|
Mailing List Archive For bugtraq@securityfocus.com Aug 2007 By Subject- 24th Chaos Communication Congress 2007: Call for Participation
- [ GLSA 200708-01 ] Macromedia Flash Player: Remote arbitrary code execution
- [ GLSA 200708-02 ] Xvid: Array indexing vulnerabilities
- [ GLSA 200708-03 ] libarchive (formerly named as bsdtar): Multiple pax Extension Header Vulnerabilities
- [ GLSA 200708-04 ] ClamAV: Denial of Service
- [ GLSA 200708-05 ] GD: Multiple vulnerabilities
- [ GLSA 200708-06 ] Net::DNS: Multiple vulnerabilities
- [ GLSA 200708-07 ] Xfce Terminal: Remote arbitrary code execution
- [ GLSA 200708-08 ] SquirrelMail G/PGP plugin: Arbitrary code execution
- [ GLSA 200708-09 ] Mozilla products: Multiple vulnerabilities
- [ GLSA 200708-10 ] MySQL: Denial of Service and information leakage
- [ GLSA 200708-11 ] Lighttpd: Multiple vulnerabilities
- [ GLSA 200708-12 ] Wireshark: Multiple vulnerabilities
- [ GLSA 200708-13 ] BIND: Weak random number generation
- [ GLSA 200708-14 ] NVIDIA drivers: Denial of Service
- [ GLSA 200708-15 ] Apache mod_jk: Directory traversal
- [ GLSA 200708-16 ] Qt: Multiple format string vulnerabilities
- [ GLSA 200708-17 ] Opera: Multiple vulnerabilities
- [ MDKSA-2007:151 ] - Updated qt3 packages fix multiple vulnerabilities
- [ MDKSA-2007:152 ] - Updated Firefox packages fix multiple vulnerabilities
- [ MDKSA-2007:153 ] - Updated gd packages fix several vulnerabilities
- [ MDKSA-2007:154 ] - Updated xine-ui packages fix denial of service and arbitrary code execution
- [ MDKSA-2007:155 ] - Updated tcpdump packages fix remote denial of service
- [ MDKSA-2007:156 ] - Updated imlib2 packages fix several issues
- [ MDKSA-2007:157 ] - Updated kdelibs packages fix cross-site scripting (XSS) vulnerabilities
- [ MDKSA-2007:158 ] - Updated xpdf packages fix vulnerability
- [ MDKSA-2007:159 ] - Updated gpdf packages fix vulnerability
- [ MDKSA-2007:160 ] - Updated pdftohtml packages fix vulnerability
- [ MDKSA-2007:161 ] - Updated poppler packages fix vulnerability
- [ MDKSA-2007:162 ] - Updated kdegraphics packages fix vulnerability
- [ MDKSA-2007:163 ] - Updated koffice packages fix vulnerability
- [ MDKSA-2007:164 ] - Updated tetex packages fix multiple vulnerabilities
- [ MDKSA-2007:165 ] - Updated cups packages fix vulnerability
- [ MDKSA-2007:166 ] - Updated rsync packages fix off-by-one buffer overflow
- [ MDKSA-2007:167 ] - Updated libvorbis packages fix vulnerabilities
- [ MDKSA-2007:167-1 ] - Updated libvorbis packages fix vulnerabilities
- [ MDKSA-2007:168 ] - Updated vim packages fix vulnerability
- [ MDKSA-2007:169 ] - Updated gdm packages fix DoS vulnerability
- [ MDKSA-2007:170 ] - Updated gimp packages fix input data validation issues in several plugins
- [ MDKSA-2007:171 ] - Updated kernel packages fix multiple vulnerabilities and bugs
- [ MDKSA-2007:172 ] - Updated clamav packages vulnerabilities
- [Aria-Security.Net] Gallery In A Box Username & Password Parameters SQL Injection
- [Aria-Security.Net] Next Gen Portfolio Manager SQL Injection
- [Aria-Security.net] SAS Hotel Management System SQL Injection
- [BuHa-Security] DoS Vulnerability in Konqueror 3.5.7
- [BuHa-Security] Winamp 5.35 (Infinite) M3U File Inclusion DoS Vulnerability
