| Author | Subject | Date |
| 3APA3A |
| | Re: Apache web server 2.2: htpasswd predictable salt weakness | 15 Feb 2008 |
| Aaron Collins |
| | Re: PIX Privilege Escalation Vulnerability | 25 Feb 2008 |
| Adam Laurie |
| | Announce: RFIDIOt credit card sub-module: ChAP.py | 21 Feb 2008 |
| admin_at_nospam |
| | aeries browser interface(ABI) 3.8.2.8 Remote SQL Injection | 21 Feb 2008 |
| | aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection | 21 Feb 2008 |
| | aeries browser interface(ABI) 3.8.2.8 XSS | 21 Feb 2008 |
| alex_zooz_zooz_at_nospam |
| | Joomla <= v1.0.14-RC1(Index.php) Remote File Inclusion Exploit | 08 Feb 2008 |
| amarkov_at_nospam |
| | Re: Nortel IP Phone DoS | 26 Feb 2008 |
| Amit Klein |
| | RE: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability" | 06 Feb 2008 |
| | A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability" | 06 Feb 2008 |
| Anurag Agarwal |
| | Certification for Web Application Security Professionals | 21 Feb 2008 |
| beenudel1986_at_nospam |
| | phpechocms v 2.0 rc3 RFI | 23 Feb 2008 |
| brad.antoniewicz_at_nospam |
| | Beehive/SendFile.NET - Secure File Transfer Appliance Hardcoded Credentials | 29 Feb 2008 |
| Brendan Dolan-Gavitt |
| | Tool release: extract Windows credentials from registry hives | 21 Feb 2008 |
| Brook Powers |
| | SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability | 08 Feb 2008 |
| Bug traq |
| | RE: ASUS Eee PC rooted out of the box | 08 Feb 2008 |
| Chris Evans |
| | Ghostscript buffer overflow | 28 Feb 2008 |
| | Sun JRE / JDK bug introduces XXE possibilities | 02 Feb 2008 |
| Cisco Systems Product Security Incident Response Team |
| | Cisco Security Advisory: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities | 13 Feb 2008 |
| | Cisco Security Advisory: SQL injection in Cisco Unified Communications Manager | 13 Feb 2008 |
| ciucciamilcalzino_at_nospam |
| | Youtube Clone Xross Site Scripting (load_message.php) | 01 Feb 2008 |
| cmiyazaki_at_nospam |
| | Re: SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability | 14 Feb 2008 |
| cocoruder |
| | Adobe Reader/Acrobat Remote PDF Print Silently Vulnerability | 08 Feb 2008 |
| CORE Security Technologies Advisories |
| | CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability | 04 Feb 2008 |
| crazy_kinq_at_nospam |
| | Netkom Internet Solutions (folder_id) Remote SQL Injection Vulnerability | 13 Feb 2008 |
| | Joovili <= v.2.1 (members_help.php) Remote File İnclude Vulnerability | 07 Feb 2008 |
| | Blackboard (id) Remote SQL Injection | 07 Feb 2008 |
| | Husrev Forums v2.0.1:PoWerBoard (tr) (id) Remote SQL Injection | 07 Feb 2008 |
| cybermilitan_at_nospam |
| | ITech Classifieds Multiple Remote Vulnerabilities | 01 Feb 2008 |
| | Domain Trader v2.0 Xss Vulnerable | 02 Feb 2008 |
| CYBSEC Advisories |
| | CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator / Documentum Webtop | 05 Feb 2008 |
| Daniel Roethlisberger |
| | Urulu 2.1 Blind SQL Injection Vulnerability (CVE-2008-0385) | 28 Feb 2008 |
| dann frazier |
| | [SECURITY] [DSA 1505-1] New alsa-driver packages fix kernel memory leak | 22 Feb 2008 |
| | [SECURITY] [DSA 1504-1] New Linux kernel 2.6.8 packages fix several issues | 22 Feb 2008 |
| | [SECURITY] [DSA 1503-1] New Linux kernel 2.4.27 packages fix several issues | 22 Feb 2008 |
| | [SECURITY] [DSA 1494-2] New linux-2.6 packages fix privilege escalation | 13 Feb 2008 |
| Danux |
| | Bypassing OfficeScan Trend Micro AV | 26 Feb 2008 |
| david.reguera_at_nospam |
| | ELFdump crash when analyzing crafted ELF file. | 13 Feb 2008 |
| david130490_at_nospam |
| | Re: Buffer Overflow Vulnerability in AxRUploadServer.dll, Activex Method (SetLogging) | 08 Feb 2008 |
| | Buffer Overflow Vulnerability in AxRUploadServer.dll, Activex Method (SetLogging) | 08 Feb 2008 |
| db_at_nospam |
| | netOffice Dwins 1.3 Remote code execution. | 29 Feb 2008 |
| | my little forum XSS | 12 Feb 2008 |
| dcid_at_nospam |
| | Re: Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management) | 25 Feb 2008 |
| dean_at_nospam |
| | Re: etomite xss | 18 Feb 2008 |
| Dominique Karg |
| | Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management) | 22 Feb 2008 |
| eagle |
| | DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks | 14 Feb 2008 |
| | DOINGSOFT-2008-02-11 - IPDiva VPN SSL Brute force attack | 14 Feb 2008 |
| ekoparty |
| | CFP - ekoparty 4th edition | 27 Feb 2008 |
| enterth3dragon_at_nospam |
