Mail Index
- [USN-930-1] Firefox and Xulrunner vulnerabilities
- [USN-930-2] apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
- [0day] Microsoft mshtml.dll CTimeoutEventList::InsertIntoTimeoutList memory leak
- Secunia Research: Adobe Reader JPEG Uninitialised Memory Vulnerability
- Secunia Research: Adobe Reader GIF Image Parsing Array-Indexing Vulnerability
- Secunia Research: Joomla BookLibrary Component Four SQL Injection Vulnerabilities
- VUPEN Security Research - Adobe Acrobat and Reader #1023 Tag Buffer Overflow Vulnerability (CVE-2010-2212)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader "newfunction" Memory Corruption Vulnerability (CVE-2010-2168)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader "pushstring" Memory Corruption Vulnerability (CVE-2010-2201)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader "newclass" Memory Corruption Vulnerability (CVE-2010-1285)
- From: VUPEN Security Research
- ZDI-10-116: Adobe Reader CLOD Progressive Mesh Continuation Resolution Remote Code Execution Vulnerability
- [USN-930-3] Firefox regression
- DDIVRT-2010-29 ALPHA Ethernet Adapter II Web-Manager 3.40.2 Authentication Bypass
- [USN-956-1] sudo vulnerability
- [SECURITY] [DSA 2066-1] New wireshark packages fix several vulnerabilities
- [Bkis-03-2010] Vulnerability in Flash Slideshow Maker Vulnerability
- Re: SAP's web module OLK SQL Injection vulnerability
- Vulnerabilities in WP-UserOnline for WordPress
- Re: [Full-disclosure] Remote Command Execution in dotDefender Site Management
- REVISION: iScripts EasySnaps 2.0 Multiple SQL Injection Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- iScripts ReserveLogic 1.0 SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- iScripts CyberMatch 1.0 Blind SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- Re: Cherokee Web Server 0.5.3 Multiple Vulnerabilities
- From: security curmudgeon
- VSR Advisory: Multiple Cisco CSS / ACE Client Certificate and HTTP Header Manipulation Vulnerabilities
- IIS5.1 Directory Authentication Bypass by using “:$I30:$Index_Allocation”
- Zoph Multiple Parameter Cross Site Scripting Vulnerabilities
- [SECURITY] [DSA-2067-1] New mahara packages fix several vulnerabilities
- IrcDelphi DCA-00010 Vulnerability Report
- From: Ewerson Guimarães (Crash) - Dclabs
- iScripts SocialWare 2.2.x Multiple Remote Vulnerability
- From: Salvatore Fresta aka Drosophila
- iScripts MultiCart 2.2 Multiple SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- [ MDVSA-2010:127 ] imlib2
- Canteen Joomla Component 1.0 Multiple Remote Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- Security Advisories from TEHTRI-Security at HITB Europe
- From: Laurent OUDOT at TEHTRI-Security
- TELUS Security Labs VR - iSCSI target Multiple Implementations iSNS Stack Buffer Overflow
- [Suspected Spam]File Download and DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- Hiding Backdoors in plain sight
- From: Mailing lists at Core Security Technologies
- Secunia Research: Joomla BookLibrary From Same Author Module "id" SQL Injection
- Editran editcp V4.1 R7 - Remote buffer overflow
- [HITB-Announce] HITB Magazine Issue 003 + HITBSecConf2010 - Amsterdam
- Re: SQL injection vulnerability in WebDB
- From: security curmudgeon
- NTSOFT BBS E-Market Professional = XSS / Remote Execution Code
- VLC Player M3U file ftp:// URI Handler Remote Stack Buffer Overflow
- Re: SQL injection vulnerability in TomatoCMS
- From: security curmudgeon
- Re: XSS vulnerability in PortalApp
- From: security curmudgeon
- Re: Two independent vulnerabilities (client and server side) in Quake3 engine and many derived games
- Xlight FTPd Multiple Directory Traversal in SFTP
- [USN-943-1] Thunderbird vulnerabilities
- pam_captcha username harvest vulnerability
- DeepSec 2010 - Call for Papers - REMINDER
- Re: Re: Two independent vulnerabilities (client and server side) in Quake3 engine and many derived games
