SecurityFocus Bugtraq
By Subject
417 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]
Starting: 08/02/04
Ending: 08/31/04
- 0day critical vulnerability/exploit targets Winamp users in the wild
- 7a69Adv#13 - USRobotics AP Wireless Denial of Service
- [ GLSA 200408-01 ] MPlayer: GUI filename handling overflow
- [ GLSA 200408-02 ] Courier: Cross-site scripting vulnerability in SqWebMail
- [ GLSA 200408-03 ] libpng: Numerous vulnerabilities
- [ GLSA 200408-04 ] PuTTY: Pre-authentication arbitrary code execution
- [ GLSA 200408-05 ] Opera: Multiple new vulnerabilities
- [ GLSA 200408-06 ] SpamAssassin: Denial of Service vulnerability
- [ GLSA 200408-07 ] Horde-IMP: Input validation vulnerability for Internet Explorer users
- [ GLSA 200408-09 ] Roundup filesystem access vulnerability
- [ GLSA 200408-10 ] gv: Exploitable Buffer Overflow
- [ GLSA 200408-11 ] Nessus: "adduser" race condition vulnerability
- [ GLSA 200408-12 ] Gaim: MSN protocol parsing function buffer overflow
- [ GLSA 200408-13 ] kdebase, kdelibs: Multiple security issues
- [ GLSA 200408-14 ] acroread: UUDecode filename buffer overflow
- [ GLSA 200408-15 ] Tomcat: Insecure Installation
- [ GLSA 200408-16 ] glibc: Information leak with LD_DEBUG
- [ GLSA 200408-17 ] rsync: Potential information leakage
- [ GLSA 200408-18 ] xine-lib: VCD MRL buffer overflow
- [ GLSA 200408-19 ] courier-imap: Remote Format String Vulnerability
- [ GLSA 200408-20 ] Qt: Image loader overflows
- [ GLSA 200408-21 ] Cacti: SQL injection vulnerability
- [ GLSA 200408-22 ] Mozilla, Firefox, Thunderbird: New releases fix vulnerabilities
- [ GLSA 200408-23 ] kdelibs: Cross-domain cookie injection vulnerability
- [ GLSA 200408-24 ] Linux Kernel: Multiple information leaks
- [ GLSA 200408-25 ] MoinMoin: Group ACL bypass
- [ GLSA 200408-26 ] zlib: Denial of service vulnerability
- [ GLSA 200408-27 ] Gaim: New vulnerabilities
- [2Cents on] vpopmail <= 5.4.2 (sybase vulnerability)
- [CLA-2004:856] Conectiva Security Announcement - libpng
- [CLA-2004:857] Conectiva Security Announcement - apache
- [CLA-2004:858] Conectiva Security Announcement - squirrelmail
- [Full-Disclosure] [PoC] Nasty bug(s) found in Axis Network Camera/Video Servers
- [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards
- [Full-Disclosure] DOS@MEHTTPS
- [Full-Disclosure] IpSwitch IMail Server <= ver 8.1 User Password Decryption
- [Full-Disclosure] Security aspects of time synchronization infrastructure
- [NGSEC-2004-6] IPD, local system denial of service.
- [NGSEC-2004-7] NtRegmon, local system denial of service.
