Bugtraq (date)
October 30, 2004
- Re: New URL spoofing bug in Microsoft Internet Explorer, http-equiv@excite.com , 18:09
- RE: New URL spoofing bug in Microsoft Internet Explorer, Larry Seltzer, 16:29
- [VulnWatch] bogofilter-SA-2004-01: RFC 2047 Denial-of-service in 0.17.4 <= bogofilter <= 0.92.7, Matthias Andree, 13:18
- Re: New URL spoofing bug in Microsoft Internet Explorer, 0-1-2-3, 07:15
- Re: New URL spoofing bug in Microsoft Internet Explorer, GuidoZ, 06:55
- Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?, Michael Engert, 06:15
- Re: New URL spoofing bug in Microsoft Internet Explorer, GuidoZ, 03:24
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Chris Paget, 03:04
- Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?, André Malo, 01:23
- Re: New URL spoofing bug in Microsoft Internet Explorer, Jérôme, 00:53
October 29, 2004
- Re: New URL spoofing bug in Microsoft Internet Explorer, Christopher J. Pilkington, 23:42
- RE: Update: Web browsers - a mini-farce (MSIE gives in), David Brodbeck, 22:52
- Re: Update: Web browsers - a mini-farce (MSIE gives in), infamous41md, 22:12
- RE: Update: Web browsers - a mini-farce (MSIE gives in), Tim Newsham, 21:42
- RE: Update: Web browsers - a mini-farce (MSIE gives in), Tim Newsham, 21:11
- Re: New URL spoofing bug in Microsoft Internet Explorer, GuidoZ, 21:01
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Michael Shigorin, 20:41
- Re: debian dhcpd, old format string bug, infamous41md, 20:31
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Valdis . Kletnieks, 20:01
- RE: libgd integer overflow, infamous41md, 19:00
- RE: New URL spoofing bug in Microsoft Internet Explorer, Larry Seltzer, 18:00
- Re: libgd integer overflow, Richard Dawe, 17:30
- local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?, Larry Cashdollar, 16:19
- Re: Mozilla Firefox (tested on 0.9.3) html-code crash., Michal Zalewski, 15:48
- [Full-Disclosure] [ GLSA 200410-31 ] Archive::Zip: Virus detection evasion, Thierry Carrez, 13:26
- [Full-Disclosure] [USN-12-1] ppp Denial of Service, Martin Pitt, 12:55
- [Full-Disclosure] [USN-11-1] libgd2 vulnerabilities, Martin Pitt, 11:24
- [USN-6-1] postgresql contributed script vulnerability, Martin Pitt, 03:40
- Re: Mozilla Firefox (tested on 0.9.3) html-code crash., Crispin Cowan, 00:08
October 28, 2004
- Re: debian dhcpd, old format string bug, Tarragon Allen, 23:48
- New URL spoofing bug in Microsoft Internet Explorer, 0-1-2-3, 22:27
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Valdis . Kletnieks, 19:56
- RE: Update: Web browsers - a mini-farce (MSIE gives in), Michael Wojcik, 19:15
- RE: Update: Web browsers - a mini-farce (MSIE gives in), David Brodbeck, 16:12
- Re: Update: Web browsers - a mini-farce (MSIE gives in), MCMuir, 15:51
- Re: Some Voters Say Machines Failed, Incorrect Choices Appear on Screens (fwd), Paul Schmehl, 15:10
- PHP4 cURL functions bypass open_basedir, FraMe, 15:00
- Re: zgv image viewing heap overflows, Chris Frey, 14:40
- [SECURITY] [DSA 575-1] New catdoc packages fix temporary file vulnerability, Martin Schulze, 14:19
- Presentation: Bypassing client application protection techniques with notepad, 3APA3A, 13:49
- [Full-Disclosure] [USN-4-1] Standard C library script vulnerabilities, Martin Pitt, 10:26
- [Full-Disclosure] [USN-9-1] tetex-bin vulnerabilities, Martin Pitt, 10:16
- [Full-Disclosure] [ GLSA 200410-30 ] GPdf, KPDF, KOffice: Vulnerabilities in included xpdf, Thierry Carrez, 06:24
- High Risk Vulnerability in RealPlayer, NGSSoftware Insight Security Research, 04:24
- [security bulletin] SSRT3526 Serviceguard potential increase in privilege, Boren, Rich (SSRT), 02:03
October 27, 2004
- High Risk Vulnerability in Quicktime for Windows, NGSSoftware Insight Security Research, 23:31
- Multiple Vulnerabilites in Quake II Server, Richard Stanway, 23:21
- EEYE: RealPlayer Zipped Skin File Buffer Overflow, Marc Maiffret, 22:41
- RE: Update: Web browsers - a mini-farce (MSIE gives in), Michael Wojcik, 22:10
