Vulnwatch: by author

95 messages starting Feb 28 05 and ending Jan 10 05
Date index | Thread index | Author index


advisories

Corsaire Security Advisory - Mitel 3300 ICP web interface DoS issue advisories (Feb 28)
Corsaire Security Advisory - Mitel 3300 ICP web interface session hijacking issue advisories (Feb 28)

Andreas Sandblad

Secunia Research: Microsoft Internet Explorer "createControlRange()" Memory Corruption Andreas Sandblad (Feb 11)
Secunia Research: Yahoo! Messenger File Transfer Filename Spoofing Andreas Sandblad (Feb 19)
Secunia Research: Microsoft Internet Explorer Multiple Vulnerabilities Andreas Sandblad (Feb 11)

Carsten H. Eiram

Secunia Research: Yahoo! Messenger Audio Setup Wizard Privilege Escalation Carsten H. Eiram (Feb 19)

Cesar

- Argeniss - Oracle Database Server Directory transversal Cesar (Mar 07)
Windows Improper Token Validation -Exploit- Cesar (Jan 10)

CIRT.DK Mailinglists

CIRT.DK Advisory - SafeNet Inc Sentinel License Manager 7.2.0.2 Buffer Overflow CIRT.DK Mailinglists (Mar 07)

class 101

[HAT-SQUAD] SafeNet Sentinel LM, UDP License Manager Exploit class 101 (Mar 14)
[HAT-SQUAD] SafeNet Sentinel LM, UDP License Manager Exploit class 101 (Mar 13)
3com 3CDaemon FTP Unauthorized "USER" Remote BOverflow class 101 (Feb 19)
[HAT-SQUAD] BadBlue, Easy P2P File Sharing Remote Exploit class 101 (Feb 28)
VERITAS Backup Exec 8.x/9.x Remote Universal Exploit class 101 (Jan 11)
[HAT-SQUAD] Computer Associates Exploit class 101 (Mar 07)

CORE Security Technologies Advisories

CORE-2004-0819: MSN Messenger PNG Image Parsing Vulnerability CORE Security Technologies Advisories (Feb 08)

customer service mailbox

iDEFENSE Security Advisory 01.13.05 - Apple iTunes Playlist Parsing Buffer Overflow Vulnerability customer service mailbox (Jan 13)
iDEFENSE Security Advisory 01.18.05 - Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow customer service mailbox (Jan 19)
iDEFENSE Security Advisory 01.13.05: MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability customer service mailbox (Jan 14)
iDEFENSE Security Advisory 01.17.05: Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability customer service mailbox (Jan 17)
iDEFENSE Security Advisory 01.14.05: Exim dns_buld_reverse() Buffer Overflow Vulnerability customer service mailbox (Jan 14)
iDEFENSE Security Advisory [IDEF0731] Exim auth_spa_server() Buffer Overflow Vulnerability customer service mailbox (Jan 07)
iDEFENSE Security Advisory 01.13.05: SGI IRIX inpview Design Error Vulnerability customer service mailbox (Jan 14)

Dave Aitel

LLSSRV Redux Dave Aitel (Mar 17)
LLSSRV Clarifications [Immunity] Dave Aitel (Mar 16)
GREENAPPLE Release Dave Aitel (Feb 08)

Derek Soeder

EEYE: Windows ANI File Parsing Buffer Overflow Derek Soeder (Jan 11)

Florian Weimer

Robustness patch for TWiki, vulnerability in ImageGalleryPlugin Florian Weimer (Feb 23)

