Mail Index
- [USN-934-1] Netpbm vulnerability
- Secunia Research: Internet Download Manager FTP Buffer Overflow Vulnerability
- SQL Injection in MS Access with backslash escaped input
- RE: STP mitm attack idea
- EUSecWest Amsterdam 2010 Call For Papers (short deadline May 5 - conf June 16/17)
- BPstyle - Graphic studio SQL Injection Vulnerabilities
- From: md . r00t . defacer
- [ MDVSA-2010:088 ] kernel
- A vulnerability in Kaspersky Antivirus
- Cross-Site Scripting vulnerability in Mango
- [SECURITY] [DSA 2040-1] New squidguard packages fix several vulnerabilities
- Puntal (index.php) Remote File Inclusion Vulnerabilities
- [ MDVSA-2010:089 ] gnutls
- RE: Puntal (index.php) Remote File Inclusion Vulnerabilities
- XSRF (CSRF) in Zikula Application Framework
- XSRF (CSRF) in eliteCMS
- Re: RE: Puntal (index.php) Remote File Inclusion Vulnerabilities
- XSS in Acuity CMS
- [SECURITY] [DSA-2041-1] New mediawiki packages fix cross-site request forgery
- [ MDVSA-2010:090 ] samba
- XSS in ecoCMS
- XSS in eliteCMS
- Re: Puntal (index.php) Remote File Inclusion Vulnerabilities
- From: Justin C. Klein Keane
- [CORE-2010-0428] Microsoft Office Visio DXF File Insertion Buffer Overflow
- From: Core Security Technologies Advisories Team
- REC0N 2010 (MONTREAL) CFP Reminder & Preview
- [ MDVSA-2010:091 ] openoffice.org
- Knowledgeroot (fckeditor) Remote Arbitrary File Upload Exploit
- [security bulletin] HPSBMA02400 SSRT080144 rev.4 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- SmartCMS v.2 SQL injection vulnerability
- Vulnerabilities in t3m_cumulus_tagcloud for TYPO3
- [security bulletin] HPSBMA02416 SSRT090008 rev.5 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [CORE-2010-0427] Windows SMTP Service DNS query Id vulnerabilities
- From: Core Security Technologies Advisories
- [security bulletin] HPSBMA02483 SSRT090257 rev.3 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- KHOBE - 8.0 earthquake for Windows desktop security software
- From: www.matousec.com - Research
- [USN-936-1] dvipng vulnerability
- [USN-937-1] TeX Live vulnerabilities
- PCRE compile workspace overflow
- Re: Knowledgeroot (fckeditor) Remote Arbitrary File Upload Exploit
- fetchmail security announcement fetchmail-SA-2010-02 (CVE-2010-1167)
- [SECURITY] [DSA 2042-1] New iscsitarget packages fix arbitrary code execution
- BaoFeng Storm M3U File Processing Buffer Overflow Vulnerability
- VMSA-2010-0008 VMware View 3.1.3 addresses an important cross-site scripting vulnerability
- From: VMware Security team
- [security bulletin] HPSBMA02201 SSRT071328 rev.1 - HP LoadRunner Agent on Windows, Remote Unauthenticated Arbitrary Code Execution
- [USN-919-1] Emacs vulnerability
- ZDI-10-080: HP Mercury LoadRunner Agent Trusted Input Remote Code Execution Vulnerability
- New web malwares attacking big hosting providers
- Vulnerability with Cisco ACE. A2 3.0 (probably all version)
- [ MDVSA-2010:092 ] cacti
- REZERVI (root) Remote Command Execution Vulnerability
- Re: KHOBE - 8.0 earthquake for Windows desktop security software
- Re: New web malwares attacking big hosting providers
- Injection of ECShop apps.
