Bugtraq (date)
December 30, 2006
- Enigma WordPress Bridge (boarddir) Remote File Include, xorontr, 16:35
- Enigma Coppermine Bridge (boarddir) Remote File Include, xorontr, 16:15
- [vuln.sg] iso_wincmd Plugin for Total Commander Buffer Overflow Vulnerability, vulnpost-remove, 12:44
- SoftArtisans FileUp(TM) viewsrc.asp remote script source disclosure exploit, inge_eivind . henriksen, 12:34
- MythControl (MythTV remote control) arbitrary code execution, sapheal, 12:24
- csrss.exe double-free vulnerability - arbitrary DWORD overwrite exploit, Reversemode, 12:14
December 29, 2006
- Re: XSS in script Mobilelib GOLD v2, gamr-14, 15:35
- DoceboLMS Xss Vuln., starext, 14:15
- LDU <= 8.x (journal.php) SQL Injection Vulnerability, starext, 13:55
- QuickCam linux device driver allows arbitrary code execution, sapheal, 11:54
- XSS with default page parameter in Oracle Portal 10g, duchaikhtn, 11:23
- XSS in script Mobilelib GOLD v2, gamr-14, 11:23
- [Full-disclosure] Information Security Behavior Management System, no me, 04:59
December 28, 2006
- Re: XSS with Vbulletin (new idea !), micmast, 17:53
- [OpenPKG-SA-2006.044] OpenPKG Security Advisory (w3m), OpenPKG GmbH, 17:53
- Re: XSS - CMS Made Simple v1.0.2, nanoymaster, 17:53
- SMS handling OpenSER remote code executing, sapheal, 17:53
- Re: XSS with Vbulletin (new idea !), l . d . 0, 17:53
- OpenSER OSP Module remote code execution, sapheal, 17:53
- Limbo CMS event module (lm_absolute_path) Remote File Include Vulnerabilities, xorontr, 17:53
- ShmooCon Announcement, B Potter, 17:49
- NtRaiseHardError Csrss.exe memory Disclosure exploit, Reversemode, 17:49
- Re: Cross site scripting & fullpath disclosure, james . brown, 17:49
- Secure Login Manager Multiple Input Validation Vulnerabilities, DoZ, 17:48
- Host directory full disclosure and input error, hack2prison, 17:48
- Re: XSS with Vbulletin (new idea !), bas, 17:48
- Re: The (in)security of Xorg and DRI, Pavel Kankovsky, 17:48
- Re: LuckyBot v3 Remote File Include, Stuart Moore, 17:48
- Re: phpcms <=- 1.1.7 Remote File Inclusion, Hugo van der Kooij, 17:47
- Re: phpcms <=- 1.1.7 Remote File Inclusion, Stuart Moore, 17:45
- Re: ERRATA (Re: "Host header cannot be trusted as an anti anti DNS-pinning measure"), Martin Johns, 17:44
- [OpenPKG-SA-2006.043] OpenPKG Security Advisory (links), OpenPKG GmbH, 17:42
- [OpenPKG-SA-2006.042] OpenPKG Security Advisory (openser), OpenPKG GmbH, 17:42
- LuckyBot v3 Remote File Include, i-k-t, 17:42
- logahead UNU edition 1.0 Remote File Upload & code execution, corrado . liotta, 17:42
- XSS - CMS Made Simple v1.0.2, Curtis Zimmerman, 17:42
- HLStats Remote SQL Injection Exploit, nospam, 17:42
- PhpbbXtra v2.0 (phpbb_root_path) Remote File Include Vulnerability, xorontr, 17:42
- phpcms <=- 1.1.7 Remote File Inclusion, Zarloule04, 17:41
- Cahier de texte V2.2 Bypass general access protection exploit, gmdarkfig, 17:41
- PHP Live! 3.2.2 Multiple Cross-Site Scripting Vulnerabilities, DoZ, 17:40
- XSS with Vbulletin (new idea !), ashraf1984, 17:40
- ERRATA (Re: "Host header cannot be trusted as an anti anti DNS-pinning measure"), Amit Klein, 17:40
- Forum AnyBoard - Sql Inyection By Firewall, Firewall1954, 17:39
- TimberWolf 1.2.2 vulnerable to XSS, corrado . liotta, 17:39
- Fishyshoop Security Vulnerability, James Gray, 17:39
- Chatwm V1.0 SqL Injection Vuln., ShaFuq31, 17:39
- Okul Merkezi Portal v1.0 Remote File IncLude Vuln., ShaFuq31, 17:39
- [Full-disclosure] iDefense Security Advisory 12.23.06: Novell Netmail IMAP append Denial of Service Vulnerability, iDefense Labs, 17:36
- [Full-disclosure] iDefense Security Advisory 12.23.06: Novell NetMail IMAPD subscribe Buffer Overflow Vulnerability, iDefense Labs, 17:36
- Multiple Bugs in Future Internet ( XSS & SQL Injection ), xx_hack_xx_2004, 17:36
- Efkan Forum v1.0 SqL Inj. Vuln., ShaFuq31, 17:36
- [Full-disclosure] Multiple Remote Vulnerabilities in KISGB, 0o_zeus_o0 elitemexico.org, 17:35
- [Full-disclosure] Botnets: a retrospective to 2006, and where we are headed in 2007, Gadi Evron, 17:35
- [Full-disclosure] ZDI-06-053: Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability, zdi-disclosures, 17:34
- [Full-disclosure] ZDI-06-054: Novell NetMail IMAP APPEND Buffer Overflow Vulnerability, zdi-disclosures, 17:34
- [Full-disclosure] ZDI-06-052: Novell NetMail NMAP STOR Buffer Overflow Vulnerability, zdi-disclosures, 17:33
- Re: [Full-disclosure] Multiple Remote Vulnerabilities in KISGB, str0ke, 17:33
