oss-sec: by date

402 messages starting Jul 01 08 and ending Sep 30 08
Date index | Thread index | Author index


Tuesday, 01 July

Re: CVE id request mercurial:Insufficient input validation Nico Golde
Re: openldap DoS Josh Bressers
Re: openldap DoS Steven M. Christey
Re: Two remote DoS issues in linuxdcpp Steven M. Christey
Re: CVE Request (pidgin) Steven M. Christey
Re: CVE id request: checkinstall Steven M. Christey
Re: CVE request: php 5.2.6 ext/imap buffer overflows Steven M. Christey
Re: CVE request for dnsmasq DoS Steven M. Christey
Re: Two remote DoS issues in linuxdcpp Robert Buchholz
Re: openldap DoS Ludwig Nussel

Wednesday, 02 July

More ruby integer overflows (rb_ary_fill / Array#fill) Tomas Hoger
Re: CVE request for dnsmasq DoS Nico Golde
Re: CVE request: phpmyadmin < 2.11.7 XSS Steven M. Christey

Thursday, 03 July

Re: Re: CVE Request (pidgin) Nico Golde
2.6.25.10 security fixes, please assign CVE id Marcus Meissner
Re: Re: CVE Request (pidgin) Josh Bressers
Re: CVE request for dnsmasq DoS Jamie Strandboge
Re: Re: CVE Request (pidgin) Vincent Danen
Re: Re: CVE Request (pidgin) Robert Buchholz
Re: Re: CVE Request (pidgin) Josh Bressers

Saturday, 05 July

Re: Re: CVE Request (pidgin) Nico Golde

Sunday, 06 July

CVE request: mybb Hanno Böck
CVE request: simple machines forum Hanno Böck
CVE request: moodle xss in < 1.8.5 Hanno Böck
Re: CVE request: moodle xss in < 1.8.5 Nico Golde

Monday, 07 July

Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jonathan Smith
Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jonathan Smith
[oCERT-2008-007] libpoppler uninitialized pointer Andrea Barisani
Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Bram Moolenaar

Tuesday, 08 July

Re: 2.6.25.10 security fixes, please assign CVE id Eugene Teo
Re: CVE request: moodle xss in < 1.8.5 Hanno Böck
CVE-2008-2931 kernel: missing check before setting mount propagation Eugene Teo
Re: CVE-2008-2931 kernel: missing check before setting mount propagation Eugene Teo
Re: CVE id request: Clamav Tomas Hoger
Re: Re: CVE Request (pidgin) Vincent Danen
Re: CVE request: moodle xss in < 1.8.5 Nico Golde
Re: CVE request for dnsmasq DoS Jamie Strandboge
Re: CVE request: mybb Steven M. Christey
Re: CVE request: simple machines forum Steven M. Christey
Re: CVE request: moodle xss in < 1.8.5 Steven M. Christey
Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Steven M. Christey
Re: 2.6.25.10 security fixes, please assign CVE id Steven M. Christey
Re: CVE request: moodle xss in < 1.8.5 Nico Golde
Major DNS vulnerability announced [CVE Question] security curmudgeon
Re: Major DNS vulnerability announced [CVE Question] Steven M. Christey
Re: Major DNS vulnerability announced [CVE Question] Jonathan Smith
Re: Major DNS vulnerability announced [CVE Question] The Fungi

Wednesday, 09 July

Re: Major DNS vulnerability announced [CVE Question] Matthias Andree
DNS vulnerability: other relevant software Matthias Geerdsen
Re: Major DNS vulnerability announced [CVE Question] Florian Weimer
Re: DNS vulnerability: other relevant software The Fungi
Re: DNS vulnerability: other relevant software Mark J Cox
CVE id request: projectl Nico Golde
CVE id request: libavformat Steffen Joeris
CVE request: PowerDNS recursor source port randomization Florian Weimer
Re: DNS vulnerability: other relevant software Robert Buchholz
Re: DNS vulnerability: other relevant software Florian Weimer
Re: DNS vulnerability: other relevant software Eugene Teo
Re: DNS vulnerability: other relevant software Eugene Teo
CVE request: multiple drupal issues in < 6.3,5.8 Hanno Böck
Re: DNS vulnerability: other relevant software Eugene Teo

