164 messages starting Jan 22 03 and ending Jan 24 03 Date index | Thread index | Author index
IE chain vulnerability Alex Loots
Opentype font file causes Windows to restart. Andrew
Buffer OverFlow in SQLBase 8.1.0 - NII Advisory Arjun Pednekar
Tru64 Unix (various versions) stdio vulnerability Arrigo Triulzi
Unreal engine: results of my research Auriemma Luigi Emule 0.27b remote crash Auriemma Luigi
Slapper/Sapphire Vulnerable non-Microsoft products Chris Wysopal Slapper/Sapphire Vulnerable non-Microsoft products (update) Chris Wysopal OpenSSL Private Key Disclosure Chris Wysopal Microsoft IIS 5.0 WebDAV remote buffer overflow Chris Wysopal Windows Scripting Engine issue Chris Wysopal Administrivia: acceptable postings Chris Wysopal
sendmail 8.12.9 available Claus Assmann
CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent CORE SECURITY TECHNOLOGIES ADVISORIES CORE-20030304-02: Vulnerability in Mutt Mail User Agent CORE Security Technologies Advisories CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability CORE Security Technologies Advisories CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome CORE Security Technologies Advisories
WinAmp v.3.0: buffer overflow D4rkGr3y CuteFTP: buffer overflow D4rkGr3y EServ/2.97 remote DoS D4rkGr3y AN HTTPd v.1.41e: DoS, CSS, real patch attack D4rkGr3y
New attack vectors and a vulnerability dissection of MS03-007 David Litchfield
WebIntelligence session hijacking vulnerability Dirk Van Droogenbroeck
Kebi Academy 2001 Web Solution Directory Traversing Vulnerability. dong-h0un U ++Danger++ Outblaze Web based e-mail that is exposed in very dangerous state !!! dong-h0un U
[INetCop Security Advisory] Remote format string vulnerability in Tanne. dong-h0un yoU
pgp4pine stack overflow vulnerability Eric AUGE
[DDI-1012] Malformed request causes denial of service in HP Instant TopTools Erik Parker
MIT Kerberos FTP client remote shell commands execution Fozzy [Hackademy Audit] MS-Windows ME IE/Outlook/HelpCenter critical vulnerability Fozzy [Hackademy Audit]
E-theni (PHP) Frog Man myphpPagetool (php) Frog Man phpMyShop (php) Frog Man php-Board (php) Frog Man DotBr (PHP) Frog Man Kietu ( PHP ) Frog Man D-Forum (PHP) Frog Man Myguestbook (PHP) Frog Man WihPhoto (PHP) Frog Man Invision Power Board (PHP) Frog Man WebChat (PHP) Frog Man GTcatalog (PHP) Frog Man PHP-Nuke 6.0 (& 6.5?) : Serious SQL Injection Security Holes Frog Man PHP-Nuke 6.0 & 6.5RC2 SQL Injection Again Frog Man PHP-Nuke : banners.php Frog Man PHP-Nuke, 'News' module : Big Security Holes Frog Man
*ALERT* INCLUDING EXPLOIT: Advisory / Exploit for mpg123 gobbles
Efficient Networks 5861 DSL Router Greg Bolshaw
[SCSA-008] Cross Site Scripting & Script Injection Vulnerability in PY-Livredor Gregory Le Bras | Security Corporation [SCSA-009] Remote Command Execution Vulnerability in PHP Ping Gregory Le Bras | Security Corporation [SCSA-010] Path Disclosure & Cross Site Scripting Vulnerability in MyABraCaDaWeb Gregory Le Bras | Security Corporation [SCSA-012] Multiple vulnerabilities in Sambar Server Gregory Le Bras | Security Corporation [SCSA-014] Remote Denial of Service Vulnerability in EZ Server Gregory Le Bras | Security Corporation
[SCSA-005] Proxomitron Naoko Long Path Buffer Overflow/DoS Grégory Le Bras | Security Corporation
Opera's Security Model is Highly Vulnerable (GM#002-OP) GreyMagic Software Phantom of the Opera (GM#003-OP) GreyMagic Software Opera Images (GM#004-OP) GreyMagic Software Opera: What's Next (GM#005-OP) GreyMagic Software Sniffing Opera's Tracks (GM#006-OP) GreyMagic Software
Terminal Emulator Security Issues H D Moore
Re: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachme nt evasion issue http-equiv () excite com
iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package iDEFENSE Labs iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords iDEFENSE Labs iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix iDEFENSE Labs iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a iDEFENSE Labs iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsing iDEFENSE Labs iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1) iDEFENSE Labs iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine iDEFENSE Labs
Fwd: Ptrace hole / Linux 2.2.25 Immo 'FaUl' Wehrenberg
Mulitple vulnerabilities found in BisonFTP Immune Advisory [immune advisory] Mulitple vulnerabilities found in BisonFTP Immune Advisory
Implementation flaws in Adobe Document Server for Reader Extensions info
Secunia Research: Opera browser Cross Site Scripting Jakob Balle
PHP Security Advisory: CGI vulnerability in PHP version 4.3.0 Jani Taskinen
TRACE used to increase the dangerous of XSS. Jeremiah Grossman
PDS: Integer overflow in FreeBSD kernel Joost Pol
IMP 2.x SQL injection vulnerabilities Jouko Pynnonen Apache Jakarta Tomcat 3 URL parsing vulnerability Jouko Pynnonen Apache Jakarta Tomcat 3 URL parsing vulnerability Jouko Pynnonen
Re: CuteFTP 5.0 XP, Buffer Overflow Kanatoko
Re: Opentype font file causes Windows to restart. Kaspar Brand
S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server Lluis Mora
shopfactory shopping cart Maarten Hartsuijker
Tool: Sapphire SQL Worm Scanner Marc Maiffret EEYE: XDR Integer Overflow Marc Maiffret
Java-Applet crashes Opera 6.05 and 7.01 Marc Schoenefeld
Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis Mark Litchfield Domino Advisories UPDATE Mark Litchfield More Lotus Domino Advisories Mark Litchfield