- Re: [Full-disclosure] Multiple Remote Vulnerabilities in KISGB, 3APA3A, 17:33
- SQID v0.2 - SQL Injection Digger., contact, 17:33
- Re: Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, Mike, 17:32
- TSLSA-2006-0074 - multi, Trustix Security Advisor, 17:32
- Re[2]: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip, Thierry Zoller, 17:32
- Xt-News 0.1 : SQL Injection Vulnerability & XSS, mr_kaliman, 17:31
- [Full-disclosure] Oracle Applications/Portal 9i/10g Cross Site Scripting, putosoft softputo, 17:30
- Re: [Full-disclosure] Oracle Portal 10g HTTP Response Splitting, putosoft softputo, 17:30
- [Full-disclosure] rPSA-2006-0234-1 firefox, rPath Update Announcements, 17:30
- RE: Enforcing Java Security Manager in Restricted Windows Environments?, Jan P. Monsch, 17:28
- Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, Michele Cicciotti, 17:28
- Re: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip, Juha-Matti Laurio, 17:27
- Re: Oracle Portal 10g HTTP Response Splitting, majororacle, 17:26
- Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, Pukhraj Singh, 17:26
- PWDumpX updated (includes CacheDump functionality), Reed Arvin, 17:26
- OpenSER 1.1.0 parse_config buffer overflow vulnerability, sapheal, 17:25
- [OpenPKG-SA-2006.040] OpenPKG Security Advisory (ruby), OpenPKG GmbH, 17:25
- Re: MkPortal Urlobox Cross Site Request Forgery, securityfocus, 17:25
- Re: MkPortal Urlobox Cross Site Request Forgery, securityfocus, 17:25
- Re: Trend Micro's Vista "0day exploit auction" claim, Simple Nomad, 17:25
- Re: RE: Trend Micro's Vista "0day exploit auction" claim, agoodhez1, 17:25
- [TOOL] untidy - XML Fuzzer, Andres Riancho, 17:25
- Re: Vulnerability in MG2 php based Image Gallery - bypass security, view password protected images, matthieu . paineauSTOPSPAM, 17:24
- SQID v0.1 - SQL Inhection Digger., contact, 17:24
- Re: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip, 3APA3A, 17:24
- Ixprim CMS 1.2 Remote Blind SQL Injection Exploit, gmdarkfig, 17:24
- Re: Enforcing Java Security Manager in Restricted Windows Environments?, jim, 17:23
- Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, Alexander Sotirov, 17:23
- Re: [Full-disclosure] Fun with event logs (semi-offtopic), Michele Cicciotti, 17:23
- [ MDKSA-2006:234 ] - Updated mono packages fix vulnerability, security, 17:23
- Re: Oracle <= 9i / 10g File System Access via utl_file Exploit, Marco Ivaldi, 17:20
- Re: [Full-disclosure] Fun with event logs (semi-offtopic), 3APA3A, 17:20
- [CAID 34876]: CA CleverPath Portal Session Inheritance Vulnerability, Williams, James K, 17:20
- [OpenPKG-SA-2006.041] OpenPKG Security Advisory (dbus), OpenPKG GmbH, 17:19
- Re: [Full-disclosure] Fun with event logs (semi-offtopic), Michele Cicciotti, 17:18
- Re: [Full-disclosure] Fun with event logs (semi-offtopic), Michele Cicciotti, 17:18
- Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, 3APA3A, 17:17
- Re: [Full-disclosure] Fun with event logs (semi-offtopic), endrazine, 17:17
- [Full-disclosure] Fun with event logs (semi-offtopic), 3APA3A, 17:16
- [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, 3APA3A, 17:16
- [Full-disclosure] NOD32 Antivirus CAB parsing Arbitrary Code Execution Advisory, security, 17:16
- RE: Trend Micro's Vista "0day exploit auction" claim, Simple Nomad, 17:12
- [Full-disclosure] [USN-397-1] mono vulnerability, Kees Cook, 17:12
- critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip, quincy, 17:12
- RE: Trend Micro's Vista "0day exploit auction" claim, Roger A. Grimes, 17:12
- [Full-disclosure] [ GLSA 200612-21 ] Ruby: Denial of Service vulnerability, Raphael Marichez, 17:11
- [Full-disclosure] [ GLSA 200612-20 ] imlib2: Multiple vulnerabilities, Raphael Marichez, 17:11
- [Full-disclosure] [ GLSA 200612-19 ] pam_ldap: Authentication bypass vulnerability, Raphael Marichez, 17:11
- [security bulletin] HPSBST02180 SSRT061288 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS06-072 Through MS06-078, security-alert, 17:11
- [security bulletin] HPSBUX02174 SSRT061239 rev.2 HP-UX Running OpenSSL Denial of Service (DoS), Increase Privilege, security-alert, 17:11
- Re: [Full-disclosure] Oracle Portal 10g HTTP Response Splitting, Brian Eaton, 17:11
- Re: Oracle <= 9i / 10g File System Access via utl_file Exploit, sumit kumar soni, 17:10
- Mono XSP ASP.NET Server sourcecode disclosure vulnerability, jose . palanco, 17:10
- Oracle Portal 10g HTTP Response Splitting, putosoft softputo, 17:08
