Mail Index
- [SECURITY] [DSA 2850-1] libyaml security update
- From: Salvatore Bonaccorso
- CVE-2014-1213 - Denial of Service in Sophos Anti Virus
- [SECURITY] [DSA 2851-1] drupal6 security update
- From: Salvatore Bonaccorso
- Security advisory, LedgerSMB 1.3.0-1.3.36
- [slackware-security] pidgin (SSA:2014-034-01)
- From: Slackware Security Team
- Security Advisory: NETGEAR Router D6300B Firmware: V1.0.0.14_1.0.14
- ESA-2014-005: EMC Documentum Foundation Services (DFS) Content Access Vulnerability
- Multiple SQL Injection Vulnerabilities in AuraCMS
- From: High-Tech Bridge Security Research
- SQL Injection in doorGets CMS
- From: High-Tech Bridge Security Research
- [SECURITY] [DSA 2853-1] horde3 security update
- Inteno DG301 Command Injection
- [ISecAuditors Security Advisories] Multiple reflected XSS vulnerabilities in Atmail WebMail
- From: ISecAuditors Security Advisories
- [SECURITY] [DSA 2855-1] libav security update
- [SECURITY] CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS
- German Telekom Bug Bounty #9 - Code Execution Vulnerability
- CVE-2014-1214 - Remote Code Execution in Projoom NovaSFH Plugin
- German Telekom Bug Bounty #10 - Arbitrary File Upload Vulnerability
- German Telekom Bug Bounty #11 - Remote SQL Injection Vulnerability
- AlienVault OSSIM SQL Injection vulnerability
- CORE-2014-0001 - Publish-It Buffer Overflow Vulnerability
- From: CORE Advisories Team
- [SECURITY] [DSA 2852-1] libgadu security update
- Information on recently-fixed Oracle VM VirtualBox vulnerabilities
- gpEasy v4.3.x CMS - Multiple Web Vulnerabilities
- Facebook Bug Bounty #12 - Client Side Exception Web Vulnerability
- WHMCS Denial of Service Vulnerability
- [SECURITY] [DSA 2856-1] libcommons-fileupload-java security update
- [oCERT-2014-001] MantisBT input sanitization errors
- [SECURITY] [DSA 2857-1] libspring-java security update
- [slackware-security] mozilla-firefox (SSA:2014-039-01)
- From: Slackware Security Team
- #CONFidence 2014- Call for Papers, only 0111 days left to become CONFidence ninja
- [slackware-security] seamonkey (SSA:2014-039-03)
- From: Slackware Security Team
- ASUS AiCloud Enabled Routers 12 Models - Authentication bypass and Sensitive file/path disclosure
- [slackware-security] mozilla-thunderbird (SSA:2014-039-02)
- From: Slackware Security Team
- Phpbb Forum Denial of Service Vulnerability
- Open-Xchange Security Advisory 2014-02-10
- [SECURITY] [DSA 2858-1] iceweasel security update
- [SECURITY] [DSA 2859-1] pidgin security update
- [mwrlabs advisory][CVE-2014-0748] Cray Aprun/Apinit Privilege Escalation
- Wordpress all_in_one_carousel Plugin /XSS/CSRF/ Vuln
- WiFi Camera Roll v1.2 iOS - Multiple Web Vulnerabilities
- [ MDVSA-2014:025 ] pidgin
- [SECURITY] [DSA 2860-1] parcimonie security update
- From: Salvatore Bonaccorso
- [CVE-2014-1903] FreePBX 2.9 through 12 RCE
- [SECURITY] [DSA 2850-2] libyaml regression update
- From: Salvatore Bonaccorso
- jDisk (stickto) v2.0.3 iOS - Multiple Web Vulnerabilities
- [ MDVSA-2014:026 ] openldap
- Mybb All Version Denial of Service Vulnerability
- APPLE-SA-2014-02-11-1 Boot Camp 5.1
- From: Apple Product Security
- ASUS RT Series Routers FTP Service - Default anonymous access
- [ MDVSA-2014:027 ] php
- Re: ASUS RT Series Routers FTP Service - Default anonymous access
- Wordpress plugin Buddypress <= 1.9.1 stored xss vulnerability
- Wordpress plugin Buddypress <= 1.9.1 privilege escalation vulnerability
- [ISecAuditors Security Advisories] - Reflected XSS vulnerability in Boxcryptor (www.boxcryptor.com)
- From: ISecAuditors Security Advisories
- Critical security flaws in Nagios NRPE client/server crypto
- RE: CVE-2014-1219 - Unauthenticated Privilege Escalation in CA 2E Web Option
