Mail Index
- [SECURITY] [DSA 2139-1] New phpmyadmin packages fix several vulnerabilities
- CA20101231-01: Security Notice for CA ARCserve D2D
- Announcing cross_fuzz, a potential 0-day in circulation, and more
- www.eVuln.com : SQL Injection in WikLink
- Geeklog 1.7.1 <= Cross Site Scripting Vulnerability
- From: YGN Ethical Hacker Group
- [ACM, Ariadne Content Manager] unauth. SQL injection + user enumeration
- Mathematica8 on Linux /tmp/MathLink vulnerability
- [DCA-00017] LinkSys BEFSR41 Multiple Stored Xss
- From: Ewerson Guimarães (Crash) - Dclabs
- Plunging Through the Palo Alto Networks Firewall
- VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
- From: VMware Security Team
- www.eVuln.com : "id" SQL Injection in WikLink
- [USN-1035-1] Evince vulnerabilities
- Getting root, the hard way
- [ MDVSA-2011:000 ] phpmyadmin
- BlogEngine.NET 1.6 Multiple Vulnerabilities
- Multiple XSS Vulnerabilities in Openfire 3.6.4 Administrative Section
- From: Walikar Riyaz Ahemed Dawalmalik
- Multiple CSRF Vulnerabilities in Openfire 3.6.4 Administrative Section
- From: Walikar Riyaz Ahemed Dawalmalik
- Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability
- From: YGN Ethical Hacker Group
- [ GLSA 201101-01 ] gif2png: User-assisted execution of arbitrary code
- Re: [ATHCON2011] CFP/ Call for Papers - AthCon IT Security Conference
- From: Kyprianos Vasilopoulos
- [SECURITY] [DSA-2140-1] New libapache2-mod-fcgid packages fixes stack overflow
- [SECURITY] [DSA-2141-2] New nss packages fix protocol design flaw
- [SECURITY] [DSA-2141-1] New apache2 packages add backward compatibility option
- [SECURITY] [DSA-2141-1] New openssl packages fix protocol design flaw
- Path disclousure in phpMySport
- SQL Injection in phpMySport
- Authentication bypass in phpMySport
- SQL Injection in Phenotype CMS
- XSRF (CSRF) in PHP MicroCMS
- XSS vulnerability in WonderCMS
- SQL Injection in phpMySport
- SQL Injection in phpMySport
- XSS vulnerability in PHP MicroCMS
- [SECURITY] [DSA-2142-1] New dpkg packages fix directory traversal
- [USN-1037-1] ifupdown update
- [USN-1039-1] AppArmor update
- [USN-1040-1] Django vulnerabilities
- [USN-1038-1] dpkg vulnerability
- GNU libc/regcomp(3) Multiple Vulnerabilities
- Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability
- From: YGN Ethical Hacker Group
- McAfee Commandline Updater
- call for participation
- From: chpardhasaradhisarma
- CUDA drivers/Linux security hole
- Web Hacking & Database Hijack Online Challenge
- [ MDVSA-2011:002 ] wireshark
- Silicon Graphics Inc (SGI) - IRIX - Local Kernel Memory Disclosure/Denial of Service
- From: Digit Security Research
- [ MDVSA-2011:003 ] MHonArc
- www.eVuln.com : "fold" and "site" SQL Injections in WikLink
- NewV: NewvCommon.ocx arbitrary command execution via the Runcommand attribute
- NewvCommon.ocx ActiveX Insecure Method Vulnerability
- NewvCommon.ocx ActiveX Remote Code Execution Vulnerability
- [ MDVSA-2011:004 ] php-phar
- SQL injection vulnerability in Energine
- XSRF (CSRF) in VaM Shop
- Stored XSS vulnerability in diafan.CMS
- Path disclosure in Energine
- XSRF (CSRF) in Energine
- XSS vulnerability in VaM Shop
- XSS vulnerability in VaM Shop
- XSS vulnerability in VaM Shop
- XSRF (CSRF) in diafan.CMS
- XSS vulnerability in diafan.CMS
- XSRF (CSRF) in Cambio
- XSRF (CSRF) in whCMS
- [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC
- ASPR #2011-01-11-1: Remote Binary Planting in Multiple F-Secure Products
- From: ACROS Security Lists
- [security bulletin] HPSBMA02621 SSRT100352 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [security bulletin] HPSBMA02557 SSRT100025 rev.2 - HP OpenView Network Node Manager (OV NNM) Running on Windows, Remote Execution of Arbitrary Code