iDefense Customer Service

iDEFENSE Security Advisory 02.08.05: IBM AIX auditselect Local Format String Vulnerability iDefense Customer Service (Feb 08)
iDEFENSE Security Advisory 01.26.05: Openswan XAUTH/PAM Buffer Overflow Vulnerability iDefense Customer Service (Jan 26)
iDEFENSE Security Advisory 03.21.05: Mac OS X CF_CHARSET_PATH Buffer Overflow Vulnerability iDefense Customer Service (Mar 21)
iDEFENSE Security Advisory 01.20.05: 3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability iDefense Customer Service (Jan 20)
iDEFENSE Security Advisory 02.10.05: IBM AIX netpmon Local Buffer Overflow Vulnerability iDefense Customer Service (Feb 10)
iDEFENSE Security Advisory 02.10.05: Computer Associates BrightStor ARCserve Backup UniversalAgent Backdoor Vulnerability iDefense Customer Service (Feb 10)
iDEFENSE Security Advisory 02.10.05: IBM AIX ipl_varyon Local Buffer Overflow Vulnerability iDefense Customer Service (Feb 10)
iDEFENSE Security Advisory 02.09.05: CA BrightStor ARCserve Backup v11 Discovery Service Remote Buffer Overflow iDefense Customer Service (Feb 10)
iDEFENSE Security Advisory 02.10.05: IBM AIX lspath Local File Access Vulnerability iDefense Customer Service (Feb 10)
iDEFENSE Security Advisory 02.11.05: ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability iDefense Customer Service (Feb 11)
iDEFENSE Security Advisory 01.24.05: DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability iDefense Customer Service (Jan 24)
iDEFENSE Security Advisory 02.07.05: IBM AIX chdev Local Format String Vulnerability iDefense Customer Service (Feb 07)
iDEFENSE Security Advisory 02.07.05: SquirrelMail S/MIME Plugin Command Injection Vulnerability iDefense Customer Service (Feb 07)

Integrigy Security

Integrigy Security Advisory - High Risk Security Issues in the Oracle Database and Oracle Applications Integrigy Security (Jan 20)

Jakob Balle

Secunia Research: Mozilla / Mozilla Firefox Download Dialog Source Spoofing Jakob Balle (Jan 04)

Mark Litchfield

RealOne Player / Real .WAV Heap Overflow File Format Vulnerability Mark Litchfield (Mar 02)

Michael Sutton

iDEFENSE Security Advisory 01.19.05: MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities Michael Sutton (Jan 20)
iDEFENSE Security Advisory 03.01.05: RealNetworks RealPlayer .smil Buffer Overflow Vulnerability Michael Sutton (Mar 01)

Michal Zalewski

Linux ISO9660 handling flaws Michal Zalewski (Mar 18)

NGSSoftware Insight Security Research

IBM DB2 db2fmp buffer overflow (#NISR05012005A) NGSSoftware Insight Security Research (Jan 05)
IBM DB2 XML functions overflows (#NISR05012005H) NGSSoftware Insight Security Research (Jan 05)
MSN Heartbeat Control Buffer Overflow NGSSoftware Insight Security Research (Jan 19)
IBM DB2 SATADMIN.SATENCRYPT buffer overflow (#NISR05012005E) NGSSoftware Insight Security Research (Jan 05)
IBM DB2 JDBC Applet Server buffer overflow (#NISR05012005D) NGSSoftware Insight Security Research (Jan 05)
IBM DB2 XML functions file creation vulnerabilities (#NISR05012005I) NGSSoftware Insight Security Research (Jan 05)
Details of Sybase ASE bugs withheld NGSSoftware Insight Security Research (Mar 21)
Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a) NGSSoftware Insight Security Research (Jan 19)
RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f) NGSSoftware Insight Security Research (Jan 19)
IBM DB2 to_char and to_date Denial Of Service (#NISR05012005G) NGSSoftware Insight Security Research (Jan 05)
RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e) NGSSoftware Insight Security Research (Jan 19)
RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g) NGSSoftware Insight Security Research (Jan 20)
High Risk Vulnerabilities in Eudora Mail Client NGSSoftware Insight Security Research (Feb 02)
Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i NGSSoftware Insight Security Research (Jan 19)
Microsoft NetDDE Service Unauthenticated Remote Buffer Overflow NGSSoftware Insight Security Research (Jan 21)
IBM DB2 Windows Permission Problems (#NISR05012005F) NGSSoftware Insight Security Research (Jan 05)
Patch available for high risk IBM DB2 Universal Database flaw NGSSoftware Insight Security Research (Feb 09)
IBM DB2 libdb2.so buffer overflow (#NISR05012005B) NGSSoftware Insight Security Research (Jan 05)
Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c) NGSSoftware Insight Security Research (Jan 19)
IBM DB2 call buffer overflow (#NISR05012005C) NGSSoftware Insight Security Research (Jan 05)

nolimit bugtraq

Real Realplayer 10 .smil local buffer overflow POC nolimit bugtraq (Mar 07)
Bay Technical Associates telnet server logon bypass nolimit bugtraq (Mar 31)

