Bugtraq: by author

263 messages starting Jul 21 09 and ending Jul 21 09
Date index | Thread index | Author index


admin

Re: Re: [Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking admin (Jul 21)

advisories

Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome advisories (Jul 16)

Akamai Security Team

Akamai Technologies Security Advisory 2009-0001 (Download Manager) Akamai Security Team (Jul 22)

Akita Software Security

PulseAudio local race condition privilege escalation vulnerability Akita Software Security (Jul 17)

alberto . morenot

HTC / Windows Mobile OBEX FTP Service Directory Traversal alberto . morenot (Jul 10)

Alexander Sotirov

Pwnie Awards 2009 Alexander Sotirov (Jul 09)

Alex Legler

[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code Alex Legler (Jul 02)
[ GLSA 200907-12 ] ISC DHCP: dhcpclient Remote execution of arbitrary code Alex Legler (Jul 14)
[ GLSA 200907-03 ] APR Utility Library: Multiple vulnerabilities Alex Legler (Jul 06)
[ GLSA 200907-02 ] ModSecurity: Denial of Service Alex Legler (Jul 02)
[ GLSA 200907-04 ] Apache: Multiple vulnerabilities Alex Legler (Jul 13)

Andrea Barisani

[oCERT-2009-010] mimeTeX and mathTeX buffer overflows and command injection Andrea Barisani (Jul 14)
[oCERT-2009-007] FCKeditor input sanitization errors Andrea Barisani (Jul 03)
[oCERT-2009-009] CamlImages integer overflows Andrea Barisani (Jul 02)
[oCERT-2009-011] Android improper camera and audio permission verification Andrea Barisani (Jul 16)
[oCERT-2009-012] libtiff tools integer overflows Andrea Barisani (Jul 13)
[oCERT-2009-008] Dillo integer overflow Andrea Barisani (Jul 06)

Andrea Purificato - bunker

Stored XSS on Communigate Pro 5.2.14 and prior versions Andrea Purificato - bunker (Jul 23)

Andrew Farmer

Re: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Andrew Farmer (Jul 22)

Andrew Mcphee

Pre-Beta Invite , New (Free) Anti-Virus Software Andrew Mcphee (Jul 29)

ascii

PHP filesystem attack vectors - Take Two ascii (Jul 27)

Bernardo Damele A. G.

[Tool] sqlmap 0.7 released Bernardo Damele A. G. (Jul 27)

Bernhard Mueller

SEC Consult SA-20090707-0 :: Symbian S60 / Nokia firmware media codecs multiple memory corruption vulnerabilities Bernhard Mueller (Jul 07)
Pwning Nokia phones (and other Symbian based smartphones) Bernhard Mueller (Jul 06)

biko linux

cross site scripting the browser google "chrome" biko linux (Jul 27)

bill . carovano

Re: Citrix XenCenterWeb Multiple Vulnerabilities bill . carovano (Jul 29)

Bkis

[Bkis-10-2009] Photo DVD Maker Professional Buffer Overflow Vulnerability Bkis (Jul 06)

c3rb3r

Sourcefire 3D Sensor and DC, privilege escalation vulnerability c3rb3r (Jul 02)

cevans

Re: [Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking cevans (Jul 17)

cfp

CFP - Security Byte / OWASP Asia 2009 cfp (Jul 07)

Choon Ming

computer crime statistics Choon Ming (Jul 27)

chris . boergermann

Re: Re: Back door trojan in acajoom-3.2.6 for joomla chris . boergermann (Jul 23)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers Cisco Systems Product Security Incident Response Team (Jul 27)
Cisco Security Advisory: Active Template Library (ATL) Vulnerability Cisco Systems Product Security Incident Response Team (Jul 28)
Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities Cisco Systems Product Security Incident Response Team (Jul 29)
Cisco Security Advisory: Vulnerabilities in Unified Contact Center Express Administration Pages Cisco Systems Product Security Incident Response Team (Jul 15)

Claudio Criscione

Citrix XenCenterWeb Multiple Vulnerabilities Claudio Criscione (Jul 07)

CORE Security Technologies Advisories

CORE-2009-0707: Firebird SQL op_connect_request main listener shutdown vulnerability CORE Security Technologies Advisories (Jul 28)
CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information Core Security Technologies Advisories (Jul 08)
CORE-2009-0227: Real Helix DNA RTSP and SETUP request handler vulnerabilities CORE Security Technologies Advisories (Jul 20)

crashfr

Phorum : Permanent Cross-Site Scripting Vulnerabilities crashfr (Jul 22)

