PDA

Bekijk Volledige Versie : Bugtraq mailing lijst



Pagina's : 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 [85] 86 87 88 89 90 91 92 93 94 95 96 97 98

  1. Re: First (Major) web hacking incidents for 2008. Sign of the year to
  2. [USN-564-1] Net-SNMP vulnerability
  3. [USN-561-1] pwlib vulnerability
  4. [ GLSA 200801-02 ] R: Multiple vulnerabilities
  5. [ MDVSA-2008:004 ] - Updated postgresql packages fix denial of service
  6. [USN-563-1] CUPS vulnerabilities
  7. iDefense Security Advisory 01.09.08: Novell NetWare Client nicm.sys
  8. my mum and sister kissing
  9. [ GLSA 200801-03 ] Claws Mail: Insecure temporary file creation
  10. [SECURITY] [DSA 1456-1] New fail2ban packages fix denial of service
  11. [ GLSA 200801-05 ] Squid: Denial of Service
  12. [USN-565-1] Squid vulnerability
  13. [ GLSA 200801-04 ] OpenAFS: Denial of Service
  14. [ MDVSA-2008:005 ] - Updated libexif packages fix multiple
  15. [SECURITY] [DSA 1457-1] New dovecot packages fix information disclosure
  16. Simple Machines Forum Cross-Site Scripting Vulnerabilities
  17. PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS,
  18. [USN-566-1] OpenSSH vulnerability
  19. uCon 2008 call for participation - Recife, Brazil
  20. Digital Armaments January-February Hacking Challenge: Special
  21. [ GLSA 200801-06 ] Xfce: Multiple vulnerabilities
  22. BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP
  23. Word 2007 Email as PDF path disclosure flaw
  24. MTCMS <=2.0 SQL Injection Vulnerbility
  25. Buffer-overflow in Quicktime Player 7.3.1.70
  26. [SECURITY] [DSA 1458-1] New openafs packages fix denial of service vulnerability
  27. [ MDVSA-2008:006 ] - Updated exiv2 packages fix vulnerability
  28. Re: Buffer-overflow in Quicktime Player 7.3.1.70
  29. [USN-567-1] Dovecot vulnerability
  30. Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70
  31. At long last -- Extra Outlooks!
  32. [ MDVSA-2008:007 ] - Updated madwifi-source,
  33. SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7
  34. Re: Linksys WRT54 GL - Session riding (CSRF)
  35. SecurityReason - Apache2 CSRF, XSS, Memory Corruption and Denial
  36. re-resting of zzuf results
  37. ImageAlbum Remote SQL Injection Vulnerabilities
  38. Re: Buffer-overflow in Quicktime Player 7.3.1.70
  39. CFP: EuroSec Workshop (March 31st, 2008)
  40. Member Area System (MAS) Remote File Include Vulnerability
  41. Naymz multiple XSS
  42. Re: At long last -- Extra Outlooks!
  43. Re: Buffer-overflow in Quicktime Player 7.3.1.70
  44. Cross site scripting (XSS) in Moodle 1.8.3
  45. [ MDVSA-2008:010 ] - Updated libxml2 packages fix DoS vulnerability
  46. [ MDVSA-2008:011 ] - Updated rsync packages fix restrictions bypass
  47. Safari 2 Denial of Service
  48. [ MDVSA-2008:009 ] - Updated autofs packages fix insecure hosts
  49. [ MDVSA-2008:008 ] - Updated kernel packages fix multiple
  50. Garment Center (index.cgi) Local File Inclusion
  51. [SECURITY] [DSA 1462-1] New hplip packages fix privilege escalation
  52. what is this?