- [ MDVSA-2014:028 ] mariadb
- [slackware-security] ntp (SSA:2014-044-02)
- From: Slackware Security Team
- [slackware-security] curl (SSA:2014-044-01)
- From: Slackware Security Team
- [ MDVSA-2014:029 ] mysql
- ESA-2014-009: RSA BSAFE® SSL-J Multiple Vulnerabilities
- [ MDVSA-2014:034 ] yaml
- [ MDVSA-2014:031 ] drupal
- [ MDVSA-2014:033 ] socat
- [ MDVSA-2014:032 ] flite
- CISTI'2014: List of Workshops
- [SWRX-2014-001] Open Web Analytics Pre-Auth SQL Injection
- phpMyBackupPro-2.4 Cross-Site Scripting vulnerability
- Full Disclosure - Linksys EA2700, EA3500, E4200 and EA4500 - Authentication Bypass to Administrative Console
- Office Assistant Pro v2.2.2 iOS - File Include Vulnerability
- mbDriveHD v1.0.7 iOS - Multiple Web Vulnerabilities
- File Hub v1.9.1 iOS - Multiple Web Vulnerabilities
- [SECURITY] [DSA 2861-1] file security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2862-1] chromium-browser security update
- Jetro Cockpit Secure Browsing vulnerability - Client missing input validation allowing RCE
- My PDF Creator & DE DM v1.4 iOS - Multiple Vulnerabilities
- [ MDVSA-2014:035 ] libpng
- [ MDVSA-2014:036 ] varnish
- Recon 2014 Call For Papers - June 27-29, 2014 - Montreal, Quebec
- [ MDVSA-2014:037 ] ffmpeg
- [ MDVSA-2014:038 ] kernel
- Re: [Full-disclosure] CVE-2013-1643 - Unauthorised Access To Other Users Email Messages in Symantec PGP Universal Web Messenger
- SEC Consult SA-20140218-0 :: Multiple critical vulnerabilities in Symantec Endpoint Protection
- From: SEC Consult Vulnerability Lab
- [ MDVSA-2014:040 ] puppet
- CVE-2014-1215 - Local Code Execution in CoreFTP Core FTP Server
- From: Portcullis Advisories
- [SECURITY] [DSA 2863-1] libtar security update
- [ MDVSA-2014:039 ] libgadu
- CA20140218-01: Security Notice for CA 2E Web Option
- [ MDVSA-2014:041 ] python
- [ MDVSA-2014:043 ] gnutls
- [ MDVSA-2014:042 ] tomcat6
- Barracuda Message Archiver 650 - Persistent Web Vulnerability
- Cisco Security Advisory: Cisco UCS Director Default Credentials Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Firewall Services Module Cut-Through Proxy Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Unauthorized Access Vulnerability in Cisco Unified SIP Phone 3905
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco IPS Software
- From: Cisco Systems Product Security Incident Response Team
- Post Exploitation - Getting username and password in the Lotus Sametime 8.5.1
- From: adrianomarciomonteiro
- [ MDVSA-2014:044 ] zarafa
- VideoCharge Studio v2.12.3.685 cc.dll CHTTPResponse::GetHttpResponse() Buffer Overflow Remote Code Execution
- [HITB-Announce] Haxpo CFP
- [slackware-security] kernel (SSA:2014-050-03)
- From: Slackware Security Team
- [slackware-security] mariadb, mysql (SSA:2014-050-02)
- From: Slackware Security Team
- SQL Injection in AdRotate
- From: High-Tech Bridge Security Research
- [ MDVSA-2014:045 ] libtar
- Android & iOS Hands-on Exploitation at SyScan 2014
- [SECURITY] [DSA 2864-1] postgresql-8.4 security update
- [CVE-2014-2035] XSS in InterWorx Web Control Panel <= 5.0.12
- [slackware-security] gnutls (SSA:2014-050-01)
- From: Slackware Security Team
- [SECURITY] [DSA 2865-1] postgresql-9.1 security update
- ASUS router drive-by code execution via XSS and authentication bypass
- Barracuda Bug Bounty #36 Firewall - Client Side Exception Handling Web Vulnerability
- [ MDVSA-2014:046 ] phpmyadmin
- CNNVD Gov CN #1 - Filter Bypass & Persistent Web Vulnerability
- [ MDVSA-2014:047 ] postgresql
- 44CON 2014 September 11th - 12th CFP Open
- CVE-2014-1223 - Cross-site Scripting in Telligent Evolution
- From: Portcullis Advisories
- APPLE-SA-2014-02-21-1 iOS 6.1.6
- From: Apple Product Security