- MMDF deliver local root exploit for SCO OpenServer 5.0.7 x86, Ramon de Carvalho Valle, 20:59
- [Full-Disclosure] [ GLSA 200410-29 ] PuTTY: Pre-authentication buffer overflow, Sune Kloppenborg Jeppesen, 20:39
- iDEFENSE Security Advisory 10.27.04 - PuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability, customer service mailbox, 19:08
- [CLA-2004:880] Conectiva Security Announcement - foomatic-filters, Conectiva Updates, 18:37
- [CLA-2004:879] Conectiva Security Announcement - kernel, Conectiva Updates, 16:26
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Valdis . Kletnieks, 16:06
- PuTTY SSH client vulnerability, Anatole Shaw, 15:35
- Crashs in Master of Orion III 1.2.5, Luigi Auriemma, 15:15
- RE: Update: Web browsers - a mini-farce (MSIE gives in), Michael Wojcik, 14:55
- [Full-Disclosure] [ GLSA 200410-28 ] rssh: Format string vulnerability, Thierry Carrez, 13:54
- [Full-Disclosure] [ GLSA 200410-27 ] mpg123: Buffer overflow vulnerabilities, Kurt Lieber, 11:13
- [Full-Disclosure] [FLSA-2004:2089] Updated mozilla packages fix security vulnerabilities, Dominic Hargreaves, 10:03
- debian dhcpd, old format string bug, infamous41md, 09:12
- Re: Update: Web browsers - a mini-farce (MSIE gives in), Valdis . Kletnieks, 07:52
- Rendering large binary file as HTML makes Mozilla Firefox stop responding, Peter Kruse, 06:21
- zgv image viewing heap overflows, infamous41md, 05:41
- [Full-Disclosure] [USN-5-1] gettext vulnerabilities, Martin Pitt, 03:50
- [Full-Disclosure] [USN-8-1] gaim vulnerabilities, Martin Pitt, 03:50
- [Full-Disclosure] [USN-3-1] GhostScript utility script vulnerabilities, Martin Pitt, 03:40
- [Full-Disclosure] [USN-7-1] imagemagick vulnerability, Martin Pitt, 03:30
- Re: Some Voters Say Machines Failed, Incorrect Choices Appear on Screens (fwd), Valdis . Kletnieks, 03:30
- wvtfpd remote root heap overflow, infamous41md, 02:40
October 26, 2004
- pppd out of bounds memory access, possible DOS, infamous41md, 22:08
- Hawking Technologies HAR11A router considered insecure, Marcus Garvey, 20:27
- inetutils tftp client, DNS resolving bofs, infamous41md, 19:57
- libgd integer overflow, infamous41md, 19:27
- pacsec.jp advisory: Firewire/IEEE 1394 Considered Harmful to Physical Security, Dragos Ruiu, 16:35
- OpenSSL 0.9.7e released (fwd from mark@openssl.org), je, 16:15
- libxml2 remote buffer overflows (not in xml parsing code though), infamous41md, 16:15
- SUSE Security Announcement: xpdf, gpdf, kpdf, pdftohtml, cups (SUSE-SA:2004:039), Thomas Biege, 16:15
- MailCarrier 2.51 SMTP server Buffer Overflow [PoC included], Jirtme, 16:15
- [Full-Disclosure] PTms04-030, pigrelax, 16:14
- Two Vulnerabilities in OpenWFE Web Client, Joxean Koret, 16:14
- [Full-Disclosure] Posting w/o checking facts, Harry Hoffman, 16:14
- RE: Critical Vulnerability in Altiris Deployment Server architecture, Brooks, Shane, 16:14
- Re: CAN-2004-0814: Linux terminal layer races, Pavel Kankovsky, 16:14
- [CLA-2004:878] Conectiva Security Announcement - zlib, Conectiva Updates, 16:14
- Bug in hotmail, security, 16:14
- Re: How to Break Windows XP SP2 + Internet Explorer 6 SP2, michael evanchik, 16:14
- Fake RedHat - Fedora Security Patch / Trojan Source Code & Analysis, K-OTiK Security, 16:14
- Re: Update: Web browsers - a mini-farce (MSIE gives in), gabrield89, 16:14
- Mozilla Firefox (tested on 0.9.3) html-code crash., ducch apple, 16:14
- RE: Update: Web browsers - a mini-farce (MSIE gives in), David Brodbeck, 16:14
- Some Voters Say Machines Failed, Incorrect Choices Appear on Screens (fwd), Atom 'Smasher', 16:14
- Re: Is Windows up to snuff for running our world?, Thor, 16:14
- STG Security Advisory: [SSA-20041022-08] MoniWiki XSS vulnerability, advisory, 16:14
- [Full-Disclosure] [ GLSA 200410-26 ] socat: Format string vulnerability, Luke Macken, 16:14
- [Full-Disclosure] [ GLSA 200410-25 ] Netatalk: Insecure tempfile handling in etc2ps.sh, Luke Macken, 16:14
- [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2, David Miller, 16:13
