Mail Index
- [ MDVSA-2009:182 ] firefox
- Re: wordpress plugins wp-Table v1.52 Remote File Inclusion Vulnerability
- From: YGN Ethical Hacker Group (http://yehg.net)
- [ MDVSA-2009:183 ] apache-mod_security
- [ MDVSA-2009:184 ] apache-mod_security
- [ MDVSA-2009:185 ] firefox
- [ MDVSA-2009:186 ] firebird
- [ MDVSA-2009:187 ] nagios
- [ MDVSA-2009:188 ] php4-eaccelerator
- [ GLSA 200908-01 ] OpenSC: Multiple vulnerabilities
- [ MDVSA-2009:189 ] apache-mod_auth_mysql
- [ GLSA 200908-02 ] BIND: Denial of Service
- Advisory: Adobe Flash Player and AIR AVM2 intf_count Integer Overflow Remote Code Execution (CVE-2009-1869)
- [SECURITY] [DSA 1848-1] New znc packages fix remote code execution
- [SECURITY] [DSA 1849-1] New xml-security-c packages fix signature forgery
- [ MDVSA-2009:190 ] OpenEXR
- [ MDVSA-2009:191 ] OpenEXR
- AST-2009-004: Remote Crash Vulnerability in RTP stack
- From: Asterisk Security Team
- [security bulletin] HPSBMA02445 SSRT090058 rev.1 - HP Serviceguard Manager, Remote Execution of Arbitrary Code, Denial of Service (DoS)
- [security bulletin] HPSBUX02181 SSRT061289 rev.4 - HP-UX Running IPFilter, Remote Denial of Service (DoS)
- Blink Blog System Authentication Bypass
- From: Salvatore Fresta aka Drosophila
- Cross-Site Scripting vulnerabiliy in Firefox and Opera
- Discloser 0.0.4-rc2 SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- Team SHATTER Security Advisory: Multiple SQL Injection vulnerabilities in Oracle Enterprise Manager
- [SECURITY] [DSA 1850-1] New libmodplug packages fix arbitrary code execution
- SAP Business One 2005 Remote Buffer Overflow Vulnerability.
- Palm Pre WebOS 1.0.4 Remote execution of arbitrary HTML code vulnerability
- [BONSAI] SQL Injection in CS-Cart
- From: Bonsai - Information Security
- Re: Multiple Flaws in Huawei D100
- [USN-810-1] NSS vulnerabilities
- [USN-810-2] NSPR update
- [USN-811-1] Firefox and Xulrunner vulnerability
- [ MDVSA-2009:192 ] phpmyadmin
- Multiple Flaws in Huawei SmartAX MT880 [was: Multiple Flaws in Huawei D100]
- ZDI-09-047: Microsoft Internet Explorer getElementsByTagName Memory Corruption Vulnerability
- ZDI-09-048: Microsoft Internet Explorer CSS Behavior Memory Corruption Vulnerability
- ZDI-09-049: Sun Java Pack200 Decoding Inner Class Count Integer Overflow Vulnerability
- ZDI-09-050: Sun Java Web Start JPEG Header Parsing Integer Overflow Vulnerability
- fetchmail security announcement fetchmail-SA-2009-01 (CVE-2009-2666)
- [SECURITY] [DSA 1851-1] New gst-plugins-bad0.10 packages fix arbitrary code execution
- [ MDVSA-2009:193 ] ruby
- [ MDVSA-2009:194 ] wireshark
- [ MDVSA-2009:195 ] apr
- [CSS09-01] SlideShowPro Director File Disclosure Vulnerability
- iDefense Security Advisory 08.06.09: Sun Java Runtime Environment (JRE) Pack200 Decompression Integer Overflow Vulnerability
- OpenCms (7.5.0) - Vulnerability: Cross-Site Scripting, Phishing Through Frames, Application Error
- iDefense Security Advisory 08.06.09: IBM AIX libC _LIB_INIT_DBG Arbitrary File Creation Vulnerability
- [ MDVSA-2009:195-1 ] apr
- iDefense Security Advisory 08.06.09: Adobe Flash Player URL Parsing Heap Overflow Vulnerability
- iDefense Security Advisory 08.06.09: Microsoft Internet Explorer HTML TIME 'ondatasetcomplete' Use After Free Vulnerability
