- [SECURITY] [DSA 1228-1] New elinks packages fix arbitrary shell command execution
- Re: Symantec LiveState Agent for Windows vulnerability - Local
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege
- EasyPage Portal ( all ver )SQL Injection
- Re: Symantec LiveState Agent for Windows vulnerabi
- eEye's Zero-Day Tracker Launch
- Re: Re: [Aria-Security Team] uGestBook SQL Injection Vuln
- Re: Symantec LiveState Agent for Windows vulnerabi
- Re: EasyPage Portal ( all ver )SQL Injection
- [security bulletin] HPSBUX02145 SSRT061202 rev.2 - HP-UX running Apache Remote Execution of Arbitrary Code, Denial of Service (DoS), and Unauthorized Access
- Re: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation
- HPSBUX02178 SSRT061267 rev.1 - HP-UX Secure Shell Remote Denial of Service (DoS)
- EEYE: Adobe Download Manager AOM Stack Buffer Overflow Vulnerability
- [ MDKSA-2006:224 ] - Updated xine-lib packages fix buffer overflow vulnerability
- [USN-390-2] evince vulnerability
- Barracuda Convert-UUlib library buffer overflow leads to remote
- Internet Explorer 6. CSS Expression Denial of Service (P.o.C.)
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit
- Uploadscript Vulnerabilities: Text file Hash password
- FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- FreeBSD Security Advisory FreeBSD-SA-06:26.gtar
- [SECURITY] [DSA 1229-1] New Asterisk packages fix arbitrary code execution
- Oracle PL/SQL Fuzzing Tool
- BTSaveMySql 1.2 (acces to config files)
- RE: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation
- Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- SYMSA-2006-012: 2X ThinClientServer Create Admin Account Replay
- GnuPG: remotely controllable function pointer [CVE-2006-6235]
- rPSA-2006-0226-1 kernel
- [ MDKSA-2006:225 ] - Updated ruby packages fix DoS vulnerability
- rPSA-2006-0227-1 gnupg
- Microsoft 0-day word vulnerability - Secunia - Extremely critical
- New MySpace worm could be on its way
- ZDI-06-044: Adobe Download Manager AOM Parsing Buffer Overflow
- [ GLSA 200612-01 ] wv library: Multiple integer overflows
- Linksys WIP 330 VoIP wireless phone crash from Nmap scan
- Digital Armaments Security Advisory 07.12.2006: Yahoo multiple
- Re: Microsoft 0-day word vulnerability - Secunia - Extremely critical
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- TSRT-06-15: Citrix Presentation Server Client ActiveX Heap Overflow
- Re: XSS in JAB Guest Book
- Some Thoughts about Office Open XML and Malware Detection
- [USN-393-1] GnuPG vulnerability
- Re: The Week of Oracle Database Bugs
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.)
- phpbb 2.0.x [xss]
- Re: Microsoft 0-day word vulnerability - Secunia - Extremely
- [USN-390-3] evince-gtk vulnerability
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- Re[2]: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- phpAdsNew-2.0.4-pr2 Remote File Inclusion Exploit
- Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass
- [USN-393-2] GnuPG2 vulnerabilities
- DUdirectory Admin Panel SQL Injection
- [OpenPKG-SA-2006.037] OpenPKG Security Advisory (gnupg)
- EEYE: Intel Network Adapter Driver Local Privilege Escalation
- [Aria-Security Team] CentOS 4.2 i686 - WHM X v3.1.0 Cross-Site
- [Aria-Security Team] cPanel 11 pops.html Cross-Site Scripting
- [Aria-Security Team] cPanel BoxTrapper Cross Site Scripting
- TSLSA-2006-0070 - multi
- [OpenPKG-SA-2006.038] OpenPKG Security Advisory (tar)
- [SECURITY] [DSA-1230-1] new l2tpns packages fix buffer overflow
- Microsoft Word 0-day Vulnerability FAQ (CVE-2006-5994) written
- Midicart vulerable
- [CAID 34846]: CA BrightStor ARCserve Backup Discovery Service Buffer Overflow Vulnerability
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.)
