Mail Index
- MDKSA-2002:024 - rsync update
- From: Mandrake Linux Security Team
- [CLA-2002:469] Conectiva Linux Security Announcement - zlib
- about zlib vulnerability
- Re: about zlib vulnerability
- Re: [RHSA-2002:026-35] Vulnerability in zlib library
- Re: about zlib vulnerability - Microsoft products
- From: Davis Ray Sickmon, Jr
- ZLib double free bug: Windows NT potentially unaffected
- Re: OpenSSH rebuild warning: problems avoiding zlib problems in Solaris
- Account Lockout Vulnerability in Oblix NetPoint v5.2
- Re: OpenSSH rebuild warning: problems avoiding zlib problems in Solaris
- [CSS] Cross Site Scripting in the translation and infoplease services of lycos.com possible
- Re: ZLib double free bug: Windows NT potentially unaffected
- Fwd: DebPloit (exploit)
- RE: ZLib double free bug: Windows NT potentially unaffected
- CERT Advisory CA-2002-08 Multiple vulnerabilities in Oracle Servers
- Re: ZLib double free bug: Windows NT potentially unaffected
- RE: [Whitehat] about zlib vulnerability
- Bug in QPopper (All Versions?)
- Re: ZLib double free bug: Windows NT potentially unaffected
- RE: Foundry Networks ServerIron don't decode URIs
- [RHSA-2002:032-12] Updated cups packages are available
- Re: OpenSSH rebuild warning: problems avoiding zlib problems in Solaris
- MSIE vulnerability exploitable with IncrediMail
- Re: ZLib double free bug: Windows NT potentially unaffected
- Re: Bug in QPopper (All Versions?)
- Re: OpenSSH rebuild warning: problems avoiding zlib problems in Solaris
- RE: MSIE vulnerability exploitable with IncrediMail
- Apache vulnerabilities on IRIX
- From: SGI Security Coordinator
- RE: MSIE vulnerability exploitable with IncrediMail
- Re: about zlib vulnerability - Microsoft products
- From: Forrest J Cavalier III
- PHP-Nuke & Post-Nuke account hijacking.
- PHP Net Toolpack: input validation error
- Re: Alteon ACEdirector signature/security bug
- [Mozilla Bug #131761] Buffer Overflow in Geck/Netscape 5.0/6.0?
- From: Jonathan A. Zdziarski
- Buffer Overflow in Geck/Netscape 5.0/6.0?
- From: Jonathan A. Zdziarski
- TSLSA-2002-0040 - zlib
- From: Trustix Secure Linux Advisor
- [ARL02-A07] ARSC Really Simple Chat System Information Path Disclosure Vulnerability
- KPMG-2002005: BitVise WinSSH Denial of Service
- [ARL02-A10] News-TNK Cross Site Scripting Vulnerability
- [ARL02-A08] BG Guestbook Cross Site Scripting Vulnerability
- Re: about zlib vulnerability - Microsoft products
- [ARL02-A09] Board-TNK Cross Site Scripting Vulnerability
- RE: MSIE vulnerability exploitable with IncrediMail
- Sun Security Bulletin #00218
- MSIE vulnerability exploitable with Eudora (was: IncrediMail)
- RE: PHP-Nuke & Post-Nuke account hijacking.
- RE: MSIE vulnerability exploitable with IncrediMail
- Re: Buffer Overflow in Geck/Netscape 5.0/6.0?
- FreeBSD Ports Security Advisory FreeBSD-SA-02:18.zlib
- From: FreeBSD Security Advisories
- Sun Security Bulletin #00217
- SOLARIS LOGIN remote via telnetd
- Re: Buffer Overflow in Geck/Netscape 5.0/6.0?
- TCP Connections to a Broadcast Address on BSD-Based Systems
- Re: phpBB2 remote execution command (fwd)
- Hosting Directory Traversal madness...