- Re: Google Script Insertion Exploit, Jirtme, 16:13
- [Full-Disclosure] [ GLSA 200410-24 ] MIT krb5: Insecure temporary file use in send-pr.sh, Thierry Carrez, 16:13
- [Full-Disclosure] re: How to Break Windows XP SP2 + Internet Explorer 6 SP2, Michael Evanchik, 16:13
- Re: [Full-Disclosure] python does mangleme (with IE bugs!), Berend-Jan Wever, 16:13
- [Full-Disclosure] [ GLSA 200410-23 ] Gaim: Multiple vulnerabilities, Matthias Geerdsen, 16:13
- [Full-Disclosure] [ GLSA 200410-22 ] MySQL: Multiple vulnerabilities, Thierry Carrez, 16:13
- Re: [Full-Disclosure] Update: Web browsers - a mini-farce (MSIE gives in), Daniel Veditz, 16:13
- [Full-Disclosure] python does mangleme (with IE bugs!), ned, 16:13
- rssh: pizzacode security alert, Derek Martin, 16:12
- dwc_articles possible sql injection, Rene, 16:12
- [Full-Disclosure] [FLSA-2004:1947] Updated glibc packages fix flaws, Marc Deslauriers, 16:12
- [Full-Disclosure] [FLSA-2004:1719] Updated Tripwire packages fix security flaw, Marc Deslauriers, 16:12
- windows 2000 server terminal server denial of service, Nick Caramella, 16:12
- Re: Full path disclosure and sql injection on CubeCart 2.0.1, sculptex, 16:12
- Ability FTP Server 2.34 Buffer Overflow Exploit, Jérôme, 16:12
- [Full-Disclosure] [USN-1-1] PNG library vulnerabilities, Matt Zimmerman, 16:12
- [Full-Disclosure] [USN-2-1] xpdf vulnerabilities, Matt Zimmerman, 16:12
- Norton AntiVirus 2004/2005 Script Blocking Redux, Daniel Milisic, 16:12
- Windows DoS in certain pGina configurations, Steven, 16:12
- Is Windows up to snuff for running our world?, Richard M. Smith, 16:12
- [Full-Disclosure] Update: Web browsers - a mini-farce (MSIE gives in), Michal Zalewski, 16:12
- Hack Dot AE, Spy Hat, 16:12
- Re: avoiding stackguard, Crispin Cowan, 16:12
- [CLA-2004:877] Conectiva Security Announcement - mozilla, Conectiva Updates, 16:12
- iDEFENSE Security Advisory XX.XX.04 - Novell SuSe Linux LibTIFF Heap Overflow Vulnerability, customer service mailbox, 16:12
- [Full-Disclosure] AOL Journals BlogID incrementing discloses account names and e-mail, Steven, 16:12
- MDKSA-2004:113 - Updated xpdf packages fix vulnerabilities, Mandrake Linux Security Team, 15:05
- MDKSA-2004:116 - Updated cups packages fix DoS vulnerabilities, Mandrake Linux Security Team, 15:05
- MDKSA-2004:115 - Updated kdegraphics packages fix DoS vulnerability, Mandrake Linux Security Team, 15:05
- Re: [Full-Disclosure] Virus/Trojan trying to connect external:445 and 212.175.149.149.6667, darren windham, 15:05
- SuSE Security Announcement: libtiff (SUSE-SA:2004:038), Marcus Meissner, 15:05
- [Fwd: Altiris Carbon Copy Remote Control local SYSTEM exploitation.], KF_lists, 15:05
- MDKSA-2004:114 - Updated gpdf packages fix DoS vulnerability, Mandrake Linux Security Team, 15:05
October 22, 2004
- [Security Bulletin] SSRT4807 HP-UX stmkfont local unauthorized privileged access, Boren, Rich (SSRT), 13:14
- [KDE security advisory] Multiple integer overflows in kpdf, Dirk Mueller, 12:53
- MDKSA-2004:112 - Updated squid packages fix SNMP processing vulnerability, Mandrake Linux Security Team, 12:23
- [Full-Disclosure] J2ME security vulnerabilities, Adam Gowdiak, 11:03
- RE: [Full-Disclosure] Virus/Trojan trying to connect external:445 and 212.175.149.149.6667, Todd Towles, 10:52
- [Full-Disclosure] Virus/Trojan trying to connect external:445 and 212.175.149.149.6667, Murat Bicer, 06:41
- Re: Critical Vulnerability in Altiris Deployment Server architecture, KF_lists, 01:48
- Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS (Risk increased), Juan C Calderon, 01:18
October 21, 2004
- HTTP Response Splitting in Serendipity 0.7-beta4, Chaotic Evil, 23:58
- [Full-Disclosure] [HV-LOW] Unsafe WAV header handling can cause DoS on Windows, vuln, 23:17
- [Full-Disclosure] [ GLSA 200410-21 ] Apache 2, mod_ssl: Bypass of SSLCipherSuite directive, Kurt Lieber, 22:57
- MDKSA-2004:110 - Updated gaim packages fix vulnerabilities, Mandrake Linux Security Team, 22:47
