Mail Index
- [ MDVSA-2008:159 ] licq
- [oCERT-2008-009] libxslt heap overflow
- Secunia Research: Blue Coat K9 Web Protection "Referer" Header Buffer Overflow
- [security bulletin] HPSBUX02286 SSRT071466 rev.1 - HP-UX Running System Administration Manager (SAM), Unintended Remote Access
- Pligg <= 9.9.0 Multiple Vulnerabilities
- From: GulfTech Security Research
- Secunia Research: Blue Coat K9 Web Protection Response Handling Buffer Overflows
- [SECURITY] [DSA 1622-1] New newsx packages fix arbitrary code execution
- [~] Greetz : Me93fg & Mr.SaFa7
- iDefense Security Advisory 07.30.08: SAP MaxDB dbmsrv Untrusted Execution Path Vulnerability
- [ GLSA 200807-15 ] Pan: User-assisted execution of arbitrary code
- [SECURITY] [DSA 1623-1] New dnsmasq packages fix cache poisoning
- [ GLSA 200807-14 ] Linux Audit: Buffer overflow
- [ GLSA 200807-13 ] VLC: Multiple vulnerabilities
- [SECURITY] [DSA 1624-1] New libxslt packages fix arbitrary code execution
- [ GLSA 200807-16 ] Python: Multiple vulnerabilities
- CA ARCserve Backup for Laptops and Desktops Server LGServer Service Vulnerability
- [CVE-2008-2370] Apache Tomcat information disclosure vulnerability
- libxslt heap overflow
- [SECURITY] [DSA 1625-1] New cupsys packages fix arbitrary code execution
- [SECURITY] [DSA 1626-1] New httrack packages fix arbitrary code execution
- [CVE-2008-1232] Apache Tomcat XSS vulnerability
- [USN-634-1] OpenLDAP vulnerability
- eVision 2.0 Sql Injection/Remote File Disclosure/Remote File Upload/IG
- DNS Multiple Race Exploiting Tool
- [USN-632-1] Python vulnerabilities
- [USN-633-1] libxslt vulnerabilities
- iDefense Security Advisory 07.31.08: Apple Mac OS X CoreGraphics PDF Type1 Font Integer Overflow Vulnerability
- n.runs-SA-2008.005 - Apple Inc. - CoreServices Framework’s CarbonCore Framework - Arbitrary Code Execution (remote)
- Re: how to request a cve id?
- From: William A. Rowe, Jr.
- Re: Windows Vista Power Management & Local Security Policy
- From: William A. Rowe, Jr.
- [ MDVSA-2008:160 ] libxslt
- file upload exploit
- iDefense Security Advisory 08.01.08: Ingres Database for Linux verifydb Insecure File Permissions Modification Vulnerability
- iDefense Security Advisory 08.01.08: Ingres Database for Linux libbecompat Stack Based Buffer Overflow Vulnerability
- iDefense Security Advisory 08.01.08: Ingres Database for Linux ingvalidpw Untrusted Library Path Vulnerability
- Pligg Auto-Voter Using XSS to Bypass CSRF Protection
- Homes 4 Sale Remote XSS Vulnerabilitiy
- Server termination in America's Army 2.8.3.1
- Keld: PHP-MySQL News Script 0.7.1 Remote SQL injection Vulnerability
- TGS CMS Remote Code Execution Exploit
- [SECURITY] [DSA 1627-1] New opensc packages fix smart card vulnerability
- UNAK-CMS Lfi
- [USN-626-2] Devhelp, Epiphany, Midbrowser and Yelp update
- Team SHATTER Security Advisory: SQL Injection in Oracle Application Server (WWEXP_API_ENGINE)
- Team SHATTER Security Advisory: Cross-site scripting in Oracle Enterprise Manager (REFRESHCHOICE Parameter)
- Team SHATTER Security Advisory: SQL Injection in Oracle Database (DBMS_DEFER_SYS.DELETE_TRAN)
- CORE-2008-0716 - Sun xVM VirtualBox Privilege Escalation Vulnerability
- From: CORE Security Technologies Advisories
- Xampp Linux 1.6.7 Multiple Cross Site Scripting Vulnerabilities
- 8e6 Technologies R3000 Internet Filter Bypass with Host Decoy
- Plogger <= 3.0 SQL Injection
- From: GulfTech Security Research
- IGES CMS <=2.0 Multiple Vulnerabilities
- Pluck 4.5.2 Multiple Cross Site Scripting Vulnerabilities
- [ GLSA 200808-01 ] xine-lib: User-assisted execution of arbitrary code
- [ GLSA 200808-02 ] Net-SNMP: Multiple vulnerabilities