- [ARL02-A11] Big Sam (Built-In Guestbook Stand-Alone Module) Multiple Vulnerabilities
- Re: [ARL02-A07] ARSC Really Simple Chat System Information Path Disclosure Vulnerability
- Identifying Kernel 2.4.x based Linux machines using UDP
- [SECURITY] [DSA-123-1] listar buffer overflow
- Excite Email Disclosure Vulnerability
- RE: Buffer Overflow in Geck/Netscape 5.0/6.0?
- phpBB2 remote execution command
- IRIX TCP/IP Initial Sequence Numbers
- From: SGI Security Coordinator
- RE: MSIE vulnerability exploitable with IncrediMail
- Potential vulnerabilities of the Microsoft RVP-based Instant Messaging
- From: Dimitrios Petropoulos
- More SWF vulnerabilities?
- Additional IRIX CDE and CDE ToolTalk Vulnerabilities update
- From: SGI Security Coordinator
- Javascript loop causes IE to crash
- move_uploaded_file breaks safe_mode restrictions in PHP
- Re: More SWF vulnerabilities?
- Bypassing libsafe format string protection
- From: Wojciech Purczynski
- Re: [VulnWatch] Bypassing libsafe format string protection
- Citrix contacts
- Re: Identifying Kernel 2.4.x based Linux machines using UDP
- Re: Identifying Kernel 2.4.x based Linux machines using UDP
- Default SNMP configuration issue with Foundry Networks EdgeIron 4802F
- Local privalege escalation issues with Webmin 0.92
- NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances
- RE: Potential vulnerabilities of the Microsoft RVP-based Instant Messaging
- RE: Identifying Kernel 2.4.x based Linux machines using UDP
- From: Fletcher, Stephen J
- [Mozilla Bug #131761] Buffer Overflow in Geck/Netscape 5.0/6.0?
- From: Jonathan A. Zdziarski
- Re: TCP Connections to a Broadcast Address on BSD-Based Systems
- [Bug 131761] Buffer Overflow in Geck/Netscape 5.0/6.0?
- From: Jonathan A. Zdziarski
- Re: Identifying Kernel 2.4.x based Linux machines using UDP
- From: Charles-Edouard Ruault
- RE: Hosting Directory Traversal madness...
- Security Update: [CSSA-2002-SCO.12] Open UNIX, UnixWare 7: rpc.cmsd can be remotely exploited
- CSS in ikonboard 3.0.1,3.0.2,3.0.3
- Re: move_uploaded_file breaks safe_mode restrictions in PHP
- Re: PHP Net Toolpack: input validation error
- RE: phpBB2 remote execution command
- RE: Citrix vulnerability disclosure/bug reports contact
- Re: Excite Email Disclosure Vulnerability
- [img]-vulnerability in vBulletin Version 2.2.2 & 2.2.1 & maybe olders
- Re: NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances
- Re: move_uploaded_file breaks safe_mode restrictions in PHP
- Re: NMRC Advisory - KeyManager Issue in ISS RealSecure
- RE: NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia A ppliances
- From: Rouland, Chris (ISSAtlanta)
- PHP script: Penguin Traceroute, Remote Command Execution
- Questionable security policies in Outlook 2002
- Fw: PHPNuke 5.4 Path Disclosure Vulnerability?
- RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecur e on Nokia Appliances
- Vulnerability in Apache for Win32 batch file processing - Remote command execution
- MDKSA-2002:025 - fix for insecure default kdm configuration
- From: Mandrake Linux Security Team
- Re: move_uploaded_file breaks safe_mode restrictions in PHP
- RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecur e on Nokia Appliances
- From: Rouland, Chris (ISSAtlanta)
- [RHSA-2002:048-06] New imlib packages available
- RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecur e on Nokia Appliances
- From: Rouland, Chris (ISSAtlanta)
- Re: TCP Connections to a Broadcast Address on BSD-Based Systems
- Re: move_uploaded_file breaks safe_mode restrictions in PHP
- RE: CSS in ikonboard 3.0.1,3.0.2,3.0.3
- How Outlook 2002 can still execute JavaScript in an HTML email message
- Xpede passwords exposed (2 vuln.)