Cru3l.b0y

wordpress plugins WP Super Cache v0.8.3 Remote File Inclusion Vulnerability Cru3l.b0y (Jul 23)
wordpress plugins wp-Table v1.52 Remote File Inclusion Vulnerability Cru3l.b0y (Jul 30)
Ocean CMS 0.0.2 Remote File Inclusion Vulnerability Cru3l.b0y (Jul 23)
LifeType 1.2.8 Remote File Inclusion Vulnerability Cru3l.b0y (Jul 23)

dann frazier

[SECURITY] [DSA 1845-1] New Linux 2.6.26 packages fix several vulnerabilities dann frazier (Jul 29)
[SECURITY] [DSA 1844-1] New Linux 2.6.24 packages fix several vulnerabilities dann frazier (Jul 29)
[SECURITY] [DSA 1846-1] New kvm packages fix denial of service dann frazier (Jul 29)

ddivulnalert

DDIVRT-2009-26 LogRover SQL Injection Authentication Bypass ddivulnalert (Jul 13)

Dennis Yurichev

Oracle CPUjul2009 Dennis Yurichev (Jul 24)

domingos . bruges

Atlantic SimpleCaddy Shopping Cart Price Manipulation domingos . bruges (Jul 10)

DSecRG

[DSECRG-09-031] Oracle BEA Weblogic 10.3 Linked ХSS vulnerability DSecRG (Jul 16)
[DSECRG-09-025] Oracle Secure Enterprise Search 10.1.8 Linked XSS vulnerability DSecRG (Jul 16)

dvlabs

TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability dvlabs (Jul 14)

Ferruh Mavituna

One Click Ownage [White Paper and Scripts] Ferruh Mavituna (Jul 03)

filip . palian

Multiple Flaws in Axesstel MV 410R filip . palian (Jul 02)

Filip Palian

Virtualmin Multiple Vulnerabilities Filip Palian (Jul 14)

Florian Weimer

[SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution Florian Weimer (Jul 14)
[SECURITY] [DSA 1838-1] New pulseaudio packages fix privilege escalation Florian Weimer (Jul 20)
[SECURITY] [DSA 1847-1] New bind9 packages fix denial of service Florian Weimer (Jul 29)

Francesco Laurita

Re: wordpress plugins wp-Table v1.52 Remote File Inclusion Vulnerability Francesco Laurita (Jul 30)

FreeBSD Security Advisories

FreeBSD Security Advisory FreeBSD-SA-09:12.bind FreeBSD Security Advisories (Jul 29)

g30rg3_x

Re: wordpress plugins WP Super Cache v0.8.3 Remote File Inclusion Vulnerability g30rg3_x (Jul 23)

GulfTech Security Research

Re: LifeType 1.2.8 Remote File Inclusion Vulnerability GulfTech Security Research (Jul 23)

gursev . kalra

Mobile Rediff Username and Password Disclosure gursev . kalra (Jul 15)
mChek 3.4 Information Disclosure gursev . kalra (Jul 21)

hadikiamarsi

Remote File Inclusion in aiocp hadikiamarsi (Jul 27)

iDefense Labs

iDefense Security Advisory 07.15.09: Microsoft Embedded OpenType Font Engine (T2EMBED.DLL) Heap Buffer Overflow Vulnerability iDefense Labs (Jul 15)
iDefense Security Advisory 07.15.09: Microsoft Office Publisher 2007 Arbitrary Pointer Dereference Vulnerability iDefense Labs (Jul 15)

Inferno

Hacking CSRF Tokens using CSS History Hack Inferno (Jul 20)

info

Admin News Tools 2.5 Remote File Download Vulnerability info (Jul 15)

infocus

[INFIGO-2009-07-09]: NASA Common Data Format remote buffer overflow(s) infocus (Jul 21)

irancrash

COMRaider Idefense Labs CreateFolder() and Copy() Insecure Method (Hard Disk Filler Exploit) irancrash (Jul 17)

ISecAuditors Security Advisories

[ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple Full Path Disclosure vulnerabilities ISecAuditors Security Advisories (Jul 24)
[ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking ISecAuditors Security Advisories (Jul 17)
[ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple XSS vulnerabilities in HTTP Headers ISecAuditors Security Advisories (Jul 02)

Jamie Strandboge

[USN-803-1] dhcp vulnerability Jamie Strandboge (Jul 14)
[USN-798-1] Firefox and Xulrunner vulnerabilities Jamie Strandboge (Jul 22)
[USN-800-1] irssi vulnerability Jamie Strandboge (Jul 13)