- [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)
- [OpenPKG-SA-2004.036] OpenPKG Security Advisory (cvstrac)
- [OpenPKG-SA-2004.038] OpenPKG Security Advisory (zlib)
- [PHP Bug] How to hide a HTTP request in the apache logs
- [PoC] Nasty bug(s) found in Axis Network Camera/Video Servers
- [security bulletin] SSRT3460 rev.3 HP-UX Network traffic can cause programs to fail
- [security bulletin] SSRT4777 HP-UX Apache, PHP remote code execution, Denial of Service
- [security bulletin] SSRT4779 - rev.0 HP-UX Netscape NSS Library Suite SSLv2 remote buffer overflow
- [security bulletin] SSRT4782 rev. 1 HP-UX CIFS Server potential remote root access
- [security bulletin] SSRT4785 rev. 0 HP-UX Process Resource Manager (PRM) potential data corruption
- [security bulletin] SSRT4788 rev. 0 HP-UX Apache Remote arbitrary code execution
- [security bulletin] SSRTSSRT4778 Rev.0 Mozilla Application Suite for HP Tru64 UNIX libpng Potential Overflows
- [SECURITY] [DSA 458-2] New python2.2 packages really fix buffer overflow
- [SECURITY] [DSA 535-1] New squirrelmail packages fix multiple vulnerabilities
- [SECURITY] [DSA 536-1] New libpng, libpng3 packages fix multiple vulnerabilities
- [SECURITY] [DSA 537-1] New Ruby packages fix insecure CGI session management
- [SECURITY] [DSA 538-1] New rsync packages fix unauthorised directory traversal and file access
- [SECURITY] [DSA 539-1] New kdelibs packages fix denial of service
- [SECURITY] [DSA 540-1] New mysql packages fix insecure temporary file creation
- [SECURITY] [DSA 541-1] New icecast-server packages fix cross site scripting
- [SECURITY] [DSA 542-1] New Qt packages fix arbitrary code execution and denial of service
- [SECURITY] [DSA 543-1] New krb5 packages fix several vulnerabilities
- [vchkpw] vpopmail <= 5.4.2 (sybase vulnerability) (fwd)]
- [VSA0402] OpenFTPD format string vulnerability
- [vulnwatch] Titan FTP Server Long Command Heap Overflow Vulnerability
- [vulnwatch] WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability
- [vulnwatch] WS_FTP Server Denial of Service Vulnerability
- A new website to search & submit win exploits
- A word of caution on the use of suphp
- Advanced usage of system() function.
- Airpwn & libpng holes
- Aladdin response regarding eSafe
- Alpha Phising [IE 6 WinXP SP2]
- ANNOUNCE: VulnDisco RADIUS protocol testsuite v1.0
- Anonymous Surfing Via Gmail Login Window - Poor Sanitization
- Anyone know IBM's security address?
- AOL Instant Messenger "Away" Message Buffer Overflow Vulnerability
- BadBlue Webserver v2.5 Denial Of Service Vulnerability
- BlackICE unprivileged local user attack
- Breaking windows LM hashes using the Time-Memory Trade-Off : Optimization & new tool
- Broadcast forced exit in Ground Control II 1.0.0.7
- Buffer overflow in sarad
- bug found
- Bug@thttpd
- Bugs fixed in Version 1.4.3
- CAU-2004-0002 - imwheel Predictable PidFile Name Race Condition
- CDE libDtHelp and dtlogin vulnerabilities on IRIX
- CDE libDtHelp LOGNAME Buffer Overflow Vulnerability
- CESA-2004-001: libpng
- CESA-2004-004: qt
- Check Point - Zone Labs Division - Response to "Weak Default Permissions Vulnerability"
- Cisco Security Advisory: Cisco IOS Malformed OSPF Packet Causes Reload
- Cisco Security Advisory: Cisco Telnet Denial of Service Vulnerability
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Secure Access Control Server
- Citadel/UX Remote DoS Vulnerability
- Clear text password exposure in Datakey's tokens and smartcards
- Clearswift Mimesweeper Path Traversal Vulnerability
- Comersus 5.098 XSS Vulnerable
- Computer Network Defence Vulnerability Alert State
- Computer Network Defence Vulnerability Alert State)
- CORE-2004-0705: Vulnerabilities in PuTTY and PSCP
- CORE-2004-0714: Cfengine RSA Authentication Heap Corruption
- Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues
- Corsaire Security Advisory - Port80 Software ServerMask inconsistencies
- Corsaire Security Advisory - Sygate Enforcer discovery packet DoS issue
- Corsaire Security Advisory - Sygate Enforcer unauthenticated broadcast issue
- Corsaire Security Advisory - Sygate Secure Enterprise replay issue
- Cross Site Scripting in XOOPS Version 2.x Dictionary module
- Cross Site Scripting Vulnerability in Sympa
- Cross-Site Scripting (XSS) in Nihuo Web Log Analyzer
- Cross-Site Scripting (XSS) in Php-Nuke 7.1.0
- CuteNews News.txt writable to world
- CVS woes: .cvspass
- CVStrac Remote Arbitrary Code Execution exploit
- D-Link DCS-900 IP camera remote exploit that change the IP
- DoS in Bird Chat 1.61
- DoS in Chat Anywhere 2.72a
- DoS in Webbsyte Chat 0.9.0
- DOS@MEHTTPS
- DOS@TFS
- Driver for display goes to a infinite loop by viewing a html!