- [RHSA-2002:035-18] Updated PHP packages are available [updated 2002-Mar-11]
- [RHSA-2002:026-43] Vulnerability in zlib library
- Gravity Storm Service Pack Manager 2000 Share Vulnerability
- Webtraversal in PCI Netsupport Manager (all version up to 7 using web extensions)
- memberlist.php of vBulletin
- PostNuke Bugged
- RE: PHPNuke 5.4 Path Disclosure Vulnerability?
- Re: PHP script: Penguin Traceroute, Remote Command Execution
- Re: move_uploaded_file breaks safe_mode restrictions in PHP
- EUDORA Re: Automatically opening + Executing attachments
- From: http-equiv@xxxxxxxxxx
- XSS + Info leak @ www.myownemail.com
- UniNet InfoSec Conference
- RE: NMRC Advisory: RealSecure KeyManager Issue - Further Explanation
- Re: PHP script: Penguin Traceroute, Remote Command Execution
- One more way to bypass NAV
- Re: Local privalege escalation issues with Webmin 0.92
- Re: PostNuke Bugged
- RE: NMRC Advisory: RealSecure KeyManager Issue - Further Explanation
- dcshop.cgi anybody can delete *.setup for database
- From: pokleyzz sakamaniaka
- Cookie vulnerability in Alguest guestbook (PHP)
- WebSight Directory System: cross-site-scripting bug
- Re: Fw: PHPNuke 5.4 Path Disclosure Vulnerability?
- 1024-bit RSA keys in danger of compromise
- Apache 1.3.24 Released! (fwd)
- re: Tomcat Security Exposure
- Re: Identifying Kernel 2.4.x based Linux machines using UDP
- Cross-site scripting.
- New Bill attempts to regulate hardware, software development
- Re: 1024-bit RSA keys in danger of compromise
- [IMG] tag vulnerability in vBulletin
- Re: memberlist.php of vBulletin
- secureinc.com Vulnerability
- Instant Web Mail additional POP3 commands and mail headers
- updated squid advisory
- Security contact for Network Associates?
- Etnus TotalView 5.
- FreeBSD Ports Security Advisory FreeBSD-SA-02:19.squid
- From: FreeBSD Security Advisories
- d_path() truncating excessive long path name vulnerability
- From: Wojciech Purczynski
- [SECURITY] [DSA 124-1] New mtr packages fix buffer overflow
- CGIscript.net - csSearch.cgi - Remote Code Execution (up to 17,000 sites vulnerable)
- Re: [RHEA-2002:024-23] Updated rpm packages available
- From: helmut g. katzgraber
- Re: Cross-site scripting.
- SouthWest Telnet talker server. DoS (Denial of Service Attack).
- DoS in debian (potato) proftpd
- RE: Security contact for Network Associates?
- JS embedding @ www.reed.co.uk
- Root compromise through LogWatch 2.1.1
- Xchat /dns command execution vulnerability
- Cisco Security Advisory: LDAP Connection Leak in CTI when User Authentication Fails
- From: Cisco Systems Product Security Incident Response Team
- NFuse Cross Site Scripting vulnerability
- RCA cable modem Deny of Service
- From: Gabriel A. Maggiotti
- Re: RCA cable modem Deny of Service
- [Advisory] phpBB 1.4.4 still suffers from Cross Site Scripting Vulnerability
- From: Florian Hobelsberger / BlueScreen
- Re: DoS in debian (potato) proftpd
- Format String Bug in Posadis DNS Server
- A buffer overflow study - generic protections
- Re: RCA cable modem Deny of Service
- Citrix Nfuse directory traversal with boilerplate.asp
- postnuke v 0.7.0.3 remote command execution
- From: pokleyzz sakamaniaka
- Re: 1024-bit RSA keys in danger of compromise
- OpenSSH channel_lookup() off by one exploit
- vuln in wwwisis: remote command execution and get files
- JS embedding @ yahoo.com
- squirrelmail 1.2.5 email user can execute command
- From: pokleyzz sakamaniaka
- [SECURITY] [DSA 125-1] New analog packages fix cross-site scripting vulnerability
- Oracle9i TSN DoS Attack
- A possible buffer overflow in libnewt
- Re: OpenSSH rebuild warning: problems avoiding zlib problems in Solaris
- IRIX FTP Bounce vulnerability
- From: SGI Security Coordinator
- Team Asylum: Online renewal sites susceptible to spammer "harvesting"
- Local Security Vulnerability in Windows NT and Windows 2000
- privacy issues in metor.com (a search engine)
- Re: Oracle9i TSN DoS Attack
- Re:[Advisory] phpBB 1.4.4 still suffers from Cross Site Scripting Vulnerability
- [CLA-2002:470] Conectiva Linux Security Announcement - imlib
- IRIX TCP/IP Denial-of-Service attacks
- From: SGI Security Coordinator
- IRIX rpc/HOSTALIASES vulnerability
- From: SGI Security Coordinator
- Re: 1024-bit RSA keys in danger of compromise
- Anonymizer, MSIE, images ...
