SecurityFocus Bugtraq
By Subject
392 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]
Starting: 04/01/04
Ending: 04/30/04
- "Delete anti-virus and firewall software" --Microsoft
- 3com NBX VOIP NetSet Denial of Service Attack
- [ GLSA 200404-01 ] Insecure sandbox temporary lockfile vulnerabilities in Portage
- [ GLSA 200404-02 ] KDE Personal Information Management Suite Remote Buffer Overflow Vulnerability
- [ GLSA 200404-03 ] Tcpdump Vulnerabilities in ISAKMP Parsing
- [ GLSA 200404-04 ] Multiple vulnerabilities in sysstat
- [ GLSA 200404-05 ] ipsec-tools contains an X.509 certificates vulnerability
- [ GLSA 200404-06 ] Util-linux login may leak sensitive data
- [ GLSA 200404-07 ] ClamAV RAR Archive Remote Denial Of Service Vulnerability
- [ GLSA 200404-08 ] GNU Automake symbolic link vulnerability
- [ GLSA 200404-09 ] Cross-realm trust vulnerability in Heimdal
- [ GLSA 200404-11 ] Multiple Vulnerabilities in pwlib
- [ GLSA 200404-12 ] Scorched 3D server chat box format string vulnerability
- [ GLSA 200404-14 ] Multiple format string vulnerabilities in cadaver
- [ GLSA 200404-15 ] XChat 2.0.x SOCKS5 Vulnerability
- [ GLSA 200404-16 ] Multiple new security vulnerabilities in monit
- [ GLSA 200404-17 ] ipsec-tools and iputils contain a remote DoS vulnerability
- [ GLSA 200404-18 ] Multiple Vulnerabilities in ssmtp
- [ GLSA 200404-19 ] Buffer overflows and format string
- [ GLSA 200404-20 ] Multiple vulnerabilities in xine
- [ GLSA 200404-21 ] Multiple Vulnerabilities in Samba
- [AppSec-research] New Worm/Virus April 8th
- [BUG-CORRECTION] IISShield "Server" header costumization
- [CLA-2004:834] Conectiva Security Announcement - openssl
- [CLA-2004:835] Conectiva Security Announcement - ethereal
- [CLA-2004:836] Conectiva Security Announcement - libxml2
- [CLA-2004:837] Conectiva Security Announcement - mod_python
- [CLA-2004:838] Conectiva Security Announcement - squid
- [cliph@isec.pl: Linux kernel setsockopt MCAST_MSFILTER integer overflow]
- [ESA-20040428-004] 'kernel' Several security and bug fixes
- [Full-Disclosure] EEYE: Symantec Multiple Firewall TCP Options Denial of Service
- [Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function Buffer Overflow Vulnerability
- [Full-Disclosure] iDEFENSE Security Advisory 04.15.04: RealNetworks Helix Universal Server Denial of Service Vulnerability
- [Full-Disclosure] Microsoft's Explorer and Internet Explorer long share name buffer overflow.
- [HOTFIX] setsockopt kernel vulnerability
- [OpenPKG-SA-2004.008] OpenPKG Security Advisory (squid)
- [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)
- [OpenPKG-SA-2004.010] OpenPKG Security Advisory (tcpdump)
- [OpenPKG-SA-2004.011] OpenPKG Security Advisory (sharutils)
- [OpenPKG-SA-2004.012] OpenPKG Security Advisory (fetchmail)
- [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)
- [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)
- [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)
- [OpenPKG-SA-2004.017] OpenPKG Security Advisory (png)
- [OpenPKG-SA-2004.018] OpenPKG Security Advisory (proftpd)
- [PNSA 2004-2] PostNuke Security Advisory PNSA 2004-2
- [product-security@apple.com: APPLE-SA-2004-04-05 Security Update 2004-04-05]]
- [RHSA-2004:159-01] Updated Subversion packages fix security vulnerability in neon
- [RHSA-2004:163-01] Updated OpenOffice packages fix security vulnerability in neon
- [RHSA-2004:166-01] Updated kernel packages resolve security vulnerabilities
- [RHSA-2004:173-00] Updated mc packages resolve several vulnerabilities
- [RHSA-2004:175-01] Updated utempter package fixes vulnerability
- [RHSA-2004:177-01] An updated X-Chat package fixes vulnerability in Socks-5 proxy
- [RHSA-2004:179-01] An updated LHA package fixes security vulnerabilities
- [RHSA-2004:181-01] Updated libpng packages fix crash
- [RHSA-2004:182-01] Updated httpd packages fix mod_ssl security issue