- [Full-disclosure] NOD32 Antivirus DOC parsing Arbitrary Code Execution Advisory, security, 17:06
- [Full-disclosure] SEC Consult SA-20061220-0 :: Typo3 Command Execution Vulnerability, SEC Consult Research, 17:06
- [Full-disclosure] ZDI-06-051: Mozilla Firefox SVG Processing Remote Code Execution Vulnerability, zdi-disclosures, 17:01
- RE: Cisco not honoring update promises?, Michael Scheidell, 17:00
- MkPortal Urlobox Cross Site Request Forgery, info, 17:00
- Multiple Bugs in MINI WEB SHOP, xx_hack_xx_2004, 17:00
- Oracle <= 9i / 10g File System Access via utl_file Exploit, none, 16:59
- Oracle <= 9i / 10g (extproc) Local/Remote Command Execution Exploit, none, 16:59
- Burak Yilmaz Download Portal Sql Injection Vuln., ShaFuq31, 16:58
- xss in Support Cards v1 ( oSTicket ), l . d . 0, 16:58
- Trend Micro's Vista "0day exploit auction" claim, Ryan Meyer, 16:57
- RE: [BULK] - New Skype Worm, Hubbard, Dan, 16:55
- New Skype Worm, Christopher Mosby, 16:54
- [Full-disclosure] HP Printers FTP Server Denial Of Service, Joxean Koret, 16:54
- Multiple XSS vulnerabiliteies in Inetmedia's information service - cityinfo., filip . palian, 16:54
- WebCalendar >=1.0 Cross-Site Scripting Vulnerabilities, 7all7, 16:53
- [ MDKSA-2006:233 ] - Updated dbus packages fix vulnerability, security, 16:51
- [ MDKSA-2006:232 ] - Updated proftpd packages fix mod_ctrls vulnerability, security, 16:50
- HITBSecConf2007 - Dubai - Call for Papers now open!, Praburaajan, 16:45
- [security bulletin] HPSBUX02178 SSRT061267 rev.2 - HP-UX Secure Shell Remote Unauthorized Denial of Service (DoS), security-alert, 16:40
- Re: Checkpoint NG3 ICMP Flood, Hugo van der Kooij, 16:39
- Re: Checkpoint NG3 ICMP Flood, Michael Schwartzkopff, 16:39
- Re: Cisco not honoring update promises?, rsmoak, 16:38
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Marcus Meissner, 16:38
- [Full-disclosure] [ GLSA 200612-18 ] ClamAV: Denial of Service, Sune Kloppenborg Jeppesen, 16:32
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Kamchybek Jusupov, 16:29
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, p . kerr, 16:28
- Checkpoint NG3 ICMP Flood, bdmoraes, 16:27
- Secunia Research: MailEnable POP Service "PASS" Command Buffer Overflow, Secunia Research, 16:27
- SYMSA-2006-013: Multiple Vulnerabilities in Mandiant First Response, research, 16:24
- RateMe <= all versions => ( main.inc.php ) Remote File Include Vulnerability, saudi, 16:23
- Re: The (in)security of Xorg and DRI, Darren Reed, 16:23
- HyperVM Cross-Site Scripting, Advisory, 16:23
- Cisco not honoring update promises?, Michael Scheidell, 16:23
- Re: The (in)security of Xorg and DRI, Darren Reed, 16:23
- Allied Telesis AT-9000/24 Ethernet switch management can be accessed from all VLANs., Pasi Sjoholm, 16:11
- Re: Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Hunger, 16:09
- [HSC Security Group] SiteCatalyst Web Login Cross Site Vulrnabilities, DoZ, 16:08
- Contra Haber Sistemi v1.0 SqL Injection Vuln., ShaFuq31, 16:08
- Re: Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, willysr, 16:08
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, George Yobst, 16:08
- Re: Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, ox90x86, 16:08
- Re: Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, bastyaelvtars, 16:08
- Re: Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, gplit, 16:08
- Odysseus 2.0 / Telemachus 1.0 (Beta), Dave, 16:08
- Doğantepe Ziyareti Defteri (tr) Sql Injection Vuln., ShaFuq31, 16:07
- XSS in gmial google, gamr-14, 16:07
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Dragos Ruiu, 16:07
- RE: Windows Explorer WMV File Denial Of Service Vulnerability, Ulises Cuñé, 16:07
- Drone Armies C&C Report - 15 Dec 2006, c2report, 16:07
- [OpenPKG-SA-2006.039] OpenPKG Security Advisory (proftpd), OpenPKG GmbH, 16:06
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Josh Bressers, 16:06
- [ MDKSA-2006:206 ] - Updated Thunderbird packages fix multiple vulnerabilities, security, 16:05
- Re: Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, Bruno Lustosa, 16:04
- Bypassing process identification of several personal firewalls and HIPS, Matousec - Transparent security Research, 16:03
- Flaw in OpenOffice.org 2.1: OpenOffice 2.1 is vulnerable to MS Word 0 day vulnerability!!!, gplit, 16:02
- Re: The (in)security of Xorg and DRI, Nicolas RUFF, 16:02
- Project Server 2003 - Credential Disclosure, Brett Moore, 16:01
