Deutschland   > Land auswählen

Sicherheitsinformationen

Xerox hat sich der Lösung von Sicherheitsproblemen verschrieben, die unsere Produkte betreffen. Diese Site bietet Xerox Kunden Informationen zu potenziellen Sicherheitslücken in Xerox Produkten. Informationen zu Sicherheitsfunktionen, die für Xerox Produkte zur Verfügung stehen, finden Sie auf den Produkt-Webseiten.

Diese Seite enthält zwei Tabellen mit Informationen: Weitere Informationen zu unseren Maßnahmen zur Behebung von Sicherheitslücken erhalten Sie direkt von Xerox.

Security News and Advisories

Document Title:Date:File Size:
Xerox Security Bulletin XRX08-004July 6, 20081 MB
Xerox Security Bulletin XRX08-003April 21, 200850 KB
Xerox Security Bulletin XRX08-001Jan. 30, 200862 KB
Xerox Security Bulletin XRX07-002Oct. 11, 2007155 KB
Xerox Security Bulletin XRX07-001July 29, 2007222 KB
Xerox Security Bulletin XRX06-007Nov. 30, 2006128 KB
Xerox Security Bulletin XRX06-006Nov. 30, 2006128 KB
Xerox Security Bulletin XRX06-005Nov. 30, 2006128 KB
Xerox Security Bulletin XRX06-004Nov. 30, 2006128 KB
Xerox Security Bulletin XRX06-003May. 06, 2006128 KB
Xerox Security Bulletin XRX06-002Jun. 03, 2006 (English:
updated Oct 2006)
128 KB
Xerox Security Bulletin XRX06-001Feb. 20, 2006189 KB
Xerox Security Bulletin XRX05-009Aug. 10, 2005128 KB
Xerox Security Bulletin XRX05-008Aug. 10, 2005189 KB
Xerox Security Bulletin XRX05-007Aug. 25, 2005132 KB
Xerox Security Bulletin XRX05-006June. 27, 2005121 KB
Xerox Security Bulletin XRX05-004Mar. 14, 200580 KB
Xerox Security Bulletin XRX05-003Mar. 14, 200580 KB
Xerox Security Bulletin XRX05-001Jan. 20, 200580 KB
Xerox Security Bulletin XRX04-009
Mar. 25, 200593 KB
Xerox Security Bulletin XRX04-008
Aug. 31, 200493 KB
Xerox Security Bulletin XRX04-007
www.xerox.com/downloads/usa/en/c/cert_XRX04D_patch.zip
Aug. 31, 2004101 KB
2.1 MB
Xerox Security Bulletin XRX04-006
www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Aug. 31, 2004103 KB
613 KB
www.xerox.com/downloads/usa/en/c/cert_XRX04A_patch.zipAug. 31, 2004118 KB
8.4 MB
Xerox Security Bulletin XRX04-004
www.xerox.com/downloads/usa/en/c/cert_XRX04-04_patch.zip
June 24, 200499 KB
28 MB
Xerox Security Bulletin XRX04-003
http://www.xerox.com/downloads/usa/en/c/cert_PS_Patch_WCP.zip
April 14, 2004146 KB
6 MB
Xerox Security Bulletin XRX04-002
http://www.xerox.com/downloads/usa/en/c/cert_HTTP_Patches.zip
March 10, 2004116 KB
28 MB
Secure Installation and Operation of Your CopyCentre™ C65/C75/C90
or WorkCentre™ Pro 65/75/90
Oct. 4, 2004140 KB
DigiPath Microsoft Patch SummaryAugust 18, 200637 KB
Secure Installation and Operation of Your WorkCentre™ M35/M45/M55
or WorkCentre Pro™ 35/45/55
Oct. 4, 2004104 KB
Security and the DocuColor 3535 EPC Hard Disk DriveNov. 19, 200314 KB
Xerox Products and Anti-Virus SoftwareFeb. 25, 200457 KB
CopyCentre™ / WorkCentre™ / WorkCentre Pro™ Security OverviewJul. 11, 2003505 KB
Xerox Product Implications When FTP Is DisabledMay 8, 200332.4 KB
CentreWare Web and the Microsoft MSDE / SQL Worm VulnerabilityFeb. 11, 20038 KB
Xerox Fiery-based DocuColor, DocuSP-based DocuTech, DigiPath and Document Centre Product SecurityJul. 18, 200221.5 KB
Xerox Document Centre Security Overview 370 KB


Xerox Responses to CERT Advisories and Vulnerability Notes

CERT Advisory or
Vulnerability Note
Number:
Document Title:Sort By:
Revision Date:
File Size:
TA04-033AMultiple Vulnerabilities in Microsoft Internet Explorer (MS04-004)May, 13 200592 KB
TA04-041AMultiple Vulnerabilities in Microsoft ASN.1 Library (MS04-007)May, 13 200586 KB
TA04-078AMultiple Vulnerabilities in OpenSSLJune 10, 200564 KB
TA04-099ACross-Domain Vulnerability in Outlook Express MHTML Protocol HandlerMay, 13 200576 KB
TA04-104AMultiple Vulnerabilities in Microsoft ProductsMay, 13 200596 KB
