|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
355 messages sorted by: [ author ] [ date ] [ thread ]
Starting: Mon Sep 01 2008 - 13:21:19 CDT
Ending: Tue Sep 30 2008 - 17:41:17 CDT
- "Exploit creation - The random approach" or "Playing with random to build exploits"
- [ GLSA 200809-01 ] yelp: User-assisted execution of arbitrary code
- [ GLSA 200809-02 ] dnsmasq: Denial of Service and DNS spoofing
- [ GLSA 200809-03 ] RealPlayer: Buffer overflow
- [ GLSA 200809-04 ] MySQL: Privilege bypass
- [ GLSA 200809-05 ] Courier Authentication Library: SQL injection vulnerability
- [ GLSA 200809-06 ] VLC: Multiple vulnerabilities
- [ GLSA 200809-07 ] libTIFF: User-assisted execution of arbitrary code
- [ GLSA 200809-08 ] Amarok: Insecure temporary file creation
- [ GLSA 200809-09 ] Postfix: Denial of Service
- [ GLSA 200809-10 ] Mantis: Multiple vulnerabilities
- [ GLSA 200809-11 ] HAVP: Denial of Service
- [ GLSA 200809-12 ] Newsbeuter: User-assisted execution of arbitrary code
- [ GLSA 200809-13 ] R: Insecure temporary file creation
- [ GLSA 200809-14 ] BitlBee: Security bypass
- [ GLSA 200809-15 ] GNU ed: User-assisted execution of arbitrary code
- [ GLSA 200809-16 ] Git: User-assisted execution of arbitrary code
- [ GLSA 200809-17 ] Wireshark: Multiple Denials of Service
- [ GLSA 200809-18 ] ClamAV: Multiple Denials of Service
- [ MDVSA-2008:182 ] wordnet
- [ MDVSA-2008:182-1 ] wordnet
- [ MDVSA-2008:183 ] opensc
- [ MDVSA-2008:184 ] libtiff
- [ MDVSA-2008:185 ] python-django
- [ MDVSA-2008:186 ] python
- [ MDVSA-2008:188 ] tomcat5
- [ MDVSA-2008:189 ] clamav
- [ MDVSA-2008:189-1 ] clamav
- [ MDVSA-2008:190 ] postfix
- [ MDVSA-2008:191 ] rsh
- [ MDVSA-2008:192 ] libxml2
- [ MDVSA-2008:193 ] kolab-server
- [ MDVSA-2008:194 ] apache2
- [ MDVSA-2008:195 ] apache
- [ MDVSA-2008:196 ] mplayer
- [ MDVSA-2008:197 ] koffice
- [ MDVSA-2008:197-1 ] koffice
- [ MDVSA-2008:198 ] R-base
- [ MDVSA-2008:199 ] wireshark
- [ MDVSA-2008:200 ] ed
- [ MDVSA-2008:201 ] pan
- [ MDVSA-2008:202 ] phpMyAdmin
- [ MDVSA-2008:203 ] awstats
- [ MDVSA-2008:204 ] blender
- [ MDVSA-2008:205 ] mozilla-firefox
- [ MDVSA-2008:206 ] mozilla-thunderbird
- [ MDVSA-2008:207 ] openafs
- [ MDVSA-2008:208 ] pam_mount
- [AJECT] Softalk IMAP Server 8.5.1 DoS vulnerability
- [AJECT] SurgeMail IMAP 3.9e vulnerability
- [ECHO_ADV_101$2008] Attachmax Dolphin <= 2.1.0 Multiple Vulnerabilities
- [Full-disclosure] [IVIZ-08-010] McAfee SafeBoot Device Encryption Plain Text Password Disclosure (v4, Build 4750 and below)
- [MajorSecurity Advisory #53]BLUEPAGE CMS - Cross Site Scripting and Session Fixation Issues
- [MajorSecurity Advisory #54]xt:Commerce - Cross Site Scripting and Session Fixation Issues
- [MajorSecurity Advisory #56]moziloWiki - Directory Traversal, XSS and SessionFixation Issues
- [NOBYTES.COM: #12] osCommerce 2.2rc2a - Information Disclosure
- [NOBYTES.COM: #13] Quick.Cart v3.1 Freeware - Cross Site Scripting
- [NOBYTES.COM: #14] Quick.Cms.Lite v2.1 Freeware - Cross Site Scripting
- [oCERT-2008-012] Horde, Popoon frameworks common input sanitization errors (XSS)
- [oCERT-2008-013] MPlayer Real demuxer heap overflow
- [oCERT-2008-014] WordNet stack and heap overflows
- [scip_Advisory 3808] D-Link DIR-100 long url filter evasion
- [scip_Advisory 3809] Pro2col StingRay FTS login username cross site scripting
- [security bulletin] HPSBMA02361 SSRT080119 rev.1 - HP OpenView Select Identity Connectors running on Windows, Local Information Disclosure