- From: Alexander K. Yezhov
- Security Update: [CSSA-2002-007.0] Linux: Updated Caldera Public Keys
- Security Update: [CSSA-2002-012.0] Linux: OpenSSH channel code vulnerability
- Security Update: [CSSA-2002-008.0] Linux: CUPS buffer overflow when reading names of attributes
- Security Update: [CSSA-2002-009.0] Linux: X server allows access to any shared memory on the system
- More Office XP problems
- Security Update: [CSSA-2002-010.0] Linux: ftp vulnerability in squid
- Security Update: [CSSA-2002-011.0] Linux: mod_ssl Buffer Overflow Condition
- Re: Local Security Vulnerability in Windows NT and Windows 2000
- From: Alexander K. Yezhov
- Security Update: [CSSA-2002-013.0] Linux: Name Service Cache Daemon (nscd) advisory
- Announcing Immunix SnackGuard
- Fun With MSN Chat Part I (Cross Scripting)
- UPDATED: Cisco Security Advisory: LDAP Connection Leak in CTI when User Authentication Fails
- From: Cisco Systems Product Security Incident Response Team
- Security Update: [CSSA-2002-005.0] Linux - LD_LIBRARY_PATH problem in KDE sessions
- packet filter fingerprinting(open but closed, closed but filtered)
- Re: invitation to my cam (fwd)
- Bypassing javascript filters - problem N3.
- From: Alexander K. Yezhov
- Progress Setuid patch Installs (Happy Easter or April fools to Progress)
- Zope security address
- Boursorama.com cookie exploit
- From: Eyrill / Securiteinfo.com
- Re: squirrelmail 1.2.5 email user can execute command
- From: Konstantin Riabitsev
- Fw: Multiple Vulnerabilties in Sambar Server
- From: NGSSoftware Insight Security Research Advisory (NISR)
- Re: Zope security address
- NSFOCUS SA2002-01: Sun Solaris Xsun "-co" heap overflow
- From: Nsfocus Security Team
- KPMG-2002006: Lotus Domino Physical Path Revealed
- Various Vulnerabilities in ZoneAlarm MailSafe
- From: Edvice Security Services
- Windows 2000 DCOM clients may leak sensitive information onto the network
- Re: A buffer overflow study - generic protections
- Firewall-1 Identification : port 257 (ie archive : 18701)
- MS 3/28/02 Security Patch for IE6 - warning!
- popper_mod 1.2.1 and previous accounts compromise
- Taxonomies
- From: Marco de Vivo [UCV]
- Outlook Express Attach Execution Exploit (img tag + innerHTML + TIF dos name)
- Happy Easter / April Fools from Snosoft (Oracle 8.1.5 tnslsnr)
- Re: IRIX FTP Bounce vulnerability
- From: Christophe Casalegno
- Re: Multiple Vulnerabilties Sambar Webserver
- RE: [VulnWatch] vuln in wwwisis: remote command execution and get files
- icecast 1.3.11 remote shell/root exploit - #temp
- Huge Privacy Threats in Webmails and How Big Companies Handle them
- IE: Remote webpage can script in local zone
- SASL (v1/v2) MYSQL/LDAP authentication patch.
