Vulnwatch: by date

127 messages starting Mar 31 03 and ending Jun 29 03
Date index | Thread index | Author index


Monday, 31 March

3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computer's ports during outbound and inbound TCP and UDP sessions Michael Puchol
iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player iDEFENSE Labs
serious vulnerability present. all doomed. over. Security Experts, Liability Limited
[SCSA-015] Remote Denial of Service Vulnerability in PowerFTP Gregory Le Bras | Security Corporation

Wednesday, 02 April

[INetCop Security Advisory] Remote Multiple Buffer Overflow vulnerability in passlogd sniffer. dong-h0un U

Thursday, 03 April

ChiTeX local root vulnerability zillion
SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow KF

Friday, 04 April

SRT2003-04-04-1106 - AOLServer Proxy Daemon API unformatted syslog() call KF

Saturday, 05 April

Abyss X1 1.1.2 remote crash Auriemma Luigi

Sunday, 06 April

PY-Membres 4.0 (PHP) Frog Man
Java Agent freezes Lotus Notes and Domino 6.0.1 (fwd) Marc Schoenefeld

Monday, 07 April

[DDI-1013] Buffer Overflow in Samba allows remote root compromise Erik Parker
Vignette Story Server sensitive information disclosure (a040703-1) @stake Advisories
Coppermine Photo Gallery remote compromise Berend-Jan Wever

Tuesday, 08 April

iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x iDEFENSE Labs

Wednesday, 09 April

Fw: Alert: Microsoft Security Bulletin - MS03-011 OC Hosting - Lance L
iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration (ISA) S iDEFENSE Labs

Thursday, 10 April

MacOS X DirectoryService Privilege Escalation (a041003-1) @stake Advisories
Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability Integrigy Security Alerts

Friday, 11 April

Buffer Overflow Vulnerability Found in MailMax Version 5 Dennis Rand
Re: Buffer Overflow Vulnerability Found in MailMax Version 5 Mark Litchfield
R7-0013: Heap Corruption in Gaim-Encryption Plugin Rapid 7 Security Advisories

Monday, 14 April

Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach Aviram Jenik

Tuesday, 15 April

[SCSA-016] Multiple vulnerabilities in Ez publish Gregory Le Bras | Security Corporation
CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability CORE Security Technologies Advisories
SRT2003-04-15-1029 - Progres BINPATHX overflow KF
SFAD03-001: iWeb Mini Web Server Remote Directory Traversal subversive

Wednesday, 16 April

Apache mod_access_referer denial of service issue zillion
[SCSA-017] Directory Traversal Vulnerability in EZ Server Gregory Le Bras | Security Corporation

Saturday, 19 April

Race in XP SCM Service Shutdown Mechanism Matthew Murphy

Sunday, 20 April

BadBlue Remote Administrative Access Vulnerability Matthew Murphy
Monkey HTTPd Remote Buffer Overflow Matthew Murphy

Monday, 21 April

Remote Vulnerabilties in mod_ntlm Matthew Murphy
PTNews v1.7.7 - Access to administrator functions without authentification scrap
AN HTTPd Sample Script File Truncation Matthew Murphy

Tuesday, 22 April

[NGSEC-2003-5] YABB SE, remote command execution labs
SRT2003-04-22-1336 - SAP DB Development Tools install flaw KF

Wednesday, 23 April

Secunia Research: Xeneo Web Server URL Encoding Denial of Service Carsten H. Eiram
Cisco Security Advisory: Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability Cisco Systems Product Security Incident Response Team
[SCSA-018] Disclosure of authentication information in Sambar Server Gregory LEBRAS
SQL injection in BttlxeForum SecurityTracker
NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS NSFOCUS Security Team

Thursday, 24 April

Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability Cisco Systems Product Security Incident Response Team
Internet Explorer Plugin.ocx heap overflow (#NISR24042003) NGSSoftware Insight Security Research
SRT2003-04-24-1532 - Options Parsing Tool library buffer overflows. KF

Friday, 25 April

True Galerie 1.0 : Admin Access & File Copy Frog Man

Saturday, 26 April

Buffer overflow in Internet Explorer's HTTP parsing code Jouko Pynnonen
3com NBX IP Phone Call manager Denial of Service - Update Michael Scheidell

Monday, 28 April

CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall CORE Security Technologies Advisories

Tuesday, 29 April

[INetCop Security Advisory] Qpopper v4.0.x poppassd local root exploit dong-h0un U
Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003) NGSSoftware Insight Security Research

Wednesday, 30 April

Cisco Security Advisory: Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service Cisco Systems Product Security Incident Response Team

Thursday, 01 May

Cisco Security Advisory: Cisco ONS15454, ONS15327, ONS15454SDH, and ONS15600 Nessus Vulnerabilities Cisco Systems Product Security Incident Response Team

Monday, 05 May

CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client CORE Security Technologies Advisories

Tuesday, 06 May

Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328) Dennis Rand
youbin local root exploit + advisory Knud Erik Højgaard

Wednesday, 07 May

Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A) NGSSoftware Insight Security Research
Multiple Vulnerabilities in SLWebmail NGSSoftware Insight Security Research
Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerabilities Cisco Systems Product Security Incident Response Team
Windows Media Player directory traversal vulnerability Jouko Pynnonen
Happymall E-Commerce Remote Command Execution SecurityTracker

