Bugtraq: by author

397 messages starting May 08 00 and ending May 22 00
Date index | Thread index | Author index


Aleph One

New Allaire Security Zone Bulletin Posted Aleph One (May 08)
CERT Advisory CA-2000-06 Aleph One (May 18)
Internet Security Systems Security Advisory: Vulnerability in Quake3Arena Auto-Download Feature Aleph One (May 03)

Alex Belits

Re: Race condition in "rm -r" Alex Belits (May 07)

Alfred Huger

You can now track Bugtraq 24/7 with Software. Alfred Huger (May 15)
Bugtraq Stats for the last 3 years available now. Alfred Huger (May 17)

Andrew Brown

Re: glibc resolver weakness Andrew Brown (May 03)

Andrew Lambeth

Re: RFP2K04: Mining BlackICE with RFPickAxe Andrew Lambeth (May 19)

Anonymous

New Solaris root exploit for /usr/lib/lp/bin/netpr Anonymous (May 12)

antirez

Re: Denial of service attack against tcpdump antirez (May 03)
glibc resolver weakness antirez (May 02)

Arend-Jan Wijtzes

fdmount buffer overflow Arend-Jan Wijtzes (May 22)

Arvel Hathcock

MDaemon Mail Server DoS - FIXED Arvel Hathcock (May 25)

Assar Westerlund

Re: BUFFER OVERRUN VULNERABILITIES IN KERBEROS Assar Westerlund (May 16)

AXENT Security Team

Prevent Current and Future E-Mail Worms AXENT Security Team (May 12)
RFP2K05 - NetProwler "Fragmentation" Issue AXENT Security Team (May 23)

axess .

Re: i think axess . (May 29)

bacano

Fw: [suse-security-announce] SuSE Security Announcement - kernel bacano (May 18)

Ben Greenbaum

Re: i think Ben Greenbaum (May 29)
Re: I think Ben Greenbaum (May 29)
Re: Omnis Weak Encryption - Many products affected Ben Greenbaum (May 25)

Benjamin Smee

Re: pam_console bug Benjamin Smee (May 03)

Bennett Todd

Re: glibc resolver weakness Bennett Todd (May 03)

bighawk

Allmanage.pl Vulnerabilities bighawk (May 15)

bind

Passive Network Mapping bind (May 04)

BindView Security Advisory

BindView Security Advisory: jolt2 - Remote DoS against NT, W2K, 9x BindView Security Advisory (May 19)

Black Watch Labs

Black Watch Labs Vulnerability Alert Black Watch Labs (May 10)
Black Watch Labs Vulnerability Alert Black Watch Labs (May 19)
Black Watch Labs Vulnerability Alert Black Watch Labs (May 19)

Blackwatchlabs

Black Watch Labs Vulnerability Alert Blackwatchlabs (May 05)

bretonh () PARANOIA PGCI CA

Denial of service attack against tcpdump bretonh () PARANOIA PGCI CA (May 02)
Re: Denial of service attack against tcpdump bretonh () PARANOIA PGCI CA (May 06)

Brian Fundakowski Feldman

Re: netkill - generic remote DoS attack Brian Fundakowski Feldman (May 03)

Brian Oblivion

NetStructure 7180 remote backdoor vulnerability Brian Oblivion (May 09)
NetStructure 7110 console backdoor Brian Oblivion (May 09)

Brock Tellier

Re: xsoldier update for Linux Mandrake Brock Tellier (May 18)

bugzilla () REDHAT COM

[RHSA-2000:028-02] Netscape 4.73 available bugzilla () REDHAT COM (May 19)

bunny_69_1 () HOTMAIL COM

Another hole in Cart32 bunny_69_1 () HOTMAIL COM (May 22)

Cami

Re: fdmount buffer overflow Cami (May 22)

Cashdollar, Larry

Re: xsoldier update for Linux Mandrake Cashdollar, Larry (May 18)

Casper Dik

Re: Solaris/SPARC 2.7 lpset exploit (well not likely !) Casper Dik (May 01)
Re: New Solaris root exploit for /usr/lib/lp/bin/netpr Casper Dik (May 15)
Re: non-exec stack Casper Dik (May 09)
Re: non-exec stack Casper Dik (May 08)
Re: Solaris 7 x86 lpset exploit. Casper Dik (May 01)
Re: Solaris 7 x86 lpset exploit. Casper Dik (May 03)

cassius () HUSHMAIL COM

Another interesting Cart32 command cassius () HUSHMAIL COM (May 03)
Cayman 3220-H DSL Router DOS cassius () HUSHMAIL COM (May 05)
Wemilo cassius () HUSHMAIL COM (Apr 30)
Cayman 3220H DSL Router Software Update and New Bonus Attack cassius () HUSHMAIL COM (May 23)
Deerfield Communications MDaemon Mail Server DoS cassius () HUSHMAIL COM (May 24)