- [security bulletin] HPSBMA02173 SSRT061230 rev. 1 - HP Integrated Lights Out (iLO & iLO 2) Running SSH Key Based Authentication Remote Unauthorized Access, security-alert, 16:01
- Windows Media MID File Denial Of Service Vulnerability, sehato, 16:01
- Windows Explorer WMV File Denial Of Service Vulnerability, sehato, 16:01
- TSLSA-2006-0072 - clamav, Trustix Security Advisor, 16:00
- [ MDKSA-2006:231 ] - Updated gdm packages fix string vulnerability, security, 16:00
- [Full-disclosure] BitDefender AV Packed PE File Parsing Engine Heap Overflow, security, 16:00
- [Full-disclosure] Fuzzers and brute forcers, Joxean Koret, 15:59
- Top 10 Real Computer Crimes for 2007, Pete Herzog, 15:58
- CanSecWest 2007 (April 18-20) Call For Papers (Deadline January 7th), Dragos Ruiu, 15:57
- [Full-disclosure] [USN-396-1] gdm vulnerability, Kees Cook, 15:57
- Re: Re: Microsoft 0-day word vulnerability - Secunia - Extremely critical, schafer_jeffrey, 15:56
- [Full-disclosure] Kerio MailServer < 6.3.1 remote Denial of Service, research, 15:56
- Re: [Full-disclosure] [fuzzing] NOT a 0day! Re: OWASP Fuzzing page, Gadi Evron, 15:56
- [ MDKSA-2006:164-2 ] - Updated xorg-x11/XFree86 packages fix integer overflow vulnerabilities, security, 15:55
- Re: [Full-disclosure] [fuzzing] NOT a 0day! Re: OWASP Fuzzing page, Juha-Matti Laurio, 15:55
- [CAID 34870]: CA Anti-Virus vetfddnt.sys, vetmonnt.sys Local Denial of Service Vulnerabilities, Williams, James K, 15:55
- [ MDKSA-2006:230 ] - Updated clamav packages fix vulnerability, security, 15:55
- Re: [Full-disclosure] iDefense Security Advisory 12.14.06: GNOME Foundation Display Manager gdmchooser Format String Vulnerability, iDefense Labs, 15:55
- [ MDKSA-2006:229 ] - Updated evince packages fix buffer overflow vulnerability, security, 15:55
- Re: [Full-disclosure] The newest Word flaw is due to malformed data structure handling, Juha-Matti Laurio, 15:55
- Re: Microsoft 0-day word vulnerability - Secunia - Extremely critical, schafer_jeffrey, 15:55
- [Full-disclosure] iDefense Security Advisory 12.14.06: GNOME Foundation Display Manager gdmchooser Format String Vulnerability, iDefense Labs, 15:54
- Re: [fuzzing] NOT a 0day! Re: [Full-disclosure] OWASP Fuzzing page, Jerome Athias, 15:54
- HyperAccess - Multiple Vulnerabilities, Brett Moore, 15:54
- Call for papers and presenters - Dec. 15th deadline, Mike Allgeier, 15:54
- The (in)security of Xorg and DRI, Darren Reed, 15:54
- GenesisTrader v1.0 - Multiple Vulnerabilities, mr_kaliman, 15:54
- Re: The newest Word flaw is due to malformed data structure handling, Steven M. Christey, 15:54
- Re: [Full-disclosure] [fuzzing] NOT a 0day! Re: OWASP Fuzzing page, Gadi Evron, 15:54
- [Full-disclosure] [ GLSA 200612-17 ] GNU Radius: Format string vulnerability, Raphael Marichez, 15:54
- [Full-disclosure] [ GLSA 200612-16 ] Links: Arbitrary Samba command execution, Raphael Marichez, 15:53
- [Full-disclosure] NOT a 0day! Re: [fuzzing] OWASP Fuzzing page, Gadi Evron, 15:53
- [Full-disclosure] [USN-380-2] avahi regression, Martin Pitt, 15:53
- [Full-disclosure] rPSA-2006-0232-1 libgsf, rPath Update Announcements, 15:53
December 13, 2006
- CORE-2006-1127: ProFTPD Controls Buffer Overflow, CORE Security Technologies Advisories, 20:03
- [Full-disclosure] ZDI-06-049: Symantec Veritas NetBackup Long Request Buffer Overflow Vulnerability, zdi-disclosures, 18:42
- [Full-disclosure] ZDI-06-050: Symantec Veritas NetBackup CONNECT_OPTIONS Buffer Overflow Vulnerability, zdi-disclosures, 18:42
- [Full-disclosure] IBM DB2 Remote DoS during CONNECT processing, Team SHATTER, 17:42
- ASP Cmd Shell On IIS 5.1, Brett Moore, 17:01
- Re: worksystem => Remote File Include Vulnerability Exploit, Laurent . van_den_reysen, 13:50
- [Full-disclosure] [USN-395-1] Linux kernel vulnerabilities, Martin Pitt, 13:29
December 12, 2006
- Re: Re: The newest Word flaw is due to malformed data structure handling, test, 21:23
- ZDI-06-046: Sophos Anti-Virus SIT Archive Parsing Buffer Overflow Vulnerability, zdi-disclosures, 21:13
- Re: shopsite advisory, bugtraq, 20:52
- [Full-disclosure] [ GLSA 200612-14 ] Trac: Cross-site request forgery, Sune Kloppenborg Jeppesen, 20:12
- [Full-disclosure] [ GLSA 200612-13 ] libgsf: Buffer overflow, Sune Kloppenborg Jeppesen, 19:52
- [Full-disclosure] [ GLSA 200612-12 ] F-PROT Antivirus: Multiple vulnerabilities, Sune Kloppenborg Jeppesen, 19:41