- CA20090806-02: Security Notice for Unicenter Asset Portfolio Management, Unicenter Desktop and Server Management, Unicenter Patch Management
- CA20090806-01: Security Notice for Data Transport Services
- CFP: International workshop on Secure Software Engineering
- [ GLSA 200908-03 ] libTIFF: User-assisted execution of arbitrary code
- [ GLSA 200908-04 ] Adobe products: Multiple vulnerabilities
- [security bulletin] HPSBUX02451 SSRT090137 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS)
- [security bulletin] HPSBOV02452 SSRT090161 rev.1 - HP TCP/IP Services for OpenVMS BIND Server Remote Denial of Service (DoS)
- [security bulletin] HPSBTU02453 SSRT091037 rev.1 - HP Tru64 UNIX BIND Server, Denial of Service (DoS)
- [SECURITY] [DSA 1852-1] New fetchmail packages fix SSL certificate verification weakness
- Subversion heap overflow
- [SECURITY] [DSA 1853-1] New memcached packages fix arbitrary code execution
- [ MDVSA-2009:196 ] samba
- iDefense Security Advisory 08.07.09: Adobe Flash Player Invalid Loader Object Reference Vulnerability
- ASUS Eee PC and other series: BIOS SMM privilege escalation vulnerabilities
- ZDI-09-051: EMC Replication Manager Client Control Service Remove Code Execution Vulnerability
- ZDI-09-052: CA Unicenter Software Delivery dtscore.dll Stack Overflow Vulnerability
- [USN-813-3] apr-util vulnerability
- [SECURITY] [DSA 1857-1] New camlimages packages fix arbitrary code execution
- [ MDVSA-2009:161-1 ] squid
- [ MDVSA-2009:198 ] firefox
- [NGENUITY] - Ticket Subject Persistent XSS in Kayako SupportSuite
- [USN-813-1] apr vulnerability
- [RT-SA-2009-005] Papoo CMS: Authenticated Arbitrary Code Execution
- From: RedTeam Pentesting GmbH
- [SECURITY] [DSA 1854-1] New APR packages fix arbitrary code execution
- [USN-813-2] Apache vulnerability
- [SECURITY] [DSA 1855-1] New subversion packages fix arbitrary code execution
- [USN-812-1] Subversion vulnerability
- [NGENUITY] - Spiceworks Multiple Vulnerabilities (XSS & CSRF)
- XSS in SqLiteManager
- [SECURITY] [DSA 1856-1] New mantis packages fix information leak
- [ MDVSA-2009:199 ] subversion
- [ MDVSA-2009:197 ] nss
- [SECURITY] [DSA 1843-2] New squid3 packages fix regression
- [SECURITY] [DSA 1858-1] New imagemagick packages fix several vulnerabilities
- [SECURITY] [DSA 1859-1] New libxml2 packages fix several issues
- [USN-814-1] openjdk-6 vulnerabilities
- [security bulletin] HPSBUX02450 SSRT090141 rev1 - HP-UX ttrace(2), Local Denial of Service (DoS)
- AST-2009-005: Remote Crash Vulnerability in SIP channel driver
- From: Asterisk Security Team
- IE7 Script
- TPTI-09-06: Microsoft Windows Workstation Service NetrGetJoinInformation Heap Corruption Vulnerability
- Sql injection in OCS Inventory NG Server 1.2.1
- [USN-815-1] libxml2 vulnerabilities
- ZDI-09-055: Microsoft Office OWC10 ActiveX Control Loading and Unloading Heap Corruption Vulnerability
- ZDI-09-057: Microsoft Remote Desktop Client Arbitrary Code Execution Vulnerability
- ZDI-09-053: Microsoft Windows WINS Service Heap Overflow Vulnerability
- ZDI-09-054: Microsoft Office OWC10.Spreadsheet ActiveX msDataSourceObject() Heap Corruption Vulnerability
- ZDI-09-056: Microsoft Office OWC10.Spreadsheet ActiveX BorderAround() Heap Corruption Vulnerability
- [security bulletin] HPSBTU02454 SSRT080172 rev.1 - HP Internet Express for Tru64 UNIX Running Samba, Remote Information Disclosure