- VNC Security Bulletin - zlib double free issue (multiple vendors and versions)
- From: Andrew van der Stock
- Re: packet filter fingerprinting(open but closed, closed but filtered)
- Re: Identifying Kernel 2.4.x based Linux machines using UDP
- RE: MS 3/28/02 Security Patch for IE6 - warning!
- RE: MS 3/28/02 Security Patch for IE6 - warning!
- Winamp: Mp3 file can control the minibrowser
- Re: packet filter fingerprinting(open but closed, closed but filtered)
- Cisco Security Advisory: Web interface vulnerabilities in ACS for Windows
- From: Cisco Systems Product Security Incident Response Team
- Re: KPMG-2002006: Lotus Domino Physical Path Revealed
- Re: Taxonomies
- [CLA-2002:471] Conectiva Linux Security Announcement - cups
- Security bugs in PhpNuke
- iXsecurity.20020316.csadmin_dir.a
- Re: Multiple Vulnerabilties Sambar Webserver
- Icecast temp patch (OR: Patches? We DO need stinkin' patches!!@$!)
- SQL injection in PHPGroupware
- Re: Bypassing javascript filters - problem N3.
- Cisco Security Advisory: Vulnerability in zlib library
- From: Cisco Systems Product Security Incident Response Team
- iXsecurity.20020313.nw6remotemanager.a
- RE: MS 3/28/02 Security Patch for IE6 - warning!
- Multiple Vendor "talkd" user validation fault.
- LogWatch 2.5 still vulnerable
- iXsecurity.20020314.csadmin_fmt.a
- IRIX SNMP Vulnerabilities
- From: SGI Security Coordinator
- Re: Taxonomies
- ISS Advisory: Remote Buffer Overflow Vulnerability in IRIX SNMP Daemon
- RE: More Office XP problems
- More Office XP problems (Version 2.0)
- Re: Winamp: Mp3 file can control the minibrowser
- Re: DoS in debian (potato) proftpd: 1.2.0pre10-2.0potato1
- Quik-Serv Web Server v1.1B Arbitrary File Disclosure
- Dynamic Guestbook V3.0 Cross Site Scripting and Arbitrary Command Execution under certain circumstances
- From: Florian Hobelsberger / BlueScreen
- SECURITY.NNO: FTGate PRO/Office hotfixes
- RFC: suggestions for SSL security enhancements in Microsoft Internet Explorer
- RE: Windows 2000 DCOM clients may leak sensitive information onto the network
- Re: SQL injection in PHPGroupware
- Re: KPMG-2002006: Lotus Domino Physical Path Revealed
- Re: Winamp: Mp3 file can control the minibrowser
- Re: Winamp: Mp3 file can control the minibrowser
- Re: DoS in debian (potato) proftpd: 1.2.0pre10-2.0potato1
- Re: Firewall-1 Identification : port 257 (ie archive : 18701)
- Security Update: [CSSA-2002-014.0] Linux: rsync supplementary groups vulnerability
- Full analysis of multiple remotely exploitable bugs in Icecast 1.3.11
- NSFOCUS SA2002-02 : Microsoft Windows MUP overlong request kernel overflow
- From: Nsfocus Security Team
- Re: More Office XP problems
- emumail.cgi
- (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability
- From: Whitecell Security Systems
- Exploit for Tarantella Enterprise 3 installation (BID 3966)
- From: Larry W. Cashdollar
- [RHSA-2002:053-12] Race conditions in logwatch
- Security Update: [CSSA-2002-015.0] Linux: Double free in zlib (libz) vulnerability
- [RHSA-2002:054-09] Race conditions in logwatch
- CA security contact
- Re: emumail.cgi
- Re: Multiple Vendor "talkd" user validation fault.
