Bugtraq: by author

233 messages starting Jun 03 08 and ending Jun 10 08
Date index | Thread index | Author index


0xjbrown41

Re: Windows Installer msiexec GUID Buffer Overflow 0xjbrown41 (Jun 03)

Admin

Pooya Site Builder (PSB) SQL Injection Vulnerabilities Admin (Jun 12)
eLineStudio Site Composer (ESC) <=2.6 Multiple Vulnerabilities Admin (Jun 19)
Academic Web Tools CMS <= 1.4.2.8 Multiple Vulnerabilities Admin (Jun 19)
QuickerSite Multiple Vulnerabilities Admin (Jun 04)
Xigla Multiple Products - Multiple Vulnerabilities Admin (Jun 11)

adv

[ECHO_ADV_99$2008] Relative Real Estate Systems <= 3.0 (listing_id) Sql Injection Vulnerability adv (Jun 25)

Akamai Security Team

Akamai Technologies Security Advisory 2008-0003 (Akamai Client Software) Akamai Security Team (Jun 06)
Akamai Technologies Security Advisory 2008-0001 (Download Manager) Akamai Security Team (Jun 04)

Alex Eden

webTA by kronos - XSS Alex Eden (Jun 09)

Andrea Barisani

[oCERT-2008-006] multiple SNMP implementations HMAC authentication spoofing Andrea Barisani (Jun 10)

Andrea Di Pasquale

ARP handler Inspection tool released Andrea Di Pasquale (Jun 02)

Asterisk Security Team

AST-2008-009: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised Asterisk Security Team (Jun 05)
AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel driver Asterisk Security Team (Jun 05)
AST-2008-008: Remote Crash Vulnerability in SIP channel driver when run in pedantic mode Asterisk Security Team (Jun 03)

azurIt

Firefox 3.0 security bug: Extensions can STILL hide themselves azurIt (Jun 23)

Bram Moolenaar

Re: Collection of Vulnerabilities in Fully Patched Vim 7.1 Bram Moolenaar (Jun 14)

Christoph Mayer

[Tool] PktAnon packet trace anonymization tool released Christoph Mayer (Jun 28)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities Cisco Systems Product Security Incident Response Team (Jun 25)
Cisco Security Advisory: Cisco Intrusion Prevention System Jumbo Frame Denial of Service Cisco Systems Product Security Incident Response Team (Jun 18)
Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA Cisco Systems Product Security Incident Response Team (Jun 04)
Cisco Security Advisory: SNMP Version 3 Authentication Vulnerabilities Cisco Systems Product Security Incident Response Team (Jun 10)

cocoruder

Akamai Download Manager File Downloaded To Arbitrary Location Vulnerability cocoruder (Jun 05)

CORE Security Technologies Advisories

CORE-2008-0425 - NASA BigView Stack Buffer Overflow CORE Security Technologies Advisories (Jun 04)
CORE-2008-0125: CitectSCADA ODBC service vulnerability CORE Security Technologies Advisories (Jun 11)

craigswright

CSW Security Advisory 0002: Oral B SmartMonitor Information Disclosure Vulnerability and DoS craigswright (Jun 19)

Craig Wright

Hacking Coffee Makers. Craig Wright (Jun 17)
A more detailed description of the Jura F90 vulnerability. Craig Wright (Jun 18)
RE: A more detailed description of the Jura F90 vulnerability. Craig Wright (Jun 19)

cwrigh20

An Apology. cwrigh20 (Jun 19)

dann frazier

[SECURITY] [DSA 1592-1] New Linux 2.6.18 packages fix overflow conditions dann frazier (Jun 09)
[SECURITY] [DSA 1592-2] New Linux 2.6.18 packages fix overflow conditions dann frazier (Jun 09)

decoder-bugtraq

Re: xt:Commerce possible DoS decoder-bugtraq (Jun 02)

DEF CON Switzerland

DEFCON Switzerland looking for DEFCON visitors DEF CON Switzerland (Jun 12)

Devin Carraway

[SECURITY] [DSA 1597-1] New mt-daapd packages fix several vulnerabilities Devin Carraway (Jun 12)

Digital Security Research Group

[DSECRG-08-026] LFI in Open Azimyt CMS 0.22 Digital Security Research Group (Jun 16)

DoZ

SchoolCenter URL Handling Cross Site Scripting Vulnerability DoZ (Jun 06)