Thursday, 10 July

Re: DNS vulnerability: other relevant software Eugene Teo
Re: DNS vulnerability: other relevant software Thomas Biege
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger
Re: DNS vulnerability: other relevant software Nathanael Hoyle

Friday, 11 July

Re: DNS vulnerability: other relevant software Bernhard R. Link
Re: DNS vulnerability: other relevant software Nathanael Hoyle
Re: CVE request: moodle xss in < 1.8.5 Nico Golde

Saturday, 12 July

CVE request: phpbb < 3.0.2 Hanno Böck
CVE requests: joomla <1.5.4 Hanno Böck
Re: CVE request for dnsmasq DoS Jamie Strandboge
CVE id request: op Nico Golde
Re: DNS vulnerability: other relevant software Florian Weimer
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jan Minář

Sunday, 13 July

Re: openldap DoS Nico Golde
CVE requests: crashers by zzuf Hanno Böck
Re: DNS vulnerability: other relevant software Florian Weimer

Monday, 14 July

Re: CVE-2008-2365 kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race -- affecting kernel versions <= 2.6.25 Marcus Meissner
CVE request: dotclear < 1.2.8 Hanno Böck

Tuesday, 15 July

Re: CVE id request: Clamav Tomas Hoger
Re: CVE Id request: vim Tomas Hoger
CVE id request: byacc Jan Lieskovsky
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger
CVE request: Wordpress XSS Hanno Böck
CVE request: phpmyadmin < 2.11.7.1 Hanno Böck

Wednesday, 16 July

Re: CVE request: phpmyadmin < 2.11.7.1 Thijs Kinkhorst
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jan Minář
Re: CVE request: phpmyadmin < 2.11.7.1 Hanno Böck
Re: CVE id request: libavformat Nico Golde
Re: CVE request: Wordpress XSS Tomas Hoger
Re: CVE request: Wordpress XSS Nico Golde
Re: CVE Request: Critical vuln in Firefox 3.0 Nico Golde
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jan Minář
Re: CVE id request: byacc Steven M. Christey
Re: CVE request: phpmyadmin < 2.11.7.1 Steven M. Christey
Re: CVE request: PowerDNS recursor source port randomization Florian Weimer

Thursday, 17 July

Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific) Michail Litvak

Friday, 18 July

Re: CVE id request: Clamav Steven M. Christey
Re: CVE id request: projectl Steven M. Christey
Re: CVE request: multiple drupal issues in < 6.3,5.8 Steven M. Christey
Re: CVE request: phpbb < 3.0.2 Steven M. Christey
Re: CVE requests: joomla <1.5.4 Steven M. Christey
Re: CVE id request: op Steven M. Christey

Sunday, 20 July

Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific) Jonathan Smith
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jonathan Smith
CVE request: punbb < 1.2.19 Hanno Böck
CVE request: mybb < 1.2.14 Hanno Böck
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger

Monday, 21 July

CVE request: mantis < 1.1.2 Tomas Hoger
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jan Minář
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Jan Minář

Wednesday, 23 July

Re: CVE request for dnsmasq DoS Josh Bressers
Re: CVE request for dnsmasq DoS Robert Buchholz
Re: CVE request for dnsmasq DoS Robert Buchholz

Friday, 25 July

CVE id request: moodle XSS and CSRF Ludwig Nussel
Re: CVE id request: moodle XSS and CSRF Steven M. Christey

Saturday, 26 July

CVE request: drupal issue in < 5.9 Miklos Vajna
Re: CVE request: drupal issue in < 5.9 Nico Golde
Re: CVE request: drupal issue in < 5.9 Miklos Vajna
Re: CVE request: drupal issue in < 5.9 Steven M. Christey