  53. Re: what is this?
  54. RE: Linksys WRT54 GL - Session riding (CSRF)
  55. Re: [Full-disclosure] what is this?
  56. F5 BIG-IP Web Management List Search XSS
  57. Re: [Full-disclosure] what is this?
  58. [SECURITY] [DSA 1460-1] New postgresql-8.1 packages fix several
  59. Re: [Full-disclosure] what is this?
  60. SQID v0.3 - SQL Injection Digger.
  61. [ MDVSA-2008:009-1 ] - Updated autofs packages fix insecure hosts
  62. Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70
  63. Re: At long last -- Extra Outlooks!
  64. RE: At long last - Extra Outlooks!
  65. RE: At long last -- Extra Outlooks!
  66. Re: At long last -- Extra Outlooks!
  67. Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70
  68. Re: what is this?
  69. [SECURITY] [DSA 1459-1] New gforge packages fix SQL injection
  70. Re: what is this?
  71. Re: what is this?
  72. Re: what is this?
  73. Re: Buffer-overflow in Quicktime Player 7.3.1.70
  74. RE: what is this?
  75. Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily
  76. Re: Garment Center (index.cgi) Local File Inclusion
  77. Re: Buffer-overflow in Quicktime Player 7.3.1.70
  78. Hacking The Interwebs
  79. [SECURITY] [DSA 1463-1] New postgresql-7.4 packages fix several
  80. Re[2]: [Full-disclosure] what is this?
  81. Re: what is this?
  82. [USN-568-1] PostgreSQL vulnerabilities
  83. [SECURITY] [DSA 1461-1] New libxml2 packages fix denial of service
  84. Re: what is this?
  85. [security bulletin] HPSBUX02303 SSRT071468 rev.1 - HP-UX Running X Font Server (xfs) Software, Remote Execution of Arbitrary Code
  86. [security bulletin] HPSBST02304 SSRT080003 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-001 to MS08-002
  87. [ MDVSA-2008:012 ] - Updated python packages fix vulnerabilities
  88. [ MDVSA-2008:013 ] - Updated python packages fix vulnerability in
  89. FreeBSD Security Advisory FreeBSD-SA-08:01.pty
  90. Re: what is this?
  91. Defeating audio captcha systems
  92. Country by Country ISA Computer Sets
  93. Re: Linksys WRT54 GL - Session riding (CSRF)
  94. Re: what is this?
  95. Re: [Full-disclosure] what is this?
  96. Re: [Full-disclosure] what is this?
  97. Re[2]: what is this?
  98. SecurityReason - Apache (mod_status) Refresh Header - Open
  99. Re[2]: what is this?
  100. Article DashBoard all version SQL Injection Vulnerability
  101. Max's File Uploader File Upload Vulnerability
  102. MicroNews Admin Direct Access vulnerability
  103. Re: what is this?
  104. RE: what is this?
  105. Re: [Full-disclosure] what is this?
  106. Re: [Full-disclosure] what is this?
  107. Re[2]: what is this?
  108. Re: Linksys WRT54 GL - Session riding (CSRF)
  109. Re: Linksys WRT54 GL - Session riding (CSRF)
  110. iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver
  111. iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer
  112. iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver
  113. iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer
  114. Pipe to FOR Crashes CMD
  115. Re: Defeating audio captcha systems
  116. Re: what is this?
  117. [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities
  118. RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit
  119. [SECURITY] [DSA 1464-1] New syslog-ng packages fix denial of service
  120. rPSA-2008-0015-1 cairo
  121. cPanel Hosting Manager (dohtaccess.html)
  122. rPSA-2008-0016-1 postgresql postgresql-server
  123. rPSA-2008-0017-1 libxml2
  124. [DSECRG-08-002] Local File Include in arias 0.99-6
  125. TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability
  126. 8e6 Technologies R3000 Internet Filter Bypass by Request Split
  127. [Aria-Security.Net] Real Estate Web SQL Injection
  128. Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow
  129. iDefense Security Advisory 01.15.08: Apple QuickTime Macintosh Resource
  130. mcGuestbook v1.2 Remote File Inc.