CDI

Re: Another hole in Cart32 CDI (May 23)

Cerberus Security Team

Alert: Buffer overflow in Rockliffe's MailSite Cerberus Security Team (May 17)
Alert: Windows NT Browser Service DoS Cerberus Security Team (May 30)
Alert: PDG Cart Overflows Cerberus Security Team (May 25)
Contemplations : Melissa, I love you - not! Cerberus Security Team (May 08)
Alert: DMailWeb buffer overflow Cerberus Security Team (May 03)
Alert: Carello File Creation flaw Cerberus Security Team (May 17)
Alert: IIS ism.dll exposes file contents Cerberus Security Team (May 11)
Alert: DNewsWeb buffer overflow Cerberus Security Team (May 05)
Alert: Listserv Web Archives (wa) buffer overflow Cerberus Security Team (May 03)

Charles M. Hannum

Re: FreeBSD Security Advisory: FreeBSD-SA-00:19.semconfig Charles M. Hannum (May 26)

Chet Uber

Call for Presentations Chet Uber (May 30)

Chmouel Boudjnah

Re: KDE: /usr/bin/kdesud, gid = 0 exploit Chmouel Boudjnah (May 28)
Re: kscd vulnerability Chmouel Boudjnah (May 25)
Re: "gdm" remote hole Chmouel Boudjnah (May 25)
Re: fdmount buffer overflow Chmouel Boudjnah (May 23)

Chris Adams

Re: Problem with FrontPage on Cobalt RaQ2/RaQ3 Chris Adams (May 23)
Problem with FrontPage on Cobalt RaQ2/RaQ3 Chris Adams (May 23)

Chris Calabrese

Re: Race condition in "rm -r" Chris Calabrese (May 08)

Chris Evans

"gdm" remote hole Chris Evans (May 21)
Nasty XFree Xserver DoS Chris Evans (May 18)
Linux knfsd DoS issue Chris Evans (May 01)
Clarification/further info on Kerberos issues Chris Evans (May 18)

chris neill

Re: Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) chris neill (May 19)
Anyone alive at Lotus? chris neill (May 29)

Christopher Schulte

Re: fdmount buffer overflow Christopher Schulte (May 24)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco IOS HTTP Server Vulnerability Cisco Systems Product Security Incident Response Team (May 15)

Clover Andrew

Re: Another hole in Cart32 Clover Andrew (May 23)
Re: "ClientSideTrojan" bug Clover Andrew (May 15)

Cory Visi

Re: Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) Cory Visi (May 31)

COVERT Labs

[COVERT-2000-05] Microsoft Windows Computer Browser Reset Vulnerability COVERT Labs (May 25)
[COVERT-2000-06] Initialized Data Overflow in Xlock COVERT Labs (May 29)

cripto

AIX 4.1.4.0 local root LC_MESSAGES /usr/sbin/arp exploit cripto (May 07)

Crispin Cowan

Re: Standard & Poors security nightmare Crispin Cowan (May 20)

Cunningham Stace D MSgt 2 AF/XTI

FW: Security Notice: Big Brother System and Network Monitor Cunningham Stace D MSgt 2 AF/XTI (May 18)

Cy Schubert - ITSD Open Systems Group

Re: Nasty XFree Xserver DoS - Workaround Cy Schubert - ITSD Open Systems Group (May 25)

daedalus

Re: Wemilo daedalus (May 02)

Damir Rajnovic

Re: An Analysis of the TACACS+ Protocol and its Implementations Damir Rajnovic (May 30)

Dan Harkless

Re: Fwd: [nohack] Yet another way to disguise files. Dan Harkless (May 17)
Re: Fwd: [nohack] Yet another way to disguise files. Dan Harkless (May 18)

Daniel Carosone

NetBSD Security Advisory 2000-002 Daniel Carosone (May 06)

Daniel Docekal

Re: Windows NT/95/98/Possible Others Denial of Service Attack. Mi crosoft ODBC Database connectivity flaw. Daniel Docekal (May 01)

Daniel P. Stasinski

AOL Instant Messenger Daniel P. Stasinski (May 08)

Dan Kaminsky

Re: Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2) Dan Kaminsky (May 29)

Darren Moffat - Solaris Sustaining Engineering

Re: New Solaris root exploit for /usr/lib/lp/bin/netpr Darren Moffat - Solaris Sustaining Engineering (May 15)

Darren Reed

Re: Analysis of jolt2.c (MS00-029) Darren Reed (May 26)

Dave Dittrich

Re: Source code to mstream, a DDoS tool Dave Dittrich (May 01)

David Brownlee

Re: Race condition in "rm -r" David Brownlee (May 07)
Re: Race condition in "rm -r" David Brownlee (May 08)

David LeBlanc

Re: Revision 2: Analysis of jolt2.c (MS00-029) David LeBlanc (May 29)