Jan van Niekerk

Re: Back door trojan in acajoom-3.2.6 for joomla Jan van Niekerk (Jul 08)

Jeffrey Walton

Re: Re: Back door trojan in acajoom-3.2.6 for joomla Jeffrey Walton (Jul 23)

Jeremiah Gowdy

RE: DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome Jeremiah Gowdy (Jul 21)

Jeremy Brown

Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit Jeremy Brown (Jul 21)

Jerome Athias

FRHACK List of Talks and Speakers released Jerome Athias (Jul 16)

jplopezy

URL spoofing bug involving Firefox's error pages and document.write jplopezy (Jul 24)

Karn Ganeshen

Fwd: cross site scripting the browser google "chrome" Karn Ganeshen (Jul 28)

Kees Cook

[USN-808-1] Bind vulnerability Kees Cook (Jul 29)
[USN-804-1] PulseAudio vulnerability Kees Cook (Jul 16)

Kingcope

Re: NcFTPd <= 2.8.5 remote jail breakout Kingcope (Jul 27)
NcFTPd <= 2.8.5 remote jail breakout Kingcope (Jul 27)
Re: THISISNOTMYEXPLOIT Kingcope (Jul 30)
Re: THISISNOTMYEXPLOIT Kingcope (Jul 30)
MySQL <= 5.0.45 post auth format string vulnerability Kingcope (Jul 09)

Kirchner Michael

Artofdefence Hyperguard Web Application Firewall: Remote Denial of Service Kirchner Michael (Jul 01)
radware AppWall Web Application Firewall: Source code disclosure on management interface Kirchner Michael (Jul 01)
phion airlock Web Application Firewall: Remote Denial of Service via Management Interface (unauthenticated) and Command Execution Kirchner Michael (Jul 01)

linuxrootkit2008

eAccelerator encoder files backup Vulnerability linuxrootkit2008 (Jul 02)

Lists

XOOPS Multiple Cross-Site Scripting Vulnerabilities - Security Advisory - SOS-09-005 Lists (Jul 31)

Liu Die Yu

Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome Liu Die Yu (Jul 06)

Lostmon lords

Fwd: Google Chrome About:blank Spoof Lostmon lords (Jul 28)

Maggi Federico

EC2ND 2009 CFP - 5th European Conference on Computer Network Defence Maggi Federico (Jul 30)

Marc Deslauriers

[USN-802-1] Apache vulnerabilities Marc Deslauriers (Jul 13)
[USN-801-1] tiff vulnerability Marc Deslauriers (Jul 13)
[USN-797-1] tiff vulnerability Marc Deslauriers (Jul 06)
[USN-796-1] Pidgin vulnerability Marc Deslauriers (Jul 06)
[USN-806-1] Python vulnerabilities Marc Deslauriers (Jul 23)
[USN-799-1] D-Bus vulnerability Marc Deslauriers (Jul 13)
[USN-794-1] Perl vulnerability Marc Deslauriers (Jul 02)
[USN-805-1] Ruby vulnerabilities Marc Deslauriers (Jul 20)
[USN-795-1] Nagios vulnerability Marc Deslauriers (Jul 02)

Maty Siman

RE: Decompilation Injection Maty Siman (Jul 07)

McDonnell, Michael

RE: computer crime statistics McDonnell, Michael (Jul 27)

Michael Theroux

RE: computer crime statistics Michael Theroux (Jul 28)

Michael Wood

Re: URL spoofing bug involving Firefox's error pages and document.write Michael Wood (Jul 27)

Michal Zalewski

Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome Michal Zalewski (Jul 15)
Re: Re[6]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Michal Zalewski (Jul 22)
Re: Re[2]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Michal Zalewski (Jul 21)
Re: Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Michal Zalewski (Jul 22)
Re: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Michal Zalewski (Jul 21)
Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome Michal Zalewski (Jul 03)

Moritz Muehlenhoff

[SECURITY] [DSA 1842-1] New openexr packages fix several vulnerabilities Moritz Muehlenhoff (Jul 28)
[SECURITY] [DSA 1835-1] New tiff packages fix several vulnerabilities Moritz Muehlenhoff (Jul 15)
[SECURITY] [DSA 1836-1] New fckeditor packages fix arbitrary code execution Moritz Muehlenhoff (Jul 16)

