Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




127 messages starting May 17 03 and ending Apr 16 03
Date index | Thread index | Author index

0x36

Buffer overflow vulnerability found in MailMax version 5 0x36

Andreas Constantinides

Plaintext Password in Settings.ini of CesarFTP Andreas Constantinides

Auriemma Luigi

Abyss X1 1.1.2 remote crash Auriemma Luigi

Aviram Jenik

Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach Aviram Jenik

Berend-Jan Wever

Coppermine Photo Gallery remote compromise Berend-Jan Wever

B.K. DeLong

Black Hat 2003 Speaker Lineup; Phil Zimmermann to Keynote B.K. DeLong

bob

Firebird local root compromise bob

Brett Moore

Windows Media Services Remote Command Execution Brett Moore
Windows Media Services Remote Command Execution #2 Brett Moore

Carsten H. Eiram

Secunia Research: Xeneo Web Server URL Encoding Denial of Service Carsten H. Eiram
Secunia Research: FTPServer/X Response Buffer Overflow Vulnerability Carsten H. Eiram

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco ONS15454, ONS15327, ONS15454SDH, and ONS15600 Nessus Vulnerabilities Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerabilities Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets Cisco Systems Product Security Incident Response Team

CORE Security Technologies Advisories

CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability CORE Security Technologies Advisories
CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall CORE Security Technologies Advisories
CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client CORE Security Technologies Advisories
CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass CORE Security Technologies Advisories

Dennis Rand

Buffer Overflow Vulnerability Found in MailMax Version 5 Dennis Rand
Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328) Dennis Rand
Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0 Dennis Rand

dong-h0un U

[INetCop Security Advisory] Remote Multiple Buffer Overflow vulnerability in passlogd sniffer. dong-h0un U
[INetCop Security Advisory] Qpopper v4.0.x poppassd local root exploit dong-h0un U
[INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability. dong-h0un U
[INetCop Security Advisory] Remote Heap Corruption Overflow vulnerability in WsMp3d. dong-h0un U
GNATS (The GNU bug-tracking system) multiple buffer overflow vulnerabilities. dong-h0un U

Erik Parker

[DDI-1013] Buffer Overflow in Samba allows remote root compromise Erik Parker

Florian Weimer

Algorithmic Complexity Attacks and the Linux Networking Code Florian Weimer

François SORIN

[KSA-001] Multiple vulnerabilities in Tutos François SORIN
[KSA-002] Multiple Vulnerabilities In Moregroupware François SORIN

Frog Man

PY-Membres 4.0 (PHP) Frog Man
True Galerie 1.0 : Admin Access & File Copy Frog Man
OneOrZero Security Problems (PHP) Frog Man
pMachine (PHP) : Include() Security Hole Frog Man

gilbert vilvoorde

XSS Vulnerability in LedNews (CGI/Perl) v0.7 gilbert vilvoorde

Gregory LEBRAS

[SCSA-018] Disclosure of authentication information in Sambar Server Gregory LEBRAS

Gregory Le Bras | Security Corporation

[SCSA-015] Remote Denial of Service Vulnerability in PowerFTP Gregory Le Bras | Security Corporation
[SCSA-016] Multiple vulnerabilities in Ez publish Gregory Le Bras | Security Corporation
[SCSA-017] Directory Traversal Vulnerability in EZ Server Gregory Le Bras | Security Corporation

GreyMagic Software

Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE) GreyMagic Software

iDEFENSE Labs

iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player iDEFENSE Labs
iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x iDEFENSE Labs
iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration (ISA) S iDEFENSE Labs
iDEFENSE Security Advisory 05.22.03: Authentication Bypass in iisPROTECT iDEFENSE Labs
iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability iDEFENSE Labs
iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing Vulnerability iDEFENSE Labs

Integrigy Security Alerts

Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability Integrigy Security Alerts

Jakob Balle

Secunia Research: Opera browser filename extension buffer overflows Jakob Balle

Jouko Pynnonen

Buffer overflow in Internet Explorer's HTTP parsing code Jouko Pynnonen
Windows Media Player directory traversal vulnerability Jouko Pynnonen

Kee Hinckley

Re: CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass Kee Hinckley

KF

SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow KF
SRT2003-04-04-1106 - AOLServer Proxy Daemon API unformatted syslog() call KF
SRT2003-04-15-1029 - Progres BINPATHX overflow KF
SRT2003-04-22-1336 - SAP DB Development Tools install flaw KF
SRT2003-04-24-1532 - Options Parsing Tool library buffer overflows. KF
SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow KF
SRT2003-06-12-0853 - ike-scan local root format string issue KF
SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue KF
SRT2003-06-13-0945 - Progress PATH based dlopen() issue KF
SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow KF

K. K. Mookhey

NII Advisory - Buffer Overflow in Analogx Proxy K. K. Mookhey

Knud Erik Højgaard

youbin local root exploit + advisory Knud Erik Højgaard
gid bin from /usr/ports/korean/elm (FreeBSD) Knud Erik Højgaard

labs

[NGSEC-2003-5] YABB SE, remote command execution labs

Marc Schoenefeld

Java Agent freezes Lotus Notes and Domino 6.0.1 (fwd) Marc Schoenefeld
Opera 7.11 java.util.zip.* Vulnerability (fwd) Marc Schoenefeld