David L. Nicol

Re: "ClientSideTrojan" bug David L. Nicol (May 11)

David Schwartz

Re: tcpdump workaround against dnsloop exploit. David Schwartz (May 06)

deepquest () NETSCAPE NET

4ward:It's a blue world! deepquest () NETSCAPE NET (May 02)
forward:Update on Web Companion Issues deepquest () NETSCAPE NET (May 10)
INFO:AppleShare IP 6.3.2 squashes security bug deepquest () NETSCAPE NET (May 02)

der Mouse

Re: Solaris 7 x86 lpset exploit. der Mouse (May 02)

dildog

Microsoft Office 2000 Advisory dildog (May 12)

Dimitri van de Giessen

Re: shtml.exe reveal local path of IIS web directory Dimitri van de Giessen (May 07)

Dimuthu Parussalla

Ipchains! Dimuthu Parussalla (May 07)
Remote Dos attack against Intel express 8100 router Dimuthu Parussalla (May 18)

D. J. Bernstein

Re: glibc resolver weakness D. J. Bernstein (May 06)

dm () JUGGERNAUT EL8 ORG

el8.org advisory - Win 95/98 DoS (RFParalyze.c) dm () JUGGERNAUT EL8 ORG (May 02)

Donald McLachlan

Re: Denial of service attack against tcpdump Donald McLachlan (May 07)

Dragos Ruiu

Re: Denial of service attack against tcpdump Dragos Ruiu (May 03)

dr_erik_wright () GMX NET

CyberCop Monitor NT 2.5 dr_erik_wright () GMX NET (May 23)

duke

klogin remote exploit duke (May 17)

Duncan Simpson

checpks non-explooitiable buffer overrun Duncan Simpson (May 17)

Earl T. Carter

Jolt2 crashes tcpdump Earl T. Carter (May 30)

eAX -

Security Bug in Jana HTTP Server eAX - (May 02)

Ed Padin

Re: IL0VEY0U worm Ed Padin (May 04)

Elias Levy

Re: IL0VEY0U worm Elias Levy (May 04)
ILOVEYOU worm Elias Levy (May 04)
Re: Another hole in Cart32 Elias Levy (May 22)
Gauntlet Firewall Vulnerability Elias Levy (May 22)
Re: IL0VEY0U worm Elias Levy (May 04)
Re: IL0VEY0U worm Elias Levy (May 04)
Re: IL0VEY0U worm Elias Levy (May 05)

emf

Security Vulnerability in IPFilter 3.3.15 and 3.4.3 emf (May 25)

Eric.Stevens () AVENTIS COM

Omnis Weak Encryption - Many products affected Eric.Stevens () AVENTIS COM (May 25)

Esteve Espuna

Cisco Bug Error Log Esteve Espuna (May 16)
Cisco Bug Esteve Espuna (May 16)

Federico G. Schwindt

more majordomo brokeness Federico G. Schwindt (May 23)

Fernando Montenegro

Possible issue with Cisco on-line help? Fernando Montenegro (May 02)
Re: Possible issue with Cisco on-line help? Fernando Montenegro (May 04)

foo

Possible symlink problems with Netscape 4.73 foo (May 10)
Re: Possible symlink problems with Netscape foo (May 10)

Foo Bar

IE Domain Confusion Vulnerability Foo Bar (May 11)

Frankie Zie

shtml.exe reveal local path of IIS web directory Frankie Zie (May 06)

Frank van Vliet

Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8 Frank van Vliet (May 10)

Fred Silva

Re: Nasty XFree Xserver DoS - Workaround Fred Silva (May 25)

FreeBSD Security Officer

FreeBSD Security Advisory: FreeBSD-SA-00:18.gnapster FreeBSD Security Officer (May 09)
FreeBSD Security Advisory: FreeBSD-SA-00:08.lynx [REVISED] FreeBSD Security Officer (May 17)
FreeBSD Security Advisory: FreeBSD-SA-00:20.krb5 FreeBSD Security Officer (May 26)
FreeBSD Security Advisory: FreeBSD-SA-00:18.gnapster [REVISED] FreeBSD Security Officer (May 17)
FreeBSD Security Advisory: FreeBSD-SA-00:16.golddig FreeBSD Security Officer (May 09)
FreeBSD Security Advisory: FreeBSD-SA-00:17.libmytinfo FreeBSD Security Officer (May 09)
FreeBSD Security Advisory: FreeBSD-SA-00:19.semconfig FreeBSD Security Officer (May 26)

fusys () ITAPAC NET

spj-003-000 - S0ftPj Advisory fusys () ITAPAC NET (May 02)

Gary Ellison

Re: glibc resolver weakness Gary Ellison (May 08)

Gary L. Burnore

Re: Advisory: Netopia R9100 router vulnerability Gary L. Burnore (May 09)

gec () ACM ORG

Key Generation Security Flaw in PGP 5.0 gec () ACM ORG (May 23)

Geo.

