Mail Index
- Zone Labs response to "Bypassing Personal Firewall (Zone Alarm Pro) Using DDE-IPC"
- From: Zone Labs Security Team
- [SECURITY] [DSA 832-1] New gopher packages fix several buffer overflows
- Re: PocketPC exploitation
- apachetop insecure temporary file creation
- [SECURITY] [DSA 830-1] New ntlmaps packages fix information leak
- Re: Serendipity: Account Hijacking / CSRF Vulnerability
- Multiple vulnerabilities in Merak Mail Server 8.2.4r with Icewarp Web Mail 5.5.1
- [ GLSA 200509-21 ] Hylafax: Insecure temporary file creation in xferfaxstats script
- Re: PocketPC exploitation
- [SECURITY] [DSA 826-1] New helix-player packages fix multiple vulnerabilities
- Re: PHP-Fusion v6.00.109 SQL Injection / admin|users credentials disclosure
- From: security curmudgeon
- Re: Bypassing Personal Firewall (Zone Alarm Pro) Using DDE-IPC
- RE: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein
- From: Sergey V. Gordeychik
- Citrix Metaframe Presentation Server bypassing policies
- [SECURITY] [DSA 831-1] New mysql-dfsg packages fix arbitrary code execution
- [USN-192-1] Squid vulnerability
- Announce: Bluetooth mailing list - Bluetraq
- iDEFENSE Security Advisory 09.30.05: RealNetworks RealPlayer/HelixPlayer RealPix Format String Vulnerability
- Buffer-overflow and directory traversal bugs in Virtools Web Player 3.0.0.100
- TSLSA-2005-0053 - unzip
- From: Trustix Security Advisor
- Re: IIS 5.1 allows for remote viewing of source code on FAT/FAT32 volumes using WebDAV
- UPDATE: [ GLSA 200509-11 ] Mozilla Suite, Mozilla Firefox: Multiple vulnerabilities
- [SECURITY] [DSA 829-1] New mysql packages fix arbitrary code execution
- BID #14752 update
- From: Josh Zlatin-Amishav
- [SECURITY] [DSA 809-2] New squid packages fix denial of service
- [ GLSA 200509-20 ] AbiWord: RTF import stack-based buffer overflow
- [SECURITY] [DSA 828-1] New squid packages fix denial of service
- [SECURITY] [DSA 827-1] New backupninja packages fix insecure temporary file
- [SECURITY] [DSA 836-1] New cfengine2 packages fix arbitrary file overwriting
- MyBloggie 2.1.3beta null char + SQL Injection -> Login Bypass
- [SECURITY] [DSA 835-1] New cfengine packages fix arbitrary file overwriting
- [Information Disclosure] NetForce v4.02 Sends NIS Password Maps with passwords hashes over sendmail
- [SECURITY] [DSA 833-1] New mysql-dfsg-4.1 packages fix arbitrary code execution
- [SECURITY] [DSA 834-1] New prozilla packages fix arbitrary code execution
- Security Advisory for Bugzilla 2.18.3, 2.20rc2, and 2.21
- RE: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- [SECURITY] [DSA 837-1] New Mozilla Firefox packages fix denial of service
- [SECURITY] [DSA 838-1] New mozilla-firefox packages fox multiple vulnerabilities
- Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- Re: Online Dating Software by AEwebworks - aeDating Script <= 4.0 Version Vulnerability
- Trillian remote crashable
- Kaspersky Antivirus Remote Heap Overflow
- RE: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- MDKSA-2005:171 - Updated kernel packages fix multiple vulnerabilities
- From: Mandriva Security Team
- [SECURITY] [DSA 840-1] New drupal packages fix remote command execution
- [SECURITY] [DSA 842-1] New egroupware packages fix arbitrary code execution
- Call for Papers - DIMVA 2006