| | Simple Machines Forum "SMF Shoutbox" Mod Persistent XSS | 10 Feb 2008 |
| f10_at_nospam |
| | Re: 123 Flash Chat Module for phpBB | 28 Feb 2008 |
| | 123 Flash Chat Module for phpBB | 28 Feb 2008 |
| | Xoops-2.0.16 Remote File Inclusion | 19 Feb 2008 |
| | hi | 10 Feb 2008 |
| Florian Weimer |
| | [SECURITY] [DSA 1499-1] New pcre3 packages fix arbitrary code execution | 19 Feb 2008 |
| | [SECURITY] [DSA 1494-1] New linux-2.6 packages fix privilege escalation | 11 Feb 2008 |
| forensec_at_nospam |
| | gkrellweather | 11 Feb 2008 |
| Foresight Linux Essential Announcement Service |
| | FLEA-2008-0007-1 gd | 12 Feb 2008 |
| | FLEA-2008-0001-1 firefox | 12 Feb 2008 |
| | FLEA-2008-0005-1 e2fsprogs | 12 Feb 2008 |
| | FLEA-2008-0004-1 rsync | 12 Feb 2008 |
| | FLEA-2008-0003-1 nss_ldap | 12 Feb 2008 |
| | FLEA-2008-0002-1 python | 12 Feb 2008 |
| | FLEA-2008-0006-1 tetex tetex-dvips tetex-fonts | 12 Feb 2008 |
| FreeBSD Security Advisories |
| | FreeBSD Security Advisory FreeBSD-SA-08:04.ipsec | 14 Feb 2008 |
| | FreeBSD Security Advisory FreeBSD-SA-08:03.sendfile | 14 Feb 2008 |
| goldshlager19_at_nospam |
| | IBM Quickr 8 Calendar Xss Injection (Bypass Quickr 8.0 Xss Filter) | 22 Feb 2008 |
| gregory |
| | Re: rPSA-2008-0052-1 kernel | 13 Feb 2008 |
| Gynvael Coldwind |
| | [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service | 16 Feb 2008 |
| hackturkiye.hackturkiye_at_nospam |
| | joomla com_simpleshop SQL Injection(section) # | 24 Feb 2008 |
| | joomla com_wines SQL Injection(id) | 24 Feb 2008 |
| | joomla com_garyscookbook SQL Injection(id) | 24 Feb 2008 |
| | php-nuke Quran SQL Injection(surano) | 23 Feb 2008 |
| | aura cms lihatberita SQL Injection(id) | 23 Feb 2008 |
| | php nuke Sections SQL Injection(print) | 23 Feb 2008 |
| | php-nuke Kuran SQL Injection(surano) | 23 Feb 2008 |
| | php nuke gallery SQL Injection(aid) | 23 Feb 2008 |
| | php-nuke Recipes SQL Injection(recipeid) | 23 Feb 2008 |
| | joomla com_hello_world SQL Injection(id) | 23 Feb 2008 |
| | joomla com_product SQL Injection(catid) | 23 Feb 2008 |
| | joomla SQL Injection(com_cms) | 21 Feb 2008 |
| | joomla SQL Injection(com_asortyment)katid | 21 Feb 2008 |
| | XOOPS Module prayerlist SQL Injection(cid) | 21 Feb 2008 |
| | joomla SQL Injection(com_most)secid | 21 Feb 2008 |
| | PHP-Nuke Module Downloads SQL Injection(sid) | 21 Feb 2008 |
| | joomla SQL Injection(com_mygallery) | 21 Feb 2008 |
| | PHP-Nuke Module Dossiers Injection(did) | 21 Feb 2008 |
| | PHP-Nuke genaral print SQL Injection(id) | 21 Feb 2008 |
| | XOOPS Module tinyevent-print SQL Injection(id) | 21 Feb 2008 |
| | PHP-Nuke Siir SQL Injection(id) | 21 Feb 2008 |
| | joomla SQL Injection(com_idvnews) | 21 Feb 2008 |
| | PHP-Nuke Module BenchmarkNewsInjection(sid) | 21 Feb 2008 |
| | joomla SQL Injection(com_joomlavvz) | 21 Feb 2008 |
| | joomla SQL Injection(com_referenzen) | 21 Feb 2008 |
| | PHP-Nuke Module Classifieds SQL Injection(Details) | 21 Feb 2008 |
| | joomla SQL Injection(com_asortyment)katid | 21 Feb 2008 |
| | PHP-Nuke Module Web_Links SQL Injection(cid) | 19 Feb 2008 |
| | XOOPS Module eEmpregos SQL Injection(cid) | 19 Feb 2008 |
| | XOOPS Module classifieds SQL Injection(cid) | 19 Feb 2008 |
| | joomla SQL Injection(com_magazine) | 18 Feb 2008 |
| | XOOPS Module seminars SQL Injection | 19 Feb 2008 |
| | joomla SQL Injection(com_foevpartners) | 18 Feb 2008 |
| | XOOPS Module events SQL Injection | 19 Feb 2008 |
| | XOOPS Module badliege SQL Injection | 19 Feb 2008 |
| | XOOPS Module vacatures SQL Injection | 19 Feb 2008 |
| | joomla SQL Injection(com_genealogy) | 18 Feb 2008 |
| | joomla SQL Injection(com_listoffreeads) | 18 Feb 2008 |
| | joomla SQL Injection(com_facileforms) | 18 Feb 2008 |
| | joomla SQL Injection(com_geoboerse) | 18 Feb 2008 |
| | joomla SQL Injection(com_team | 18 Feb 2008 |
| | joomla SQL Injection(com_iigcatalog) | 18 Feb 2008 |
| | XOOPS Module myTopics-print SQL Injection(articleid) | 18 Feb 2008 |
| | joomla SQL Injection(com_detail) | 18 Feb 2008 |
| | joomla SQL Injection(com_formtool) | 18 Feb 2008 |
| | XOOPS Module section SQL Injection(articleid) | 18 Feb 2008 |
| | (tip=sollinkicerik)SQL Injection Vulnerability | 16 Feb 2008 |
| | joomla SQL Injection (cat)(com_downloads) | 16 Feb 2008 |
| | Wordpress Plugin (wp-people) SQL Injection | 16 Feb 2008 |
| | joomla SQL Injection(com_ricette) | 16 Feb 2008 |
| | joomla SQL Injection(com_jooget) | 16 Feb 2008 |
