Mail Index
- Linksys WAG54G2 Web Management Console Local Arbitrary Shell Command Injection Vulnerability
- CFP 26C3 / 26th Chaos Communication Congress
- [ MDVSA-2009:125 ] wireshark
- ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing Windows Explorer remote buffer overflow poc
- FIREFOX URL space character SPOOF
- [SECURITY] [DSA 1807-1] New cyrus-sasl2/cyrus-sasl2-heimdal packages fix arbitrary code execution
- [ MDVSA-2009:124 ] apache
- OCS Inventory NG 1.02 - Multiple SQL Injections
- (Post Form --> Parent Register (name)) Credentials Changer (SQLi) EXPLOIT -- Online Grades & Attendance v-3.2.6-->
- ASMAX AR 804 gu Web Management Console Arbitrary Shell Command Injection Vulnerability
- MULTIPLE SQL INJECTION VULNERABILITIES -- Online Grades & Attendance v-3.2.6 -->
- FRHACK 2009 Final Call For Papers extended
- Re: MULTIPLE REMOTE VULNERABILITIES --Small Pirates v-2.1-->
- [SECURITY] [DSA 1808-1] New drupal6 packages fix insufficient input sanitising
- ACSAC 2009 submissions due June 8 and June 10 (extended)
- ZDI-09-024: Safenet SoftRemote IKE Service Remote Stack Overflow Vulnerability
- Zemana Antilogger 1.9.2 DoS attack
- [USN-778-1] cron vulnerability
- Re: (Post Form --> Parent Register (name)) Credentials Changer (SQLi) EXPLOIT -- Online Grades & Attendance v-3.2.6-->
- The father of all bombs - another webdav fiasco
- Re: Re: (Post Form --> Parent Register (name)) Credentials Changer (SQLi) EXPLOIT -- Online Grades & Attendance v-3.2.6-->
- Secunia Research: Apple QuickTime MS ADPCM Encoding Buffer Overflow
- (Post Form --> 'cc') Blind (SQLi) EXPLOIT --Online Grades & Attendance <= v-3.2.6-->
- Secunia Research: QuickTime Sorenson Video 3 Content Parsing Vulnerability
- ACDSee Products TIFF and Font Parsing Buffer Overflow Vulnerabilities
- From: VUPEN Security Research
- [ MDVSA-2009:126 ] eggdrop
- [SECURITY] [DSA 1809-1] New Linux 2.6.26 packages fix several vulnerabilities
- MULTIPLE LOCAL FILE INCLUSION VULNERABILITIES -- Online Grades & Attendance <= v-3.2.6 -->
- [security bulletin] HPSBUX02429 SSRT090058 rev.2 - HP-UX Running Java, Remote Execution of Arbitrary Code and Other Vulnerabilities
- ZDI-09-025: Apple Quicktime Picture Viewer FLC Delta-Encoded Frame Decompression Vulnerability
- ZDI-09-026: Apple QuickTime Packed-bit Decoding Heap Overflow Vulnerability
- ZDI-09-027: Apple Quicktime PICT Opcode 0x8201 Heap Overflow Vulnerability
- ZDI-09-028: Apple QuickTime CRGN Atom Parsing Heap Buffer Overflow Vulnerability
- ZDI-09-029: Apple QuickTime Jpeg2000 Marker Size Heap Overflow Vulnerability
- ZDI-09-030: Apple Quicktime PICT Opcode 0x71 Heap Overflow Vulnerability
- TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption Vulnerability
- [SECURITY] [DSA 1810-1] New cups/cupsys packages fix denial of service
- TPTI-09-03: Apple iTunes Multiple Protocol Handler Buffer Overflow Vulnerabilities
- CORE-2009-0420 - Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability
- From: CORE Security Technologies Advisories
- [SECURITY] [DSA 1810-1] New libapache-mod-jk packages fix information disclosure
- Advisory: Apple QuickTime Image Description Atom Sign Extension Memory Corruption
- [USN-781-1] Pidgin vulnerabilities
- [USN-781-2] Gaim vulnerabilities
- Re: TPTI-09-03: Apple iTunes Multiple Protocol Handler Buffer Overflow Vulnerabilities
- [USN-780-1] CUPS vulnerability
- [SECURITY] CVE-2009-0033 Apache Tomcat DoS when using Java AJP connector
- [SECURITY] CVE-2009-0580 Apache Tomcat User enumeration vulnerability with FORM authentication
- [ MDVSA-2009:127 ] gaim
- OCS Inventory NG 1.02 - Directory Traversal
