Mail Index
- Re: [FD] Safari Address Spoofing (How We Got It)
- [FD] [CFP] SOURCE Dublin, Sept 5-8, Trinity College
- From: Genevieve Southwick
- [FD] Freebox OS Web interface 3.0.2 XSS, CSRF
- [FD] Call for Papers for 3rd Balkan Computer Congress – BalCCon2k15
- [FD] t2'15: Call for Papers 2015 (Helsinki / Finland)
- [FD] WebDrive 12.2 (B4172) - Buffer Overflow Vulnerability
- Re: [FD] Safari Address Spoofing (How We Got It)
- Re: [FD] Safari Address Spoofing (How We Got It)
- Re: [FD] Safari Address Spoofing (How We Got It)
- [FD] [Multiple CVE's]: various critical vulnerabilities in SysAid Help Desk (RCE, file download, DoS, etc)
- [FD] [CVE-2015-1234] Tanium all versions arbitrary file overwrite
- [FD] [CVE-2015-4051]: Beckhoff IPC diagnostics < 1.8 : Authentication bypass
- From: The Security Factory
- [FD] Broken, Abandoned, and Forgotten Code, Part 7
- [FD] 1 Click Audio Converter v2.3.6 - Activex Buffer Overflow
- [FD] 1 Click Audio Converter v2.3.6 - Activex Buffer Overflow
- [FD] 1 Click Extract Audio v2.3.6 - Activex Buffer Overflow
- [FD] NEW VMSA-2015-0004 - VMware Workstation, Fusion and Horizon View Client updates address critical security issues
- From: VMware Security Response Center
- [FD] [call for paper] SIGIR workshop: privacy-preserving information retrieval
- Re: [FD] [CVE-2015-1234] Tanium all versions arbitrary file overwrite
- [FD] Xloner v3.1.2 wordpress plugin authenticated command execution and XSS
- From: Larry W. Cashdollar
- [FD] [CVE-2015-4342]SQL Injection and Location header injection from cdef id
- [FD] Broken, Abandoned, and Forgotten Code, Intermission
- [FD] Fwd: Potentially critical buffer overflow in TinySRP
- [FD] [RT-SA-2015-003] Alcatel-Lucent OmniSwitch Web Interface Weak Session ID
- From: RedTeam Pentesting GmbH
- [FD] [RT-SA-2015-004] Alcatel-Lucent OmniSwitch Web Interface Cross-Site Request Forgery
- From: RedTeam Pentesting GmbH
- [FD] Heroku Bug Bounty #2 - (API) Re Auth Session Bypass Vulnerability
- [FD] This POODLE Bites: Exploiting The SSL 3.0 Fallback
- [FD] Remote file upload vulnerability in aviary-image-editor-add-on-for-gravity-forms v3.0beta Wordpress plugin
- From: Larry W. Cashdollar
- [FD] Authentication Bypass in Pandora FMS
- [FD] 2 vulns 1 line in RNCryptor (PHP) + Call to Action
- [FD] [KIS-2015-01] Concrete5 <= 5.7.3.1 (sendmail) Remote Code Execution Vulnerability
- [FD] [KIS-2015-02] Concrete5 <= 5.7.3.1 Multiple Reflected Cross-Site Scripting Vulnerabilities
- [FD] [KIS-2015-03] Concrete5 <= 5.7.4 (Access.php) SQL Injection Vulnerability
- [FD] Apache vulnerability program faulting module ntdll.dll
- [FD] SAP Security Notes June 2015
- [FD] 6kbbs v8.0 Weak Encryption Cryptography Security Vulnerabilities
- [FD] FC2 & Rakuten Online Websites Multiple XSS (Cross-site Scripting) and Open Redirect Cyber Vulnerabilities
- [FD] Path Traversal vulnerability in Wordpress plugin se-html5-album-audio-player v1.1.0
- From: Larry W. Cashdollar
- [FD] D-Link DSP-W110 - multiple vulnerabilities
- [FD] XSS vulnerability Adobe Connect 9.3 (CVE-2015-0343 )
- [FD] The token order of OpVectorTimesScalar and OpMatrixTimesScalar which generated in glslangValidator isn't consistant with SPEC
- [FD] Yoast Wordpress SEO Plugin <= 2.1.1 Stored, Authenticated XSS
- [FD] OpenBSD "sys_execve()" Executable Header Parsing Denial of Service Vulnerability
- [FD] E-Detective Lawful Interception System - multiple security vulnerabilities
- [FD] [RT-SA-2015-002] SQL Injection in TYPO3 Extension Akronymmanager
- From: RedTeam Pentesting GmbH
- [FD] Cross-Site Request Forgery Vulnerability in Users to CSV Wordpress Plugin v1.4.5
- [FD] eBay Security Assessment
- Re: [FD] Announcing NorthSec 2015 - Montreal, May 21-24
- [FD] [CVE-2015-4553]Dedecms variable coverage leads to getshell
- [FD] CVE-2015-4453 - Authentication bypass in OpenEMR
- [FD] SpiderOak.com - Disclousure of sensitive information
- [FD] Broken, Abandoned, and Forgotten Code, Part 8
- [FD] ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
- [FD] ZTE ZXV10 W300 v3.1.0c_DR0 - UI Session Delete Vulnerability
- [FD] Ebay Magento Bug Bounty #17 - Client Side Cross Site Scripting Web Vulnerability
- [FD] Ebay Magento Bug Bounty #10 - Persistent Filename Vulnerability