- [SECURITY] [DSA 839-1] New apachetop packages fix insecure temporary file
- RE: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- RE: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- Advisory: WZCS vulnerabilities
- Re: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides
- [ GLSA 200510-01 ] gtkdiskfree: Insecure temporary file creation
- [USN-155-3] Fixed mozilla locale packages
- [USN-193-1] dia vulnerability
- [ GLSA 200510-02 ] Berkeley MPEG Tools: Multiple insecure temporary files
- [security bulletin] SSRT051041 rev.0 - HP-UX Mozilla Remote Unauthorized Execution of Privileged Code or Denial of Service (DoS)
- [SECURITY] [DSA 833-2] New mysql-dfsg-4.1 package fixes arbitrary code execution
- [ GLSA 200510-03 ] Uim: Privilege escalation vulnerability
- From: Sune Kloppenborg Jeppesen
- A common researcher diagnosis error: misreading error messages
- [security bulletin] SSRT051040 rev.0 - HP-UX Mozilla Remote Unauthorized Execution of Privileged Code
- [security bulletin] SSRT5940 rev.2 - HP-UX Mozilla remote, unauthorized user may execute privileged code
- [security bulletin] SSRT051030 rev.1 - HP OpenView Event Correlation Services (OV ECS) Remote Unauthorized Privileged Access
- [security bulletin] SSRT051023 rev.5 - HP OpenView Network Node Manager (OV NNM) Remote Unauthorized Privileged Access
- [ GLSA 200510-04 ] Texinfo: Insecure temporary file creation
- iDEFENSE Security Advisory 10.04.05: UW-IMAP Netmailbox Name Parsing Buffer Overflow Vulnerability
- iDEFENSE Security Advisory 10.04.05: Symantec AntiVirus Scan Engine Web Service Buffer Overflow Vulnerability
- RE: iDEFENSE Security Advisory 10.04.05: Symantec AntiVirus Scan Engine Web Service Buffer Overflow Vulnerability
- [SECURITY] [DSA 843-1] New arc packages fix insecure temporary files
- RE: Advisory: WZCS vulnerabilities
- Patches available for critical flaws in HP Openview
- From: NGSSoftware Insight Security Research
- [SECURITY] [DSA 844-1] New mod-auth-shadow packages fix authentication bypass
- Some new whitepapers ...
- Secunia Research: ALZip Multiple Archive Handling Buffer Overflow
- PAKCON II: Call for Paper (CfP), Final Call!
- Announcement : Core Banking Application Security List
- RE: Some new whitepapers ...
- [security bulletin] SSRT4743, SSRT4884 rev.1 - HP Tru64 UNIX TCP/IP remote Denial of Service (DoS)
- Secunia Research: PHP-Fusion Two SQL Injection Vulnerabilities
- Secunia Research: Webroot Desktop Firewall Two Vulnerabilities
- Planet Technology Corp FGSW2402RS switch default password / "backdoor"
- WASC Threat Classification in 4 languages
- [security bulletin] SSRT051004 rev.1 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege
- aspReady FAQ - open for SQL-injections
- [ GLSA 200510-06 ] Dia: Arbitrary code execution through SVG import
- From: Sune Kloppenborg Jeppesen
- High Risk Vulnerability in Sun Directory Server
- From: NGSSoftware Insight Security Research
- Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- [SECURITY] [DSA 845-1] New mason packages fix missing init script
- Re: Some new whitepapers ...
- [ GLSA 200510-05 ] Ruby: Security bypass vulnerability
- From: Sune Kloppenborg Jeppesen
- [USN-194-1] texinfo vulnerability
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- xloadimage buffer overflow.