- Re: [Full-Disclosure] cPanel check only the first 8 characters of webmail password, Evert Daman, 22:17
- MDKSA-2004:111 - Updated wxGTK2 packages fix vulnerabilities, Mandrake Linux Security Team, 20:56
- SQL Injection in UBB.threads 3.4.x, Florian Rock, 20:06
- [Full-Disclosure] cPanel check only the first 8 characters of webmail password, Andrey Bayora, 18:05
- SuSE Security Announcement: kernel (SUSE-SA:2004:037), Marcus Meissner, 14:43
- Critical Vulnerability in Altiris Deployment Server architecture, Brian Gallagher, 14:03
- [Full-Disclosure] [ GLSA 200410-20 ] Xpdf, CUPS: Multiple integer overflows, Thierry Carrez, 13:23
- CAN-2004-0814: Linux terminal layer races, Alan Cox, 13:13
- [Full-Disclosure] NSFOCUS SA2004-02 : HP-UX stmkfont Local Privilege Escalation Vulnerability, NSFOCUS Security Team, 12:12
- [Full-Disclosure] [ GLSA 200410-19 ] glibc: Insecure tempfile handling in catchsegv script, Luke Macken, 11:52
- MDKSA-2004:107 - Updated mozilla packages fix vulnerabilities, Mandrake Linux Security Team, 01:58
- mpg123 "getauthfromurl" buffer overflow, Carlos Barros, 01:37
October 20, 2004
- MDKSA-2004:108 - Updated cvs packages fix vulnerability, Mandrake Linux Security Team, 23:06
- Re: Norton AntiVirus 2004 Script Blocking Failure (Includes PoC and rant), secure, 21:05
- [Full-Disclosure] [ GLSA 200410-18 ] Ghostscript: Insecure temporary file use in multiple scripts, Thierry Carrez, 20:25
- [Full-Disclosure] [ GLSA 200410-17 ] OpenOffice.org: Temporary files disclosure, Thierry Carrez, 20:25
- [Full-Disclosure] Re: [Unpatched] New 0day exploit for XPSP2, Juergen Schmidt, 19:45
- [Full-Disclosure] Norton AntiVirus 2004/2005 Script Blocking Redux, Daniel Milisic, 17:14
- MDKSA-2004:109 - Updated libtiff packages fix multiple vulnerabilities, Mandrake Linux Security Team, 15:43
- [EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap Overflow (PoC), houseofdabus HOD, 15:13
- Buffer-overflow in Age of Sail II 1.04.151, Luigi Auriemma, 14:53
- [VulnWatch] MS-DOS Device Name Denial Of Service Vulnerability in Abyss Web Server X1 for Windows, R00tCr4ck, 14:22
- [Full-Disclosure] RE: How to Break Windows XP SP2 + Internet Explorer 6 SP2, Thor Larholm, 13:22
- [Full-Disclosure] Netscape Webmail Cross Site Scripting Vulnerability, Steven Adair, 04:28
- [Full-Disclosure] America Online Webmail Cross Site Scripting Vulnerability, Steven Adair, 04:08
October 19, 2004
- Re: New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory, Chris Norton, 16:43
- Google Script Insertion Exploit, Jim Ley, 14:52
- Broadcast crash in Vypress Tonecast 1.3, Luigi Auriemma, 13:52
- avoiding stackguard, vallez, 13:52
- Multiple AntiVirus Reserved Device Name Handling Vulnerability, Sowhat ., 13:11
- [Full-Disclosure] Remote Rootkit Scanner for Windows, Andres Tarasco, 12:01
- RE: [IE 6 SP2] Possible URL Spoofing, Dror Shalev, 11:51
- [Full-Disclosure] Major Client Crash in 3D FTP, Bakchodiya, 09:00
- [Full-Disclosure] UnixWare 7.1.4 UnixWare 7.1.3 : The error handling in the inflate and inflateBack functions in ZLib compression library allows local users to cause a denial of service, please_reply_to_security, 07:19
- Re: [IE 6 SP2] Possible URL Spoofing, Paul Kurczaba, 04:48
- [CLA-2004:875] Conectiva Security Announcement - gtk+, Conectiva Updates, 04:38
- RE: Writing Trojans that bypass Windows XP Service Pack 2 Firewall, Simon Zuckerbraun, 02:37
- apexec.pl is still vulnerable against Directory Traversal., Zero_X www.lobnan.de Team, 01:57
- Mutiple AntiVirus Reserved Device Name Handling Vulnerability, Sowhat ., 01:07
- Re: Writing Trojans that bypass Windows XP Service Pack 2 Firewall, Jay Calvert, 00:16
October 18, 2004
- ProFTPD 1.2.x remote users enumeration bug - correction, LSS Security, 19:34
- Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS, Juan C Calderon, 19:04
- [Powie's PSCRIPT Forum] Multiple SQL-Injection Vulnerabilities, Christoph Jeschke, 18:54