- [FD] Ebay Magento Bug Bounty #12 - Cross Site Request Forgery Web Vulnerability
- [FD] IBM Domino Web Server Cross-site Scripting Vulnerability (CVE-2015-1981)
- [FD] Cross-Site Request Forgery in Google Analyticator Wordpress Plugin v6.4.9.3 before rev @1183563
- [FD] Tutanota Encrypted Email service - Malleable Ciphertext (AES-CBC with no MAC)
- [FD] [Survey] Help shape the future of IDSs
- From: Antonio Augusto Santos
- [FD] ManageEngine Asset Explorer v6.1 - Persistent Vulnerability
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-003] SAP NetWeaver Dispatcher Buffer Overflow - RCE, DoS
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-004] SAP NetWeaver Portal XMLValidationComponent - XXE
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-005] SAP Mobile Platform - XXE
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-006] SAP NetWeaver Portal ReportXmlViewer - XXE
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-007] SAP Management Console ReadProfile Parameters - Information disclosure
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-008] SAP Afaria 7 XcListener - DoS in the module XeClient.Dll
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-009] SAP Afaria 7 XcListener - Missing authorization check
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-010] SYBASE SQL Anywhere 12 and 16 - DoS
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-011] SAP Mobile Platform 3.0 - XXE
- [FD] CVE-2015-4413 - Wordpress “Nextend Facebook Connect” Cross Site Scripting
- [FD] CVE-2015-4557 - Wordpress “Nextend Twitter Connect” & “Nextend Google Connect” Cross Site Scripting
- [FD] New version: smalisca - Static Code Analysis tool for Smali files
- [FD] Minds.com - Several Issues
- [FD] XSS vulnerability in manage engine.
- [FD] Haka v0.3.0 release
- [FD] ROP 101 Blog
- [FD] Securing SAP Systems from XSS vulnerabilities Part 2: Defense for SAP NetWeaver ABAP
- [FD] CVE-2015-3443 XSS in Thycotic Secret Server version 8.6.000000 to 8.8.000004
- [FD] Recomendation: Flaw in K9 Web Protection 4.4.268
- [FD] SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILS
- From: Raschin Ghanad-Tavakoli
- [FD] SEC Consult SA-20150626-0 :: Critical vulnerabilities in Polycom RealPresence Resource Manager (RPRM) allow surveillance on conferences
- From: SEC Consult Vulnerability Lab
- [FD] Remote file download vulnerability in download-zip-attachments v1.0
- From: Larry W. Cashdollar
- [FD] Arbitrary File download in wordpress plugin wp-instance-rename v1.0
- From: Larry W. Cashdollar
- [FD] Response to Decision Group press release about security vulnerabilities in E-Detective Lawful Interception System
- Re: [FD] Response to Decision Group press release about security vulnerabilities in E-Detective Lawful Interception System
- [FD] WedgeOS Multiple Vulnerabilities
- [FD] Watchguard XCS Multiple Vulnerabilities
- [FD] Courier mail server: Write heap overflow in mailbot tool and out of bounds heap read in imap folder parser
- [FD] CollabNet Subversion Edge Hook Script Privilege Escalation
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge Password Hash Leak
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge downloadHook local file inclusion
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge show local file inclusion
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge tail local file inclusion
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge insecure password change
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge missing brute force protection
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge autocomplete on
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge missing clickjacking protection
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge weak password policy
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge missing XSRF protection
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge weak password storage mechanism
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge missing single login restriction
- From: Oliver-Tobias Ripka
- [FD] CollabNet Subversion Edge index local file inclusion
- From: Oliver-Tobias Ripka
- [FD] XXE Injection in NetIQ Access
Mail converted by MHonArc