- [SECURITY] CVE-2009-0783 Apache Tomcat Information disclosure
- [InterN0T] moziloCMS 1.11.1 - XSS Vulnerability
- [InterN0T] LightNEasy 2.2.2 - HTML Injection Vulnerability
- [InterN0T] SiteCore.NET 6.0.0 - XSS Vulnerability
- [InterN0T] Geeklog 1.5 - Pre-Installation Vulnerabilities
- [InterN0T] Flatnux 2009-03-27 - XSS Vulnerabilities + More
- SQL INJECTION VULNERABILITY--LightOpen CMS Devel 0.1-->
- [ MDVSA-2009:128 ] libmodplug
- [SECURITY] [DSA 1812-1] New apr-util packages fix several vulnerabilities
- Re: [InterN0T] Geeklog 1.5 - Pre-Installation Vulnerabilities
- Re: [SECURITY] CVE-2009-0580 Apache Tomcat User enumeration vulnerability with FORM authentication
- From: Christopher Schultz
- Re: Re: [InterN0T] Geeklog 1.5 - Pre-Installation Vulnerabilities
- [Security] XM Easy Personal FTP Server Multiple DoS vulnerabilities
- [ MDVSA-2009:129 ] file
- [SECURITY] CVE-2009-0580 UPDATED Apache Tomcat User enumeration vulnerability with FORM authentication
- [ISecAuditors Security Advisories] Joomla! 1.5.10 JA_Purity Multiple Persistent XSS
- From: ISecAuditors Security Advisories
- LightOpenCMS 0.1 pre-alpha Remote SQL Injection
- From: Salvatore \"drosophila\" Fresta
- Reminder: DeepSec 2009 Call for Papers is open
- EC2ND 2009 CFP - 5th European Conference on Computer Network Defence
- Re: Exploiting IE8 UTF-7 XSS Vulnerability using Local Redirection
- Re: [Full-disclosure] Cross Site Scripting in PHP Nuke 8.0 Version
- Re: [InterN0T] SiteCore.NET 6.0.0 - XSS Vulnerability-fixed
- SQL INJECTION VULNERABILITY--Kjtechforce mailman Beta-1-->
- [security bulletin] HPSBMA02433 SSRT090084 rev.1 - HP Discovery & Dependency Mapping Inventory (DDMI) Running on Windows, Remote Unauthorized Access
- [ MDVSA-2009:130 ] gstreamer0.10-plugins-good
- ('dest') Blind (SQLi) EXPLOIT --Kjtechforce mailman Beta-1 -->
- [SECURITY] [DSA 1813-1] New evolution-data-server packages fix several vulnerabilities
- [DSECRG-09-015] SAP GUI 6.4 Buffer Overflow vulnerability
- [ MDVSA-2009:131-1 ] apr-util
- [ MDVSA-2009:132 ] libsndfile
- [ MDVSA-2009:131 ] apr-util
- Rasterbar libtorrent arbitrary file overwrite vulnerability
- [USN-783-1] eCryptfs vulnerability
- New paper by Amit Klein (Trusteer) - Temporary user tracking in major browsers and Cross-domain information leakage and attacks
- ZDI-09-031: libpurple MSN Protocol SLP Message Heap Overflow Vulnerability
- [USN-784-1] ImageMagick vulnerability
- ZDI-09-034: Apple Safari SVG Set.targetElement() Memory Corruption Vulnerability
- [SECURITY] CVE-2008-5515 RequestDispatcher directory traversal vulnerability
- ZDI-09-033: Apple WebKit dir Attribute Freeing Dangling Object Pointer Vulnerability
- ZDI-09-032: Apple WebKit attr() Invalid Attribute Memory Corruption Vulnerability
- Apple Safari local file theft vulnerability
- XMLHttpRequest file upload vulnerability Chrome 2 & Safari 3
- TELUS Security Labs VR - Microsoft Office Excel Malformed Records Stack Buffer Overflow
- [security bulletin] HPSBMA02430 SSRT080094 rev.1 - HP OpenView Network Node Manager (OV NNM) Running SNMP and MIB, Remote Execution of Arbitrary Code, Denial of Service (DoS)
- MULTIPLE LOCAL FILE INCLUSION VULNERABILITIES --S-CMS <= v-2.0 Beta3-->
- [USN-785-1] ipsec-tools vulnerabilities
- MULTIPLE SQL INJECTION VULNERABILITIES --S-CMS <= v-2.0 Beta3-->
- (Post Form var 'username') BLIND SQLi exploit --S-CMS <= v-2.0 Beta3-->
- New paper - Testing the Enterprise Security: Anti-Spam and Anti-Virus Solutions
- Re: XMLHttpRequest file upload vulnerability Chrome 2 & Safari 3