NTMail Proxy Exploit Geo. (May 12)

Gerald Combs

Re: Denial of service attack against tcpdump Gerald Combs (May 03)

Gert Doering

Re: non-exec stack Gert Doering (May 09)

Glynn Clements

Re: Race condition in "rm -r" Glynn Clements (May 07)
Re: Race condition in "rm -r" Glynn Clements (May 07)
Re: Race condition in "rm -r" Glynn Clements (May 06)

gramble none

Gauntlet Exploit proof gramble none (May 24)

Grant Bayley

"Microsoft to publish details of Kerberos Authorisation Data in Windows 2000" Grant Bayley (May 01)

Greg Olszewski

Re: fdmount buffer overflow Greg Olszewski (May 22)
Re: "gdm" remote hole Greg Olszewski (May 23)

Hannah Schröter

Re: CVS DoS Hannah Schröter (May 02)

Henrik .H

Re: Eudora Pro & Outlook Overflow - too long filenames again Henrik .H (May 16)

Horst von Brand

Re: aaa_base still vulnerable after upgrade Horst von Brand (May 01)

Howard M. Kash III

Vulnerability in CGI counter 4.0.7 by George Burgyan Howard M. Kash III (May 15)

http-equiv () excite com

MICROSOFT SECURITY FLAW? http-equiv () excite com (May 15)

Hugo.van.der.Kooij () CAIW NL

Esafe Protect Gateway issue still unresolved! Hugo.van.der.Kooij () CAIW NL (May 01)
Re: Denial of service attack against tcpdump Hugo.van.der.Kooij () CAIW NL (May 09)

Ignacio Kadel-Garcia

Re: [cert] SSH Authentication Vulnerability Ignacio Kadel-Garcia (May 11)

Jaanus Kase

Re: ILOVEYOU worm Jaanus Kase (May 04)

James Sneeringer

Re: Cisco Bug James Sneeringer (May 16)

Jason R Thorpe

Re: Foward: FreeBSD Security Advisory: FreeBSD-SA-00:19.semconfig Jason R Thorpe (May 26)

Jay Mobley

I think Jay Mobley (May 23)

Jay R. Ashworth

Re: Microsoft to release a new Outlook Security patch Jay R. Ashworth (May 19)

Jeff Dafoe

Re: Windows NT/95/98/Possible Others Denial of Service Attack. Microsoft ODBC Database connectivity flaw. Jeff Dafoe (May 02)
Re: Windows NT/95/98/Possible Others Denial of Service Attack. Microsoft ODBC Database connectivity flaw. Jeff Dafoe (May 01)

Jeff Lovell

Cobalt Networks - Security Advisory - Frontpage Jeff Lovell (May 25)

Jeffrey I. Schiller

BUFFER OVERRUN VULNERABILITIES IN KERBEROS Jeffrey I. Schiller (May 16)
Yet Another Kerberos Patch Jeffrey I. Schiller (May 17)

Jeffrey Paul

Re: Advisory: Netopia R9100 router vulnerability Jeffrey Paul (May 13)

Jeremy Rauch

Re: New Solaris root exploit for /usr/lib/lp/bin/netpr Jeremy Rauch (May 15)
Re: SuSE Security Announcement - aaa_base - UPDATE Jeremy Rauch (May 03)

Jim Early

Gnapster Vulnerability Compromises User-readable Files Jim Early (May 10)

Jim Knoble

Re: Standard & Poors security nightmare Jim Knoble (May 18)

Jim Paris

Kerberos ksu and krshd exploits Jim Paris (May 18)

Jim Riley

Re: Eudora Sensitive to Long Filenames Jim Riley (May 24)

j nickson

Corel Linux Default Install j nickson (May 29)

Joao Pedro Gonçalves

Re: Banner Rotation 01 Joao Pedro Gonçalves (May 17)

John P. McNeely

SSH Authentication Vulnerability John P. McNeely (May 10)

Jose Nazario

Re: Vulnerability in infosrch.cgi Jose Nazario (May 24)
Re: Qpopper 2.53 remote problem, user can gain gid=mail Jose Nazario (May 24)

Joseph Moran

Re: "Microsoft to publish details of Kerberos Authorisation Data in Windows 2000" Joseph Moran (May 02)

Josh Rollyson

Fwd: [nohack] Yet another way to disguise files. Josh Rollyson (May 16)

Juan M. Bello Rivas

Re: Fun with UltraBoard V1.6X Juan M. Bello Rivas (May 05)

Justin Gunther

Steal Passwords Using SQL Server EM Justin Gunther (May 25)

Justin King

Re: Another hole in Cart32 Justin King (May 24)

Justin Tripp

Security Bulletins Digest (fwd) Justin Tripp (May 04)
Security Bulletins Digest (fwd) Justin Tripp (May 03)

