Bugtraq: by date

126 messages starting Jun 03 13 and ending Jun 29 13
Date index | Thread index | Author index


Monday, 03 June

[ MDVSA-2013:171 ] gnutls security
[SECURITY] [DSA 2699-1] iceweasel security update Moritz Muehlenhoff
[SECURITY] [DSA 2700-1] wireshark security update Moritz Muehlenhoff
[SECURITY] [DSA 2701-1] krb5 security update Michael Gilbert
Vulnerable Microsoft VC++ 2005 RTM runtime libraries installed with "Microsoft Security Essentials" (and numerous other Microsoft products) Stefan Kanthak
CVE-2013-3662 - Sketchup MAC Pict Material Palette Stack Corruption Felipe Manzano
CVE-2013-3663 - SketchUp BMP RLE8 Heap Overflow Felipe Manzano
CVE-2013-3664 - Sketchup Multiple Vulnerabilities Felipe Manzano
Unauthenticated command execution on Netgear DGN devices roberto
Imperva SecureSphere Operations Manager version 9.0.0.5 - Multiple issues Pedro Andujar
DS3 Authentication Server - Multiple Issues Pedro Andujar
Open-Xchange Security Advisory 2013-06-03 Martin Braun
[ISecAuditors Security Advisories] Multiple Vulnerabilities in Telaen <= 1.3.0 ISecAuditors Security Advisories

Tuesday, 04 June

CVE-2013-3724 Monkey HTTPD 1.1.1 - Denial of Service Vulnerability dougtko
CVE-2013-3843 Monkey HTTPD 1.2.0 - Buffer Overflow DoS Vulnerability With Possible Arbitrary Code Execution dougtko
[SECURITY] [DSA 2702-1] telepathy-gabble security update Salvatore Bonaccorso
Re: Monkey HTTPD 1.1.1 - Denial of Service Vulnerability dougtko

Wednesday, 05 June

[security bulletin] HPSBMU02883 SSRT101227 rev.1 - HP Data Protector, Remote Increase of Privilege, Denial of Service (DoS), Execution of Arbitrary Code security-alert
[CORE-2013-0103] Mac OSX Server DirectoryService buffer overflow CORE Security Technologies Advisories

Thursday, 06 June

CVE-2013-3734 - JBoss AS Administration Console - Password Returned in Later Response amroot
[ANN] Struts 2.3.14.3 GA (fast-track) release available Lukasz Lenart
SEC Consult SA-20130605-0 :: Multiple vulnerabilities in CTERA Portal SEC Consult Vulnerability Lab
CORE-2013-0517 - Xpient Cash Drawer Operation Vulnerability CORE Security Technologies Advisories
APPLE-SA-2013-06-04-2 Safari 6.0.5 Apple Product Security
APPLE-SA-2013-06-04-1 OS X Mountain Lion v10.8.4 and Security Update 2013-002 Apple Product Security

Monday, 10 June

Re: [#1298868584] Copy&paste from web browser considered dangerous Google Security
DEFCON London - DC4420 - June CFP - Lightning talks!!! - Tuesday 25th June 2013 Major Malfunction

Tuesday, 11 June

WordPress 3.5.1, Denial of Service Krzysztof Katowicz-Kowalewski
Re: Netgear FVG318 is vunerable to DOS attack No
Re: Re: Netgear FVG318 is vunerable to DOS attack no
Fail2ban 0.8.9, Denial of Service (Apache rules only) Krzysztof Katowicz-Kowalewski
Bluetooth Chat Connect v1.0 iOS - Multiple Vulnerabilities Vulnerability Lab
[SECURITY] [DSA 2703-1] subversion security update Salvatore Bonaccorso
[SECURITY] [DSA 2704-1] mesa security update Raphael Geissert
CVE-2013-3739 Local File Inclusion in Weathermap <= 0.97C Anthony Dubuissez
[SECURITY] [DSA 2705-1] pymongo security update Giuseppe Iuculano
[SECURITY] [DSA 2706-1] chromium-browser security update Giuseppe Iuculano
[slackware-security] php (SSA:2013-161-01) Slackware Security Team
CFP: IEEE SafeConfig: 6th Symposium on Security Analytics and Automation James Joshi
[security bulletin] HPSBHF02885 rev.1 - HP Integrated Lights-Out iLO3 and iLO4 using Single-Sign-On (SSO), Remote Unauthorized Access security-alert
t2'13: Call for Papers 2013 (Helsinki / Finland) Tomi Tuominen
Re: WordPress 3.5.1, Denial of Service Peter Bex