- [BuHa-Security] Winamp 5.35 (Infinite) M3U File Inclusion Stack Overflow
- [CFP] Kiwicon 2k7 - Call For Papers
- [ELEYTT] 3SIERPIEN2007
- [ELEYTT] 4SIERPIEN2007
- [Full-disclosure] Konqueror: URL address bar spoofing vulnerabilities
- [Full-disclosure] McAfee Virus Scan for Linux and Unix v5.10.0 Local Buffer Overflow
- [Full-disclosure] SecNiche : Microsoft Internet Explorer Pop up Blocker Bypassing and Dos Vulnerability
- [HISPASEC] Blizzard StarCraft Brood War 1.15.1 Remote DoS
- [HISPASEC] Fileinfo 2.0.9 plugin for Total Commander multiple vulnerabilities
- [HS-A007] Qbik WinGate Remote Denial of Service
- [o0o] Bypassing servlet input validation filters (OWASP Stinger + Struts example)
- [Reversemode Advisory] CheckPoint ZoneLabs Vsdatant.sys multiple local privilege escalation vulnerabilities
- [security bulletin] HPSBMA02235 SSRT061260 rev.1 - HP OpenView Internet Service (OVIS) Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02237 SSRT061260 rev.1 - HP OpenView Performance Agent (OVPA) Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02238 SSRT061260 rev.1 - HP OpenView Reporter Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02239 SSRT061260 rev.1 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02241 SSRT061260 rev.1 - HP OpenView Service Quality Manager (OV SQM) Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02242 SSRT061260 rev.1 - HP OpenView Network Node Manager (OV NNM) Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02244 SSRT061260 rev.1 - HP OpenView Business Process Insight and Related Products Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02245 SSRT061260 rev.1 - HP OpenView Dashboard Running Shared Trace Service, Remote Arbitrary Code Execution
- [security bulletin] HPSBMA02246 SSRT061260 rev.1 - HP OpenView Performance Insight (OVPI) Running Shared Trace Service, Remote Arbitrary Code Execution --------
- [security bulletin] HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS)
- [security bulletin] HPSBUX02247 SSRT071432 rev.1 - HP-UX Running ARPA Transport, Local Denial of Service (DoS)
- [security bulletin] HPSBUX02248 SSRT071437 rev.1 - HP-UX Running ARPA Transport, Remote Denial of Service (DoS)
- [security bulletin] HPSBUX02251 SSRT071449 rev.1 - HP-UX Running BIND, Remote DNS Cache Poisoning
- [SECURITY] [DSA 1344-1] New iceweasel packages fix several vulnerabilities
- [SECURITY] [DSA 1345-1] New xulrunner packages fix several vulnerabilities
- [SECURITY] [DSA 1346-1] New iceape packages fix several vulnerabilities
- [SECURITY] [DSA 1347-1] New xpdf packages fix arbitrary code execution
- [SECURITY] [DSA 1348-1] New poppler packages fix arbitrary code execution
- [SECURITY] [DSA 1349-1] New libextractor packages fix arbitrary code execution
- [SECURITY] [DSA 1350-1] New tetex-bin packages fix arbitrary code execution
- [SECURITY] [DSA 1351-] New bochs packages fix privilege escalation
- [SECURITY] [DSA 1352-1] New pdfkit.framework packages fix arbitrary code execution
- [SECURITY] [DSA 1353-1] New tcpdump packages fix arbitrary code execution
- [SECURITY] [DSA 1354-1] New gpdf packages fix arbitrary code execution
- [SECURITY] [DSA 1355-1] New kdegraphics packages fix arbitrary code execution
