Bugtraq (date)
October 31, 2007
- [Full-disclosure] ZDI-07-064: Novell Client Trust Heap Overflow Vulnerability, zdi-disclosures, 20:16
- [Full-disclosure] ZDI-07-063: RealPlayer RA Field Size File Processing Heap Oveflow Vulnerability, zdi-disclosures, 20:16
- [Full-disclosure] ZDI-07-061: RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability, zdi-disclosures, 20:16
- [Full-disclosure] ZDI-07-060: HP OpenView Radia Integration Server File System Exposure Vulnerability, zdi-disclosures, 20:06
- [Full-disclosure] ZDI-07-062: RealNetworks RealPlayer PLS File Memory Corruption Vulnerability, zdi-disclosures, 20:06
- [Full-disclosure] ZDI-07-058: Oracle E-Business Suite SQL Injection Vulnerability, zdi-disclosures, 19:55
- [Full-disclosure] ZDI-07-059: Verity KeyView SDK Multiple File Format Parsing Vulnerabilities, zdi-disclosures, 19:55
- rPSA-2007-0227-1 cups, rPath Update Announcements, 17:39
- (tool announcement) bunny the fuzzer, Michal Zalewski, 17:18
- [security bulletin] HPSBMA02238 SSRT061260 rev.2 - HP OpenView Reporter Running Shared Trace Service, Remote Arbitrary Code Execution, security-alert, 16:15
- [security bulletin] HPSBMA02237 SSRT061260 rev.2 - HP OpenView Performance Agent (OVPA) Running Shared Trace Service, Remote Arbitrary Code Execution, security-alert, 16:05
- [security bulletin] HPSBMA02236 SSRT061260 rev.2 - HP OpenView Performance Manager (OVPM) Running Shared Trace Service on HP-UX, Solaris, and Windows, Remote Arbitrary Code Execution, security-alert, 16:05
- [Full-disclosure] iDefense Security Advisory 10.31.07: Symantec Altiris Deployment Solution TFTP/MTFTP Service Directory Traversal Vulnerability, iDefense Labs, 15:13
- [Full-disclosure] iDefense Security Advisory 10.31.07: Macrovision InstallShield Update Service ActiveX Unsafe Method Vulnerability, iDefense Labs, 14:52
- Re: [Full-disclosure] [gentoo-announce] [ GLSA 200710-30 ] OpenSSL: Remote execution of arbitrary code, Steffan Baron, 14:30
- Re: Comments re ISC's announcement on bind9 security, Shane Kerr, 13:39
- Re: [gentoo-announce] [ GLSA 200710-30 ] OpenSSL: Remote execution of arbitrary code, Steffan Baron, 12:46
- Secunia Research: McAfee E-Business Server Auth Packet Handling Buffer Overflow, Secunia Research, 12:04
- Secunia Research: CUPS IPP Tags Memory Corruption Vulnerability, Secunia Research, 11:54
- [Full-disclosure] SEC Consult SA-20071031-0 :: Perdition IMAP Proxy Format String Vulnerability, Bernhard Mueller, 08:47
October 30, 2007
- In Memoriam: Jun-ichiro Hagino, Dragos Ruiu, 19:01
- ILIAS <= 3.8.3 Cross Site Scripting, L4teral, 17:58
- [Full-disclosure] [ GLSA 200710-30 ] OpenSSL: Remote execution of arbitrary code, Pierre-Yves Rofes, 17:48
- [Full-disclosure] [ GLSA 200710-31 ] Opera: Multiple vulnerabilities, Raphael Marichez, 17:26
- Re: Firefox / IE6 crash on javascript nested loops, Jan Heisterkamp, 17:16
- Firefox / IE6 crash on javascript nested loops, thabob, 15:31
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX bellmail Stack Buffer Overflow Vulnerability, iDefense Labs, 15:21
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX ftp domacro Parameter Buffer Overflow Vulnerability, iDefense Labs, 15:20
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX lquerypv Stack Buffer Overflow Vulnerability, iDefense Labs, 15:10
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX lqueryvg Stack Buffer Overflow Vulnerability, iDefense Labs, 14:58
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX dig dns_name_fromtext Integer Underflow Vulnerability, iDefense Labs, 14:58
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX 5.2 crontab BSS Buffer Overflow Vulnerability, iDefense Labs, 14:48
- [Full-disclosure] iDefense Security Advisory 10.30.07: IBM AIX swcons Local Arbitrary File Access Vulnerability, iDefense Labs, 14:37
- DeepSec 2007 Registration: hurry up, seats are filling fast, Stefano Zanero, 12:41
- Airkiosk/formlib application is XSS vuln, skienlab, 12:41
- Django 0.96 (stable) Admin Panel CSRF, J. Carlos Nieto, 12:30
- Secunia Research: IPSwitch IMail Server IMail Client Buffer Overflow, Secunia Research, 12:09
- Siebel Security Basics, Jonathan Katz, 12:09
- [Full-disclosure] RFIDIOt release - version 0.1q, Adam Laurie, 06:27
October 29, 2007
- Re: [Full-disclosure] Holes in the firewall of Mac OS X Leopard, Juergen Schmidt, 20:41
- Re: Holes in the firewall of Mac OS X Leopard, Brandon S. Allbery KF8NH, 18:46
- Holes in the firewall of Mac OS X Leopard, Juergen Schmidt, 18:36
- Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096), Stefan Kanthak, 18:25
- Memory overwrites in JVM via malformed TrueType font, NGSSoftware Insight Security Research, 18:25
- Windows binary of "Virtual Floppy Drive 2.1" contains vulnerable zlib (CAN-2005-2096), Stefan Kanthak, 18:14
- Untrusted Java applet can connect to localhost, NGSSoftware Insight Security Research, 18:03
- Heap overflow in RealPlayer ID3 tag parser, NGSSoftware Insight Security Research, 16:50
- Comments re ISC's announcement on bind9 security, Network Protocol Security, 16:50
