Mail Index
- Re: [FD] Cisco AnyConnect elevation of privileges via DLL side loading
- Re: [FD] Cisco AnyConnect elevation of privileges via DMG install script
- [FD] Tool: Race condition chaser on windows
- [FD] CVE-2015-2342 VMware vCenter Remote Code Execution
- [FD] Telegram - Multiple Vulnerabilities
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] Shell Injection in Pygments FontManager._get_nix_font_path
- [FD] Vulnerabilities in Callisto 821+R3 ADSL Router
- [FD] Mac OS X local root (rsh/libmalloc)
- [FD] APPLE-SA-2015-09-30-01 iOS 9.0.2
- From: Apple Product Security
- [FD] APPLE-SA-2015-09-30-2 Safari 9
- From: Apple Product Security
- [FD] APPLE-SA-2015-09-30-3 OS X El Capitan 10.11
- From: Apple Product Security
- [FD] Komento Joomla! component Persistent XSS
- [FD] Charter Spectrum Business HTTP MITM
- [FD] Sicherheitslücke - Liferay Portal Enterprise Edition
- [FD] ManageEngine ServiceDesk Plus <= 9.1 build 9110 - Path Traversal
- [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- [FD] Qualys Security Advisory - OpenSMTPD Audit Report
- From: Qualys Security Advisory
- [FD] CVE-2015-6237 - Tripwire IP360 VnE Remote Administrative API Authentication Bypass/Privilege Acquisition Vulnerability
- Re: [FD] Telegram - Multiple Vulnerabilities
- [FD] Apple Safari URI spoofing (CVE-2015-5764)
- [FD] WinRar Settings Import Command Execution
- [FD] Persistent XSS - Liferay Portal Enterprise Edition
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] Blind SQL Injection in admin panel PHP-Fusion <= v7.02.07
- From: Manuel Garcia Cardenas
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- [FD] u-design wordpress theme DOM XSS
- [FD] DDos Attack To Drop The Internet
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] Authentication Bypass in Netgear Router Firmware N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img
- Re: [FD] Authentication Bypass in Netgear Router Firmware N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img
- Re: [FD] Authentication Bypass in Netgear Router Firmware N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img
- [FD] [REVIVE-SA-2015-001] Revive Adserver - Multiple vulnerabilities
- [FD] CSRF vulnerabilities in Callisto 821+R3 ADSL Router
- [FD] TestLink Security Advisory - SQL Injection Vulnerability - CVE-2015-7390
- [FD] TestLink Security Advisory - Multiple XSS Vulnerabilities - CVE-2015-7391
- [FD] CVE-2015-2652 – Unauthenticated File Upload in Oracle E-business Suite.
- [FD] Drupal 8.0.0-beta14 Vendor Script Vulnerable to XSS
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] A comprehensive study of Huawei 3G routers - XSS, CSRF, DoS, unauthenticated firmware update, RCE
- Re: [FD] DDos Attack To Drop The Internet
- Re: [FD] DDos Attack To Drop The Internet
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- [FD] [RT-SA-2015-006] Buffalo LinkStation Authentication Bypass
- From: RedTeam Pentesting GmbH
- [FD] Veeam Backup & Replication Local Privilege Escalation Vulnerability
- [FD] Broken, Abandoned, and Forgotten Code, Part 13
- [FD] WebComIndia CMS 2015Q4 - Auth Bypass Vulnerability
- [FD] PayPal Inc Bug Bounty #119 - URL Redirect Web Vulnerability
- [FD] W150D Wireless N 150 ADSL2 Modem Router - Cross Site Request Forgery Vulnerability
- [FD] FreeYouTubeToMP3 Converter 4.0.1 - Buffer Overflow Vulnerability
- [FD] Exploit NetUSB CVE-2015-3036
- [FD] DirectAdmin (1.44.3) CSRF Vulnerability
- [FD] Writing Cisco IOS Rootkits
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] JScript 5.7 (MSIE 8) RegExpBase::FBadHeader regular expression use-after-free
- [FD] Buffer overflow in tiny-AES128-C
- [FD] Vantage Point Security Advisory 2015-003
- [FD] Vantage Point Security Advisory 2015-002
- [FD] IntelliSec Advisory - Multiple Vulnerabilities in Kerio Control Firewall
- [FD] Full Path Disclosure vulnerability in JM Twitter Cards reveals the location of the WordPress installation on the server (WordPress plugin)
- [FD] Mozilla extensions: a security nightmare (part 2)
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- [FD] PayPal Inc Bug Bounty #117 - Session Fixation Vulnerability
- [FD] Freemake Video Downloader 3.7.1 - Code Execution Vulnerability
- [FD] Unicorn CPU Emulator Framework is out!