- [Full-Disclosure] [ GLSA 200410-16 ] PostgreSQL: Insecure temporary file use in make_oidjoins_check, Thierry Carrez, 18:13
- IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS, Juan C Calderon, 17:43
- Re: EEYE: Windows VDM #UD Local Privilege Escalation, Jim Hatfield, 17:23
- [Full-Disclosure] [ GLSA 200410-15 ] Squid: Remote DoS vulnerability, Luke Macken, 17:23
- Re: Norton AntiVirus 2004 Script Blocking Failure (Includes PoC and rant), secure, 16:12
- Re: Directory traversal in Yak! 2.1.2, bil, 15:12
- Re: Adobe acrobat / Adobe Reader 6 can read local files, Shannon Eric Peevey, 15:12
- Re: [IE 6 SP2] Possible URL Spoofing, http-equiv@excite.com, 14:51
- iDEFENSE Security Advisory 10.18.04: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability, customer service mailbox, 14:31
- Re: 3COM Wireless router (3CRADSL72) information disclosure, mccauley@gmx.net, 13:51
- IISShield and ASP.NET canonicalization, Tiago Halm, 13:31
- [Full-Disclosure] Multiple vulnerabilities in Sage Saleslogix, Carl, 12:50
- Re: New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory, SysAdminKC, 12:40
- ms04-031 pre-auth ??, Sinan Eren, 12:20
- Re: Format String Vulnerability in Valve's CS-Source, Some One, 12:10
- [Full-Disclosure] Web browsers - a mini-farce, Michal Zalewski, 11:50
- Re: New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory, marco correnti, 11:50
- [Full-Disclosure] [ GLSA 200410-14 ] phpMyAdmin: Vulnerability in MIME-based transformation system, Thierry Carrez, 10:37
- [Full-Disclosure] cPanel hardlink backup issue, Karol Więsek, 10:37
- [Full-Disclosure] cPanel symlink chmod issue, Karol Więsek, 10:14
- [Full-Disclosure] cPanel hardlink chown issue, Karol Więsek, 09:51
- [Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities, Dominic Hargreaves, 09:27
October 15, 2004
- RE: Writing Trojans that bypass Windows XP Service Pack 2 Firewall, Polazzo Justin, 21:14
- [IE 6 SP2] Possible URL Spoofing, Andrew Hunter, 20:44
- [Full-Disclosure] Re: Writing Trojans that bypass Windows XP Service Pack 2 Firewall, mrinfosec, 20:14
- [Full-Disclosure] Re: Bypass of Antivirus software with GDI+ bug exploit Mutations, ennis, 20:04
- More details on BID 11408 (3com 3cradsl72 wireless router), Ivan Casado, 19:13
- Re: [VulnWatch] CORE-2004-0802: IIS NNTP Service XPAT Command Vulnerabilities, wirepair, 18:23
- Clientexec Billing Software, bugtraq, 18:13
- Re: [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall, Martin Mkrtchian, 17:22
- Directory traversal in Yak! 2.1.2, Luigi Auriemma, 17:22
- Norton AntiVirus 2004 Script Blocking Failure (Includes PoC and rant), Daniel Milisic, 16:42
- Microsoft Windows NetDDE Service Buffer Overflow, NGSSoftware Insight Security Research, 16:42
- Re: Format String Vulnerability in Valve's CS-Source, Luigi Auriemma, 16:32
- ProFTPD 1.2.x remote users enumeration bug, LSS Security, 16:32
- Re: Insecure Default Service DACL's in Windows 2003, Jean-Baptiste Marchand, 16:01
- a path disclosure and a posibility file inclusion and vulneability in thepeak file upload v1.3, keitel andres ortega, 15:51
- Re: EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability, Bipin Gautam, 15:21
- TSLSA-2004-0054 - multi, Trustix Security Advisor, 15:00
- [OpenPKG-SA-2004.044] OpenPKG Security Advisory (modssl), OpenPKG, 14:50
- [Full-Disclosure] [ GLSA 200410-13 ] BNC: Input validation flaw, Thierry Carrez, 09:54
- [Full-Disclosure] Re: Insecure Default Service DACL's in Windows 2003, Jean-Baptiste Marchand, 06:23
- [Full-Disclosure] [FLSA-2004:2102] Updated samba packages fix security vulnerability [updated], Dominic Hargreaves, 00:10
October 14, 2004
- Format String Vulnerability in Valve's CS-Source, Some One, 20:38
- Re: Adobe acrobat / Adobe Reader 6 can read local files, Nick Leoncavallo, 20:18
- UPDATE: Format String Vulnerability in Valve's CS-Source, Some One, 19:48
- ACROS Security: Session Fixation in JRun Management Console, ACROS Security, 19:37