- Secunia Research: Internet Explorer Script Error Handling Memory Corruption, Secunia Research, 18:51
- Re: The newest Word flaw is due to malformed data structure handling, Dave \"No, not that one\" Korn, 18:31
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.), chinese soup, 18:11
- BLOG:CMS Remote file include Vulnerability, security, 18:00
- rPSA-2006-0230-1 evince, rPath Update Announcements, 17:50
- Re: PHP 5.2.0 session.save_path safe_mode and open_basedir bypass, Ismail Donmez, 17:40
- [Full-disclosure] iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so Directory Traversal Vulnerability, iDefense Labs, 17:09
- [Full-disclosure] iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so 'doprf()' Buffer Overflow Vulnerability, iDefense Labs, 17:09
- [Full-disclosure] ZDI-06-045: Sophos Anti-Virus CPIO Archive Parsing Buffer Overflow Vulnerability, zdi-disclosures, 16:49
- [Full-disclosure] ZDI-06-048: Microsoft Internet Explorer normalize() Function Memory Corruption Vulnerability, zdi-disclosures, 16:49
- [Full-disclosure] ZDI-06-047: Microsoft Visual Studio WmiScriptUtils.dll Cross-Zone Scripting Vulnerability, zdi-disclosures, 16:39
- rPSA-2006-0231-1 squirrelmail, rPath Update Announcements, 16:29
- Re: [Full-disclosure] [fuzzing] OWASP Fuzzing page, Joxean Koret, 16:19
- Web Apps- Rad Upload Version 3.02 Remote File Include Vulnerability, rko . thelegendkiller, 15:49
- [SBDA] SiteKiosk - FileSystem Access, Brett Moore, 15:38
- [ MDKSA-2006:228 ] - Updated gnupg packages fix vulnerability, security, 14:58
- [Full-disclosure] OpenLDAP kbind authentication buffer overflow, Solar Eclipse, 14:08
- Re: [Full-disclosure] looking for security community input, ZYRO, 13:47
- Re: [Full-disclosure] The newest Word flaw is due to malformed data structure handling, Alexander Sotirov, 13:07
- [Full-disclosure] [ GLSA 200612-09 ] MadWifi: Kernel driver buffer overflow, Raphael Marichez, 12:56
- [ MDKSA-2006:227 ] - Updated kdegraphics packages fix EXIF vulnerability, security, 00:21
December 11, 2006
- Secunia Research: AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow, Secunia Research, 23:21
- RFID access control tokens widely open to cloning, Adam Laurie, 22:30
- Re: LS-20060908 - Computer Associates BrightStor ARCserve Backup, Williams, James K, 21:29
- The newest Word flaw is due to malformed data structure handling, Juha-Matti Laurio, 21:09
- [ GLSA 200612-10 ] Tar: Directory traversal vulnerability, Matthias Geerdsen, 20:59
- Re: LS-20061001 - Computer Associates BrightStor ARCserve Backup, Williams, James K, 20:39
- Secunia Research: MailEnable IMAP Service Buffer Overflow Vulnerability, Secunia Research, 19:28
- shopsite advisory, DoZ, 18:58
- Firefox 2.0 security bug: Extensions can hide themself, azurIt, 16:37
- [ MDKSA-2006:226 ] - Updated squirrelmail packages fix vulnerabilities, security, 15:47
- D-LINK DWL-2000AP+ remote DoS, poplix, 15:06
- Unauthenticated access to IBM Host On-Demand administration pages, Ferguson, David (Kansas City), 15:06
- [SBDA] - ColdFusion MX7 - Multiple Vulnerabilities, Brett Moore, 14:46
- WASC-Announcement: MX Injection - Capturing and Exploiting Hidden Mail Servers By Vicente Aguilera Diaz, robert, 14:26
- [Full-disclosure] ERRATA: [ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities, Raphael Marichez, 07:43
December 10, 2006
- Re: [Full-disclosure] Another, different MS Word 0-day vulnerability reported, Juha-Matti Laurio, 22:40
- Re: [Full-disclosure] looking for security community input, Stack Smasher, 22:10
- [Full-disclosure] looking for security community input, Gadi Evron, 20:39
- Re: [Full-disclosure] Another, different MS Word 0-day vulnerability reported, Juha-Matti Laurio, 19:49
- [Full-disclosure] Another, different MS Word 0-day vulnerability reported, Juha-Matti Laurio, 19:39
- [Full-disclosure] Several updates in Microsoft Word 0-day (CVE-2006-5994) FAQ document, Juha-Matti Laurio, 19:29
- [Full-disclosure] [ GLSA 200612-09 ] MadWifi: Kernel driver buffer overflow, Raphael Marichez, 18:58
- [Full-disclosure] RFIDIOt release - version 0.1i, Adam Laurie, 18:38
- [Full-disclosure] Multiple vulnerabilities in Winamp Web Interface 7.5.13, Luigi Auriemma, 18:18
- [Full-disclosure] [ GLSA 200612-08 ] SeaMonkey: Multiple vulnerabilities, Raphael Marichez, 16:47
- [Full-disclosure] [ GLSA 200612-07 ] Mozilla Firefox: Multiple vulnerabilities, Raphael Marichez, 16:37
- [Full-disclosure] [ GLSA 200612-06 ] Mozilla Thunderbird: Multiple vulnerabilities, Raphael Marichez, 16:37