- [security bulletin] HPSBMA02362 SSRT080044, SSRT080045 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)
- [security bulletin] HPSBMA02369 SSRT080115 rev.1 - HP ProLiant Essentials Rapid Deployment Pack (RDP) Running Symantec Altiris Deployment Solution, Remote SQL Injection, Remote or Local Gain Extended Privileges, Local Denial of Service (DoS)
- [security bulletin] HPSBMA02373 SSRT071467 rev.1 - HP Insight Diagnostics, Remote Unauthorized Access to Files
- [security bulletin] HPSBOV02364 SSRT080078 rev.1 - HP OpenVMS SMGRTL Run Time Library, Local Authorized User, Gain Privileged Access
- [security bulletin] HPSBOV02364 SSRT080078 rev.2 - HP OpenVMS SMGRTL Run Time Library, Local Authorized User, Gain Privileged Access
- [security bulletin] HPSBOV02364 SSRT080078 rev.3 - HP OpenVMS SMGRTL Run Time Library, Local Authorized User, Gain Privileged Access
- [security bulletin] HPSBST02372 SSRT080133 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-052 to MS08-055
- [security bulletin] HPSBUX02370 SSRT071459 rev.1 - HP-UX Running rpcbind, Remote Denial of Service (DoS)
- [SECURITY] [DSA 1627-2] New opensc package fix incomplete check
- [SECURITY] [DSA 1633-1] New slash packages fix multiple vulnerabilities
- [SECURITY] [DSA 1634-1] New wordnet packages fix arbitrary code execution
- [SECURITY] [DSA 1634-2] New wordnet packages fix regression
- [SECURITY] [DSA 1635-1] New freetype packages fix multiple vulnerabilities
- [SECURITY] [DSA 1636-1] New Linux 2.6.24 packages fix several vulnerabilities
- [SECURITY] [DSA 1637-1] New git-core packages fix buffer overflow
- [SECURITY] [DSA 1638-1] New openssh packages fix denial of service
- [SECURITY] [DSA 1639-1] New twiki packages execution of arbitrary code
- [SECURITY] [DSA 1640-1] New python-django packages fix cross site request forgery
- [SECURITY] [DSA 1641-1] New phpmyadmin packages fix several issues
- [SECURITY] [DSA 1642-1] New horde3 packages fix cross site scripting
- [SECURITY] [DSA-1619-2] New python-dns package fixes regression
- [SECURITY] CVE-2008-2938 - Apache Tomcat information disclosure vulnerability - Updated
- [Suspected Spam][CVE-2008-4042] Postfix Linux-only local denial of service - PoC
- [Suspected Spam]New IETF I-D-: Security Assessment of the Internet Protocol version 4
- [TKADV2008-007] Linux Kernel SCTP-AUTH API Information Disclosure Vulnerability and NULL Pointer Dereferences
- [Tool] Distack framework for attack detection and traffic analysis
- [Tool] sqlmap 0.6 released
- [USN-639-1] tiff vulnerability
- [USN-640-1] libxml2 vulnerability
- [USN-641-1] Racoon vulnerabilities
- [USN-642-1] Postfix vulnerabilities
- [USN-643-1] FreeType vulnerabilities
- [USN-644-1] libxml2 vulnerabilities
- [USN-645-1] Firefox and xulrunner vulnerabilities
- [USN-645-2] Firefox vulnerabilities
- [USN-645-3] Firefox and xulrunner regression
- [USN-646-1] rdesktop vulnerabilities
- [USN-647-1] Thunderbird vulnerabilities
- [USN-648-1] nasm vulnerability
- [WEB SECURITY] PR08-20: Bypassing ASP .NET "ValidateRequest" for Script Injection Attacks
- adnforum <= 1.0b / Insecure Cookie Handling Vulnerability
- Advanced Electron Forum <= 1.0.6 Remote Code Execution
- Advisory 04/2008: Joomla Weak Random Password Reset Token Vulnerability
- Advisory 05/2008: Wordpress user_login Column SQL Truncation Vulnerability
- Advisory : Google Chrome Carriage Return Null Object Memory Exhaustion Remote Dos.