Wednesday, 12 June

[security bulletin] HPSBMU02884 rev.1 - HP Service Manager and HP ServiceCenter, Cross Site Scripting (XSS) and Disclosure of Information security-alert
CORE-2013-0430 - Buffer overflow in Ubiquiti airCam RTSP service CORE Security Technologies Advisories
Re: WordPress 3.5.1, Denial of Service Solar Designer
SQL Injection in Dolphin advisory
[ MDVSA-2013:172 ] wireshark security

Thursday, 13 June

Slideware of recent presentations about IPv6 security Fernando Gont
[SECURITY] [DSA 2707-1] dbus security update Yves-Alexis Perez
[ MDVSA-2013:173 ] subversion security
LSE Leading Security Experts GmbH - LSE-2013-06-13 - Avira AntiVir Engine LSE Leading Security Experts GmbH (Security Advisories)
Re: WordPress 3.5.1, Denial of Service Henri Salo

Monday, 17 June

[security bulletin] HPSBHF02885 rev.2 - HP Integrated Lights-Out iLO3 and iLO4 using Single-Sign-On (SSO), Remote Unauthorized Access security-alert

Tuesday, 18 June

CVE-2013-2153: Apache Santuario C++ signature bypass vulnerability Cantor, Scott
CVE-2013-2155: Apache Santuario C++ denial of service vulnerability Cantor, Scott
CVE-2013-2154: Apache Santuario C++ stack overflow vulnerability Cantor, Scott
Re: CVE-2013-2156: Apache Santuario C++ heap overflow vulnerability Cantor, Scott
FreeBSD Security Advisory FreeBSD-SA-13:06.mmap FreeBSD Security Advisories
[SECURITY] [DSA 2710-1] xml-security-c security update Salvatore Bonaccorso
Apple and Wifi Hotspot Credentials Management Vulnerability Jeffrey Walton
Re: Apple and Wifi Hotspot Credentials Management Vulnerability Jeffrey Walton
APPLE-SA-2013-06-18-1 Java for OS X 2013-004 and Mac OS X v10.6 Update 16 Apple Product Security
[SECURITY] [DSA 2698-1] tiff security update Michael Gilbert
[SECURITY] [DSA 2628-2] nss-pam-ldapd update Moritz Muehlenhoff

Wednesday, 19 June

ESA-2013-045: RSA BSAFE® SSL-C Security Update for SSL/TLS Plaintext Recovery (aka “Lucky Thirteen”) Vulnerability Security Alert
ESA-2013-039: RSA BSAFE® SSL-J Multiple Vulnerabilities Security Alert
ESA-2013-032 RSA BSAFE® Micro Edition Suite Security Update for SSL/TLS Plaintext Recovery (aka “Lucky Thirteen”) Vulnerability Security Alert
Remote code execution in Puppet andreas . lindqvist
Facebook critical design flaw jjshoe
Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software Cisco Systems Product Security Incident Response Team
[SECURITY] [DSA 2711-1] haproxy security update Moritz Muehlenhoff
[CVE-2013-0523] IBM WebSphere Commerce: Encrypted URL Parameter Vulnerable to Padding Oracle Attacks VSR Advisories
Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Hunger

Thursday, 20 June

Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Emiel Kollof
Joomla crypto vulnerability (all versions) Marco Beierer
[SECURITY] [DSA 2712-1] otrs2 security update Florian Weimer
Android ICS "adb restore" directory traversal vulnerability (resending after bounce) Ariel Berkman
[security bulletin] HPSBUX02876 SSRT101148 rev.2 - HP-UX Running BIND, Remote Denial of Service (DoS) security-alert

