Entire Site
DOE-CIRC
DOE-CIRC Home
DOE-CIRC Home
About CIRC
About CIRC
Incident Reporting
Incident Reporting
Scope
Reportable Incidents
Reporting Procedures
Report Content
Forms
Negative Reporting
Bulletins
Bulletins
Latest
Latest
High Risk
High Risk
Revised
Revised
Bulletin Archive
Bulletin Archive
Technical Bulletins
Technical Bulletins
Search
Search
C-Notes
C-Notes
Recent C-Notes
Recent C-Notes
C-Notes Archive
C-Notes Archive
Documents
and Publications
Documents and Publications
CIRC Documents
Other Publications
Conference Proceedings
Public Law
Tools
Tools
NID and SafePatch
DISA INFOSEC Tools
Multi-Platform Trusted Copy
IEBT v.1.01
Public Tools
-Windows
-Windows
-MAC
-MAC
-UNIX
-UNIX
Security Links
Security Links
Advanced Search
Advanced Search
Contact CIRC
Contact CIRC
Maintenance Schedule
The DOE-CIRC server will be unavailable during the following scheduled events:
Routine maintenance:
Every Thursday from 5:00 - 9:00pm (PST)
You are here:
DOE Home
>
CIO Home
>
CIRC Home
>
Bulletins
>
Archive
>
O Series
O Series Bulletins (FY 2004):
O-001: Sun aspppls(1M) does not create the temporary file /tmp/.asppp.fifo safely
O-002: Microsoft Internet Explorer Cumulative Patch
O-003: HP Potential Security Vulnerability in dtprintinfo
O-004: Microsoft Buffer Overrun in Messenger Service Could Allow Code Execution
O-005: Microsoft Exchange Server Vulnerabilities
O-006: Microsoft Authenticode Verification Vulnerability
O-007: Microsoft Windows Help and Support Center Buffer Overrun Vulnerability
O-008: Microsoft Troubleshooter ActiveX Control Buffer Overflow Vulnerability
O-009: Microsoft Listbox and ComboBox Control Buffer Overrun Vulnerabilities
O-010: Microsoft Exchange Server 5.5 Outlook Web Access Vulnerability
O-011: Sun Vulnerability in Solaris "AnswerBook2 Documentation" Admin Script
O-012: Sun Vulnerability in Solaris "AnswerBook2 Documentation" Server Daemon
O-013: Buffer Overflow in Oracle Binary
O-014: SGI Wildcard Exportfs Issue in Network File System (NFS)
O-015: Apache HTTP Server 2.0.48 Release Fixes Security Vulnerabilities
O-016: Apache HTTP Server 1.3.29 Release Fixes Security Vulnerability
O-017: Oracle SQL Injection Vulnerability in Oracle9i Application Server
O-018: Hewlett Packard Java VM Classloader (J2SE)
O-019: Hewlett Packard NLSPATH may contain any path
O-020: Sun Buffer Overflow Vulnerability in the CDE DtHelp Library
O-021: Microsoft Cumulative Security Update for Internet Explorer
O-022: Microsoft Buffer Overrun Vulnerability in Workstation Service
O-023: Microsoft Word and Excel Vulnerabilities
O-024: Microsoft Buffer Overrun in Microsoft FrontPage Server Extensions
O-025: PeopleSoft IClient Servlet Remote Command Execution Vulnerability
O-026: Red Hat Updated PostgreSQL Packages Fix Buffer Overflow
O-027: Red Hat Updated XFree86 Packages Provide Security and Bug Fixes
O-028: Hewlett Packard dtmailpr
O-029: Sun Security Vulnerability on Sun Systems with a PGX32 Frame Buffer
O-030: Hewlett Packard VirtualVault OpenSSH Vulnerabilities
O-031: Red Hat Updated 2.4 Kernel Fixes Privilege Escalation Security Vulnerability
O-032: HP shar(1) Utility Vulnerability
O-033: Sun Xsun Server in Direct Graphics Access (DGA) Vulnerabilities
O-034: rsync Heap Overflow Vulnerability
O-035: Sun 'dtprintinfo(1)' CDE Print Viewer Vulnerability
O-036: CISCO Authentication Library in ACNS Vulnerability
O-037: Red Hat GnuPG Packages ElGamal Keys Vulnerability
