|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
355 messages sorted by: [ author ] [ date ] [ thread ]
Starting: Mon Nov 03 2003 - 10:30:34 CST
Ending: Mon Dec 01 2003 - 13:01:31 CST
- "Security at Microsoft" document available
- ..researchers org..)
- [aadams<img src="/imgs/at.gif" border=0 align=middle>securityfocus.com: Linux Kernel <= 2.4.21 MXCSR Local DOS Exploitation]
- [ANNOUNCE] Python network security tools: Pcapy, Impacket, InlineEgg
- [BUGZILLA] Security Advisory - information leak
- [BUGZILLA] Security Advisory - SQL injection, information leak
- [bWM#017] Cross-Site-Scripting <img src="/imgs/at.gif" border=0 align=middle> PHPKIT
- [CLA-2003:774] Conectiva Security Announcement - bugzilla
- [CLA-2003:775] Conectiva Security Announcement - apache
- [CLA-2003:777] Conectiva Security Announcement - thttpd
- [CLA-2003:778] Conectiva Security Announcement - net-snmp
- [CLA-2003:779] Conectiva Security Announcement - cups
- [CLA-2003:780] Conectiva Security Announcement - ethereal
- [CLA-2003:781] Conectiva Security Announcement - mpg123
- [CLA-2003:782] Conectiva Security Announcement - xinetd
- [CLA-2003:783] Conectiva Security Announcement - hylafax
- [CLA-2003:784] Conectiva Security Announcement - postgresql
- [CLA-2003:786] Conectiva Security Announcement - zebra
- [CommerceSQL] Remote File Read Vulnerability
- [ESA-20031104-029] 'openssl' ASN.1 parsing denial of service
- [ESA-20031105-030] 'apache' buffer overflow in mod_alias and mod_rewrite
- [ESA-20031126-031] BIND cache poisoning vulnerability
- [Exploit]: Microsoft FPSE fp30reg.dll Overflow Remote Exploit (MS03-051)
- [Full-Disclosure] [SECURITY] [DSA 397-1] New PostgreSQL packages fix buffer overflow
- [Full-Disclosure] hard links on Linux create local DoS vulnerability and security problems
- [Full-Disclosure] Microsoft prepares security assault on Linux
- [Full-Disclosure] Proof of concept for Windows Workstation Se rvice overflow
- [Hat-Squad] phpBB search_id injection exploit
- [OpenCA Advisory] Vulnerabilities in signature verification
- [OpenPKG-SA-2003.048] OpenPKG Security Advisory (postgresql)
- [OpenPKG-SA-2003.049] OpenPKG Security Advisory (zebra)
- [OpenPKG-SA-2003.050] OpenPKG Security Advisory (screen)
- [OpenSSL Advisory] Denial of Service in ASN.1 parsing
- [Opera 7] Arbitrary File Auto-Saved Vulnerability.
- [RHSA-2003:275-01] Updated CUPS packages fix denial of service
- [RHSA-2003:286-01] Updated XFree86 packages provide security and bug fixes
- [RHSA-2003:287-01] Updated XFree86 packages provide security and bug fixes
- [RHSA-2003:288-01] Updated XFree86 packages provide security and bug fixes
- [RHSA-2003:296-01] Updated stunnel packages available
- [RHSA-2003:307-01] Updated zebra packages fix security vulnerabilities
- [RHSA-2003:309-01] Updated fileutils/coreutils package fix ls vulnerabilities
- [RHSA-2003:311-01] Updated Pan packages fix denial of service vulnerability
- [RHSA-2003:313-01] Updated PostgreSQL packages fix buffer overflow
- [RHSA-2003:316-01] Updated iproute packages fix local security vulnerability
- [RHSA-2003:323-01] Updated Ethereal packages fix security issues
- [RHSA-2003:325-01] Updated glibc packages provide security and bug fixes
- [RHSA-2003:342-01] Updated EPIC packages fix security vulnerability
- [SCSA-021] Anonymous Mail Forwarding Vulnerabilities in vbPortal
- [SECURITY] [DSA 398-1] New conquest packages fix local conquest exploit
- [SECURITY] [DSA 399-1] New epic4 packages fix denial of service
- [SECURITY] [DSA 400-1] New omega-rpg packages fix local games exploit
- [SECURITY] [DSA 401-1] New hylafax packages fix remote root exploit
- [SECURITY] [DSA 402-1] New minimalist package fixes remote command execution
- [SECURITY] Some Debian Project machines have been compromised
- [securitylab.ru & security.nnov] Kerio Winroute Firewall Xroxy problem
- [securitylab.ru] EffectOffice Server 2.9 problem
- [slackware-security] apache security update (SSA:2003-308-01)
- [SNS Advisory No.69] Eudora "Reply-To-All" Buffer Overflow Vulnerability
- A resource for the Fake players bug
- ANNOUNCE: New mailing list for secure application development, SC-L
- Apple Safari 1.1 (v100)
- Applied Watch Response to Bugtraq.org post - Was: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)
- BackToFramedJpu - a successor of BackToJpu attack
- buffer overflow in unace (linux extractor for .ace files)
- Cache Disclosure Leads to MYCOMPUTER Zone and Remote Compromise
- CERT Summary CS-2003-04
- Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue
- Corsaire Security Advisory: PeopleSoft IScript XSS issue
- Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues
- Cutenews 1.3 information disclosure
- DailyDose v 1.1
- Directory traversal in The TelCondex SimpleWebserver 2.13.31027 Build 3289.
