Mail Index
- Cisco Security Advisory: Cisco Unified Presence Server Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Prime Central for Hosted Collaboration Solution Assurance Excessive CPU Utilization Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- [ MDVSA-2013:016 ] php
- [waraxe-2013-SA#097] - Multiple Vulnerabilities in PHP-Fusion 7.02.05
- Unauthenticated remote access to D-Link DIR-645 devices
- [KIS-2013-03] Joomla! <= 3.0.2 (highlight.php) PHP Object Injection Vulnerability
- Multiple Vulnerabilities in Piwigo
- Cross-Site Scripting (XSS) in Geeklog
- Stored Cross-site Scripting ('XSS') in Airvana HubBub C1-600-RT Femtocell
- PHEARCON Call For Papers
- Fileutils ruby gem possible remote command execution and insecure file handling in /tmp
- ESA-2013-012: RSA® Authentication Agent 7.1.1 for Microsoft Windows® Access Control Vulnerability
- [SECURITY] [DSA 2635-1] cfingerd security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2636-1] xen security update
- [SECURITY] [DSA 2636-2] xen regression update
- [slackware-security] httpd (SSA:2013-062-01)
- From: Slackware Security Team
- [SE-2012-01] One more attack affecting Oracle's Java SE 7u15
- From: Security Explorations
- rpi-update tmpfile vulnerability
- CVE-2013-1413
- [CVE-REQUEST] Foscam <= 11.37.2.48 path traversal vulnerability
- Proofpoint Protection Server Session Persistence
- Remote command execution for Ruby Gem ftpd-0.2.1
- Remote system freeze thanks to Kaspersky Internet Security 2013
- [IA32] HP Intelligent Management Center v5.1 E0202 topoContent.jsf Non-Persistent Cross-Site Scripting
- [SECURITY] [DSA 2637-1] apache2 security update
- APPLE-SA-2013-03-04-1 Java for OS X 2013-002 and Mac OS X v10.6 Update 14
- From: Apple Product Security
- [SECURITY] [DSA 2638-1] openafs security update
- WordPress Count-Per-Day plugin 3.2.5. Type-1 (reflected) Cross Site Scripting (XSS)
- [PT-2013-17] Arbitrary Files Reading in mnoGoSearch
- RE: [Full-disclosure] Remote system freeze thanks to Kaspersky Internet Security 2013 (SA52053)
- From: Vulnerability Mailbox
- [SECURITY] [DSA 2639-1] php5 security update
- [ MDVSA-2013:017 ] libxml2
- Varnish 2.1.5, 3.0.3 DoS in VRY_Create() while parsing Vary header
- Samsung TV DoS (possible overflow) via SOAPACTION
- Varnish 2.1.5 DoS in STV_alloc() while parsing Content-Length header
- Squid 3.2.7 DoS (loop, 100% cpu) strHdrAcptLangGetItem() at errorpage.cc
- SIP Witch 0.7.4 w/libosip2-4.0.0 DoS via NULL pointer derefence in libosip2
- Varnish 2.1.5, 3.0.3 DoS in http_GetHdr() while parsing Vary header
- Squid 3.2.5 httpMakeVaryMark() header value DoS, 2.7.Stable9 memory corruption.
- Varnish 2.1.5 DoS in fetch_straight() while parsing Content-Length header
- Apache Subversion mod_dav_svn DoS via MKACTIVITY/PROPFIND
- Re: Kingcopes AthCon 2012 Slides & Notes --> Video online
- Re: rpi-update tmpfile vulnerability
- OS Command Injection in CosCms
- Multiple XSS vulnerabilities in Events Manager WordPress plugin
- [SECURITY] CVE-2013-0248 Apache Commons FileUpload - Insecure examples
- Verax NMS Authenication Bypass (CVE-2013-1350)
- Verax NMS Password Replay Attack (CVE-2013-1351)
- Verax NMS Hardcoded Private Key (CVE-2013-1352)
- Verax NMS Password Disclosure (CVE-2013-1631)
- [ MDVSA-2013:018 ] openssl
- DDIVRT-2013-51 DALIM Dialog Server 'logfile' Local File Inclusion
- [security bulletin] HPSBMU02849 SSRT101124 rev.1 - HP ServiceCenter, Remote Denial of Service (DoS)
- [slackware-security] sudo (SSA:2013-065-01)
- From: Slackware Security Team
- [security bulletin] HPSBPI02851 SSRT101078 rev.1 - Certain HP LaserJet Pro Printers, Unauthorized Access to Data
- [ MDVSA-2013:019 ] gnutls
- [security bulletin] HPSBGN02854 SSRT100881 rev.1 - HP Intelligent Management Center (iMC), iMC TACACS+ Authentication Manager (TAM), and iMC User Access Manager (UAM), Cross Site Scripting (XSS), Remote Code Execution, Remote Disclosure of Information
- Untrusted Pointer Dereference Vulnerability in Corel WordPerfect X6
- Multiple NULL Pointer Dereference Vulnerabilities in Corel Quattro Pro X6