O-038: CISCO Unity Vulnerabilities on IBM-based Servers
O-039: CISCO FWSM Vulnerabilities
O-040: CISCO PIX Vulnerabilities
O-041: Sun 'lpstat' Printing Vulnerability
O-042: Red Hat 'lftp' Buffer Overflow Vulnerability
O-043: Red Hat Updated Kernel Packages
O-044: Sun Security Issue Involving the tcsh(1) ls-F Builtin on Solaris 8
O-045: Red Hat 'mremap()' function Vulnerability
O-046: HP 'ypxfrd' daemon Vulnerability
O-047: Debian 'nd' WebDAV command line Buffer Overflow Vulnerability
O-048: Debian fsp Buffer Overflow Vulnerability
O-049: Red Hat Updated CVS Packages Fix Minor Security Issue
O-050: Cisco Vulnerabilities in H.323 Message Processing
O-051: Microsoft Buffer Overflow in ISA Server 2000
O-052: Microsoft Vulnerability in Exchange Server 2003 Could Lead to Privilege Escalation
O-053: Microsoft Buffer Overrun in MDAC Function Could Allow Code Execution
O-054: Red Hat Updated kdepim Packages Resolve Security Vulnerability
O-055: Red Hat Updated elm Packages Fix Vulnerability in frm Command
O-056: Hewlett-Packard dtterm Vulnerability
O-057: Hewlett-Packard libDtSvc Vulnerability
O-058: Hewlett-Packard SharedX Vulnerability
O-059: Debian Linux-Kernel-2.4.17-ia64 Vulnerabilities
O-060: Debian Password Expiration Vulnerability
O-061: Red Hat Updated tcpdump Packages Fix Various Vulnerabilities
O-062: CERT: Multiple H.323 Message Vulnerabilities
O-063: Red Hat Elevated Privileges Vulnerability
O-064: HP 'rwrite' Utility Vulnerability
O-065: Security Vulnerabilities in ASN.1
O-066: Cisco - Voice Product Vulnerabilities on IBM Servers
O-067: Sun Vulnerability with Loading Arbitrary Kernel Modules
O-068: Microsoft Internet Explorer Cumulative Patch
O-069: Sun kcms_server Daemon Vulnerability
O-070: Sun Basic Security Module (BSM) Vulnerability
O-071: Debian kernel-patch-2.4.17 Interger Overflow
O-072: Check Point FireWall-1 HTTP Security Server Vulnerability
O-073: Check Point VPN-1 Server and VPN Client Buffer Overflow Vulnerability
O-074: Red Hat Cross-site Scripting Vulnerability in Mailman Package
O-075: RealPlayer / RealOne Player Buffer Overrun Vulnerabilities
O-076: Microsoft Vulnerability in Virtual PC for Mac
O-077: Microsoft Vulnerability in the Windows Internet Naming Service (WINS)
O-078: Samba - Unauthorized Access to SMB Accounts
O-079: SGI - Userland Binary Vulnerabilities
O-080: Novell iChain Telnet Service Vulnerability
O-081: Red Hat Updated XFree86 Packages Fix Privilege Escalation Vulnerability
O-082: Red Hat Updated Kernel Packages Resolve Security Vulnerabilities
O-083: Red Hat Updated Metamail Packages Fix Vulnerabilities
O-084: Zone Labs SMTP Processing Vulnerability
O-085: Vulnerability in SMB Parsing in ISS Products
O-086: Red Hat Updated libxml2 Packages Fix Security Vulnerability
O-087: Red Hat Updated util-linux Packages Fix Information Leak
O-088: Sun passwd(1) Command Vulnerability
O-089: Sun Security Vulnerability in "/usr/lib/print/conv_fix"
O-090: Vulnerability in Novell Client Firewall Tray Icon
O-091: Adobe Reader 5.1 XFDF Buffer Overflow Vulnerability
O-092: WinZip Vulnerable to Buffer Overflow in Handling of MIME Archive Parameters
O-093: Oracle9i Database Buffer Overflow Vulnerabilities
O-094: Linux mremap(2) System Call Vulnerability
O-095: wu-ftpd 'chmod' and S/Key Vulnerabilities
O-096: Microsoft Outlook Could Allow Unauthorized Code Execution
O-097: Red Hat Sysstat Packages contain Vulnerability