- LS-20060908 - Computer Associates BrightStor ARCserve Backup
- LS-20061001 - Computer Associates BrightStor ARCserve Backup
- Animated Smiley Generator File Include Vul.
- ASX Playlists and Jumping to Conclusions
- [USN-394-1] Ruby vulnerability
- PHP 5.2.0 session.save_path safe_mode and open_basedir bypass
- PhpBB Toplist 1.3.7 Xss Vuln.
- Enforcing Java Security Manager in Restricted Windows Environments?
- iDefense Security Advisory 12.08.06: Multiple Vendor Antivirus RAR
- iDefense Security Advisory 12.08.06: Sophos Antivirus CHM Chunk Name
- iDefense Security Advisory 12.08.06: Sophos Antivirus CHM File Heap
- Re: XSS in JAB Guest Book
- Call For Papers: SecurityOPUS 2007
- [ GLSA 200612-02 ] xine-lib: Buffer overflow
- KDPics Multiple Vulnerabities
- ProNews V1.5 XSS & SQL Injection
- Messageriescripthp V2.0 XSS & SQL Injection
- AnnonceScriptHP V2.0 Multiple Vulnerabilities
- [SECURITY] [DSA 1231-1] New gnupg packages fix arbitrary code execution
- [SECURITY] [DSA 1232-1] New clamav packages fix denial of service
- [SECURITY] [DSA 1233-1] New Linux 2.6.8 packages fix several vulnerabilities
- WASC-Announcement: MX Injection - Capturing and Exploiting Hidden Mail Servers By Vicente Aguilera Diaz
- [SBDA] - ColdFusion MX7 - Multiple Vulnerabilities
- Unauthenticated access to IBM Host On-Demand administration pages
- D-LINK DWL-2000AP+ remote DoS
- [ GLSA 200612-09 ] MadWifi: Kernel driver buffer overflow
- [ MDKSA-2006:226 ] - Updated squirrelmail packages fix vulnerabilities
- RFIDIOt release - version 0.1i
- Firefox 2.0 security bug: Extensions can hide themself
- ERRATA: [ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities
- Multiple vulnerabilities in Winamp Web Interface 7.5.13
- [ GLSA 200612-08 ] SeaMonkey: Multiple vulnerabilities
- Several updates in Microsoft Word 0-day (CVE-2006-5994) FAQ
- Another, different MS Word 0-day vulnerability reported
- looking for security community input
- shopsite advisory
- Secunia Research: MailEnable IMAP Service Buffer Overflow
- Re: Another, different MS Word 0-day vulnerability reported
- [ GLSA 200612-06 ] Mozilla Thunderbird: Multiple vulnerabilities
- Re: LS-20061001 - Computer Associates BrightStor ARCserve Backup
- [ GLSA 200612-10 ] Tar: Directory traversal vulnerability
- The newest Word flaw is due to malformed data structure handling
- Re: LS-20060908 - Computer Associates BrightStor ARCserve Backup
- [ GLSA 200612-04 ] ModPlug: Multiple buffer overflows
- [ GLSA 200612-03 ] GnuPG: Multiple vulnerabilities
- RFID access control tokens widely open to cloning
- [ GLSA 200612-07 ] Mozilla Firefox: Multiple vulnerabilities
- Secunia Research: AOL CDDBControl ActiveX Control
- [ GLSA 200612-05 ] KOffice shared libraries: Heap corruption
- [ MDKSA-2006:227 ] - Updated kdegraphics packages fix EXIF vulnerability
- [ GLSA 200612-09 ] MadWifi: Kernel driver buffer overflow
- Re: The newest Word flaw is due to malformed data structure handling
- [ MDKSA-2006:228 ] - Updated gnupg packages fix vulnerability
- OpenLDAP kbind authentication buffer overflow
- [SBDA] SiteKiosk - FileSystem Access
- Web Apps- Rad Upload Version 3.02 Remote File Include Vulnerability
- rPSA-2006-0230-1 evince
- rPSA-2006-0231-1 squirrelmail
- Re: PHP 5.2.0 session.save_path safe_mode and open_basedir bypass
- ZDI-06-045: Sophos Anti-Virus CPIO Archive Parsing Buffer Overflow
- Re: [fuzzing] OWASP Fuzzing page
- BLOG:CMS Remote file include Vulnerability
- Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.)