- DCP-Portal Multiple XSS Vulnerabilities
- Cisco Security Advisory: Hard-Coded SNMP Community Names in Cisco Industrial Ethernet 3000 Series Switches Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [ MDVSA-2010:130 ] heimdal
- MODx Installation File XSS Vulnerability
- ArtForms 2.1b7.2 RC2 Joomla Component Multiple Remote Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- PBS Pro race condition vulnerability
- From: Bartłomiej Balcerek
- RunCMS XSS Vulnerability via User Agent
- Sandbox 2.0.3 Multiple Remote Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- [ MDVSA-2010:129 ] heimdal
- [ MDVSA-2010:128 ] lftp
- Exponent Slideshow XSS Vulnerability
- Pligg Installation File XSS Vulnerability
- [USN-960-1] libpng vulnerabilities
- XSS vulnerability in CruxPA
- XSS vulnerability in CruxPA
- XSS vulnerability in CruxPA
- [USN-959-1] PAM vulnerability
- XSS vulnerability in CruxPA
- XSS vulnerability in CruxCMS
- XSS vulnerability in CruxCMS
- Re: RunCMS XSS Vulnerability via User Agent
- Re: MODx Installation File XSS Vulnerability
- [scip_Advisory 4143] Shemes Grabbit Malicious NZB Date Denial of Service
- Re: MODx Installation File XSS Vulnerability
- Pligg Installation File XSS Vulnerability
- Vulnerabilities in SimpNews
- [SECURITY] CVE-2010-2227: Apache Tomcat Remote Denial Of Service and Information Disclosure Vulnerability
- [SECURITY] [DSA-2069-1] New znc packages fix denial of service
- XSS holes dotDefender
- Re: IIS5.1 Directory Authentication Bypass by using ?:$I30:$Index_Allocation?
- [SECURITY] [DSA-2068-1] New python-cjson packages fix denial of service
- Opera Crash by <canvas> Element
- IE6 css set Denial of Service Vulnerability
- Metasploit Framework 3.4.1 Released
- [ MDVSA-2010:131 ] iscsitarget
- Re: Re: IIS5.1 Directory Authentication Bypass by using ?:$I30:$Index_Allocation?
- FreeBSD Security Advisory FreeBSD-SA-10:07.mbuf
- From: FreeBSD Security Advisories
- VMSA-2010-0011 VMware Studio 2.1 addresses security vulnerabilities in virtual appliances created with Studio 2.0.
- From: VMware Security Team
- [security bulletin] HPSBMA02547 SSRT100179 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Execution of Arbitrary Code and Other Vulnerabilities
- [security bulletin] HPSBMA02548 SSRT100126 rev.1 - HP Insight Orchestration for Windows, Remote Unauthorized Access
- [security bulletin] HPSBMA02549 SSRT090158 rev.1 - HP Insight Control Power Management for Windows, Local Unauthorized Access to Data, Denial of Service (DoS)
- [security bulletin] HPSBUX02450 SSRT090141 rev1 - HP-UX ttrace(2), Local Denial of Service (DoS)
- [security bulletin] HPSBUX02451 SSRT090137 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS)
- [security bulletin] HPSBTU02453 SSRT091037 rev.1 - HP Tru64 UNIX BIND Server, Denial of Service (DoS)
- [security bulletin] HPSBMA02550 SSRT100170 rev.1 - HP Insight Software Installer for Windows, Local Unauthorized Access to Data, Remote Cross Site Request Forgery (CSRF)
- [security bulletin] HPSBMA02551 SSRT100165 rev.1 - HP Virtual Connect Enterprise Manager for Windows, Remote Cross Site Scripting (XSS)
- [security bulletin] HPSBMA02553 SSRT100184 rev.1 - HP Insight Control Server Migration for Windows, Local and Remote Unauthorized Access to Data, Remote Cross Site Request Forgery (CSRF), Cross Site Scripting (XSS)
- VUPEN Security Research - Winamp Player FLV Data Processing Multiple Overflow Vulnerabilities
- From: VUPEN Security Research
- [security bulletin] HPSBMA02555 SSRT100064 rev.1 - HP Client Automation Enterprise Infrastructure (Radia) Remote Disclosure of Information
- ZDI-10-117: Microsoft Office Access AccWizObjects ActiveX Control Uninitialized Imports Remote Code Execution Vulnerability
- [USN-961-1] Ghostscript vulnerabilities
- Re: hashdays 2010 - Call for Papers (#days CFP)
- SQL injection vulnerability in CMSQLite
- SQL injection vulnerability in CMSQLite