- rPSA-2007-0225-2 firefox thunderbird, rPath Update Announcements, 15:57
- [SECURITY] [DSA 1388-3] New dhcp packages fix arbitrary code execution, Noah Meyerhans, 15:06
- SAXON version 5.4 SQL Injection Vulnerability, securityresearch, 14:55
- SAXON version 5.4 Multiple Path Disclosure Vulnerabilities, securityresearch, 14:44
- Security Briefings, angelo, 14:33
- SAXON version 5.4 XSS Attack Vulnerability, securityresearch, 14:33
- AGTC-Membership system v1.1a (adduser) Remote Add Admin Exploit, Guns, 14:23
- Secunia Research: IBM Tivoli Storage Manager Client CAD Service Script Insertion, Secunia Research, 14:12
- Omnistar Live Software Cross-Site Scripting Vulrnability, DoZ, 14:12
- Final Call for Papers for Security Track at ApacheCon Europe 2008, Lars Eilebrecht, 13:30
- Webroot Desktop Firewall <=5.5.10.20 DNS recursion, komarov, 12:36
- [Full-disclosure] Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in procedure DBMS_AQADM_SYS.DBLINK_INFO, Team SHATTER, 12:26
- [Full-disclosure] Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in function MDSYS.SDO_CS.TRANSFORM, Team SHATTER, 12:26
- [waraxe-2007-SA#059] - XSS in WordPress 2.3, come2waraxe, 12:15
- teatro 1.6 ( basePath ) Remote File Include Vulnerability, alkomandoz-hacker, 12:04
- Smart-Shop Shopping Cart Cross-Site Scripting Vulrnability, DoZ, 11:53
- [Full-disclosure] Advisory SE-2007-01: TikiWiki Remote PHP Code Evaluation Vulnerability, Stefan Esser, 07:46
October 26, 2007
- rPSA-2007-0225-1 firefox, rPath Update Announcements, 18:05
- Re: Novell OpenSUSE SWAMP multiple XSS, test, 14:57
- Micro Login System v1.0 (userpwd.txt) Password Disclosure Vulnerability, Guns, 13:33
- [Full-disclosure] FLEA-2007-0060-1 initscripts, Foresight Linux Essential Announcement Service, 06:11
- [Full-disclosure] RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Corruption, Piotr Bania, 01:43
- [Full-disclosure] RealNetworks RealPlayer/RealOne Player/Helix Player Remote Memory Corruption, Piotr Bania, 01:43
October 25, 2007
- [Trick] VigileCMS All Versions DataMining Remote Hash Disclosure, kingoftheworld92, 20:12
- Multi Host Forum Pro phpbb & ipb Multiple Sql Injection, kingoftheworld92, 20:02
- [Full-disclosure] [ GLSA 200710-29 ] Sylpheed, Claws Mail: User-assisted remote execution of arbitrary code, Raphael Marichez, 19:40
- [Full-disclosure] [ GLSA 200710-28 ] Qt: Buffer overflow, Raphael Marichez, 19:19
- [Full-disclosure] [USN-538-1] libpng vulnerabilities, Kees Cook, 19:08
- TikiWiki <= 1.9.8.1 Cross Site Scripting / Local File Inclusion, L4teral, 17:53
- usd250 helpdesk XSS vulnerabily., Joseph . giron13, 15:57
- Directory traversal flaw in shttp, digineo Advisories, 15:36
- i-Gallery 3.4 bug crack password!, hackerbinhphuoc, 15:03
- [Full-disclosure] iDefense Security Advisory 10.25.07: Trend Micro Tmxpflt.sys IOCTL 0xa0284403 Buffer Overflow Vulnerability, iDefense Labs, 14:31
- Re: Re: RE: playing for fun with <=IE7, laurent . gaffie, 14:10
- First ever ModSecurity public training at OWASP/WASC conf in SJ, Ofer Shezaf, 14:10
- Re: A-Cart SQL Injection And Cross-Site Scripting, laurent . gaffie, 13:59
- HPSBMA02133 SSRT061201 rev.6 - HP Oracle for OpenView (OfO) Critical Patch Update, security-alert, 13:17
- Flatnuke3 Remote Cookie Manipoulation / Privilege Escalation, kingoftheworld92, 13:06
October 24, 2007
- [Full-disclosure] [ GLSA 200710-27 ] ImageMagick: Multiple vulnerabilities, Raphael Marichez, 19:55
- [Full-disclosure] [ GLSA 200710-26 ] HPLIP: Privilege escalation, Raphael Marichez, 19:34
- [Full-disclosure] [ GLSA 200710-25 ] MLDonkey: Privilege escalation, Raphael Marichez, 19:22
- [Full-disclosure] rPSA-2007-0221-1 php php-mysql php-pgsql, rPath Update Announcements, 15:01
- [Full-disclosure] iDefense Security Advisory 10.23.07: IBM Lotus Domino IMAP Buffer Overflow Vulnerability, iDefense Labs, 14:50
- [Full-disclosure] iDefense Security Advisory 10.23.07: IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability, iDefense Labs, 14:08
- OSI CODES - PHP Live! Remote File Inclusion, [ NO REPLY ], 13:47
- Bosdev Multiple vulnerabilities, Joseph . giron13, 13:37
- Novell OpenSUSE SWAMP multiple XSS, morin . josh, 13:15
- [GS07-02] RSA Keon Multiple Cross-Site Scripting Vulnerabilities, Fatih Ozavci, 13:04
- [Aria-Security.Net] CodeWidgets.Com Online Event Registration Multiple login SQL Injection, [ NO REPLY ], 12:54
- Aleris Software Systems Web Publisher Calendar SQL injection, Joseph . giron13, 12:43
- HPSBMA02279 SSRT071298 rev.1 - HP OpenView Configuration Management (CM) Infrastructure (Radia) and Client Configuration Manager (CCM) Running httpd.tkd, Remote Unauthorized Access to Data, security-alert, 12:43
- Aria-Security.Net [Web based alpha tabbed address book SQL Injection], [ NO REPLY ], 12:33
- [Full-disclosure] rPSA-2007-0222-1 cpio tar, rPath Update Announcements, 00:29
October 23, 2007
- [SECURITY] [DSA 1394-1] New reprepro packages fix authentication bypass, Thijs Kinkhorst, 19:07
- [Full-disclosure] [USN-537-1] gnome-screensaver vulnerability, Kees Cook, 18:45
- [Full-disclosure] [USN-536-1] Thunderbird vulnerabilities, Kees Cook, 18:45