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- [SECURITY] [DSA 846-1] New cpio packages fix several vulnerabilities
- [security bulletin] SSRT051043 rev.0 - Apache Remote Unauthorized access
- [security bulletin] SSRT051003 rev.1 - HP-UX Java Web Start remote unauthorized privileged access
- Cross-Site-Scripting Vulnerabilities in Oracle HTMLDB
- Plaintext Password Vulnerabilitiy during Installation of Oracle HTMLDB
- Cross-Site-Scripting Vulnerability in Oracle iSQL*Plus
- Cross-Site-Scripting Vulnerability in Oracle XMLDB
- Shutdown TNS Listener via Oracle iSQL*Plus
- Shutdown TNS Listener via Oracle Forms Servlet
- MDKSA-2005:172 - Updated openssh packages fix GSSAPI credentials vulnerability
- From: Mandriva Security Team
- MDKSA-2005:173 - Updated mozilla-firefox packages fix vulnerabilities
- From: Mandriva Security Team
- MDKSA-2005:174 - Updated mozilla-thunderbird packages fix multiple vulnerabilities
- From: Mandriva Security Team
- MDKSA-2005:175 - Updated texinfo packages fix temporary file vulnerability
- From: Mandriva Security Team
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Aenovo Multiple Vulnerabilities
- [ GLSA 200510-07 ] RealPlayer, Helix Player: Format string vulnerability
- Re: [Dailydave] Security contact for ...
- From: security curmudgeon
- MailEnable W3C Logging Remote Buffer Overflow Proof of Concept
- Utopia News Pro 1.1.3 SQL Injection / cross site scripting
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Security contact for ...
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- [ GLSA 200510-09 ] Weex: Format string vulnerability
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200510-08 ] xine-lib: Format string vulnerability
- From: Sune Kloppenborg Jeppesen
- [SECURITY] [DSA 849-1] New shorewall packages fix firewall bypass
- [SECURITY] [DSA 848-1] New masqmail packages fix several vulnerabilities
- [SECURITY] [DSA 847-1] New dia packages fix arbitrary code execution
- Cyphor 0.19 SQL Injection / Board takeover / cross site scripting
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers
- MDKSA-2005:177 - Updated hylafax packages fix temporary file vulnerability
- From: Mandriva Security Team
- MDKSA-2005:176 - Updated webmin package fixes authentication bypass vulnerability
- From: Mandriva Security Team
- gnome-pty-helper writes arbitrary utmp records
- Antivirus detection bypass by special crafted archive.
- [USN-196-1] Xine library vulnerability
- [USN-198-1] cfengine vulnerabilities
- [USN-197-1] Shorewall vulnerability
- [USN-199-1] Linux kernel vulnerabilities
- [USN-195-1] Ruby vulnerability
- CodeCon 2006 Call For Papers
- [EEYEB20050803] - Windows UMPNPMGR wsprintfW Stack Buffer Overflow Vulnerability
- [EEYEB20050915] - MDT2DD.DLL COM Object Uninitialized Heap Memory Vulnerability
- [EEYEB20050708] Microsoft Distributed Transaction Coordinator Memory Modification Vulnerability
- [EEYEB20050510] - Microsoft DirectShow Remote Code Vulnerability
- iDEFENSE Security Advisory 10.11.05: Microsoft Distributed Transaction Controller TIP DoS Vulnerability
- iDEFENSE Security Advisory 10.11.05: Microsoft Distributed Transaction Controller Packet Relay DoS Vulnerability
- The Malloc Maleficarum
- From: Phantasmal Phantasmagoria
- Secunia Research: WinRAR Format String and Buffer Overflow Vulnerabilities
- [KDE Security Advisory] KOffice/KWord RTF import buffer overflow
- XSS vulnerability in Zeroblog
- FreeBSD Security Advisory FreeBSD-SA-05:21.openssl
- From: FreeBSD Security Advisories
- [SECURITY] [DSA 862-1] New Ruby 1.6 packages fix safety bypass
- [SECURITY] [DSA 861-1] New uw-imap packages fix arbitrary code execution
- [SECURITY] [DSA 860-1] New Ruby packages fix safety bypass