| | WordPress SQL Injection(wp-content-simple-forum) | 16 Feb 2008 |
| | joomla SQL Injection(com_galeria) | 16 Feb 2008 |
| | joomla SQL Injection(com_filebase) | 16 Feb 2008 |
| | joomla SQL Injection(com_detail) | 16 Feb 2008 |
| | Wordpress Plugin (wp-content/recipe) SQL Injection | 16 Feb 2008 |
| | joomla SQL Injection(com_profile) | 16 Feb 2008 |
| | WordPress forumaction (PAGE_id)(user)SQL Injection | 16 Feb 2008 |
| | joomla SQL Injection(com_emcompose) | 16 Feb 2008 |
| | joomla SQL Injection(com_sg) | 15 Feb 2008 |
| | joomla SQL Injection(com_filebase) | 15 Feb 2008 |
| | joomla SQL Injection(com_lexikon) | 15 Feb 2008 |
| | joomla SQL Injection( com_scheduling) | 16 Feb 2008 |
| | joomla SQL Injection(com_salesrep) | 15 Feb 2008 |
| | Simple Forum Version 1.7-1.9(pagename) | 15 Feb 2008 |
| | all version Wordpress FORUM S@L injection | 15 Feb 2008 |
| | joomla faq SQL Injection | 13 Feb 2008 |
| | joomla com_activities sql injection | 13 Feb 2008 |
| | Ecommerce Websites from b1st.com SQL Injection | 15 Feb 2008 |
| | joomla "com_smslist" sql injecton | 15 Feb 2008 |
| | Simple Forum Version 1.10-1.11 SQL Injection | 15 Feb 2008 |
| | SellOwnHouse login SQL Injection | 13 Feb 2008 |
| | joomla "com_omnirealestate" S@L Injection | 13 Feb 2008 |
| | joomla "com_model" | 13 Feb 2008 |
| | joomla upload php code or picture (com_uhp) | 13 Feb 2008 |
| | all forums.asp hack | 13 Feb 2008 |
| | Provided By Development Solutions SQL Injection Exploit(panel) | 13 Feb 2008 |
| | joomll(k12.tr)(com_mezun)SQL Injection | 12 Feb 2008 |
| | Kommentare zum Download script SQL Injection | 12 Feb 2008 |
| | joomla (k12.tr)(com_iomezun)SQL Injection | 12 Feb 2008 |
| hadihadi_zedehal_2006_at_nospam |
| | artmedic_weblog Cross Site Scriptting Vulnerbility | 15 Feb 2008 |
| Hamza Almersoumi |
| | Softbiz jokes and funny pictures (index.php) sql injection | 24 Feb 2008 |
| Hendrik Jan Verheij |
| | Joomla 1.0.13 - 1.0.14 / (remote) PHP file inclusion possible if old configuration.php | 14 Feb 2008 |
| Hernan Ochoa |
| | Release: Pass-The-Hash toolkit v1.3 | 29 Feb 2008 |
| hk_at_nospam |
| | Re: PR07-38: XSS on sIFR | 05 Feb 2008 |
| houssamix_at_nospam |
| | PKs Movie Database version 3.0.3 (SQL/XSS) | 09 Feb 2008 |
| iDefense Labs |
| | iDefense Security Advisory 02.26.08: Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability | 27 Feb 2008 |
| | iDefense Security Advisory 02.26.08: Symantec Scan Engine 5.1.2 RAR File Buffer Overflow Vulnerability | 26 Feb 2008 |
| | iDefense Security Advisory 02.26.08: Symantec Scan Engine 5.1.2 RAR File Denial of Service Vulnerability | 26 Feb 2008 |
| | Re: iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities | 20 Feb 2008 |
| | iDefense Security Advisory 02.20.08: Symantec Veritas Storage Foundation Scheduler Service DoS Vulnerability | 21 Feb 2008 |
| | iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities | 20 Feb 2008 |
| | iDefense Security Advisory 02.12.08: Adobe Flash Media Server 2 Memory Corruption Vulnerability | 13 Feb 2008 |
| | iDefense Security Advisory 02.12.08: Adobe Flash Media Server 2 Multiple Integer Overflow Vulnerabilities | 13 Feb 2008 |
| | iDefense Security Advisory 02.12.08: Microsoft Office Works Converter Heap Overflow Vulnerability | 12 Feb 2008 |
| | iDefense Security Advisory 02.12.08: Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability | 13 Feb 2008 |
| | iDefense Security Advisory 02.12.08: Microsoft Internet Explorer Property Memory Corruption Vulnerability | 13 Feb 2008 |
| | iDefense Security Advisory 02.12.08: ClamAV libclamav PE File Integer Overflow Vulnerability | 12 Feb 2008 |
| | iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat Multiple Stack-based Buffer Overflow Vulnerabilities | 09 Feb 2008 |
| | iDefense Security Advisory 02.08.08: Adobe Reader Security Provider Unsafe Libary Path Vulnerability | 09 Feb 2008 |
| | iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat JavaScript Insecure Method Exposure Vulnerability | 09 Feb 2008 |
| | iDefense Security Advisory 02.07.08: IBM DB2 Universal Database Administration Server Memory Corruption Vulnerability | 07 Feb 2008 |
| | iDefense Security Advisory 02.07.08: IBM DB2 Universal Database db2pd Arbitrary Library Loading Vulnerability | 07 Feb 2008 |
| | iDefense Security Advisory 02.04.08: Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability | 06 Feb 2008 |