- Advisory : Opera Window Object Suppressing Remote Denial of Service
- Advisory: Google Chrome Window Object Suppressing Remote Denial of Service.
- Advisory: Mozilla Firefox User Interface Null Pointer Dereference Dispatcher Crash and Remote Denial of Service.
- Annutel - Annuaire Téléphonique v1.0 Sensetive Files (MDP)
- Aruba Mobility Controller Shared Default Certificate
- Aruba Mobility Controller Shared Default Certificate - Response from Aruba Networks
- ASP News Remote Password Disclouse Vulnerability
- Atheros Vendor Specific Information Element Overflow
- Autodesk DWF Viewer Control / LiveUpdate Module remote code execution exploit
- Avant Browser <= 11.7 Build 9 Integer Denial Of Service Exploit
- Baidu Hi IM client software DoS bug, div zero make client crash
- Baidu Hi IM software parsing plaintext stack overflow
- Blue Coat xss
- C4 Security Advisory - ABB PCU400 4.4-4.6 Remote Buffer Overflow
- CA Service Desk Multiple Cross-Site Scripting Vulnerabilities
- Chrome(0.2.149.27) title(not the tag) Denial of Service(Freeze) exploit
- Cisco Secure ACS Denial Of Service Vulnerability
- Cisco Secure ACS EAP Parsing Vulnerability
- Cisco Security Advisory: Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
- Cisco Security Advisory: Cisco IOS IPS Denial of Service Vulnerability
- Cisco Security Advisory: Cisco IOS MPLS Forwarding Infrastructure Denial of Service Vulnerability
- Cisco Security Advisory: Cisco IOS MPLS VPN May Leak Information
- Cisco Security Advisory: Cisco IOS NAT Skinny Call Control Protocol Vulnerability
- Cisco Security Advisory: Cisco IOS Software Firewall Application Inspection Control Vulnerability
- Cisco Security Advisory: Cisco IOS Software Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
- Cisco Security Advisory: Cisco uBR10012 Series Devices SNMP Vulnerability
- Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities
- Cisco Security Advisory: Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
- Cisco Security Advisory: Multiple Multicast Vulnerabilities in Cisco IOS Software
- Cisco Security Advisory: Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA
- Cisco Security Advisory: Vulnerability in Cisco IOS While Processing SSL Packet
- clamav: Crash with crafted chm, CVE-2008-1389
- Clients format strings in the Unreal engine
- community real-time BGP hijack notification service
- CORE-2008-0126: iPhone Safari JavaScript alert Denial of Service
- Crashing ZoneAlarm 8.0.020.000 by Checkpoint (Component : TrueVector)
- Critical Vulnerability in Apple Quicktime’s Indeo Codec
- Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120
- Cross Site Scripting (XSS) Vulnerabilitiy in fuzzylime (cms) >=3.02, CVE-2008-3098
- Crux Gallery <= 1.32 / Insecure Cookie Handling Vulnerability
- CS-Cart <= 1.3.5 SQL Injection
- csphonebook 1.02 Remote XSS Vulnerabilitiy
- cyask 3.x Local File Inclusion Vulnerability
- DATAC RealWin 2.0 SCADA Software - Remote PreaAuth Exploit
- DeepSec 2008 - Conference Schedule
- DEFCON London - DC4420 - September meet this Thursday 11th
- Directory traversal in the webadmin of Unreal Tournament 3 1.3
- Drupal Ajax Checklist Module SQL Injection Vulnerability
- Drupal Brilliant Gallery module SQL injection vulnerability
- drupal: Session hijacking vulnerability, CVE-2008-3661
- E-Php B2B Trading Marketplace(cid) Remote SQL Injection Vulnerability
- Estonian Cyber Security Strategy document -- now available online
- Exploit
- Ezphotogallery 2.1 Multiple Vulnerabilities ( Xss/Login Bypass/Sql injection Exploit/File Disclosure)
- Failed assertion in the Unreal engine
- FreeBSD Security Advisory FreeBSD-SA-08:07.amd64
- FreeBSD Security Advisory FreeBSD-SA-08:08.nmount
- FreeBSD Security Advisory FreeBSD-SA-08:09.icmp6
- FtitzBox
- Fwd: Returned post for bugtraq<img src="/imgs/at.gif" border=0 align=middle>securityfocus.com
- Google Chrome 0.2.149.27 'SaveAs' Function Buffer Overflow Vulnerability
- Google Chrome Auto download exploit ..