- [Vulz] PHP Basic Multiple Vulnerabilities by Xcross87 & Alucar, pete.houston.17187, 18:35
- [Full-disclosure] [USN-531-2] dhcp vulnerability, Kees Cook, 17:42
- [Full-disclosure] 3proxy 0.5.3j released (bugfix), 3APA3A, 16:39
- SYMSA-2007-013: Lotus Notes Memory Mapped Files Vulnerability, research, 16:39
- [Vulz] PHP Basic Multiple Vulnerabilities by Xcross87 & Alucar, pete . houston . 17187, 16:06
- Korean GHBoard Multiple Vulnerabilities by Xcross87, pete . houston . 17187, 16:06
- [ MDKSA-2007:202 ] - Updated Firefox packages fix multiple vulnerabilities, security, 15:55
- [Vulz] eFileMan 7.x Multiple Vulnerabilities by Xcross87, pete . houston . 17187, 15:44
- [Vulz] eLouai's Download Script Remote File Download Vulnerability, pete . houston . 17187, 15:12
- [Vulz] Japanese PHP Gallery Hosting File Upload Vulz, pete . houston . 17187, 15:01
- [Vulz] Seeblick 1.0 Beta File Upload Vulz, pete . houston . 17187, 14:51
- SYMSA-2007-012: Microsoft Windows CE IGMP Denial of Service, research, 13:38
- [vuln.sg] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities, vulnpost-remove, 13:38
- Re: [Full-disclosure] IRM Discover More Vulnerabilities in Cisco IOS, crazy frog crazy frog, 13:16
- CFP for HITBSecConf2008 - Dubai now open, Praburaajan, 13:15
- [ MDKSA-2007:201 ] - Updated hplip packages fix vulnerabilities, security, 12:43
- [Full-disclosure] IRM Discover More Vulnerabilities in Cisco IOS, Andy Davis, 12:32
- [Full-disclosure] Airscanner Mobile Security Advisory #07101401: Mobile-spy Victim/User Phone/SMS/URL Log Spoofing and Persistent XSS Injection, Seth Fogie, 12:21
- [Full-disclosure] [PoC] DNS Recursion bandwidth amplification, Shadow, 10:46
- [Full-disclosure] [ GLSA 200710-24 ] OpenOffice.org: Heap-based buffer overflow, Raphael Marichez, 04:45
- [Full-disclosure] [USN-535-1] Firefox vulnerabilities, Kees Cook, 02:41
October 22, 2007
- [Full-disclosure] [USN-501-2] Ghostscript vulnerability, Kees Cook, 19:58
- Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue, advisories, 19:27
- [ GLSA 200710-23 ] Star: Directory traversal vulnerability, Raphael Marichez, 19:26
- [Full-disclosure] Camino release 1.5.2 fixes several vulnerabilities, Juha-Matti Laurio, 17:51
- Jeebles Directory Local File Inclusion, hack2prison, 17:30
- Hackish XSS in shoutbox/blocco.php, deme, 17:30
- [TOOL] w3af - Web Application Attack and Audit Framework, Andres Riancho, 17:09
- Folder Access bypass, hack2prison, 16:48
- Cracking the iPhone (5 article series), H D Moore, 16:48
- [Full-disclosure] [USN-531-1] dhcp vulnerability, Kees Cook, 16:37
- [Full-disclosure] [USN-534-1] OpenSSL vulnerability, Kees Cook, 16:16
- [Full-disclosure] [USN-533-1] util-linux vulnerability, Kees Cook, 16:15
- [Full-disclosure] [USN-532-1] nagios-plugins vulnerability, Kees Cook, 16:04
- [Full-disclosure] simple dns rebinding protection with dnsmasq, Collin R. Mulliner, 16:04
- [ELEYTT] Public Advisory 20-10-2007, Michal Bucko, 14:06
- Simple PHP Blog (sphpblog) <= 0.5.1 Multiple Vulnerabilities, gmdarkfig, 13:56
- [Aria-Security.Net] dmcms.0.7.0 SQL Injection, [No Reply], 13:45
- PacSec 2007 Agenda (Tokyo 11-29/30), Dragos Ruiu, 13:24
- Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096), Stefan Kanthak, 13:24
October 20, 2007
- [Full-disclosure] [ GLSA 200710-22 ] TRAMP: Insecure temporary file creation, Raphael Marichez, 19:16
- [Full-disclosure] [ GLSA 200710-21 ] TikiWiki: Arbitrary command execution, Raphael Marichez, 18:14
- ReloadCMS Vulnerable, sekuru, 14:15
- Simple Machines Forum multiple sql injection flaws with exploit code., th3 . r00k . spammenot, 13:44
- Re: Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096), farion42, 13:33
- [Aria-Security.Net] SearchSimon Lite Cross-Site Scripting Vuln., [ NO REPLY ], 13:23
October 18, 2007
- [Full-disclosure] [ GLSA 200710-20 ] PDFKit, ImageKits: Buffer overflow, Raphael Marichez, 20:25
- [ MDKSA-2007:200 ] - Updated tk packages fix vulnerabilities, security, 19:54
- [Full-disclosure] S21SEC-038-en: Alcatel Omnivista 4760 Cross-Site Scripting, S21sec Labs, 19:33
- [Full-disclosure] [ GLSA 200710-19 ] The Sleuth Kit: Integer underflow, Raphael Marichez, 19:11
- Official Windows binaries of "curl" contain vulnerable zlib 1.2.2 (CAN-2005-2096), Stefan Kanthak, 19:01
- Softwin's anti-virus BitDefender contains vulnerable zlib (CA-2007-07), Stefan Kanthak, 18:50
- [Full-disclosure] Serious holes affecting SiteBar 3.3.8, Tim Brown, 18:50
- Windows binary of "GSview 4.8" contain vulnerable zlib (CAN-2005-2096), Stefan Kanthak, 18:39
- [Full-disclosure] [ GLSA 200710-18 ] util-linux: Local privilege escalation, Raphael Marichez, 18:07
- rPSA-2007-0219-1 libpng, rPath Update Announcements, 17:36
- [CORRECTED] Microsoft Windows XP SP2/2003 - Macrovision SecDrv.sys privilege escalation (0day), Reversemode, 17:25
- Re[2]: [Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu, Thierry Zoller, 17:04
- Re: Multiple CSRF in SimplePHPBlog, Hanno BÃck, 16:53
- Re: SSH attacks - anyone else seen these?, Tim, 16:53