- versatileBulletinBoard V1.0.0 RC2 (possibly prior versions) multiple SQL injection vulnerabilities / login bypass / board takeover
- iDEFENSE Security Advisory 10.10.05: Kaspersky Anti-Virus Engine CHM File Parser Buffer Overflow Vulnerability
- iDEFENSE Security Advisory 10.10.05: SGI IRIX runpriv Design Error Vulnerability
- [SECURITY] [DSA 859-1] New xli packages fix arbitrary code execution
- [SECURITY] [DSA 858-1] New xloadimage packages fix arbitrary code execution
- [SECURITYREASON.COM] phpMyAdmin Local file inclusion 2.6.4-pl1
- PullThePlug Contest: Call For Papers
- Re: Opinion: Complete failure of Oracle security response and utter neglect of t
- [SECURITY] [DSA 857-1] New graphviz packages fix insecure temporary file
- [SECURITY] [DSA 856-1] New py2play packages fix arbitrary code execution
- [SECURITY] [DSA 855-1] New weex packages fix arbitrary code execution
- Announcement: The Web Application Firewall Evaluation Criteria v1
- [SECURITY] [DSA 854-1] New tcpdump packages fix denial of service
- [SECURITY] [DSA 853-1] New ethereal packages fix several vulnerabilities
- [SECURITY] [DSA 852-1] New up-imapproxy packages fix arbitrary code execution
- [SECURITY] [DSA 851-1] New openvpn packages fix denial of service
- [SECURITY] [DSA 850-1] New tcpdump packages fix denial of service
- [USN-200-1] Thunderbird vulnerabilities
- [ GLSA 200510-10 ] uw-imap: Remote buffer overflow
- using php local file include vulnerabilities for command execution
- MDKSA-2005:180 - Updated xine-lib packages fixes cddb vulnerability
- From: Mandriva Security Team
- MDKSA-2005:179 - Updated openssl packages fix vulnerabilities
- From: Mandriva Security Team
- Re: using php local file include vulnerabilities for command execution
- MDKSA-2005:178 - Updated squirrelmail packages fixes XSS vulberability
- From: Mandriva Security Team
- [USN-202-1] KOffice vulnerability
- [SECURITY] [DSA 863-1] New xine-lib packages fix arbitrary code execution
- [ GLSA 200510-11 ] OpenSSL: SSL 2.0 protocol rollback
- [SEC-1 Advisory] GFI MailSecurity 8.1 Web Module Buffer Overflow
- [USN-201-1] SqWebmail vulnerabilities
- MDKSA-2005:181 - Updated squid packages fix vulnerabilities
- From: Mandriva Security Team
- Linux Orinoco drivers information leakage
- Re: [SECURITYREASON.COM] phpMyAdmin Local file inclusion 2.6.4-pl1
- Research for network security news article
- [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability
- VERITAS NetBackup: Java User-Interface, format string vulnerability
- Re: VoIP-Phones: Weakness in proccessing SIP-Notify-Messages
- ZDI-05-001: VERITAS NetBackup Remote Code Execution
- Secunia Research: Novell NetMail NMAP Agent "USER" Buffer Overflow Vulnerability
- [SECURITY] [DSA 865-1] New hylafax packages fix insecure temporary files
- [SECURITY] [DSA 864-1] New Ruby 1.8 packages fix safety bypass
- Kerio Personal Firewall and Kerio Server Firewall FWDRV driver Local Denial of Service
- Yapig: XSS / Code Injection Vulnerability
- [USN-203-1] Abiword vulnerabilities
- Secunia Research: AhnLab V3 Antivirus ALZ/UUE/XXE Archive Handling Buffer Overflow
- [security bulletin] SSRT051041 rev.1 - HP-UX Mozilla Remote Unauthorized Execution of Privileged Code or Denial of Service (DoS)
- [security bulletin] SSRT5975 HP-UX Running on Itanium Platforms Local Denial of Service (DoS)
- iDEFENSE Security Advisory 10.13.05: Multiple Vendor XMail 'sendmail' Recipient Buffer Overflow Vulnerability
- iDEFENSE Security Advisory 10.13.05: Multiple Vendor wget/curl NTLM Username Buffer Overflow Vulnerability
- [USN-205-1] Curl and wget vulnerabilities
- Re: Antivirus detection bypass by special crafted archive.