- XSS vulnerability in Jaws
- [Wintercore Research] Consona Products - Multiple vulnerabilities
- pmwiki: persistent cross site scripting (XSS), CVE-2010-1481
- CMS Made Simple: backend cross site scripting (XSS), CVE-2010-1482
- rPSA-2010-0034-1 ntp ntp-utils
- From: rPath Update Announcements
- rPSA-2010-0036-1 openssl openssl-scripts
- From: rPath Update Announcements
- rPSA-2010-0037-1 kernel
- From: rPath Update Announcements
- [ MDVSA-2010:093 ] mysql
- Vulnerabilities in Sebo - webstore
- XSS vulnerability in EasyPublish CMS
- XSS vulnerability in Advanced Poll
- SA00001-2010
- Family Connections 2.2.3 Multiple Remote Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- Turnkey Innovations SQL Injection Vulnerability
- From: md . r00t . defacer
- Month of PHP Security - Summary - 1st May - 10th May
- 29o3 CMS (LibDir) Multiple Remote File Inclusion Vulnerability
- XSS in Saurus CMS
- Re: [Full-disclosure] Month of PHP Security - Summary - 1st May - 10th May
- [SECURITY] [DSA 2044-1] New mplayer packages fix arbitrary code execution
- Re: Vulnerabilities in Sebo - webstore
- Re: Vulnerabilities in Sebo - webstore
- From: Salvatore Fresta aka Drosophila
- [ MDVSA-2010:090-1 ] samba
- [security bulletin] HPSBMA02528 SSRT100106 rev.1 - HP Performance Center Agent on Windows, Remote Unauthenticated Arbitrary Code Execution
- {PRL} Microsoft Windows Outlook Express and Windows Mail Integer Overflow
- XSS in DynamiXgate Affiliate Store Builder
- Re: Vulnerabilities in Sebo - webstore
- From: Salvatore Fresta aka Drosophila
- [SECURITY] [DSA 2043-1] New vlc packages fix arbitrary code execution
- [security bulletin] HPSBMA02527 SSRT010098 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [SECURITY] [DSA 2045-1] New libtheora packages fix arbitrary code execution
- [CORE-2010-0405] Adobe Director Invalid Read
- From: Core Security Technologies Advisories Team
- Vulnerability in widget Cumulus for BlogEngine.NET
- Multiple memory corruption vulnerabilities in Ghostscript
- ZDI-10-081: HP OpenView NNM ovet_demandpoll sel CGI Variable Format String Remote Code Execution Vulnerability
- CFP for ekoparty 0x10 is now open! [ Buenos Aires, Argentina ]
- From: ekoparty Security Conference
- ZDI-10-089: Adobe Shockwave Director PAMI Chunk Remote Code Execution Vulnerability
- ZDI-10-082: HP OpenView NNM netmon sel CGI Variable Remote Code Execution Vulnerability
- ZDI-10-083: HP OpenView NNM snmpviewer.exe CGI Multiple Variable Remote Code Execution Vulnerability
- ZDI-10-084: HP OpenView NNM getnnmdata.exe CGI Invalid MaxAge Remote Code Execution Vulnerability
- ZDI-10-085: HP OpenView NNM getnnmdata.exe CGI Invalid ICount Remote Code Execution Vulnerability
- ZDI-10-086: HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution Vulnerability
- ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Execution Vulnerability
- ZDI-10-088: Adobe Shockwave Player 3D Parsing Memory Corruption Vulnerability
- Palo Alto Network Vulnerability - Cross-Site Scripting (XSS)
- [CAL-20100204-1]Adobe Shockwave Player Director File Parsing ATOM size infinite loop vulnerability
- [CAL-20100204-2]Adobe Shockwave Player Director File Parsing integer overflow vulnerability
- [CAL-20100204-3]Adobe Shockwave Player Director File Parsing RCSL Pointer Overwrite
- iDefense Security Advisory 05.11.10: Abobe Shockwave Player Heap Memory Indexing Vulnerability
- Secunia Research: Adobe Shockwave Player 3D Parsing Memory Corruption
- Secunia Research: Adobe Shockwave Player Signedness Error Vulnerability
- PolyPager 1.0rc10 (fckeditor) File Upload Security Issue
- Secunia Research: Adobe Shockwave Player Array Indexing Vulnerability
- [ MDVSA-2010:094 ] tetex
- Secunia Research: Adobe Shockwave Player Integer Overflow Vulnerability
- Secunia Research: Adobe Shockwave Player Asset Entry Parsing Vulnerability
- Secunia Research: Adobe Shockwave Player Font Processing Buffer Overflow
- VUPEN Security Research - Adobe Shockwave IML32 Multiple Code Execution Vulnerabilities (CVE-2010-0129)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Shockwave 3D Two Remote Code Execution Vulnerabilities (CVE-2010-1284)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Shockwave DIRAPI Multiple Code Execution Vulnerabilities (CVE-2010-1280)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Shockwave 3D Blocks Field Code Execution Vulnerability (CVE-2010-1283)