- [SECURITY] [DSA 2122-2] New glibc packages fix privilege escalation
- 2011 Rocky Mountain Information Security Conference Call for Papers
- [USN-1009-2] GNU C Library vulnerability
- SECURITY ADVISORY IBM Cognos 8 Business Intelligence 8.4.1
- [USN-1042-1] PHP vulnerabilities
- [USN-1043-1] Little CMS vulnerability
- Call for Papers: DIMVA 2011 - Extended Deadline Jan 21
- [Onapsis Security Advisory 2011-001] SAP Management Console Unauthenticated Service Restart
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2011-002] SAP Management Console Information Disclosure
- From: Onapsis Research Labs
- iDefense Security Advisory 01.10.11: HP Network Node Manager Command Injection Vulnerability
- [security bulletin] HPSBMA02621 SSRT100352 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- [SECURITY] [DSA-2141-4] New lighttpd packages fix regression
- CONFidence 2011 - Call for Papers - 24-25.05.2011 Krakow, Poland
- [security bulletin] HPSBMA02624 SSRT100195 rev.1 - HP LoadRunner, Remote Execution of Arbitrary Code
- [USN-1042-2] PHP5 regression
- Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11)
- [MajorSecurity SA-081]Contao CMS 2.9.2 - Persistent Cross Site Scripting Issue
- [ MDVSA-2011:005 ] evince
- [security bulletin] HPSBUX02608 SSRT100333 rev.2 - HP-UX Running Java, Remote Execution of Arbitrary Code, Disclosure of Information, and Other Vulnerabilities
- [SECURITY] [DSA-2143-1] New mysql-dfsg-5.0 packages fix several vulnerabilities
- Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability
- From: YGN Ethical Hacker Group
- [ MDVSA-2011:007 ] wireshark
- [ MDVSA-2011:006 ] subversion
- [ MDVSA-2011:006 ] subversion
- Remote Code Execution in ICQ 7
- [ MDVSA-2011:008 ] perl-CGI
- [ MDVSA-2011:009 ] gif2png
- [ MDVSA-2011:011 ] opensc
- [ GLSA 201101-06 ] IO::Socket::SSL: Certificate validation error
- [SECURITY] [DSA 2146-1] Security update for mydms
- [ GLSA 201101-02 ] Tor: Remote heap-based buffer overflow
- [ GLSA 201101-04 ] aria2: Directory traversal
- [SECURITY] [DSA 2147-1] Security update for pimd
- [ GLSA 201101-03 ] libvpx: User-assisted execution of arbitrary code
- [SECURITY] [DSA 2145-1] Security update for libsmi
- [SECURITY] [DSA 2144-1] Security update for wireshark
- [ GLSA 201101-07 ] Prewikka: password disclosure
- [ GLSA 201101-05 ] OpenAFS: Arbitrary code execution
- [ MDVSA-2011:010 ] xfig
- Kingsoft AntiVirus 2011 SP5.2 KisKrnl.sys <= 2011.1.13.89 Local Kernel Mode D.O.S Exploit(3 lines of code)
- 'Seo Panel' Cookie-Rendered Persistent XSS Vulnerability (CVE-2010-4331)
- [ MDVSA-2011:012 ] mysql
- [SECURITY] [DSA 2148-1] Security update for tor
- AST-2011-001: Stack buffer overflow in SIP channel driver
- From: Asterisk Security Team
- [USN-1044-1] D-Bus vulnerability
- Simploo CMS Community Edition - Remote PHP Code Execution Issue
- [USN-1045-2] util-linux update
- [ MDVSA-2011:013 ] hplip
- [USN-1045-1] FUSE vulnerability
- [security bulletin] HPSBMA02625 SSRT100138 rev.1 - HP OpenView Storage Data Protector, Remote Execution of Arbitrary Code
- [SECURITY] [DSA 2149-1] Security update for dbus
- [USN-1046-1] Sudo vulnerability
- DotNetNuke Remote Code Execution vulnerability
- SQL Injection in Pixie
- SQL Injection in Pixie
- [security bulletin] HPSBUX02623 SSRT100355 rev.1 - HP-UX Running Kerberos, Remote Unauthorized Modification
- [security bulletin] HPSBMA02622 SSRT100342 rev.1 - HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Cross Site Scripting (XSS)
- [TEHTRI-Security] CVE-2010-2599: Update your BlackBerry
- From: Laurent OUDOT at TEHTRI-Security
- [ MDVSA-2011:014 ] ccid