- RTasarim WebAdmin modul SQL injection
- Google Talk cleartext proxy credentials vulnerability
- MDKSA-2005:182 - Updated curl packages fix NTLM authentication vulnerability
- From: Mandriva Security Team
- Airscanner Mobile Security Advisory #05101001: iTunes Shared Music Denial of Service/Spoofing/Flooding/Abuse
- MDKSA-2005:183 - Updated wget packages fix NTLM authentication vulnerability
- From: Mandriva Security Team
- Gallery 2.x Remote File Access Vulnerability
- CAID 33485 - Computer Associates iGateway debug mode HTTP GET request buffer overflow vulnerability
- Trusted Digital, Trusted Mobility Suite Authorization Bypass Vulnerability
- [ GLSA 200510-12 ] KOffice, KWord: RTF import buffer overflow
- From: Sune Kloppenborg Jeppesen
- [USN-204-1] SSL library vulnerability
- MDKSA-2005:184 - Updated cfengine packages fix temporary file vulnerabilities
- From: Mandriva Security Team
- [KAPDA::#6] Punbb SQL Injection Vulnerability
- Security Contacr for Mycall
- [ GLSA 200510-13 ] SPE: Insecure file permissions
- MDKSA-2005:185 - Updated koffice packages fix KWord RTF import overflow vulnerability
- From: Mandriva Security Team
- Re: Google Talk cleartext proxy credentials vulnerability
- [ GLSA 200510-14 ] Perl, Qt-UnixODBC, CMake: RUNPATH issues
- [USN-206-1] Lynx vulnerability
- [USN-208-1] SSH server vulnerability
- [USN-207-1] PHP vulnerability
- [USN-208-1] graphviz vulnerability
- Exploiting Windows Device Drivers Whitepaper
- Ciscos VPN-Client-Passwords can be decrypted
- Yahoo RSS XSS Vulnerability (Correction)
- SUSE Security Announcement: OpenWBEM (SUSE-SA:2005:060)
- ie7 will have more mechanisms
- flexbackup default config insecure temporary file creation
- [OpenPKG-SA-2005.022] OpenPKG Security Advisory (openssl)
- Lynx Remote Buffer Overflow
- Yahoo RSS XSS Vulnerability
- PHP local safedir restriction bypass
- [ GLSA 200510-15 ] Lynx: Buffer overflow in NNTP processing
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200510-16 ] phpMyAdmin: Local file inclusion vulnerability
- From: Sune Kloppenborg Jeppesen
- Re: Aenovo Multiple Vulnerabilities (Patch)
- winrar 3.50 Exploit
- [USN-210-1] netpbm vulnerability
- Re: [Full-disclosure] [USN-208-1] SSH server vulnerability
- Secunia Research: MySource Cross-Site Scripting and File Inclusion Vulnerabilities
- Re: [Full-disclosure] Kerio Personal Firewall and Kerio Server Firewall FWDRV driver Local Denial of Service
- SECURECon 2006 Call for papers!
- MDKSA-2005:186 - Updated lynx packages fix remote buffer overflow
- From: Mandriva Security Team
- Re: [Full-disclosure] Ciscos VPN-Client-Passwords can be decrypted
- NetFlow Analyzer 4 XSS Vulnerability
- e107 remote commands execution
- Windows host based firewall tester
- Linksys WRT54G/S Directory Traversal
- Re: [KAPDA::#6] Punbb SQL Injection Vulnerability
- Multiple Critical and High Vulnerabilities in Oracle Database Server
- From: NGSSoftware Insight Security Research
- Re: Require many large corporate emails for contact regarding vulnerability.