Friday, 21 June

DC4420 - London DEFCON - June meet - Lightning Talks!!! - Tuesday 25th June 2013 Tony Naggs

Sunday, 23 June

FreeBSD Security Advisory FreeBSD-SA-13:06.mmap [REVISED] FreeBSD Security Advisories
Facebook Information Disclosure Packet Storm
ASUS RT-N66U Router - HTTPS Directory traversal and full file access and credential disclosure vuln kyle Lovett
GreHack 2013 - CFP ends on June, 30 - Conf: Nov. 15, Grenoble, France F. Duchene

Monday, 24 June

Linksys X3000 - Multiple Vulnerabilities devnull
[slackware-security] curl (SSA:2013-174-01) Slackware Security Team
CFP: IEEE SafeConfig: 6th Symposium on Security Analytics and Automation (Deadline Extended) James Joshi
[ MDVSA-2013:176 ] kernel security
[security bulletin] HPSBHF02878 rev.1 - HP Smart Zero Client, Unauthorized Access security-alert
Re: Facebook Information Disclosure Jeffrey Walton
[SECURITY] [DSA 2713-1] curl security update Salvatore Bonaccorso

Tuesday, 25 June

Re: Facebook Information Disclosure terry white
SEC Consult SA-20130625-0 :: Multiple vulnerabilities in IceWarp Mail Server SEC Consult Vulnerability Lab
Barnraiser Prairie OpenID idp: Directory traversal attack prairie
[ MDVSA-2013:177 ] dbus security
[ MDVSA-2013:178 ] nfs-utils security

Wednesday, 26 June

[Full-disclosure] Magnolia CMS multiple access control vulnerabilities Adrian Furtuna
[SECURITY] [DSA 2714-1] kfreebsd-9 security update Moritz Muehlenhoff
Multiple XSS Vulnerabilities in Xaraya advisory
[SECURITY] [DSA 2716-1] iceweasel security update Moritz Muehlenhoff
Security focus, we need your help Adnan Ahmad
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Email Security Appliance Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Web Security Appliance Cisco Systems Product Security Incident Response Team
[ MDVSA-2013:179 ] firefox security

Thursday, 27 June

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Content Security Management Appliance Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco ASA Next-Generation Firewall Fragmented Traffic Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team
[SECURITY] [DSA 2715-1] puppet security update Raphael Geissert
[security bulletin] HPSBST02890 rev.1 - HP StoreOnce D2D Backup System, Unauthorized Remote Access and Modification security-alert
[security bulletin] HPSBUX02886 rev.1 - HP-UX Running HP Secure Shell, Remote Denial of Service (DoS) security-alert
CVE-2013-2210 Cantor, Scott
[ MDVSA-2013:180 ] curl security
[ MDVSA-2013:181 ] mesa security
[ MDVSA-2013:182 ] mesa security
[ MDVSA-2013:183 ] java-1.7.0-openjdk security
[ MDVSA-2013:184 ] perl-Dancer security
[ MDVSA-2013:185 ] perl-Module-Signature security
Re: Re: EMC Avamar: World writable cache files security_alert
eFile Wifi Transfer Manager 1.0 iOS - Multiple Vulnerabilities Vulnerability Lab

Friday, 28 June

Mobile USB Drive HD 1.2 - Arbitrary File Upload Vulnerability Vulnerability Lab
Barracuda CudaTel 2.6.02.04 - Multiple Web Vulnerabilities Vulnerability Lab
Barracuda CudaTel 2.6.02.04 - Persistent Web Vulnerability Vulnerability Lab
[slackware-security] ruby (SSA:2013-178-01) Slackware Security Team
Re: Barracuda CudaTel 2.6.02.04 - Persistent Web Vulnerability Henri Salo
[ MDVSA-2013:186 ] puppet security
Re: EMC Avamar: World writable cache files security_alert

Saturday, 29 June

[SECURITY] [DSA 2717-1] xml-security-c security update Salvatore Bonaccorso
Wordpress wp-private-messages Plugin Sql Injection vulnerability iedb . team