Mail Index
- [SECURITY] [DSA 2376-2] ipmitool security update
- [ MDVSA-2011:198 ] phpmyadmin
- [SECURITY] [DSA 2377-1] cyrus-imapd-2.2 security update
- [ MDVSA-2012:001 ] fcgi
- [ MDVSA-2012:002 ] t1lib
- BigACE CMS - XSS Vulnerabilities
- OpenKM 5.1.7 Privilege Escalation
- From: Cyrill Brunschwiler
- OpenKM 5.1.7 OS Command Execution (XSRF based)
- From: Cyrill Brunschwiler
- Tinyguestbook XSS
- [RT-SA-2012-001] Bugzilla: Cross-Site Scripting in Chart Generator
- From: RedTeam Pentesting GmbH
- mavili guestbook - SQL Injection and XSS Vulnerabilities
- [SE-2011-01] Security vulnerabilities in a digital satellite TV platform
- From: Security Explorations
- Re: PHP Booking Calendar 10e XSS
- SQL Injection Vulnerability in OpenEMR 4.1.0
- From: Netsparker Advisories
- Re: Tinyguestbook XSS
- [SECURITY] [DSA 2378-1] ffmpeg security update
- InfoSec Southwest 2012 CFP First-round Speaker Selections
- Re: [SE-2011-01] Security vulnerabilities in a digital satellite TV platform
- From: Security Explorations
- Google Chrome HTTPS Address Bar Spoofing
- From: ACROS Security Lists
- TWSL2012-001: Cross-Site Scripting Vulnerability in Textpattern Content Management System
- From: Trustwave Advisories
- Re: OpenKM 5.1.7 Privilege Escalation
- Open Redirection Vulnerability in Orchard 1.3.9
- From: Netsparker Advisories
- Multiple vulnerabilities in ImpressCMS
- [SECURITY] [DSA 2379-1] krb5 security update
- [SECURITY] [DSA 2380-1] foomatic-filters security update
- [ GLSA 201201-01 ] phpMyAdmin: Multiple vulnerabilities
- Revised IETF I-D: Advice on IPv6 RA-Guard Implementation
- HServer webserver - Directory Traversal Vulnerability
- NGS00109 Technical Advisory: Remote Code Execution in ImpressPages CMS
- NGS00106 Technical Advisory: Increased exploitation of Oracle GlassFish Server Administration Console Remote Authentication Bypass Vulnerability
- SEC Consult SA-20120104-0 :: Multiple critical vulnerabilities in Apache Struts2
- From: SEC Consult Vulnerability Lab
- Ggb Guestbook - XSS Vulnerabilities
- VLC media player v1.1.11 (.amr) Local Crash PoC
- VertrigoServ 2.25 Cross-Site-Scripting vulnerability
- SQLiteManager 1.2.4 Multiple Cross-Site-Scripting vulnerabilities
- ZDI-12-001 : HP Managed Printing Administration img_id Multiple Vulnerabilities
- ZDI-12-004 : Apple Quicktime JPEG2000 COD Remote Code Execution Vulnerability
- ZDI-12-006 : Novell Netware XNFS.NLM NFS Rename Remote Code Execution Vulnerability
- ZDI-12-002 : HP OpenView NNM ov.dll _OVBuildPath Remote Code Execution Vulnerability
- ZDI-12-005 : Apple Quicktime RLE BGRA Decoding Remote Code Execution Vulnerability
- ZDI-12-007 : Novell Netware XNFS.NLM STAT Notify Remote Code Execution Vulnerability
- [ GLSA 201201-02 ] MySQL: Multiple vulnerabilities
- [SECURITY] [DSA 2381-1] squid3 security update
- IpTools(Tiny TCP/IP server) - WebServer Directory Traversal Vulnerability
- IpTools - Rcmd Remote Overflow Vulnerability
- ZDI-12-003 : HP OpenView NNM webappmon.exe parameter Remote Code Execution Vulnerability
- [ GLSA 201201-03 ] Chromium, V8: Multiple vulnerabilities
- [SECURITY] [DSA 2382-1] ecryptfs-utils security update
- [SECURITY] [DSA 2383-1] super security update
- [security bulletin] HPSBPI02728 SSRT100692 rev.3 - Certain HP Printers and HP Digital Senders, Remote Firmware Update Enabled by Default
- [security bulletin] HPSBPI02733 SSRT100646 rev.1 - Certain HP LaserJet Printers, Remote Unauthorized Access to Files
- [SECURITY] [DSA 2384-1] cacti security update
- From: <@securityfocus.com Luk Claes
- Re: [SE-2011-01] Security vulnerabilities in a digital satellite TV platform
- From: Security Explorations
- DDIVRT-2011-37 HP JetDirect Device Page Directory Traversal (CVE-2011-4785)
- Simple Mail Server - SMTP Authentication Bypass Vulnerability
- AppSec DC 2012 CFP EXTENDED!
- p0f3 release candidate
- Is Your Online Bank Vulnerable To Currency Rounding Attacks?