NSFOCUS Security Team

NSFOCUS SA2005-01 : Buffer Overflow in WinAMP in_cdda.dll CDA Device Name NSFOCUS Security Team (Jan 27)

Paul Laudanski

Re: ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6 Paul Laudanski (Mar 27)

Paul Starzetz

Linux kernel sys_uselib local root vulnerability Paul Starzetz (Jan 07)
Linux kernel i386 SMP page fault handler privilege escalation Paul Starzetz (Jan 12)

Peter Kruse

Remote DoS in GFI MailEssentials due to a bug in Microsoft HTML parser Peter Kruse (Jan 03)

Rafel Ivgi

Finjan Security Advisory: Microsoft Office XP Remote Buffer Overflow Vulnerability Rafel Ivgi (Feb 08)

Rafel Ivgi, The-Insider

Kazaa Sig2Dat Protocol Remote Integer Overflow and Denial Of Service by creating files in arbitrary locations Rafel Ivgi, The-Insider (Jan 18)
WinAce & WinHKI - ZIP File Directory Transversal Rafel Ivgi, The-Insider (Jan 06)
WinHKI - ARC File Extraction of 1KB to 1.56GB Rafel Ivgi, The-Insider (Jan 06)
WinHKI - LHA File Incorrect Filename Handeling Leads to Crash/Underflow Rafel Ivgi, The-Insider (Jan 06)
WinHKI - BH File Directory Transversal Rafel Ivgi, The-Insider (Jan 06)
Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability Rafel Ivgi, The-Insider (Jan 18)
WinHKI - CAB File Directory Transversal Rafel Ivgi, The-Insider (Jan 06)
WinAce - GZIP File Directory Transversal Rafel Ivgi, The-Insider (Jan 06)

RUXCON Call for Papers

RUXCON 2005 Call for Papers RUXCON Call for Papers (Mar 22)

Shiva Persaud

Re: iDEFENSE Security Advisory 02.10.05: IBM AIX netpmon Local Buffer Overflow Vulnerability Shiva Persaud (Feb 10)
Re:iDEFENSE Security Advisory 02.10.05: IBM AIX ipl_varyon Local Buffer Overflow Vulnerability Shiva Persaud (Feb 10)
Re: iDEFENSE Security Advisory 02.08.05: IBM AIX auditselect Local Format String Vulnerability Shiva Persaud (Feb 08)
Re: iDEFENSE Security Advisory 02.10.05: IBM AIX lspath Local File Access Vulnerability Shiva Persaud (Feb 10)

Simple Nomad

Re: Details of Sybase ASE bugs withheld Simple Nomad (Mar 23)

Stefano Di Paola

Mysql CREATE FUNCTION mysql.func table arbitrary library injection Stefano Di Paola (Mar 10)
Mysql CREATE FUNCTION libc arbitrary code execution. Stefano Di Paola (Mar 10)
Mysql insecure temporary file creation with CREATE TEMPORARY TABLE privilege escalation Stefano Di Paola (Mar 10)

Sullo

Cyclades AlterPath Manager Vulnerabilities Sullo (Feb 24)

Team SHATTER (Application Security, Inc.)

[AppSecInc Team SHATTER Security Advisory] Microsoft Windows Improper Token Validation Team SHATTER (Application Security, Inc.) (Jan 10)
[AppSecInc Team SHATTER Security Advisory] Microsoft Windows LPC heap overflow Team SHATTER (Application Security, Inc.) (Jan 10)