- Secunia Research: Microsoft Excel Record Parsing Array Indexing Vulnerability
- Secunia Research: Microsoft Excel String Parsing Integer Overflow Vulnerability
- CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept
- Re: XMLHttpRequest file upload vulnerability Chrome 2 & Safari 3
- CORE-2009-0521 - DX Studio Player Firefox plug-in command injection
- From: CORE Security Technologies Advisories
- CORE-2008-0826 - Internet Explorer Security Zone restrictions bypass
- From: CORE Security Technologies Advisories
- catching up on several recently fixed bugs of note
- [USN-775-2] Quagga regression
- FreeBSD Security Advisory FreeBSD-SA-09:11.ntpd
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-09:10.ipv6
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-09:09.pipe
- From: FreeBSD Security Advisories
- [SECURITY] UPDATED CVE-2008-5515 RequestDispatcher directory traversal vulnerability
- [security bulletin] HPSBUX02435 SSRT090059 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Bypass Security Restrictions
- ZDI-09-037: Microsoft Internet Explorer Concurrent Ajax Request Memory Corruption Vulnerability
- ZDI-09-038: Microsoft Internet Explorer Event Handler Memory Corruption Vulnerability
- FortiGuard Advisory: Microsoft Internet Explorer DHTML Handling Remote Memory Corruption Vulnerability
- From: noreply-secresearch@xxxxxxxxxxxx
- ZDI-09-041: Microsoft Internet Explorer 8 Rows Property Dangling Pointer Code Execution Vulnerability
- ZDI-09-035: Microsoft Word Document Stack Based Buffer Overflow Vulnerability
- FortiGuard Advisory: Apple Safari Remote Memory Corruption Vulnerability
- From: noreply-secresearch@xxxxxxxxxxxx
- XM Easy Personal FTP Server HELP and TYPE command Remote Denial of Service exploit
- From: vinodsharma . mimit
- ZDI-09-040: Microsoft Office Excel QSIR Record Pointer Corruption Vulnerability
- [ECHO_ADV_110$2009] Firefox (GNU/Linux version) <= 3.0.10 Denial Of Services
- ZDI-09-039: Microsoft Internet Explorer onreadystatechange Memory Corruption Vulnerability
- Secunia Research: Microsoft PowerPoint Freelance Layout Parsing Vulnerability
- Secunia Research: Adobe Reader JBIG2 Text Region Segment Buffer Overflow
- Apple Safari cross-domain XML theft vulnerability
- ZDI-09-036: Microsoft Internet Explorer setCapture Memory Corruption Vulnerability
- [USN-786-1] apr-util vulnerabilities
- F5 FirePass Cross-Site Scripting vulnerability
- ZDI-09-042: Adobe Reader U3D RHAdobeMeta Stack Overflow Vulnerability
- (Post Form login var 'username') BLIND SQLi exploit--Open Biller 0.1-->
- MULTIPLE SQL INJECTION VULNERABILITIES --Splog <= v-1.2 Beta-->
- iDefense Security Advisory 06.11.09: Microsoft Active Directory Hexdecimal DN AttributeValue Invalid Free Vulnerability
- iDefense Security Advisory 06.11.09: Multiple Vendor WebKit Error Handling Use After Free Vulnerability
- ModSecurity (Core Rules) HTTP Parameter Pollution Filter Bypass Vulnerability
- iDefense Security Advisory 06.11.09: Microsoft Excel SST Record Integer Overflow Vulnerability
- FortiGuard Advisory: Adobe Reader/Acrobat TrueType Font Processing Memory Corruption Vulnerability
- From: noreply-secresearch@xxxxxxxxxxxx
- iDefense Security Advisory 06.11.09: Microsoft Windows 2000 Print Spooler Remote Stack Buffer Overflow Vulnerability
- iDefense Security Advisory 06.11.09: Adobe Reader and Acrobat FlateDecode Integer Overflow Vulnerability
- VUPEN Security - Microsoft Office Word Document Parsing Buffer Overflow Vulnerability
- From: VUPEN Security Research
- VUPEN Security - Adobe Acrobat and Reader JBIG2 Filter Heap Overflow Vulnerability
