SecurityFocus Bugtraq
By Subject
355 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]
Starting: 10/01/03
Ending: 10/31/03
- "Local" and "Remote" considered insufficient
- (Fw) : mIRC 6.12 (latest) DCC Exploit
- *ADDENDUM* New AIM Expliot/Worm/Adware-script (realphx.com related)
- @stake tool announcement: RedFang 2.5: The Bluetooth Hunter
- [ANNOUNCE] mod_security 1.7 released
- [CLA-2003:751] Conectiva Security Announcement - openssl
- [CLA-2003:757] Conectiva Security Announcement - vixie-cron
- [CLA-2003:758] Conectiva Security Announcement - vixie-cron
- [CLA-2003:760] Conectiva Security Announcement - mplayer
- [CLA-2003:762] Conectiva Security Announcement - glibc
- [CLA-2003:765] Conectiva Security Announcement - ircd
- [CLA-2003:766] Conectiva Security Announcement - gdm
- [CLA-2003:768] Conectiva Security Announcement - fileutils
- [CLA-2003:769] Conectiva Security Announcement - sane
- [CLA-2003:771] Conectiva Security Announcement - anonftp
- [CLA-2003:773] Conectiva Security Announcement - libnids
- [ESA-20031003-028] Potential OpenSSL DoS.
- [Full-Disclosure] [SECURITY] [DSA-393-1] New OpenSSL packages correct denial of service issues
- [LSD] Security vulnerability in SUN's Java Virtual Machine implementation
- [OpenPKG-SA-2003.045] OpenPKG Security Advisory (ircd)
- [OpenPKG-SA-2003.046] OpenPKG Security Advisory (apache)
- [OpenPKG-SA-2003.047] OpenPKG Security Advisory (postgresql)
- [PAPER] Juggling with packets: floating data storage
- [RHSA-2003:256-02] Updated Perl packages fix security issues.
- [RHSA-2003:278-01] Updated SANE packages fix remote vulnerabilities
- [RHSA-2003:281-01] Updated MySQL packages fix vulnerability
- [securemac] Local vulnerability: MacOSX Screensaver locking bypass.
- [SECURITY] [DSA 394-1] New openssl095 packages fix denial of service
- [SECURITY] [DSA 395-1] New tomcat4 packages fix denial of service
- [SECURITY] [DSA 396-1] New thttpd packages fix information leak, DoS and arbitrary code execution
- [SECURITY] [DSA-393-1] New OpenSSL packages correct denial of service issues
- [slackware-security] fetchmail security update (SSA:2003-300-02)
- [slackware-security] gdm security update (SSA:2003-300-01)
- [slackware-security] OpenSSL security update (SSA:2003-273-01)
- a dangerous fast spreading (yet simple) trojan horse (Now IRC.Trojan.Fgt)
- a dangerous fast spreading (yet simple) trojan horse.
- Access Runner DSL Console vulnerability update
- Adobe SVG Viewer Active Scripting Bypass (GM#002-MC)
- Adobe SVG Viewer Cross Domain and Zone Access (GM#004-MC)
- Adobe SVG Viewer Local and Remote File Reading (GM#003-MC)
- Advanced Poll : PHP Code Injection, File Include, Phpinfo
- Advisory: Sun's jre/jdk 1.4.2 multiple vulernabilities in linux installers
- Bad news on RPC DCOM vulnerability
- Betr.: IE 6 XML Patch Bypass
- buffer overflow in IRCD software
- Buffer Overflow in Yahoo messenger Client
- ByteHoard Directory Traversal Vulnerability
- Cafelog WordPress / b2 SQL injection vulnerabilities discovered and fixed in CVS
- CensorNet: Cross Site Scripting Vulnerability
- Cisco 6509 switch telnet vulnerability
- Cisco LEAP Insecurities + POC
- Cisco Security Advisory: SSL Implementation Vulnerabilities
- Class-action suit points to Microsoft security flaws
- Cobalt RaQ Control Panel Cross Site Scripting
- ColdFusion SQL Error Pages XSS
- Concern about Checkpoint and SSL Vulnerability
- Conexant Access Runner DSL Console login bypass vulnerability
- Console Root On OSX up to 10.2.8
- Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues
- Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue
- Cross Site Java applets
- Cross-Site Scripting Vulnerability in Wrensoft Zoom Search Engine
- CSS Vulnerability in Bajie HTTP JServer
- Dansie Shopping Cart Discloses Installation Path to Remote Users
- DCP Portal - 5.5 holes
- Dictionary attack against Cisco's LEAP, Wireless LANs vulnerable
- Divine OpenMarket Content Server XSS
- DoS in Plug and Play Web Server Proxy Server
- E107 DoS vulnerability