O-098: NetScreen IVE Vulnerability may lead to Remote Script Execution
O-099: Sun Basic Security Module Auditing Functionality Vulnerability
O-100: Certificate Compromise using HP HTTP Server
O-101: OpenSSL Denial of Service Vulnerability
O-102: IBM AIX rexecd Vulnerability
O-103: Apache HTTP Server mod_access Information Disclosure
O-104: ICQ Parsing in ISS Products May Lead to Buffer Overflow
O-105: Multiple Vulnerabilities in Ethereal 0.10.2
O-106: Mozilla 1.4.2 Vulnerabilities
O-107: vfte Buffer Overflow Vulnerabilities
O-108: Squid ACL Bypass Vulnerability
O-109: Heimdal Kerberos Cross-Realm Vulnerability
O-110: MAC OS X Jaguar and Panther Security Vulnerabilities
O-111: CISCO WLSE and HSE Contain Default Passwords
O-112: Cisco IPSec Module Malformed IKE Packet Vulnerability
O-113: 'tcpdump' Denial of Service
O-114: Microsoft Security Update for Microsoft Windows
O-115: Microsoft Cumulative Update for RPC/DCOM
O-116: Microsoft Cumulative Security Update for Outlook Express
O-117: Microsoft Jet Database Engine Buffer Overrun
O-118: HP OpenView Operations Remote Unauthorized Access
O-119: HP Tru64 UNIX WU-FTPD Security Vulnerabilities
O-120: HP Web Jetadmin Security Vulnerabilities
O-121: linux-kernel-2.4.17, 2.4.18 and 2.4.19 Vulnerabilities
O-122: Red Hat Updated OpenOffice Packages Fix Security Vulnerability in Neon
O-123: Debian 483-1 MySQL
O-124: Cisco TCP Vulnerabilities in Multiple Cisco Products
O-125: Cisco Vulnerabilities in SNMP Message Processing
O-126: Red Hat Updated Kernel Packages Fix Several Vulnerabilities
O-127: Linux kernel Vulnerabilities
O-128: Apache HTTP Server 2.0.49 Release Fixes Security Vulnerabilities
O-129: Common Desktop Environment (CDE) dtlogin XDMCP parser Vulnerability
O-130: Perl and ActivePerl win32_stat Buffer Overflow
O-131: AIX Symlink and Buffer Overflow Vulnerabilities in LVM Commands
O-132: BEA WebLogic Server and Express Certificate Spoofing Vulnerability
O-133: 'utempter' Package Vulnerability
O-134: 'rsync' Directory Traversal Vulnerability
O-135: Apple QuickTime Integer Overflow
O-136: HP Web JetAdmin Vulnerabilities
O-137: SGI IRIX Networking Security Vulnerabilities
O-138: Mac OS X Jaguar and Panther Security Vulnerabilities
O-139: Apple Mac OS X AppleFileServer Authentication Vulnerability
O-140: Microsoft HCP Protocol URL Validation Vulnerability
O-141: Symantec Client Firewall Remote Access Vulnerabilities
O-142: Hewlett Packaged HP-UX dtlogin Vulnerability
O-143: Gnome Toolkit (GTK+) Support Libraries Vulnerability
O-144: Sun ypserv and ypxfrd Vulnerabilities
O-145: Red Hat Updated Kernel Packages for Enterprise Linux 3
O-146: kdelibs Package Vulnerabilities
O-147: Linux CVS Server Heap Overflow Vulnerability
O-148: Linux Neon and Cadaver Buffer Overflow Vulnerability
O-149: Norton AntiVirus 2004 ActiveX Control Vulnerability
O-150: Multiple Security Problems in Ethereal 0.10.3
O-151: Apple Mac OS X Help Viewer Vulnerability
O-152: HP OpenView Select Access Remote Unauthorized Access
O-153: Oracle E-Business Suite SQL Injection Vulnerability
O-154: Microsoft – Crystal Reports Web Viewer Information Disclosure Vulnerability
O-155: Kerberos Buffer Overflow Vulnerability
O-156: Multiple Vulnerabilities in CVS
O-157: Cisco CatOS Telnet, HTTP and SSH Vulnerability
O-158: FTP Client Improperly handles Pipe Character in File Names
O-159: NETGEAR WG602 Wireless Access Point Default Backdoor Account Vulnerability