Dragos Ruiu

BA-Con 2008 CFP - Buenos Aires, Sept. 30 / Oct. 1 (closes July 11 2008) Dragos Ruiu (Jun 27)

dubingyao

Remote DoS vulnerability in Linksys WRH54G dubingyao (Jun 05)

DVLabs

TPTI-08-05: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow Vulnerability DVLabs (Jun 04)

Eduardo Jorge

XSS - NEXTGEN GALLERY 0.96 WORDPRESS PLUGIN Eduardo Jorge (Jun 09)
Muitiple XSS - Glassfish Web Interface (Sun Java System Application Server 9.1_01 (build b09d-fcs) ) Eduardo Jorge (Jun 16)
XSS - Glassfish Web Admin Interface (Sun Java System Application Server 9.1_01 (build b09d-fcs) ) Eduardo Jorge (Jun 10)

erdc

[ECHO_ADV_98$2008] Pre Ads Portal <= 2.0 Sql Injection Vulnerability erdc (Jun 16)
[ECHO_ADV_97$2008] Pre News Manager <= 1.0 (index.php id) Sql Injection Vulnerability erdc (Jun 16)
[ECHO_ADV_96$2008] HiveMaker Professional <= 1.0.2 (cid) Sql Injection Vulnerability erdc (Jun 02)

Ferruh Mavituna

Diigo Toolbar - Global XSS and Information Leakage in SSL URLs Ferruh Mavituna (Jun 20)

Gadi Evron

Announcement && CFP: ISOI 5, Tallinn Estonia Gadi Evron (Jun 18)

Ghost hacker

RSS-aggregator (display) Remote File Inclusion Vulnerability Ghost hacker (Jun 25)
IdeBox (include) Remote File Inclusion Vulnerability Ghost hacker (Jun 25)
mcGuestbook 1.2 (lang) Remote File Inclusion Vulnerability Ghost hacker (Jun 25)

glafkos

DUC NO-IP Local Password Information Disclosure Vulnerability glafkos (Jun 16)

hadihadi_zedehal_2006

e107 Plugin echat MENU Blind SQL Injection Vulnerability hadihadi_zedehal_2006 (Jun 05)
OtomiGenX v2.2 Ultimate Authentication bypass Vulnerability hadihadi_zedehal_2006 (Jun 02)

hh-ua

Re: RFI ====> vBulletin v3.6.5 hh-ua (Jun 19)

iDefense Labs

iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension Gradient Creation Integer Overflow Vulnerability iDefense Labs (Jun 11)
iDefense Security Advisory 06.10.08: Multiple Vendor FreeType2 PFB Memory Corruption Vulnerability iDefense Labs (Jun 10)
Re: iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalation Vulnerability iDefense Labs (Jun 06)
iDefense Security Advisory 06.11.08: Multiple Vendor X Server MIT-SHM Extension Information Disclosure Vulnerability iDefense Labs (Jun 11)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Information Disclosure Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.11.08: Multiple Vendor X Server Record and Security Extensions Multiple Memory Corruption Vulnerabilities iDefense Labs (Jun 11)
iDefense Security Advisory 06.04.08: Skype File URI Security Bypass Code Execution Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages File Creation Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.10.08: Multiple Vendor FreeType2 PFB Integer Overflow Vulnerability iDefense Labs (Jun 10)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Buffer Overflow Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.04.08: VMware Multiple Products vmware-authd Untrusted Library Loading Vulnerability iDefense Labs (Jun 05)
iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalation Vulnerability iDefense Labs (Jun 05)
Re: iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalation Vulnerability iDefense Labs (Jun 05)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Multiple Command Injection Vulnerabilities iDefense Labs (Jun 04)
iDefense Security Advisory 06.10.08: Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability iDefense Labs (Jun 10)
iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension ProcRenderCreateCursor() Integer Overflow Vulnerability iDefense Labs (Jun 11)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Multiple Directory Traversal Vulnerabilities iDefense Labs (Jun 04)
iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension AllocateGlyph() Integer Overflow Vulnerability iDefense Labs (Jun 11)
iDefense Security Advisory 06.04.08: Kaspersky Internet Security IOCTL Stack Based Buffer Overflow Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Authorization Bypass Vulnerability iDefense Labs (Jun 04)
iDefense Security Advisory 06.10.08: Multiple Vendor FreeType2 Multiple Heap Overflow Vulnerabilities iDefense Labs (Jun 10)

inode

SNMPv3 Authentication Bypass - CVE-2008-0960 inode (Jun 12)

ipsdix

[NSG 03-06-2008] C6 Messenger Installation Url DownloaderActiveX Control Remote Download & Execute Exploit ipsdix (Jun 03)

irancrash

VistaReseller Panel BETA Xss Vulnerability irancrash (Jun 16)