MustLive

Re: DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome MustLive (Jul 21)
Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome MustLive (Jul 15)
Re: DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome MustLive (Jul 27)
Re: wordpress plugins WP Super Cache v0.8.3 Remote File Inclusion Vulnerability MustLive (Jul 23)
Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome MustLive (Jul 27)
Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... MustLive (Jul 20)
DoS vulnerabilities in Internet Explorer MustLive (Jul 27)
Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome MustLive (Jul 28)
DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome MustLive (Jul 20)
Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome MustLive (Jul 03)

Neil Dickey

Re: Update: [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG) Neil Dickey (Jul 13)

Nick Boyce

Re: Update: [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG) Nick Boyce (Jul 14)
Re: Re[2]: Update: [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG) Nick Boyce (Jul 15)

Nico Golde

[SECURITY] [DSA 1828-1] New ocsinventory-agent packages fix arbitrary code execution Nico Golde (Jul 07)
[SECURITY] [DSA 1841-1] New git-core packages fix denial of service Nico Golde (Jul 27)
[SECURITY] [DSA 1843-1] New squid3 packages fix denial of service Nico Golde (Jul 28)
[SECURITY] [DSA 1825-1] New nagios2/nagios3 packages fix arbitrary code execution Nico Golde (Jul 03)

noreply-secresearch () fortinet com

FortiGuard Advisory: Microsoft Office Web Components Remote Memory Corruption Vulnerability noreply-secresearch () fortinet com (Jul 14)

nospam

EPSON Status Monitor 3 local privilege escalation vulnerability nospam (Jul 30)
Adobe related service (getPlus_HelperSvc.exe) local elevation of privileges nospam (Jul 20)

Paul Petersen

RE: computer crime statistics Paul Petersen (Jul 28)

Praburaajan

REMINDER : HITBSecConf2009 - Malaysia: Call for Papers Praburaajan (Jul 01)

Rajendra Prasad . Palnaty

Need information, for MPlayer demux_open_vqf TwinVQ File Handling Buffer Overflow CVE-2008-5616 Rajendra Prasad . Palnaty (Jul 22)

R Dicaire

Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... R Dicaire (Jul 15)

RISE Security

[RISE-2009002] Linux eCryptfs parse_tag_11_packet Literal Data Buffer Overflow Vulnerability RISE Security (Jul 28)
[RISE-2009003] Linux eCryptfs parse_tag_3_packet Encrypted Key Buffer Overflow Vulnerability RISE Security (Jul 28)

Robert Buchholz

[ GLSA 200907-15 ] Nagios: Execution of arbitrary code Robert Buchholz (Jul 20)
[ GLSA 200907-06 ] Adobe Reader: User-assisted execution of arbitrary code Robert Buchholz (Jul 13)
[ GLSA 200907-13 ] PulseAudio: Local privilege escalation Robert Buchholz (Jul 16)
[ GLSA 200907-11 ] GStreamer plug-ins: User-assisted execution of arbitrary code Robert Buchholz (Jul 13)
[ GLSA 200907-08 ] Multiple Ralink wireless drivers: Execution of arbitrary code Robert Buchholz (Jul 13)
[ GLSA 200907-07 ] ModPlug: User-assisted execution of arbitrary code Robert Buchholz (Jul 13)
[ GLSA 200907-05 ] git: git-daemon Denial of Service Robert Buchholz (Jul 13)
[ GLSA 200907-16 ] Python: Integer overflows Robert Buchholz (Jul 20)
[ GLSA 200907-09 ] Cyrus-SASL: Execution of arbitrary code Robert Buchholz (Jul 13)
[ GLSA 200907-14 ] Rasterbar libtorrent: Directory traversal Robert Buchholz (Jul 17)
[ GLSA 200907-10 ] Syslog-ng: Chroot escape Robert Buchholz (Jul 13)

rPath Update Announcements

rPSA-2009-0111-1 kernel rPath Update Announcements (Jul 27)
rPSA-2009-0113-1 bind bind-utils rPath Update Announcements (Jul 30)

Satan_hackers

Avax Vector ActiveX 1.3 (avPreview.ocx) Denial of Service Exploit Satan_hackers (Jul 06)

Scotty

Re: computer crime statistics Scotty (Jul 28)

secfocus2

Re: Asante FM2008 10/100 Ethernet switch backdoor login secfocus2 (Jul 24)