  131. Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5
  132. Country by Country Computer Sets now available for ISA 2004
  133. TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability
  134. SQL scalar function to convert big int to dot notation
  135. [waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10
  136. [waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10
  137. Gradman <= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion
  138. [ MDVSA-2008:014 ] - Updated apache 1.3.x packages fix multiple
  139. [USN-570-1] boost vulnerabilities
  140. [ MDVSA-2008:015 ] - Updated apache 2.0.x packages fix multiple
  141. [security bulletin] HPSBMA02133 SSRT061201 rev.7 - HP Oracle for OpenView (OfO) Critical Patch Update
  142. [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution
  143. JoomlaFlash Component Multiple Remote File Inclusion
  144. PHPEchoCMS Multible remote vulnerabilitis
  145. rPSA-2008-0018-1 mysql mysql-bench mysql-server
  146. Re: [CVE-2007-2449] Apache Tomcat XSS vulnerabilities in the JSP
  147. [ MDVSA-2008:016 ] - Updated apache 2.2.x packages fix multiple
  148. rPSA-2008-0021-1 kernel
  149. [SECURITY] [DSA 1465-2] New apt-listchanges packages fix arbitrary code execution
  150. Re: Utimaco Safeguard Easy vulnerability
  151. Clever Copy <=3.0 Multiple Remote Vulnerabilities
  152. [CSNC] OKI C5510MFP Printer Password Disclosure
  153. RE: Skype videomood XSS
  154. CORE-2007-1119: CORE FORCE Kernel Buffer Overflow
  155. iDefense Security Advisory 01.17.08: Multiple Vendor X Server XInput
  156. iDefense Security Advisory 01.17.08: Multiple Vendor X Server TOG-CUP
  157. iDefense Security Advisory 01.17.08: Multiple Vendor X Server EVI
  158. iDefense Security Advisory 01.17.08: Multiple Vendor X Server XFree86-Misc
  159. IMF 2008 - Call for Papers
  160. [FIXED] Remote Denial of Service for SSH service at Dell DRAC4
  161. [USN-571-1] X.org vulnerabilities
  162. Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities
  163. common dns misconfiguration can lead to "same site" scripting
  164. New search engine for exploits
  165. Re: Member Area System (MAS) Remote File Include Vulnerability
  166. Making big money...
  167. SocksCap Stack Overflow (<= 2.40-051231)
  168. Re: Country by Country ISA Computer Sets
  169. Re: Country by Country ISA Computer Sets
  170. SinFP fingerprinting tool online demo
  171. RE: Country by Country ISA Computer Sets
  172. Re: mcGuestbook v1.2 Remote File Inc.
  173. Re: Article DashBoard all version SQL Injection Vulnerability
  174. RE: Country by Country ISA Computer Sets
  175. Re: Country by Country ISA Computer Sets
  176. Re: Tiger Team: New TV series about pen testers airing on CourtTV
  177. MyBB 1.2.11 Multiple XSRF Vulnerabilities
  178. Re: Re: Utimaco Safeguard Easy vulnerability
  179. RE: Country by Country ISA Computer Sets
  180. [USN-572-1] apt-listchanges vulnerability
  181. [USN-571-2] X.org regression
  182. [SECURITY] [DSA 1466-2] New xorg-server packages fix regression
  183. [SECURITY] [DSA 1467-1] New mantis packages fix several vulnerabilities
  184. Re: common dns misconfiguration can lead to "same site" scripting
  185. Make MoneY EaSy n FaST !!!!!!! 100% Working..Tested!
  186. RE: Country by Country ISA Computer Sets
  187. Bloofox CMS SQL Injection (Authentication bypass) , Source code
  188. [SECURITY] [DSA 1468-1] New tomcat5.5 packages fix several vulnerabilities
  189. Php Search Remote Inclusion
  190. AXIGEN 5.0.x AXIMilter Format String Exploit
  191. MegaBBS ASP Forum Cross-Site Scripting
  192. Re: common dns misconfiguration can lead to "same site" scripting
  193. WifiZoo v1.3 released (minor release)
  194. Flaw in Alice gate2 pluswifi adsl modem
  195. boastMachine <=3.1 SQL Injection Vulnerbility
  196. [ GLSA 200801-09 ] X.Org X server and Xfont library: Multiple vulnerabilities