- [SCSA-028] Nuked-Klan Multiple Vulnerabilities
- [SECURITY] [DSA 431-2] New perl packages fix information leak in suidperl
- [SECURITY] [DSA 460-2] New sysstat packages fix insecure temporary file creation
- [SECURITY] [DSA 470-1] New Linux 2.4.17 packages fix several local root exploits (hppa)
- [SECURITY] [DSA 471-1] New interchange packages fix information leak
- [SECURITY] [DSA 472-1] New fte packages fix buffer overflows
- [SECURITY] [DSA 473-1] New oftpd packages fix denial of service
- [SECURITY] [DSA 474-1] New squid packages fix ACL bypass
- [SECURITY] [DSA 475-1] New Linux 2.4.18 packages fix several local root exploits (hppa)
- [SECURITY] [DSA 476-1] New heimdal packages fix cross-realm vulnerability
- [SECURITY] [DSA 477-1] New xine-ui packages fix insecure temporary file creation
- [SECURITY] [DSA 478-1] New tcpdump packages fix denial of service
- [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)
- [SECURITY] [DSA 486-1] New cvs packages fix multiple vulnerabilities
- [SECURITY] [DSA 487-1] New neon packages fix format string vulnerabilities
- [SECURITY] [DSA 488-1] New logcheck packages fix insecure temporary directory
- [SECURITY] [DSA 489-1] New Linux 2.4.17 packages fix local root exploit (mips+mipsel)
- [SECURITY] [DSA 490-1] New Zope packages fix arbitrary code execution
- [SECURITY] [DSA 491-1] New Linux 2.4.19 packages fix local root exploit (mips)
- [SECURITY] [DSA 492-1] New iproute packages fix denial of service
- [SECURITY] [DSA 493-1] New xchat packages fix arbitrary code execution
- [SECURITY] [DSA 495-1] New Linux 2.4.16 packages fix local root exploit (arm)
- [SECURITY] [DSA 496-1] New eterm packages fix indirect arbitrary command execution
- [SECURITY] [DSA 497-1] New mc packages fix several vulnerabilities
- [SECURITY] [DSA 498-1] New libpng packages fix denial of service
- [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]
- [slackware-security] cvs security update (SSA:2004-108-02)
- [slackware-security] kernel security updates (SSA:2004-119-01)
- [slackware-security] tcpdump denial of service (SSA:2004-108-01)
- [slackware-security] utempter security update (SSA:2004-110-01)
- [slackware-security] xine security update (SSA:2004-111-01)
- [Unpatched] 4 new Microsoft patches, 4 old updated, 24 vulnerabilities
- [waraxe-2004-SA#013 - Critical sql injection bug in PhpBB 2.0.8 and in older versions]
- [waraxe-2004-SA#014 - Cross-Site Scripting aka XSS in AzDGDatingLite]
- [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]
- [waraxe-2004-SA#016 - Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3]
- [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]
- [waraxe-2004-SA#018 - Admin-level authentication bypass in phpnuke 6.x-7.2]
- [waraxe-2004-SA#019 - Critical sql injection bug in Phorum 3.4.7]
- [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]
- [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2]
- [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6]
- [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector System 1.15b1 for PhpNuke]
- A technical description of the SSL PCT vulnerability (CVE-2003-0719)
- Adobe Acrobat Reader PDF file DoS vulnerability
- Advanced Guestbook 2.2 -- SQL Injection Exploit
- Advisory: Multiple Vulnerabilities in Monit
- After Ms patches last Wed ...
- after ms patches...
- ANNOUNCE: SecLegal mailing list
- Apache - all versions vulnerability in OLD procesors.
- Arbitrary file overwriting in Unreal engine through UMOD
- Automated wireless client penetration tool "hotspotter" released.
- Backdoor in X-Micro WLAN 11b Broadband Router
- BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)
- BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure
- blaxxun3D(blaxxun Platform) 7 - Remote Buffer Overflow
- Browser bugs [DoS] ... where will you draw a line?