- Re: Oracle Auto Service Request /tmp file clobbering vulnerability
- Re: Squid 3.2.7 DoS (loop, 100% cpu) strHdrAcptLangGetItem() at errorpage.cc
- [ MDVSA-2013:020 ] wireshark
- [ MDVSA-2013:021 ] java-1.6.0-openjdk
- SEC Consult SA-20130308-0 :: Multiple critical vulnerabilities in GroundWork Monitor Enterprise (part 1)
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20130308-1 :: Multiple vulnerabilities in GroundWork Monitor Enterprise (part 2)
- From: SEC Consult Vulnerability Lab
- Stored XSS in Terillion Reviews Wordpress Plugin
- [SECURITY] [DSA 2642-1] sudo security update
- [slackware-security] mozilla-thunderbird (SSA:2013-068-02)
- From: Slackware Security Team
- [slackware-security] mozilla-firefox (SSA:2013-068-01)
- From: Slackware Security Team
- [SECURITY] [DSA 2641-1] perl security update
- From: Salvatore Bonaccorso
- Recon 2013 Call For Papers - June 21-23, 2013 - Montreal, Quebec
- OpenFabrics ibutils 1.5.7 /tmp clobbering vulnerability
- [ISecAuditors Security Advisories] Reflected XSS in Asteriskguru Queue Statistics
- From: ISecAuditors Security Advisories
- Privoxy Proxy Authentication Credential Exposure - CVE-2013-2503
- Host tracking in IPv6 (SI6 Networks' IPv6 toolkit v1.3.3)
- SEC Consult SA-20130311-0 :: Persistent cross-site scripting in jforum
- From: SEC Consult Vulnerability Lab
- AthCon 2013 Rev. Challenge 2013
- Results of a XSLT fuzzing effort
- Re: Squid 3.2.7 DoS (loop, 100% cpu) strHdrAcptLangGetItem() at errorpage.cc
- Re: Squid 3.2.7 DoS (loop, 100% cpu) strHdrAcptLangGetItem() at errorpage.cc
- Privoxy Proxy Authentication Credential Exposure - CVE-2013-2503
- Announcing ChronIC - a wearable Sub-GHz RF hacking tool
- Re: Squid 3.2.7 DoS (loop, 100% cpu) strHdrAcptLangGetItem() at errorpage.cc
- TagScanner v5.1 - Stack Buffer Overflow Vulnerability
- [SECURITY] [DSA 2643-1] puppet security update
- Open-Xchange Security Advisory 2013-03-13
- SEC Consult SA-20130313-0 :: QlikView Desktop Client Integer Overflow
- From: SEC Consult Vulnerability Lab
- [ MDVSA-2013:022 ] openssh
- [CVE-2013-1814] Apache Rave exposes User over API
- [ MDVSA-2013:023 ] coreutils
- Cisco Video Surveillance Operations Manager Multiple vulnerabilities
- Re: [CVE-REQUEST] Foscam <= 11.37.2.48 path traversal vulnerability
- [ MDVSA-2013:024 ] firefox
- Re: SQLi found in Kodak Insite
- [slackware-security] perl (SSA:2013-072-01)
- From: Slackware Security Team
- [slackware-security] seamonkey (SSA:2013-072-02)
- From: Slackware Security Team
- [ MDVSA-2013:025 ] pidgin
- [SECURITY] [DSA 2640-1] zoneminder security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2644-1] wireshark security update
- APPLE-SA-2013-03-14-1 OS X Mountain Lion v10.8.3 and Security Update 2013-001
- From: Apple Product Security
- APPLE-SA-2013-03-14-2 Safari 6.0.3
- From: Apple Product Security
- [SECURITY] [DSA 2645-1] inetutils security update
- Curl Ruby Gem Remote command execution
- MiniMagic ruby gem remote code execution
- DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal
- Skype Click to Call Update Service local privilege escalation
- From: Oliver-Tobias Ripka
- [SECURITY] [DSA 2647-1] firebird2.1 security update
- [SECURITY] [DSA 2648-1] firebird2.5 security update
- n.runs-SA-2013.002 - Polycom - Firmware Update Command Injection
- n.runs-SA-2013.003 - Polycom - H.323 CDR Database SQL Injection
- n.runs-SA-2013.004 - Polycom - H.323 Format String Vulnerability
- n.runs-SA-2013.001 - Polycom - Command Shell Grants System-Level Access
- [SECURITY] [DSA 2646-1] typo3-src security update
- [SECURITY] [DSA 2649-1] lighttpd security update
- [SECURITY] [DSA 2650-1] libvirt-bin security update
- [slackware-security] ruby (SSA:2013-075-01)
- From: Slackware Security Team
- Remote command execution in fastreader ruby gem
- [SECURITY] [DSA 2650-2] libvirt regression update
- [ MDVSA-2013:026 ] sudo
- [SE-2012-01] The "allowed behavior" in Java SE 7 (Issue 54)
- From: Security Explorations
- [ MDVSA-2013:027 ] clamav
- [ MDVSA-2013:028 ] nagios