- [security bulletin] HPSBOV02539 SSRT090267 rev.1 - HP OpenVMS Auditing, Local Information Disclosure, Elevation of Privilege, Denial of Service (DoS)
- XSS vulnerability in Diem
- XSS vulnerability in CMSQLite
- XSS vulnerability in Diem
- SQL injection vulnerability in CMSQLite
- XSS vulnerability in Diem
- TPTI-10-04: Oracle Secure Backup Scheduler Service Remote Code Execution Vulnerability
- ZDI-10-118: Oracle Secure Backup Administration uname Authentication Bypass Vulnerability
- Secunia Research: GIGABYTE Dldrv2 ActiveX Control Array Indexing Vulnerability
- [Suspected Spam]Cross-Site Scripting vulnerabilities in SimpGB
- ZDI-10-119: Oracle Secure Backup Administration $other Variable Command Injection Remote Code Execution Vulnerability
- [security bulletin] HPSBMA02439 SSRT080082 rev.3 - HP OpenView SNMP Emanate Master Agent Running on HP-UX, Linux, Solaris, and Windows, Remote Unauthorized Access
- Pwnie Awards 2010
- ZDI-10-120: Oracle Secure Backup Administration objectname Command Injection Remote Code Execution Vulnerability
- PR09-16: Juniper Secure Access series (Juniper IVE) Cross-Site Scripting Vulnerability
- ZDI-10-121: Command Injection Remote Code Execution Vulnerability
- ZDI-10-122: Oracle Secure Backup Administration Command Injection Remote Code Execution Vulnerability
- SAPGui BI wadmxhtml.dll Tags Property Heap Corruption
- ZDI-10-123: Oracle Secure Backup Administration Authentication Bypass Vulnerability
- ZDI-10-124: Oracle Secure Backup Web Interface Various Post-Auth Command Injection Remote Code Execution Vulnerabilities
- CVE-2010-2375: WebLogic Plugin HTTP Injection via Encoded URLs
- cPanel XSS Vulnerability
- [ MDVSA-2010:132 ] python
- ZDI-10-125: IBM SolidDB solid.exe Handshake Request Username Field Remote Code Execution Vulnerability
- Re: pam_captcha username harvest vulnerability
- Opera Browser Address Bar Spoofing Vulnerability
- [USN-962-1] VTE vulnerability
- [security bulletin] HPSBMA02554 SSRT100018 rev.2 - HP Insight Control for Linux, Remote Execution of Arbitrary Code, Remote Denial of Service (DoS), Remote Unauthorized Access
- XSS vulnerability in DSite CMS
- Outlook PR_ATTACH_METHOD file execution vulnerability
- From: Akita Software Security
- XSS vulnerability in Gekko Web Builder
- XSS vulnerability in Pligg search module
- [SECURITY] [DSA 2070-1] New freetype packages fix several vulnerabilities
- XSS vulnerability in Taggon CMS
- XSS vulnerability in WebPress
- Secunia Research: GIGABYTE Dldrv2 ActiveX Control Unsafe Methods
- Re: pam_captcha username harvest vulnerability
- XSS vulnerability in WebPress
- [SECURITY] [DSA 2071-1] New libmikmod packages fix several vulnerabilities
- XSS vulnerability in phpwcms
- Stored XSS vulnerability in Pixie
- [security bulletin] HPSBUX02556 SSRT100014 rev.1 - HP-UX Running rpc.ttdbserver, Remote Execution of Arbitrary Code
- XSS vulnerability in Pixie
- [security bulletin] HPSBMA02550 SSRT100170 rev.2 - HP Insight Software Installer for Windows, Local Unauthorized Access to Data, Remote Cross Site Request Forgery (CSRF)
- XSS vulnerability in FestOS
- XSRF (CSRF) in Pixie
- XSS vulnerability in FestOS
- XSRF (CSRF) in Pixie
- {PRL} Novell Groupwise Webaccess Stack Overflow
- XSS vulnerability in WebPress
- XSRF (CSRF) in phpwcms
- XSS vulnerability in WebPress
- ClubHack2010 CFP
- OWASP Appsec Germany Call for Papers
- IS-2010-006 - D-Link DAP-1160 formFilter buffer overflow
- [ MDVSA-2010:133 ] libpng
- Kiwicon IV: Our Worst CFP Yet
- [ MDVSA-2010:134 ] ghostscript
- [ MDVSA-2010:136 ] ghostscript
- [ MDVSA-2010:135 ] ghostscript
- [MajorSecurity SA-076]Conpresso CMS - Cross site Scripting vulnerabilities
- ZDI-10-126: Ipswitch Imail Server List Mailer Reply-To Address Remote Code Execution Vulnerability
- ZDI-10-127: Ipswitch Imail Server Mailing List Remote Code Execution Vulnerability
- Re: ZDI-10-121: Command Injection Remote Code Execution Vulnerability