Jamie Strandboge

[USN-612-10] OpenVPN regression Jamie Strandboge (Jun 13)
[USN-621-1] Ruby vulnerabilities Jamie Strandboge (Jun 27)
[USN-615-1] Evolution vulnerabilities Jamie Strandboge (Jun 07)
[USN-612-9] openssl-blacklist update Jamie Strandboge (Jun 13)
[USN-617-1] Samba vulnerabilities Jamie Strandboge (Jun 18)
[USN-620-1] OpenSSL vulnerabilities Jamie Strandboge (Jun 26)
[USN-612-11] openssl-blacklist update Jamie Strandboge (Jun 19)

Jan Minář

Collection of Vulnerabilities in Fully Patched Vim 7.1 Jan Minář (Jun 14)

Jessica Hope

Exploit for vBulletin "obscure" XSS (3.7.1 & 3.6.10) Jessica Hope (Jun 13)
vBulletin 3.7.1 PL1 and lower, vBulletin 3.6.10 PL1: XSS in modcp index Jessica Hope (Jun 19)

jgrove_2000

Vulnerability in Network General/Net Scout product jgrove_2000 (Jun 06)

Jon Kibler

Re: Summary of AS/400 Vulnerability Information Jon Kibler (Jun 23)
AS/400 Vulnerabilities Jon Kibler (Jun 13)

jplopezy

Pidgin 2.4.1 Vulnerability jplopezy (Jun 26)
Rhythmbox Vulnerability jplopezy (Jun 26)
Evolution Vulnerability jplopezy (Jun 26)

Kees Cook

[USN-616-1] X.org vulnerabilities Kees Cook (Jun 13)
[USN-614-1] Linux kernel vulnerabilities Kees Cook (Jun 03)

lars

TYPO3 Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core lars (Jun 11)

LIUDIEYU dot COM

Technical Details of Security Issues Regarding Safari for Windows LIUDIEYU dot COM (Jun 14)

Luigi Auriemma

NULL pointer in World in Conflict 1.008 Luigi Auriemma (Jun 23)
Re: Double Denial of Service in Call of Duty 4 1.6 Luigi Auriemma (Jun 30)
Denial of Service in S.T.A.L.K.E.R. 1.0006 Luigi Auriemma (Jun 16)
Multiple vulnerabilities in S.T.A.L.K.E.R. 1.0006 Luigi Auriemma (Jun 30)
Double Denial of Service in Call of Duty 4 1.6 Luigi Auriemma (Jun 23)
NULL pointer in the HTTP/XML-RPC service of Crysis 1.21 Luigi Auriemma (Jun 17)
Server freezed in Skulltag 0.97d2-RC2 Luigi Auriemma (Jun 17)
Endless loop in Halo 1.07 Luigi Auriemma (Jun 30)
Re: ZDI-08-034: HP StorageWorks Storage Mirroring Authentication Processing Stack Overflow Vulnerability Luigi Auriemma (Jun 04)

ma+bt

fetchmail security announcement fetchmail-SA-2007-02 (CVE-2007-4565) ma+bt (Jun 17)
fetchmail security announcement fetchmail-SA-2008-01 (CVE-2008-2711) ma+bt (Jun 17)
fetchmail REVISED security announcement fetchmail-SA-2008-01 (CVE-2008-2711) ma+bt (Jun 24)

Major Malfunction

London DEFCON June meet - DC4420 - Thursday 5th June Major Malfunction (Jun 03)

Marco Ivaldi

Re: AS/400 Vulnerabilities Marco Ivaldi (Jun 16)

Mark Thomas

[SECURITY] CVE-2008-1947: Tomcat host-manager XSS vulnerability Mark Thomas (Jun 03)

Matthias Geerdsen

[ GLSA 200806-07 ] X.Org X server: Multiple vulnerabilities Matthias Geerdsen (Jun 19)

Max Moser

BackTrack 3 Final has been released Max Moser (Jun 20)

Michael Wojcik

RE: AS/400 Vulnerabilities Michael Wojcik (Jun 13)
RE: Securify bulletin: Microsoft Active Directory Denial-of-service Michael Wojcik (Jun 13)

mikuvoli

Returnil Virtual System 2008 - Password Disclosure Issue mikuvoli (Jun 16)

m . memelli

FreeSSHD 1.2.1 (Post Auth) Remote Seh Overflow Exploit m . memelli (Jun 07)