- CFP C H A S E - 2 0 0 7 Lahore Pakistan, chase, 16:42
- [security bulletin] HPSBMA02274 SSRT071445 rev.2 - HP System Management Homepage (SMH) for HP-UX, Remote Cross Site Scripting (XSS), security-alert, 15:08
- [security bulletin] HPSBUX02273 SSRT071476 rev.2 - HP-UX Running Apache, Remote Unauthorized Denial of Service (DoS), security-alert, 14:57
- Nortel Telephony Server Denial of Service, daniel . stirnimann, 14:36
- Latest web hacking incidents, Ofer Shezaf, 14:25
- Nortel IP Phone forced re-authentication, daniel . stirnimann, 14:14
- Nortel IP Phone Flooding Denial of Service, daniel . stirniman, 13:53
- Nortel IP Phone Surveillance Mode, daniel . stirnimann, 13:42
- Nortel UNIStim IP Softphone Buffer-Overflow, daniel . stirnimann, 13:21
- Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day), Reversemode, 13:10
October 17, 2007
- SYMSA-2007-011: Microsoft WM5 PocketPC Phone Ed SMS Handler Issue, research, 17:49
- [ MDKSA-2007:199 ] - Updated phpMyAdmin packages fix multiple vulnerabilities, security, 17:39
- Re: SSH attacks - anyone else seen these?, pand0ra, 17:17
- Re: Netgear FVG318 is vunerable to DOS attack, NetGear, 16:24
- Re: SSH attacks - anyone else seen these?, James Lay, 15:42
- Re: [Full-disclosure] SQL Injection Flaw in Oracle Workspace Manager, full-disclosure, 15:31
- Re: RE: CheckPoint Secure Platform Multiple Buffer Overflows, hvazquez, 14:47
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, KJK::Hyperion, 14:15
- AST-2007-023 - SQL Injection Vulnerabilty in cdr_addon_mysql, Asterisk Security Team, 13:54
- Multiple CSRF in SimplePHPBlog, deme, 13:12
- [Full-disclosure] SQL Injection Flaw in Oracle Workspace Manager, David Litchfield, 12:29
- [Full-disclosure] Oracle audit issue with XMLDB ftp service, NGSSoftware Insight Security Research, 10:55
- [Full-disclosure] Multiple SQL Injection Flaws in Oracle CTX_DOC package, NGSSoftware Insight Security Research, 10:55
- [Full-disclosure] (no subject), NGSSoftware Insight Security Research, 10:54
- [Full-disclosure] Oracle RDBMS TNS Data packet DoS, NGSSoftware Insight Security Research, 10:54
- Re: [Full-disclosure] Third-party patch for CVE-2007-3896, UPDATE NOW, full-disclosure, 10:13
- Re: [Full-disclosure] Third-party patch for CVE-2007-3896, UPDATE NOW, KJK::Hyperion, 09:52
- [Full-disclosure] Oracle TNS Listener DoS and/or remote memory inspection, NGSSoftware Insight Security Research, 09:31
- [Full-disclosure] Net & System Security 2007, giovanni manunta, 06:46
October 16, 2007
- [Full-disclosure] [ GLSA 200710-17 ] Balsa: Buffer overflow, Raphael Marichez, 20:07
- Re: SSH attacks - anyone else seen these?, Jose Nazario, 18:55
- [ MDKSA-2007:195 ] - Updated kernel packages fix multiple vulnerabilities and bugs, security, 18:44
- Re: SSH attacks - anyone else seen these?, Mark R. Bowyer, 18:24
- Re: SSH attacks - anyone else seen these?, Gayathri Swaminathan, 18:02
- RE: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Andy Davis, 17:51
- [security bulletin] HPSBUX02277 SSRT071453 rev.1 - HP-UX Running OpenSSL, Local Denial of Service (DoS), security-alert, 17:51
- [security bulletin] HPSBTU02276 SSRT071472 rev.1 - HP Tru64 UNIX Running Apache Tomcat, Remote Unauthorized Access, Remote Denial of Service (DoS), security-alert, 17:30
- [ MDKSA-2007:196 ] - Updated kernel packages fix multiple vulnerabilities and bugs, security, 17:30
- [security bulletin] HPSBST02280 SSRT071480 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-055 to MS07-060, security-alert, 17:08
- [ MDKSA-2007:197 ] - Updated tar packages prevent buffer overflow, security, 17:08
- [security bulletin] HPSBMA02230 SSRT071436 rev.2 - HP Select Identity, Remote Unauthorized Access, security-alert, 16:47
- SSH attacks - anyone else seen these?, Tim, 16:37
- Secunia Research: IrfanView Palette File Importing Buffer Overflow Vulnerability, Secunia Research, 16:26
- [ MDKSA-2007:198 ] - Updated util-linux packages fix vulnerability, security, 15:54
- WWWISIS <= 7.1 (IsisScript) Multiple Vulnerabilities, jose luis góngora fernández, 15:33
- FW: [Dailydave] Canada's Response to Black Hat - SecTor 2007, Taylor, Gord, 15:11
- about phpMyAdmin setup.php XSS vulnerability, Marc Delisle, 14:39
- CVE-2007-4600 - Mathcad Protect Worksheet Vulnerability, bugtraq, 14:17
- [Full-disclosure] IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX, Andy Davis, 13:56
October 15, 2007
- Re: RE: playing for fun with <=IE7, jason . gerfen, 21:03
- HTML Injection Vuln in nssboard, kcghost, 20:32
- Re: [Full-disclosure] playing for fun with <=IE7, avivra, 20:00
- RE: playing for fun with <=IE7, Roger A. Grimes, 19:39
- Xcomputer - Lang Parameter Cross-Site Scripting Vulnerability, jose luis góngora fernández, 19:28
- Stringbeans (Portal) - Lang Parameter Cross-Site Scripting Vulnerability, jose luis góngora fernández, 18:35
- InnovaShop?® (mgs.jps) Cross Siting Scripting, jose luis góngora fernández, 18:24
- SYMSA-2007-010: Microsoft ActiveSync 4.x Weak Password Obfuscation, research, 18:03
- RE: playing for fun with <=IE7, James C. Slora Jr., 17:32