- EartStation 5 P2P application contains malicious code
- EMML, EMGB : Include() hole
- eMule 2.2 [0.29c] - Web Control Panel - DOS(Denial Of Service)
- exploiting fortigate firewall through webinterface
- Fastream NetFile FTP/WebServer 6.0 CSS Vulnerability
- Few issues previously unpublished in English
- Finjan Software Discovers a New Critical Vulnerability In Microsoft Hotmail
- FirstClass 7.1 HTTP Server: Remote Directory Listing
- Free OverflowGuard Personal Edition Released
- FreeBSD Security Advisory FreeBSD-SA-03:15.openssh
- FreeBSD Security Advisory FreeBSD-SA-03:16.filedesc
- FreeBSD Security Advisory FreeBSD-SA-03:17.procfs
- FreeBSD Security Advisory FreeBSD-SA-03:18.openssl
- Gaim festival plugin exploit
- Gallery 1.4 including file vulnerability
- Gast Arbeiter Privilege Escalation
- Geeklog exploit
- Get admin level on Goldlink script v3.0
- GLSA: apache (200310-04)
- GLSA: cfengine (200310-02)
- GLSA: openssl (200309-19)
- GuppY : XSS, Files Reading/Writing
- Half-Life 2 source code stolen through IE exploit
- HPUX dtprintinfo buffer overflow vulnerability
- HTML Help API - Privilege Escalation
- I have fixes for the Geeklog vulnerabilities
- IE 6 XML Patch Bypass
- IE bug: loading HTML under a graphic file name - summary
- IE remote code execution
- IE6 & Java 1.4.2_02 applet: Hardware stress on floppy drive
- IE6 CSS-Crash
- Immunix Secured OS 7+ apache update
- Immunix Secured OS 7+ fetchmail update
- Internet Explorer and Opera local zone restriction bypass
- IRM 008: Citrix Metaframe XP is vulnerable to Cross Site Scripting
- Is it safe yet?
- JAP Wins Court Victory
- Java 1.4.2_02 InsecurityManager JVM crash
- JBoss 3.2.1: Remote Command Injection
- JS/HTML code injection in File-Sharing for NET v1.5 and Forums Web Server v1.5
- Les Visiteurs v2.0.1 code injection vulnerability
- Libnids <= 1.17 buffer overflow
- LinkSys EtherFast Router Denial of Service Attack
- Listbox And Combobox Control Buffer Overflow
- Local root exploit in SuSE Linux 7.3Pro
- Local root exploit in SuSE Linux 8.2Pro
- Local root vuln in kpopup
- Local stackbased overflow found for silly Poker v0.25.5 (advisory + poc exploit)
- Mac OS X Arbitrary File Overwrite via Core Files
- Mac OS X Long argv[] buffer overflow
- Mac OS X Systemic Insecure File Permissions
- Mac OS X vulnerabilities
- Mac OS X vulnerabilities ['Virus checked"]
- Macos 10.2.8
- mah-jong[v1.4]: server/client remote buffer overflow exploit.
- MDKSA-2003:096-1 - Updated apache2 packages fix CGI scripting deadlock
- MDKSA-2003:097 - Updated mplayer packages fix buffer overflow vulnerability
- MDKSA-2003:098 - Updated openssl packages fix vulnerabilities
- MDKSA-2003:099 - Updated sane packages fix remote vulnerabilities
- MDKSA-2003:100 - Updated gdm packages fix local vulnerabilities
- MDKSA-2003:101 - Updated fetchmail packages fix DoS vulnerability
- Medieval Total War <= 1.1 broadcast Connection expired
- Medieval Total War <= 1.1 broadcast crash
- Microsoft got it wrong
- Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)
- Microsoft Windows Security Bulletin Summary October
- Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability
- Mimail.C
- Minihttpserver File-Sharing for NET Directory Traversal Vulnerability
- mod_security 1.7RC1 to 1.7.1 vulnerability
- MOSDEF Initial Release
- MS03-046 Microsoft Exchange 2000 Heap Overflow
- Multiple Heap Overflows in FTP Desktop
- Multiple SQL Injection Vulnerabilities in DeskPRO
- Multiple Vulnerabilities in Led-Forums
- Multiple vulnerabilities in WinShadow
- Musicqueue multiple local vulnerabilities
- myPHPCalendar : Informations Disclosure, File Include
- Nachi/Welchia/LovSan.D version 2 appears to be spreading
- NetBSD Security Advisory 2003-015: Remote and local vulnerabilities in XFree86 font libraries
- NetBSD Security Advisory 2003-016: Sendmail - another prescan() bug CAN-2003-0694
- NetBSD Security Advisory 2003-017: OpenSSL multiple vulnerabilities
- New AIM Expliot/Worm/Adware-script (realphx.com related)
- New FAQ on worm/worm containment
- New IE crash: CSS + HTML