Sunday, 27 July

Re: CVE request: drupal issue in < 5.9 Nico Golde
CVE id request: horde3/turba2 Nico Golde
Re: CVE request: drupal issue in < 5.9 Miklos Vajna
cups patches for CVE-2008-0597 and CVE-2008-0596 Steffen Joeris
Re: CVE request: drupal issue in < 5.9 Nico Golde
Re: cups patches for CVE-2008-0597 and CVE-2008-0596 Robert Buchholz
Re: CVE request: drupal issue in < 5.9 Miklos Vajna
Links < 2.1 security issue Pierre-Yves Rofes
Re: Links < 2.1 security issue Steven M. Christey
Re: CVE id request: horde3/turba2 Steven M. Christey
Re: CVE request: mantis < 1.1.2 Steven M. Christey
Re: CVE request: mybb < 1.2.14 Steven M. Christey
Re: CVE request: punbb < 1.2.19 Steven M. Christey

Monday, 28 July

Re: cups patches for CVE-2008-0597 and CVE-2008-0596 Tomas Hoger
Re: CVE id request: horde3/turba2 Tomas Hoger
Re: CVE id request: horde3/turba2 Nico Golde
CVE request: phpmyadmin < 2.11.8 Hanno Böck
Re: Links < 2.1 security issue Nico Golde
Re: CVE id request: horde3/turba2 Steven M. Christey

Wednesday, 30 July

CVE request: condor < 7.0.4 Mark J Cox

Thursday, 31 July

Mono ASP.net cross site scripting issue Marcus Meissner
[oCERT-2008-009] libxslt heap overflow Andrea Barisani
OpenSC Security Advisory Andreas Jellinghaus
Re: Mono ASP.net cross site scripting issue Steven M. Christey
Re: CVE request: condor < 7.0.4 Steven M. Christey
CVE request: vtigercrm < 5.0.4 Hanno Böck
SVG vulnerability affecting Firefox, evince, eog, Gimp? Alexander Konovalenko
CVE request: phpwebgallery < 1.7.2 Hanno Böck
Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Steven M. Christey
Re: SVG vulnerability affecting Firefox, evince, eog, Gimp? Josh Bressers

Friday, 01 August

Re: CVE request: phpwebgallery < 1.7.2 Pierre-Yves Rofes

Saturday, 02 August

CVE request: Contenido < 4.8.7, < 4.6.24 Hanno Böck

Sunday, 03 August

CVE request: OpenVPN (client) 2.1-beta14 through 2.1-rc8 Tomas Hoger

Monday, 04 August

CVE request: httrack buffer overflow Thijs Kinkhorst
Re: CVE request: httrack buffer overflow Tomas Hoger
Re: CVE request: httrack buffer overflow Thijs Kinkhorst
Re: CVE request: httrack buffer overflow Steven M. Christey
source for CVE feed (was: Re: [oss-security] CVE request: httrack buffer overflow) Thijs Kinkhorst
Re: SVG vulnerability affecting Firefox, evince, eog, Gimp? Jan Lieskovsky
Re: source for CVE feed (was: Re: [oss-security] CVE request: httrack buffer overflow) Steven M. Christey
Re: source for CVE feed (was: Re: [oss-security] CVE request: httrack buffer overflow) Steven M. Christey
Re: CVE request: Contenido < 4.8.7, < 4.6.24 Steven M. Christey
Re: CVE request: phpmyadmin < 2.11.8 Steven M. Christey
Re: CVE request: OpenVPN (client) 2.1-beta14 through 2.1-rc8 Steven M. Christey
Re: CVE request: vtigercrm < 5.0.4 Steven M. Christey
CVE id request: openttd Nico Golde
Re: Re: source for CVE feed (was: Re: [oss-security] CVE request: httrack buffer overflow) Nico Golde
Re: CVE id request: openttd Robert Buchholz

Tuesday, 05 August

Re: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10 Tomas Hoger
CVE Request (pidgin) Josh Bressers
Re: CVE id request: openttd Nico Golde

Wednesday, 06 August

CVE-2008-2939 low severity Apache httpd XSS Mark J Cox

Thursday, 07 August

CVE id request: git Nico Golde
Re: CVE id request: git Tomas Hoger
Re: CVE Request (pidgin) Steven M. Christey
Re: CVE id request: git Steven M. Christey
Re: CVE id request: openttd Steven M. Christey