- ACROS Security: HTML Injection in JRun Management Console, ACROS Security, 19:17
- ACROS Security: Unsanitized Session ID Cookie Allows Modifying Server Response, ACROS Security, 19:07
- New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory, John Bissell, 18:47
- 3COM Wireless router (3CRADSL72) information disclosure, Karb0nOxyde -, 18:37
- CESA-2004-006: libtiff, chris, 18:06
- [HV-MED] UPDATE: RIM Blackberry DoS, data loss, vuln, 16:54
- [CLA-2004:873] Conectiva Security Announcement - samba, Conectiva Updates, 15:32
- [CLA-2004:872] Conectiva Security Announcement - cups, Conectiva Updates, 15:02
- SetWindowLong Shatter Attacks, Brett Moore, 14:41
- Buffer Overflow In Microsoft Excel, Brett Moore, 14:10
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations, Cassidy Macfarlane, 14:10
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations, Todd Towles, 13:49
- [Full-Disclosure] [ GLSA 200410-12 ] WordPress: HTTP response splitting and XSS vulnerabilities, Luke Macken, 13:08
- [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations, Andrey Bayora, 10:13
- [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations, Andrey Bayora, 08:12
- [Full-Disclosure] [FLSA-2004:1833] Updated lha resolves security vulnerabilities, Marc Deslauriers, 08:02
- [Full-Disclosure] [FLSA-2004:1888] Updated mod_ssl package fixes Apache security vulnerabilities, Marc Deslauriers, 07:42
- [Full-Disclosure] [FLSA-2004:1737] Updated httpd packages fix a mod_proxy security vulnerability, Marc Deslauriers, 07:12
- MSN Gaming Heartbeat Component Buffer Overflow, NGSSoftware Insight Security Research, 05:09
- [ GLSA 200410-09 ] LessTif: Integer and stack overflows in libXpm, Luke Macken, 05:09
- EEYE: Windows VDM #UD Local Privilege Escalation, Derek Soeder, 00:27
October 13, 2004
- [ GLSA 200410-10 ] gettext: Insecure temporary file handling, Luke Macken, 22:46
- IT Underground Talks, Dave Aitel, 22:26
- EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability, Derek Soeder, 22:05
- BindView Advisory: Memory Leak and DoS in NT4 RPC server, advisory, 17:32
- [FLSA-2004:2102] Updated samba packages fix security vulnerability, Dominic Hargreaves, 17:01
- [Full-Disclosure] Multiple Cross Site Scripting Vulnerabilities in FuseTalk, steven, 16:31
- [Full-Disclosure] Buffer-overflow in ShixxNOTE 6.net, Luigi Auriemma, 15:31
- XXS in SCT email client, Matthew Oyer, 14:40
- XXS in fusetalk forum, Matthew Oyer, 14:10
- [Full-Disclosure] [ GLSA 200410-11 ] tiff: Buffer overflows in image decoding, Thierry Carrez, 12:49
- [Full-Disclosure] [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss, vuln, 02:13
- [hackgen-2004-#002] - Remote file inclusion bug in ocPortal 1.0.3., Exoduks, 00:21
October 12, 2004
- MS October Security bulletins, albatross, 22:30
- Microsoft IIS 5.x/6.0 WebDAV (XML parser) attribute blowup DoS, Amit Klein (AKsecurity), 22:30
- Reverse Engineering the First Pocket PC Trojan, kers0r, 21:40
- Re: Regression in IE: Accessing remote/local content in IE (GM#009-IE), Nick FitzGerald, 20:29
- RE: Insecure Default Service DACL's in Windows 2003, Kurt Dillard, 19:38
- Insecure Default Service DACL's in Windows 2003, Ziots, Edward, 18:28
- UnixWare 7.1.4 : Multiple Vulnerabilities in libpng, please_reply_to_security, 18:07
- Microsoft Internet Explorer Install Engine Control Buffer Overflow, NGSSoftware Insight Security Research, 17:17
- [SECURITY] [DSA 563-2] New cyrus-sasl packages really fix arbitrary code execution, Martin Schulze, 16:46
- UnixWare 7.1.3up UnixWare 7.1.4 : CUPS before 1.1.21 allows remote attackers to cause a denial of service, please_reply_to_security, 16:36
- Micronet wireless broadband router SP916BM admin password reset when power off, MrJoe, 16:06
- Regression in IE: Accessing remote/local content in IE (GM#009-IE), GreyMagic Security, 15:46
- MonkeyShell: using XML-RPC for access to a remote shell, Abe Usher, 13:45
- FW: problem in voip environment, Walton, John Michael (John), 12:54