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, James (njan) Eaton-Lee, 13:35
- [Full-disclosure] eXtremail(ly easy) remote roots, mu-b, 09:47
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, gjgowey, 09:16
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, pdp (architect), 08:45
- Re: [Full-disclosure] I made third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling), KJK::Hyperion, 01:41
- [Full-disclosure] I made third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling), KJK::Hyperion, 01:41
October 14, 2007
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, C Q, 21:02
- [Full-disclosure] [ GLSA 200710-16 ] X.Org X server: Composite local privilege escalation, Pierre-Yves Rofes, 20:09
- [Full-disclosure] [ GLSA 200710-15 ] KDM: Local privilege escalation, Pierre-Yves Rofes, 19:48
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, C Q, 16:53
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, pdp (architect), 01:11
- [Full-disclosure] Third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling) available, KJK::Hyperion, 00:50
October 13, 2007
- [Full-disclosure] Clients buffer-overflow in Live for Speed 0.5X10, Luigi Auriemma, 17:17
- playing for fun with <=IE7, laurent . gaffie, 14:21
- VImpX ActiveX (VImpX.ocx v. 4.7.3.0) Remote, saw_xyz, 13:49
- [Full-disclosure] [ GLSA 200710-14 ] DenyHosts: Denial of Service, Pierre-Yves Rofes, 09:20
- [Full-disclosure] [ GLSA 200710-13 ] Ampache: Multiple vulnerabilities, Pierre-Yves Rofes, 09:10
October 12, 2007
- [Full-disclosure] [ GLSA 200710-12 ] T1Lib: Buffer overflow, Pierre-Yves Rofes, 19:42
- [Full-disclosure] [ GLSA 200710-11 ] X Font Server: Multiple Vulnerabilities, Pierre-Yves Rofes, 19:00
- [Full-disclosure] [ GLSA 200710-10 ] SKK Tools: Insecure temporary file creation, Raphael Marichez, 18:18
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Mark Senior, 17:45
- [Full-disclosure] [USN-530-1] hplip vulnerability, Kees Cook, 17:03
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Roman Medina-Heigl Hernandez, 15:18
- Re: Remote Desktop Command Fixation Attacks, hvdkooij, 15:07
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Thor (Hammer of God), 14:25
- Re: Joomla! swMenuFree 4.6 Component Remote File Include, sean, 13:42
- Re: [Full-disclosure] Tikiwiki 1.9.8 exploit ITW, full-disclosure, 10:45
- [Full-disclosure] SEC Consult SA-20071012-0 :: Madwifi xrates element remote DOS, Bernhard Mueller, 09:12
- Re: [Full-disclosure] Tikiwiki 1.9.8 exploit ITW, 3APA3A, 08:00
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Pete Simpson, 06:17
October 11, 2007
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, John C. A. Bambenek, CISSP, 20:17
- [Full-disclosure] Tikiwiki 1.9.8 exploit ITW, Moritz Naumann, 19:35
- [CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities, Williams, James K, 19:13
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Jim Harrison, 19:13
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Xo Plague, 19:13
- [Full-disclosure] rPSA-2007-0214-1 initscripts, rPath Update Announcements, 19:13
- [Full-disclosure] S21SEC-037-en: OPAL SIP Protocol Remote Denial of Service, S21sec Labs, 18:52
- [security bulletin] HPSBMA02230 SSRT071436 rev.1 - HP Select Identity, Remote Unauthorized Access, security-alert, 18:41
- EEYE: CA BrightStor ArcServe Backup Server Arbitrary Pointer Dereference, eEye Advisories, 17:57
- [Full-disclosure] iDefense Security Advisory 10.11.07: Multiple Vendor FLAC Library Multiple Integer Overflow Vulnerabilities, iDefense Labs, 17:57
- [security bulletin] HPSBUX02273 SSRT071476 rev. 1 - HP-UX running Apache, Remote Unauthorized Denial of Service (DoS), security-alert, 17:36
- Re: Remote Desktop Command Fixation Attacks, pdp (architect), 17:25
- RE: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Andy Davis, 17:14
- [Full-disclosure] [USN-529-1] Tk vulnerability, Kees Cook, 16:53
- Re: URI handling as the harbinger of interaction errors, Florian Weimer, 16:53
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Alex Everett, 16:53
- Re: Vulnerabilities, Victor Brilon, 16:52
- RE: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Andy Davis, 16:42
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Halvar Flake, 16:41
- Re: Vulnerabilities, sottwell, 16:41
- Black Hat Tokyo + DC and Europe CfPs now open., Jeff Moss, 16:09
- Joomla! swMenuFree 4.6 Component Remote File Include, Guns, 15:59
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Florian Weimer, 15:48
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Halvar Flake, 15:38
- Re: RE: CheckPoint Secure Platform Multiple Buffer Overflows, fwadmin, 15:38
- M$ will fix URI?, Memisyazici, Aras, 15:27
- October Microsoft Tuesday, Todd Manning, 14:55
- [ MDKSA-2007:194 ] - Updated libvorbis packages fix vulnerabilities, security, 14:45
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, pdp (architect), 14:24
- Fwd: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape,Miranda, Skype, merigoth, 14:02
- URI handling as the harbinger of interaction errors, Steven M. Christey, 13:41