- DOE Releases Interim Report on Blackouts/Power Outages, Focus on Cyber Security
- DoS for Ganglia
- DoS in PureFTPd
- DoS in PureFTPd - continue.
- double slash moves cache from INTERNET zone to MYCOMPUTER zone
- EEYE: Windows Workstation Service Remote Buffer Overflow
- EPIC4 remote client-side stack-based overflow(exploit)
- Eudora 6.0.1 attachment spoof
- Eudora 6.0.1 LaunchProtect
- FreeBSD Security Advisory FreeBSD-SA-03:19.bind
- FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability
- FreeRADIUS <= 0.9.3 rlm_smb module stack overflow vulnerability
- Frontpage Extensions Remote Command Execution
- Funny article
- Funny article")
- Gaim IRC Local Account Information Leakage
- Gamespy uses DMCA to destroy bug research and full disclosure
- Geeklog exploit
- GLSA: apache (200310-03)
- GLSA: ethereal (200311-04)
- GLSA: glibc (200311-05)
- GLSA: hylafax (200311-03)
- GLSA: kdebase (200311-01)
- GLSA: libnids (200311-07)
- GLSA: opera (200311-02)
- GLSA: phpsysinfo (200311-06)
- GNU screen buffer overflow
- GnuPG's ElGamal signing keys compromised
- Half Life dedicated server information leak and DoS
- hard links on Linux create local DoS vulnerability and security problems
- HijackClickV2 - a successor of HijackClick attack
- HPUX dtmailpr buffer overflow vulnerability
- HylaFAX - Format String Vulnerability Fixed
- IA WebMail 3.x PoC
- IA WebMail 3.x PoC Code
- idsearch.com and googleMS.DLL
- IE Remote Compromise by Getting Cache Location
- IE: double slash moves cache from INTERNET zone to MYCOMPUTER zone
- Immunix Secured OS 7+ bind update
- Immunix Secured OS 7+ fileutils update
- Insecure handling of procfs descriptors in UnixWare 7.1.1, 7.1.3 and Open UNIX 8.0.0 can lead to local privilege escalation.
- Invalid ContentType may disclose cache directory
- iwconfig vulnerability - the last code was demaged sending by email
- Jason Maloney's CGI Guestbook Remote Command Execution Vulnerability.
- Liteserve Buffer Overflow in Handling Server's Log.
- Local PoC exploit for Unace v2.2
- Local PoC exploit terminatorX v3.81
- m00-mod_gzip.c
- MDKSA-2003:102 - Updated postgresql packages fix buffer overflow vulnerability
- MDKSA-2003:103 - Updated apache packages fix vulnerabilities
- MDKSA-2003:104 - Updated CUPS packages fix denial of service vulnerability
- MDKSA-2003:105 - Updated hylafax packages fix remote root vulnerability
- MDKSA-2003:106 - Updated fileutils and coreutils packages fix vulnerabilities
- MDKSA-2003:107 - Updated glibc packagess fix vulnerabilities
- MDKSA-2003:108 - Updated stunnel packagess fix vulnerabilities
- MDKSA-2003:109 - Updated gnupg packages fix vulnerability with ElGamal signing keys
- MHTML Redirection Leads to Downloading EXE and Executing
- Microsoft SharePoint Portal and Team Services
- Minor OpenSSH/pam vuln (non-exploitable)
- Monit 4.1 HTTP interface multiple security vulnerabilities
- MS03-048: Thor and unpatched?
- MSIE clientCaps "isComponentInstalled" and "getComponentVersion" registry information leakage
- MSN messenger improper file transfer ip-address field parsing
- multiple payload handling flaws in isakmpd
- Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)
- Multiple SQL Injection Vulnerabilities in Oracle Application Server 9i and RDBMS (#NISR05112003)
- Multiple vulnerability in NetServe 1.0.7
- nCUBE Server Manager
- New "Clean" IE Remote Compromise
- New version of ike-scan (IPsec IKE scanner) available - v1.5.1
- NIPrint remote exploit
- Nokia IPSO Script Injection Vulnerability leads to Passive Remote Root, via Network Voyager
- Note for "Invalid ContentType may disclose cache directory"
- NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability
- NSFOCUS SA2003-08: HP-UX libc NLSPATH Environment Variable Privilege Elevation Vulnerability
- OpenAutoClassifieds XSS attack
- OpenBSD kernel holes ...
