Bugtraq
- [USN-930-3] Firefox regression
- ZDI-10-116: Adobe Reader CLOD Progressive Mesh Continuation Resolution Remote Code Execution Vulnerability
- VUPEN Security Research - Adobe Acrobat and Reader "newclass" Memory Corruption Vulnerability (CVE-2010-1285)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader "pushstring" Memory Corruption Vulnerability (CVE-2010-2201)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader "newfunction" Memory Corruption Vulnerability (CVE-2010-2168)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Acrobat and Reader #1023 Tag Buffer Overflow Vulnerability (CVE-2010-2212)
- From: VUPEN Security Research
- Secunia Research: Joomla BookLibrary Component Four SQL Injection Vulnerabilities
- Secunia Research: Adobe Reader GIF Image Parsing Array-Indexing Vulnerability
- Secunia Research: Adobe Reader JPEG Uninitialised Memory Vulnerability
- [0day] Microsoft mshtml.dll CTimeoutEventList::InsertIntoTimeoutList memory leak
- [USN-930-2] apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
- [USN-930-1] Firefox and Xulrunner vulnerabilities
- [USN-927-5] nspr update
- SAP's web module OLK SQL Injection vulnerability
- [USN-927-4] nss vulnerability
- IS-2010-005 - D-Link DAP-1160 Authentication Bypass
- Secunia Research: TaskFreak "tznMessage" Cross-Site Scripting Vulnerability
- Secunia Research: TaskFreak "password" SQL Injection Vulnerability
- Extended deadline, Call for Papers EC2ND 2010
- XSS vulnerability in Grafik CMS
- XSS vulnerability in PortalApp
- iDefense Security Advisory 06.21.10: Multiple Vendor LibTIFF 3.9.2 Stack Buffer Overflow Vulnerability
- XSS vulnerability in PortalApp
- XSS vulnerability in Grafik CMS
- SQL injection vulnerability in Grafik CMS
- XSS vulnerability in PortalApp
- SQL injection vulnerability in TomatoCMS
- London DEFCON June meet - DC4420 - Wed 30th June 2010
- ref_fuzz and other fun bugs
- New IETF Internet-Drafts on TCP timestamps
- IS-2010-004 - D-Link DAP-1160 Unauthenticated Remote Configuration
- Denial-of-Service Vulnerability in IDA Pro
- [SECURITY] [DSA 2065-1] New kvirc packages fix several vulnerabilities
- [SECURITY] [DSA 2064-1] New xulrunner packages fix several vulnerabilities
- Re: Sysax Multi Server "open", "unlink", "mkdir", "scp_get" Commands DoS Vulnerabilities
- Nuance OmniPage 16 Professional installs multiple vulnerable Microsoft runtime libraries
- [security bulletin] HPSBUX02544 SSRT100107 rev.1 - HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code
- [SWRX-2010-001] Cisco ASA HTTP Response Splitting Vulnerability
- ZDI-10-115: Adobe Flash Player AVM newFrameState Integer Overfow Remote Code Execution Vulnerability
- ZDI-10-114: Adobe Flash Player AVM2 getouterscope Opcode Remote Code Execution Vulnerability
- VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel
- From: VMware Security team
- [Suspected Spam]Vulnerabilities in Cimy Counter for WordPress
- XSS vulnerability in ForumCMS
- SQL injection vulnerability in WebDB
- [ MDVSA-2010:126 ] mozilla-thunderbird
- SQL injection vulnerability in WebDB
- [ MDVSA-2010:125 ] firefox
- [ MDVSA-2010:124 ] pulseaudio
- CORE-2010-0316 - Novell iManager Multiple Vulnerabilities
- From: CORE Security Technologies Advisories
- ZDI-10-113: Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability
- [ MDVSA-2010:123 ] libneon0.27
- RE: [Full-disclosure] Microsoft Help Files (.CHM): 'Locked File' Feature Bypass
- From: Thor (Hammer of God)
- Apache Axis Session Fixation Vulnerability
- From: Tiago Ferreira Barbosa
- Microsoft Help Files (.CHM): 'Locked File' Feature Bypass
- [security bulletin] HPSBMA02439 SSRT080082 rev.2 - HP OpenView SNMP Emanate Master Agent Running on HP-UX, Linux, Solaris, and Windows, Remote Unauthorized Access
- Weborf DCA-00012 Vulnerability Report
- From: Ewerson Guimarães (Crash) - Dclabs
- IS-2010-003 - Linksys WAP54Gv3 debug.cgi Cross-Site Scripting
- [ MDVSA-2010:122 ] fastjar
- [security bulletin] HPSBUX02541 SSRT100145 rev.1 - HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File
- From: Morris, John R. (SSRT)
- [ MDVSA-2010:121 ] pango
- [scip_Advisory 4142] Skype Client for Mac Chat Unicode Denial of Service