- From: VUPEN Security Research
- [USN-787-1] Apache vulnerabilities
- Secunia Research: Mozilla Firefox Java Applet Loading Vulnerability
- Serena Dimensions CM has insufficient default privileges
- From: roland . gruber . extern
- [USN-779-1] Firefox and Xulrunner vulnerabilities
- [TZO-31-2009] Ikarus multiple generic evasions (CAB,ZIP,RAR)
- [TZO-32-2009] Norman generic bypass (RAR)
- [TZO-33-2009] Frisk F-prot evasion (TAR)
- [TZO-36-2009] Apple Safari & Quicktime Denial of Service
- [SECURITY] [DSA 1815-1] New libtorrent-rasterbar packages fix denial of service
- [waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 1.09
- [TZO-37-2009] Apple Safari <v4 Remote code execution
- [TZO-30-2009] Kaspersky and the silent patch that wasn't (PDF evasion, forced full disclosure)
- SugarCRM 5.2.0e Remote Code Execution
- Link Logger syslogd resource overwhelm DoS
- CakeCMS XSRF Vulnerability
- [InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities
- [InterN0T] SkyBlueCanvas 1.1 r237 - Multiple Vulnerabilities
- [InterN0T] TBDev 01-01-2008 - Multiple Vulnerabilities
- [InterN0T] transLucid 1.75 - Multiple Vulnerabilities
- [InterN0T] Webmedia Explorer - XSS Vulnerability
- [SECURITY] [DSA 1814-1] New libsndfile packages fix arbitrary code execution
- [USN-788-1] Tomcat vulnerabilities
- [DSF-02-2009] - Zoki Catalog SQL Injection
- Netgear DG632 Router Authentication Bypass Vulnerability
- Netgear DG632 Router Remote DoS Vulnerability
- Re: Netgear DG632 Router Remote DoS Vulnerability
- Re: VUPEN Security - Microsoft Office Word Document Parsing Buffer Overflow Vulnerability
- Re: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability
- [TZO-33-2009] Fprot generic bypass (TAR)
- Re[2]: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability
- From: Vladimir '3APA3A' Dubrovin
- [TZO-40-2009] Clamav generic bypass (RAR,CAB,ZIP)
- CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities
- CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities (Updated)
- CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability
- Official release of "Keykeriki" open source wireless keyboard sniffer
- [ MDVSA-2009:133 ] irssi
- phpMyTourney adminfunctions.php Remote File Include Vulnerabilities
- WinAppDbg version 1.2 is out!
- From: Mario Alejandro Vilas Jerez
- Re: [Full-disclosure] WinAppDbg version 1.2 is out!
- Re: [Full-disclosure] WinAppDbg version 1.2 is out!
- From: Mario Alejandro Vilas Jerez
- ZDI-09-043: Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability
- [SECURITY] [DSA 1816-1] New apache2 packages fix privilege escalation
- CERT-FI statement on the Outpost24 TCP issues updated
- [ MDVSA-2009:134 ] firefox
- [ MDVSA-2009:135 ] kernel
- [SECURITY] [DSA 1817-1] New ctorrent packages fix arbitrary code execution
- [SECURITY] [DSA 1818-1] New gforge packages fix insufficient input sanitising
- [TZO-34-2009] Frisk FPROT generic evasion (RAR,ARJ,LHA)
- [TZO-43-2009] - Clamav generic evasion (CAB)
- iPhone Safari phone-auto-dial vulnerability (original date: Nov. 2008)
- [SECURITY] [DSA 1820-1] New xulrunner packages fix several vulnerabilities
- Nokia 6212 classic URI spoofing and DoS advisory (original date: Dec. 2008)
- ERRATA: [TZO-32-2009] Norman generic bypass (RAR)
- The Möbius Defense, the end of Defense in Depth
- Re: CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept
- [SECURITY] [DSA 1819-1] New vlc packages fix several vulnerabilities
- Re: Advisory: Apple QuickTime Image Description Atom Sign Extension Memory Corruption
- Re: iPhone Safari phone-auto-dial vulnerability (original date: Nov. 2008)