Secunia Research

Secunia Research: Novell eDirectory iMonitor "Accept-Language" Buffer Overflow Secunia Research (Jul 14)

security

[ MDVSA-2009:182 ] firefox security (Jul 31)
[ MDVSA-2009:155 ] git security (Jul 20)
[ MDVSA-2009:165 ] ghostscript security (Jul 28)
[ MDVSA-2009:163 ] tomcat5 security (Jul 28)
[ MDVSA-2009:178 ] squid security (Jul 29)
[ MDVSA-2009:167 ] php security (Jul 28)
[ MDVSA-2009:173 ] pidgin security (Jul 29)
[ MDVSA-2009:169 ] libtiff security (Jul 29)
[ MDVSA-2009:175 ] pango security (Jul 29)
[ MDVSA-2009:172 ] dhcp security (Jul 29)
[ MDVSA-2009:161 ] squid security (Jul 28)
[ MDVSA-2009:152 ] pulseaudio security (Jul 17)
[ MDVSA-2009:184 ] apache-mod_security security (Jul 31)
[ MDVSA-2009:168 ] apache security (Jul 28)
[ MDVSA-2009:160 ] ruby security (Jul 28)
[ MDVSA-2009:149 ] apache security (Jul 09)
[ MDVSA-2009:150 ] libtiff security (Jul 13)
[ MDVSA-2009:159 ] mysql security (Jul 27)
[ MDVSA-2009:153 ] dhcp security (Jul 20)
[ MDVSA-2009:151 ] dhcp security (Jul 16)
[ MDVSA-2009:180 ] compface security (Jul 29)
[ MDVSA-2009:156 ] net-snmp security (Jul 20)
[ MDVSA-2009:171 ] pulseaudio security (Jul 29)
[ MDVSA-2009:179 ] mysql security (Jul 29)
[ MDVSA-2009:162 ] java-1.6.0-openjdk security (Jul 28)
[ MDVSA-2009:166 ] c-client security (Jul 28)
[ MDVSA-2009:181 ] bind security (Jul 29)
[ MDVSA-2009:174 ] perl-Compress-Raw-Zlib security (Jul 29)
[ MDVSA-2009:154 ] dhcp security (Jul 20)
[ MDVSA-2009:149 ] apache security (Jul 09)
Re: URL spoofing bug involving Firefox's error pages and document.write security (Jul 27)
[ MDVSA-2009:148 ] kernel security (Jul 07)
[ MDVSA-2009:177 ] ruby security (Jul 29)
[ MDVSA-2009:164 ] jasper security (Jul 28)
[ MDVSA-2009:176 ] git security (Jul 29)
[ MDVSA-2009:157 ] perl-Compress-Raw-Zlib security (Jul 20)
[ MDVSA-2009:183 ] apache-mod_security security (Jul 31)
[ MDVSA-2009:170 ] initscripts security (Jul 29)
[ MDVA-2009:158 ] pango security (Jul 24)
[ MDVSA-2009:124-1 ] apache security (Jul 08)

security-alert

[security bulletin] HPSBGN02446 SSRT090111 rev.1 - HP ProCurve Threat Management Services zl Module (J9155A), Remote Unauthorized Access, Denial of Service (DoS) security-alert (Jul 13)
[security bulletin] HPSBPI02398 SSRT080166 rev.4 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files security-alert (Jul 06)
[security bulletin] HPSBUX02437 SSRT090038 rev.1 - HP-UX Running XNTP, Remote Execution of Arbitrary Code security-alert (Jul 22)
[security bulletin] HPSBUX02421 SSRT090047 rev.1 - HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code security-alert (Jul 30)
[security bulletin] HPSBMA02438 SSRT090092 rev.1 - HP ProLiant DL/ML 100 Series G5/G6 Servers with ProLiant Onboard Administrator Powered by LO100i, Remote Denial of Service (DoS) security-alert (Jul 28)
[security bulletin] HPSBUX02440 SSRT090106 rev.1 - HP-UX Running NFS/ONCplus, Local Denial of Service (DoS) security-alert (Jul 02)
[security bulletin] HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code security-alert (Jul 02)

security curmudgeon

Re: PHP-Revista Multiple vulnerabilities security curmudgeon (Jul 20)

shuanglei

RainbowCrack 1.4 is released - The Time-Memory Tradeoff Hash Cracker shuanglei (Jul 22)

SmOk3

IXXO Cart! Standalone and Joomla Component SQL Injection SmOk3 (Jul 27)

Stefan Fritsch

[SECURITY] [DSA 1834-2] New apache/apache2-mpm-itk fix regression Stefan Fritsch (Jul 30)
[SECURITY] [DSA 1834-1] New apache2 packages fix denial of service Stefan Fritsch (Jul 15)