- ZDI-10-128: Ipswitch Imail Server Queuemgr Format String Remote Code Execution Vulnerability
- ZDI-10-129: Novell Netware Groupwise Internet Gateway Remote Code Execution Vulnerability
- A new zombie port scanning attack
- {PRL} Novell Groupwise Internet Agent Stack Overflow
- RedShop 1.0.23.1 Joomla Component Blind SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- [ MDVSA-2010:137 ] freetype2
- [SECURITY] [DSA 2072-1] New libpng packages fix several vulnerabilities
- YACK CMS 10.5.27 Remote File Inclusion Vulnerability
- Microsoft ClickOnce MITM Vulnerabilities
- SeaMonkey 2.0.5 Address Bar Spoofing Vulnerability
- VMSA-2010-0012 VMware vCenter Update Manager fix for Jetty Web server addresses important security vulnerabilities
- From: VMware Security Team
- PoC for CVE-2010-1869 (ghostscript) and CVE-2010-1039 (rpc.pcnfsd)
- CVE-2010-2382: Solaris flar unsafe use of temporary files
- CVE-2010-2382: Solaris nfslogd unsafe use of temporary files
- CVE-2010-2384: Solaris wbem unsafe use of temporary files
- [USN-963-1] FreeType vulnerabilities
- [security bulletin] HPSBMA02425 SSRT080091 rev.3 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [security bulletin] HPSBMA02558 SSRT010158 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [Onapsis Security Advisory 2010-006] SAP J2EE Web Services Navigator Cross-Site Scripting
- From: Onapsis Research Labs
- ZDI-10-130: Mozilla Firefox NodeIterator Remote Code Execution Vulnerability
- ZDI-10-131: Mozilla Firefox nsTreeSelection Dangling Pointer Remote Code Execution Vulnerability
- ZDI-10-132: Mozilla Firefox Plugin Parameter EnsureCachedAttrParamArrays Remote Code Execution Vulnerability
- ZDI-10-133: Mozilla Firefox CSS font-face Remote Code Execution Vulnerability
- ZDI-10-134: Mozilla Firefox DOM Attribute Cloning Remote Code Execution Vulnerability
- ZDI-10-135: Novell Groupwise WebAccess Multiple Cross-Site Scripting Vulnerabilities
- [SECURITY] [DSA 2074-1] New ncompress packages fix execution of arbitrary code
- [USN-940-2] Kerberos vulnerability
- ESA-2010-011: RSA, The Security Division of EMC, announces a fix for potential security vulnerability in RSAR Federated Identity Manager
- [oCERT-2010-002] Joomla input sanitization errors (XSS)
- [SECURITY] [DSA 2073-1] New mlmmj packages fix directory traversal
- [security bulletin] HPSBMA02557 SSRT100025 rev.1- HP OpenView Network Node Manager (OV NNM) Running on Windows, Remote Execution of Arbitrary Code
- Cisco Security Advisory: CDS Internet Streamer: Web Server Directory Traversal Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Mozilla Firefox 3.5.x Address Bar Spoofing Vulnerability
- [Suspected Spam]SQL Injection vulnerability in coWiki
- VUPEN Security Research - HP OpenView Network Node Manager "nnmrptconfig.exe" Buffer Overflow (CVE-2010-2703)
- From: VUPEN Security Research
- VUPEN Security Research - HP OpenView Network Node Manager "ov.dll" Buffer Overflow Vulnerability (CVE-2010-2704)
- From: VUPEN Security Research
- [security bulletin] HPSBMA02558 SSRT100158 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [security bulletin] HPSBMA02551 SSRT100065 rev.2 - HP Virtual Connect Enterprise Manager for Windows, Remote Cross Site Scripting (XSS)
- ZDI-10-137: Hewlett-Packard OpenView NNM webappmon.exe execvp_nc Remote Code Execution Vulnerability
- ZDI-10-136: Novell Teaming ajaxUploadImageFile Remote Code Execution Vulnerability
- XSS vulnerability in Spitfire search
- XSS vulnerability in Spitfire
- XSS vulnerability in Spitfire
- XSS vulnerability in Spitfire
- XSS vulnerability in Spitfire
- vBulletin - Critical Information Disclosure
- [DSECRG-09-068] SAP NetWaver SLD - multiple XSS
- [USN-927-8] Thunderbird update
- [USN-927-7] nspr update
- RE: vBulletin - Critical Information Disclosure
- [USN-957-1] Firefox and Xulrunner vulnerabilities