- Bugfinder Being Indicted As Criminal ("Counterfeiter") in France
- Bugfinder Being Indicted As Criminal]
- CAN-2004-0155: The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections
- cdp buffer overflow vulnerability
- Cisco Security Advisory: A default Username and Password in WLSE and HSE devices
- Cisco Security Advisory: Cisco IPSec VPN Services Module Malformed IKE Packet Vulnerability
- Cisco Security Advisory: TCP Vulnerabilities in Multiple IOS Based Cisco Products
- Cisco Security Advisory: TCP Vulnerabilities in Multiple Non-IOS-Based Cisco Products
- Cisco Security Advisory: Vulnerabilities in SNMP Message Processing
- Cisco Security Notice: Cisco IPsec VPN Implementation Group Password Usage Vulnerability
- Citadel/UX 6.20 fixes local permissions vulnerability
- cqure.net.20040430.citrixmetaframe
- Cross Site Scripting in Moodle < 1.3
- Dameware Mini Remote Control Version 4.2 Weak Key Agreement Scheme
- DoS in Crackalaka 1.0.8
- DoS in NETFile FTP/Web Server
- DoS in Rsniff 1.0
- EEYE: Symantec Multiple Firewall TCP Options Denial of Service
- EEYE: Windows Expand-Down Data Segment Local Privilege Escalation
- EEYE: Windows Local Security Authority Service Remote Buffer Overflow
- EEYE: Yahoo! Mail Account Filter Overflow Hijack
- eMule <= 0.42d Remote Exploit
- eMule v0.42d Buffer Overflow
- Enterprise Application Security
- eSignal v7 remote buffer overflow
- Eudora 6.1 is evil
- Exchange pop3 remote exploit
- Followup: vuln in WinBlox monitor for winnt
- Format string bug in IGI 2: Covert Strike 1.3
- Format String in Cherokee
- Foundstone Labs Advisory: Citrix MetaFrame Password Manager 2.0
- FreeBSD Security Advisory FreeBSD-SA-04:07.cvs
- Full-Disclosure is now ILLEGAL in France ! (Vulnerabilties, Technical details, Exploits ...)
- Gnome nautilus bug
- GNU Sharutils buffer overflow vulnerability
- GNU Sharutils buffer overflow vulnerability.
- Google using Expired Cert and SSLv2
- Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache
- Horde webmail: mysql access
- HP Web Jetadmin
- HP Web JetAdmin vulnerabilities.
- IBM Director 3.1 Windows Agent Remote DoS
- Idea of CAW (Creation of Attack Wood)
- IE 6 Print Without Prompt
- IE Certificate Stealing (Phising) bug
- IETF Draft on Transmission Control Protocol security considerations
- Include vulnerability in GEMITEL v 3.50
- Index viewing in imgSvr 0.4
- Internet Explorer 6 - Crash
- Internet Explorer XSS published unpatched in SP1 AND SP2
- IPv4 fragmentation --> The Rose Attack
- IRIX ftpd ftp_syslog issue with anonymous FTP
- IRIX Update Some Network Drivers May Leak Data
- Kerio Personal Firewall 4 and IE 6 "Bug"
- Kerio Personal Firewall 4.0.13 - Remote DoS (Crash)
- KPhone STUN DoS (Malformed STUN Packets)
- Linux kernel setsockopt MCAST_MSFILTER integer overflow
- LNSA-#2004-0008: Multiple security problems in Monit
- LNSA-#2004-0009: GNU Automake symbolic link vulnerability
- LNSA-#2004-0010: login may leak sensitive data
- LNSA-#2004-0011: CVS Server and Client Vulnerabilities
- LNSA-#2004-0012: Multiple format string vulnerabilities in neon
- Macromedia Dreamweaver Remote Database Scripts (#NISR05042004B)
- Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure
- McAfee Freescan ActiveX Information Disclosure [Additional Details & PoC]
- MDKSA-2004:026 - Updated mplayer packages fix remotely exploitable vulnerability
- MDKSA-2004:027 - Updated ipsec-tools packages fix vulnerability in racoon
- MDKSA-2004:031 - Updated utempter packages fix several vulnerabilities
- MDKSA-2004:031-1 - Updated utempter packages fix several vulnerabilities
- MDKSA-2004:032 - Updated libneon packages fix temporary file insecurities
- MDKSA-2004:033 - Updated xine-ui packages fix temporary file insecurities
- MDKSA-2004:034 - Updated MySQL packages fix temporary file insecurities
- MDKSA-2004:035 - Updated samba packages fix privilege escalation vulnerability
- MDKSA-2004:037 - Updated kernel packages fix multiple vulnerabilities
- MDKSA-2004:038 - Updated sysklogd packages fix vulnerability
- MDKSA-2004:039 - Updated mc packages fix vulnerabilities
- MDKSA-2004:040 - Updated libpng packages fix vulnerability
- Metasploit Framework 2.0 Released!
- Microsoft Help and Support Center argument injection vulnerability
- Microsoft IE iframe src DoS already reported to Microsoft
- Microsoft Internet Explorer BMP file memory DoS vulnerability
- Microsoft Outlook Express EML file Crash vulnerability
- Microsoft's Explorer and Internet Explorer long share name buffer overflow.