- ZDI-10-111: Adobe Flash Player LocalConnection Memory Corruption Remote Code Execution Vulnerability
- [USN-952-1] CUPS vulnerabilities
- CSRF in PHPWCMS 1.4.5
- [USN-953-1] fastjar vulnerability
- [USN-955-2] libpam-opie vulnerability
- [USN-955-1] OPIE vulnerability
- [USN-954-1] tiff vulnerabilities
- ZDI-10-112: Novell Access Manager Arbitrary File Upload Remote Code Execution Vulnerability
- [ MDVSA-2010:120 ] squirrelmail
- Sysax Multi Server "open", "unlink", "mkdir", "scp_get" Commands DoS Vulnerabilities
- XSS vulnerability in the search module of synType CMS
- Stored XSS vulnerability in synType CMS comment text field
- XSS vulnerability in Scribe CMS
- XSS vulnerability in Scribe CMS
- XSS vulnerability in Scribe CMS
- Wing FTP Server PORT Command DoS Vulnerability
- Vulnerabilities in eSitesBuilder
- Remote Arbitrary Code Execution Vulnerability in UFO: Alien Invasion
- NSOADV-2010-009: AnNoText Third-Party ActiveX Control file overwrite vulnerability
- NSOADV-2010-008: AnNoText Third-Party ActiveX Control Buffer Overflow
- [MajorSecurity SA-075]CMS RedAks 2.0 - SQL injection vulnerability
- Re: Nakid CMS (fckeditor) Remote Arbitrary File Upload Exploit
- XCon 2010 XFocus Information Security Conference Call for Paper
- CVE-2010-1622: Spring Framework execution of arbitrary code
- TitanFTP Server COMB directory traversal
- [security bulletin] HPSBUX02543 SSRT100152 rev.1 - HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access,
- [SECURITY] [DSA 2063-1] New pmount packages fix denial of service
- Vulnerabilities in Firebook
- TEHTRI-Security released 13 0days against web tools used by evil attackers
- From: Laurent OUDOT at TEHTRI-Security
- [ MDVSA-2010:119 ] samba
- [ MDVSA-2010:118 ] sudo
- [SECURITY] [DSA 2062-1] New sudo packages fix environment sanitization bypass vulnerability
- TurboFTP Server Directory Traversal Vulnerability
- [MajorSecurity SA-074]CMS RedAks 2.0 - Multiple Cross-site Scripting issues
- iDefense Security Advisory 06.16.10: Samba 3.3.12 Memory Corruption Vulnerability
- [security bulletin] HPSBOV02540 SSRT090249 rev.1 - HP SSL for OpenVMS, Remote Unauthorized Data Injection, Denial of Service(Dos)
- ZDI-10-109: Adobe Flash Player Multiple Atom MP4 Parsing Remote Code Execution Vulnerability
- ZDI-10-110: Adobe Flash Player Multiple Tag JPEG Parsing Remote Code Execution Vulnerability
- [USN-951-1] Samba vulnerability
- [SECURITY] [DSA 2061-1] New samba packages fix arbitrary code execution
- [ MDVSA-2010:117 ] cacti
- [Onapsis Security Advisory 2010-005] SAP J2EE Telnet Administration Security Check Bypass
- From: Onapsis Research Labs
- ZDI-10-108: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability
- VUPEN Security Research - Adobe Flash Player "newclass" Invalid Pointer Vulnerability (CVE-2010-2173)
- From: VUPEN Security Research
- VUPEN Security Research - Adobe Flash Player "newfunction" Invalid Pointer Vulnerability (CVE-2010-2174)
- From: VUPEN Security Research
- Nakid CMS (fckeditor) Remote Arbitrary File Upload Exploit
- VUPEN Security Research - Adobe Flash Player GIF/JPEG Data Parsing Heap Overflow Vulnerabilities (CVE-2010-2167)
- From: VUPEN Security Research
- TitanFTP Server Arbitrary File Disclosure
- Re: Dlink Di-604 router authenticated user ping tool Xss and DoS
- [SECURITY] [DSA 2054-2] New bind9 packages fix cache poisoning
- CORE-2010-0514: XnView MBM Processing Heap Overflow
- From: CORE Security Technologies Advisories
- [ GLSA 201006-21 ] UnrealIRCd: Multiple vulnerabilities
- [SECURITY] [DSA 2060-1] New cacti packages fix SQL injection
- DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- [security bulletin] HPSBPI02532 SSRT100111 rev.2 - HP MFP Digital Sending Software Running on Windows, Local Unauthorized Access
- [security bulletin] HPSBMA02537 SSRT010027 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- Re: SQL injection vulnerability in boastMachine
- From: security curmudgeon
- [MajorSecurity SA-073]Subdreamer CMS - SQL injection vulnerability
- SQL injection vulnerability in MODx CMS
- [advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068
- From: William A. Rowe Jr.