- London DEFCON - DC4420 - Tuesday 25th January 2011 - SOCIAL
- Code execution in Microsoft Fax Cover Page Editor
- [ MDVSA-2011:015 ] pcsc-lite
- IETF RFC on Port Randomization
- NSOADV-2010-010: DATEV Multiple Applications DLL Hijacking Vulnerability
- [ MDVSA-2011:016 ] t1lib
- [ MDVSA-2011:017 ] tetex
- [ GLSA 201101-09 ] Adobe Flash Player: Multiple vulnerabilities
- [ GLSA 201101-08 ] Adobe Reader: Multiple vulnerabilities
- [ MDVSA-2011:018 ] sudo
- [SECURITY] [DSA 2150-1] request-tracker3.6 security update
- [USN-1047-1] AWStats vulnerability
- [USN-1048-1] Tomcat vulnerability
- ESA-2011-001: RSA, The Security Division of EMC, addresses RKM 1.5 C Client SQL Injection Vulnerability
- phpcms V9 BLind SQL Injection Vulnerability
- [CFP] LACSEC 2011: 6th Network Security Event for Latin America and the Caribbean
- HTB22794: Path disclousure in Pixelpost
- [DSECRG-00153] Oracle Document Capture Actbar2.ocx - insecure method
- HTB22791: File Content Disclosure in Pixelpost
- [DSECRG-00143] SAP Crystal Reports 2008 - ActiveX insecure methods
- HTB22788: XSS in Pivotx
- [DSECRG-11-005] Oracle Document Capture empop3.dll - insecure method
- [DSECRG-11-006] Oracle Document Capture ActiveX - Insecure method, buffer overflow
- HTB22792: XSS in Pixelpost
- [DSECRG-11-007] Oracle Document Capture ImportBodyText - read files
- HTB22790: XSS in Pivotx
- [DSECRG-11-008] Open Edge RDBMS - Multiple architecture vulnerabilities (UNPATCHED)
- HTB22789: Path disclousure in Pivotx
- HTB22787: Path disclousure in Pligg CMS
- [security bulletin] HPSBMA02624 SSRT100195 rev.2 - HP LoadRunner and HP Performace Center, Remote Execution of Arbitrary Code
- syslog-ng wrong file permission vulnerability
- [OVSA20110118] OpenVAS Manager Vulnerable To Command Injection
- [DSECRG-00142] SAP Crystal Reports 2008 - actionNavjsp_xss
- [DSECRG-00145] SAP Crystal Reports 2008 - Directory Traversal
- [security bulletin] HPSBMA02626 SSRT100301 rev.1 - HP OpenView Storage Data Protector, Remote Denial of Service (DoS)
- [USN-1051-1] HPLIP vulnerability
- ESA-2011-003: EMC NetWorker librpc.dll spoofing vulnerability.
- HTB22795: Path disclosure in Hycus CMS
- Microsoft IIS 6 parsing directory “x.asp” Vulnerability
- PRTG V8.1.2.1809 XSS Bugs in login.htm and error.htm
- Re: Remote Code Execution in ICQ 7
- VUPEN Security Research - Novell GroupWise "TZID" Variable Remote Buffer Overflow Vulnerability (VUPEN-SR-2011-004)
- From: VUPEN Security Research
- [ MDVSA-2011:019 ] libuser
- IETF RFC on "the implementation of the TCP urgent mechanism"
- Vanilla Forums 2.0.16 <= Cross Site Scripting Vulnerability
- From: YGN Ethical Hacker Group
- Huawei HG default WEP/WPA generator
- Cisco Security Advisory: Cisco Content Services Gateway Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities
- Lomtec ActiveWeb Professional 3.0 CMS Allows Arbitrary File Upload and Execution as SYSTEM in ColdFusion (2010-WEB-002) (CERT VU#528212)
- From: StenoPlasma @ www.ExploitDevelopment.com
- OpenOffice.org Multiple Memory Corruption Vulnerabilities
- HTB22797: Path disclousure in BLOG:CMS
- HTB22796: Path disclousure in DBHcms
- [USN-1052-1] OpenJDK vulnerability
- HTB22793: XSRF (CSRF) in KaiBB
- CA20101231-01: Security Notice for CA ARCserve D2D (updated)
- [SECURITY] [DSA 2152-1] hplip security update
- FreeBSD local denial of service - forced reboot
- TELUS Security Labs VR - Symantec Alert Management System HNDLRSVC Arbitrary Command Execution
- TELUS Security Labs VR - Symantec Antivirus Intel Alert Handler Service Denial of Service
- TELUS Security Labs VR - Novell ZENworks Handheld Management ZfHIPCND.exe Buffer Overflow
Mail converted by MHonArc