Katherine M. Moussouris

[TL-Security-Announce] xlockmore TLSA2000012-1.txt Katherine M. Moussouris (May 30)
Re: kscd vulnerability Katherine M. Moussouris (May 25)
[TL-Security-Announce] openLDAP TLSA2000010-1 Katherine M. Moussouris (May 17)
Re: fdmount buffer overflow Katherine M. Moussouris (May 24)
[TL-Security-Announce] gpm TLSA2000011-1 Katherine M. Moussouris (May 26)
Re: "gdm" remote hole Katherine M. Moussouris (May 22)

Kevin Fu

new vulnerability in Netscape effectively disables SSL server auth Kevin Fu (May 26)

Kevin Kadow

Re: Standard & Poors security nightmare Kevin Kadow (May 25)

Kingpin

Aladdin eToken 3.3.3.x Hardware USB Key Private Data Extraction Kingpin (May 04)

Kragen Sitaker

"ClientSideTrojan" bug Kragen Sitaker (May 09)

krahmer () CS UNI-POTSDAM DE

Re: strike#2 krahmer () CS UNI-POTSDAM DE (May 31)

Kris Kennaway

Re: CVS DoS Kris Kennaway (May 01)
Re: BUFFER OVERRUN VULNERABILITIES IN KERBEROS Kris Kennaway (May 18)

Larry Olin Horn

Re: Fwd: [nohack] Yet another way to disguise files. Larry Olin Horn (May 18)

Larz Sherer

Re: ZoneAlarm Larz Sherer (May 12)

Laurent LEVIER

Windows DoS code (jolt2.c) Laurent LEVIER (May 25)
Trivial bug in IIS5 SSL Laurent LEVIER (May 28)

Lisa Napier

Re: Possible issue with Cisco on-line help? Lisa Napier (May 09)

Luciano Martins

Re: DST2K0004b: Authentication issue in WebShield SMTP v4.5.44 Management Tool Luciano Martins (May 25)
Re: DST2K0004b: Authentication issue in WebShield SMTP v4.5.44 Management Tool Luciano Martins (May 27)

Magosanyi Arpad

Re: "ClientSideTrojan" bug Magosanyi Arpad (May 16)

Marc

Reminder: MaxClientRequestBuffer Marc (May 03)

Marc Heuse

SuSE Security Announcement - aaa_base - UPDATE Marc Heuse (May 02)

Marc Slemko

Re: IE Domain Confusion Vulnerability doesn't matter much Marc Slemko (May 12)

Marcy Abene

Re: el8.org advisory - Win 95/98 DoS (RFParalyze.c) Marcy Abene (May 03)

Marek Roy

IBM HTTP SERVER / APACHE Marek Roy (May 31)

Mariusz Woloszyn

Re: Libsafe Protecting Critical Elements of Stacks Mariusz Woloszyn (May 04)

Martin Drury

Fw: Steal Passwords Using SQL Server EM Martin Drury (May 30)

Matt

Re: Microsoft Security Bulletin (MS00-036) Matt (May 26)
Re: RFP2K04: Mining BlackICE with RFPickAxe Matt (May 18)

Matt Carothers

Re: shtml.exe reveal local path of IIS web directory Matt Carothers (May 13)

Matthew J.Francis

Re: "ClientSideTrojan" bug Matthew J.Francis (May 11)

Matt Wilson

Re: fdmount buffer overflow Matt Wilson (May 24)
Re: kscd vulnerability Matt Wilson (May 24)

Maurycy Prodeus

Re: Qpopper 2.53 problem, user can gain gid=mail Maurycy Prodeus (May 27)

Michael Form

Re: Another hole in Cart32 Michael Form (May 22)

Michal Zalewski

Re: pam_console bug Michal Zalewski (May 04)
pam_console bug Michal Zalewski (May 02)
Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) Michal Zalewski (May 18)
"I don't think I really love you" Michal Zalewski (May 07)

Michel Kaempf

`sniffit -L mail' vulnerabilities Michel Kaempf (May 25)

Microsoft Product Security

Microsoft Security Bulletin (MS00-038) Microsoft Product Security (May 30)
Microsoft Security Bulletin (MS00-034) Microsoft Product Security (May 12)
Microsoft Security Bulletin (MS00-030) Microsoft Product Security (May 11)
Microsoft Security Bulletin (MS00-033) Microsoft Product Security (May 17)
Microsoft Security Bulletin (MS00-029) Microsoft Product Security (May 19)
Microsoft Security Bulletin (MS00-031) Microsoft Product Security (May 10)
Microsoft Security Bulletin (MS00-036) Microsoft Product Security (May 26)
Microsoft Security Bulletin (MS00-035) Microsoft Product Security (May 30)