- Google Chrome Automatic File Download
- Google Chrome Browser (ver.0.2.149.27) Vulnerability
- Google Docs (HTML code) Multiple Cross Site Scripting Vulnerabilities
- Has anyone implemented "double forward DNS"?
- Hi Two Points to consider
- HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)
- hyBook Remote Password Disclouse Vulnerability
- IAS Helper COM Component (iashlpr.dll) activex remote DOS
- iDefense Security Advisory 09.09.08: Apple QuickTime PICT Integer Overflow Vulnerability
- iDefense Security Advisory 09.09.08: Microsoft Windows GDI+ Gradient Fill Heap Overflow Vulnerability
- In search of examples of malicious source code
- Insomnia : ISVA-080910.1 - MS Office OneNote URL Handling Vulnerability
- InstallShield Update Agent - Downloads and executes "Rule Scripts" insecurely.
- International Hacking & Security Conference "POC2008"
- Internet Information Service (adsiis.dll) activex remote DOS
- Internet Information Service remote set password
- Linksys/Cisco WRT350N 1.0.3.7 Insecure Samba Static Configuration
- Login Password Sample Remote Password Disclouse Vulnerability
- LooYu Web IM 2008 Cross-Site Scripting Vulnerabilities
- MapCal - The Mapping Calendar (v. 0.1) Remote SQL Injection
- Marvell Driver EAPoL-Key Length Overflow
- Marvell Driver Null SSID Association Request Vulnerability
- menalto gallery: Session hijacking vulnerability, CVE-2008-3102
- menalto gallery: Session hijacking vulnerability, CVE-2008-3102)
- menalto gallery: Session hijacking vulnerability, CVE-2008-3662
- Microsoft Internet Explorer DoS in Rendering Malicious PNG Files.
- Microsoft Windows WRITE_ANDX SMB command handling Kernel DoS
- minb Remote Code Execution Exploit
- Miranda IM Client Password Disclosure Vulnerability.
- MS Internet Explorer 7 Denial Of Service Exploit
- Multiple Cross Site Scripting (XSS) and SQL injection Vulnerabilities in XRMS, CVE-2008-3664
- Multiple Cross Site Scripting (XSS) Vulnerabilities in vtigerCRM 5.0.4, CVE-2008-3101
- Multiple MicroWorld products insecure directory permissions
- multiple vendor ftpd - Cross-site request forgery
- Multiple Vulnerabilities: LedgerSMB < 1.2.15
- MyFWB 1.0 Remote SQL Injection
- MySQL command-line client HTML injection vulnerability
- Nooms 1.1
- Novell ZENWorks for Desktops Version 6.5 Remote (Heap-Based) PoC
- OpenWiki<--v0.78 Cross-Site Scripting
- Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy
- other google chrome crash
- ParsaWeb CMS SQL Injection
- PHP Calendar Script Remote XSS (Permanent) Vulnerabilities
- php create_function commond injection vulnerability
- PHP pro bid v 6.04 SQL injection
- phpAdultSite CMS flaws
- PhpWebGallery 1.3.4 Multiple Vulnerabilities (XSS/LFI)
- PhsBlog v0.2 Bypass Sql injection Filtering Exploit
- Pidgin IM Client Password Disclosure Vulnerability.