- [Full-Disclosure] Microsoft cabarc directory traversal, Jelmer, 11:54
- [Full-Disclosure] Adobe acrobat / Adobe Reader 6 can read local files, Jelmer, 11:24
- [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall, americanidiot, 11:13
October 09, 2004
- [Full-Disclosure] [ GLSA 200410-09 ] LessTif: Integer and stack overflows in libXpm, Luke Macken, 20:42
- [Full-Disclosure] [FLSA-2004:2068] Updated httpd packages fix security issues, Marc Deslauriers, 17:31
- [Full-Disclosure] [ GLSA 200410-08 ] ncompress: Buffer overflow, Thierry Carrez, 16:20
- [Full-Disclosure] [ GLSA 200410-07 ] ed: Insecure temporary file handling, Thierry Carrez, 16:10
- [Full-Disclosure] [ GLSA 200410-06 ] CUPS: Leakage of sensitive information, Kurt Lieber, 10:56
October 08, 2004
- [Full-Disclosure] Re: Yet another IE aperture, GreyMagic Security, 23:01
- TSLSA-2004-0053 - cyrus-sasl, Trustix Security Advisor, 19:00
- MDKSA-2004:106 - Updated cyrus-sasl packages fix local vulnerability, Mandrake Linux Security Team, 18:49
- [Full-Disclosure] Limited \secure\ buffer-overflow in some old Monolith games, Luigi Auriemma, 18:19
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities, dave, 09:25
- [Full-Disclosure] [FLSA-2004:1257] Updated netpbm packages fix security vulnerabilities, Dominic Hargreaves, 08:24
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities, Martin Viktora, 06:23
October 07, 2004
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities, Jason Coombs PivX Solutions, 23:21
- [Full-Disclosure] [FLSA-2004:1868] Updated php packages fix security issues, Marc Deslauriers, 22:41
- [Full-Disclosure] Re: ASP.NET cannonicalization issue, Jelson Pat, 19:39
- [Full-Disclosure] Re: ASP.NET cannonicalization issue, Jelson Pat, 19:19
- [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities, Drew Copley, 17:58
- [Full-Disclosure] ASP.NET cannonicalization issue, Evans, Arian, 17:17
- [Full-Disclosure] [FLSA-2004:1735] Updated cvs packages fix security vulnerabilities, Dominic Hargreaves, 15:37
- Server crash in Flash Messaging 5.2.0g, Luigi Auriemma, 14:56
- [Full-Disclosure] [sb] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities, Kurt Lieber, 14:56
- HTTP Response Splitting Vulnerability in Wordpress 1.2, Chaotic Evil, 14:55
- [Full-Disclosure] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities, Kurt Lieber, 14:55
- Full path disclosure and sql injection on CubeCart 2.0.1, Pedro Sanches, 14:55
- Re: Buffer Overflow in Spider game, Matt Zimmerman, 14:55
- Hi, webhelp, 14:55
- New Microsoft Security Response Center PGP Key [pgp], Microsoft Security Response Center, 14:55
- [Gosecure Adivsory] Neoteris IVE Vulnerability, Jian Hui Wang, 14:55
- Re: Multiple vulnerabilities in BlackBoard, Yves Goergen, 14:55
- Patch available for high risk flaws in the AtHoc Toolbar, NGSSoftware Insight Security Research, 14:55
- [Full-Disclosure] [HV-HIGH] MS Word multiple exceptions, at least one exploitable, vuln, 14:55
- MDKSA-2004:105 - Updated xine-lib packages fix multiple vulnerabilities, Mandrake Linux Security Team, 14:55
- [GoSecure Advisory] Neoteris IVE Vulnerability, Jian Hui Wang, 14:55
- CodeCon 2005 Call for Papers, Len Sassaman, 14:55
- Latest Apple Sec update, Michael Bartosh, 14:55
- [Full-Disclosure] Directory traversal in Tridcomm 1.3, Luigi Auriemma, 14:55
- SUSE Security Announcement: mozilla (SUSE-SA:2004:036), Sebastian Krahmer, 14:55
- [VulnWatch] Patch available for high risk flaws in the AtHoc Toolbar, NGSSoftware Insight Security Research, 14:55
- GDI+ JPEG exploit, albatross, 14:54
- [VulnWatch] Patch available for multiple high risk vulnerabilities in RealPlayer, NGSSoftware Insight Security Research, 14:54
- Patch available for multiple high risk vulnerabilities in RealPlayer, NGSSoftware Insight Security Research, 14:54
- Multiple vulnerabilities in BlackBoard, Lin Xiaofeng, 14:54
- [Full-Disclosure] [Maxpatrol Security Advisory] Multiple vulnerabilities in DCP-Portal, Alexander Antipov, 14:54