- Re: Multiple vulnerabilities in several ATEN IP KVM Switches
- Chavoosh CMS SQL Injection Vulnerability
- [PT-2008-09] Microsoft Windows MSMQ Privilege Escalation Vulnerability
- 2WIRE Gateway Authentication Bypass & Password Reset
- Plume CMS Multiple SQL Injection Vulnerabilities - Security Advisory - SOS-09-006
- [security bulletin] HPSBUX02437 SSRT090038 rev.2 - HP-UX Running XNTP, Remote Execution of Arbitrary Code
- Hijacking Safari 4 Top Sites with Phish Bombs
- JibberBook GuestBook 2.3 Multiple Vulnerabilities
- [DSECRG-09-033] SAP Netweaver UDDI - XSS Security Vulnerability
- [ MDVSA-2009:200 ] libxml
- Microsoft Wordpad Memory Exhaustion (msftedit)
- [ MDVSA-2009:201 ] fetchmail
- [SECURITY] [DSA 1860-1] New Ruby packages fix several issues
- [USN-816-1] fetchmail vulnerability
- Elkapax CMS Cross site scripting vulnerability
- Authentication Bypass of Snom Phone Web Interface
- Windows 7 Firewire Attacks - and Defense Techniques
- From: Security Research Publications
- [security bulletin] HPSBMA02447 SSRT090062 rev.1 - Insight Control Suite For Linux (ICE-LX) Cross Site Request Forgery (CSRF) , Remote Execution of Arbitrary Code, Denial of Service (DoS), and Other Vulnerabilities
- Static analysis tool exposition (SATE) 2009 - call for participation
- Chris Paget Defcon RFID Presentation Slides Now Online
- From: Timothy (Thor) Mullen
- Fwd: Follow-up: Heartland CEO on Data Breach: QSAs Let Us Down
- Re: Re: Re: Back door trojan in acajoom-3.2.6 for joomla
- KIWICON ]|[ - 2009 Call For Papers
- Linux NULL pointer dereference due to incorrect proto_ops initializations
- [IMF 2009] Call for Participation
- [SECURITY] [DSA 1861-1] New libxml packages fix several issues
- Re: Linux NULL pointer dereference due to incorrect proto_ops initializations
- From: Przemyslaw Frasunek
- new vulnerability founded by ostoure
- ICQ 6.5 HTML-injection vulnerability
- ClubHack2009: Call for Papers/Speakers
- [ MDVSA-2009:202 ] memcached
- [SECURITY] [DSA 1862-1] New Linux 2.6.26 packages fix privilege escalation
- [SECURITY] [DSA 1863-1] New zope2.10/zope2.9 packages fix arbitrary code execution
- [ MDVSA-2009:203 ] curl
- DUgallery 3.0 / Remote Admin Bug
- [DSECRG-09-022] Adobe Coldfusion 8 Multiple Linked XSS Vulnerabilies
- [SECURITY] [DSA 1864-1] New Linux 2.6.24 packages fix privilege escalation
- Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit
- Piwigo SQL Injection Vulnerability - Security Advisory - SOS-09-007
- DeepSec 2009 - Preliminary Schedule is online
- [DSECRG-09-052] Adobe JRun 4 Directory Traversal Vulnerabilities
- [DSECRG-09-051] Adobe JRun 4 Multiple XSS
- [ MDVSA-2009:204 ] wxgtk
- [SECURITY] [DSA 1865-1] New Linux 2.6.18 packages fix several vulnerabilities
- TheGreenBow VPN Client tgbvpn.sys DoS and Potential Local
- [ MDVSA-2009:205 ] kernel
- Vtiger CRM 5.0.4 Multiple Vulnerabilities
- Safari buffer overflow
- Re: [DSECRG-09-022] Adobe Coldfusion 8 Multiple Linked XSS Vulnerabilies
- Re: Multiple vulnerabilities in several ATEN IP KVM Switches
- Re: common dns misconfiguration can lead to "same site" scripting
- [USN-818-1] curl vulnerability
- ntop <= 3.3.10 Basic Authentication Null Pointer Denial of Service
- Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- (Reposting truncated message) Re: ntop <= 3.3.10 Basic Authentication Null Pointer Denial of Service