Marek Bialoglowy

Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED Marek Bialoglowy

Mark Litchfield

Re: Buffer Overflow Vulnerability Found in MailMax Version 5 Mark Litchfield
Remote Buffer Overrun WebAdmin.exe Mark Litchfield

Matthew Murphy

Race in XP SCM Service Shutdown Mechanism Matthew Murphy
BadBlue Remote Administrative Access Vulnerability Matthew Murphy
Monkey HTTPd Remote Buffer Overflow Matthew Murphy
Remote Vulnerabilties in mod_ntlm Matthew Murphy
AN HTTPd Sample Script File Truncation Matthew Murphy
eServ Memory Leak Enables Denial of Service Attacks Matthew Murphy

mattmurphy () kc rr com

BadBlue Remote Administrative Interface Access Vulnerability mattmurphy () kc rr com

Michael Puchol

3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computer's ports during outbound and inbound TCP and UDP sessions Michael Puchol

Michael Scheidell

3com NBX IP Phone Call manager Denial of Service - Update Michael Scheidell

Muhammad Faisal Rauf Danka

Hotmail & Passport (.NET Accounts) Vulnerability Muhammad Faisal Rauf Danka

NGSSoftware Insight Security Research

Internet Explorer Plugin.ocx heap overflow (#NISR24042003) NGSSoftware Insight Security Research
Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003) NGSSoftware Insight Security Research
Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A) NGSSoftware Insight Security Research
Multiple Vulnerabilities in SLWebmail NGSSoftware Insight Security Research

NSFOCUS Security Team

NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS NSFOCUS Security Team
NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability NSFOCUS Security Team

OC Hosting - Lance L

Fw: Alert: Microsoft Security Bulletin - MS03-011 OC Hosting - Lance L

Peter Winter-Smith

Vulnerability in ' poster version.two' Peter Winter-Smith
P-News 1.16 Admin Access Vulnerability Peter Winter-Smith
Admin Account Creation Vulnerability in CuteNews 1.x Peter Winter-Smith

pokleyzz

Webfroot Shoutbox 2.32 directory traversal and code injection. pokleyzz
Geeklog 1.3.7sr1 and below multiple vulnerabilities. pokleyzz
b2 cafelog 0.6.1 remote command execution. pokleyzz

Rain Forest Puppy

Linux 2.4 kernel ioperm vuln Rain Forest Puppy
Linux 2.4 kernel ioperm vuln *is* for 2.4 Rain Forest Puppy
More S21sec Vignette advisories Rain Forest Puppy
Administrivia: Vulnwatch DNS issues affecting availability Rain Forest Puppy
Ethereal < 0.9.13 vulns Rain Forest Puppy

Rapid 7 Security Advisories

R7-0013: Heap Corruption in Gaim-Encryption Plugin Rapid 7 Security Advisories

Rick

phpBB password disclosure by sql injection Rick

S21SEC

S21SEC-016-en - Vignette SSI Injection S21SEC
S21SEC-017-en - Vignette /vgn/legacy/save SQL access S21SEC

scheidell

SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm) scheidell

scrap

PTNews v1.7.7 - Access to administrator functions without authentification scrap

SecurITeam BugTraq Monitoring

Multiple Vulnerabilities Found in Mailtraq (DoS, Password Decryption, Directory Traversal) SecurITeam BugTraq Monitoring

Security Experts, Liability Limited

serious vulnerability present. all doomed. over. Security Experts, Liability Limited

SecurityTracker

SQL injection in BttlxeForum SecurityTracker
Happymall E-Commerce Remote Command Execution SecurityTracker

SGI Security Coordinator

MIPSPro Compiler Predictable Temp File vulnerability SGI Security Coordinator
Multiple IPv6-Induced Bugs & Vulnerabilities on IRIX SGI Security Coordinator

sharpiemarker

Snitz Forum 3.3.03 Remote Command Execution sharpiemarker

silentscripter

Multiple vulnerabilities in paBox silentscripter

SPI Labs

Multiple Vulnerabilities in Sun-One Application Server SPI Labs
Internet Information Services 5.0 Denial of service SPI Labs

@stake Advisories

Vignette Story Server sensitive information disclosure (a040703-1) @stake Advisories
MacOS X DirectoryService Privilege Escalation (a041003-1) @stake Advisories
Apple AirPort Administrative Password Obfuscation (a051203-1) @stake Advisories
Nokia GGSN (IP650 Based) DoS @stake Advisories

Steve

Administrivia - VulnWatch.Org still down Steve
Administrivia - Temporary fix for VulnWatch.org Steve

subversive

SFAD03-001: iWeb Mini Web Server Remote Directory Traversal subversive

vulnwatch-return-887-lists_vulnwatch=insecure.org

R7-0014: RSA SecurID ACE Agent Cross Site Scripting vulnwatch-return-887-lists_vulnwatch=insecure.org

zillion

ChiTeX local root vulnerability zillion
Apache mod_access_referer denial of service issue zillion
Previous period Next period
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]