- From: ACROS Security Lists
- Re: Simple Mail Server - SMTP Authentication Bypass Vulnerability
- [ MDVSA-2012:003 ] apache
- ZDI-12-008 : Citrix Provisioning Services streamprocess.exe vDisk Name Parsing Remote Code Execution Vulnerability
- ZDI-12-009 : Citrix Provisioning Services Stream Service 0x40020000 Remote Code Execution Vulnerability
- ZDI-12-010 : Citrix Provisioning Services Stream Service 0x40020006 Remote Code Execution Vulnerability
- ZDI-12-011 : Novell Netware XNFS caller_name xdrDecodeString Remote Code Execution Vulnerability
- [SECURITY] [DSA 2385-1] pdns security update
- Multiple Cross-Site-Scripting vulnerabilities in x3cms
- VUPEN Security Research - Adobe Acrobat and Reader Image Processing Integer Overflow (APSB12-01)
- From: VUPEN Security Research
- [PT-2011-01] Cross-Site Scripting in Kayako Support Suite
- [PT-2011-02] PHP code Injection in Kayako Support Suite
- Multiple XSS in KnowledgeTree Community Edition
- [PT-2011-03] Information disclosure in Kayako Support Suite
- [PT-2011-03] Information disclosure in Kayako Support Suite
- Secunia Research: NTR ActiveX Control Four Buffer Overflow Vulnerabilities
- Secunia Research: NTR ActiveX Control "StopModule()" Input Validation Vulnerability
- [PT-2011-04] Cross-Site Scripting in Kayako Support Suite
- [SECURITY] [DSA 2387-1] simplesamlphp security update
- [security bulletin] HPSBPI02698 SSRT100404 rev.2 - HP Easy Printer Care Software Running on Windows, Remote Execution of Arbitrary Code
- GreenBrowser iframe content Double Free Vulnerability
- [SECURITY] [DSA 2386-1] openttd security update
- Office arbitrary ClickOnce application execution vulnerability
- From: Akita Software Security
- AthCon 2012 CFP is now OPEN!
- From: Christian Papathanasiou
- Revised IETF I-D: IPv6 Neighbor Discovery, SEND, and IPv6 Fragmentation
- SafeSEH+SEHOP all-at-once bypass explotation method principles
- [ MDVSA-2012:004 ] t1lib
- ZDI-12-012 : (0Day) McAfee SaaS myCIOScn.dll ShowReport Method Remote Command Execution
- ZDI-12-013 : HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution Vulnerability
- ZDI-12-015 : (0Day) HP StorageWorks P2000 G3 Directory Traversal and Default Account Vulnerabilities
- ZDI-12-014 : HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution Vulnerability
- ZDI-12-016 : (0Day) HP Diagnostics Server magentservice.exe Remote Code Execution Vulnerability
- ME020567: MailEnable webmail cross-site scripting vulnerability CVE-2012-0389
- [security bulletin] HPSBST02735 SSRT100516 rev.1 - HP StorageWorks Modular Smart Array P2000 G3, Remote Execution of Arbitrary Code
- PHP 5.3.8 Multiple vulnerabilities
- BoltWire 3.4.16 Multiple XSS vulnerabilities
- ATutor 2.0.3 Multiple XSS vulnerabilities
- [SECURITY] [DSA 2388-1] t1lib security update
- [SECURITY] [DSA 2390-1] openssl security update
- [SECURITY] [DSA 2389-1] linux-2.6 security update
- [Announcement] ClubHack Mag Issue 24-Jan 2012 Released
- First-hop security in IPv6
- Re: Multiple XSS in KnowledgeTree Community Edition
- Family Connections 2.7.2 Multiple XSS
- phpVideoPro Multiple XSS vulnerabilities
- Beehive Forum 101 Multiple XSS vulnerabilities
- (CFP) LACSEC 2012: 7th Network Security Event for Latin America and the Caribbean
- [Announcement] ClubHack Mag - Call for Articles
- Re: Multiple XSS in KnowledgeTree Community Edition
- [ MDVSA-2012:005 ] libxml2
- [ MDVSA-2012:006 ] openssl
- [ MDVSA-2012:007 ] openssl
- Re: p0f3 release candidate
- pwgen: non-uniform distribution of passwords
- [SECURITY] CVE-2011-3375 Apache Tomcat Information disclosure
- [SECURITY] CVE-2012-0022 Apache Tomcat Denial of Service
- ESA-2012-003: EMC SourceOne Web Search Sensitive Information Disclosure Vulnerability.