- [security bulletin] HPSBMA02448 SSRT061231 rev.1 - HP Network Node Manager (NNM) Remote Console Running on Windows, Local Execution of Arbitrary Code, Denial of Service (DoS)
- [ GLSA 200908-07 ] Perl Compress::Raw modules: Denial of Service
- CA20090818-01: Security Notice for CA Host-Based Intrusion Prevention System
- [ GLSA 200908-05 ] Subversion: Remote execution of arbitrary code
- [ GLSA 200908-08 ] ISC DHCP: dhcpd Denial of Service
- [ GLSA 200908-10 ] Dillo: User-assisted execution of arbitrary code
- CA20090818-02: Security Notice for CA Internet Security Suite
- [ GLSA 200908-09 ] DokuWiki: Local file inclusion
- [ GLSA 200908-06 ] CDF: User-assisted execution of arbitrary code
- CORE-2009-0727: Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability
- From: CORE Security Technologies Advisories
- [SECURITY] [DSA 1868-1] New kde4libs packages fix several vulnerabilities
- rPSA-2009-0118-1 mod_dav_svn subversion
- From: rPath Update Announcements
- [SECURITY] [DSA 1867-1] New kdelibs packages fix several vulnerabilities
- rPSA-2009-0119-1 apr apr-util
- From: rPath Update Announcements
- [SECURITY] [DSA 1866-1] New kdegraphics packages fix several vulnerabilities
- rPSA-2009-0121-1 kernel open-vm-tools
- From: rPath Update Announcements
- ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vulnerability
- ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities
- [ MDVSA-2009:206 ] wget
- Re: Elkapax CMS Cross site scripting vulnerability
- From: security curmudgeon
- [USN-802-2] Apache regression
- Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Adobe Flex 3.3 SDK DOM-Based XSS
- iDefense Security Advisory 08.11.09: Microsoft Office Web Components 2000 Buffer Overflow Vulnerability
- [SECURITY] [DSA 1869-1] New curl packages fix SSL certificate verification weakness
- [ MDVSA-2009:207 ] perl-Compress-Raw-Bzip2
- [SECURITY] [DSA 1870-1] New pidgin packages fix arbitrary code execution
- [Bkis-11-2009] ProShow Gold Buffer Overflow Vulnerabilities
- [USN-809-1] GnuTLS vulnerabilities
- iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Information Disclosure Vulnerability
- [USN-820-1] Pidgin vulnerability
- Bypassing OWASP ESAPI XSS Protection inside Javascript
- iDefense Security Advisory 08.11.09: Multiple Vendor Microsoft ATL/MFC ActiveX Type Confusion Vulnerability
- iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Security Bypass Vulnerability
- RE: Bypassing OWASP ESAPI XSS Protection inside Javascript
- t2?09 Challenge - Free Tickets Available
- SQL Injection vulnerabilities in Subdreamer CMS
- [ MDVSA-2009:208 ] libgadu
- [USN-817-1] Thunderbird vulnerabilities
- [ MDVSA-2009:209 ] java-1.6.0-openjdk
- [ MDVSA-2009:210 ] gnutls
- VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server
- From: VMware Security team
- Clear Text Storage of Password in CS-MARS v6.0.4 and Earlier
- Infinity <= v2.X.X (Local File Disclosure/Auth Bypass) Vulnerabilities
- Re: Clear Text Storage of Password in CS-MARS v6.0.4 and Earlier
- Cuteflow Version 2.10.3 "edituser.php" Security Bypass Vulnerability
- DoS vulnerabilities in Mozilla Firefox, Internet Explorer and Chrome
- FreeBSD <= 6.1 kqueue() NULL pointer dereference
- From: Przemyslaw Frasunek
- Local Kernel Buffer Overflow vulnerability in Avast!