Friday, 08 August

Re: CVE request: phpmyadmin < 2.11.8 Nico Golde
CVE request: php-5.2.6 overflow issues Christian Hoffmann
Re: CVE request: php-5.2.6 overflow issues Joe Orton
Re: CVE request: php-5.2.6 overflow issues Christian Hoffmann
Re: CVE request: php-5.2.6 overflow issues Joe Orton

Monday, 11 August

CVE id requests: ruby Steffen Joeris
CVE Request (ipsec-tools) Josh Bressers
Multiple CVE Request (ruby) Jan Lieskovsky

Tuesday, 12 August

CVE request: tikiwiki < 2.0 Hanno Böck
CVE Request (ipsec-tools again) Josh Bressers
horde webmail edition < 1.1.1 Hanno Böck
Joomla 1.5.x core. Emanuele Gentili
Re: CVE request: phpmyadmin < 2.11.8 Steven M. Christey
Re: horde webmail edition < 1.1.1 Steven M. Christey
Re: CVE Request (ipsec-tools again) Steven M. Christey
Re: CVE Request (ipsec-tools) Steven M. Christey
Re: CVE id requests: ruby Steven M. Christey
Re: CVE request: tikiwiki < 2.0 Steven M. Christey
Re: CVE request: php-5.2.6 overflow issues Steven M. Christey

Wednesday, 13 August

Re: horde webmail edition < 1.1.1 Nico Golde
Re: Joomla 1.5.x core. Nico Golde
Re: CVE request: php-5.2.6 overflow issues Christian Hoffmann
Re: horde webmail edition < 1.1.1 Tomas Hoger
Re: horde webmail edition < 1.1.1 Nico Golde
Re: horde webmail edition < 1.1.1 Tomas Hoger
amarok temp file vuln Vincent Danen

Thursday, 14 August

CVE request: openfire login page XSS (JM-629) Robert Buchholz
HAVP 0.89 fixes a crash Raphael Marichez
Re: HAVP 0.89 fixes a crash Steven M. Christey
Re: CVE request: openfire login page XSS (JM-629) Steven M. Christey
Re: CVE id requests: ruby Steven M. Christey
Re: amarok temp file vuln Steven M. Christey
Re: horde webmail edition < 1.1.1 Steven M. Christey
Re: Joomla 1.5.x core. Steven M. Christey
CVE request: drupal 5.10/6.4 Hanno Böck

Friday, 15 August

CVE id request: mktemp Nico Golde
CVE-2008-3276 Linux kernel dccp_setsockopt_change() integer overflow Eugene Teo
CVE request for neon Joe Orton
Re: CVE id request: mktemp Todd C. Miller

Saturday, 16 August

Re: horde webmail edition < 1.1.1 Nico Golde

Monday, 18 August

Re: CVE id request: mktemp Sebastian Krahmer
Re: CVE id request: mktemp Nico Golde
Re: CVE id request: mktemp Todd C. Miller
Re: CVE id request: mktemp Nico Golde
Re: CVE id request: mktemp Todd C. Miller
Re: CVE id request: mktemp Steven M. Christey
Re: CVE id request: mktemp Nico Golde

Tuesday, 19 August

wordpress 2.6.1 Hanno Böck
swfdec 0.6.8 stable update Marcus Meissner
Re: swfdec 0.6.8 stable update Nico Golde

Wednesday, 20 August

Re: CVE request: drupal 5.10/6.4 Steven M. Christey
Re: CVE request for neon Steven M. Christey
Re: wordpress 2.6.1 Steven M. Christey
FW: CVE-2008-1668 - ftpd 2.4 - unauthorized root access - patch details Morris, John R. (SSRT)
Re: CVE request for neon Joe Orton

Friday, 22 August

[oCERT-2008-008] multiple heap overflows in xine-lib Will Drewry

Saturday, 23 August

Re: swfdec 0.6.8 stable update Marcus Meissner
Re: libxml2 denial of service flaw (CVE-2008-3281) Robert Buchholz
Re: swfdec 0.6.8 stable update Nico Golde
CVE id request: vlc Nico Golde