TA04-111AVulnerabilities in TCPApril 5, 200564 KB
TA04-163ACross-Domain Redirect Vulnerability in Internet ExplorerJune 13, 200581 KB
TA04-174AMultiple Vulnerabilities in ISC DHCP 3June 14, 200562 KB
TA04-184AInternet Explorer Update to Disable ADODB.Stream ActiveX ControlJune 13, 200588 KB
TA04-212ACritical Vulnerabilities in Microsoft Windows (MS04-025)June 13, 200587 KB
TA04-217AMultiple Vulnerabilities in libpngMay, 13 200572 KB
TA04-260AMicrosoft Windows JPEG component buffer overflowMay 13, 2005101 KB
TA04-293AMultiple Vulnerabilities in Microsoft Internet Explorer (MS04-038)May 13, 2005101 KB
TA04-315ABuffer Overflow in Microsoft Internet ExplorerJune 13, 2005103 KB
TA04-336AUpdate for Microsoft Internet Explorer HTML Elements Vulnerability (MS04-040)June 13, 2005103 KB
TA05-012BMicrosoft Windows HTML Help ActiveX Control Cross-Domain Vulnerability (MS05-001)May 13, 2005101 KB
CA-2004-01Multiple H.323 Message Vulnerabilities (MS04-001)April 5, 200564 KB
CA-2004-02Email-borne VirusesApril 5, 200557 KB
CA-2003-04MS-SQL Server Worm (MS02-061)Dec. 8, 200332 KB
CA-2003-07Remote Buffer Overflow in SendmailJan. 22, 200435 KB
CA-2003-12Buffer Overflow in SendmailJan. 22, 200435 KB
CA-2003-16Buffer Overflow in Microsoft RPC (MS03-026)Jan. 12, 200439 KB
CA-2003-19Exploitation of Vulnerabilities in Microsoft RPC Interface (MS03-026)Jan. 12, 200439 KB
CA-2003-20W32/Blaster worm (MS03-026)Jan. 12, 200439 KB
CA-2003-22Multiple Vulnerabilities in Microsoft Internet Explorer (MS03-032)March 2, 200490 KB
CA-2003-23RPCSS Vulnerabilities in Microsoft Windows (MS03-039)June 17, 200469 KB
CA-2003-25Buffer Overflow in SendmailJan. 22, 200434 KB
CA-2003-28Buffer Overflow in Windows Workstation Service (MS03-049)March 2, 200483 KB
CA-2002-03Multiple Vulnerabilities in Many Implementations of SNMPJan. 15, 200331 KB
CA-2002-12Format String Vulnerability in ISC DHCPDJul. 17, 200273 KB
CA-2002-17Apache Web Server Chunk Handling VulnerabilityMay 13, 200394 KB
CA-2002-18OpenSSH Vulnerabilities in Challenge Response HandlingDec. 8, 200329 KB
CA-2002-23Multiple Vulnerabilities in OpenSSLDec. 8, 200327 KB
CA-2002-27Apache/mod_ssl WormDec. 8, 200328 KB
CA-2002-28Trojan Horse Sendmail DistributionDec. 8, 200329 KB
CA-2002-29Buffer Overflow in Kerberos Administration DaemonDec. 8, 200327 KB
CA-2002-30Trojan Horse tcpdump and libpcap DistributionsDec. 8, 200326 KB
CA-2002-36Multiple Vulnerabilities in SSH ImplementationsDec. 8, 200327 KB
VU#104555Buffer Overflow in mod_sslJan. 22, 200434 KB
VU#106324Microsoft Windows contains a vulnerability in the way the Windows Shell launches applications (MS04-024)May 13, 200581 KB
VU#111673SGI IRIX "xfsdump" creates quota information files insecurelyJan. 22, 200434 KB
VU#119262Microsoft Windows kernel fails to reset values in CPU data structures (MS04-032)May 13, 2005102 KB
VU#130614Microsoft Outlook Express vulnerable to remote code execution (MS05-030)June 16, 200554 KB
VU#140470Apple Mac OS X Server Admin fails to properly restrict users from using the proxy service (Apple Security Update 2005-005)May 16, 200566 KB
VU#142121zlib "gzprintf()" function vulnerable to buffer overflowOct. 20, 200457 KB
VU#145486Apple Cocoa applications vulnerable to denial of service via malformed TIFF image (Apple Security Update 2005-005)May 16, 200566 KB
VU#149953ISC "dhcrelay" fails to limit hop count when malicious bootp packet is receivedJan. 22, 200427 KB
VU#177584Microsoft Windows kernel vulnerable to a denial-of-service condition via animated cursor (.ani) frame number (MS05-002) June 13, 2005104 KB
VU#187196Microsoft Windows fails to properly process showHelp URLs (MS04-023)May 13, 200579 KB
VU#189754Microsoft Internet Explorer buffer overflow in PNG image rendering component (MS05-025)June 16, 200570 KB