- Dynix Webpac Input Validation
- ERRATA: [ GLSA 200406-14 ] aspell: Buffer overflow in word-list-compress
- ERRATA: [ GLSA 200408-21 ] Cacti: SQL injection vulnerability
- EXPLOIT libpng
- EXPLOIT: Qt bmp heap overflow
- First symbian OS trojan discovered in the wild
- First vulnerabilities in the SP2 - XP ?...
- Fwd: New possible scam method : forged websites using XUL (Firefox)
- Gaucho v1.4 Build 145 Buffer Overflow
- GNU/Linux 'info Buffer Overflow
- GoScript Remote Command Execution
- gv buffer overflows: here, there, and everywhere
- Hafiye-1.0 Terminal Escape Sequence Injection Vulnerability
- Hastymail security update
- HTTP Response Splitting vulnerability in Microsoft Outlook Web Access for Exchange 5.5
- IE, Firefox, Opera DoS
- IE, Firefox, Opera DoS (*not* a DoS, not even close)
- Images being pulled in Outlook 2003 even though don't download pictures is set?
- Immunity, Inc. Release: libdisassemble
- International DNS compromise?
- Internet Explorer Local File/Directory Detection
- IpSwitch IMail Server <= ver 8.1 User Password Decryption
- Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability - [Full-Disclosure] iDEFENSE Security Advisory 08.25.04
- IRM 010: Top Layer Attack Mitigator IPS 5500 Denial of Service
- ISS BlackIce Server Protect Unprivileged User Attack
- Java XSLT security advisory addendum
- JS/Zerolin
- JShop Input Validation Hole in 'page.php' Permits Cross-Site Scripting Attacks
- Kaspersky Labs says Electronic Jihad on the Internet quite possible tomorrow
- KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities
- KDE Security Advisory: Konqueror Cross-Domain Cookie Injection
- Keene Digital Media Server Directory Traversal
- Limited buffer overflow in Painkiller 1.31
- Linux kernel file offset pointer races
- Linux OpenExchange - cleartext rootpw in swap
- LNSA-#2004-0017: rsync (Aug, 17 2004)
- local denial of Service, Yellowdog linux to 3.0.1
- Mantis Bugtracker Remote PHP Code Execution Vulnerability
- MDKSA-2004:079 - Updated libpng packages fix multiple vulnerabilities
- MDKSA-2004:080 - Updated shorewall packages fix temporary file vulnerabilities
- MDKSA-2004:081 - Updated gaim packages fix remotely exploitable vulnerabilities
- MDKSA-2004:082 - Updated mozilla packages fix multiple vulnerabilities
- MDKSA-2004:083 - Updated rsync packages fix remotely-exploitable vulnerability
- MDKSA-2004:084 - Updated spamassassin packages fixes possible malformed message vulnerability
- MDKSA-2004:084 - Updated spamassassin packages fixes possible malformed message vulnerability (OpenBSD 3.5 too??)
- MDKSA-2004:085 - Updated qt3 packages fix multiple vulnerabilities
- MDKSA-2004:086 - Updated kdelibs and kdebase packages fix multiple vulnerabilities
- MDKSA-2004:087 - Updated kernel packages fix multiple vulnerabilities
- Metasploit Framework v2.2
- Microsoft Internet Explorer 6 Protocol Handler Vulnerability
- Microsoft updates documentation on Windows time synchronization
- Microsoft Windows XP SP2
- MITKRB5-SA-2004-003: ASN.1 decoder denial-of-service
- MS XP SP2 Windows Security Center allows spoofing
- MS04-025 - Ignorance is truly bliss....