- [SECURITY] [DSA 1356-1] New Linux 2.6.18 packages fix several vulnerabilities
- [SECURITY] [DSA 1357-1] New koffice packages fix arbitrary code execution
- [SECURITY] [DSA 1358-1] New asterisk packages fix several vulnerabilities
- [SECURITY] [DSA 1359-1] New dovecot packages fix directory traversal
- [SECURITY] [DSA 1360-1] New rsync packages fix arbitrary code execution
- [SECURITY] [DSA 1361-1] New postfix-policyd packages fix arbitrary code execution
- [SECURITY] [DSA 1362-1] New lighttpd packages fix several vulnerabilities
- [SECURITY] [DSA 1363-1] New Linux 2.6.18 packages fix several vulnerabilities
- [USN-469-2] Enigmail regression
- [USN-494-1] Gimp vulnerability
- [USN-495-1] Qt vulnerability
- [USN-496-1] koffice vulnerability
- [USN-496-2] poppler vulnerability
- [USN-497-1] xfce4-terminal vulnerability
- [USN-498-1] libvorbis vulnerabilities
- [USN-499-1] Apache vulnerabilities
- [USN-500-1] rsync vulnerability
- [USN-501-1] jasper vulnerability
- [USN-502-1] KDE vulnerabilities
- [USN-503-1] Thunderbird vulnerabilities
- [USN-504-1] Emacs vulnerability
- [USN-505-1] vim vulnerability
- [USN-506-1] tar vulnerability
- [USN-507-1] tcp-wrappers vulnerability
- [USN-508-1] Linux kernel vulnerabilities
- [USN-509-1] Linux kernel vulnerabilities
- [USN-510-1] Linux kernel vulnerabilities
- [Whitepaper SecNiche] Insecurities in Implementing Serialization in BISON
- Abledesign Dynamic Picture Frame XSS
- about recent phpMyAdmin "vulnerabilities"
- Aceboard forum, SQL injection
- Active Gmail "Sidejacking" - https is NOT ENOUGH
- AL-Athkar.v2.0 Remote File Include
- AL-Caricatier V.2.5 Remote File Include
- ALL vgallite Remote File Include
- Announcement: Releasing CORE GRASP for PHP. An open source, dynamic web application protection system.
- Another Oracle Forensics Paper...
- Ariadne CMS Remote File Inclusion
- ASA-2007-019: Remote crash vulnerability in Skinny channel driver
- AST-2007-020: Resource Exhaustion Vulnerability in Asterisk SIP channel driver
- AST-2007-021: Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage
- Astaro DOS and POP3 bypass issues partially resolved
- AuraCMS [Forum Module] - Remote SQL Injection
- Aztech router DSL600EU IP and ARP spoof
- Baidu Soba Remote Code Execute Vulnerability(FGA-2007-10)
- Beautifier Version 0.1 Remote File Include Vulnerability // MefistoLabs.Com
- BellaBook Admin Bypass/Remote Code Execution
- Best Top List Remote File Upload Vulnerability
- BH/DC: Tactical Exploitation Materials
- Bilder Uploader 1.3 Remote Command Execution Vulnerability
- BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer)
- Buffer-overflow in the Asura engine
- C-SAM oneWallet forget password Cross Site Scripting vulnerability
- Camino release 1.5.1 fixes several vulnerabilities
- cfp: TRsec, Istanbul Turkey
- Cisco CSS WebNS ssh crash
- Cisco NHRP denial of service (cisco-sa-20070808-nhrp)
- Cisco Security Advisory: Cisco IOS Secure Copy Authorization Bypass Vulnerability
- Cisco Security Advisory: Local Privilege Escalation Vulnerabilities in Cisco VPN Client
- Cisco Security Advisory: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
- Community input/questions for ISOI 3?