- IRM Advisory: Cisco IOS LPD Remote Stack Overflow, Andy Davis, 13:30
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, gboyce, 12:48
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Paul Melson, 11:45
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, Obscure, 11:45
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 10:32
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, gboyce, 10:22
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, gjgowey, 10:22
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, pdp (architect), 09:30
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, M. Burnett, 08:28
- [Full-disclosure] CA BrightStor ARCServe BackUp Message Engine Remote Stack Overflow Vulnerability, hfli, 05:33
- [Full-disclosure] [USN-528-1] MySQL vulnerabilities, Kees Cook, 04:31
- [Full-disclosure] CORE-2007-0928: Stack-based buffer overflow vulnerability in OpenBSDâs DHCP server, Core Security Technologies Advisories, 00:54
October 10, 2007
- [ELEYTT] 10PAZDZIERNIK2007, Michal Bucko, 21:46
- Re: [Full-disclosure] ZDI-07-056: IBM DB2 DB2JDS Multiple Vulnerabilities, Joel Jaeggli, 21:24
- RE: Remote Desktop Command Fixation Attacks, Thor (Hammer of God), 21:24
- [Full-disclosure] TPTI-07-18: EMC RepliStor Server Heap Overflow Vulnerability, TSRT, 19:48
- [Full-disclosure] ZDI-07-057: Firebird process_packet() Remote Stack Overflow Vulnerability, zdi-disclosures, 19:48
- [Full-disclosure] ZDI-07-055: Microsoft Windows DCERPC Authentication Denial of Service Vulnerability, zdi-disclosures, 19:38
- [Full-disclosure] ZDI-07-056: IBM DB2 DB2JDS Multiple Vulnerabilities, zdi-disclosures, 19:38
- Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Halvar Flake, 19:17
- AST-2007-022: Buffer overflows in voicemail when using IMAP storage, The Asterisk Development Team, 19:07
- Re: Remote Desktop Command Fixation Attacks, Steve Shockley, 18:56
- [SECURITY] [DSA 1379-2] New openssl packages fix arbitrary code execution, Noah Meyerhans, 17:30
- Re: [Full-disclosure] Vulnerabilities digest, full-disclosure, 16:38
- [Full-disclosure] Vulnerabilities digest, 3APA3A, 16:27
- [Full-disclosure] iDefense Security Advisory 10.10.07: Kaspersky Web Scanner ActiveX Format String Vulnerability, iDefense Labs, 16:05
- Re: [Full-disclosure] 0day: Hacking secured CITRIX from outside, M.B.Jr., 15:54
- Re: [Full-disclosure] 0day: Hacking secured CITRIX from outside, full-disclosure, 15:43
- Re: [Full-disclosure] Remote Desktop Command Fixation Attacks, full-disclosure, 15:43
- Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques, Damir Rajnovic, 15:00
- [Full-disclosure] 0day: Hacking secured CITRIX from outside, pdp (architect), 14:49
- Several vulnerabilities in CMS Made Simple 1.1.3.1, Omid, 14:28
- Remote Desktop Command Fixation Attacks, pdp (architect), 14:27
- wmtrssreader joomla component 1.0 Remote File Include Vulnerability, cyber-crime, 14:17
- 3Com WIFI router remote administration vulnerability., Guy Mizrahi, 14:06
- Regarding vulnerability in ViArt Shop, support, 13:55
- Re: [Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu, Sergio Alvarez, 13:02
- Re: [Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu, Thierry Zoller, 11:06
- Re: [Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu, Felix 'FX' Lindner, 08:07
- Re: [Full-disclosure] iDefense Security Advisory 10.09.07:Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow, gjgowey, 06:23
- Re: [Full-disclosure] iDefense Security Advisory 10.09.07: Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow, Nick FitzGerald, 06:13
- Re: [Full-disclosure] Report to Recipient(s), gjgowey, 00:52
October 09, 2007
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, KJK::Hyperion, 23:07
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, john lokka, 22:57
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Gregory Rubin, 22:46
- [Full-disclosure] [ GLSA 200710-08 ] KOffice, KWord, KPDF, KDE Graphics Libraries: Stack-based buffer overflow, Pierre-Yves Rofes, 20:10
- [Full-disclosure] [ GLSA 200710-09 ] NX 2.1: User-assisted execution of arbitrary code, Pierre-Yves Rofes, 19:59
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 18:54
- RE: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Jim Slora, 17:07
- [Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu, Thierry Zoller, 16:55
- [Full-disclosure] iDefense Security Advisory 10.09.07: Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow, iDefense Labs, 16:34
- [Full-disclosure] NULL pointer crash in World in Conflict 1.000, Luigi Auriemma, 16:23
- Research: Cybercrime and the Electoral System, Oliver Friedrichs, 15:40
- LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues, Chris Travers, 15:40
- Vulnerabilities, xoxland, 15:29
- [Full-disclosure] [USN-527-1] xen-3.0 vulnerability, Kees Cook, 15:19
- DNewsWeb Softwares Cross Site Scripting Vulrnability, DoZ, 15:08
- Viart Shopping Cart Directory Transversal Vuln, [ NO REPLY ], 14:25
- Black Hat Tokyo + DC and Europe CfPs now open., Jeff Moss, 14:14
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 14:04