VU#192995Integer overflow in xdr_array() function when deserializing the XDR stream (MS02-027)Dec. 4, 200328 KB
VU#200132Various *NIX PDF readers/viewers execute commands embedded within hyperlinksJan. 22, 200434 KB
VU#206537Apache vulnerable to DoSJan. 22, 200427 KB
VU#210606Apple Mac OS X "disk://" URI handler stores arbitrary files in a known location (Apple Security Update 2004-06-07) June 13, 200570 KB
VU#218526Microsoft Windows contains vulnerability in Window Management API (MS04-032)May 13, 2005101 KB
VU#220821Microsoft Print Spooler service contains a buffer overflow (MS05-043)Aug. 10, 200571 KB
VU#222050Microsoft Internet Explorer Content Advisor contains a buffer overflow (MS05-020)June 16, 200591 KB
VU#222750TCP/IP implementations do not adequately validate ICMP error messages (MS05-019; Sun Alert 57746)June 13, 200555 KB
VU#228028Microsoft Windows Task Scheduler Buffer Overflow (MS04-022)May 13, 200578 KB
VU#229595Overly large OPT record assertionDec. 4, 200326 KB
VU#233754Microsoft Windows does not adequately validate IP options (MS05-019)June 7, 200565 KB
VU#258390Apple Mac OS X with Bluetooth enabled may allow file exchange without prompting users (Apple Security Update 2005-005)May 16, 200566 KB
VU#258721Various FTP clients fail to account for pipe (|) characters in default file namesJan. 22, 200434 KB
VU#258905Multiple implementations of LDAP Directory Server vulnerable to buffer overflowJune 7, 200557 KB
VU#259197Microsoft Client Server Runtime System Vulnerability (MS05-018)June 16, 200591 KB
VU#275193Microsoft Exchange Server contains unchecked buffer in SMTP extended verb handling (MS05-021)June 16, 200579 KB
VU#283646Microsoft ASP.NET fails to perform proper canonicalization (MS05-004)June 10, 200583 KB
VU#284857ISC DHCPD minires library contains multiple buffer overflows Dec. 4, 200333 KB
VU#312313Solaris X Window Font Service (XFS) daemon contains buffer overflow in Dispatch() funtionDec. 4, 200333 KB
VU#331694Apple Mac OS X chpass/chfn/chsh utilities do not properly validate external programs (Apple Security Update 2005-005)June 7, 200565 KB
VU#354486Apple Mac OS X Server NetInfo Setup Tool fails to validate command line parameters (Apple Security Update 2005-005)June 7, 200565 KB
VU#356070Apple Terminal fails to properly sanitize input for "x-man-page" URI (Apple Security Update 2005-005)May 16, 200567 KB
VU#356600Microsoft Internet Explorer DHTML Editing ActiveX control contains a cross-domain vulnerability (MS05-013)June 13, 200591 KB
VU#377804Multiple Open Software Foundation Distributed Computing Environment (DCE) implementations vulnerable to DoSJan. 22, 200432 KB
VU#383779ZIP archives containing files with large filenames can cause buffer overflows (MS02-054)Dec. 4, 200334 KB
VU#390742Sun Solaris Volume Manager (SVM) fails to properly handle malformed probe requestsApril 5, 200565 KB
VU#394792Microsoft Windows SMTP component vulnerable to remote code execution (MS04-035)April 5, 200586 KB
VU#405955util-linux package vulnerable to privilege escalation when "ptmptmp" file is not removed properly when using "chfn" utilityDec. 4, 200328 KB
VU#406121Apache mod-dav module vulnerable to DoSDec. 4, 200328 KB
VU#412115Network device drivers reuse old frame buffer data to pad packetsDec. 4, 200327 KB
VU#412566Solaris conv_fix insecure file handling vulnerabilityApril 5, 200559 KB
VU#422156Microsoft Exchange Server fails to properly handle specially crafted SMTP extended verb requests (MS03-046)July 1, 200459 KB
VU#428230Multiple vulnerabilities in S/MIME implementationsJan. 22, 200431 KB
VU#435444Microsoft Outlook Web Access (OWA) contains cross-site scripting vulnerability in the "Compose New Message" form (MS03-047)July 1, 200459 KB