- Contact at Secure Computing
- ContentDM Search.php XSS Vulnerability
- Coppermine Photo Gallery (yabbse.inc.php) Remote File Inclusion Vulnerability
- CORRECTION: EXPL0it FIXED :JPG PoC denial of service exploit by CrazyAngel
- COSEINC Linux Advisory #1: Linux Kernel Parent Process Death Signal Vulnerability
- CounterPath X-Lite SIP phone Remote Denial of Service vulnerability
- Crash in Zoidcom 0.6.7
- Cross Platform remote IM vulnerability / DOS
- Cross Site Request Forgery in 2wire routers
- CVE-2007-3382: Handling of cookies containing a ' character
- CVE-2007-3384: XSS in Tomcat cookies example
- CVE-2007-3385: Handling of \" in cookies
- CVE-2007-3386: XSS in Host Manager
- Default Root Password in Infrant (now Netgear) ReadyNAS "RAIDiator"
- Design flaw in AS3 socket handling allows port probing
- DeskPRO Admin Panel Multiple HTML Injections
- Digital Armaments Security Advisory 24.07.2006: Siemens Speedstream Wireless/Router Denial of Service Vulnerability
- DoS in Microsoft Media Player 11 on Win XP SP2
- DOS issue in Astaro Version 7 packet filter reporting, POSSIBLE security issue in POP3 proxy
- EEYE: VGX.DLL Compressed Content Heap Overflow Vulnerability
- EEYE: Windows Metafile AttemptWrite Heap Overflow
- Encryption Weakness in Sun Sun AS 9.0_0.1 (build b02-p01)
- EnterpriseDB Advanced Server 8.2 Unitialized Pointer
- Envolution (News) <= v1.1.0 Remote SQL Injection
- eXV2.de Browser Cookie is not properly sanitised
- eyeOS checksum prediction
- EZPhotoSales 1.9.3 Multiple Vulnerabilities
- FCMS (Family Connections) <= 0.1.1 Remote Command Execution Exploit // www.MefistoLabs.com
- File Uploader Version 1.1 Remote Command Execution Vulnerability
- FinDix Remote File Inclusion Vulnerability
- FLEA-2007-0038-1 gimp
- FLEA-2007-0039-1 firefox
- FLEA-2007-0040-1 thunderbird
- FLEA-2007-0041-1 gdm
- FLEA-2007-0042-1 qt
- FLEA-2007-0043-1 openssl
- FLEA-2007-0044-1 tetex tetex-dvips tetex-fonts
- FLEA-2007-0045-1 poppler
- FLEA-2007-0046-1 cups
- FLEA-2007-0047-1 rsync
- FLEA-2007-0048-1 xterm
- FLEA-2007-0049-1 tar
- Found nice mass exploits for fedora and imap
- FreeBSD Security Advisory FreeBSD-SA-07:01.jail [REVISED]
- FreeBSD Security Advisory FreeBSD-SA-07:06.tcpdump
- FreeBSD Security Advisory FreeBSD-SA-07:07.bind
- Gstebuch Version 1.5 Remote Command Execution Vulnerability
- Guestbook Script 1.9 RFI
- Guidance Software response to iSEC report on EnCase
- Gurur Haber v2.0
- Heap overflow in Skulltag 0.97d-beta4.1
- HPSBMA02236 SSRT061260 rev.1 - HP OpenView Performance Manager (OVPM) Running Shared Trace Service on HP-UX, Solaris, and Windows, Remote Arbitrary Code Execution
- HPSBMA02239 SSRT061260 rev.2 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution
- HPSBMA02240 SSRT061260 rev.1 - HP OpenView Operations Manager for Windows (OVOW) with the OpenView Operations Add On Module for OpenView Operations-Business Availability Center Integration Running Shared Trace Service, Remote Arbitrary Code Execution
- HPSBMA02242 SSRT061260 rev.2 - HP OpenView Network Node Manager (OV NNM) Running Shared Trace Service, Remote Arbitrary Code Execution --------
- HPSBST02255 SSRT071456 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-042 to MS07-050