- From: VUPEN Security Research
- [security bulletin] HPSBMA02522 SSRT100086 rev.1 - HP Insight Control Server Migration for Windows, Remote Cross Site Scripting (XSS)
- [security bulletin] HPSBMA02520 SSRT100071 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Unauthorized Access to Data
- Secunia Research: TomatoCMS Script Insertion Vulnerabilities
- Secunia Research: TomatoCMS "q" SQL Injection Vulnerability
- Secunia Research: IrfanView PSD Image Parsing Sign-Extension Vulnerability
- Secunia Research: IrfanView PSD RLE Decompression Buffer Overflow
- Cisco Security Advisory: Multiple vulnerabilities in Cisco PGW Softswitch
- From: Cisco Systems Product Security Incident Response Team
- Secunia Research: KDE KGet metalink "name" Directory Traversal Vulnerability
- [security bulletin] HPSBPI02532 SSRT100111 rev.1 - HP MFP Digital Sending Software Running on Windows, Local Unauthorized Access
- Secunia Research: Free Download Manager metalink "name" Directory Traversal
- [USN-938-1] KDENetwork vulnerability
- Secunia Research: Free Download Manager Four Buffer Overflow Vulnerabilities
- Secunia Research: KDE KGet Insecure File Operation Vulnerability
- Secunia Research: aria2 metalink "name" Directory Traversal Vulnerability
- [ MDVSA-2010:095 ] libxext
- XSS vulnerability in NPDS
- Blind SQL injection vulnerability in NPDS REvolution
- Joomla Component advertising (com_aardvertiser) File Inclusion Vulnerability
- LinksAutomation Multiple Remote Vulnerabilities
- From: md . r00t . defacer
- [SECURITY] [DSA-2046-1] New phpgroupware packages fix several vulnerabilities
- Vulnerability in tagcloud for Kasseler CMS
- CfP: GameSec 2010 - Deadline extended to 31 May 2010
- Re: [CORE-2010-0405] Adobe Director Invalid Read
- From: Core Security Technologies Advisories
- Re: Secunia Research: KDE KGet Insecure File Operation Vulnerability
- From: Vladimir '3APA3A' Dubrovin
- phpGroupWare SQL Injections and Local File Inclusion Vulnerabilities (CVE-2010-0403 and CVE-2010-0404)
- Mathematica on Linux /tmp/MathLink vulnerability
- phpvidz Administrative Password Disclosure
- Vulnerability in 3D user cloud for Joomla
- XSS, SQL injection vulnerability in I-Vision CMS
- Joomla component SimpleDownload Local File Inclusion
- From: jerzy . patraszewski
- [oCERT-2010-001] multiple http client unexpected download filename vulnerability
- CVE-2010-1454: SpringSource tc Server unauthenticated remote access to JMX interface
- [ MDVSA-2010:096 ] tetex
- [SECURITY] [DSA 2047-1] New aria2 packages fix directory traversal
- DEF CON 18 CFP closing in two weeks
- Call for Papers: EC2ND 2010
- [security bulletin] HPSBMA02534 SSRT090180 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Unauthorized Information Disclosure, Unauthorized Data Modification, Denial of Service (DoS)
- Re: Vulnerability in 3D user cloud for Joomla
- [security bulletin] HPSBGN02511 SSRT100022 rev.3 - Certain HP Small Form Factor, Microtower and Workstations PC's with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code
- [SECURITY] [DSA 2038-2] New pidgin packages fix regression
- XSS vulnerability in JComments, Joomla
- [ MDVSA-2010:097 ] pidgin
- XSS vulnerability in NPDS REvolution
- DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- Security Awareness for kids
- [security bulletin] HPSBOV02497 SSRT090245 rev.3 - HP TCP/IP Services for OpenVMS Running NTP, Remote Execution of Arbitrary Code, Denial of Service (DoS)
- Stored XSS vulnerability in NPDS REvolution
- Re: XSS vulnerability in NPDS
- [security bulletin] HPSBMA02535 SSRT100029 rev.1 - HP Performance Manager, Remote Unauthorized Access, Cross Site Scripting (XSS), Denial of Service (DoS)
- MITKRB5-SA-2010-005 [CVE-2010-1321] GSS-API lib null pointer deref
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- [ MDVSA-2010:099 ] wireshark
- [Suspected Spam][USN-939-1] X.org vulnerabilities
- [ MDVSA-2010:098 ] kdenetwork4
- [security bulletin] HPSBUX02523 SSRT100036 rev.1 - HP-UX Running ONCPlus, Remote Denial of Service (DoS), Increase in Privilege