- Re: CA security contact
- Re: Techniques for Vulneability discovery
- Re: emumail.cgi
- RE: VNC Security Bulletin - zlib double free issue (multiple vendors and versions)
- From: Andrew van der Stock
- RE: CA security contact
- Re: CA security contact
- Re: VNC Security Bulletin - zlib double free issue (multiple vendors and versions)
- Re: VNC Security Bulletin - zlib double free issue (multiple vendors and versions)
- RE: More Office XP problems
- RE: More Office XP problems
- RE: More Office XP problems
- RE: Multiple Vendor "talkd" user validation fault
- IMP 2.2.8 (SECURITY) released
- NetWare Remote Manager patches
- Anthill login and JavaScript vulnerabilities
- Typsoft FTP Server: yet another directory traversal vulnerability
- KPMG-2002007: Watchguard SOHO Denial of Service
- multiple CGIscript.net scripts - Remote Code Execution
- SuSE Security Announcement: ucdsnmp (SuSE-SA:2002:012)
- Unauthorized remote control access to systems running Funk Softwa re's Proxy v3.x
- Re: emumail.cgi
- RE: More Office XP problems
- Re: VNC Security Bulletin - zlib double free issue (multiple vendors and versions)
- RE: More Office XP problems
- regarding SSL issues
- Security Update: [CSSA-2002-SCO.14] Open UNIX 8.0.0 UnixWare 7.1.1 : X server allows access to any shared memory on the system
- Cisco Security Advisory: Aironet Telnet Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Vulnerability: Windows2000Server running Terminalservices
- Re: emumail.cgi
- IE Word ActiveX DoS Loop
- [RHSA-2001:089-08] Updated tcpdump packages available for Red Hat Linux 6.2 and 7.x
- Abyss Webserver 1.0 Administration password file retrieval exploit
- Re: Vulnerability: Windows2000Server running Terminalservices
- MS02-018
- Cisco Security Advisory: Solaris /bin/log vulnerability
- From: Cisco Systems Product Security Incident Response Team
- @stake advisory: .htr heap overflow in IIS 4.0 and 5.0
- Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues
- Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow
- Re: emumail.cgi, one more local vulnerability (not verified)
- IIS allows universal CrossSiteScripting
- SPIKE version released that detects .HTR and ISAPI overflows (see spike.sourceforge.net)
- KPMG-2002008: Watchguard SOHO IP Restrictions Flaw
- KPMG-2002009: Microsoft IIS W3SVC Denial of Service
- KPMG-2002010: Microsoft IIS .htr ISAPI buffer overrun
- Re: CA security contact
- SOAP::Lite hole
- ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT
- iXsecurity.20020327.tivoli_tsm_dsmcad.a
- IRIX Mail, mailx, timed and sort vulnerabilities
- From: SGI Security Coordinator
- Re: MS02-018
- RE: Windows 2000 Sec rollup 2 patch -- Ouch!
- [SNS Advisory No.49] A Possibility of Internet Information Server/Services Cross Site Scripting
- local root compromise in openbsd 3.0 and below
- From: Przemyslaw Frasunek
- OpenBSD Local Root Compromise
- Re: local root compromise in openbsd 3.0 and below
- iXsecurity.20020328.tivoli_tsm_dsmsvc.a
- IBM Informix Web DataBlade: SQL injection
- RE: MS02-018
- IBM Informix Web DataBlade: Auto-decoding HTML entities
- Security Update: [CSSA-2002-SCO.15] Open UNIX 8.0.0 UnixWare 7.1.1 : Buffer overflow in libX11 with -xrm
- Re: OpenBSD Local Root Compromise
- Inn (Inter Net News) security problems
- re: gobbles ntop alert
- From: Burton M. Strauss III
- Re: (SRADV00006) Remote command execution vulnerabilities in phpGroupWare
- Re: SQL injection in PHPGroupware
- Re: Cisco Security Advisory: Solaris /bin/log vulnerability
- From: Charles M. Richmond
- R: MS02-018
- MDKSA-2002:026 - libsafe update
- From: Mandrake Linux Security Team
- OpenBSD 3.0: Bug in rshd(8) and rexecd(8) (fwd)
- SWS Vuln (small but important to those using it.)
