via a custom field to the search page.</content>
    <published>2010-09-01T00:00:00+09:00</published>
    <updated>2010-09-01T00:00:00+09:00</updated>
  </entry>
</feed>