| | iDefense Security Advisory 01.31.08: IBM Informix Dynamic Server SQLIDEBUG File Creation Vulnerability | 04 Feb 2008 |
| | iDefense Security Advisory 01.31.08: IBM Informix Dynamic Server onedcu File Creation Vulnerability | 04 Feb 2008 |
| info_at_nospam |
| | LiveCart XSS vulnerability fixed since version 1.1.0 | 01 Feb 2008 |
| infocus |
| | [INFIGO-2008-02-13]: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability | 15 Feb 2008 |
| IOActive Advisories |
| | IOActive Security Advisory: Multiple Remote SiteScope Vulnerabilities | 12 Feb 2008 |
| | IOActive Security Advisory: Legacy mod_jk2 Buffer Overflow | 12 Feb 2008 |
| ivangaravito_at_nospam |
| | Re: Tested on Webmin 1.390 | 06 Feb 2008 |
| Jacob Appelbaum |
| | Re: Loginwindow.app and Mac OS X | 29 Feb 2008 |
| | Loginwindow.app and Mac OS X | 28 Feb 2008 |
| | Cold Boot Attacks on Disk Encryption | 22 Feb 2008 |
| jamboomla_at_nospam |
| | Re: Mambo 4.6.3 Path Disclosure, XSS , XSRF, DOS | 27 Feb 2008 |
| Jamie Strandboge |
| | [USN-582-1] Thunderbird vulnerabilities | 29 Feb 2008 |
| | [USN-580-1] libcdio vulnerability | 21 Feb 2008 |
| | [USN-579-1] Qt vulnerability | 21 Feb 2008 |
| | [USN-578-1] Linux kernel vulnerabilities | 14 Feb 2008 |
| | [USN-576-1] Firefox vulnerabilities | 08 Feb 2008 |
| | [USN-575-1] Apache vulnerabilities | 05 Feb 2008 |
| jfvanmeter_at_nospam |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| Jon R. Kibler |
| | Academic Computer Security Conference | 21 Feb 2008 |
| jyvaeskylae_at_nospam |
| | Re: artmedic_weblog Cross Site Scriptting Vulnerbility | 15 Feb 2008 |
| Kees Cook |
| | [USN-581-1] PCRE vulnerability | 22 Feb 2008 |
| Krzysztof Burghardt |
| | Search Unleashed 0.2.10 JavaScript injection (Wordpress plugin) | 13 Feb 2008 |
| L4teral |
| | ATutor <= 1.5.5 Cross Site Scripting | 17 Feb 2008 |
| | ProjectPier <= 0.80 Cross Site Scripting and Request Forgery | 17 Feb 2008 |
| | Anon Proxy Server <= 0.102 remote buffer overflow | 03 Feb 2008 |
| laurent.gaffie_at_nospam |
| | QuickTime <= 7.4.1 QTPlugin.ocx Multiple Remote Stack Overflow | 12 Feb 2008 |
| | jetAudio <= 7.0.5 (.ASX) Remote Stack Overflow | 08 Feb 2008 |
| linke_z_at_nospam |
| | Re: ACER Travelmate 600 and 800 series - Smartcard flawed Implementation | 12 Feb 2008 |
| lovebug_at_nospam |
| | php-nuke sql injection reportaj [secid] | 26 Feb 2008 |
| luca.carettoni_at_nospam |
| | Philips VOIP841 Multiple Vulnerabilities | 14 Feb 2008 |
| Luigi Auriemma |
| | Buffer-overflow in the passwords handling of Trend Micro OfficeScan 8.0 and possibly other products | 27 Feb 2008 |
| | NULL pointer in SurgeFTP 2.3a2 | 25 Feb 2008 |
| | Format string and buffer-overflow in SurgeMail 38k4 | 25 Feb 2008 |
| | Multiple vulnerabilities in Double-Take 5.0.0.2865 | 22 Feb 2008 |
| | Heap overflow in Sybase MobiLink 10.0.1.3629 | 20 Feb 2008 |
| | Access violation and limited informations disclosure in webcamXP 3.72.440.0 | 19 Feb 2008 |
| | Two heap overflow in Foxit WAC Server 2.0 Build 3503 | 19 Feb 2008 |
| | Multiple buffer-overflow in NowSMS v2007.06.27 | 19 Feb 2008 |
| | NULL pointer crash in freeSSHd 1.20 | 19 Feb 2008 |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| | Directory traversal and DoS in WinIPDS G52-33-021 | 12 Feb 2008 |
| | Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 12 Feb 2008 |
| | Unicode buffer-overflow in RPM Remote Print Manager 4.5.1.11 | 12 Feb 2008 |
| | Format string and buffer-overflow in Lst Network Print Server 9.4.2 build 105 | 11 Feb 2008 |
| | Format string and DoS in Opium OPI and cyanPrintIP servers 4.10.x | 11 Feb 2008 |
| | Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 | 11 Feb 2008 |
| | Multiple vulnerabilities in EztremeZ-IP File and Printer Server 5.1.2x15 | 11 Feb 2008 |
| | NULL byte writing in Emerald, RadiusNT/X and Air Marshal | 08 Feb 2008 |
| | Multiple vulnerabilities in Ipswitch Instant Messaging 2.0.8.1 | 07 Feb 2008 |
| | Chat vulnerabilities in TinTin++ 1.97.9 | 06 Feb 2008 |
| | Logs visualization in WS_FTP Server Manager 6.1.0.0 | 06 Feb 2008 |
| | Multiple vulnerabilities in SAPlpd 6.28 | 04 Feb 2008 |
| | Multiple vulnerabilities in WinCom LPD Total 3.0.2.623 | 04 Feb 2008 |
| | Socket termination in FTP Log Server 7.9.14.0 | 04 Feb 2008 |
| manuel.no_spam.bruneau_at_nospam |
| | Re: Joomla 1.0.13 - 1.0.14 / (remote) PHP file inclusion possible if old configuration.php | 15 Feb 2008 |
| marcin.kopec_at_nospam |
| | SQL-injection, XSS in OSSIM (Open Source Security Information Management) | 21 Feb 2008 |