- [ GLSA 200808-03 ] Mozilla products: Multiple vulnerabilities
- [ GLSA 200808-04 ] Wireshark: Denial of Service
- rPSA-2008-0245-1 cups
- From: rPath Update Announcements
- rPSA-2008-0246-1 gaim
- From: rPath Update Announcements
- PHP-NUKE module Kleinanzeigen SQL injection (lid)
- MyClan Sql Injection
- Re: 8e6 Technologies R3000 Internet Filter Bypass with Host Decoy
- Interesting things at sec-consult.com, DNS-whitepaper available tomorrow
- CA Products That Embed Ingres Multiple Vulnerabilities
- Google Notebook and Google Bookmarks Cross Site Scripting Vulnerabilities
- Apache HTTP Server mod_proxy_ftp Wildcard Characters Cross-Site Scripting
- [ GLSA 200808-05 ] ISC DHCP: Denial of Service
- [USN-635-1] xine-lib vulnerabilities
- [ GLSA 200808-06 ] libxslt: Execution of arbitrary code
- [security bulletin] HPSBUX02351 SSRT080058 rev.3 - HP-UX Running BIND, Remote DNS Cache Poisoning
- [security bulletin] HPSBUX02355 SSRT080023 rev.1 - HP-UX Using libc, Remote Denial of Service (DoS)
- OpenVMS fingerd remote stack overflow
- Endless loop and resources consumption in Halo 1.0.7.0615
- Re: [Full-disclosure] [funsec] facebook messages worm
- Re: [funsec] facebook messages worm
- facebook messages worm
- Whitepaper: DNS zone redelegation
- Re: [funsec] facebook messages worm
- Re: [funsec] facebook messages worm
- [SE-2008-01] J2ME Security Vulnerabilities 2008
- From: Security Explorations
- [ MDVSA-2008:161 ] rxvt
- Re: OpenVMS fingerd remote stack overflow
- From: Kevin Finisterre (lists)
- e107 <= 0.7.11 Arbitrary Variable Overwriting
- From: GulfTech Security Research
- Re: [SE-2008-01] J2ME Security Vulnerabilities 2008
- Re: OpenVMS fingerd remote stack overflow
- Re: OpenVMS fingerd remote stack overflow
- [ MDVSA-2008:162 ] qemu
- [ MDVSA-2008:163 ] python
- re: [SE-2008-01] J2ME Security Vulnerabilities 2008
- From: Security Explorations
- [ MDVSA-2008:164 ] python
- Re: Re: [SE-2008-01] J2ME Security Vulnerabilities 2008
- Re: [funsec] facebook messages worm
- OpenID/Debian PRNG/DNS Cache poisoning advisory
- [AJECT] NoticeWare IMAP Email Server 4.6.2 DoS vulnerability
- Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- [AJECT] WinGate Email Server (IMAP) vulnerability
- Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory
- Vim: Unfixed Vulnerabilities in Tar Plugin Version 20
- RE: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- [ GLSA 200808-07 ] ClamAV: Multiple Denials of Service
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- [ GLSA 200808-08 ] stunnel: Security bypass
- Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory
- [DSECRG-08-035] Local File Include Vulnerability in Gallery 1.5.7, 1.6-alpha3
- From: Digital Security Research Group [DSecRG]
- [ GLSA 200808-09 ] OpenLDAP: Denial of Service vulnerability
- RE: OpenID/Debian PRNG/DNS Cache poisoning advisory
- RE: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- New paper: An Illustrated Guide to the Kaminsky DNS Vulnerability
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenVMS fingerd remote stack overflow
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- key blacklisting & file size (was: OpenID/Debian PRNG/DNS Cache poisoning advisory)
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- [security bulletin] HPSBUX02351 SSRT080058 rev.4 - HP-UX Running BIND, Remote DNS Cache Poisoning
- Kayako SupportSuite < 3.30.00 Multiple Vulnerabilities
- From: GulfTech Security Research
- [ GLSA 200808-10 ] Adobe Reader: User-assisted execution of arbitrary code
- Ovidentia Sql Injection
- [SECURITY] [DSA 1627-1] New PowerDNS packages reduce DNS spoofing risk
- Re: [DSECRG-08-035] Local File Include Vulnerability in Gallery 1.5.7, 1.6-alpha3