- [Full-disclosure] [ GLSA 200612-05 ] KOffice shared libraries: Heap corruption, Sune Kloppenborg Jeppesen, 12:45
- [Full-disclosure] [ GLSA 200612-04 ] ModPlug: Multiple buffer overflows, Raphael Marichez, 11:15
- [Full-disclosure] [ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities, Raphael Marichez, 11:15
December 09, 2006
- AnnonceScriptHP V2.0 Multiple Vulnerabilities, mr_kaliman, 15:48
- Messageriescripthp V2.0 XSS & SQL Injection, mr_kaliman, 15:38
- ProNews V1.5 XSS & SQL Injection, mr_kaliman, 15:27
- KDPics Multiple Vulnerabities, mr_kaliman, 15:17
- Re: XSS in JAB Guest Book, Barnz, 14:47
- [Full-disclosure] [ GLSA 200612-02 ] xine-lib: Buffer overflow, Sune Kloppenborg Jeppesen, 05:23
- [Full-disclosure] Call For Papers: SecurityOPUS 2007, Sharkey, 04:13
December 08, 2006
- PhpBB Toplist 1.3.7 Xss Vuln., starext, 22:00
- ASX Playlists and Jumping to Conclusions, Sûnnet Beskerming, 20:59
- [Full-disclosure] iDefense Security Advisory 12.08.06: Sophos Antivirus CHM File Heap Overflow Vulnerability, iDefense Labs, 20:39
- [Full-disclosure] iDefense Security Advisory 12.08.06: Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability, iDefense Labs, 20:39
- [Full-disclosure] iDefense Security Advisory 12.08.06: Multiple Vendor Antivirus RAR File Denial of Service Vulnerability, iDefense Labs, 20:39
- PHP 5.2.0 session.save_path safe_mode and open_basedir bypass, cxib, 20:19
- Animated Smiley Generator File Include Vul., starext, 20:09
- LS-20061001 - Computer Associates BrightStor ARCserve Backup v11.5 Remote Buffer Overflow Vulnerability, advisories, 19:48
- LS-20060908 - Computer Associates BrightStor ARCserve Backup v11.5 Remote Buffer Overflow Vulnerability, advisories, 19:38
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.), chinese soup, 19:28
- [CAID 34846]: CA BrightStor ARCserve Backup Discovery Service Buffer Overflow Vulnerability, Williams, James K, 17:47
- Midicart vulerable, ifx, 17:17
- [OpenPKG-SA-2006.038] OpenPKG Security Advisory (tar), OpenPKG GmbH, 15:36
- TSLSA-2006-0070 - multi, Trustix Security Advisor, 15:26
- [Aria-Security Team] cPanel BoxTrapper Cross Site Scripting, Advisory, 15:16
- [Aria-Security Team] cPanel 11 pops.html Cross-Site Scripting, Advisory, 14:56
- [Full-disclosure] Enforcing Java Security Manager in Restricted Windows Environments?, Jan P. Monsch, 14:46
- [Aria-Security Team] CentOS 4.2 i686 - WHM X v3.1.0 Cross-Site Scripting, Advisory, 14:46
- [Full-disclosure] [USN-394-1] Ruby vulnerability, Kees Cook, 03:31
- Re: [Full-disclosure] Some Thoughts about Office Open XML and Malware Detection, Robert Kim Wireless Internet Advisor, 03:21
- EEYE: Intel Network Adapter Driver Local Privilege Escalation, eEye Advisories, 00:40
December 07, 2006
- [OpenPKG-SA-2006.037] OpenPKG Security Advisory (gnupg), OpenPKG GmbH, 23:39
- [Full-disclosure] Microsoft Word 0-day Vulnerability FAQ (CVE-2006-5994) written, Juha-Matti Laurio, 22:59
- DUdirectory Admin Panel SQL Injection, Meftun, 21:07
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, Tomasz Kojm, 18:46
- phpAdsNew-2.0.4-pr2 Remote File Inclusion Exploit, crackers_child, 18:36
- Re[2]: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, 3APA3A, 18:26
- [Full-disclosure] [USN-393-2] GnuPG2 vulnerabilities, Kees Cook, 18:16
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, michele.sandrelli@katamail.com, 18:06
- Re: Microsoft 0-day word vulnerability - Secunia - Extremely critical, Juha-Matti Laurio, 17:56
- phpbb 2.0.x [xss], saps . audit, 17:35
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.), Andrius Paurys, 17:15
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, Luke Borg, 17:05
- Re: The Week of Oracle Database Bugs, Tony Jambu, 16:55
- Re: XSS in JAB Guest Book, Steven M. Christey, 16:05
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, Gadi Evron, 15:34
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass, Tomasz Kojm, 15:24
- Re: Microsoft 0-day word vulnerability - Secunia - Extremely critical, Andrew Simmons, 15:24
- [Full-disclosure] Some Thoughts about Office Open XML and Malware Detection, Jan P. Monsch, 15:04
- Digital Armaments Security Advisory 07.12.2006: Yahoo multiple services authentication bypass Vulnerability, info, 14:54
- Linksys WIP 330 VoIP wireless phone crash from Nmap scan, Shawn Merdinger, 14:44