- Multiple Cross Site Scripting Vulnerabilities in eGroupWare
- Multiple vulnerabilities in eNdonesia CMS
- Multiple Vulnerabilities in Free Web Chat
- multiple vulnerabilities in lukemftpd/tnftpd on mailhost.freebsd.lublin.pl
- Multiple Vulnerabilities in Mantis Bugtracker
- Multiple vulnerabilities in MyDMS
- Multiple vulnerabilities in PHP-FUSION
- Multiple Vulnerabilities In Xedus Webserver
- MusicDaemon <= 0.0.3 /etc/shadow Stealer / DoS Exploit
- NetBSD Security Advisory 2004-009: ftpd root escalation
- NETGEAR DG834G SPECIAL FEATURES
- New google's top query?
- New MyDoom variant
- New Paper: Microsoft Windows, a lower Total Cost of Ownership
- New possible scam method : forged websites using XUL (Firefox)
- NGSEC's response to Idefense overflow protections whitepaper.
- NGSEC's response to Idefense overflow protections whitepaper. (PART II)
- NullyFake - Site Spoofing in MSIE
- Open Security Group Advisory #6
- OPEN3S - Local Privilege Elevation through Oracle products (Unix Platform)
- Opera Local File/Directory Detection (GM#009-OP)
- Opera: Location, Location, Location
- Opera: Location, Location, Location (GM#008-OP)
- Pavuk Digest Authentication Buffer Overflow
- PHP Code Snippet Library Multiple Cross-Site Scripting (XSS) Vulnerabilities
- Posible security bug in phpMyWebhosting
- Possible root compromose with bsdmainutils 6.0.x < 6.0.15 (Debian testing/unstable)
- Possible Security Issues In LiveWorld Products
- pscript.de PFORUM XSS Vulnerability
- ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows
- QuiXplorer directory traversal
- RealVNC 4.0 DoS
- recent gaim advisory
- recent iDefense advisories not being posted to bugtraq includes CVS information disclosure bug (CAN-2004-0778)
- Remote Command Execution
- Remote crash in tcpdump from OpenBSD
- Running renamed executables with CMD.EXE
- SA-20040802 GnuTLS certificate chain verification bug
- Security aspects of time synchronization infrastructure
- Security Center and Windows XP clients in domain
- Security contact for RSA Security
- SGI Advanced Linux Environment 2.4 security update #24
- SGI Advanced Linux Environment 3 Security Update #9
- SGI ProPack 3: Kernel Update #3 - Security and other fixes
- SHA-0 Broken, MD5 Rumored Broken
- SideFind
- Sonicwall diag tool includes VPN credentlials
- SoX Exploiter by Rosiello Security
- spamcop.net allows everyone to grab mail addresses and reset passwords
- SpecificMAIL Technical Brief
- SQL Injection in CACTI
- Squirrelmail chpasswd local root bruteforce exploit
- SSC Advisory TSA-051 (T-mobile wireless and Verizon Northwest)
- SuSE Linux K-Menu YAST Control Center Priviledge Escalation Vulnerability
- SUSE Security Announcement: gaim (SUSE-SA:2004:025)
- SUSE Security Announcement: kernel (SUSE-SA:2004:024)
- SUSE Security Announcement: libpng (SUSE-SA:2004:023)
- SUSE Security Announcement: qt3 (SUSE-SA:2004:027)
- SUSE Security Announcement: rsync (SUSE-SA:2004:026)
- Third party cookie handling in Opera can lead to potential compromises in Servers relying on redirection
- TSL-2004-0043 - multi
- TSLSA-2004-0040 - libpng
- TSLSA-2004-0041 - kernel
- TSLSA-2004-0042 - rsync
- TSSA-2004-020-ES - rsync
- Type xxs
- Unsecure file permission of ZoneAlarm pro.
- vpopmail <= 5.4.2 (sybase vulnerability)
- vulnerabilities in JetboxOne CMS
- Vulnerabilities in Merak Webmail Server.
- Vulnerability: OpenBSD 3.5 Kernel Panic.
- WebAPP directory traversal and ability to retrieve the DES encrypted password hash
- What A Drag II XP SP2
- What A Drag! -revisited-
- Window Washer 5.5: False Sense of Security
- Windows doesn't verify digital signature of CRL files
- Winmx Software making calls to Port 25
- Xines_Mine.c Open Security Group Advisory
- xss in moodle (post.php)
- XV multiple buffer overflows, exploit included
- Yahoo! E-mail Service Vulnerability
Last message date: 08/31/04
Archived on: 08/31/04 CEST
417 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]