O-160: Microsoft Windows 2000 Advanced Server Security Bypass
O-161: RealPlayer Security Vulnerabilities
O-162: Red Hat Updated Tripwire Packages Fix Security Flaw
O-163: Cisco IOS Malformed BGP Packet Causes Reload
O-164: Red Hat Updated Kernel Packages Fix Security Vulnerabilities
O-165: Updated libpng Packages Fix Security Issue
O-166: Sun StorEdge Enterprise Storage Manager (ESM) 2.1 Vulnerability
O-167: SGI - System Call SGI_IOPROBE Vulnerability
O-168: Squid - NTLM Authentication Buffer Overflow Vulnerability
O-169: Apache Buffer Overflow Vulnerability
O-170: HP-UX Netscape Vulnerabilities
O-171: Hewlett Packard OpenSSL Potential Vulnerabilities
O-172: Sun Solaris 9 Patches
O-173: Debian Webmin Vulnerabilities
O-174: Ethereal Multiple Problems in 0.10.4
O-175: 'shell:' Protocol Security Issue
O-176: Adobe Acrobat and Adobe Reader Filename Handler Buffer Overflow
O-177: Multiple Vulnerabilities in ISC DHCP 3
O-178: Vulnerability in Task Scheduler Could Allow Code Execution
O-179: Microsoft Update for IIS 4.0 (841373)
O-180: Microsoft Utility Manager Vulnerability
O-181: Microsoft Vulnerability in POSIX Could Allow Code Execution
O-182: Microsoft Vulnerability in HTML Help Could Allow Code Execution
O-183: Microsoft Vulnerability in Windows Shell Could Allow Remote Code Execution
O-184: PHP memory_limit and strip_tags Vulnerabilities
O-185: Sun Java System Web Server Cross-site Scripting Vulnerability
O-186: Samba Buffer Overrun Vulnerabilities
O-187: 'chown(2)' System Call Vulnerability
O-188: libapache-mod-ssl
O-189: HP-UX xfs and stmkfont Vulnerabilities
O-190: Check Point ASN.1 VPN-1 Buffer Overrun
O-191: Microsoft Cumulative Security Update for Internet Explorer (867801)
O-192: libpng" Package Vulnerabilities
O-193: Linux Kernel Packages Updated
O-194: GNOME VFS "extfs" Vulnerability
O-195: Mozilla Updated Security Packages
O-196: "glibc" Buffer Overflow Vulnerabilities
O-197: Microsoft Exchange Server 5.5 Outlook Web Access Vulnerability
O-198: 'rsync' Unsanitised Input Processing
O-199: Cisco IOS Malformed OSPF Packet Causes Reload
O-200: Updated PAM Packages
O-201: Qt Package Vulnerabilities
O-202: Buffer Overflow in the CDE Mailer dtmail(1X)
O-203: Cisco Secure Access Control Server Vulnerabilities
O-204: Netscape NSS Library Suite Remote Buffer Overflow
O-205: Adobe Acrobat Reader Uuencoding Buffer Overflow
O-206: Entrust LibKmp Library Vulnerabilities
O-207: Cisco IOS Telnet Denial of Service Vulnerability
O-208: Kerberos krb5 Vulnerabilities
O-209: Oracle Database Server Vulnerabilities
O-210: LHA Packages Buffer Overflow Vulnerability
O-211: Potential Buffer Overflows in WinZip
O-212: Apple Security Update
O-213: Windows Buffer Overrun in JPEG Processing Could Allow Code Execution
O-214: Windows Vulnerability in WordPerfect Converter Could Allow Code Execution
O-215: "imlib" and "imlib2" Packages Vulnerability
O-216: "gtk2" Package vulnerability
O-217: "gdk-pixbuf" Package vulnerability
O-218: HP Web Jetadmin Remote Access Vulnerability
O-219: Sudo - "Sudoedit" Vulnerabilities
O-220: "Any to PostScript" (a2ps) Filter Vulnerability
O-221: Apache HTTP Server 2.0.52 Released
O-222: libXpm Library Contains Multiple Integer Overflow Vulnerabilities
O-223: RealNetworks, Inc. Releases Update to Address Security Vulnerabilities
U.S. Department of Energy | 1000 Independence Ave., SW | Washington, DC 20585
1-800-dial-DOE | f/202-586-4403