- [Full-disclosure] [ GLSA 200612-01 ] wv library: Multiple integer overflows, Sune Kloppenborg Jeppesen, 08:42
- [Full-disclosure] New MySpace worm could be on its way, pdp (architect), 04:40
- [Full-disclosure] [USN-393-1] GnuPG vulnerability, Kees Cook, 00:18
December 06, 2006
- [Full-disclosure] TSRT-06-15: Citrix Presentation Server Client ActiveX Heap Overflow Vulnerability, TSRT, 23:18
- Microsoft 0-day word vulnerability - Secunia - Extremely critical, Ryan Buena, 22:57
- [Full-disclosure] ZDI-06-044: Adobe Download Manager AOM Parsing Buffer Overflow Vulnerability, zdi-disclosures, 22:37
- [Full-disclosure] [USN-390-3] evince-gtk vulnerability, Kees Cook, 22:27
- rPSA-2006-0227-1 gnupg, rPath Update Announcements, 21:06
- [ MDKSA-2006:225 ] - Updated ruby packages fix DoS vulnerability, security, 18:15
- GnuPG: remotely controllable function pointer [CVE-2006-6235], Werner Koch, 16:44
- SYMSA-2006-012: 2X ThinClientServer Create Admin Account Replay Vulnerability, research, 16:03
- Multiple Vendor Unusual MIME Encoding Content Filter Bypass, Hendrik Weimer, 15:53
- RE: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, Michael Scheidell, 15:33
- BTSaveMySql 1.2 (acces to config files), sn0oPy . team, 15:23
- [Full-disclosure] rPSA-2006-0226-1 kernel, rPath Update Announcements, 15:03
- FreeBSD Security Advisory FreeBSD-SA-06:26.gtar, FreeBSD Security Advisories, 14:32
- FreeBSD Security Advisory FreeBSD-SA-06:25.kmem, FreeBSD Security Advisories, 14:12
- Uploadscript Vulnerabilities: Text file Hash password, hack2prison, 14:02
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.), José Carlos Nieto Jarquín, 13:52
- Internet Explorer 6. CSS Expression Denial of Service (P.o.C.), José Carlos Nieto Jarquín, 13:42
- Barracuda Convert-UUlib library buffer overflow leads to remote compromise, Jean-Sébastien Guay-Leroux, 13:32
- [ MDKSA-2006:224 ] - Updated xine-lib packages fix buffer overflow vulnerability, security, 13:02
- EEYE: Adobe Download Manager AOM Stack Buffer Overflow Vulnerability, eEye Advisories, 12:41
- [Full-disclosure] Oracle PL/SQL Fuzzing Tool, Joxean Koret, 10:51
- [Full-disclosure] [USN-390-2] evince vulnerability, Kees Cook, 01:17
December 05, 2006
- HPSBUX02178 SSRT061267 rev.1 - HP-UX Secure Shell Remote Denial of Service (DoS), security-alert, 22:26
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, Ansgar -59cobalt- Wiechers, 21:55
- [security bulletin] HPSBUX02145 SSRT061202 rev.2 - HP-UX running Apache Remote Execution of Arbitrary Code, Denial of Service (DoS), and Unauthorized Access, security-alert, 20:25
- Re: EasyPage Portal ( all ver )SQL Injection, saps . audit, 20:05
- Re: Symantec LiveState Agent for Windows vulnerabi, eugeny gladkih, 19:44
- Re: Re: [Aria-Security Team] uGestBook SQL Injection Vuln, saps . audit, 19:24
- eEye's Zero-Day Tracker Launch, chinese soup, 19:04
- Re: Symantec LiveState Agent for Windows vulnerabi, Damjan, 18:54
- EasyPage Portal ( all ver )SQL Injection, matrix, 18:34
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, Steve Shockley, 18:24
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, Thor (Hammer of God), 18:04
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, eugeny gladkih, 17:23
- DistrRTgen 1.0 launched!, Martin Jørgensen, 16:43
- CYBSEC - Security Pre-Advisory: SAP Internet Graphics Service (IGS) Remote Arbitrary File Removal, Mariano Nuñez Di Croce, 16:43
- CYBSEC - Security Pre-Advisory: SAP Internet Graphics Service (IGS) Undocumented Features, Mariano Nuñez Di Croce, 16:23
- Re: [Aria-Security Team] uGestBook SQL Injection Vuln, Stuart Moore, 15:42
- URL Rdirecction Bug Yahoo, matrix, 15:32
- RE: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, Michael Scheidell, 15:22
- Re: Evolve Merchant[ injection sql ], tony, 15:02
- Re: GnuPG 1.4 and 2.0 buffer overflow, Damien Miller, 14:52
- [KOffice security advisory] KOffice OLEfilter integer overflow, Dirk Mueller, 14:52
- Re: MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit, 3APA3A, 14:42
- SNORT Covered channels detector patch, fryxar fryxar, 14:32
December 04, 2006
- new xss in modbb forum, h angel, 23:56
- Re: Multiple bugs in TFT-Gallery, simo64, 23:26
- [Full-disclosure] TSRT-06-14: IBM Tivoli Storage Manager Mutiple Buffer Overflow Vulnerabilities, TSRT, 21:45
- XSS in JAB Guest Book, nj, 21:15
- Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation, ss_team, 21:05
- [ MDKSA-2006:214-1 ] - Updated gv packages fix buffer overflow vulnerability, security, 20:44