| Mario Sergio Candian |
| | cacti -- Multiple security vulnerabilities have been discovered | 12 Feb 2008 |
| Mark Thomas |
| | [SECURITY] CVE-2007-6286: Tomcat duplicate request processing vulnerability | 08 Feb 2008 |
| | [SECURITY] CVE-2007-5333: Tomcat Cookie handling vulnerabilities | 08 Feb 2008 |
| | CVE-2008-0002: Tomcat information disclosure vulnerability | 08 Feb 2008 |
| Matt Johnston |
| | Re: Loginwindow.app and Mac OS X | 29 Feb 2008 |
| Matteo Beccati |
| | [OPENADS-SA-2008-001] Openads 2.4.2 vulnerability fixed | 04 Feb 2008 |
| Matthieu Suiche |
| | SandMan 1.0.080226 is out! | 26 Feb 2008 |
| mattyg_at_nospam |
| | Re: Philips VOIP841 Multiple Vulnerabilities | 15 Feb 2008 |
| Michael Neal Vasquez |
| | Checkpoint SecuRemote/Secure Client NGX Auto Local Logon Vulnerability | 07 Feb 2008 |
| morin.josh_at_nospam |
| | Apple iPhone 1.1.3 remote DoS exploit | 05 Feb 2008 |
| Moritz Muehlenhoff |
| | [SECURITY] [DSA 1506-1] New iceape packages fix several vulnerabilities | 24 Feb 2008 |
| | [SECURITY] [DSA 1495-2] New nagios-plugins packages fix regression | 17 Feb 2008 |
| | [SECURITY] [DSA 1497-1] New clamav packages fix several vulnerabilities | 16 Feb 2008 |
| | [SECURITY] [DSA 1496-1] New mplayer packages fix arbitrary code execution | 12 Feb 2008 |
| | [SECURITY] [DSA 1495-1] New nagios-plugins packages fix several vulnerabilities | 12 Feb 2008 |
| | [SECURITY] [DSA 1493-1] New sdl-image1.2 packages fix arbitrary code execution | 10 Feb 2008 |
| | [SECURITY] [DSA 1490-1] New tk8.3 packages fix arbitrary code execution | 10 Feb 2008 |
| | [SECURITY] [DSA 1491-1] New tk8.4 packages fix arbitrary code execution | 10 Feb 2008 |
| | [SECURITY] [DSA 1492-1] New wml packages fix denial of service | 10 Feb 2008 |
| | [SECURITY] [DSA 1489-1] New iceweasel packages fix several vulnerabilities | 10 Feb 2008 |
| | [SECURITY] [DSA 1484-1] New xulrunner packages fix several vulnerabilities | 10 Feb 2008 |
| | [SECURITY] [DSA 1485-1] New icedove packages fix several vulnerabilities | 10 Feb 2008 |
| | [SECURITY] [DSA 1487-1] New libexif packages fix several vulnerabilities | 08 Feb 2008 |
| | [SECURITY] [DSA 1482-1] New squid packages fix denial of service | 05 Feb 2008 |
| | [SECURITY] [DSA 1480-1] New poppler packages fix several vulnerabilities | 05 Feb 2008 |
| | [SECURITY] [DSA 1481-1] New python-cherrypy packages fix denial of service | 05 Feb 2008 |
| muuratsalo experimental hack lab |
| | lightblog 9.6 local file inclusion vulnerability | 17 Feb 2008 |
| | banpro-dms 1.0 local file inclusion vulnerability | 16 Feb 2008 |
| | scribe 0.2 local file inclusion vulnerability | 14 Feb 2008 |
| | PlutoStatus Locator v1.0pre (alpha) local file inclusion vulnerability | 14 Feb 2008 |
| | artmedic weblog multiple local file inclusion vulnerabilities | 13 Feb 2008 |
| | artmedic weblog multiple xss vulnerabilities | 12 Feb 2008 |
| | mini-pub 0.3 multiple vulnerabilities | 07 Feb 2008 |
| nbbn_at_nospam |
| | Wordpress Plugin Sniplets 1.1.2 Multiple Vulnerabilities | 25 Feb 2008 |
| | WoltLab Burning Board 3.0.3 PL1 SQL-Injection Vulnerability | 19 Feb 2008 |
| | RunCMS 1.6.1 Multiple XSS and XSRF Vulnerabilties | 16 Feb 2008 |
| | Wordpress Pluging wp-footnotes 2.2 (admin_panel.php) Multiple Vulnerabilites | 01 Feb 2008 |
| | Wordpress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities | 02 Feb 2008 |
| nnposter_at_nospam |
| | Packeteer Products File Listing XSS | 24 Feb 2008 |
| | Alkacon OpenCms tree_files.jsp resource XSS | 24 Feb 2008 |
| | F5 BIG-IP Web Management Console CSRF (with example) | 10 Feb 2008 |
| | F5 BIG-IP Web Management Console CSRF | 10 Feb 2008 |
| no-reply_at_nospam |
| | Mambo com_Musica "id" Remote SQL Injection | 01 Mar 2008 |
| | PHP-Nuke My_eGallery "gid" Remote SQL Injection | 28 Feb 2008 |
| | Aria-Security.Net: Joomla Com_publication "pid" Remote SQL Injection | 23 Feb 2008 |
| | Php Nuke "Sell" module SQL Injection ("cid") | 25 Feb 2008 |
| | Pigyard Art Gallery Multiple SQL Injection | 25 Feb 2008 |
| | Joomla com_inter "id" Remote SQL Injection | 24 Feb 2008 |
| | Joomla Com_blog "pid" Remote SQL Injection | 24 Feb 2008 |
| | Joomla com_stat "id" Remote SQL Injection | 24 Feb 2008 |
| | [Aria-Security.Net] BestWebApp Dating System SQL Injection | 22 Feb 2008 |
| | Mercury v1.1.5 Send Message Cross-Site Scripting | 10 Feb 2008 |
| | پيش گزيده Website Design Chat Software Remote Cross-Site Scripting | 10 Feb 2008 |