Microsoft Security Response Center

Re: BUFFER OVERRUN VULNERABILITIES IN KERBEROS Microsoft Security Response Center (May 17)
Re: Eudora Pro & Outlook Overflow - too long filenames again Microsoft Security Response Center (May 16)

Mikael Olsson

Addendum: Analysis of jolt2.c (MS00-029) Mikael Olsson (May 26)
Analysis of jolt2.c (MS00-029) Mikael Olsson (May 26)
Revision 2: Analysis of jolt2.c (MS00-029) Mikael Olsson (May 27)

Mike Bush

Security Bulletins Digest (fwd) Mike Bush (May 17)

Mitja Kolsek

ALERT: Bypassing Warnings For Invalid SSL Certificates In Netscape Navigator Mitja Kolsek (May 10)

mock () ACTIVESTATE COM

Re: Fwd: [nohack] Yet another way to disguise files. mock () ACTIVESTATE COM (May 19)

Moritz Jodeit

Buffer Overflows with long file extensions in Windows Moritz Jodeit (May 25)

Morten Welinder

Race condition in "rm -r" Morten Welinder (May 03)

Mudge

Re: antisniff latest ("two times fixed") version still exploitable, l0phtl0phe-kid.c Mudge (May 18)

NAI Labs

Trend Micro InterScan VirusWall Remote Overflow NAI Labs (May 04)

Nate Eldredge

Re: non-exec stack Nate Eldredge (May 10)

Nathan Neulinger

(old) informix security hole with ruserok() style security Nathan Neulinger (May 18)

NetBSD Security Officer

NetBSD Security Advisory 2000-006 NetBSD Security Officer (May 28)
NetBSD Security Advisory 2000-003 NetBSD Security Officer (May 28)
NetBSD Security Advisory 2000-005 NetBSD Security Officer (May 28)
NetBSD Security Advisory 2000-004 NetBSD Security Officer (May 28)

Neulinger, Nathan R.

Re: Cobalt Networks - Security Advisory - Frontpage Neulinger, Nathan R. (May 25)

NHC Research

[NHC20000504a.0: NetBSD Panics when sent unaligned IP options] NHC Research (May 06)

Nishad Herath

Re: Alert: DNewsWeb buffer overflow Nishad Herath (May 06)

Noah

Re: Problem with FrontPage on Cobalt RaQ2/RaQ3 Noah (May 23)

noir

KDE: /usr/bin/kdesud, gid = 0 exploit noir (May 26)
Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2) noir (May 27)

Ollie Whitehouse

Re: DST2K0004b: Authentication issue in WebShield SMTP v4.5.44 Ma nagement Tool Ollie Whitehouse (May 27)

Omachonu Ogali

Mac OS X Signature Omachonu Ogali (May 03)

Oppenheimer, Max

Re: AOL Instant Messenger Oppenheimer, Max (May 09)

Patrick J. Volkerding

Buffer Overflow in fdmount (fwd) Patrick J. Volkerding (May 25)

Patrick Oonk

vnc remote dictionary based cracker Patrick Oonk (May 23)
About VNC Patrick Oonk (May 24)

Patrick Turcotte

Re: Denial of Service Against pcAnywhere. Patrick Turcotte (May 03)

Paul Cardon

Re: Source code to mstream, a DDoS tool Paul Cardon (May 01)

Paul D. Carlucci

Re: Ipchains! Paul D. Carlucci (May 10)

Paulo Ribeiro

fdmount 0.8 exploit Paulo Ribeiro (May 22)

Pedro Quintanilha

Re: RFP2K05: NetProwler vs. RFProwler Pedro Quintanilha (May 23)

Peter da Silva

Re: Solaris 7 x86 lpset exploit. Peter da Silva (May 01)
Re: Solaris 7 x86 lpset exploit. Peter da Silva (May 04)

Peter D. Thompson Yezek

formmail patch Peter D. Thompson Yezek (May 26)

Peter Leonard

Re: "Microsoft to publish details of Kerberos Authorisation Data in Windows 2000" Peter Leonard (May 02)

Peter van Dijk

How we defaced www.apache.org Peter van Dijk (May 04)

Peter W

Re: Fwd: [nohack] Yet another way to disguise files. Peter W (May 18)
issues with free Perl CGI's (Re: Black Watch Labs...) Peter W (May 10)
Re: vnc remote dictionary based cracker Peter W (May 24)

Pierre Benoit

Vulnerability in EMURL-based e-mail providers Pierre Benoit (May 15)

Prizm

Qpopper 2.53 remote problem, user can gain gid=mail Prizm (May 23)
Re: Qpopper 2.53 problem, user can gain gid=mail Prizm (May 25)

Psarras Nikos

Re: fingerd Psarras Nikos (May 02)