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability, 3APA3A, 14:54
- Re: Full path disclosure in PHP Links - more, LSS Security, 14:54
- [Full-Disclosure] [ GLSA 200410-04 ] PHP: Memory disclosure and arbitrary location file upload, Dan Margolis, 14:54
- Re: Buffer Overflow in Spider game, van Helsing, 14:54
- ERRATA: Potential Arbitrary File Access (CAN-2004-0815), Gerald (Jerry) Carter, 14:54
- Test your windows OS, Berend-Jan Wever, 14:54
- Re: Full path disclosure in PHP Links, Scott T. Cameron, 14:54
- Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bug, Bipin Gautam, 14:54
- [Full-Disclosure] [MAXPATROL Security Advisories] Cross site scripting in Invision Power Board, Alexander Antipov, 14:53
- [Full-Disclosure] [ GLSA 200410-03 ] NetKit-telnetd: buffer overflows in telnet and telnetd, Thierry Carrez, 14:53
- [VulnWatch] Patch available for critical IBM DB2 Universal Database flaws, NGSSoftware Insight Security Research, 14:53
- Re: EEYE: RealPlayer pnen3260.dll Heap Overflow, Chenghuai Lu, 14:53
- SUSE Security Announcement: samba (SUSE-SA:2004:035), Thomas Biege, 14:53
- [security bulletin]SSRT4826 rev.0 Mozilla Application Suite for HP Tru64 UNIX Multiple Potential Security Vulnerabilities, Boren, Rich (SSRT), 14:53
- Patch available for critical IBM DB2 Universal Database flaws, NGSSoftware Insight Security Research, 14:53
- Re: Buffer Overflow in Spider game, Steve Kemp, 14:53
- [Full-Disclosure] RE: On Polymorphic Evasion (an alphanumeric version), m conover, 14:53
- FreeBSD Security Advisory FreeBSD-SA-04:15.syscons, FreeBSD Security Advisories, 14:53
- Full path disclosure in PHP Links, Nikyt0x Argentina, 14:53
- Buffer Overflow in Spider game, Security Team, 14:52
- [LoWNOISE] IPSWITCH WhatsUp Gold 8.03 Remote fr33 exploit, ET LoWNOISE, 14:52
- Re: Oracle 9i Union Flaw, Peter J. Holzer, 14:52
October 02, 2004
- [Full-Disclosure] Re: On Polymorphic Evasion, Vlad902, 22:18
- Re: cdrecord local root exploit, Solar Designer, 17:56
- Re:2. Code execution in Icecast 2.0.1(exploit with shellcode), me, 17:16
- In-game format string in Judge Dredd vs. Death 1.01, Luigi Auriemma, 16:35
- Security advisory - Xerces-C++ 2.5.0: Attribute blowup, Amit Klein (AKsecurity), 15:45
- [Full-Disclosure] [FLSA-2004:1733] Updated squirrelmail resolves security vulnerabilities, Dominic Hargreaves, 12:44
- dbPowerAmp Buffer Overflow And Dos Vulnerabilities, GulfTech Security, 00:49
- Re: cdrecord local root exploit, Jason T. Miller, 00:29
October 01, 2004
- Re: Promiscuous email printing in Canon imageRunner, Marco Ivaldi, 22:59
- [Full-Disclosure] On Polymorphic Evasion, Phantasmal Phantasmagoria, 22:18
- Re: Oracle 9i Union Flaw, Brandon Petty, 22:08
- Oracle 9i Union Flaw, Brandon Petty, 20:57
- MDKSA-2004:104 - Updated samba packages fix vulnerability, Mandrake Linux Security Team, 19:27
- Re: cdrdao local root exploit, newbug Tseng, 19:27
- Re: cdrecord local root exploit, Greg A. Woods, 18:46
- Re: Possible GDI Exploit Vector, Babar Shafiq Nazmi, 17:16
- Broadcast buffer-overflow in Vypress Messenger 3.5.1, Luigi Auriemma, 16:55
- EEYE: RealPlayer pnen3260.dll Heap Overflow, Marc Maiffret, 16:35
- SQL Injection vulnerability in bBlog 0.7.3, James McGlinn, 16:05
- Multiple Vulnerabilities in AJ-Fork, Ahmad Muammar, 14:55
- TSLSA-2004-0051 - samba, Trustix Security Advisor, 13:54
- [Full-Disclosure] [ GLSA 200410-01 ] sharutils: Buffer overflows in shar.c and unshar.c, Thierry Carrez, 09:52
- Re: Diebold Global Election Management System (GEMS) Backdoor Acc ount Allows Authenticated Users to Modify Votes, Shawn McMahon, 03:50
- RE: Diebold Global Election Management System (GEMS) Backdoor, David Schwartz, 03:00
- CFMX vulnerability, Eric Lackey, 02:09
- [SECURITY] [DSA 553-1] New getmail packages fix root compromise, Martin Schulze, 01:59
- RE: Promiscuous email printing in Canon imageRunner, Jeff Bates, 01:39
- iDEFENSE Security Advisory 09.30.04 - Samba Arbitrary File Access Vulnerability, customer service mailbox, 00:59