| | Tested on Webmin 1.390 | 06 Feb 2008 |
| Noah Meyerhans |
| | [SECURITY] [DSA 1509-1] New koffice packages fix multiple vulnerabilities | 25 Feb 2008 |
| | [SECURITY] [DSA 1502-1] New wordpress packages fix multiple vulnerabilities | 22 Feb 2008 |
| | [SECURITY] [DSA 1483-1] New net-snmp packages fix denial of service vulnerability | 06 Feb 2008 |
| oc photon |
| | Re: Loginwindow.app and Mac OS X | 29 Feb 2008 |
| Ofer Shezaf |
| | Web Hacking Incidents Database Update for Feb 20th | 20 Feb 2008 |
| | Web Hacking Incidenets Database 2007 annual Report is out | 08 Feb 2008 |
| omnipresent_at_nospam |
| | LightBlog Remote File Upload Vulnerability | 01 Feb 2008 |
| Open Phugu |
| | Some interesting hashes | 09 Feb 2008 |
| organiser_at_nospam |
| | SyScan'08 Call for Paper/Training | 13 Feb 2008 |
| Ozgur Ozdemircili |
| | Crafty Syntax Xss Vulnerability | 18 Feb 2008 |
| p_s3rver_at_nospam |
| | Vwar New Bug | 13 Feb 2008 |
| | Vwar 1.5.0 | 10 Feb 2008 |
| packet_at_nospam |
| | Re: Powered by Pagetool Ver (1.04-05-06-07) | 25 Feb 2008 |
| | Re: Vwar New Bug | 13 Feb 2008 |
| Paul Laudanski |
| | CastleCops Six Years Old | 23 Feb 2008 |
| Pete Herzog |
| | security and aluminum foil hats | 28 Feb 2008 |
| Peter Watkins |
| | Re: Apache web server 2.2: htpasswd predictable salt weakness | 15 Feb 2008 |
| | Apache web server 2.2: htpasswd predictable salt weakness | 14 Feb 2008 |
| Pierre-Yves Rofes |
| | [ GLSA 200802-11 ] Asterisk: Multiple vulnerabilities | 26 Feb 2008 |
| | [ GLSA 200802-09 ] ClamAV: Multiple vulnerabilities | 21 Feb 2008 |
| | [ GLSA 200802-07 ] Pulseaudio: Privilege escalation | 13 Feb 2008 |
| | [ GLSA 200802-06 ] scponly: Multiple vulnerabilities | 12 Feb 2008 |
| | [ GLSA 200802-05 ] Gnumeric: User-assisted execution of arbitrary code | 12 Feb 2008 |
| | [ GLSA 200802-04 ] Gallery: Multiple vulnerabilities | 11 Feb 2008 |
| | [ GLSA 200802-03 ] Horde IMP: Security bypass | 11 Feb 2008 |
| | [ GLSA 200802-02 ] Doomsday: Multiple vulnerabilities | 06 Feb 2008 |
| ProCheckUp Research |
| | PR07-41: XSS on Juniper Networks Secure Access 2000 | 28 Feb 2008 |
| | PR07-42: Webroot disclosure on Juniper Networks Secure Access 2000 | 28 Feb 2008 |
| | ZyXEL Gateways Vulnerability Research: http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf | 21 Feb 2008 |
| | PR06-12: XSS on BEA Plumtree Foundation and AquaLogic Interaction portals | 19 Feb 2008 |
| | PR08-01: Several XSS, a cross-domain redirect and a webroot disclosure on Spyce - Python Server Pages (PSP) | 19 Feb 2008 |
| ralph_at_nospam |
| | Re: etomite xss | 18 Feb 2008 |
| Raphael Marichez |
| | [ GLSA 200802-08 ] Boost: Denial of Service | 14 Feb 2008 |
| | [ GLSA 200802-01 ] SDL_image: Two buffer overflow vulnerabilities | 06 Feb 2008 |
| Raymond_Villafania_at_nospam |
| | RE: Buffer-overflow in the passwords handling of Trend Micro OfficeScan 8.0 and possibly other products | 28 Feb 2008 |
| research_at_nospam |
| | SYMSA-2008-001: Lyris ListManager - Multiple Vulnerabilities | 18 Feb 2008 |
| Reversemode |
| | [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient | 13 Feb 2008 |
| richard_at_nospam |
| | Re: XSS on Obedit v3.03 | 13 Feb 2008 |
| RISE Security |
| | Re: RE: ASUS Eee PC rooted out of the box | 08 Feb 2008 |
| | ASUS Eee PC rooted out of the box | 08 Feb 2008 |
| Robert Buchholz |
| | [ GLSA 200802-12 ] xine-lib: User-assisted execution of arbitrary code | 26 Feb 2008 |
| | [ GLSA 200802-10 ] Python: PCRE Integer overflow | 23 Feb 2008 |
| robert.ingruber_at_nospam |
| | Re: Multiple vulnerabilities in SAPlpd 6.28 | 05 Feb 2008 |
| rose-of-a_at_nospam |
| | Re: DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks | 14 Feb 2008 |
| rPath Update Announcements |
| | rPSA-2008-0094-1 kernel | 29 Feb 2008 |
| | rPSA-2008-0093-1 thunderbird | 29 Feb 2008 |
| | rPSA-2008-0092-1 tshark wireshark | 29 Feb 2008 |
| | rPSA-2008-0091-1 cups | 29 Feb 2008 |
| | rPSA-2008-0082-1 espgs | 28 Feb 2008 |
| | rPSA-2008-0088-1 am-utils | 28 Feb 2008 |
| | rPSA-2008-0086-1 pcre | 28 Feb 2008 |
| | rPSA-2008-0084-1 lighttpd | 28 Feb 2008 |
| | rPSA-2008-0059-1 openldap openldap-clients openldap-servers | 12 Feb 2008 |
| | rPSA-2008-0056-1 mailman | 15 Feb 2008 |
| | rPSA-2008-0063-1 boost | 13 Feb 2008 |
| | rPSA-2008-0061-1 SDL_image | 13 Feb 2008 |
| | rPSA-2008-0054-1 tk | 12 Feb 2008 |
| | rPSA-2008-0052-1 kernel | 12 Feb 2008 |