  197. Call Jacking: Phreaking the BT Home Hub
  198. BLOG:CMS 4.2.1.c (DIR_PLUGINS) Multiple Remote File Include
  199. [SECURITY] [DSA 1470-1] New horde3 packages fix denial of service
  200. [SECURITY] [DSA 1469-1] New flac packages fix arbitrary code execution
  201. Belkin Wireless G Plus MIMO Router F5D9230-4 Authentication
  202. Pass-The-Hash Toolkit v1.2 released.
  203. [ GLSA 200801-07 ] Adobe Flash Player: Multiple vulnerabilities
  204. [ GLSA 200801-08 ] libcdio: User-assisted execution of arbitrary code
  205. [waraxe-2008-SA#063] - Information Leakage in Kayako SupportSuite
  206. [ MDVSA-2008:017 ] - Updated MySQL packages fix multiple
  207. [waraxe-2008-SA#064] - Sql Injection in MyBB 1.2.11
  208. [SECURITY] [DSA 1471-1] New libvorbis packages fix several vulnerabilities
  209. [SECURITY] [DSA 1472-1] New xine-lib packages fix arbitrary code execution
  210. Re: 8e6 Technologies R3000 Internet Filter Bypass by Request Split
  211. PR07-38: XSS on sIFR
  212. [ MDVSA-2008:019 ] - Updated cairo packages fix vulnerability
  213. Some hashes for the record
  214. Troopers 08 Security Conference, Call for Papers
  215. RE: Country by Country ISA Computer Sets
  216. Re: common dns misconfiguration can lead to "same site" scripting
  217. [SECURITY] [DSA 1473-1] New scponly packages fix arbitrary code execution
  218. [ MDVSA-2008:018 ] - Updated gFTP packages fix vulnerabilities
  219. Re: common dns misconfiguration can lead to "same site" scripting
  220. PacerCMS Multiple Vulnerabilities (XSS/SQL)
  221. DeluxeBB 1.1 XSS Vulnerabilitie
  222. Re: PR07-38: XSS on sIFR
  223. =?UTF-8?Q?XSRF_under_Dean=E2=80=99s_Permalinks_Migration _1.0?=
  224. Apache mod_negotiation Xss and Http Response Splitting
  225. SDL_Image 1.2.6 and prior GIF handling buffer overflow
  226. PHP 5.2.5 cURL safe_mode bypass
  227. [security bulletin] HPSBUX02306 SSRT071463 rev.1 - HP-UX Running ARPA Transport, Remote Denial of Service (DoS)
  228. UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication
  229. Web Wiz Forums Directory traversal
  230. Web Wiz Rich Text Editor Directory traversal + HTM/HTML file
  231. Web Wiz NewsPad Directory traversal
  232. [ MDVSA-2008:020 ] - Updated xine-lib packages fix remote code
  233. Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability
  234. Cisco Security Advisory: Default Passwords in the Application Velocity System
  235. Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and
  236. Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation
  237. Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection
  238. RE: Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability
  239. Woltlab Burning Board 2.3.6 PL2 Remote Delete Thread XSRF Vulnerability
  240. [SECURITY] [DSA 1474-1] New exiv2 packages fix arbitrary code execution
  241. [ GLSA 200801-10 ] TikiWiki: Multiple vulnerabilities
  242. [SECURITY] [DSA 1444-2] New php5 packages fix regression
  243. PIX Privilege Escalation Vulnerability
  244. [ MDVSA-2008:025 ] - Updated x11-server-xgl packages fix multiple
  245. ImageShack Toolbar FileUploader Class insecurities
  246. [ MDVSA-2008:021 ] - Updated XFree86 packages fix multiple
  247. [ MDVSA-2008:022 ] - Updated xorg-x11 packages fix multiple
  248. [ MDVSA-2008:023 ] - Updated x11-server packages fix multiple
  249. [ MDVSA-2008:024 ] - Updated libxfont packages fix font handling
  250. Tiger PHP News System SQL Injection