CDHaha Download


[3,587]

MS11-061 Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250)

2011-08-11 |

Remote Desktop Client此安全更新可解决远程桌面 Web 访问中一个秘密报告的漏洞。 该漏洞是一个跨站点脚本执行 (XSS) 漏洞,可能允许特权提升,使攻击者能够在目标用户的上下文中在站点上执行任意命令。 当浏览到 Internet 区域中的远程桌面 Web 访问服务器时,Internet Explorer 8 和 Internet Explorer 9 中的 XSS 筛选器可针对其用户阻止此攻击。 默认情况下,Internet Explorer 8 和 Internet Explorer 9 中的 XSS 筛选器在 Intranet 区域中未启用。

对于 Windows Server 2008 R2 所有受支持的版本,此安全更新的等级为“重要”。此安全更新通过更正远程桌面 Web 访问的登录页面验证输入参数的方式来解决漏洞。
More

[3,104]

MS11-060 Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978)

2011-08-10 |

VisioThis security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Important for all supported editions of Microsoft Visio 2003, Microsoft Visio 2007, and Microsoft Visio 2010. The security update addresses the vulnerabilities by correcting the way that Microsoft Visio validates objects in memory when parsing specially crafted Visio files.
More

[3,361]

MS11-059 Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656)

2011-08-10 |

MDAC此安全更新解决了 Microsoft Windows 中一个秘密报告的漏洞。 如果用户打开与特制库文件位于同一网络目录下的合法 Excel 文件(如 .xlsx 文件),此漏洞可能允许远程执行代码。 成功利用此漏洞的攻击者可以获得与登录用户相同的用户权限。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。

对于 Windows 7 和 Windows Server 2008 R2 的所有受支持版本,此安全更新等级为“重要”。此安全更新通过更正 Windows Data Access Tracing 组件加载外部库的方式来解决漏洞。
More

[4,536]

MS11-058 Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485)

2011-08-10 |

DNS Server此安全更新可解决 Windows DNS 服务器中两个秘密报告的漏洞。 如果攻击者注册域、创建 NAPTR DNS 资源记录,然后将特制 NAPTR 查询发送到目标 DNS 服务器,则这些漏洞中较为严重的漏洞可能允许远程执行代码。 没有启用 DNS 角色的服务器不受威胁。

对于 Windows Server 2008 的 32 位和基于 x64 的版本以及 Windows Server 2008 R2 的基于 x64 的版本,此安全更新的等级为“严重”;对于 Windows Server 2003 的所有受支持版本,此安全更新的等级为“重要”。该安全更新通过修改 DNS 服务器处理内存中的 NAPTR 查询的方式以及在使用之前初始化内存中的对象的方式来解决漏洞。
More

[4,163]

MS11-057 Cumulative Security Update for Internet Explorer (2559049)

2011-08-10 |

Internet Explorer此安全更新可解决 Internet Explorer 中五个秘密报告的漏洞和两个公开披露的漏洞。 最严重的漏洞可能在用户使用 Internet Explorer 查看特制网页时允许远程执行代码。 成功利用这些漏洞的攻击者可以获得与本地用户相同的用户权限。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。

对于 Windows 客户端上的 Internet Explorer 6、Internet Explorer 7、Internet Explorer 8 和 Internet Explorer 9,此安全更新的等级为“严重”;对于 Windows 服务器上的 Internet Explorer 6,此安全更新的等级为“重要”。 此更新通过修改 Internet Explorer 处理内存对象、处理 JavaScript 事件处理程序、某些过程期间呈现数据、访问存储在本地计算机中的文件以及管理 Cookie 文件的方式和修改 telnet 处理程序执行相关应用的方式解决漏洞。
More

[7,673]

Business Contact Manager for Outlook 2010 Service Pack 1

2011-07-29 |

OutlookBusiness Contact Manager for Outlook 2010 Service Pack 1 contains stability improvements and fixes functionality issues reported by customers.

Microsoft Business Contact Manager for Outlook 2010 Service Pack 1 (SP1) provides the latest updates for Business Contact Manager for Outlook 2010. This service pack includes two main categories of fixes:
Previously unreleased fixes that were made specifically for this service pack. In addition to general product fixes, these fixes include improvements in stability, performance, and in security.
All the public updates that were released through June 2011, and all the cumulative updates that were released through April 2011.
More

[5,659]

Windows Live Mesh for Mac 2011(15.4.5726)

2011-07-21 |

Windows Live Mesh for MacKeep your files in sync between your computers, whether Mac or PC.

Windows Live Mesh for Mac brings Live Mesh and the previous version of Windows Live Sync together into one product. With Windows Live Mesh for Mac, you can keep the folders you choose in sync across your computers (Mac and PC) so the files you need are always right there with you.

* Supported Operating Systems:Apple Mac OS X;Apple Mac OS X v. 10.5 Leopard
* Supported Operating System Versions: Mac OS X v10.5 Leopard, Mac OS X v10.6 Snow Leopard
* Supported Processor Architectures: Intel-based Mac computers only
More

[6,069]

iWeb 3.0.4 Updater

2011-07-18 |

iWebDesigning a website may seem difficult, but with iWeb, it’s easily within your reach. Create your site using themes. Customize it with photos, movies, text, and widgets. Then publish to MobileMe or any other hosting service. iWeb even notifies Facebook when your site changes and adds a link to your profile so your friends stay up to date.

Design the website you’ve always wanted.
A Mac and iWeb.* That’s all you need to design and publish your own personal website. Start by picking an Apple-designed theme. Each theme comes with coordinated fonts, backgrounds, and colors to give your site a consistent look throughout.

Next choose a page template. iWeb features ready-made templates for welcome, about me, photo album, movie, blog, and podcast pages. Create as many pages as you like.

Then it’s time to customize your layout with easy-to-use iWeb tools. Drag in photos or movies or type text into placeholders. Resize and rotate photos. Create overlays. There’s no coding required. No complicated design programs to buy. No obstacles between you and a great-looking website.
More

[3,135]

Microsoft July 2011 Security Release ISO Image

2011-07-14 |

ISO Image此 DVD5 ISO 映像文件包含 2011 年 7 月 12 日在 Windows Update 上发布的 Windows 安全更新程序。 该映像不包含其他 Microsoft 产品的安全更新程序。此 DVD5 ISO 映像旨在供需要下载每个安全更新程序的多种语言版本,并且不使用诸如 Windows Server Update Services (WSUS) 这样的自动解决方案的管理员使用。可以使用此 ISO 映像同时下载所有语言的多个更新程序。

重要说明:在部署这些更新程序之前,请务必查看位于 http://www.microsoft.com/technet/security 上的各个安全公告,以确保这些文件未在更近的日期更新过。
More

[3,833]

MS11-056 Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938)

2011-07-13 |

Client/Server 此安全更新解决了 Microsoft Windows 客户端/服务器运行时子系统 (CSRSS) 中 5 个秘密报告的漏洞。 如果攻击者登录用户的系统,并运行特制应用程序,则此漏洞可能允许提升特权。 攻击者必须拥有有效的登录凭据并能本地登录才能利用漏洞。

对于 Microsoft Windows 所有受支持的版本,此安全更新的等级为“重要”。 该安全更新通过不允许多个控制台对象与一个进程相关联、修改 CSRSS 初始化内存的方式、在用户输入用作数组的索引之前验证用户输入以及修改边界检查以防止内存损坏来解决漏洞。
More