- [ MDVSA-2010:116 ] perl
- Stored XSS vulnerability in AneCMS blog module
- Cherokee Web Server 0.5.3 Multiple Vulnerabilities
- SQL injection vulnerability in AneCMS
- SQL injection vulnerability in MODx CMS and Application Framework
- [ MDVSA-2010:115 ] perl
- SQL injection vulnerability in MODx CMS and Application Framework
- Re: [oss-security] [oCERT-2010-001] multiple http client unexpected download filename vulnerability
- [ MDVSA-2010:114 ] dhcp
- Secunia Research: Creative Software AutoUpdate Engine 2 ActiveX Control Buffer Overflow
- iDefense Security Advisory 06.10.10: Adobe Flash Player Use-After-Free Vulnerability
- iDefense Security Advisory 06.10.10: Adobe Flash Player Out Of Bounds Memory Indexing Vulnerability
- ZDI-10-107: Multiple Sourcefire Products Static Web SSL Keys Vulnerability
- iDefense Security Advisory 06.07.10: Multiple Vendor WebKit HTML Caption Use After Free Vulnerability
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- [SECURITY] [DSA 2059-1] New pcsc-lite packages fix privilege escalation
- [MajorSecurity SA-071]phpFaber CMS - Multiple stored Cross-site Scripting issues
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- Vulnerabilities in Belavir for WordPress
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- [SECURITY] [DSA 2058-1] New glibc packages fix several vulnerabilities
- Awcm Cms Local File Inclusion Vulnerability
- [ MDVSA-2010:113 ] wireshark
- TPTI-10-03: Sophos Anti-Virus SAVOnAccessFilter Local Privilege Escalation Vulnerability
- PR09-17: Juniper Secure Access seriers (Juniper IVE) authenticated XSS & REDIRECTION
- Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
- McAfee UTM Firewall Help Reflected Cross-Site Scripting
- VUPEN Security Research - Microsoft Office Excel ExternName Buffer Overflow Vulnerability (CVE-2010-1249)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Windows Kernel "GetDCEx()" Memory Corruption Vulnerability (CVE-2010-0484)
- From: VUPEN Security Research
- [MajorSecurity SA-068]Anantasoft Gazelle CMS - change admin password via Cross-site Request Forgery
- VUPEN Security Research - Microsoft Office Excel HFPicture Buffer Overflow Vulnerability (CVE-2010-1248)
- From: VUPEN Security Research
- [MajorSecurity SA-069]Invision Power Board - stored Cross site Scripting
- CA20100608-01: Security Notice for CA PSFormX and WebScan ActiveX Controls
- Cisco Security Advisory: Cisco Application Extension Platform Privilege Escalation Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Vulnerabilities in Cisco Unified Contact Center Express
- From: Cisco Systems Product Security Incident Response Team
- RE: RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )
- [MajorSecurity SA-070]Plume CMS - change Admin Password via Cross-site Request Forgery
- VUPEN Security Research - Microsoft Office Excel WOPT Heap Corruption Vulnerability (CVE-2010-0824)
- From: VUPEN Security Research
- [USN-950-1] MySQL vulnerabilities
- VUPEN Security Research - Microsoft Office Excel RTD Stack Overflow Vulnerability (CVE-2010-1246)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Office Excel SxView Memory Corruption Vulnerability (CVE-2010-1245)
- From: VUPEN Security Research
- Re: [oss-security] [oCERT-2010-001] multiple http client unexpected download filename vulnerability
- VUPEN Security Research - Microsoft Office Excel EDG Heap Overflow Vulnerability (CVE-2010-1250)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Office Excel RTD Heap Corruption Vulnerability (CVE-2010-1247)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Office Excel OBJ Stack Overflow Vulnerability (CVE-2010-0822)