- Re: The newest Word flaw is due to malformed data structure handling
- Secunia Research: Internet Explorer Script Error Handling Memory
- ZDI-06-047: Microsoft Visual Studio WmiScriptUtils.dll Cross-Zone Scripting
- [ GLSA 200612-12 ] F-PROT Antivirus: Multiple vulnerabilities
- ZDI-06-048: Microsoft Internet Explorer normalize() Function Memory
- [ GLSA 200612-13 ] libgsf: Buffer overflow
- [ GLSA 200612-14 ] Trac: Cross-site request forgery
- Re: shopsite advisory
- ZDI-06-046: Sophos Anti-Virus SIT Archive Parsing Buffer Overflow
- Re: Re: The newest Word flaw is due to malformed data structure
- iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so
- iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so
- Re: worksystem => Remote File Include Vulnerability Exploit
- [SECURITY] [DSA-1234-1] New ruby1.6 package fix denial of service
- [SECURITY] [DSA-1235-1] New ruby1.8 package fix denial of service
- [SECURITY] [DSA-1236-1] New enemies-of-carlotta package fix missing sanity checks
- ASP Cmd Shell On IIS 5.1
- IBM DB2 Remote DoS during CONNECT processing
- ZDI-06-050: Symantec Veritas NetBackup CONNECT_OPTIONS Buffer Overflow
- CORE-2006-1127: ProFTPD Controls Buffer Overflow
- Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day
- RE: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day
- Xt-News 0.1 : SQL Injection Vulnerability & XSS
- rPSA-2006-0234-1 firefox
- Oracle Applications/Portal 9i/10g Cross Site Scripting
- Re[2]: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip
- TSLSA-2006-0074 - multi
- Re: [Full-disclosure] Oracle Portal 10g HTTP Response Splitting
- Re: Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory
- Efkan Forum v1.0 SqL Inj. Vuln.
- Multiple Bugs in Future Internet ( XSS & SQL Injection )
- SQID v0.2 - SQL Injection Digger.
- Re: Multiple Remote Vulnerabilities in KISGB
- Re: Multiple Remote Vulnerabilities in KISGB
- ZDI-06-052: Novell NetMail NMAP STOR Buffer Overflow Vulnerability
- ZDI-06-053: Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability
- ZDI-06-054: Novell NetMail IMAP APPEND Buffer Overflow Vulnerability
- iDefense Security Advisory 12.23.06: Novell NetMail IMAPD subscribe
- iDefense Security Advisory 12.23.06: Novell Netmail IMAP append Denial
- Okul Merkezi Portal v1.0 Remote File IncLude Vuln.
- Chatwm V1.0 SqL Injection Vuln.
- Fishyshoop Security Vulnerability
- TimberWolf 1.2.2 vulnerable to XSS
- Forum AnyBoard - Sql Inyection By Firewall
- ERRATA (Re:
- XSS with Vbulletin (new idea !)