- [FD] hackercon berlin: hack4 the year is 2015
- [FD] netis RealTek wireless router / ADSL modem Multiple Vulnerabilities
- [FD] PROLiNK H5004NK ADSL Wireless Modem Multiple Vulnerabilities
- [FD] UISGCON11 CFP
- [FD] CakePHP Xml class SSRF Vulnerability
- [FD] APPLE-SA-2015-10-15-1 Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
- From: Apple Product Security
- Re: [FD] Watch your Downloads: the risk of the "auto-download" feature on Microsoft Edge and Google Chrome
- [FD] Qualys Security Advisory - LibreSSL (CVE-2015-5333 and CVE-2015-5334)
- From: Qualys Security Advisory
- [FD] Events Made Easy WordPress plugin CSRF + Persistent XSS
- [FD] ERPSCAN Research Advisory [ERPSCAN-15-017] SAP NetWeaver J2EE DAS service - Unauthorized Access
- [FD] CarolinaCon-12 - March 2016 - Call for Speakers/Papers/Presenters/Demos
- [FD] Western Digital - My Passport / My Book self-encrypting external hard drive series - Multiple vulnerabilities
- [FD] Seagate Central NAS vulnerabilities
- Re: [FD] WinRAR SFX v5.21 - Remote Code Execution Vulnerability
- [FD] Firefox FindMyDevice Critical ClickJacking Security Vulnerability
- [FD] [SE-2014-02] Google App Engine Java security sandbox bypasses (Issue 42)
- From: Security Explorations
- [FD] APPLE-SA-2015-10-21-1 iOS 9.1
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-2 watchOS 2.0.1
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-3 Safari 9.0.1
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-4 OS X El Capitan 10.11.1 and Security Update 2015-007
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-5 iTunes 12.3.1
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-6 Mac EFI Security Update 2015-002
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-7 Xcode 7.1
- From: Apple Product Security
- [FD] APPLE-SA-2015-10-21-8 OS X Server 5.0.15
- From: Apple Product Security
- [FD] SiteWIX - (edit_photo2.php id) SQL Injection Exploit
- [FD] Simple PHP static code analysis for security researchers
- [FD] SEC Consult SA-20151022-0 :: Lime Survey Multiple Critical Vulnerabilities
- From: SEC Consult Vulnerability Lab
- [FD] Back to the future NTP attacks new attack vector
- [FD] Back to the future EMV attacks
- [FD] [ERPSCAN-15-025] Oracle E-Business Suite Database user enumeration Vulnerability
- [FD] [ERPSCAN-15-026] Oracle E-Business Suite - SQL injection Vulnerability
- [FD] [ERPSCAN-15-027] Oracle E-Business Suite - Cross Site Scripting Vulnerability
- [FD] AoF and CSRF vulnerabilities in D-Link DCS-2103
- [FD] Timing attack vulnerability in most Zeus server-sides
- [FD] RootedCON 2016 CFP
- [FD] CVE-2015-7724 - Privilege Escalation Via Symlink Attacks On POSIX Shared Memory With Insecure Permissions In AMD fglrx-driver
- From: Portcullis Advisories
- [FD] CVE-2015-7723 - Privilege Escalation Via Symlink Attacks On POSIX Shared Memory With Insecure Permissions In AMD fglrx-driver
- From: Portcullis Advisories
- [FD] eBay Magento <= 1.9.2.1 XML eXternal Entity Injection (XXE) on PHP FPM
- [FD] KeeFarce - A KeePass 2.x database extraction tool
- [FD] Pligg CMS 2.0.2: Code Execution & CSRF
- [FD] Pligg CMS 2.0.2: Directory Traversal
- [FD] Pligg CMS 2.0.2: Multiple SQL Injections
- [FD] [ERPSCAN-15-028] Oracle E-Business Suite - XXE injection Vulnerability
- [FD] [ERPSCAN-15-029] Oracle E-Business Suite - XXE injection Vulnerability
- [FD] [ERPSCAN-15-030] Oracle E-Business Suite - XXE injection Vulnerability
- [FD] Xen VM Escape
- [FD] Arbitrary code execution resp. escalation of privilege with Mozilla's SETUP.EXE
Mail converted by MHonArc