- From: VUPEN Security Research
- Dlink Di-604 router authenticated user ping tool Xss and DoS
- From: Ewerson Guimarães (Crash) - Dclabs
- [CORE-2010-0415] SQL Injection in CubeCart PHP Free & Commercial Shopping Cart Application
- From: CORE Security Technologies Advisories
- [security bulletin] HPSBMA02537 SSRT010027 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
- ZDI-10-105: Hewlett-Packard OpenView NNM ovwebsnmpsrv.exe Bad Option Remote Code Execution Vulnerability
- tool: ref_fuzz (CVE-2010-1259 / MS10-035 and more)
- ZDI-10-102: Microsoft Internet Explorer Stylesheet Array Removal Remote Code Execution Vulnerability
- IS-2010-002 - Linksys WAP54Gv3 Remote Debug Root Shell
- ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability
- ZDI-10-104: Microsoft Office Excel SxView Record Parsing Remote Code Execution Vulnerability
- ZDI-10-103: Microsoft Office Excel DBQueryExt Record Unspecified ADO Object Remote Code Execution Vulnerability
- ZDI-10-092: Apple Webkit Option Element ContentEditable Remote Code Execution Vulnerability
- ZDI-10-100: Apple Webkit ConditionEventListener Remote Code Execution Vulnerability
- ZDI-10-094: Apple Webkit SelectionController via Marquee Event Remote Code Execution Vulnerability
- ZDI-10-101: Apple Webkit SVG RadialGradiant Run-in Remote Code Execution Vulnerability
- ZDI-10-093: Apple Webkit CSS Charset Text Transformation Remote Code Execution Vulnerability
- ZDI-10-099: Apple Webkit ProcessInstruction Target Error Message Insertion Remote Code Execution Vulnerability
- ZDI-10-096: Apple Webkit Recursive Use Element Remote Code Execution Vulnerability
- ZDI-10-098: Apple Webkit First-Letter Pseudo-Element Style Remote Code Execution Vulnerability
- ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability
- ZDI-10-091: Apple Webkit Attribute Child Removal Remote Code Execution Vulnerability
- ZDI-10-097: Apple Webkit ContentEditable moveParagraphs Uninitialized Element Remote Code Execution Vulnerability
- [ MDVSA-2010:111 ] glibc
- ArpON (Arp handler inspectiON) 2.0 released!
- Blue Arc Group - IgnitionSuite CMS WebDMailer unsubscribe issue
- Paessler - PRTG Traffic Grapher XSS
- The XCon2010 is coming
- DoS attacks on email clients via protocol handlers
- Recon 2010 - Speaker list, new additional capacity for sold-out training, party details
- VUPEN Security Research - Apple Safari WebKit HTML Button Use-after-free Vulnerability (CVE-2010-1392)
- From: VUPEN Security Research
- Re: RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )
- SQL injection vulnerability in boastMachine
- XSS vulnerability in boastMachine
- XSRF (CSRF) in CuteSITE CMS
- XSS vulnerability in CuteSITE CMS
- Core FTP Server(SFTP module) 'open' and 'stat' Commands Remote Denial of Service Vulnerability
- [SECURITY] [DSA 2057-1] New mysql-dfsg-5.0 packages fix several vulnerabilities
- [SECURITY] [DSA 2054-1] New bind9 packages fix cache poisoning
- [SECURITY] [DSA 2056-1] New zonecheck packages fix cross-site scripting
- [SECURITY] [DSA 2055-1] New OpenOffice.org packages fix arbitrary code execution
- SQL injection vulnerability in CuteSITE CMS
- Core FTP mini-sftp-server Several DoS and Directory Traversal Vulnerabilities
- [security bulletin] HPSBUX02451 SSRT090137 rev.3 - HP-UX Running BIND, Remote Denial of Service (DoS)
- Vulnerabilities in Gigya Socialize for WordPress
- [ GLSA 201006-18 ] Oracle JRE/JDK: Multiple vulnerabilities
- [ GLSA 201006-19 ] Bugzilla: Multiple vulnerabilities
- Re[3]: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers
- [ GLSA 201006-20 ] Asterisk: Multiple vulnerabilities