VU#442569MIT Kerberos vulnerable to ticket splicing when using Kerberos4 triple DES service ticketsJan. 22, 200434 KB
VU#457875Various DNS service implementations generate multiple simultaneous queries for the same resource recordDec. 4, 200327 KB
VU#464113TCP/IP implementations handle unusual flag combinations inconsistentlyDec. 4, 200325 KB
VU#467036Microsoft Help and Support Center contains buffer overflow in code used to handle HCP protocol (MS03-044)July 1, 200469 KB
VU#489397Microsoft Server Message Block vulnerable to buffer overflow (MS05-027)June 16, 200570 KB
VU#490628Microsoft Windows Remote Desktop Protocol service input validation vulnerability (MS05-041)Aug. 10, 200571 KB
VU#516825Integer overflow in Sun RPC XDR library routinesDec. 4, 200329 KB
VU#524227GNU screen contains buffer overflowJan. 22, 200426 KB
VU#528719Multiple implementations of the Session Initiation Protocol (SIP) contain vulnerabilitiesApr. 7, 200435 KB
VU#546483Multiple networking devices fail to set the "Secure" attribute of a cookieApril 5, 200557 KB
VU#575892Buffer overflow in Microsoft Messenger Service (MS03-043)July 1, 200479 KB
VU#578798Apple Mac OS X help system may interpret inappropriate local script files (Apple Security Update 2004-06-07)July 1, 200459 KB
VU#580299Microsoft Internet Explorer contains URL decoding zone spoofing vulnerability (MS05-014)June 13, 200590 KB
VU#582934Apple Mac OS X Foundation Framework vulnerable to buffer overflow via incorrect handling of an environmental variable (Apple Security Update 2005-005)June 7, 200565 KB
VU#597889Microsoft COM Structured Storage Vulnerability (MS05-012)June 13, 200590 KB
VU#610133Microsoft Windows domain controller denial of service in Kerberos message handling (MS05-042)Aug. 11, 200571 KB
VU#623217Cryptographic weakness in Kerberos Version 4 protocolJan. 22, 200434 KB
VU#640488Microsoft Windows contains an unchecked buffer in the NetDDE services (MS04-031)May 13, 2005102 KB
VU#647436Microsoft Windows contains a buffer overflow in the POSIX subsystem (MS04-020)May 13, 200577 KB
VU#648406Apple Mac OS X AppleFileServer fails to properly handle certain authentication requests (Apple Security Update 2004-05-03)July 1, 200459 KB
VU#649374Microsoft Windows processing of zip files contains a buffer overflow (MS04-034)May 13, 200598 KB
VU#650181Microsoft Object Management DoS Vulnerability (MS05-018)June 16, 200591 KB
VU#652537Microsoft Windows SMB packet validation vulnerability (MS05-011)June 13, 200589 KB
VU#673051Microsoft Windows Shell and HTML Application Host may allow remote code execution (MS05-016)June 16, 200591 KB
VU#694782Sun Solaris passwd command allows for privilege escalationApril 5, 200559 KB
VU#698835Microsoft DHTML Drag-and-Drop events insufficiently validated (MS05-008 & MS05-014)June 13, 200593 KB
VU#706838Apple Mac OS X vulnerable to buffer overflow via vpnd daemon (Apple Security Update 2005-005)June 7, 200565 KB
VU#717748Microsoft Internet Information Server (IIS) 4.0 contains a buffer overflow in the redirect function (MS04-021)May 13, 200471 KB
VU#718542Microsoft Agent vulnerable to trusted site spoofing (MS05-032)June 16, 200570 KB
VU#738331Domain Name System (DNS) resolver libraries vulnerable to read buffer overflowDec. 4, 200327 KB
VU#756122Microsoft Internet Explorer URL validation routine contains a buffer overflow (MS05-020)June 16, 200591 KB
VU#763513Microsoft Message Queuing vulnerable to buffer overflow (MS05-017)Aug. 9, 200563 KB
VU#774338Microsoft Internet Explorer DHTML objects contain a race condition (MS05-020)June 16, 200591 KB
VU#775933Microsoft Windows Kernel Vulnerability (MS05-018)June 16, 200591 KB