Sunday, 24 August

Re: CVE id request: vlc Pınar Yanardağ
Re: CVE id request: vlc Nico Golde
Re: Re: libxml2 denial of service flaw (CVE-2008-3281) Nico Golde
Re: Re: libxml2 denial of service flaw (CVE-2008-3281) Nico Golde
Re: CVE id request: vlc Pınar Yanardağ

Monday, 25 August

CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API Eugene Teo
Pardus Bugs / Patches, Was: Re: [oss-security] CVE id request: vlc Robert Buchholz
CVE Request (gpicview) Jan Lieskovsky
CVE Request (ruby) Jan Lieskovsky
Re: Re: libxml2 denial of service flaw (CVE-2008-3281) Vincent Danen
Re: Re: libxml2 denial of service flaw (CVE-2008-3281) Tomas Hoger
Re: Re: libxml2 denial of service flaw (CVE-2008-3281) Vincent Danen
Re: [vendor-sec] Re: [oss-security] Re: libxml2 denial of service flaw (CVE-2008-3281) Florian Weimer
Re: Pardus Bugs / Patches, Was: Re: [oss-security] CVE id request: vlc Pınar Yanardağ
Re: Re: [vendor-sec] Re: [oss-security] Re: libxml2 denial of service flaw (CVE-2008-3281) Vincent Danen

Tuesday, 26 August

Re: CVE Request (ruby) Pınar Yanardağ
CVE Request (samba) Jan Lieskovsky
Re: CVE Request (samba) Steven M. Christey
Re: CVE Request (ruby) Steven M. Christey
Re: CVE Request (gpicview) Steven M. Christey
Re: CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API Steven M. Christey
Re: CVE id request: vlc Steven M. Christey
Re: CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API Eugene Teo
CVE-2008-3526 Linux kernel sctp_setsockopt_auth_key() integer overflow Eugene Teo
Re: CVE Request (gpicview) Jan Lieskovsky

Wednesday, 27 August

opensc 0.11.6 with fixed security update Andreas Jellinghaus
CVE id request: awstats Nico Golde
Re: CVE id request: awstats Nico Golde
Re: CVE id request: awstats Steve Kemp
Re: CVE id request: awstats Nico Golde
CVE request: mono Sys.Web header injection Marcus Meissner

Thursday, 28 August

Re: CVE-2008-3526 Linux kernel sctp_setsockopt_auth_key() integer overflow Eugene Teo
CVE-2008-3525 kernel: missing capability checks in sbni_ioctl() Eugene Teo

Friday, 29 August

CVE request for bitlbee Miklos Vajna

Saturday, 30 August

Re: CVE Request (gpicview) Nico Golde

Sunday, 31 August

GNU ed heap overflow Florian Weimer
Re: CVE Request (gpicview) Jan Lieskovsky

Monday, 01 September

Re: GNU ed heap overflow Tavis Ormandy
Re: GNU ed heap overflow Florian Weimer
CVE id request: newsbeuter Nico Golde
[oCERT-2008-014] WordNet stack and heap overflows Rob Holland

Tuesday, 02 September

Re: CVE id request: newsbeuter Nico Golde
Re: CVE Request (gpicview) Robert Buchholz

Wednesday, 03 September

request for CVE: clamav 0.94 release Marcus Meissner
CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Jan Lieskovsky
django CSRF vuln Vincent Danen
CVE id request: dns2tcp Nico Golde
CVE request: kernel: dio: zero struct dio with kzalloc instead of manually Eugene Teo
CVE request: kernel: sunrpc: fix possible overrun on read of /proc/sys/sunrpc/transports Eugene Teo