Qpopper Support

Re: Qpopper 2.53 remote problem, user can gain gid=mail Qpopper Support (May 24)
Security Vulnerability in Qpopper 2.53 (Upgrade to 3.0.2) Qpopper Support (May 23)

rain forest puppy

RFP2K04: Mining BlackICE with RFPickAxe rain forest puppy (May 17)
Re: RFP2K04: Mining BlackICE with RFPickAxe rain forest puppy (May 19)
RFP2K05: NetProwler vs. RFProwler rain forest puppy (May 19)

Raymond Dijkxhoorn

[RHSA-2000:005-05] New majordomo packages available (fwd) Raymond Dijkxhoorn (May 31)

Renaud Deraison

announce : Nessus 1.0 released Renaud Deraison (May 17)

Richard M. Smith

IE Domain Confusion Vulnerability is an Email problem also Richard M. Smith (May 12)
Microsoft to release a new Outlook Security patch Richard M. Smith (May 15)
Re: IE Domain Confusion Vulnerability doesn't matter much Richard M. Smith (May 15)

Richard Seaman, Jr.

Re: Standard & Poors security nightmare Richard Seaman, Jr. (May 20)
Re: Standard & Poors security nightmare Richard Seaman, Jr. (May 21)

Richard Trott

Re: more majordomo brokeness Richard Trott (May 31)
New OpenBSD patches Richard Trott (May 28)

Robert Graham

Re: RFP2K04: Mining BlackICE with RFPickAxe Robert Graham (May 17)
Re: CyberCop Monitor NT 2.5 Robert Graham (May 24)

Rob Lindenbusch

Gauntlet CyberPatrol Buffer Overflow Rob Lindenbusch (May 22)

Rob Tashjian

Re: Advisory: Netopia R9100 router vulnerability Rob Tashjian (May 10)
Re: Advisory: Netopia R9100 router vulnerability Rob Tashjian (May 10)

Roger Safian

June 2000 FIRST Conference Reminder Roger Safian (May 08)

Ron DuFresne

Re: Fwd: [nohack] Yet another way to disguise files. Ron DuFresne (May 16)

Ron Moritz

Eudora Sensitive to Long Filenames Ron Moritz (May 18)

route () TRADECRAFT INFONEXUS COM

Announcement: Phrack Lovin' route () TRADECRAFT INFONEXUS COM (May 01)

rpc

infosrch.cgi 'interactive' shell rpc (May 23)

rudi carell

Fun with UltraBoard V1.6X rudi carell (May 03)

Russ

Re: MICROSOFT SECURITY FLAW? Russ (May 18)
Re: Steal Passwords Using SQL Server EM Russ (May 30)

salme () US IBM COM

Filesystem vulnerability in AIX salme () US IBM COM (May 23)

Sebastian

antisniff x86/linux remote root exploit, including "fixed" 1.02 version Sebastian (May 16)
Re: Qpopper 2.53 remote problem, user can gain gid=mail Sebastian (May 25)
antisniff latest ("two times fixed") version still exploitable, l0phtl0phe-kid.c Sebastian (May 18)
KDE::KApplication feature? Sebastian (May 31)
Re: Denial of service attack against tcpdump Sebastian (May 03)
Re: Fwd: tcpdump workaround against dnsloop exploit. Sebastian (May 07)
Re: kscd vulnerability Sebastian (May 25)
kscd vulnerability Sebastian (May 16)

Security

Re: shtml.exe reveal local path of IIS web directory Security (May 08)
Re: Source code to mstream, a DDoS tool Security (May 01)

Security Team

DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool Security Team (May 25)
DST2K0004b: Authentication issue in WebShield SMTP v4.5.44 Manage ment Tool Security Team (May 25)

sert sert

Re: Another hole in Cart32 sert sert (May 22)

Servio Medina

MetaProducts Offline Explorer Directory Traversal Vulnerability Servio Medina (May 22)

Seth McGann

Self-Replication Using Gnutella Seth McGann (May 09)

SGI Security Coordinator

Vulnerability in infosrch.cgi SGI Security Coordinator (May 22)

Shivdasani, Meenoo

Re: Gauntlet Exploit proof Shivdasani, Meenoo (May 25)

Skahan, Vince

Re: more majordomo brokeness Skahan, Vince (May 30)

SMILER

Re: shtml.exe reveal local path of IIS web directory SMILER (May 07)
Re: Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) SMILER (May 23)

Solar Designer

An Analysis of the TACACS+ Protocol and its Implementations Solar Designer (May 30)

stanislav shalunov

Re: netkill - generic remote DoS attack stanislav shalunov (May 03)

Stephen Friedl

Advisory: Netopia R9100 router vulnerability Stephen Friedl (May 08)
Standard & Poors security nightmare Stephen Friedl (May 17)

Stephen J. Friedl

Re: Standard & Poors security nightmare Stephen J. Friedl (May 24)

Steven M. Bellovin

Re: glibc resolver weakness Steven M. Bellovin (May 03)