- PhpPortal v1 Insecure Cookie Handling Vulnerability
- MULTIPLE LOCAL FILE INCLUSION VULNERABILITIES --FretsWeb 1.2-->
- [ MDVSA-2009:137 ] java-1.6.0-openjdk
- (GET var 'name') BLIND SQL INJECTION EXPLOIT --FretsWeb 1.2-->
- [USN-789-1] GStreamer Good Plugins vulnerability
- CMS Buzz (XSS/PC/HI) Multiple Remote Vulnerabilities
- FretsWeb 1.2 (name) Remote Blind SQL Injection Exploit
- phportal 1.0 Insecure Cookie Handling Vulnerability
- fuzzylime cms <= 3.03a Local Inclusion / Arbitrary File Corruption PoC
- FretsWeb 1.2 Multiple Local File Inclusion Vulnerabilities
- [RISE-2009001] ToolTalk rpc.ttdbserverd _tt_internal_realpath Buffer Overflow Vulnerability
- Back door trojan in acajoom-3.2.6 for joomla
- [ MDVSA-2009:136 ] tomcat5
- [SECURITY] [DSA 1821-1] New amule packages fix insufficient input sanitising
- [ MDVSA-2009:138 ] tomcat5
- CFP: ISOI 7 - Sept 17, 18 - San Diego
- [SECURITY] [DSA 1822-1] New mahara packages fix cross-site scripting
- n.runs-SA-2009.006 - Apple Safari - Null pointer dereference
- n.runs-SA-2009.005 - Apple Safari - Information disclosure
- Authentication Bypas in BASE version 1.2.4 and prior
- Re: Authentication Bypass in BASE version 1.2.4 and prior
- [ MDVSA-2009:139 ] libtorrent-rasterbar
- Trustwave's SpiderLabs Security Advisory TWSL2009-002
- From: Trustwave Advisories
- CHASE - 2009 Lahoe Pakistan | Call for Papers
- From: Muhammad Farooq-i-Azam
- Cisco Security Advisory: Cisco Physical Access Gateway Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Re: Authentication Bypas in BASE version 1.2.4 and prior
- Cisco Security Advisory: Vulnerabilities in Cisco Video Surveillance Products
- From: Cisco Systems Product Security Incident Response Team
- [USN-790-1] Cyrus SASL vulnerability
- [USN-791-1] Moodle vulnerabilities
- [USN-791-2] Moodle vulnerability
- [USN-791-3] Smarty vulnerability
- [ MDVSA-2009:140 ] gaim
- (POST var 'resetpwemail') BLIND SQL INJECTION EXPLOIT --AlumniServer v-1.0.1-->
- [USN-792-1] OpenSSL vulnerabilities
- iDefense Security Advisory 06.25.09: Unisys Business Information Server Stack Buffer Overflow
- [SECURITY] [DSA 1823-1] New samba packages fix several vulnerabilities
- iDefense Security Advisory 06.25.09: Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability
- SQL INJECTION VULNERABILITY --AlumniServer v-1.0.1-->
- [SECURITY] [DSA 1824-1] New phpmyadmin packages fix several vulnerabilities
- [USN-782-1] Thunderbird vulnerabilities
- Security Assessment of TCP at the IETF
- aMSN SSL Certificate Vulnerability
- From: Gabriel Menezes Nunes
- Gizmo SSL Certificate Vulnerability
- From: Gabriel Menezes Nunes
- Trillian SSL Certificate Vulnerability
- From: Gabriel Menezes Nunes
- Report vulnerabilities
- evil little dictionary
- Re: Trillian SSL Certificate Vulnerability
- MULTIPLE SQL INJECTION VULNERABILITIES --PHP-AddressBook v-4.0.x-->
- [ MDVSA-2009:141 ] mozilla-thunderbird
- iDefense Security Advisory 06.26.09: HP Network Node Manager rping Stack Buffer Overflow Vulnerability
- [ MDVSA-2009:143 ] netpbm
- [ GLSA 200906-01 ] libpng: Information disclosure
- Mega File Manager Remote File Vuln
- osTicket v1.6 RC4 Admin Login Blind SQLi
- [ MDVSA-2009:145 ] php
- Shakacon III - Presentations Posted to site
- [ MDVSA-2009:142 ] jasper
- AjaxPortal v3.0 Remote File Inclusion Vulnerability
- [ MDVSA-2009:144 ] ghostscript
- [ GLSA 200906-02 ] Ruby: Denial of Service
- [ MDVSA-2009:146 ] imap
- [ GLSA 200906-03 ] phpMyAdmin: Multiple vulnerabilities
- [ GLSA 200906-04 ] Apache Tomcat JK Connector: Information disclosure
Mail converted by MHonArc