- Re: local root compromise in openbsd 3.0 and below
- Remote buffer overflow in Webalizer
- Security Update: [CSSA-2002-SCO.16] UnixWare 7.1.1 : Multiple Vulnerabilities in BIND
- Ability to read buddy list of AIM users
- SunSop: cross-site-scripting bug
- Using the backbutton in IE is dangerous
- Re: Ability to read buddy list of AIM users
- From: Andrew J. Stackhouse
- Vulnerabilities in the Melange Chat Server
- Nortel CVX 1800s will dump all local user names and passwords via SNMP
- Re: local root compromise in openbsd 3.0 and below
- Re: local root compromise in openbsd 3.0 and below
- Several x-dev.de Guestbook and xNewsletter Vulnerabilities ( www.x-dev.de )
- From: Florian Hobelsberger / BlueScreen
- Possible vulnerabilities of ICQ files opened in IE or OE
- wbboard 1.1.1 Cross Site Scripting Vulnerability
- IRIX XFS filesystem denial of service attack
- From: SGI Security Coordinator
- buffer overflow, using greek characters, AGAIN!
- Raptor Firewall FTP Bounce vulnerability
- About: Using the backbutton in IE is dangerous
- Demarc PureSecure 1.05 may be other (user can bypass login)
- From: pokleyzz sakamaniaka
- Vulnerability in HP Photosmart/Deskjet Drivers for Mac OS X (root compromise)
- From: Dr Andreas F Muller
- A crash course with Linux Kernel 2.4.x, IP ID values & RFC 791
- w00w00 on Microsoft IE/Office for Mac OS
- Cisco Security Advisory: Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
- From: Cisco Systems Product Security Incident Response Team
- Re: IRIX XFS filesystem denial of service attack
- Norton Personal Firewall 2002 vulnerable to SYN/FIN scan
- ansi outer join syntax in Oracle allows access to any data
- Re: w00w00 on Microsoft IE/Office for Mac OS
- [SECURITY] [DSA-126-1] Horde and IMP cross-site scripting attack
- Re: ansi outer join syntax in Oracle allows access to any data
- FreeBSD Security Advisory FreeBSD-SA-02:20.syncache
- From: FreeBSD Security Advisories
- Security Update: [CSSA-2002-016.0] Linux: horde/imp cross scripting vulnerabilities
- MDKSA-2002:027 - squid update
- From: Mandrake Linux Security Team
- IRIX cron daemon vulnerability
- From: SGI Security Coordinator
- Re: IRIX XFS filesystem denial of service attack
- Microsoft Security Bulletin MS02-019: Unchecked Buffer in Internet Explorer and Office for Mac Can Cause Code to Execute (Q321309)
- Microsoft FTP Service STAT Globbing DoS
- Melange Chat POC DOS
- Demarc Security Update Advisory
- From: Demarc Security Support
- Re: Possible vulnerabilities of ICQ files opened in IE or OE
- RE: Ability to read buddy list of AIM users
- [SECURITY] [DSA-127-1] buffer overflow in xpilot-server
- RE: Using the backbutton in IE is dangerous
- Snort exploits
- Multiple Vulnerabilities in PostBoard
- [CERT-intexxia] AOLServer DB Proxy Daemon Format String Vulnerability
- Re: Remote buffer overflow in Webalizer
- An alternative method to check LKM backdoor/rootkit
- RE: Ability to read buddy list of AIM users
- Re: Ability to read buddy list of AIM users
- Microsoft IIS 5.0 CodeBrws.asp Source Disclosure
- Mailman/Pipermail private mailing list/local user vulnerability
- Re: ansi outer join syntax in Oracle allows access to any data
- AIM's 'Direct Connection' feature could lead to arbitrary file creation
- [SNS Advisory No.51] Compaq Tru64 UNIX libc Buffer Overflow Vulnerability
- [SNS Advisory No.50] Compaq Tru64 UNIX dtprintinfo "-session" Buffer Overflow Vulnerability
- Re: ansi outer join syntax in Oracle allows access to any data