- APPLE-SA-2014-02-21-2 iOS 7.0.6
- From: Mihaela Popescu-Stanesti
- APPLE-SA-2014-02-21-3 Apple TV 6.0.2
- From: Mihaela Popescu-Stanesti
- APPLE-SA-2014-02-21-2 iOS 7.0.6
- From: Apple Product Security
- APPLE-SA-2014-02-21-1 iOS 6.1.6
- From: Apple Product Security
- APPLE-SA-2014-02-21-3 Apple TV 6.0.2
- From: Apple Product Security
- DC4420 - London DEFCON - meeting Tuesday, 25th February 2014
- [SECURITY] [DSA 2866-1] gnutls26 security update
- From: Salvatore Bonaccorso
- [CISTI'2014]: Iberian Conference on IST; Barcelona; Deadline: February 28
- [SECURITY] [DSA 2867-1] otrs2 security update
- From: Salvatore Bonaccorso
- Barracuda Networks Bug Bounty #35 - Persistent Web Vulnerability
- WiFiles HD v1.3 iOS - File Include Web Vulnerability
- [security bulletin] HPSBMU02964 rev.1 - HP Service Manager, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access, Disclosure of Information and Authentication Issues
- [security bulletin] HPSBST02937 rev.1 - HP StoreVirtual 4000 and StoreVirtual VSA Software dbd_manager, Remote Execution of Arbitrary Code
- [security bulletin] HPSBMU02971 rev.1 - HP Application Information Optimizer, Remote Execution of Code, Information Disclosure
- [SECURITY] CVE-2014-0033 Session fixation still possible with disableURLRewriting enabled
- [SECURITY] CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service)
- [SECURITY] CVE-2013-4590 Information disclosure via XXE when running untrusted web applications
- [SECURITY] CVE-2013-4286 Incomplete fix for CVE-2005-2090 (Information disclosure)
- Barracuda Networks Firewall Bug Bounty #32 - Filter Bypass & Persistent Web Vulnerabilities
- [RT-SA-2014-001] McAfee ePolicy Orchestrator: XML External Entity Expansion in Dashboard
- From: RedTeam Pentesting GmbH
- APPLE-SA-2014-02-25-1 OS X Mavericks 10.9.2 and Security Update 2014-001
- From: Apple Product Security
- APPLE-SA-2014-02-25-2 Safari 6.1.2 and Safari 7.0.2
- From: Apple Product Security
- [security bulletin] HPSBPI02869 SSRT100936 rev.3 - HP LaserJet MFP Printers, HP Color LaserJet MFP Printers, Certain HP LaserJet Printers, Remote Unauthorized Access to Files
- [security bulletin] HPSBMU02966 rev.1 - HP Operations Orchestration, Unauthorized Access to Information
- [security bulletin] HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software Security - Apache Tomcat and Oracle Updates
- APPLE-SA-2014-02-25-3 QuickTime 7.7.5
- From: Apple Product Security
- Authentication-Bypass in CosmoShop ePRO V10.17.00 (and lower, maybe higher)
- Persistent XSS in Media File Renamer V1.7.0 wordpress plugin
- From: Larry W. Cashdollar
- Barracuda Networks Bug Bounty #31 Firewall - Persistent Access Policy Vulnerability
- Cisco Security Advisory: Cisco Prime Infrastructure Command Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Barracuda Networks Backup Appliance Application - Persistent Web Vulnerability
- Office 365 - Account Hijacking Cookie Re-Use Flaw, extended
- Update: CVE-2014-0053 Information Disclosure when using Grails
- From: Pivotal Security Team
- SEC Consult SA-20140227-0 :: Local Buffer Overflow vulnerability in SAS for Windows (Statistical Analysis System)
- From: SEC Consult Vulnerability Lab
- Multiple Vulnerabilities in VideoWhisper Live Streaming Integration WP Plugin
- From: High-Tech Bridge Security Research
- [slackware-security] subversion (SSA:2014-058-01)
- From: Slackware Security Team
- SEC Consult SA-20140228-0 :: Privilege escalation vulnerability in MICROSENS Profi Line Modular Industrial Switch
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20140228-1 :: Authentication bypass (SSRF) and local file disclosure in Plex Media Server
- From: SEC Consult Vulnerability Lab
Mail converted by MHonArc