- [Suspected Spam][USN-947-2] Linux kernel regression
- RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )
- CA20100603-01: Security Notice for CA ARCserve Backup
- [USN-948-1] GnuTLS vulnerability
- Multiple vulnerabilities in Exim
- eFront Multiple Parameter Cross Site Scripting Vulnerabilities
- RE: [ GLSA 201006-13 ] Smarty: Multiple vulnerabilities
- [security bulletin] HPSBMA02538 SSRT100136 rev.1 - HP ServiceCenter Running on AIX, HP-UX, Linux, Solaris, and Windows, Remote Cross Site Scripting (XSS)
- [security bulletin] HPSBST02536 SSRT100057 rev.1 - HP StorageWorks Storage Mirroring, Remote Unauthorized Access
- [ GLSA 201006-17 ] lighttpd: Denial of Service
- [ GLSA 201006-16 ] GD: User-assisted execution of arbitrary code
- [ GLSA 201006-15 ] XEmacs: User-assisted execution of arbitrary code
- [security bulletin] HPSBUX02531 SSRT100108 rev.1 - HP-UX Running Apache-based Web Server, Remote Denial of Service (DoS), Unauthorized Access
- [security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary Code, Disclosure of Information, and Other Vulnerabilities
- [ GLSA 201006-14 ] Newt: User-assisted execution of arbitrary code
- [ GLSA 201006-13 ] Smarty: Multiple vulnerabilities
- [Suspected Spam][USN-946-1] Net-SNMP vulnerability
- DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- [ GLSA 201006-12 ] Fetchmail: Multiple vulnerabilities
- [ GLSA 201006-11 ] BIND: Multiple vulnerabilities
- [ GLSA 201006-10 ] multipath-tools: World-writeable socket
- TEHTRI-Security: Many 0days soon released at SyScan Singapore 2010
- From: Laurent OUDOT at TEHTRI-Security
- Wing FTP Server - Cross Site Scripting Vulnerability
- Trend Micro Data Loss Prevention 5.2 Data Leakage
- [20100501] - Core - Joomla! Multiple XSS Vulnerabilities in Back End Administrative Module Core Components
- Re: Nginx 0.8.35 Space Character Remote Source Disclosure
- From: Mailing lists at Core Security Technologies
- SFCB vulnerabilities
- Applicure dotDefender 4.0 administrative interface cross site scripting
- Re: RE: Nginx 0.8.35 Space Character Remote Source Disclosure
- [ GLSA 201006-09 ] sudo: Privilege escalation
- [ GLSA 201006-08 ] nano: Multiple vulnerabilities
- ZDI-10-090: Novell ZENworks Configuration Management Preboot Service Remote Code Execution Vulnerability
- [ GLSA 201006-07 ] SILC: Multiple vulnerabilities
- [ GLSA 201006-06 ] Transmission: Multiple vulnerabilities
- [ GLSA 201006-05 ] Wireshark: Multiple vulnerabilities
- [ GLSA 201006-04 ] xine-lib: User-assisted execution of arbitrary code
- [ GLSA 201006-03 ] ImageMagick: User-assisted execution of arbitrary code
- Onapsis Research Labs: Onapsis Bizploit - The opensource ERP Penetration Testing framework
- From: Onapsis Research Labs
- [ GLSA 201006-02 ] CamlImages: User-assisted execution of arbitrary code
- Re: [Full-disclosure] PuTTY private key passphrase stealing attack
- Re: [Full-disclosure] PuTTY private key passphrase stealing attack
- [ GLSA 201006-01 ] FreeType 1: User-assisted execution of arbitrary code
- Re: [Full-disclosure] PuTTY private key passphrase stealing attack
- PuTTY private key passphrase stealing attack
- XSS vulnerability in Ecomat CMS
- SQL injection vulnerability in Ecomat CMS
- DoS vulnerability in Internet Explorer
- [Bkis-02-2010] Multiple Vulnerabilities in CMS Made Simple - Bkis
- Re: Nginx 0.8.35 Space Character Remote Source Disclosure
- RE: Nginx 0.8.35 Space Character Remote Source Disclosure
- Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera
- RE: Ghostscript 8.64 executes random code at startup
- Winamp v5.571 malicious AVI file handling DoS Vulnerability