- Metasploit Framework 3.4.0 Released
- Caucho Technology Resin digest.php Cross Site Scripting Vulnerability
- The New ISO Hacking Standard
- [ MDVSA-2010:100 ] krb5
- Secunia Research: Orbit Downloader metalink "name" Directory Traversal
- [ MDVSA-2010:101 ] mysql
- Linux Mint 8 mintUpdate Insecure Temporary File Creation
- [ MDVSA-2010:102 ] ghostscript
- [Suspected Spam][USN-940-1] Kerberos vulnerabilities
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- [Kil13r-SA-20100513] Adobe Flash Player 10.0 Denial Of Service Vulnerability
- Smart Douran CMS Remote File Download
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- [HITB-Announce] HITBSecConf2010 - Malaysia Call for Papers
- [USN-941-1] MoinMoin vulnerability
- RE: STP mitm attack idea
- From: Guillermo Marro Bruno
- XSS bug in US Robotics firmware USR5463-v0_06.bin
- [ MDVSA-2010:082-1 ] clamav
- Re: The New ISO Hacking Standard
- Multiple vulnerabilities within 3Com* iMC (Intelligent Management Center)
- XSS vulnerability in LiSK CMS
- Vulnerability in widget Flash Tag Cloud for Blogsa and other ASP.NET engines
- XSRF (CSRF) in ocPortal
- [ MDVSA-2010:104 ] dovecot
- Cacti Multiple Parameter Cross Site Scripting Vulnerabilities
- Re: The New ISO Hacking Standard
- PHP-Calendar "description" and "lastaction" Cross Site Scripting Vulnerabilities
- [USN-942-1] PostgreSQL vulnerabilities
- Mastering Trust in Security Assessments
- XSS vulnerability in LiSK CMS
- [ MDVSA-2010:103 ] postgresql
- Month of PHP Security - Summary - 11st May - 21th
- Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability
- OSSTMM 3 based Home Security Vacation Guide v.2!
- PR10-03: Authenticated Cross-Site Scripting (XSS) within the Apache Axis2 administration console
- HP-UX, IBM AIX, SGI IRIX Remote Vulnerability - CVE-2010-1039
- XSS vulnerability in gpEasy CMS
- SQL injection vulnerability in LiSK CMS
- SQL injection vulnerability in LiSK CMS
- XSRF (CSRF) in NPDS REvolution
- Re: Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability
- [Bkis-01-2010] Multiple Vulnerabilities in BigAce - Bkis
- [SECURITY] [DSA 2049-1] New barnowl packages fix arbitrary code execution
- [SECURITY] [DSA 2048-1] New dvipng packages fix arbitrary code execution
- [ MDVSA-2010:105 ] openoffice.org
- Re: IBM Lotus 6.x names.nsf Cross Site Scripting Vulnerability
- From: security curmudgeon
- [SECURITY] [DSA 2050-1] New kdegraphics packages fix several vulnerabilities
- CompleteFTP Server v 4.x "PORT" command Remote DOS exploit
- Denial of Dervice vulnerability in Helix Mobile Server (RealNetworks) (14.0.0.348) with long string to PluginDirectory in rmserver.cfg file
- [SECURITY] [DSA 2051-1] New postgresql-8.3 packages fix several vulnerabilities
- [ MDVSA-2010:106 ] aria2
- Secunia Research: Ziproxy Two Integer Overflow Vulnerabilities
- [SECURITY] [DSA 2052-1] New krb5 packages fix denial of service
- [SECURITY] [DSA 2052-1] New krb5 packages fix denial of service
- Scientific Atlanta DPC2100 WebSTAR Cable Modem vulnerabilities
- [SECURITY] [DSA 2053-1] New Linux 2.6.26 packages fix several issues
- Webby Webserver v1.01 - Buffer overflow vulnerability with overwritten structured exception handler (SEH)
- Sun Solaris 10 libc/*convert (*cvt) buffer overflow
- Ghostscript 8.64 executes random code at startup
- Sun Solaris 10 filesystem rm(1),find(1),etc, Denial-of-service
- Sun Solaris 10 ftpd Cross-site request forgery
- Hustoj is HUST ACM OnlineJudge "fckeditor" file upload security issue
- Vulnerabilities in DS-Syndicate for Joomla
- [Bkis-01-2010] Multiple Vulnerabilities in BigAce - Bkis
- Kingsoft WebShield KAVSafe.sys <= 2010.4.14.609(2010.5.23) Kernel Mode Local Privilege Escalation Vulnerability
- JV2 Folder Gallery 3.1.1 (popup_slideshow.php) Multiple Vulnerability
- New vulnerabilities in plugin DS-Syndicate for Joomla
- rPSA-2010-0039-1 openssl openssl-scripts
- From: rPath Update Announcements
- Re: Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability
- London DEFCON May meet - DC4420 - Wed 26th May 2010
- Kingsoft WebShield KAVSafe.sys <= 2010.4.14.609(2010.5.23) Kernel Mode Local Privilege Escalation Vulnerability
- OSSTMM 3 STAR Released!