- HPSBTU02256 SSRT071449 rev.1 - HP Tru64 UNIX or HP Tru64 Internet Express running BIND, Remote DNS Cache Poisoning
- HPSBUX02249 SSRT071442 rev.1 HP-UX Running the Ignite-UX or the DynRootDisk (DRD) get_system_info Command, Local Unqualified Configuration Change
- Hunkaray Okul Portali v1.1 (tr) Sql injection Vuln
- IBM Rational ClearQuest Web SQL Injection Login Bypass
- iDefense Security Advisory 08.07.07: Apple Mac OS X mDNSResponder HTTP Request Heap Overflow Vulnerability
- iDefense Security Advisory 08.07.07: Hewlett-Packard HP-UX Remote ldcconn Buffer Overflow Vulnerability
- iDefense Security Advisory 08.09.07: Hewlett-Packard OpenView Operations OVTrace Buffer Overflow Vulnerabilities
- iDefense Security Advisory 08.14.07: Microsoft Windows Vista Sidebar RSS Feeds Gadget Cross Site Scripting Vulnerability
- iDefense Security Advisory 08.14.07: Microsoft XML Core Services XMLDOM Memory Corruption Vulnerability
- iDefense Security Advisory 08.15.07: ESRI ArcSDE Numeric Literal Buffer Overflow Vulnerability
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database buildDasPaths Buffer Overflow Vulnerability
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Directory Creation Vulnerability
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Directory Traversal Vulnerability
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple File Creation Vulnerabilities
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple Race Condition Vulnerabilities
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple Untrusted Search Path Vulnerabilities
- iDefense Security Advisory 08.20.07: Check Point Zone Labs Multiple Products Privilege Escalation Vulnerability
- iDefense Security Advisory 08.20.07: Check Point Zone Labs VSDATANT Multiple IOCTL Privilege Escalation Vulnerabilities
- iDefense Security Advisory 08.20.07: Trend Micro SSAPI Long Path Buffer Overflow Vulnerability
- iDefense Security Advisory 08.21.07: Trend Micro ServerProtect Multiple Buffer Overflow Vulnerabilities
- iDefense Security Advisory 08.21.07: Trend Micro ServerProtect RPCFN_SYNC_TASK Integer Overflow Vulnerability
- iDefense Security Advisory 08.27.07: Motorola Timbuktu Multiple Buffer Overflow Vulnerabilities
- iDefense Security Advisory 08.27.07: Motorola Timbuktu Pro Directory Traversal Vulnerability
- iDefense Security Advisory 08.30.07: Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities
- IMF 2007 - Call for Participation
- Immunity Debugger is now released
- Immunity Debugger v1.1 Release
- InterWorx-CP Multiple HTML Injections Vulnerabilitie
- Invision Power Board D22-Shoutbox HTML Injections
- JobLister3 SQL injection vulnerabilities
- Join us at OWASP Mumbai Meet : 6th September 2007
- Joomla 1.0.12 CMS - Session fixation Issue in backend Administration interface
- Joomla Component SimpleFAQ V2.11 - Remote SQL Injection
- Joomla J! Reactions Component Remote File include Bug
- Konqueror: URL address bar spoofing vulnerabilities
- la-nai cms_v1.2.14 - Remote SQL Injection
- Lib2 PHP v0.2 (DOCUMENT_ROOT) Remote File Inclusion Vulnerability
- Local Privilege Escalation Vulnerabilities in Lotus Notes Client