- [SECURITY] [DSA 1871-1] New wordpress packages fix several vulnerabilities
- [ MDVSA-2009:211 ] expat
- Radvision's Scopia Cross Site Scripting Vulnerabilities
- From: Francesco Bianchino
- [ MDVSA-2009:212 ] python
- CoolPreviews - Firefox Extension - Chrome Privileged Code Injection
- From: Roberto Suggi Liverani
- [ MDVSA-2009:212 ] python
- [ MDVSA-2009:213 ] wxgtk
- WM Downloader (.Smi/ .Ram/ .pls/ .smil/ .wax/ .wpl File) Local Buffer Overflow Exploit
- [ MDVSA-2009:213 ] wxgtk
- [ MDVSA-2009:214 ] python-celementtree
- [ MDVSA-2009:215 ] audacity
- [ MDVSA-2009:216 ] mozilla-thunderbird
- [ MDVSA-2009:217 ] mozilla-thunderbird
- Feed Sidebar Firefox Extension - Privileged Code Injection
- ScribeFire Firefox Extension - Privileged Code Injection
- WizzRSS Firefox Extension - Privileged Code Injection
- AiO ( All into One) Flash Mixer 3 (.afp File) Crash Vulnerability Exploit
- FLIP Flash Album Deluxe 1.8.407.1 (.fft File) Crash Vulnerability Exploit
- Update Scanner - Firefox Extension - Chrome Privileged Code Injection
- From: Roberto Suggi Liverani
- DoS vulnerability in Google Chrome
- Packet Storm is back online.
- Re: SQL Injection vulnerabilities in Subdreamer CMS
- [ MDVSA-2009:218 ] w3c-libwww
- [ MDVSA-2009:219 ] kompozer
- [SECURITY] [DSA 1872-1] New Linux 2.6.18 packages fix several vulnerabilities
- rPSA-2009-0122-1 idle python
- From: rPath Update Announcements
- [USN-822-1] KDE-Libs vulnerabilities
- [ MDVSA-2009:220 ] davfs
- rPSA-2009-0124-1 curl
- From: rPath Update Announcements
- [USN-823-1] KDE-Graphics vulnerabilities
- rPSA-2009-0123-1 apr-util
- From: rPath Update Announcements
- [USN-824-1] PHP vulnerability
- [USN-825-1] libvorbis vulnerability
- [ MDVSA-2009:221 ] libneon0.27
- Xerox WorkCentre multiple models Denial of Service
- From: Henri Lindberg - Smilehouse Oy
- CONFidence 2009, November, CfP
- RE: DoS vulnerability in Google Chrome
- EesySec Personal Firewall Remote Buffer Overflow Exploit
- Re: DoS vulnerability in Google Chrome
- Re: [IVIZ-08-009] Grub Legacy Security Model bypass exploiting wrong BIOS API usage
- [security bulletin] HPSBTU02453 SSRT091037 rev.2 - HP Tru64 UNIX or HP Tru64 Internet Express Running BIND Server, Denial of Service (DoS)
- HyperVM File Permissions Local Vulnerability
- [SECURITY] [DSA 1833-2] New dhcp3 packages fix arbitrary code execution
- iDefense Security Advisory 08.25.09: Autonomy KeyView Excel File SST Parsing Integer Overflow Vulnerability
- Oracle PL/SQL Injection Flaw in REPCAT_RPC.VALIDATE_REMOTE_RC
- Bypassing DBMS_ASSERT in certain situations
- Oracle 11g (11.1.0.6) Password Policy and Compliance
- H4RDW4RE presentations updated
- From: Thor (Hammer of God)
- Re: DoS vulnerability in Google Chrome
- [PT-2009-05] CA Internet Security Suite Denial of Service Vulnerability
- RE: H4RDW4RE presentations updated
- From: Thor (Hammer of God)
- Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- [MORNINGSTAR-2009-01] Multiple security issues in Open Auto Classifieds version <= 1.5.9
- [SECURITY] [DSA 1873-1] New xulrunner packages fix spoofing vulnerabilities
- [SECURITY] [DSA 1874-1] New nss packages fix several vulnerabilities
- [USN-826-1] Mono vulnerabilities
- [SECURITY] [DSA 1871-2] New wordpress packages fix regression
- Team SHATTER Security Advisory: Buffer Overflow in Resource Manager of Oracle Database - Plan name parameter
- Cross-Site Scripting vulnerability in Mozilla, Firefox, SeaMonkey, Orca Browser and Maxthon
- [ MDVSA-2009:222 ] squirrelmail
- [ MDVSA-2009:223 ] xerces-c
Mail converted by MHonArc