Thursday, 08 May

Hotmail & Passport (.NET Accounts) Vulnerability Muhammad Faisal Rauf Danka
SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow KF

Friday, 09 May

Firebird local root compromise bob

Sunday, 11 May

Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0 Dennis Rand
Opera 7.11 java.util.zip.* Vulnerability (fwd) Marc Schoenefeld
eServ Memory Leak Enables Denial of Service Attacks Matthew Murphy

Monday, 12 May

Secunia Research: Opera browser filename extension buffer overflows Jakob Balle
Apple AirPort Administrative Password Obfuscation (a051203-1) @stake Advisories
Snitz Forum 3.3.03 Remote Command Execution sharpiemarker

Wednesday, 14 May

Vulnerability in ' poster version.two' Peter Winter-Smith
Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED Marek Bialoglowy

Thursday, 15 May

OneOrZero Security Problems (PHP) Frog Man
Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets Cisco Systems Product Security Incident Response Team

Saturday, 17 May

Buffer overflow vulnerability found in MailMax version 5 0x36
Algorithmic Complexity Attacks and the Linux Networking Code Florian Weimer

Tuesday, 20 May

Plaintext Password in Settings.ini of CesarFTP Andreas Constantinides
BadBlue Remote Administrative Interface Access Vulnerability mattmurphy () kc rr com
Linux 2.4 kernel ioperm vuln Rain Forest Puppy

Wednesday, 21 May

[INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability. dong-h0un U
[INetCop Security Advisory] Remote Heap Corruption Overflow vulnerability in WsMp3d. dong-h0un U

Thursday, 22 May

Linux 2.4 kernel ioperm vuln *is* for 2.4 Rain Forest Puppy
iDEFENSE Security Advisory 05.22.03: Authentication Bypass in iisPROTECT iDEFENSE Labs

Saturday, 24 May

P-News 1.16 Admin Access Vulnerability Peter Winter-Smith

Monday, 26 May

NII Advisory - Buffer Overflow in Analogx Proxy K. K. Mookhey
S21SEC-016-en - Vignette SSI Injection S21SEC
S21SEC-017-en - Vignette /vgn/legacy/save SQL access S21SEC
More S21sec Vignette advisories Rain Forest Puppy

Tuesday, 27 May

CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass CORE Security Technologies Advisories
Multiple Vulnerabilities in Sun-One Application Server SPI Labs
Re: CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass Kee Hinckley

Wednesday, 28 May

Internet Information Services 5.0 Denial of service SPI Labs
Webfroot Shoutbox 2.32 directory traversal and code injection. pokleyzz
SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm) scheidell
Geeklog 1.3.7sr1 and below multiple vulnerabilities. pokleyzz

Thursday, 29 May

b2 cafelog 0.6.1 remote command execution. pokleyzz

Friday, 30 May

NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability NSFOCUS Security Team
iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability iDEFENSE Labs

Saturday, 31 May

Windows Media Services Remote Command Execution Brett Moore

Friday, 06 June

Administrivia: Vulnwatch DNS issues affecting availability Rain Forest Puppy

Monday, 09 June

Nokia GGSN (IP650 Based) DoS @stake Advisories

Tuesday, 10 June

Administrivia - VulnWatch.Org still down Steve
Administrivia - Temporary fix for VulnWatch.org Steve

Friday, 13 June

SRT2003-06-12-0853 - ike-scan local root format string issue KF

Saturday, 14 June

SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue KF
SRT2003-06-13-0945 - Progress PATH based dlopen() issue KF
pMachine (PHP) : Include() Security Hole Frog Man

Sunday, 15 June

XSS Vulnerability in LedNews (CGI/Perl) v0.7 gilbert vilvoorde

Monday, 16 June

Multiple Vulnerabilities Found in Mailtraq (DoS, Password Decryption, Directory Traversal) SecurITeam BugTraq Monitoring
iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing Vulnerability iDEFENSE Labs

Tuesday, 17 June

Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE) GreyMagic Software
MIPSPro Compiler Predictable Temp File vulnerability SGI Security Coordinator
Ethereal < 0.9.13 vulns Rain Forest Puppy

Wednesday, 18 June

Black Hat 2003 Speaker Lineup; Phil Zimmermann to Keynote B.K. DeLong
R7-0014: RSA SecurID ACE Agent Cross Site Scripting vulnwatch-return-887-lists_vulnwatch=insecure.org

Thursday, 19 June

phpBB password disclosure by sql injection Rick

Friday, 20 June

SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow KF

Monday, 23 June

GNATS (The GNU bug-tracking system) multiple buffer overflow vulnerabilities. dong-h0un U
gid bin from /usr/ports/korean/elm (FreeBSD) Knud Erik Højgaard
[KSA-001] Multiple vulnerabilities in Tutos François SORIN

Tuesday, 24 June

Remote Buffer Overrun WebAdmin.exe Mark Litchfield
Multiple IPv6-Induced Bugs & Vulnerabilities on IRIX SGI Security Coordinator

Wednesday, 25 June

Windows Media Services Remote Command Execution #2 Brett Moore

Thursday, 26 June

Secunia Research: FTPServer/X Response Buffer Overflow Vulnerability Carsten H. Eiram
[KSA-002] Multiple Vulnerabilities In Moregroupware François SORIN

Sunday, 29 June

Admin Account Creation Vulnerability in CuteNews 1.x Peter Winter-Smith
Multiple vulnerabilities in paBox silentscripter