- Plesk 8.6.0 authentication flaw allows to gain virtual user priviledges
- PoCfix (PoC for Postfix local root vuln - CVE-2008-2936)
- Postfix Linux-only local denial of service
- Remote File Inclusion Vulnerability
- RES: Google Chrome Automatic File Download
- Risky Chrome (The perfect cleartext password offering )
- RPG.Board <= 0.0.8Beta2 Remote SQL Injection
- rPSA-2008-0264-1 ruby
- rPSA-2008-0268-1 libtiff
- rPSA-2008-0276-1 mercurial mercurial-hgk
- rPSA-2008-0278-1 tshark wireshark
- rPSA-2008-0286-1 mono
- RUXCON 2008 Final Call For Papers
- Sagem Router F<img src="/imgs/at.gif" border=0 align=middle>ST 2404 Remote Denial Of Service Exploit
- Sama XSS Bug
- Secunia Research: Novell iPrint Client nipplib.dll "IppCreateServerRef()" Buffer Overflow
- Secunia Research: Trend Micro OfficeScan "cgiRecvFile.exe" Buffer Overflow
- SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability
- Security flaw in Airtel DSL modems
- Server termination in the Unreal engine 3
- ShmooCon 2009 CFP
- shoutbox Remote Password Disclouse Vulnerability
- Skype IM Client Password Disclosure Vulnerability.
- SQL Injection in EasyRealtorPRO 2008
- SQL Smuggling
- sqlvdir.dll ActiveX Remote Buffer Overflow Exploit
- Squirrelmail: Session hijacking vulnerability, CVE-2008-3663
- Stash v1.0.3 Admin bypass / Remote File Disclosure
- Sun M-class hardware denial of service
- T2´08 Challenge - Free Tickets Available
- Team SHATTER Security Advisory: IBM DB2 UDB - Buffer overrun in XMLQUERY and XMLEXISTS
- Team SHATTER Security Advisory: Security Vulnerability in CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio
- The Gemini Portal <= 4.7 / Insecure Cookie Handling Vulnerability
- ToorCon X Lineup & Training Seminars Posted & Pre-Registration Ending
- TPTI-08-06: Landesk QIP Server Service Heal Packet Buffer Overflow
- TransLucid 1.75 (fckeditor) Remote Arbitrary File Upload
- Verizon FIOS (and DSL?) wireless access point insecure default WEP key
- vi can run arbitrary commands via 'tags' file
- VMSA-2008-0015 Updated ESXi and ESX 3.5 packages address critical security issue in openwsman
- WASC Announcement: 2007 Web Application Security Statistics Published
- White Wolf Labs #080922-1: Exploitation Through ActiveSync 4.x
- Windows GDI+ GIF memory corruption
- WordPress MU < 2.6 wpmu-blogs.php Crose Site Scrpting vulnerability
- XCon 2008 Call for Paper
- xoops-1.3.10 shell command execute vulnerability ( causing snoopy class )
- Xss In Datalife Engine CMS 7.2
- xss in hackmeeting.org
- ZDI-08-055: Microsoft Windows GDI+ BMP Parsing Code Execution Vulnerability
- ZDI-08-056: Microsoft Windows GDI+ GIF Parsing Code Execution Vulnerability
- ZDI-08-057: Apple QuickTime IV32 Codec Parsing Stack Overflow Vulnerability
- ZDI-08-058: Apple QuickTime Panorama PDAT Atom Parsing Buffer Overflow Vulnerability
- ZDI-08-059: Apple QuickTime STSZ Atom Parsing Heap Corruption Vulnerability
- ZDI-08-060: Apple QuickTime AVC1 Atom Parsing Heap Overflow Vulnerability
- ZDI-08-061: Apple QuickTime Player H.264 Parsing Heap Corruption Vulnerability
- ZDI-08-062: Apple QuickTime MDAT Frame Parsing Memory Corruption Vulnerability
- Zen Cart <= 1.3.8a SQL Injection
- ZoneAlarm Security Suite buffer overflow
Last message date: Tue Sep 30 2008 - 17:41:17 CDT
Archived on: Tue Sep 30 2008 - 17:41:20 CDT
355 messages sorted by: [ author ] [ date ] [ thread ]
mandriva.com