- NGS00440 Patch Notification: Windows USB RNDIS driver kernel pool overflow
- Cisco Security Response: Cisco IOS and Cisco IOS XE Type 4 Passwords Issue
- From: Cisco Systems Product Security Incident Response Team
- NOPcon 2013 - Call for paper - Istanbul , Turkey
- Remote command execution in Ruby Gem Command Wrap
- VUPEN Security Research - Mozilla Firefox "nsHTMLEditRules" Use-After-Free (MFSA-2013-29 / CVE-2013-0787)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Internet Explorer 10-9-8-7-6 "OnResize" Use-after-free (MS13-021 / CVE-2013-0087)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Internet Explorer 10-9-8-7-6 "OnMove" Use-after-free (MS13-021 / CVE-2013-0087)
- From: VUPEN Security Research
- CA20130319-01: Security Notice for SiteMinder products using SAML
- [waraxe-2013-SA#098] - Directory Traversal Vulnerabilities in OpenCart 1.5.5.1
- Re: VUPEN Security Research - Microsoft Internet Explorer 10-9-8-7-6 "OnResize" Use-after-free (MS13-021 / CVE-2013-0087)
- APPLE-SA-2013-03-19-1 iOS 6.1.3
- From: Apple Product Security
- APPLE-SA-2013-03-19-2 Apple TV 5.2.1
- From: Apple Product Security
- [IA49] Photodex ProShow Producer v5.0.3310 ScsiAccess Local Privilege Escalation
- [SECURITY] [DSA 2641-2] libapache2-mod-perl2 update related to DSA 2641-1
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2651-1] smokeping security update
- From: Salvatore Bonaccorso
- [SE-2011-01] PoC code for digital SAT TV research released
- From: Security Explorations
- [security bulletin] HPSBUX02856 SSRT101104 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS) and Unauthorized Disclosure
- [waraxe-2013-SA#099] - Update Spoofing Vulnerability in LibreOffice 4.0.1.2
- DC4420 - London DEFCON - March meet - Tuesday 26th March 2013
- [slackware-security] php (SSA:2013-081-01)
- From: Slackware Security Team
- [security bulletin] HPSBPV02855 SSRT100512 rev.1 - HP ProCurve 1700-8(J9079A) and 1700-24(J9080A) Switches, Cross Site Request Forgery (CSRF)
- [SECURITY] [DSA 2652-1] libxml2 security update
- Report OWASP WAF Naxsi bypass Vulnerability
- SynConnect PMS SQL Injection Vulnerability
- From: bhadresh . k . patel
- ESA-2013-016: EMC Smarts Network Configuration Manager
- [security bulletin] HPSBOV02852 SSRT101108 rev.1 - HP SSL for OpenVMS, Remote Denial of Service (DoS), Unauthorized Disclosure of Information, Unauthorized Modification
- [security bulletin] HPSBUX02857 SSRT101103 rev.1 - HP-UX Running Java, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
- [SECURITY] [DSA 2653-1] icinga security update
- Re: Report OWASP WAF Naxsi bypass Vulnerability
- [slackware-security] dhcp (SSA:2013-086-02)
- From: Slackware Security Team
- [slackware-security] bind (SSA:2013-086-01)
- From: Slackware Security Team
- Path Traversal in AWS XMS
- McAfee Virtual Technician ActiveX Control Insecure Method
- [security bulletin] HPSBST02848 SSRT101112 rev.1 - HP XP P9000 Command View Advanced Edition Suite Products, Remote Disclosure of Information
- Cisco Security Advisory: Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software IP Service Level Agreement Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Protocol Translation Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Smart Install Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Network Address Translation Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Internet Key Exchange Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Resource Reservation Protocol Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- ESA-2013-018: EMC Smarts Product - Cross Site Scripting Vulnerability
- WordPress podPress Plugin XSS in SWF
- AST-2013-001: Buffer Overflow Exploit Through SIP SDP Header
- From: Asterisk Security Team
- AST-2013-002: Denial of Service in HTTP server
- From: Asterisk Security Team
- AST-2013-003: Username disclosure in SIP channel driver
- From: Asterisk Security Team
- Workshop Proposal/Paper Submission Deadlines
- [SECURITY] [DSA 2655-1] rails security update
Mail converted by MHonArc