Moose

GSC Privilege Escalation Exploit Moose (Jun 14)

Moritz Muehlenhoff

[SECURITY] [DSA 1594-1] New imlib2 packages fix arbitrary code execution Moritz Muehlenhoff (Jun 11)
[SECURITY] [DSA 1593-1] New tomcat5.5 packages cross-site scripting Moritz Muehlenhoff (Jun 09)
[SECURITY] [DSA 1599-1] New dbus packages fix privilege escalation Moritz Muehlenhoff (Jun 26)

Nam Nguyen

[BMSA 2008-07] Format string vulnerability in 5th street Nam Nguyen (Jun 25)

Nicolas A. Economou

iPhoneDbg Toolkit Nicolas A. Economou (Jun 17)

nnposter

F5 FirePass Content Inspection Management XSS nnposter (Jun 05)

none

Flat Calendar v1.1 Remote Permission Bypass Vulnerability none (Jun 11)
phpRaider <= v1.0.6,7 Maybe Other Versions Remote File include Vulnerable none (Jun 11)

Oliver Goebel

IMF 2008 - Deadline Extension (2nd try) Oliver Goebel (Jun 04)

Oliver Lavery

AccessMe Tool Release Oliver Lavery (Jun 03)

ork

Security and Hacking Papers - Updated! ork (Jun 30)

packet

Re: Remote SQL Injection packet (Jun 30)

Patrick Webster

Windows Installer msiexec GUID Buffer Overflow Patrick Webster (Jun 03)

pelzi

Multiple vulnerabilities in TietoEnator's Procapita school administration system, at least version "842 Procapita 840SP1" pelzi (Jun 26)

Pete Herzog

Trust Testing and Metrics Pete Herzog (Jun 23)

Pierre-Yves Rofes

[ GLSA 200806-05 ] cbrPager: User-assisted execution of arbitrary code Pierre-Yves Rofes (Jun 17)
[ GLSA 200806-06 ] Evolution: User-assisted execution of arbitrary code Pierre-Yves Rofes (Jun 17)
[ GLSA 200806-04 ] rdesktop: Multiple vulnerabilities Pierre-Yves Rofes (Jun 14)

Psymera

Many bugs on CMS system Piugame Psymera (Jun 10)

rand

CSIS-RI-0003: Multiple buffer overflow vulnerabilities in HP ActiveX rand (Jun 04)

Robert Buchholz

[ GLSA 200806-10 ] FreeType: User-assisted execution of arbitrary code Robert Buchholz (Jun 24)
[ GLSA 200806-09 ] libvorbis: Multiple vulnerabilities Robert Buchholz (Jun 24)
[ GLSA 200806-08 ] OpenSSL: Denial of Service Robert Buchholz (Jun 24)

rPath Update Announcements

rPSA-2008-0207-1 kernel rPath Update Announcements (Jun 27)
rPSA-2008-0201-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs rPath Update Announcements (Jun 21)
rPSA-2008-0181-1 openssl openssl-scripts rPath Update Announcements (Jun 02)
rPSA-2008-0206-1 ruby rPath Update Announcements (Jun 26)
rPSA-2008-0189-1 kernel xen rPath Update Announcements (Jun 12)
rPSA-2008-0185-1 vsftpd rPath Update Announcements (Jun 06)
rPSA-2008-0200-1 xorg-server rPath Update Announcements (Jun 21)
rPSA-2008-0180-1 samba samba-client samba-server samba-swat rPath Update Announcements (Jun 02)

S21sec labs

S21SEC-044-en:OpenDocMan Cross Site Scripting (XSS) S21sec labs (Jun 17)

saidmoftakhar

Remote SQL Injection saidmoftakhar (Jun 30)

Secunia Research

Secunia Research: Akamai Red Swoosh Cross-Site Request Forgery Secunia Research (Jun 06)
Secunia Research: TorrentTrader Multiple SQL Injection Vulnerabilities Secunia Research (Jun 18)
Secunia Research: uTorrent / BitTorrent Web UI HTTP "Range" Header DoS Secunia Research (Jun 11)
Secunia Research: XnView, NConvert, and GFL SDK Sun TAAC Buffer Overflow Secunia Research (Jun 20)
Secunia Research: Apple QuickTime PICT Image Parsing Buffer Overflow Secunia Research (Jun 10)