Steve Wolfe

"ILOVEYOU" virus analysis Steve Wolfe (May 04)

suid () SUID KG

Vuln in calender.pl (Matt Kruse calender script) suid () SUID KG (May 16)

Su, Nick

Re: Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) Su, Nick (May 20)

swlodin () IQUEST NET

Kerberos Vulnerability and IBM SP2 Frame swlodin () IQUEST NET (May 24)

TAKAGI, Hiromitsu

Re: Reappearance of an old IE security bug TAKAGI, Hiromitsu (May 12)

|[TDP]|

CProxy v3.3 SP 2 DoS |[TDP]| (May 16)
Remote xploit for MDBMS |[TDP]| (May 24)

The Cr0W

2.2.14 Kernel exec/open bug (?) The Cr0W (May 05)

The Hidden

Formated and commented loveletter. The Hidden (May 04)

THE INFAMOUS

xsoldier update for Linux Mandrake THE INFAMOUS (May 17)
Fwd: tcpdump workaround against dnsloop exploit. THE INFAMOUS (May 03)

Theo de Raadt

Re: New OpenBSD patches Theo de Raadt (May 28)
Re: FreeBSD Security Advisory: FreeBSD-SA-00:19.semconfig Theo de Raadt (May 26)
Re: FreeBSD Security Advisory: FreeBSD-SA-00:19.semconfig Theo de Raadt (May 26)

Thomas Biege

Re: SuSE 6.3 Gnomelib buffer overflow Thomas Biege (May 03)
SuSE Security Announcement: kmulti Thomas Biege (May 29)
Re: "gdm" remote hole Thomas Biege (May 22)

Tim Newsham

non-exec stack Tim Newsham (May 06)

Todd C. Miller

Re: Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8 Todd C. Miller (May 10)

Tollef Fog Heen

Buffer overflows in Skyline/SpinBox client Tollef Fog Heen (Apr 30)

Tomasz Grabowski

Re: fdmount buffer overflow Tomasz Grabowski (May 24)

Tom Daniels

KNapster Vulnerability Compromises User-readable Files Tom Daniels (May 10)

Tom Yu

revised patches for kerberos vulnerability Tom Yu (May 19)

Tony Nugent

Re: [linux-security] Re: [RHSA-2000:028-02] Netscape 4.73 available Tony Nugent (May 28)

Troy Bollinger

Re: AIX 4.1.4.0 local root LC_MESSAGES /usr/sbin/arp exploit Troy Bollinger (May 08)

Ultor

Eudora Pro & Outlook Overflow - too long filenames again Ultor (May 15)
Overflow in Outlook Express 4.* - too long filenames with graphic format extension Ultor (May 12)

Ussr Labs

Remote DoS attack in Internet Information Server 4.0 & 5.0 "Malformed Extension Data in URL" Vulnerability Ussr Labs (May 11)
HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability Ussr Labs (May 24)
HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability Ussr Labs (May 24)

Valdis.Kletnieks () VT EDU

Re: aaa_base still vulnerable after upgrade Valdis.Kletnieks () VT EDU (May 01)
Re: glibc resolver weakness Valdis.Kletnieks () VT EDU (May 03)

Vandoorselaere Yoann

Re: fdmount buffer overflow Vandoorselaere Yoann (May 23)

Vincent Power

Re: Corel Linux Default Install Vincent Power (May 29)

visi0n

AUX Security Advisory on Be/OS 5.0 (DoS) visi0n (May 17)

Vitaly Fedrushkov

Aladdin Software Security SecretDisk console blocking failure Vitaly Fedrushkov (May 25)

Vladimir Dubrovin

Re: [COVERT-2000-05] Microsoft Windows Computer Browser Reset Vulnerability Vladimir Dubrovin (May 26)

Warren Barrow

ISSalert: Internet Security Systems Security Advisory: Microsoft IIS Remote Denial of Service Attack Warren Barrow (May 11)

Warren Young

Re: Standard & Poors security nightmare Warren Young (May 23)

weed5312 () UIDAHO EDU

Re: el8.org advisory - Win 95/98 DoS (RFParalyze.c) weed5312 () UIDAHO EDU (May 03)

Weston Pawlowski

Re: Nasty XFree Xserver DoS Weston Pawlowski (May 22)

White Vampire

Re: "gdm" remote hole White Vampire (May 24)

Will Price

PGP Security Advisory for PGP 5.0 Will Price (May 30)

wizdumb () LEET ORG

Various Lame Stuff wizdumb () LEET ORG (May 16)
E-Serv Security Flaws Fixed wizdumb () LEET ORG (May 28)

ZhaoQian

»Ø¸´: Re: non-exec stac ZhaoQian (May 10)

zillion

Banner Rotation 01 zillion (May 16)

zoran () UVINC COM

QuickCommerce Vulnerability zoran () UVINC COM (May 22)