- [security bulletin] HPSBMA02275 SSRT071445 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS), security-alert, 14:03
- [security bulletin] HPSBMA02274 SSRT071445 rev.1 - HP System Management Homepage (SMH) for HP-UX, Remote Cross Site Scripting (XSS), security-alert, 13:52
- [security bulletin] HPSBUX02181 SSRT061289 rev.3 - HP-UX Running IPFilter, Remote Denial of Service (DoS), security-alert, 13:41
- [security bulletin] HPSBUX01137 SSRT5954 rev.11 - HP-UX Running TCP/IP (IPv4), Remote Denial of Service (DoS), security-alert, 13:20
- [security bulletin] HPSBUX02262 SSRT071447 rev. 1 - HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS), security-alert, 13:09
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Andreas Lindenblatt, 08:48
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Andreas Lindenblatt, 06:44
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Brett Moore, 06:44
- [Full-disclosure] rPSA-2007-0212-1 util-linux, rPath Update Announcements, 06:34
- [Full-disclosure] rPSA-2007-0210-1 xen, rPath Update Announcements, 06:34
October 08, 2007
- [Full-disclosure] BT Home Flub: Pwnin the BT Home Hub, Adrian P, 18:49
- TorrentTrader Classic Mutiple Remote vulnerabilities, security, 14:07
- new vuln in snewscms.net.ru in lang file, info, 13:35
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Morning Wood, 08:35
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, 3APA3A, 07:33
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, KJK::Hyperion, 01:22
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, gjgowey, 01:22
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Lamer Buster, 00:51
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, KJK::Hyperion, 00:51
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Geo., 00:41
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Geo., 00:30
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Geo., 00:20
October 07, 2007
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, KJK::Hyperion, 22:27
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Glynn Clements, 22:06
- [Full-disclosure] [ GLSA 200710-07 ] Tk: Buffer overflow, Raphael Marichez, 19:40
- [Full-disclosure] [ GLSA 200710-06 ] OpenSSL: Multiple vulnerabilities, Pierre-Yves Rofes, 19:09
- [Full-disclosure] [ GLSA 200710-05 ] QGit: Insecure temporary file creation, Pierre-Yves Rofes, 18:59
- [Full-disclosure] [ GLSA 200710-04 ] libsndfile: Buffer overflow, Raphael Marichez, 17:57
- [Full-disclosure] [ GLSA 200710-03 ] libvorbis: Multiple vulnerabilities, Raphael Marichez, 17:47
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 15:32
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Valdis . Kletnieks, 12:57
- Re: [Full-disclosure] SSHatter 0.6, full-disclosure, 12:26
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, gjgowey, 08:41
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, terry white, 08:10
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Roger A. Grimes, 08:10
- [Full-disclosure] [ GLSA 200710-02 ] PHP: Multiple vulnerabilities, Raphael Marichez, 07:18
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, James Matthews, 05:35
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Geo., 03:32
October 06, 2007
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Kurt Dillard, 16:36
- Else If cms Multiple Remote vulnerabilities, security, 16:05
- idmos-phoenix cms Remote File inclusion, security, 15:34
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 14:42
- CMS Creamotion - Remote File inclusion, security, 14:32
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Geo., 14:21
- [Full-disclosure] SSHatter 0.6, Tim Brown, 13:49
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 13:49
- Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Thierry Zoller, 12:47
- RE: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Juergen Schmidt, 11:55
- Re: BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer), Amit Klein, 11:55
- [Aria-Security] Stuffed Tracker Multiple Cross-Site Scripting VULN, [ NO REPLY ], 11:45
October 05, 2007
- RE: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Roger A. Grimes, 17:37
- Re: Re: file upload vulnerability in joomla media component, vinodsharma . mimit, 16:54
- Reporting Vulnerable Public Web mail, ivan . sanchez, 16:54
- [Full-disclosure] Format string in The Dawn of Time 1.69s beta4, Luigi Auriemma, 16:22
- [Full-disclosure] Multiple vulnerabilities in Dropteam 1.3.3, Luigi Auriemma, 16:22
- rPSA-2007-0209-1 elinks, rPath Update Announcements, 14:05
- [ MDKSA-2007:193 ] - Updated openssl packages fix vulnerabilities, security, 13:44
- Re: [Full-disclosure] iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability, Joey Mengele, 12:18
- [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype, Juergen Schmidt, 12:07
October 04, 2007
- [Full-disclosure] [USN-524-1] OpenOffice.org vulnerability, Kees Cook, 22:45
- [Full-disclosure] [USN-526-1] debian-goodies vulnerability, Kees Cook, 22:34
- [Full-disclosure] [USN-525-1] libsndfile vulnerability, Kees Cook, 21:53