Thursday, 04 September

Re: request for CVE: clamav 0.94 release Hanno Böck
CVE request: kernel: nfsd: fix buffer overrun decoding NFSv4 acl Eugene Teo
Re: OpenSSH key blacklisting Tim Brown
Re: CVE Request (gpicview) Nico Golde
Re: CVE Request (gpicview) Nico Golde
Re: CVE Request (gpicview) Steven M. Christey
Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Steven M. Christey
Re: CVE request: mono Sys.Web header injection Steven M. Christey
Re: CVE id request: newsbeuter Steven M. Christey
Re: [oCERT-2008-014] WordNet stack and heap overflows Steven M. Christey
Re: request for CVE: clamav 0.94 release Steven M. Christey
Re: django CSRF vuln Steven M. Christey
Re: CVE id request: dns2tcp Steven M. Christey
Re: CVE request: kernel: dio: zero struct dio with kzalloc instead of manually Steven M. Christey
Re: CVE request: kernel: sunrpc: fix possible overrun on read of /proc/sys/sunrpc/transports Steven M. Christey
Re: CVE request: kernel: nfsd: fix buffer overrun decoding NFSv4 acl Steven M. Christey
Re: CVE id request: newsbeuter Nico Golde
Re: CVE id request: newsbeuter Steven M. Christey
Re: GNU ed heap overflow Steven M. Christey
Re: GNU ed heap overflow Steven M. Christey
Re: CVE id request: newsbeuter Nico Golde
Re: GNU ed heap overflow Florian Weimer

Friday, 05 September

CVE request: kernel: local keyboard DoS through LED switching Eugene Teo
Re: opensc 0.11.6 with fixed security update Ludwig Nussel
CVE request: pam_mount: conf: re-add luserconf security checks Eugene Teo
CVE id requests: gmanedit Steffen Joeris

Saturday, 06 September

CVE request: pam_mount < 0.47 missing security checks Hanno Böck

Monday, 08 September

Re: CVE request for bitlbee Tomas Hoger

Tuesday, 09 September

CVE request: mybb < 1.4.1 Hanno Böck
cve request: punbb < 1.2.20 xss Hanno Böck
CVE request (libpng) Pınar Yanardağ
CVE request: MySQL empty bit-string literal server crash Robert Buchholz
ssmtp =2.62 unitialized memory disclosure Robert Buchholz
Re: ssmtp =2.62 unitialized memory disclosure Steven M. Christey
Re: CVE request: MySQL empty bit-string literal server crash Steven M. Christey
Re: CVE request (libpng) Steven M. Christey
Re: CVE request: mybb < 1.4.1 Steven M. Christey
Re: cve request: punbb < 1.2.20 xss Steven M. Christey
Re: CVE request for bitlbee Steven M. Christey
Re: CVE request: pam_mount < 0.47 missing security checks Steven M. Christey
Re: CVE id requests: gmanedit Steven M. Christey
Re: opensc 0.11.6 with fixed security update Steven M. Christey
Re: CVE request: kernel: local keyboard DoS through LED switching Steven M. Christey
Re: CVE request: kernel: local keyboard DoS through LED switching Eugene Teo
Re: CVE request: kernel: local keyboard DoS through LED switching Steven M. Christey
Re: CVE request: kernel: local keyboard DoS through LED switching Eugene Teo
Re: CVE id requests: gmanedit Nico Golde
Re: CVE request: MySQL incomplete fix for CVE-2008-2079 Tomas Hoger

Wednesday, 10 September

[oCERT-2008-012] Horde, Popoon frameworks common input sanitization errors (XSS) Will Drewry

Thursday, 11 September

Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Tomas Hoger
Re: ssmtp =2.62 unitialized memory disclosure Robert Buchholz
[oss-list] CVE request (vim) Jan Lieskovsky
Re: [oss-list] CVE request (vim) Pınar Yanardağ
CVE request: joomla < 1.5.7 Hanno Böck
CVE request: wordpress < 2.6.2 Hanno Böck
Re: [oss-list] CVE request (vim) Jan Minář
CVE request for Joomla multiple vuln. Emanuele Gentili

Saturday, 13 September

Re: CVE Request (gpicview) Robert Buchholz
CVE request: Ruby on Rails <2.1.1 :limit and :offset SQL injection Robert Buchholz