- OpenLinux: Key validity bug in GnuPG 1.2.1 and earlier
- OpenLinux: Linux NFS utils package contains remotely exploitable off-by-one bug
- OpenLinux: Multiple vulnerabilities have reported in Ethereal 0.9.12
- OpenLinux: Sendmail prescan remotely exploitable vulnerability
- OpenLinux: ucd-snmp remote heap overflow
- OpenLinux: unzip directory traversal
- OpenLinux: Webmin/Usermin Session ID Spoofing Vulnerability
- OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7: Multiple vulnerabilities affecting several components of gwxlibs
- OpenServer 5.0.7 : OpenSSH: multiple buffer handling problems
- OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Perl cross-site scripting vulnerability.
- OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Various Apache security fixes
- Opera directory traversal and buffer overflow
- Opera Directory Traversal in Internal URI Protocol (Advisory)
- Opera Skinned & Opera Directory Traversal (Additional Details & a Simple Exploit)
- Opera Skinned : Arbitrary File Dropping And Execution (Advisory)
- PCL-0002: Session Hijacking in "Sqwebmail"
- PHP-Coolfile version 1.4 unauthorized access
- phpBB 2.06 search.php SQL injection
- PHPlist, file injection vulnerability
- phpWebFileManager v2.0.0 - Directory traversal
- Pieterpost - access to "vitual" account
- POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III
- PowerPortal v1.1b Cross-Site Scripting Vulnerability
- PrimeBase SQL Database server cleartext password storage. (fwd)
- Proof of concept for Windows Workstation Service overflow
- pServ 2.0.x:beta webserver remote buffer overflow exploit by jsk
- Quagga remote vulnerability
- R7-0016: Sybase ASE 12.5 Remote Password Array Denial of Service
- Remote DoS in FreeRADIUS, all versions.
- Remote execution in My_eGallery
- remote exploit for mod_gzip (with debug_mode)
- RNN's Guestbook 1.2 Multiple Vulnerabilities
- Rolis Guestbook v1.0 - PHP injection
- Root Directory Listing on RH default apache
- Router Worm?
- rpc remote return-into-libc exploit
- rpc.mountd Vulnerabilities on SGI IRIX
- SAP DB priv. escalation/remote code execution
- Secure Network Operations SRT2003-11-13-0218, PCAnywhere allows local users to become SYSTEM
- Security researchers organization
- Serious flaws in bluetooth security lead to disclosure of personal data
- SGI Advanced Linux Environment security update #5
- SGI ProPack v2.3 security update
- ShoutCast server 1.9.2/win32
- simple buffer overflow in gedit
- SIRCD: Anyone can set umode +o(oper).
- Six Step IE Remote Compromise Cache Attack
- Speedtouch 510 DOS
- SQL Injection
- sql injection in phpbb
- SRT2003-11-02-0115 - NIPrint LPD-LPR Remote overflow
- SRT2003-11-02-0218 - NIPrint LPD-LPR Local Help API SYSTEM exploit
- SRT2003-11-06-0710 - IBM DB2 Multiple local security issues
- SRT2003-11-11-1151 - clamav-milter remote exploit / DoS
- SRT2003-11-13-0218 - PCAnywhere local SYSTEM exploit
- SRT2003-TURKEY-DAY - *novelty* - detecttr.c Trace Route detection vulnerability
- Surfboard <= 1.1.8 vulns
- SUSE Security Announcement: bind8 (SuSE-SA:2003:047)
- SUSE Security Announcement: hylafax (SuSE-SA:2003:045)
- SUSE Security Announcement: sane (SuSE-SA:2003:046)
- Symbol Technologies Default WEP KEYS Vulnerability
- terminatorX 3.8.1 local vulnerabilities
- terminatorX stack-based overflow (exploit)
- The Developer Implications of Windows XP SP2
- Thomnson TCM315 Denial of service
- TSLSA-2003-0044 - bind
- TSLSA-2003-0045 - stunnel
- UnAce 2.20 Exploitable Stack-Based Overflow (exploit code)
- Unauthorized access in Web Wiz Forum
- Unhackable network really unhackable?
- Unichat Vulnerabilities
- UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : CDE libDtHelp buffer overflow
- UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.
- UPDATE: PSK Cracking using IKE Aggressive Mode
- Virtual Programming VP-ASP Shopping Cart 5.0 multiple SQL Injection Vulnerabilities
- VMWare GSX Server Authentication Server Buffer Overflow Vulnerability - Update
- Web Wiz Forums ver. 7.01
- webfs 1.7.x:webserver remote file overflow exploit (use ftpd to mkdir)
- Webwasher Classic Error-Message XSS Vulnerability
- Xitami Denial of Service in Handling malformed request
- YAK! 2.1.0 still vulnerable
- yet another panic() in OpenBSD
Last message date: Mon Dec 01 2003 - 13:01:31 CST
Archived on: Mon Dec 01 2003 - 13:01:32 CST
355 messages sorted by: [ author ] [ date ] [ thread ]
lists.debian.org