| | rPSA-2008-0051-1 firefox | 09 Feb 2008 |
| | rPSA-2008-0048-1 kernel | 08 Feb 2008 |
| | rPSA-2008-0046-1 gd | 06 Feb 2008 |
| | rPSA-2008-0043-1 icu | 06 Feb 2008 |
| | rPSA-2008-0040-1 mysql mysql-bench mysql-server | 05 Feb 2008 |
| rvandenbrink_at_nospam |
| | Re: Re: PIX Privilege Escalation Vulnerability | 05 Feb 2008 |
| S21sec labs |
| | S21SEC-040-en: Infinite invalid authentication attempts possible in BEA WebLogic Server | 25 Feb 2008 |
| s4tan |
| | Cacti 0.8.7a Multiple Vulnerabilities | 12 Feb 2008 |
| securfrog_at_nospam |
| | Sami FTP Server 2.0.* Multiple Remote Vulnerabilities | 15 Feb 2008 |
| | UniversalFtp Server 1.0.44 Multiple Remote Denial of service | 14 Feb 2008 |
| | Re: UniversalFtp Server 1.0.44 Multiple Remote Denial of service | 14 Feb 2008 |
| | Rosoft Media Player 4.1.8 Buffer Overflow ( .M3U) | 14 Feb 2008 |
| | dBpowerAMP Audio Player Release 2 Remote Buffer Overflow | 05 Feb 2008 |
| | NERO Media Player <= 1.4.0.35b Remote Buffer Overflow( .M3U) | 05 Feb 2008 |
| | IpSwitch WS_FTPSERVER with SSH remote Buffer Overflow | 02 Feb 2008 |
| | Titan FTP Server Remote Heap Overflow (USER/PASS) | 01 Feb 2008 |
| Security Basic |
| | Thanks to all, ExploitSearch in Top5 security must-have | 13 Feb 2008 |
| security-alert_at_nospam |
| | [security bulletin] HPSBGN02298 SSRT071502 rev.3 - HP Notebook PC Quick Launch Button (QLB) Software Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access | 22 Feb 2008 |
| | [security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013 | 21 Feb 2008 |
| | [security bulletin] HPSBTU02311 SSRT080001 rev.1 - HP Tru64 UNIX running Perl, Remote Execution of Arbitrary Code | 20 Feb 2008 |
| | [security bulletin] HPSBUX02313 SSRT080015 rev.1 - HP-UX Running Apache, Remote Execution of Arbitrary Code | 13 Feb 2008 |
| | [security bulletin] HPSBMA02274 SSRT071445 rev.3 - HP System Management Homepage (SMH) for HP-UX, Remote Cross Site Scripting (XSS) | 13 Feb 2008 |
| | [security bulletin] HPSBUX02249 SSRT071442 rev.3 - HP-UX Running the Ignite-UX or the DynRootDisk (DRD) get_system_info Command, Local Unqualified Configuration Change | 13 Feb 2008 |
| | [security bulletin] HPSBMA02309 SSRT080013 rev.1 - HP Select Identity Software, Remote Unauthorized Access | 07 Feb 2008 |
| | [security bulletin] HPSBGN02310 SSRT080007 rev.1 - HP Virtual Rooms Running on Windows, Remote Execution of Arbitrary Code | 06 Feb 2008 |
| | [security bulletin] HPSBST02302 SSRT071474 rev.1 - HP Storage Essentials SRM, Remote Unauthorized Access | 06 Feb 2008 |
| | [security bulletin] HPSBMA02307 SSRT071420 rev.1 - HP OpenView Network Node Manager (OV NNM) Remote Denial of Service (DoS) | 05 Feb 2008 |
| | [security bulletin] HPSBUX02308 SSRT080010 rev.1 - HP-UX Running Apache, Remote Execution of Arbitrary Code | 04 Feb 2008 |
| security_at_nospam |
| | [ MDVSA-2008:056 ] - Updated gnumeric packages fix vulnerability | 29 Feb 2008 |
| | [ MDVSA-2008:055 ] - Updated ghostscript packages fix arbitrary code execution vulnerability | 29 Feb 2008 |
| | PHPMyTourney Remote file include Vulnerability | 29 Feb 2008 |
| | [ MDVSA-2008:054 ] - Updated dbus packages fix vulnerability | 28 Feb 2008 |
| | [ MDVSA-2008:053 ] - Updated pcre packages fix vulnerability | 27 Feb 2008 |
| | [ MDVSA-2008:052 ] - Updated cacti packages fix multiple vulnerabilities | 27 Feb 2008 |
| | [ MDVSA-2008:051 ] - Updated cups packages fix vulnerabilities | 26 Feb 2008 |
| | [ MDVSA-2008:050 ] - Updated cups packages fix multiple vulnerabilities | 26 Feb 2008 |
| | [ MDVSA-2008:049 ] - Updated nss_ldap package fixes race condition allowing user data theft | 25 Feb 2008 |
| | [ MDVSA-2008:048 ] - Updated Firefox packages fix multiple vulnerabilities | 22 Feb 2008 |
| | [ MDVSA-2008:046-1 ] - Updated xine-lib package fixes arbitrary code execution vulnerability | 21 Feb 2008 |
| | [ MDVSA-2007:047 ] - Updated Thunderbird packages fix multiple vulnerabilities | 19 Feb 2008 |
| | [ MDVSA-2008:046 ] - Updated xine-lib package fixes arbitrary code execution vulnerability | 15 Feb 2008 |
| | [ MDVSA-2008:045 ] - Updated MPlayer packages fix a few vulnerabilities | 14 Feb 2008 |
| | [ MDVSA-2008:044 ] - Updated kernel packages fix multiple vulnerabilities and bugs | 12 Feb 2008 |
| | [ MDVSA-2008:043 ] - Updated kernel packages fix multiple vulnerabilities and bugs | 12 Feb 2008 |
| | [ MDVSA-2008:039 ] - Updated netpbm packages fix buffer overflow vulnerability | 08 Feb 2008 |