- Re: aBitWhizzy [local file include], john . goodman, 20:34
- [Full-disclosure] [USN-391-1] libgsf vulnerability, Kees Cook, 20:03
- [Full-disclosure] [USN-392-1] xine-lib vulnerability, Kees Cook, 19:53
- Multiple bugs in TFT-Gallery, nj, 19:53
- Re: Invision Gallery 2.0.7 SQL Injection Vulnerability, emin, 19:13
- [Aria-Security Team] uGestBook SQL Injection Vuln, Advisory, 19:03
- Re: UPublisher Exploit - Superfreaker, me, 18:32
- Vt-Forum Lite System V.1.3 Xss Vuln., starext, 18:02
- MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit, ajannhwt, 17:02
- PhpMyAdmin 2.7.0-pl2 Path Disclosure | Multiple CRLF/Http Response Splitting, ajannhwt, 16:41
- 2[xss]Vulnerabilities in Script Mobile Ac4p.com, gamr-14, 16:31
- SMF upload XSS vulnerability, Jessica Hope, 16:21
- Online BookMarks Multiple SQL Injection/XSS Vulnerabilities, security, 15:41
- [ISecAuditors Security Advisories] XSS vulnerability in error page of ISMail, ISecAuditors Security Advisories, 15:21
- [Full-disclosure] rPSA-2006-0211-2 doxygen libpng, rPath Update Announcements, 15:11
- Metyus Okul Ynetim Sistemi V.1.0 (tr) Sql injection Vuln., ShaFuq31, 15:00
- [ISecAuditors Security Advisories] IMAP/SMTP Injection in Hastymail, ISecAuditors Security Advisories, 14:50
- listpics v5, blasterim, 14:40
- [ISecAuditors Advisories] BlueSocket web administration is vulnerable to XSS, ISecAuditors Security Advisories, 14:20
- [Full-disclosure] F-Prot Antivirus for Unix: heap overflow and Denial of Service, research, 11:28
December 02, 2006
- [Aria-Security Team] DuWare DuPaypal SQL Injection Vuln, Advisory, 17:41
- [Aria-Security Team] DuWare DuForum SQL Injection Vuln, Advisory, 17:11
- CuteNews 1.3.6 XSS, emulamex, 17:01
- [Aria-Security Team] DuWare DuDownloads SQL Injection Vuln, Advisory, 16:41
- [ MDKSA-2006:222 ] - Updated koffice packages fixes integer overflow vulnerability, security, 16:21
- KhaledMuratList mdb, blasterim, 16:11
- PHPNews 1.3.0 XSS, emulamex, 16:01
- [Aria-Security Team] DuWare DuPortal SQL Injection Vuln, Advisory, 15:40
- [Aria-Security Team] DuWare DuClassMate SQL Injection Vuln, Advisory, 15:10
- [Aria-Security Team] DuWare DuNews SQL Injection Vuln, Advisory, 15:00
- [ MDKSA-2006:223 ] - Updated ImageMagick packages fixes vulnerability, security, 14:50
- freeqboard <= 1.1 (qb_path) Remote File Include Vulnerability, -= SHELL =- -= SHELL =-, 03:56
- Re: safely concatenating strings in portable C (Re: GnuPG 1.4 and 2.0 buffer overflow), Simon Josefsson, 02:55
- TSLSA-2006-0068 - multi, Trustix Security Advisor, 00:54
- Aspee Ziyareti Defteri (tr) Sql injection Vuln., ShaFuq31, 00:44
December 01, 2006
- [Full-disclosure] iDefense Security Advisory 12.01.06: Novell ZENworks Asset Management Msg.dll Heap Overflow Vulnerability, iDefense Labs, 18:41
- [Full-disclosure] iDefense Security Advisory 12.01.06: Novell ZENworks Asset Management Collection Client Heap Overflow Vulnerability, iDefense Labs, 18:41
- Outpost Bypassing Self-Protection via Advanced DLL injection with handle stealing Vulnerability, Matousec - Transparent security Research, 18:41
- Layered Defense Advisory: Novell Client 4.91 Format String Vulnerability, dh, 17:50
- [Aria-Security.Net] Web Hosting Control Panel - cPanel 11 Multiple Cross-Site Scripting Vulnerabilites, Advisory, 16:40
- [ MDKSA-2006:221 ] - Updated gnupg packages fix vulnerability, security, 15:49
- [ MDKSA-2006:220 ] - Updated libgsf packages fix heap buffer overflow vulnerability, security, 15:19
- Re: Invision Community Blog Mod 1.2.4 .PHP SQL Injection Vulnerability, emin, 14:49
- Invision Gallery 2.0.7 SQL Injection Vulnerability, infection, 14:39
- Re: [Full-disclosure] Financial firms warned of Qaeda cyber attack, SDALAN04, 12:37
- [Full-disclosure] Financial firms warned of Qaeda cyber attack, Juha-Matti Laurio, 12:17
- [Full-disclosure] deV!L`z Clanportal - Arbitrary File Upload [061124b], Tim Weber, 07:25
- [Full-disclosure] deV!L`z Clanportal - SQL Injection [061124a], Tim Weber, 07:05
- [Full-disclosure] rPSA-2006-0224-1 gnupg, rPath Update Announcements, 07:05
- [Full-disclosure] rPSA-2006-0222-1 tar, rPath Update Announcements, 06:54
- [Full-disclosure] rPSA-2006-0220-1 dovecot, rPath Update Announcements, 06:54
- [Full-disclosure] rPSA-2006-0221-1 openldap openldap-clients openldap-servers, rPath Update Announcements, 06:54
- LifeType version 1.1.2 Multiple Path Disclosure Vulnerabilities, jesper . jurcenoks, 00:32