- [SECURITY] [DSA 1241-1] New squirrelmail packages fix cross-site scripting
- PHP Live! 3.2.2 Multiple Cross-Site Scripting Vulnerabilities
- Beat Internet filter with SSL proxies
- Cahier de texte V2.2 Bypass general access protection exploit
- phpcms <=- 1.1.7 Remote File Inclusion
- PhpbbXtra v2.0 (phpbb_root_path) Remote File Include Vulnerability
- HLStats Remote SQL Injection Exploit
- XSS - CMS Made Simple v1.0.2
- logahead UNU edition 1.0 Remote File Upload & code execution
- LuckyBot v3 Remote File Include
- [OpenPKG-SA-2006.042] OpenPKG Security Advisory (openser)
- [OpenPKG-SA-2006.043] OpenPKG Security Advisory (links)
- MI5 Persecution: the BBC, television and radio
- MI5 Persecution: bugging and counter-surveillance
- Re: ERRATA (Re: "Host header cannot be trusted as an anti anti DNS-pinning measure")
- Re: phpcms <=- 1.1.7 Remote File Inclusion
- MI5 Persecution: abuse in set-up situations and in public
- MI5 Persecution: my response to the harassment
- MI5 Persecution: their methods and tactics
- MI5 Persecution: why the security services?
- MI5 Persecution: BBC h2g2 online
- MI5 Persecution: Bizarre magazine
- MI5 Persecution: Financial Times
- Re: phpcms <=- 1.1.7 Remote File Inclusion
- Re: LuckyBot v3 Remote File Include
- Re: The (in)security of Xorg and DRI
- Re: XSS with Vbulletin (new idea !)
- Host directory full disclosure and input error
- Secure Login Manager Multiple Input Validation Vulnerabilities
- Re: Cross site scripting & fullpath disclosure
- NtRaiseHardError Csrss.exe memory Disclosure exploit
- ShmooCon Announcement
- [SECURITY] [DSA 1242-1] New elog packages fix arbitrary code execution
- Limbo CMS event module (lm_absolute_path) Remote File Include
- [SECURITY] [DSA 1243-1] New evince packages fix arbitrary code execution
- OpenSER OSP Module remote code execution
- Re: XSS with Vbulletin (new idea !)
- SMS handling OpenSER remote code executing
- Re: XSS - CMS Made Simple v1.0.2
- [OpenPKG-SA-2006.044] OpenPKG Security Advisory (w3m)
- Re: XSS with Vbulletin (new idea !)
- [SECURITY] [DSA 1214-2] Updated gv packages fix arbitrary code execution
- [SECURITY] [DSA 1244-1] New xine-lib packages fix arbitrary code execution
- XSS in script Mobilelib GOLD v2
- XSS with default page parameter in Oracle Portal 10g
- QuickCam linux device driver allows arbitrary code execution
- LDU <= 8.x (journal.php) SQL Injection Vulnerability
- Re: XSS in script Mobilelib GOLD v2
- csrss.exe double-free vulnerability - arbitrary DWORD overwrite exploit
- MythControl (MythTV remote control) arbitrary code execution
- SoftArtisans FileUp(TM) viewsrc.asp remote script source
- [vuln.sg] iso_wincmd Plugin for Total Commander Buffer Overflow
- Enigma Coppermine Bridge (boarddir) Remote File Include
- Enigma WordPress Bridge (boarddir) Remote File Include
- MI5 Persecution: .net magazine article
- MI5 Persecution: Observer article
- Spooky Login Multiple HTML Injection Vulnerability
- Re: PocketPC MMS - Remote Code Injection/Execution Vulnerability
- Rediff Bol Downloader Allows Downloading and Spawning Arbitary Files
- WinZip FileView ActiveX controls CreateNewFolderFromName Method
- PHPIrc_bot <= Remote File Include
- vBulletin vCard PRO XSS
- Re: PlatinumFTP 1.0.18 remote DoS
- WinZip10.0 FileView ActiveX Controls CreateNewFolderFromName
- [NGSEC] ngGame #3 - BrainStorming
- BattleBlog Database Download Vulnerability
- Kerio Fake 'iphlpapi' DLL injection Vulnerability
- Re: PHP as a secure language? PHP worms? [was: Re: new linux malware]
- golden book XSS
- rblog Database Download Vulnerability
- ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
- Re: PHP as a secure language? PHP worms? [was: Re: new linux
- AShop Shopping Cart Multiple XSS Vulnerabilities