- New OpenSSL remote vulnerability (issue date 2003/10/02)
- New Tool: MetaCoretex (DB Security Scanner)
- New Vulnerability
- Norton Internet Security 2003 XSS
- Norton Internet Security Blocked Sites XSS
- OpenLinux: wu-ftpd fb_realpath() off-by-one bug
- Openoffice 1.1.0 DoS
- OpenServer 5.0.5 : Insecure creation of files in /tmp
- OpenServer 5.0.7 : OpenSSH: multiple buffer handling problems
- OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Multiple security vulnerabilities in Xsco
- OpenSSL
- OpenSSL - revised url
- Opera HREF escaped server name overflow
- Origo ASR-8100 ADSL router remote factory reset
- patch for vulnerability in cgiemail
- PeopleSoft <Control><J> Information Disclosure
- PeopleSoft <LONGCHAR >and <VARCHAR> Data Upload
- PeopleSoft Grid Option Vulnerability
- PHP-Nuke Path Disclosure Vulnerability
- PHP-Nuke SQL Injection
- PHP-Nuke v 6.7 + Windows = File Upload
- PINE-CERT-20030901: Integer Overflow in FreeBSD Kernel [fhold]
- PINE-CERT-20030902: Integer Overflow in FreeBSD Kernel [uio]
- possible issue with IPv4 mapped address and $REMOTE_ADDR in CGI
- Process Killing - Playing with PostThreadMessage
- Proof of concept for Windows Messenger Service overflow
- ptl-2003-01: IBM DB2 LOAD Command Stack Overflow Vulnerability
- ptl-2003-02: IBM DB2 INVOKE Command Stack Overflow Vulnerability
- Redirection and refresh parses local file
- Remote overflow in thttpd
- Remote root exploit for proftpd \n bug
- Root Directory Listing on RH default apache
- SA-20031006 slocate buffer overflow - exploitation proof
- SA-20031006 slocate vulnerability
- Serious Sam is not so serious
- SGI Advanced Linux Environment security update #2
- SGI Advanced Linux Environment security update #3
- SGI Advanced Linux Environment security update #4
- sh-httpd `wildcard character' vulnerability
- Shatter XP
- Shattering By Example
- SiteKiosk terminal software
- SNAP Innovation's PrimeBase Database 4.2 poor default file permissions.
- Some serious security holes in 'The Bat!'
- SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version
- SSGbook (ASP)
- STG Security Advisory: [SSA-20031025-05] InfronTech WebTide 7.04 Directory and File Disclosure Vulnerability
- SuSE Security Announcement: lsh (SuSE-SA:2003:041)
- SuSE Security Announcement: mysql (SuSE-SA:2003:042)
- SuSE Security Announcement: openssl (SuSE-SA:2003:043)
- SUSE Security Announcement: thttpd (SuSE-SA:2003:044)
- TelCondex SimpleWebserver Buffer Overflow
- The joys of impurity (was: MOSDEF, InlineEgg)
- Tool Release: Xprobe2 0.2
- TRACKtheCLICK Script Injection Vulnerabilities
- TSLSA-2003-0001 - openssl
- TSLSA-2003-0003 - openssl
- UK's Internet Infrastructure Open to Prying Eyes
- UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : OpenSSL Multiple Vulnerabilities
- Unpatched Internet Explorer Bugs
- Update JBoss 308 & 321: Remote Command Injection
- Verisign fighting back at ICANN
- Virginity Security Advisory 2003-002 : Tritanium Bulletin Board - Read and write from/to internal (protected) Threads
- Visualroute Server - reverse tracerouting
- VMware GSX Server and ESX Server OpenSSL vulnerability patches
- VMWare GSX Server Authentication Server Buffer Overflow Vulnerability - Update
- Vulnerabilities in Easy File Sharing Web Server (1.2 NEW).
- Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting Attack (Microsoft Security Bulletin MS03-047)
- Weaknesses in LEAP Challenge/Response
- Web Wiz Forums ver. 7.01
- Webmails + Internet Explorer can create unwanted javascript execution
- What software breaks because of this DNS feature?
- Wildcard exportfs issue in NFS on IRIX
- WU-FTPD 2.6.2 Freezer
- XLS Attack on AES (Rijndael)
- ZH2003-28SA (security advisory): file inclusion vulnerability in PayPal Store Front
- ZH2003-31SA (security advisory): file inclusion vulnerability in cpCommerce
- ZH2003-3SP (security patch): multiple vulnerabilities in mod_gzip 1.3.x debug mode
Last message date: 10/31/03
Archived on: 10/31/03 CET
355 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]