Securify Bulletins

Securify bulletin: Microsoft Active Directory Denial-of-service Securify Bulletins (Jun 13)

security

[ MDVSA-2008:120 ] - Updated nasm packages fix vulnerability security (Jun 23)
[ MDVSA-2008:117 ] - Updated fetchmail packages fix DoS vulnerability security (Jun 20)
[ MDVSA-2008:109 ] - Updated kernel packages fix bugs security (Jun 03)
[ MDVSA-2008:121 ] - Updated freetype2 packages fix vulnerabilities security (Jun 23)
[ MDVSA-2008:114 ] - Updated util-linux-ng packages fix log injection issue security (Jun 14)
[ MDVSA-2008:110 ] - Updated Firefox packages fix vulnerabilities security (Jun 06)
[ MDVSA-2008:123 ] - Updated imlib2 packages fix vulnerabilities security (Jun 25)
[ MDVSA-2008:113 ] - Updated kernel packages fix security issue security (Jun 14)
[ MDVSA-2008:116 ] - Updated x11-server packages fix several vulnerabilities security (Jun 16)
[ MDVSA-2008:112 ] - Updated kernel packages fix security issues security (Jun 12)
ERRATA - n.runs-SA-2008.001 - Jscape Secure FTP Applet security (Jun 25)
[ MDVSA-2008:122 ] - Updated clamav packages fix vulnerability security (Jun 24)
[ MDVSA-2008:115 ] - Updated x11-server packages fix several vulnerabilities security (Jun 16)
[ MDVSA-2008:124 ] - Updated xine-lib packages fix vulnerability in Speex decoder security (Jun 27)
n.runs-SA-2008.001 - Jscape Secure FTP Applet security (Jun 23)
[ MDVSA-2008:111 ] - Updated Evolution packages fix vulnerabilities security (Jun 10)
[ MDVSA-2008:118 ] - Updated net-snmp/ucd-snmp packages fix vulnerabilities security (Jun 20)
[ MDVSA-2008:119 ] - Updated exiv2 packages fix vulnerability security (Jun 21)

security-alert

[security bulletin] HPSBUX02341 SSRT080075 rev.1 - HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code security-alert (Jun 27)
[security bulletin] HPSBMA02338 SSRT080024, SSRT080041 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Denial of Service (DoS) security-alert (Jun 30)
[security bulletin] HPSBUX02342 SSRT080063 rev.1 - HP-UX Running Apache or Tomcat with PHP, Remote Execution of Arbitrary Code security-alert (Jun 11)
[security bulletin] HPSBST02312 SSRT071428 rev.1 - HP StorageWorks Storage Mirroring Software, Remote Execution of Arbitrary Code security-alert (Jun 03)
[security bulletin] HPSBMA02338 SSRT080024, SSRT080041 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Denial of Service (DoS) security-alert (Jun 10)
[security bulletin] HPSBUX02342 SSRT080063 rev.2 - HP-UX Running Apache with PHP, Remote Execution of Arbitrary Code security-alert (Jun 27)
[security bulletin] HPSBST02344 SSRT080087 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-030 to MS08-036 security-alert (Jun 18)
[security bulletin] HPSBMA02340 SSRT080024, SSRT080041 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Denial of Service (DoS) security-alert (Jun 11)
[security bulletin] HPSBMA02326 SSRT071490 rev.1 - HP Instant Support HPISDataManager.dll Running on Windows, Remote Execution of Arbitrary Code security-alert (Jun 04)
[security bulletin] HPSBST02312 SSRT071428 rev.2 - HP StorageWorks Storage Mirroring Software, Remote Execution of Arbitrary Code security-alert (Jun 05)

security curmudgeon

Re: AS/400 Vulnerabilities security curmudgeon (Jun 14)

suzanne . hawley

Advisory: Xerox Workaround & planned patch suzanne . hawley (Jun 03)

Sylvain

RSS-aggregator Multiple vulnerabilities Sylvain (Jun 30)
PHPEasyData 1.5.4 Multiple Vulnerabilities Sylvain (Jun 11)

sys-project

ComicShout 2.8 (news.php news_id) SQL Injection Vulnerability sys-project (Jun 02)
E-SMART CART (productsofcat.asp) Remote SQL Injection Vulnerability sys-project (Jun 16)
BP Blog 6.0 (id) Remote Blind SQL Injection Vulnerability sys-project (Jun 02)
PHP JOBWEBSITE PRO (JobSearch3.php) SQL Injection Vulnerability sys-project (Jun 16)
ASPPortal Free Version (Topic_Id) Remote SQL Injection Vulnerability sys-project (Jun 12)

tan_prathan

WEBAlbum <= 2.0 Remote Stored Cross Site Scripting Vulnerability tan_prathan (Jun 05)
SMEweb 1.4b (SQL/XSS) Multiple Remote Vulnerabilities tan_prathan (Jun 05)
The Rat CMS (SQL/XSS) Multiple Remote Vulnerabilities tan_prathan (Jun 26)
Benja CMS 0.1 (Upload/XSS) Multiple Remote Vulnerabilities tan_prathan (Jun 23)

the_3dit0r

WellyBlog Open Source Blog Portal Cross Site Scripting Vulnerabilitiy the_3dit0r (Jun 26)