| | [ MDVSA-2008:038 ] - Updated gd packages fix buffer overflow vulnerability | 08 Feb 2008 |
| | [ MDVSA-2008:042 ] - Updated Qt4 packages fix vulnerability in QSslSocket | 08 Feb 2008 |
| | [ MDVSA-2008:040 ] - Updated SDL_image packages fix vulnerabilities | 08 Feb 2008 |
| | [ MDVSA-2008:041 ] - Updated tk packages fix buffer overflow vulnerability | 08 Feb 2008 |
| | [ MDVSA-2008:037 ] - Updated libcdio packages fix DoS vulnerability | 07 Feb 2008 |
| | [ MDVSA-2008:036 ] - Updated CUPS packages fix SNMP vulnerability | 06 Feb 2008 |
| | [ MDVSA-2008:035 ] - Updated libcdio packages fix DoS vulnerability | 05 Feb 2008 |
| | [ MDVSA-2008:034 ] - Updated emacs packages fix vulnerabilities | 05 Feb 2008 |
| | [ MDVSA-2008:033 ] - Updated ruby-gnome2 packages fix arbitrary code execution vulnerability | 01 Feb 2008 |
| | [ MDVSA-2008:032 ] - Updated boost packages fix DoS vulnerabilities | 01 Feb 2008 |
| | [ MDVSA-2008:031 ] - | 01 Feb 2008 |
| Sekomirza_at_nospam |
| | StatCounteX 3.0 & 3.1 Admin Vulnerability | 14 Feb 2008 |
| sex_at_nospam |
| | LI-countdown SQL Injection Vulnerability | 12 Feb 2008 |
| si0uxsecurity_at_nospam |
| | Re: CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference | 19 Feb 2008 |
| sipherr_at_nospam |
| | Re: Re: Nortel IP Phone DoS | 26 Feb 2008 |
| | Nortel IP Phone DoS | 26 Feb 2008 |
| staad1_at_nospam |
| | Default Multiple Joomla! Component com_rapidrecipe "user_id=" Remote SQL Inj. | 10 Feb 2008 |
| Stefan Esser |
| | Advisory SE-2008-01: PunBB Blind Password Recovery Vulnerability | 20 Feb 2008 |
| Stefano Zanero |
| | CFP: Workshop on Open Source Software for Computer and Network Forensics | 20 Feb 2008 |
| | Final CFP: EuroSec Workshop (March 31st, 2008) | 10 Feb 2008 |
| Steve Kemp |
| | [SECURITY] [DSA 1507-1] New turba2 packages fix permission testing | 24 Feb 2008 |
| | [SECURITY] [DSA 1500-1] New splitvt packages fix privilege escalation | 21 Feb 2008 |
| | [SECURITY] [DSA 1498-1] New libimager-perl packages fix arbitrary code execution | 19 Feb 2008 |
| | [SECURITY] [DSA 1486-1] New gnatsweb packages fix cross-site scripting | 05 Feb 2008 |
| Steve Shockley |
| | Re: Logs visualization in WS_FTP Server Manager 6.1.0.0 | 06 Feb 2008 |
| sub |
| | The Everything Development System - SQL Injection | 01 Feb 2008 |
| subere_at_nospam |
| | EDLGraph 1.0 | 21 Feb 2008 |
| Sw33t.h4cK3r_at_nospam |
| | SQL in Archimede Net 2000 "E-Guest_show.php" | 01 Feb 2008 |
| sys-project_at_nospam |
| | Centreon <= 1.4.2.3 (index.php) Remote File Disclosure | 29 Feb 2008 |
| | Simple CMS <= 1.0.3 (indexen.php area) Remote SQL Injection Exploit | 17 Feb 2008 |
| th3.r00k.nospam_at_nospam |
| | etomite xss | 14 Feb 2008 |
| theredc0ders_at_nospam |
| | phpShop <= v 0.8.1 Remote SQL injection / Filter Bypass | 02 Feb 2008 |
| Thijs Kinkhorst |
| | [SECURITY] [DSA 1510-1] New ghostscript packages fix arbitrary code execution | 27 Feb 2008 |
| | [SECURITY] [DSA 1508-1] New diatheke packages fix arbirary shell command execution | 25 Feb 2008 |
| | [SECURITY] [DSA 1501-1] New dspam packages fix information disclosure | 21 Feb 2008 |
| | [SECURITY] [DSA 1488-1] New phpbb2 packages fix several vulnerabilities | 09 Feb 2008 |
| Thor (Hammer of God) |
| | ExtraOutlook 1.2 Released | 11 Feb 2008 |
| Tim Newsham |
| | Re: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability" | 06 Feb 2008 |
| Tonnerre Lombard |
| | Re: [Full-disclosure] rPSA-2008-0052-1 kernel | 14 Feb 2008 |
| Trancer |
| | JSPWiki Multiple Vulnerabilities | 13 Feb 2008 |
| turkish-warrorr_at_nospam |
| | Powered by Pagetool Ver (1.04-05-06-07) | 24 Feb 2008 |
| vijayv_at_nospam |
| | XSS on XRMS- open source CRM | 28 Feb 2008 |
| VMware Security team |
| | VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates | 21 Feb 2008 |
| Wojciech Purczynski |
| | CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference | 12 Feb 2008 |
| zdi-disclosures_at_nospam |
| | ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability | 20 Feb 2008 |
| | ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability | 13 Feb 2008 |
| | ZDI-08-005: Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability | 11 Feb 2008 |
| | ZDI-08-004: Adobe AcrobatReader Javascript for PDF Integer Overflow Vulnerability | 11 Feb 2008 |
| | ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability | 06 Feb 2008 |
| رومانسي هكر |
| | aliboard Beta Upload Shell From ControlPanel | 11 Feb 2008 |