- Local privilege escalation vulnerability in Cisco VPN client
- Mambo 4.6.2 CMS - Session fixation Issue in backend Administration interface
- Mambo Component SimpleFAQ V2.11 - Remote SQL Injection
- Mapos Bilder Galerie Version 1.0 Remote Command Execution Vulnerability
- McAfee Virus Scan for Linux and Unix v5.10.0 Local Buffer Overflow
- mcNews (skinfile) Remote File Include Vulnerability
- Minimo .2 and more Firefox 2.0.0.6 Password Manager Vulnerabilites
- Moonware Software Multiple Vulnerabilities
- More on VMWare poor guest isolation design
- MS07-042 XMLDOM substringData() PoC
- Multiple denial of service in Soldat 1.4.2/2.6.2
- Multiple OS kernel insecure handling of stdio file descriptor
- Multiple vulnerabilities in Babo Violent 2 2.08.00
- Multiple vulnerabilities in Doomsday 1.9.0-beta5.1
- Multiple vulnerabilities in ircu
- Multiple vulnerabilities in Live for Speed 0.5X10
- Multiple vulnerabilities in rFactor 1.250
- Multiple vulnerabilities in Toribash 2.71
- MySQLDumper vulnerability: Bypassing Apache based access control possible
- n.runs, Sophos, German laws, and customer safety
- n.runs-SA-2007.025 - ClamAV Remote Code Execution Advisory
- n.runs-SA-2007.026 - Sophos Antivirus BZip parsing Infinite Loop Advisory
- n.runs-SA-2007.027 - Sophos Antivirus UPX parsing Arbitrary CodeExecution Advisory
- Neuron Blog Admin Permission Bypass and Remote File Upload Vulnerability
- New Oracle Forensics Paper
- No cON Name 2007 - CALL FOR PAPERS
- NSFOCUS SA2007-01 : Microsoft IE5 CSS Parsing Memory Corruption Vulnerability
- Olate Download 3.4.1 ~ admin.php ~ Admin authentication bypassing
- Olate Download 3.4.1~environment.php.php~Code Execution
- Olate Download 3.4.2 ~ userupload.php ~ Upload Executable Files
- Olate Download 3.4.2~download.php ~ sql injection
- Olate Download 3.4.2~modules/core/fldm.php~comments tag [url] XSS
- Olate Download 3.4.2~modules/core/uim.php~XSS
- Olate Download 3.4.2~uploads folder ~ directory traversal
- OpenBSD 4.1 - Heap overflow vulnerabillity
- our de France Pool 1.0.1 Remote File İnclude Bug
- OWASP Mumbai Meeting : 6th Sep 2007
- PHP Blue Dragon CMS 3.0.0 Remote File Inclusion Vulnerability (0dd exploit)
- PHP-Nuke (ALL versions) Multiple XSS and HTML injection
- php-stats xss whois.php
- PHPCentral Login Script Remote Command Execution Vulnerability
- PHPCentral Poll Script Remote Command Execution Vulnerability
- phpDVD v1.0.4 (dvd_config_file) Remote File Include Exploit
- PhpGedView login page multiple XSS
- phpress 0.2.0 (adisplay.php) Remote File Inclusion
- Pluck 4.3 themes.php Remote File Inclusion and disclosure
- PR07-23: Non-persistent Cross-site Scripting (XSS) on Absolute Poll Manager XE admin page
- Pwnie Awards Ceremony
- Question about exploit exposing SSN & user info
- Ragnarok Online Control Panel Authentication Bypass Vulnerability [new method]
- Release of Pass-The-Hash Toolkit for Windows v1.0
- Reminder: HITBSecConf2007 - Malaysia is less than 2 weeks away
- Remote Denial of Service for SSH service at Dell DRAC4 (maybe Mocana SSH)
- Remote Denial of Service for SSH service at Dell DRAC4 (maybeMocana SSH)
- Remote Memory Read in Diskeeper 9 - 2007
- report a bug !