Corsaire Security Advisory - Clearswift MAILsweeper MIME attachme nt evasion issue Martin O'Neal Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue Martin O'Neal
Multible Vulns in PlatinumFTP server matrix Directory traversal vulnerabilities found in NITE ftp-server version 1.83 matrix Multible vulnerabilities found in Shambala Server version 4.5 matrix Directory Traversal vulnerability found in Enceladus Server Suite version 3.9 matrix Multiple vulnerabilities found in PlatinumFTPserver V1.0.7 matrix Banner Buffer Overflows found in Multible FTP Clients matrix Multible vulnerabilities found in Forum Web Server v1.60 matrix
Path Parsing Errata in Apache HTTP Server mattmurphy () kc rr com
BitKeeper remote shell command execution/local vulnerability Maurycy Prodeus
Potential disclosure of sensitive information in Netscape 7.0 email client Michael Puchol
Sendmail: -1 gone wild Michal Zalewski
PivX Advisory MK002A Intuit TurboTax Information Disclosure Vulnerability Mkristovich PivX Advisory MK002B H&R Block TaxCut Information Disclosure Vulnerability Mkristovich
A security vulnerability in S8Forum NaSsEr .M.Sh vulnerability in versatile BulletinBoard Allows Gaining Administrative Privileges. NaSsEr .M.Sh
Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003) NGSSoftware Insight Security Research Oracle unauthenticated remote system compromise (#NISR16022003a) NGSSoftware Insight Security Research Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b) NGSSoftware Insight Security Research Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c) NGSSoftware Insight Security Research Oracle9i Application Server Format String Vulnerability (#NISR16022003d) NGSSoftware Insight Security Research Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a) NGSSoftware Insight Security Research Lotus Domino Web Server iNotes Overflow (#NISR17022003b) NGSSoftware Insight Security Research Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c) NGSSoftware Insight Security Research Oracle bfilename function buffer overflow vulnerability (#NISR16022003e) NGSSoftware Insight Security Research ISMAIL (All Versions) Remote Buffer Overrun NGSSoftware Insight Security Research
NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability NSFCOSU Security Team NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability NSFCOSU Security Team NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability NSFCOSU Security Team
More information regarding Etherleak Ofir Arkin
SOHO Routefinder 550 VPN, DoS and Buffer Overflow Peter Kruse
3com RAS 1500 Remote vulnerabilities. Piotr Chytla
Cpanel 5 and below remote command execution and local root vulnerabilities pokleyzz
iis 0day exploit Rafael Nuñez This is the WebDav Exploit ffs Rafael Nuñez
Followup to Gobbles post Rain Forest Puppy CERT Advisory CA-2003-01 Buffer Overflows in ISC DHCPD Minires Library (fwd) Rain Forest Puppy Multiple MySQL bugs Rain Forest Puppy administrivia: cross-site tracing Rain Forest Puppy CERT Advisory CA-2003-03 Buffer Overflow in Windows Locator Service (fwd) Rain Forest Puppy CERT Advisory CA-2003-06 Multiple vulnerabilities in SIP/VoIP Rain Forest Puppy
R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication Rapid 7 Security Advisories R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow Rapid 7 Security Advisories R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression Rapid 7 Security Advisories
Assorted Trend Vulns Rev 2.0 Rod Boron
Security bug in CGI::Lite::escape_dangerous_chars() function Ronald F. Guilmette
Postnuke v 0.723 SQL injection and directory traversing saleh
RE: Assorted Trend Vulns Rev 2.0 Shayne Sivley
libIM.a buffer overflow vulnerability. Shiva Persaud
Etherleak: Ethernet frame padding information leakage (A010603-1) @stake Advisories @stake Advisory: TruBlueEnvironment Privilege Escalation Attack @stake Advisories QuickTime/Darwin Streaming Administration Server - Multiple Vulnerabilities @stake Advisories Nokia 6210 DoS SMS Issue @stake Advisories Sun ONE (iPlanet) Application Server Connector Module Overflow @stake Advisories Nokia SGSN (DX200 Based Network Element) SNMP issue @stake Advisories ePolicy Orchestrator Format String Vulnerability (a031703-1) @stake Advisories
Advisory 01/2003: CVS remote vulnerability Stefan Esser
Etnereal Advisory (Guninski #60) Steve
eEye - SQL Sapphire Worm Analysis Steve W. Manzuik
[SecurityOffice] Netcharts XBRL Server v4.0.0 Information Leakage Vulnerability Tamer Sahin
Alexandria-dev / sourceforge multiple vulnerabilities Thomas Kristensen
Re: Opentype font file causes Windows to restart. Tiina Anita Muukkonen
.MHT Buffer Overflow in Internet Explorer Tom Tanaka
phpBB SQL Injection vulnerability Ulf Harnhammar Hypermail buffer overflows Ulf Harnhammar Rogue buffer overflow Ulf Harnhammar
Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged Vladimir Katalov
Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities Wojciech Purczynski
ISS Security Brief: PeopleSoft XML External Entities Vulnerability X-Force ISS Security Brief: Microsoft SQL Slammer Worm Propagation X-Force ISS Security Brief: Remote Sendmail Header Processing Vulnerability X-Force ISS Security Brief: Snort RPC Preprocessing Vulnerability X-Force ISS Security Brief: PeopleSoft PeopleTools Remote Command Execution Vulnerability X-Force
Re: New Web Vulnerability - Cross-Site Tracing xss-is-lame