The Dark Tangent

DEFCON 16 Updates - Get involved! The Dark Tangent (Jun 03)

Thijs Kinkhorst

[SECURITY] [DSA 1598-1] New libtk-img packages fix arbitrary code execution Thijs Kinkhorst (Jun 20)
[SECURITY] [DSA 1595-1] New xorg-server packages fix several vulnerabilities Thijs Kinkhorst (Jun 12)
[SECURITY] [DSA 1596-1] New typo3 packages fix several vulnerabilities Thijs Kinkhorst (Jun 12)
[SECURITY] [DSA 1553-2] New ikiwiki packages fix regression Thijs Kinkhorst (Jun 02)
[SECURITY] [DSA 1591-1] New libvorbis packages fix several vulnerabilities Thijs Kinkhorst (Jun 03)

Thor (Hammer of God)

RE: A more detailed description of the Jura F90 vulnerability. Thor (Hammer of God) (Jun 19)
RE: A more detailed description of the Jura F90 vulnerability. Thor (Hammer of God) (Jun 18)
RE: Windows Installer msiexec GUID Buffer Overflow Thor (Hammer of God) (Jun 03)

Tobias Heinlein

[ GLSA 200806-01 ] mtr: Stack-based buffer overflow Tobias Heinlein (Jun 03)
[ GLSA 200806-03 ] Imlib 2: User-assisted execution of arbitrary code Tobias Heinlein (Jun 09)
[ GLSA 200806-02 ] libxslt: Execution of arbitrary code Tobias Heinlein (Jun 03)
[ GLSA 200806-11 ] IBM JDK/JRE: Multiple vulnerabilities Tobias Heinlein (Jun 25)

unohope

[web-app] ErfurtWiki <= R1.02b (css) Local File Inclusion Vulnerability unohope (Jun 10)
[web-app] Tornado Knowledge Retrieval System <= 4.2 Remote XSS Vulnerability unohope (Jun 10)
[web-app] DCFM Blog 0.9.4 (comments) Remote SQL Injection Vulnerability unohope (Jun 10)
[web-app] Insanely Simple Blog 0.5 (index) Remote SQL Injection Vulnerabilities unohope (Jun 10)
[web-app] yBlog 0.2.2.2 Multiple Remote Vulnerabilities unohope (Jun 10)

Vladimir '3APA3A' Dubrovin

Re: IdeBox (include) Remote File Inclusion Vulnerability Vladimir '3APA3A' Dubrovin (Jun 25)

VMware Security team

VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security team (Jun 04)

William A. Rowe, Jr.

Further Correction to BID 29112 "Apache Server HTML Injection and UTF-7 XSS Vulnerability" William A. Rowe, Jr. (Jun 09)

Williams, James K

CA ARCserve Backup Discovery Service Denial of Service Vulnerability Williams, James K (Jun 18)
CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities Williams, James K (Jun 05)

yago jesus

New Release of 'Unhide' (20080519) yago jesus (Jun 27)

zdi-disclosures

ZDI-08-035: CA ETrust Secure Content Manager Gateway FTP PASV Stack Overflow Vulnerability zdi-disclosures (Jun 04)
ZDI-08-040: Microsoft DirectX SAMI File Format Name Parsing Stack Overflow Vulnerability zdi-disclosures (Jun 10)
ZDI-08-039: Microsoft Internet Explorer DOM Ojbect substringData() Heap Overflow Vulnerability zdi-disclosures (Jun 10)
ZDI-08-034: HP StorageWorks Storage Mirroring Authentication Processing Stack Overflow Vulnerability zdi-disclosures (Jun 04)
ZDI-08-037: Apple QuickTime Indeo Video Buffer Overflow Vulnerability zdi-disclosures (Jun 10)
ZDI-08-036: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow zdi-disclosures (Jun 04)
ZDI-08-038: QuickTime SMIL qtnext Redirect File Execution zdi-disclosures (Jun 10)