- Ripe Website Manager SQL Injection and Cross Site Scripting Vulnerabilities
- rPSA-2007-0153-1 qt-x11-free
- rPSA-2007-0154-1 cups poppler tetex tetex-afm tetex-dvips tetex-fonts tetex-latex tetex-xdvi
- rPSA-2007-0155-1 openssl openssl-scripts
- rPSA-2007-0157-1 firefox thunderbird
- rPSA-2007-0160-1 openoffice.org
- rPSA-2007-0161-1 dovecot
- rPSA-2007-0164-1 kernel
- rPSA-2007-0168-1 rsync
- rPSA-2007-0169-1 xterm
- rPSA-2007-0172-1 tar
- Safari for windows remote arbitry file upload
- SecNiche : Microsoft Internet Explorer Pop up Blocker Bypassing and Dos Vulnerability
- Security Advisory for Bugzilla 3.0, 2.22.1, and 2.20.4
- security contact for uat.edu needed
- Security vulnerability in BufferZone 2.5
- security vulnerability in VMware
- Shoutbox 1.0 Remote Command Execution Vulnerability
- SIDVault LDAP Server Remote Buffer Overflow
- SIEMENS Gigaset SE361 router XSS
- Skype Network Remote DoS Exploit
- SolpotCrew Advisory #15 (home_edition2001) - Weblogicnet (files_dir) Remote File Inclusion
- Sony: The Return Of The Rootkit
- SOTEeSKLEP Remote File Disclosure Vulnerability
- SPIP v1.7 Remote File Inclusion Bug
- SQL Injection in Cisco CallManager
- Streamripper 1.62.1 - Buffer Overflows
- Summercon 2007 Atlanta August 24 - 26
- Sunshop v4.0 <= Blind SQL Injection exploit
- SYMSA-2007-007: Palm OS Treo Smartphone Denial of Service
- Systme de vote en temps rel v1.0 Remote File include Bug
- Team SHATTER Advisory: IBM DB2 Buffer overflow in sysproc.auth_list_groups_for_authid
- TeamSpeak 2 Server Vulnerabilities?
- The Korean Hacking & Security Conference "POC 2007" call for papers
- The Long Run
- Tikiwiki 1.9.7 HTML/embed object injection
- TlbInf32 ActiveX Command Execution
- ToorCon 9 CFP
- TPTI-07-14: HP OpenView Multiple Product Shared Trace Service Stack Overflow Vulnerabilities
- Trackeur v.1 Remote File İnclude Bug
- TS-2007-001-0: BlueCat Networks Adonis Linux-HA heartbeat DoS Vulnerability
- TS-2007-002-0: BlueCat Networks Adonis root Privilege Access
- TS-2007-003-0: BlueCat Networks Adonis CLI root privilege escalation
- TSLSA-2007-0024 - multi
- Unexploitable buffer-overflow in the logging function of the Unreal engine
- Updated: VMware poor guest isolation design
- vBulletin V3.6.8 XSS Password Md5 Hash
- VietPHP Remote File Inclusion Vulnerbility
- VMWare poor guest isolation design
- VNSECON07 Materials released
- Vulnerabilities digest
- Vulnerability in multiple "now playing" scripts for various IRC clients
- Web News 1.1 Remote Command Execution Vulnerability
- WengoPhone SIP phone Remote Denial of Service vulnerability
- WikiWebWeaver 1.1 beta Upload Shell Vulnerability
- WireShark MMS Remote Denial of Service vulnerability
- X-Diesel Unreal Commander v0.92 (build 573) multiple vulnerabilities
- XSS vulnerability in Cisco MeetingPlace
- ZDI-07-045: Novell Client NWSPOOL.DLL Stack Overflow Vulnerability
- ZDI-07-046: Microsoft Windows Media Player Skin Parsing Size Mismatch Heap Overflow Vulnerability
- ZDI-07-047: Microsoft Windows Media Player Malformed Skin Header Code Execution Vulnerability
- ZDI-07-048: Microsoft Internet Explorer substringData() Heap Overflow Vulnerability
- ZDI-07-049: EMC Legato Networker Remote Exec Service Stack Overflow Vulnerabilities
- Zyxel Zywall 2 multiple vulnerabilities
|