- monit 4.1 POC
- Monit <= 4.2 Remote Root Exploit
- MS Patches last Mon - Recap
- MS Patches last Wed - SOLUTION
- MS04-011 Break SSL support in IE 6.0.3790.0 with Windows 2003
- MS04-011 SSL Remote DoS PoC
- MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)
- Multi stage attacks on networks?
- Multiple Vulnerabilities In OpenBB
- Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]
- Multiple vulnerabilities paFileDB
- Multiple vulnerabilities PHP-Nuke Video Gallery Module for PHP-Nuke
- Multiple XSS vulnerabilities in Microsoft SharePoint Portal Server 2001
- NcFTP - password leaking
- NetBSD Security Advisory 2004-005: Denial of service vulnerabilities in OpenSSL
- NetBSD Security Advisory 2004-006: TCP protocol and implementation vulnerability
- Netegrity SiteMinder Affiliate Agent Cookie Overflow
- NetSky.q Virus. Looking for more detailed information on how the DOS will be performed.
- Netsky.R, auto execute w/ IE6 ?
- Network Intelligence Advisory - Denial of Service Vulnerability in ColdFusion MX
- NEW backdoor in X-Micro WLAN 11b Broadband Router
- new IE vurn
- new internet explorer exploit (was new worm)
- New Paper - SQL Injection Signatures Evasion
- new strange worm
- New Worm/Virus April 8th
- New Worm??? - High level of activity on port 445
- NGSSoftware Insight Security Research Advisory
- NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP
- Norton AntiVirus nested file manual scan bypass.....
- Open Source Vulnerability Database Opens for Public Access
- OpenLinux: util-linux could leak sensitive data
- OpenLinux: vim arbitrary commands execution through modelines
- Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S)
- Paper: Comparing binaries with graph isomorphisms
- Papers: The Invisible Catalog
- Perl code exploting TCP not checking RST ACK.
- phpBB 2.0.8a and lower - IP spoofing vulnerability
- phpBB modified by Przemo arbitary code execution
- Phrack #62 Call for Papers
- Pikachu -Turn on WEP !
- Possible DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow.
- Potential Microsoft PCT worm (MS04-011)
- PSR - #2004-001 Remote - LCDProc
- PSR - #2004-002 Remote - LCDProc
- REAL One Player R3T File Format Stack Overflow
- Release of Cisco Attack tool Asleap
- Releasing full source code of WinBlox
- Remote Exploit for Aborior's Encore Web Forum
- Remote Format String Vulnerabilities in eXtremail
- resources consumption in DiGi WWW Server
- Samsung SmartEther SS6215S Switch
- SCT javascript execution vulnerability
- SECURITY.NNOV: Sambar security quest
- SGI Advanced Linux Environment security update #17
- SGI Advanced Linux Environment security update #18
- SGI Advanced Linux Environment security update #19
- SGI ProPack v2.4: Kernel update #3
- SMC Routers have remote administration enabled by default
- Solaris 9 patch 113579-03 introduces a NIS security bug
- Solaris vfs_getvfssw() local kernel exploit
- Source Code To Test IPv4 fragmentation --> The Rose Attack
- Spammers can hide behind 'Email a friend/article' scripts.
- Squirrelmail Chpasswod bof
- SquirrelMail Cross Scripting Attacks....
- ssmtp insecure file creation
- Support Contact Info
- SuSEs YaST Online Update - possible symlink attack
- Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow
- Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow, Apr 7 2004 2:22AM
- TCP Reset Attacks: Paper and Code Now Availble
- Texutil symlink vulnerability.
- TOOL: Adder - runtime patching in python
- TSLSA-2004-0020 - kernel
- TSLSA-2004-0024 - rsync
- TSLSA-2004-0025 - multi
- UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : perl unsafe Safe compartment
- UPDATE: Cisco Security Notice: Dictionary Attack on Cisco LEAP Vulnerability
- UPDATE: LCDproc Buffer Overflow and Format String Vulnerabilities
- US-CERT Technical Cyber Security Alert TA04-111A -- Vulnerabilities in TCP
- void.at - neon format string bugs
- Vulnerabilities in long-lived TCP connections on SGI systems
- WinSCP Denial of Service
- XSS, Admin Access via Cookie and File Upload vulnerability in NewsPHP.
- ZA Security Hole
- Zaep AntiSpam Cross Site Scripting
Last message date: 04/30/04
Archived on: 04/30/04 CEST
392 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]