VU#800829Telnet Client Information Disclosure Vulnerability (MS05-033; RHSA-2005:504-06; Sun Alert 101665, 101671)June 16, 200552 KB
VU#803539Multiple vendors' Domain Name System (DNS) stub resolvers vulnerable to buffer overflowDec. 4, 200334 KB
VU#806278Microsoft Windows contains buffer overflow in processing of WMF and EMF image files (MS04-032)May 13, 2005102 KB
VU#820427Microsoft Hyperlink Object Library buffer overflow (MS05-015)June 13, 200590 KB
VU#823971Microsoft Internet Explorer contains a Channel Definition Format (CDF) cross-domain vulnerability (MS05-014)June 13, 200591 KB
VU#838572Microsoft Authenticode mechanism installs ActiveX controls without prompting user (MS03-041)July 1, 200478 KB
VU#844360Domain Name System (DNS) stub resolver libraries vulnerable to buffer overflows via network name or address lookupsDec. 4, 200326 KB
VU#843771Microsoft Internet Explorer contains a DHTML method heap memory corruption vulnerability (MS05-014)June 13, 200591 KB
VU#849993Some implementations of mod_dav contain a format string vulnerability in "ap_log_rerror()" functionDec. 4, 200328 KB
VU#850785Sun KCMS library service daemon does not adequately validate location of KCMS profilesJan. 22, 200432 KB
VU#851869Microsoft HTML Help input validation error (MS05-026)June 16, 200570 KB
VU#852283Cached malformed SIG record buffer overflowDec. 4, 200326 KB
VU#868580Microsoft Windows Utility Manager launches applications with system privileges (MS04-019)May 13, 200471 KB
VU#869640Microsoft Outlook Express fails to properly validate malformed e-mail headers (MS04-018)April 5, 200560 KB
VU#879386Multiple Buffer Overflow Vulnerabilities in QNXOct. 31, 2002 19.2 KB
VU#881254Sun Java System Portal Server fails to properly handle changes to display optionsApril 5, 200560 KB
VU#886601Internet Key Exchange (IKE) protocol discloses identity when Aggressive Mode shared secret authentication is usedDec. 8, 200326 KB
VU#895508Postfix vulnerable to DoS by supplying a remote SMTP listener with a malformed envelope addressJan. 22, 200431 KB
VU#910998Microsoft Windows kernel fails to properly handle invalid opcodes used in DOS emulation (MS04-032)May 13, 2005102 KB
VU#911505Pam_xauth may insecurely forward "X MIT-Magic-Cookies" to new sessions Jan. 22, 200434 KB
VU#920060Microsoft Windows HTML Help component fails to properly validate input data (MS04-023)May 13, 200579 KB
VU#927278Multiple vulnerabilities in X.400 implementationsJan. 22, 200431 KB
VU#927889Microsoft OLE buffer overflow (MS05-012)June 13, 200591 KB
VU#929115PHP fails to properly parse the headers of HTTP POST requestsDec. 8, 200328 KB
VU#939074Microsoft Windows XP named pipe fails to restrict anonymous access (MS05-007)June 13, 200581 KB
VU#943749Microsoft font processing buffer overflow vulnerability (MS05-018)June 16, 200591 KB
VU#944241rpc.walld fails to properly validate messages before broadcasting to clientsJan. 22, 200434 KB
VU#959049Several COM objects cause memory corruption in Microsoft Internet Explorer (MS05-038)Aug. 10, 200571 KB
VU#965206Microsoft Internet Explorer JPEG rendering library vulnerable to buffer overflow (MS05-038)Aug. 10, 200571 KB
VU#967668Microsoft Windows ListBox and ComboBox controls vulnerable to buffer overflow when supplied crafted Windows message (MS03-045)July 1, 200471 KB
VU#973654Linux kernel fails to properly handle floating point signals generated by "fsave" and "frstor" July 1, 200460 KB
VU#978316Vulnerability in OpenSSH daemon (sshd)Jan. 22, 200433 KB
VU#989932Microsoft contains a buffer overflow in the Local Troubleshooter ActiveX control (Tshoot.ocx) (MS03-042)July 1, 200474 KB
VU#998653Microsoft Plug and Play contains a buffer overflow vulnerability (MS05-039)Aug. 10, 200571 KB


Related Links:
US-CERT - United States Computer Emergency Readiness Team