Monday, 15 September

CVE Request (python) Jan Lieskovsky
phpMyAdmin code execution (CVE request) Thijs Kinkhorst
Re: CVE request: Ruby on Rails <2.1.1 :limit and :offset SQL injection Steven M. Christey
Re: phpMyAdmin code execution (CVE request) Steven M. Christey
Re: CVE request: MySQL incomplete fix for CVE-2008-2079 Steven M. Christey
Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Steven M. Christey
Re: [oss-list] CVE request (vim) Steven M. Christey
Re: [oss-list] CVE request (vim) Steven M. Christey
Re: CVE request: joomla < 1.5.7 Steven M. Christey
Re: CVE request: wordpress < 2.6.2 Steven M. Christey
Re: CVE Request (python) Steven M. Christey

Tuesday, 16 September

CVE request: kernel: splice: fix bad unlock_page() in error case Eugene Teo

Wednesday, 17 September

CVE Request (mercurial) Josh Bressers
CVE-2008-3528 Linux kernel ext[234] directory corruption DoS Eugene Teo

Thursday, 18 September

CVE Request (openswan, emacspeak, cman) Jan Lieskovsky
CVE Request (gallery2) Josh Bressers
Re: CVE Request (gallery2) Hanno Böck

Friday, 19 September

CVE request: Opera < 9.52 multiple vulnerabilities Pierre-Yves Rofes
CVE request: pdnsd <1.2.7 Denial of Service Robert Buchholz
viewvc security flaw? Josh Bressers

Saturday, 20 September

Re: viewvc security flaw? Robert Buchholz

Monday, 22 September

CVE id request: proftpd Steffen Joeris
CVE req: phpmyadmin < 2.11.9.2 xss Hanno Böck

Tuesday, 23 September

CVE id request: fraud2 Steffen Joeris
Re: CVE Request (gallery2) Steven M. Christey
Re: CVE Request (openswan, emacspeak, cman) Steven M. Christey
Re: CVE request: pdnsd <1.2.7 Denial of Service Steven M. Christey
Re: CVE request: Opera < 9.52 multiple vulnerabilities Steven M. Christey

Wednesday, 24 September

CVE request: kernel: open() call allows setgid bit when user is not in new file's group Eugene Teo
Re: CVE id request: fraud2 Robert Buchholz
Re: CVE id request: fraud2 Steven M. Christey
Re: CVE request: kernel: open() call allows setgid bit when user is not in new file's group Steven M. Christey
CVE-2008-4113 update: kernel: sctp: fix random memory dereference with SCTP_HMAC_IDENT option Eugene Teo

Friday, 26 September

CVE id request: faad2 Steffen Joeris
Re: CVE id request: faad2 Josh Bressers
Re: CVE id request: faad2 Steffen Joeris
CVE-2008-4182 clarification Josh Bressers
CVE Request (lighttpd) Josh Bressers
Re: CVE-2008-4113 update: kernel: sctp: fix random memory dereference with SCTP_HMAC_IDENT option Steven M. Christey
Re: CVE-2008-4113 update: kernel: sctp: fix random memory dereference with SCTP_HMAC_IDENT option Eugene Teo
Re: CVE-2008-4113 update: kernel: sctp: fix random memory dereference with SCTP_HMAC_IDENT option Eugene Teo

Monday, 29 September

CVE id request: ftpd Steffen Joeris
Re: CVE id request: ftpd Robert Buchholz
Re: CVE Request (mercurial) Ludwig Nussel
Re: CVE-2008-4113 update: kernel: sctp: fix random memory dereference with SCTP_HMAC_IDENT option Eugene Teo
Re: CVE Request (mercurial) Robert Buchholz
Re: CVE Request (mercurial) Christian Hoffmann
[oCERT-2008-013] MPlayer Real demuxer heap overflow Andrea Barisani

Tuesday, 30 September

Re: CVE request: lighttpd issues Christian Hoffmann
Re: CVE request: lighttpd issues Christian Hoffmann
Re: Re: CVE request: lighttpd issues Steven M. Christey
Re: CVE id request: ftpd Steven M. Christey
Re: CVE id request: ftpd Josh Bressers
CVE Request (xen) Josh Bressers
Re: CVE id request: ftpd Steven M. Christey