- K-Links Directory Blind SQL Injection Exploit
- From: hadihadi_zedehal_2006
- rPSA-2008-0249-1 openldap openldap-clients openldap-servers
- From: rPath Update Announcements
- rPSA-2008-0247-1 gvim vim vim-minimal
- From: rPath Update Announcements
- [ GLSA 200808-11 ] UUDeview: Insecure temporary file creation
- Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability
- Re: Team SHATTER Security Advisory: SQL Injection in Oracle Database (DBMS_DEFER_SYS.DELETE_TRAN)
- Layered Defense Research Advisory: Alcatel-Lucent OmniSwitch products, Stack Buffer Overflow
- RE: OpenID/Debian PRNG/DNS Cache poisoning advisory
- From: Clausen, Martin (DK - Copenhagen)
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: TGS CMS Remote Code Execution Exploit
- iDefense Security Advisory 08.04.08: Solaris snoop SMB Decoding Multiple Format String Vulnerabilities
- [AJECT] hMailServer 4.4.1 DoS vulnerability
- iDefense Security Advisory 08.04.08: Solaris snoop SMB Decoding Multiple Stack Buffer Overflow Vulnerabilities
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- From: Forrest J. Cavalier III
- Internet attacks against Georgian web sites
- VMSA-2008-0012 Updated VirtualCenter addresses User Account Disclosure Vulnerability
- From: VMware Security Team
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- rPSA-2008-0253-1 git gitweb
- From: rPath Update Announcements
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- CA Host-Based Intrusion Prevention System SDK kmxfw.sys Multiple Vulnerabilities
- VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl
- From: VMware Security Team
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Surf Jack - HTTPS will not save you
- Re: OpenID/Debian PRNG/DNS Cache poisoning advisory
- Re: [funsec] Internet attacks against Georgian web sites
- Re: [funsec] Internet attacks against Georgian web sites
- [security bulletin] HPSBUX02356 SSRT080051 rev.1 - HP-UX Running ftpd, Remote Privileged Access
- ZDI-08-048: Microsoft Excel COUNTRY Record Memory Corruption Vulnerability
- ZDI-08-051: Microsoft Internet Explorer Table Layout Memory Corruption Vulnerability
- ZDI-08-049: Microsoft Windows Graphics Rendering Engine PICT Heap Corruption
- iDefense Security Advisory 08.12.08: Microsoft Office BMP Input Filter Heap Overflow Vulnerability
- Re: Vim: Netrw: FTP User Name and Password Disclosure
- [ MDVSA-2008:167 ] kernel
- ZDI-08-050: Microsoft Internet Explorer XHTML Rendering Memory Corruption Vulnerability
- [ MDVSA-2008:166 ] clamav
- Vim: Netrw: FTP User Name and Password Disclosure
- iDefense Security Advisory 08.12.08: Microsoft Office WPG Image File Heap Buffer Overflow Vulnerability
- [TKADV2008-006] CA HIPS KmxFw.sys Kernel Memory Corruption
- iDefense Security Advisory 08.12.08: Microsoft PowerPoint Viewer 2003 Out of Bounds Array Index Vulnerability
- iDefense Security Advisory 08.12.08: Microsoft PowerPoint Viewer 2003 Cstring Integer Overflow Vulnerability
- iDefense Security Advisory 08.12.08: Microsoft Excel Chart AxesSet Invalid Array Index Vulnerability
- iDefense Security Advisory 08.12.08: Microsoft Excel FORMAT Record Invalid Array Index Vulnerability
- iDefense Security Advisory 08.12.08: Microsoft Windows Color Management Module Heap Buffer Overflow Vulnerability
- rPSA-2008-0243-1 idle python
- From: rPath Update Announcements
- Vim 7.2c.002 Fixes Arbitrary Command Execution when Handling Tar Archives
- NULL pointer in Ventrilo 3.0.2
- [security bulletin] HPSBTU02358 SSRT080058 rev.1 - HP Tru64 UNIX running BIND, Remote DNS Cache Poisoning
- CORE-2008-0103: Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass
- From: CORE Security Technologies Advisories
- [ MDVSA-2008:170 ] cups
- Microsoft Windows Messenger Remote Illegal Access Vulnerability
- [ MDVSA-2008:168 ] stunnel
- [ MDVSA-2008:169 ] hplip
- [security bulletin] HPSBOV02357 SSRT080058 rev.1 - HP OpenVMS TCP/IP Services running BIND, Remote DNS Cache Poisoning
- Postfix local privilege escalation via hardlinked symlinks
- SYM08-015_SFW_SecurityUpdateBypass
- ZDI-08-053: Symantec Veritas Storage Foundation Scheduler Service NULL Session Authentication Bypass Vulnerability
- Security Assessment of the Internet Protocol
- rPSA-2008-0255-1 freetype
- From: rPath Update Announcements
- [ GLSA 200808-12 ] Postfix: Local privilege escalation vulnerability
- Cisco Security Advisory: Vulnerability in Cisco WebEx Meeting Manager ActiveX Control
- From: Cisco Systems Product Security Incident Response Team
- Re: MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface
- munky-bliki lfi
- Mambo 4.6.2 Full Version - Multiple Cross Site Scripting - By Khashayar Fereidani
- FlexCMS <= 2.5 Cross Site Scripting Vulnerability
- [ MDVSA-2008:171 ] postfix
- [ MDVSA-2008:172 ] amarok
- PHP Live Helper <= 2.0.1 Multiple Vulnerabilities
- From: GulfTech Security Research
- Nokia 6131 NFC URI/URL Spoofing and DoS Advisory
- Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user
- NewsHOWLER 1.03 Beta Cookie Handling Via Sql injection
- [DSECRG-08-036] Multiple Security Vulnerabilities in Freeway eCommerce 1.4.1.171
- From: Digital Security Research Group [DSecRG]
- Tool: PorkBind v1.3 Nameserver Security Scanner (New Version)
- Ovidentia 6.6.5 XSS (index.php)‏
- [security bulletin] HPSBMA02345 SSRT080039 rev.2 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS)
- [SECURITY] [DSA 1629-1] New postfix packages fix privilege escalation
- [SECURITY] [DSA 1629-2] New postfix packages fix installability problem on i386
- [security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051
- SunShop <= 4.1.4 SQL Injection
- From: GulfTech Security Research
- Vanilla <= 1.1.4 Script Injection/ XSS
- From: GulfTech Security Research
- [ MDVSA-2008:173 ] kdegraphics
- [ MDVSA-2008:174 ] kernel
- [USN-636-1] Postfix vulnerability
- ToorCon 10 Call For Papers
- Folder Lock <= 5.9.5 Local Password Information Disclosure
- [ MDVSA-2008:175 ] yelp
- IMF 2008 - Call for Participation
- [ MDVSA-2008:176 ] mtr
- CORE-2008-0624: Anzio Web Print Object Buffer Overflow
- From: CORE Security Technologies Advisories
- Null Byte Local file Inclusion in FAR - PHP Project version:1.0
- CORE-2008-0813 - vBulletin Cross Site Scripting Vulnerability
- From: CORE Security Technologies Advisories
- rPSA-2008-0259-1 postfix
- From: rPath Update Announcements
- [ MDVSA-2008:177 ] xine-lib
- [ MDVSA-2008:178 ] xine-lib
- UPDATE: [ GLSA 200804-22 ] PowerDNS Recursor: DNS Cache Poisoning
- [SECURITY] [DSA 1630-1] New Linux 2.6.18 packages fix several vulnerabilities
- TimeTrex Time and Attendance Cookie Theft
- Contest: Best Advances for OpenVAS Network Vulnerability Tests
- Call For Papers - Hackers 2 Hackers Conference 5th Edition - Brazil
- PR08-20: Bypassing ASP .NET "ValidateRequest" for Script Injection Attacks
- From: ProCheckUp Research
- Vim: Arbitrary Code Execution in Commands: K, Control-], g]
- RE: TimeTrex Time and Attendance Cookie Theft
- [ MDVSA-2008:179 ] metisse
- [ MDVSA-2008:180 ] libxml2
- Secunia Research: Trend Micro Products Web Management Authentication Bypass
- Fedora confirms: Our servers were breached
- Apple OSX Leopard (10.5+), inadequate ACL insight can create vuln
- From: bgtrq . tryfixingit
- Re: Null Byte Local file Inclusion in FAR - PHP Project version:1.0