- Revision: Multiple Critical and High Vulnerabilities in Oracle Database Server
- Metasploit Framework v2.5
- SUSE Security Announcement: openSSL protocol downgrade attack (SUSE-SA:2005:061)
- Re: [KAPDA::#6] Punbb SQL Injection Vulnerability
- SecurityAlert SA025 : PHPNuke Remote Directory Traversal
- Re: Windows host based firewall tester
- cacam_logsecurity_win32 exploit published on 20051018 by Metasploit
- Cisco Security Advisory:Cisco 11500 Content Services Switch SSL Malformed Client Certificate Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [security bulletin] SSRT051052 rev.0 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access
- [SECURITY] [DSA 868-1] New Mozilla Thunderbird packages fix several vulnerabilities
- RE: CAID 33485 - Computer Associates iGateway debug mode HTTP GET request buffer overflow vulnerability
- XSS & Path Disclosure in Chipmunk's products
- Oracle 10g - emagent.exe Stack-Based Overflow
- [SECURITY] [DSA 866-1] New Mozilla packages fix several vulnerabilities
- Oracle Workflow CSS Vulnerability wf_monitor
- [SECURITY] [DSA 867-1] New module-assistant package fixes insecure temporary file
- Oracle Workflow CSS Vulnerability wf_route
- Vulnerabilities in Oracle E-Business Suite 11i - Critical Patch Update October 2005
- [ GLSA 200510-17 ] AbiWord: New RTF import buffer overflows
- [ GLSA 200510-18 ] Netpbm: Buffer overflow in pnmtopng
- [USN-211-1] Enigmail vulnerability
- iDEFENSE Security Advisory 10.20.05: Multiple Vendor Ethereal srvloc Buffer Overflow Vulnerability
- iDEFENSE Security Advisory 10.20.05: Symantec Norton AntiVirus LiveUpdate Local Privilege Escalation
- iDEFENSE Security Advisory 10.20.05: Symantec Norton AntiVirus DiskMountNotify Local Privilege Escalation
- [Argeniss] Story of a dumb patch (Paper advisoryabout CSRSS and Windows Explorer vulnerabilities)
- UnixWare 7.1.4 UnixWare 7.1.3 : ppp buffer overflow
- From: please_reply_to_security
- OpenServer 5.0.7 : authsh and backupsh buffer overflow
- From: please_reply_to_security
- F.E.A.R. 1.01 likes lithsock
- [SECURITY] [DSA 869-1] New eric packages fix arbitrary code execution
- Nuked klan 1.7: XSS vulnerability
- MDKSA-2005:187 - Updated dia packages fix python SVG import vulnerability.
- From: Mandriva Security Team
- MDKSA-2005:188 - Updated graphviz packages fix temporary file vulnerability.
- From: Mandriva Security Team
- MDKSA-2005:189 - Updated imap packages fix buffer overflow vulnerabilities.
- From: Mandriva Security Team
- MDKSA-2005:190 - Updated nss_ldap/pam_ldap packages fix privilege vulnerabilities.
- From: Mandriva Security Team
- MDKSA-2005:191 - Updated ruby packages fix safe level and taint flag protections vulnerability
- From: Mandriva Security Team
- MDKSA-2005:192 - Updated xli packages fix buffer overflow vulnerabilities.