- Arbitrary UNC file read in IE 8
- SQL injection vulnerability in Zabbix <= 1.8.1
- XSS vulnerability in razorCMS
- XSS vulnerability in GetSimple CMS
- XSS vulnerability in RuubikCMS
- SQL injection vulnerability in 360 Web Manager
- XSS vulnerability in 360 Web Manager
- SQL injection vulnerability in 360 Web Manager
- Flock web browser v2.5.6 (Remote Memory Corrupt) Crash Exploit
- [ MDVSA-2010:107 ] mysql
- [Suspected Spam][USN-944-1] GNU C Library vulnerabilities
- Re: Ghostscript 8.64 executes random code at startup
- Re: Sun Solaris 10 filesystem rm(1),find(1),etc, Denial-of-service
- CfP: GameSec 2010 - 5 days left to the deadline
- Re: Ghostscript 8.64 executes random code at startup
- From: Krzysztof Żelechowski
- Cyberoam SSL VPN Client - Plain-text Storage of Username and Password
- Re: Ghostscript 8.64 executes random code at startup
- [ MDVSA-2010:108 ] kolab-horde-framework
- ESA-2010-007: EMC Avamar Denial Of Service Vulnerability
- [security bulletin] HPSBGN02315 SSRT071487 rev.1 - HP TestDirector for Quality Center running on AIX, Linux and Solaris, Remote Unauthorized Access
- [ MDVSA-2010:108 ] kolab-horde-framework
- [security bulletin] HPSBMA02442 SSRT090108 rev.1 - HP Business Availability Center Running Apache, Remote Cross Site Scripting (XSS), Cross Site Request Forgery (CSRF), Denial of Service (DoS)
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Network Building Mediator
- From: Cisco Systems Product Security Incident Response Team
- [ MDVSA-2010:108 ] kolab-horde-framework
- Static analysis tool exposition (SATE) 2010 Call for participation
- Re: SQL injection vulnerability in 360 Web Manager
- Re: Ghostscript 8.64 executes random code at startup
- FreeBSD Security Advisory FreeBSD-SA-10:04.jail
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-10:05.opie
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-10:06.nfsclient
- From: FreeBSD Security Advisories
- Cross Site URL Hijacking by using Error Object in Mozilla Firefox
- EUSecWest 2010 MiniCFP (conf Jun 16/17) and PacSec 2010 CFP (conf Nov 10/11, deadline July 30)
- [ MDVSA-2010:110 ] clamav
- [ MDVSA-2010:109 ] gtk+2.0
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- clearsite Remote File Include Vulnerability
- [USN-945-1] ClamAV vulnerabilities
- VMSA-2010-0009 ESXi ntp and ESX Service Console third party updates
- From: VMware Security team
- [Suspected Spam]DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- SQL injection in OSCommerce Add-On Visitor Web Stats
- From: Christopher Schramm
- Re: Ghostscript 8.64 executes random code at startup
- Administrivia: Real domain names in PoC/exploit examples
- CVE-2010-2020: FreeBSD kernel NFS client local vulnerabilities
- From: Patroklos Argyroudis
- Re: Administrivia: Real domain names in PoC/exploit examples
- Re: Administrivia: Real domain names in PoC/exploit examples
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- Re[2]: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- From: Vladimir '3APA3A' Dubrovin
- Re: [Suspected Spam]DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- SQL injection vulnerability in ImpressPages CMS
- SQL injection vulnerability in ImpressPages CMS
- Re: Re[2]: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- Groone's Simple Contact Form (abspath) Remote File Inclusion Vulnerability
- SQL injection vulnerability in ImpressPages CMS
- Re[4]: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- From: Vladimir '3APA3A' Dubrovin
- Nginx 0.8.35 Space Character Remote Source Disclosure
- [security bulletin] HPSBUX02523 SSRT100036 rev.2 - HP-UX Running ONCplus rpc.pcnfsd, Remote Denial of Service (DoS), Increase in Privilege
- [Suspected Spam]Vulnerability in ArtDesign CMS
- DM Database Server Memory Corruption Vulnerability
- IS-2010-001 - Netgear WG602v4 Saved Pass Stack Overflow
- GR Board v1.8.6.1 stab (page.php?theme) Remote File Inclusion Vulnerability
- Re: Ghostscript 8.64 executes random code at startup
Mail converted by MHonArc