- [DSECRG-09-040] SAP Netweaver wsnavigator XSS Security Vulnerability
- [USN-930-4] Firefox and Xulrunner vulnerabilities
- [USN-930-5] ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
- [ MDVSA-2010:138 ] iputils
- [USN-927-6] NSS vulnerability
- Foofus.net Security Advisory: Symantec AMS Intel Alert Handler service Design Flaw
- Internet Explorer 8.0 Address Bar Spoofing Vulnerability
- DM Filemanager (fckeditor) Remote Arbitrary File Upload Exploit
- Call For Papers - Hackers 2 Hackers Conference 7th Edition - Brazil
- From: Rodrigo Rubira Branco (BSDaemon)
- Multiple vulnerabilities in MC Content Manager
- WhiteBoard 0.1.30 Multiple Blind SQL Injection Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- QQplayer smi File Processing Buffer Overflow Vulnerability
- Mac OS X WebDAV kernel extension local denial-of-service
- [LWSA-2010-001] Likewise Open 5.4 & 6.0
- Re: Internet Explorer 8.0 Address Bar Spoofing Vulnerability
- [USN-958-1] Thunderbird vulnerabilities
- [USN-957-2] Firefox and Xulrunner vulnerability
- Nessus Vulnerabilities
- iKAT - Interactive Kiosk Attack Tool v3 : Defcon 18 Edition
- Paper on the law and Implantable Devices security
- [USN-930-6] Firefox and Xulrunner vulnerability
- Heap Overflow/DoS Vulnerability in Media Player Classic
- XSS vulnerability in SyndeoCMS
- SQL injection vulnerability in Theeta CMS
- XSS vulnerability in SyndeoCMS
- XSS vulnerability in Theeta CMS
- XSS vulnerability in SyndeoCMS
- XSS vulnerability in Theeta CMS
- XSS vulnerability in Theeta CMS
- FuzzDiff tool
- [USN-964-1] Likewise Open vulnerability
- [MajorSecurity SA-079]PHPKIT WCMS - Multiple stored Cross Site Scripting Issues
- London DEFCON July meet - DC4420 - Wed 28th July 2010
- TTVideo 1.0 Joomla Component SQL Injection Vulnerability
- From: Salvatore Fresta aka Drosophila
- [ MDVSA-2010:140 ] php
- [ MDVSA-2010:141 ] samba
- [SECURITY] [DSA 2076-1] New gnupg2 packages fix potential code execution
- [SECURITY] [DSA 2075-1] New xulrunner packages fix several vulnerabilities
- Appointinator 1.0.1 Joomla Component Multiple Remote Vulnerabilities
- From: Salvatore Fresta aka Drosophila
- Re: TTVideo 1.0 Joomla Component SQL Injection Vulnerability
- Secunia Research: Autonomy KeyView Compound File Parsing Buffer Overflow
- Secunia Research: Autonomy KeyView wkssr.dll Floating Point Conversion Buffer Overflow
- Secunia Research: Autonomy KeyView rtfsr.dll RTF Parsing Signedness Error
- Secunia Research: Autonomy KeyView wosr.dll Data Block Parsing Buffer Overflow
- Secunia Research: Autonomy KeyView wkssr.dll Integer Underflow Vulnerability
- Secunia Research: Autonomy KeyView wkssr.dll String Indexing Vulnerability
- Secunia Research: Autonomy KeyView wkssr.dll Record Parsing Buffer Overflows
- Jira Enterprise 4.0.1 - Multiple Low Risk Vulnerabilities
- [security bulletin] HPSBMA02549 SSRT090158 rev.2 - HP Insight Control Power Management for Windows, Local Unauthorized Read Access to Data
- PhotoMap Gallery 1.6.0 Joomla Component Multiple Blind SQL Injection
- From: Salvatore Fresta aka Drosophila
- Vulnerabilities in Cetera eCommerce
- New vulnerabilities in Cetera eCommerce
- [security bulletin] HPSBUX02556 SSRT100014 rev.2 - HP-UX Running rpc.ttdbserver, Remote Execution of Arbitrary Code
- PBBooking 1.0.4_3 Joomla Component Multiple Blind SQL Injection
- From: Salvatore Fresta aka Drosophila
- CFP NcN 2010
- From: Jose Nicolas Castellano
- [ MDVSA-2010:142 ] openldap
- [HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th
- [SECURITY] [DSA 2077-1] New openldap packages fix potential code execution
- Insomnia : ISVA-100730.1 - CMS Multiple SQL injection Vulnerabilities
- Akamai Download Manager arbitrary file download & execution
- From: Akita Software Security
- Day of bugs in WordPress 2
- ESA-2010-012: EMC Disk Library (EDL) Denial Of Service Vulnerability
- XSS vulnerability in Campsite
- XSS vulnerability in Campsite
Mail converted by MHonArc