- DDIVRT-2007-05 NetSupport Manager Client Buffer Overflow, vulnerabilityresearch, 19:48
- [ GLSA 200710-01 ] RPCSEC_GSS library: Buffer overflow, Pierre-Yves Rofes, 19:27
- [Aria-Security] Stuffed Tracker Multiple Cross-Site Scripting VULN, [ NO REPLY ], 18:24
- Re: Re[2]: 0day: mIRC pwns Windows, Gavin Hanover, 16:39
- Re: 0day: mIRC pwns Windows, Fred Elliot, 15:57
- Re: [Full-disclosure] iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability, iDefense Labs, 15:57
- Re: OpenSSL SSL_get_shared_ciphers() off-by-one buffer overflow, ejc, 15:46
- Re: 0day: mIRC pwns Windows, Greg Rubin, 14:54
- Re: [Full-disclosure] iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability, 3APA3A, 14:11
- Re: Two buffer-overflow in FSD V2.052 d9 and FSFDT V3.000 d9[EXPLOIT], weak, 14:01
- [RISE-2007002] Borland InterBase Multiple Buffer Overflow Vulnerabilities, RISE Security, 13:50
- Re[2]: 0day: mIRC pwns Windows, 3APA3A, 13:39
- [RISE-2007003] Firebird Relational Database Multiple Buffer Overflow Vulnerabilities, RISE Security, 13:29
- [Full-disclosure] FLEA-2007-0059-1 qt qt-tools, Foresight Linux Essential Announcement Service, 09:50
- [Full-disclosure] Cart32 Arbitrary File Download Vulnerability, Paul Craig, 06:44
October 03, 2007
- FreeBSD Security Advisory FreeBSD-SA-07:08.openssl, FreeBSD Security Advisories, 21:18
- [Full-disclosure] [USN-523-1] ImageMagick vulnerabilities, Kees Cook, 20:46
- [Full-disclosure] FLEA-2007-0058-1 openssl openssl-scripts, Foresight Linux Essential Announcement Service, 20:35
- Content Builder 0.7.5 RFI Bug, mehrad1989, 19:34
- Re: 0day: mIRC pwns Windows, Gregory Rubin, 18:32
- rPSA-2007-0206-1 openssl openssl-scripts, rPath Update Announcements, 18:21
- Re: 0day: mIRC pwns Windows, Gavin Hanover, 18:11
- rPSA-2007-0205-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs, rPath Update Announcements, 18:11
- rPSA-2007-0204-1 qt-x11-free, rPath Update Announcements, 18:00
- DRBGuestbook Remote XSS Vulnerability, gokhankaya, 16:57
- Re: BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer), sathyakrishnadas, 16:47
- Re: Ruby Net::HTTPS library does not validate server certificate CN, Thomas, 16:36
- RE: CheckPoint Secure Platform Multiple Buffer Overflows, Hugo van der Kooij, 16:25
- International Hacking & Security Conference "POC200", poc2007, 16:15
- 0day: mIRC pwns Windows, jinc4fareijj, 16:15
- RE: CheckPoint Secure Platform Multiple Buffer Overflows, Tony Reusser, 15:33
- [Full-disclosure] iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability, iDefense Labs, 12:12
- Re: [Full-disclosure] The real motivations of vulnerability disclosure, endrazine, 09:37
- [Full-disclosure] FLEA-2007-0057-1 pidgin, Foresight Linux Essential Announcement Service, 05:50
- [Full-disclosure] The real motivations of vulnerability disclosure, Mr Frog, 04:18
October 02, 2007
- [Full-disclosure] rPSA-2007-0203-1 rmake rmake-proxy rmake-repos, rPath Update Announcements, 21:25
- [Full-disclosure] iDefense Security Advisory 10.02.07: Multiple Vendor X Font Server Multiple Vulnerabilities, iDefense Labs, 19:51
- [SECURITY] [DSA 1379-1] New openssl packages fix arbitrary code execution, Noah Meyerhans, 18:38
- [Full-disclosure] TPTI-07-16: CA BrightStor Hierarchical Storage Manager Buffer Overflow Vulnerabilities, TSRT, 18:37
- [Full-disclosure] TPTI-07-17: CA BrightStor Hierarchical Storage Manager SQL Injection Vulnerabilities, TSRT, 18:27
- Re: dvddb-0.6 media sql-inj. vuln., james, 18:26
- [Full-disclosure] Original Photo Gallery Remote Command Execution, ascii, 16:41
- Re: CheckPoint Secure Platform Multiple Buffer Overflows, hvazquez, 14:15
- WifiZoo v1.2 release, Hernan Ochoa, 13:11
- [ MDKSA-2007:192 ] - Updated mplayer packages fix vulnerability, security, 12:50
October 01, 2007
- [ MDKSA-2007:191 ] - Updated libsndfile packages fix vulnerability, security, 18:40
- Immunity Debugger v1.2 Release, Nicolas Waisman, 17:37
- ClubHack - CFP closing by 15th October 2007, `ClubHack `, 17:37
- Re: phpBB Mod OpenID 0.2.0 BBStore.php Remote File Inclusion, str0ke, 17:27
- ASP-CMS version 1 default password location., joseph . giron13, 16:55
- smbftpd 0.96 format string vulnerability, Jerry Illikainen, 16:23
- CheckPoint Secure Platform Multiple Buffer Overflows, hvazquez, 16:12
- New Advisory: X-script GuestBook, m2x, 16:12
- Re: OpenSSL SSL_get_shared_ciphers() off-by-one buffer overflow, snagg, 16:01
- phpBB Mod OpenID 0.2.0 BBStore.php Remote File Inclusion, h3llcode, 15:40
- eGov Content Manager Cross Site Scripting Vulrnability, DoZ, 15:40
- [Full-disclosure] Two buffer-overflow in FSD V2.052 d9 and FSFDT V3.000 d9, Luigi Auriemma, 15:40
- [Full-disclosure] Format string in the Doom 3 engine through PB, Luigi Auriemma, 15:40
- [Full-disclosure] Format string in F.E.A.R. 1.08 through PB, Luigi Auriemma, 15:29
- [Full-disclosure] Unexploitable buffer-overflow in America's Army 2.8.2 through PB, Luigi Auriemma, 15:29
- ASP Product catalog SQL injection vulnerability, joseph . giron13, 15:29
- Affiliate Network Pro Multiple Input Validation and Local file inclusion, hack2prison, 15:08