- From: Mandriva Security Team
- [SNS Advisory No.84] Oracle Application Server HTTP Response Splitting Vulnerability
- Secunia Research: ZipGenius Multiple Archive Handling Buffer Overflow
- SEC-CONSULT-SA-20051021-0: Yahoo/MSIE XSS
- [security bulletin] SSRT051052 rev.1 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access
- Windows UMPNPMGR wsprintfW Stack Buffer Overflow Vulnerability PoC
- phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
- PhpNuke 7.8 with all security fixes/patches "Your_Account", "Downloads", "Web Links" SQL Injection / Remote commans execution
- DBoardGear SQL Injection
- SUSE Security Announcement: permissions (SUSE-SA:2005:062)
- DCP - portal XSS & SQL attacks
- Remote File Inclusion in forum PunBB
- Advisory 16/2005: phpMyAdmin Local File Inclusion Vulnerability
- TSLSA-2005-0059 - multi
- From: Trustix Security Advisor
- Nuked klan 1.7: Bypassed level admin on forum(corrected)
- Insecure Temporary Files in BMC/Control-M Agent
- [security bulletin] SSRT051055 rev.0 - HP Oracle for OpenView (OfO) Critical Patch Update October 2005
- Revised draft on ICMP attacks
- Possible Bug in PHP-Fusion 6.0.204
- aRCHILLES Newsworld < 1.5.0-rc1 Multiple Vulnerabilities
- [KAPDA::#8] Domain Manager Pro Vulnerability
- SQL saphp Lesson
- File Including In FLAT NUKE
- Zomplog Script Injection Vulnerability =>3.4 (all versions vulnerable)
- php < 4.4.1 htaccess apache dos
- From: Eric Romang / ZATAZ.com
- Nuked klan 1.7: Remote Exploit
- Nuked klan 1.7: SQL vulnerability
- Flat Nuke Cross Site Scripting
- iDEFENSE Security Advisory 10.24.05: SCO Openserver backupsh 'Home' Buffer Overflow Vulnerability
- PHP iCalendar CSS
- Skype security advisory
- From: . EADS CCR DCR/STI/C
- DboardGear - uncorrect import themes (SQL-inject)
- [SECURITY] [DSA 871-1] New libgda2 packages fix arbitrary code execution
- Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- [ GLSA 200510-19 ] cURL: NTLM username stack overflow
- [ GLSA 200510-20 ] Zope: File inclusion through RestructuredText
- [SNS Advisory No.85] XOOPS Multiple Cross-site Scripting Vulnerabilities
- [ GLSA 200510-21 ] phpMyAdmin: Local file inclusion and XSS vulnerabilities
- iDEFENSE Security Advisory 10.24.05: SCO Unixware Setuid ppp prompt Buffer Overflow Vulnerability
- [SECURITY] [DSA 870-1] New sudo packages fix arbitrary command execution
- RE: Possible Bug in PHP-Fusion 6.0.204
- Mozilla Thunderbird SMTP down-negotiation weakness
- Network Appliance iSCSI Authentication Bypass
- [SECURITY] [DSA 871-2] New libgda2 packages fix arbitrary code execution
- SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability
- SEC-Consult SA 20051025-1 :: RSA ACE Web Agent XSS
- iDEFENSE Security Advisory 10.24.05: SCO Openserver authsh 'Home' Buffer Overflow Vulnerability
- SparkleBlog Journal.php HTML Injection Vulnerability =>v2.1 (all versions vulnerable)
- [SECURITY] [DSA 548-2] New imlib packages fix arbitrary code execution
- MDKSA-2005:193 - Updated ethereal packages fix multiple vulnerabilities
- From: Mandriva Security Team
- Looking for a security contact at Macrovision/InstallShield
- Re: Mozilla Thunderbird SMTP down-negotiation weakness
- Secunia Research: Mantis "t_core_path" File Inclusion Vulnerability
- Woltlab Burning Board info_db.php multiple SQL injection
- SQL-Injection in MyBulletinBoard allows attacker to become a board admin.
- Looking for security contacts at Sony and Lenovo (FKA IBM)
- phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
- [SECURITY] [DSA 873-1] New net-snmp packages fix denial of service
- [KAPDA::#9] Techno Dreams Scripts Vulnerabilities
- Re: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte
- Re: Mozilla Thunderbird SMTP down-negotiation weakness
- Update for the magic byte bug
- MDKSA-2005:197 - Updated unzip packages fix suid, permissions vulnerabilities.