Stefan Kanthak

Vulnerable DLLs distributed with Terratec HomeCinema 6.3 Stefan Kanthak (Jul 16)

Steffen Joeris

[SECURITY] [DSA 1837-1] New dbus packages fix denial of service Steffen Joeris (Jul 20)
[SECURITY] [DSA 1839-1] New gst-plugins-good0.10 packages fix arbitrary code execution Steffen Joeris (Jul 20)
[SECURITY] [DSA 1826-1] New eggdrop packages fix several vulnerabilities Steffen Joeris (Jul 06)
[SECURITY] [DSA 1753-2] End-of-life announcement for icedove in oldstable Steffen Joeris (Jul 13)
[SECURITY] [DSA 1827-1] New ipplan packages fix cross-site scripting Steffen Joeris (Jul 06)
[SECURITY] [DSA 1829-2] New sork-passwd-h3 packages fix regression Steffen Joeris (Jul 14)
[SECURITY] [DSA 1829-1] New sork-passwd-h3 packages fix cross-site scripting Steffen Joeris (Jul 13)
[SECURITY] [DSA 1840-1] New xulrunner packages fix several vulnerabilities Steffen Joeris (Jul 23)
[SECURITY] [DSA 1830-1] New icedove packages fix several vulnerabilities Steffen Joeris (Jul 13)

Steven M. Christey

Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Steven M. Christey (Jul 21)
Re: Re[2]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Steven M. Christey (Jul 21)

SySS security advisories -- Christoph Bott

Cisco WLC 4402 Denial-of-Service vulnerability SySS security advisories -- Christoph Bott (Jul 27)

Thierry Zoller

Re[8]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 22)
Re[6]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 22)
Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... Thierry Zoller (Jul 21)
Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details) Thierry Zoller (Jul 15)
Re[2]: Update: [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG) Thierry Zoller (Jul 14)
Update: [TZO-27-2009] Firefox Denial of Service (Keygen) Thierry Zoller (Jul 09)
Re[2]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 22)
Re:[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... Thierry Zoller (Jul 15)
Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 21)
Re[2]: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... Thierry Zoller (Jul 16)
[GSEC-TZO-45-2009] iPhone remote code execution Thierry Zoller (Jul 23)
Re[2]: Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details) Thierry Zoller (Jul 16)
Re[2]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 21)
Update: [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG) Thierry Zoller (Jul 10)
[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... Thierry Zoller (Jul 15)
Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3.... Thierry Zoller (Jul 22)

Thijs Kinkhorst

[SECURITY] [DSA 1832-1] New camlimages packages fix arbitrary code execution Thijs Kinkhorst (Jul 13)
[SECURITY] [DSA 1831-1] New djbdns packages fix privilege escalation Thijs Kinkhorst (Jul 13)

Tim Brown

High security hole in NullLogic Groupware Tim Brown (Jul 06)
Medium security hole in TekRADIUS Tim Brown (Jul 06)

tixxDZ

[DZC-2009-001] The Movie Player and VLC Media Player Real Data Transport parsing integer underflow. tixxDZ (Jul 27)

Vicente Aguilera

Re: [Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking Vicente Aguilera (Jul 20)

Vladimir '3APA3A' Dubrovin

Re: XAMPP for Windows (Xss/PHPinfo) Multiple Vulnerability Vladimir '3APA3A' Dubrovin (Jul 02)
Re: Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details) Vladimir '3APA3A' Dubrovin (Jul 16)

VMware Security Team

VMSA-2009-0008 ESX Service Console update for krb5 VMware Security Team (Jul 01)
VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl VMware Security team (Jul 13)

xu shaopei

Re: URL spoofing bug involving Firefox's error pages and document.write xu shaopei (Jul 27)

y3nh4ck3r

MULTIPLE ARBITRARY INFORMATION DISCLOSURE AND EDITION --ILIAS LMS <= 3.10.7/3.9.9--> y3nh4ck3r (Jul 15)

YGN Ethical Hacker Group (http://yehg.net)

Re: wordpress plugins wp-Table v1.52 Remote File Inclusion Vulnerability YGN Ethical Hacker Group (http://yehg.net) (Jul 31)
Re: URL spoofing bug involving Firefox's error pages and document.write YGN Ethical Hacker Group (http://yehg.net) (Jul 27)

ZDI Disclosures

ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability ZDI Disclosures (Jul 14)
ZDI-09-046: Novell Privileged User Manager Remote DLL Injection Vulnerability ZDI Disclosures (Jul 21)