- Re: pwgen: non-uniform distribution of passwords
- Reflection Scan: an Off-Path Attack on TCP
- XSS in OneOrZero AIMS
- [ MDVSA-2012:008 ] perl
- [ MDVSA-2012:009 ] perl
- Cisco Security Advisory: Cisco Digital Media Manager Privilege Escalation Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IP Video Phone E20 Default Root Account
- From: Cisco Systems Product Security Incident Response Team
- Drupal CKEditor 3.0 - 3.6.2 - Persistent EventHandler XSS
- From: InterN0T Advisories
- Xpra memory disclosure
- [security bulletin] HPSBMU02736 SSRT100699 rev.1 - HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Unauthorized Access to Sensitive Information
- Advisory 01/2012: Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow
- Re: pwgen: non-uniform distribution of passwords
- appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Vulnerability
- Webcalendar 1.2.4 'location' XSS
- [Suspected Spam] Barracuda Spam/Virus WAF 600 - Multiple Web Vulnerabilities
- From: research@xxxxxxxxxxxxxxxxxxxxx
- InfoSec Southwest 2012 Open Registration
- DC4420 - London DEFCON - 24 January 2012
- [ MDVSA-2012:010 ] cacti
- [ GLSA 201201-04 ] Logsurfer: Arbitrary code execution
- [SECURITY] [DSA 2391-1] phpmyadmin security update
- DDIVRT-2011-39 SolarWinds Storage Manager Server SQL Injection Authentication Bypass
- AllWebMenus < 1.1.9 WordPress Menu Plugin Arbitrary file upload
- [Suspected Spam] Bart`s CMS - SQL Injection Vulnerability
- From: research@xxxxxxxxxxxxxxxxxxxxx
- Re: pwgen: non-uniform distribution of passwords
- ZDI-12-017 : Oracle Outside In OOXML Relationship Tag Parsing Remote Code Execution Vulnerability
- [SECURITY] [DSA 2301-2] rails regression
- [SECURITY] [DSA 2392-1] openssl security update
- SQL injection in Bigware shop software
- [ GLSA 201201-12 ] Tor: Multiple vulnerabilities
- Wordpress Kish Guest Posting Plugin 1.0 (uploadify.php) Unrestricted File Upload Vulnerability
- [ GLSA 201201-13 ] MIT Kerberos 5: Multiple vulnerabilities
- [ GLSA 201201-14 ] MIT Kerberos 5 Applications: Multiple vulnerabilities
- NGS00193 Patch Notification: Trend Micro DataArmor and DriveArmor - Restricted Environment breakout, Privilege Escalation and Full Disk Decryption
- Only 7 Days Left: SANS AppSec 2012 CFP
- [security bulletin] HPSBUX02719 SSRT100658 rev.4 - HP-UX Running BIND, Remote Denial of Service (DoS)
- NGS00118 Patch Notification: Symantec PCAnywhere Remote Code Execution as SYSTEM
- [security bulletin] HPSBUX02734 SSRT100729 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Unauthorized Access
- [security bulletin] HPSBUX02729 SSRT100687 rev.3 - HP-UX Running BIND, Remote Denial of Service (DoS)
- NGS00117 Patch Notification: Symantec PCAnywhere Local Privilege Escalation
- TWSL2012-002: Multiple Vulnerabilities in WordPress
- From: Trustwave Advisories
- Multiple vulnerabilities in OSclass
- CSRF (Cross-Site Request Forgery) in DClassifieds
- [security bulletin] HPSBUX02730 SSRT100710 rev.1 - HP-UX Running Java, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
- D-Link DIR-601 TFTP Directory Traversal Vulnerability
- [SECURITY] [DSA-2393-1] bip security update
- NX Web Companion Spoofing Arbitrary Code Execution Vulnerability
- ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability
- Cisco Security Advisory: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- ESA-2012-005: EMC NetWorker buffer overflow vulnerability
- ESA-2012-007: RSA, The Security Division of EMC, announces security fixes for RSA enVision
- [SECURITY] [DSA 2394-1] libxml2 security update
- [HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon
- [ GLSA 201201-15 ] ktsuss: Privilege escalation
- AdaCore Security Advisory SA-2012-L119-003 Hash collisions in AWS
- [SECURITY] [DSA 2395-1] wireshark security update
- [SECURITY] [DSA 2396-1] qemu-kvm security update
- [ GLSA 201201-17 ] Chromium: Multiple vulnerabilities
- [ GLSA 201201-16 ] X.Org X Server/X Keyboard Configuration Database: Screen lock bypass
- eBank IT Online Banking - Multiple Web Vulnerabilities
- From: research@xxxxxxxxxxxxxxxxxxxxx
- FAA US Academy (AFS) - Auth Bypass Vulnerability
- From: research@xxxxxxxxxxxxxxxxxxxxx
- [SECURITY] [DSA 2397-1] icu security update
- Mibew messenger multiple XSS
- Multiple vulnerabilities in postfixadmin
- [ MDVSA-2012:011 ] openssl
- Multiple vulnerabilities in OSClass
- [ GLSA 201201-18 ] bip: Multiple vulnerabilities
- [ GLSA 201201-19 ] Adobe Reader: Multiple vulnerabilities
- Advisory: sudo 1.8 Format String Vulnerability
- From: joernchen of Phenoelit
Mail converted by MHonArc