- From: Mandriva Security Team
- MDKSA-2005:193-1 - Updated ethereal packages fix multiple vulnerabilities
- From: Mandriva Security Team
- MDKSA-2005:198 - Updated uim packages fix suid linking vulnerabilities.
- From: Mandriva Security Team
- MDKSA-2005:195 - Updated squid packages fix vulnerabilities
- From: Mandriva Security Team
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- MDKSA-2005:186-1 - Updated lynx packages fix remote buffer overflow
- From: Mandriva Security Team
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- MDKSA-2005:194 - Updated php-imap packages fix buffer overflow vulnerabilities.
- From: Mandriva Security Team
- MDKSA-2005:196 - Updated perl-Compress-Zlib packages fix vulnerabilities
- From: Mandriva Security Team
- [SECURITY] [DSA 872-1] New koffice packages fix arbitrary code execution
- PHP-Nuke Cross-Site Scripting Vulnerability
- MDKSA-2005:199 - Updated netpbm packages fix pnmtopng vulnerabilities
- From: Mandriva Security Team
- RE: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte
- [SECURITY] [DSA 874-1] New lynx packages fix arbitrary code execution
- fetchmail security announcement 2005-02 (CVE-2005-3088)
- [SECURITY] [DSA 875-1] New OpenSSL packages fix cryptographic weakness
- [SECURITY] [DSA 876-1] New lynx-ssl packages fix arbitrary code execution
- Secunia Research: ATutor Multiple Vulnerabilities
- [CIRT.DK] - Novell ZENworks Patch Management Server 6.0.0.52 - SQL injection
- [SECURITY] [DSA 878-1] New netpbm-free packages fix arbitrary code execution
- [ GLSA 200510-23 ] TikiWiki: XSS vulnerability
- MDKSA-2005:201 - Updated sudo packages fix vulnerability
- From: Mandriva Security Team
- [ GLSA 200510-22 ] SELinux PAM: Local password guessing attack
- [SECURITY] [DSA 877-1] New gnump3d packages fix several vulnerabilities
- MDKSA-2005:200 - Updated apache-mod_auth_shadow packages fix security restriction bypass issues.
- From: Mandriva Security Team
- [ GLSA 200510-24 ] Mantis: Multiple vulnerabilities
- iDefense Security Advisory 10.28.05: Multiple Vendor chmlib CHM File Handling Buffer Overflow Vulnerability
- Re: [ GLSA 200510-23 ] TikiWiki: XSS vulnerability
- Re: [ GLSA 200510-23 ] TikiWiki: XSS vulnerability
- File Including In PBLang
- Multiple vulnerabilities within RockLiffe MailSite Express WebMail
- Remote File Inclusion in vCard :)
- Re: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte
- Re: Mozilla Thunderbird SMTP down-negotiation weakness
- Re: Mozilla Thunderbird SMTP down-negotiation weakness
- Remote MySQL User on Cpanel Default installation with blank password
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- Re: phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through forged magic byte
- Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability
- Re: [Full-disclosure] Re: phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
- Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability
- From: SEC Consult Research
- Re: [Full-disclosure] Re: phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
- Re: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte
- From: Eygene A. Ryabinkin
- Re: Network Appliance iSCSI Authentication Bypass
- Re: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte
- Re: Network Appliance iSCSI Authentication Bypass
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- Re: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through
- Vulnerability in MG2 php based Image Gallery - bypass security, view password protected images
- Re: Remote File Inclusion in forum PunBB
- Mirabilis ICQ 2003a Buffer Overflow Download Shellcoded Exploit
- uplod phpshell in PHP Advanced Transfer Manager
- Trend Micro's Response to the Magic Byte Bug
Mail converted by MHonArc 2.6.10