- [SECURITY] [DSA 1631-1] New libxml2 packages fix denial of service
- [oCERT-2008-008] multiple heap overflows in xine-lib
- Re: RE: TimeTrex Time and Attendance Cookie Theft
- Re: Fedora confirms: Our servers were breached
- OneNews Beta 2 Multiple Vulnerabilities
- Re: TimeTrex Time and Attendance Cookie Theft
- Secunia Research: Novell iPrint Client ActiveX Control "GetFileList()" Information Disclosure
- RE: Arbitrary Code Execution in Commands: K, Control-], g]
- [DSECRG-08-038] Multiple Local File Include Vulnerabilities in ezContents CMS 2.0.3
- From: Digital Security Research Group [DSecRG]
- Secunia Research: Calendarix Basic Two SQL Injection Vulnerabilities
- Secunia Research: Novell iPrint Client ActiveX Control Multiple Buffer Overflows
- [DSECRG-08-037] Multiple Local File Include Vulnerabilities in Pluck CMS 4.5.2
- From: Digital Security Research Group [DSecRG]
- SECOBJADV-2008-03.2: PartyGaming PartyPoker Malicious Update Vulnerability
- From: Security Objectives Corporation
- [IVIZ-08-009] Grub Legacy Security Model bypass exploiting wrong BIOS API usage
- From: iViZ Security Advisories
- [IVIZ-08-006] DiskCryptor Security Model bypass exploiting wrong BIOS API usage
- From: iViZ Security Advisories
- Crafty Syntax Live Help <= 2.14.6 SQL Injection
- From: GulfTech Security Research
- ToorCon X CFP Closing and Workshops and Seminars discounted until Friday!
- Mini-NUKE v2.3 Freehost (tr) Multiple Remote SQL Injection Vulnerabilities
- ZoneMinder Multiple Vulnerabilities
- Hopeless comments regarding the pointless "HP System Management Homepage (SMH) Unspecified XSS"
- [SECURITY] [DSA 1632-1] New tiff packages fix arbitrary code execution
- Multiple Vulnerabilities in AWStats Totals
- [SECURITY] [DSA 1631-1] New libxml2 packages fix denial of service
- White Wolf Labs #080826-1: Kyocera Mita Scanner File Utility (Multiple)
- PacSec 2008 CFP (Deadline Sept. 1, Conference Nov. 12/13) and BA-Con 2008 Speakers (Sept .30/ Oct. 1)
- [ MDVSA-2008:180-1 ] libxml2
- [security bulletin] HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges
- [IVIZ-08-008] LILO Security Model bypass exploiting wrong BIOS API usage
- From: iViZ Security Advisories
- [IVIZ-08-007] DriveCrypt Security Model bypass exploiting wrong BIOS API usage
- From: iViZ Security Advisories
- [IVIZ-08-003] TrueCrypt Security Model bypass exploiting wrong BIOS API usage
- From: iViZ Security Advisories
- [USN-638-1] Yelp vulnerability
- [IVIZ-08-004] Intel BIOS Plain Text Password Disclosure
- From: iViZ Security Advisories
- XSS and Data Manipulation attacks found in CMS PHPCart.
- [IVIZ-08-002] Hewlett-Packard BIOS Plain Text Password Disclosure
- From: iViZ Security Advisories
- [IVIZ-08-005] IBM Lenovo BIOS Plain Text Password Disclosure
- From: iViZ Security Advisories
- [security bulletin] HPSBUX02365 SSRT080118 rev.1 - HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)
- reviving the botnets@ mailing list: a new statregy in fighting cyber crime
- ZDI-08-054: Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability
- [scip_Advisory 3807] Dreambox DM500 webserver long URL request denial of service
- [Advisory] Invision Power Board <= 2.3.5 Multiple Vulnerabilities and Security Bypass
- [ MDVSA-2008:181 ] ipsec-tools
- [Exploit] Invision Power Board <= 2.3.5 Multiple Vulnerabilities
- Re: [Exploit] Invision Power Board <= 2.3.5 Multiple Vulnerabilities
- VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.
- From: VMware Security team
- Re: [Advisory] Invision Power Board <= 2.3.5 Multiple Vulnerabilities and Security Bypass
- [SECURITY] [DSA-1597-2] New mt-daapd package fix regression
Mail converted by MHonArc