- Webtrends Reporting Center Buffer Overflow (#NISR17042002C)
- From: NGSSoftware Insight Security Research
- Back Office Web Administrator Authentication Bypass (#NISR17042002A)
- From: NGSSoftware Insight Security Research
- Ammendum: A crash course with Linux Kernel 2.4.x, IP ID values & RFC 791
- Buffer Overrun in Talentsoft's Web+ (3) (#NISR17042002B)
- From: NGSSoftware Insight Security Research
- Re: Microsoft IIS 5.0 CodeBrws.asp Source Disclosure
- KPMG-2002011: Windows 2000 microsoft-ds Denial of Service
- IBM Informix Web DataBlade: Local root by design
- Re: Microsoft IIS 5.0 CodeBrws.asp Source Disclosure
- RE: Microsoft IIS 5.0 CodeBrws.asp Source Disclosure
- Microsoft Security Bulletin MS02-019: Unchecked Buffer in Internet Explorer and Office for Mac Can Cause Code to Execute (Q321309)
- Re: An alternative method to check LKM backdoor/rootkit
- Re: Snort exploits
- RE: Raptor Firewall FTP Bounce vulnerability
- From: Lysel Christian Emre
- RE: Raptor Firewall FTP Bounce vulnerability
- segfault in ntop
- KPMG-2002012: Sambar Webserver Serverside Fileparse Bypass
- IBM Security Advisory: IBM Tivoli Policy Director WebSEAL
- Re: Raptor Firewall FTP Bounce vulnerability
- Re: An alternative method to check LKM backdoor/rootkit
- RE: An alternative method to check LKM backdoor/rootkit
- RE: Raptor Firewall FTP Bounce vulnerability
- Re: Remote buffer overflow in Webalizer
- From: Bradford L. Barrett
- RE: Snort exploits
- [[ TH 026 Inc. ]] SA #1 - Multiple vulnerabilities in PVote 1.5
- FreeBSD Security Advisory FreeBSD-SA-02:21.tcpip
- From: FreeBSD Security Advisories
- Re: fragroute vs. snort: the tempest in a teacup
- Re: Snort exploits
- KPMG-2002013: Coldfusion Path Disclosure
- MDKSA-2002:024-1 - rsync update
- From: Mandrake Linux Security Team
- KPMG-2002012: (Re-submitted) Sambar Webserver Serverside Fileparse Bypass
- Re: An alternative method to check LKM backdoor/rootkit
- From: Karsten W. Rohrbach
- Re: Microsoft IIS 5.0 CodeBrws.asp Source Disclosure
- RE: segfault in ntop
- Re: [Snort-devel] Re: Re: Snort exploits
- Re: Snort exploits
- FreeBSD Security Advisory FreeBSD-SA-02:18.zlib [REVISED]
- From: FreeBSD Security Advisories
- fragroute vs. snort: the tempest in a teacup
- Restricted Shells
- Re: Microsoft Security Bulletin - MS02-020
- HiverCon 2002
- Microsoft Security Bulletin MS02-020:SQL Extended Procedure Functions Contain Unchecked Buffers (Q319507)
- Re: KPMG-2002013: Coldfusion Path Disclosure
- List of extended sprocs that are vulnerable? FW: Microsoft Security Bulletin MS02-020
- Howto exploit a remote format bug automatically
- Amazon.com Password limit
- Remote Timing Techniques over TCP/IP
- Re: fragroute vs. snort: the tempest in a teacup
- Re: Snort exploits
- Re: Snort exploits
- Re: ansi outer join syntax in Oracle allows access to any data
- 答复: An alternative method to check LKM backdoor/rootkit
- MHonArc v2.5.2 Script Filtering Bypass Vulnerability
- Re: Remote buffer overflow in Webalizer
- Re: List of extended sprocs that are vulnerable? FW: Microsoft Security Bulletin MS02-020
- RE: KPMG-2002013: ColdFusion Path Disclosure
- [[ TH 026 Inc. ]] SA #2 - IcrediBB 1.1, Cross Site Scripting vulnerability.
- Re: Remote Timing Techniques over TCP/IP
- Re: Remote Timing Techniques over TCP/IP
- Re: Howto exploit a remote format bug automatically
- KPMG-2002014: Foundstone Fscan Format String Bug
- Re: fragroute vs. snort: the tempest in a teacup
- KPMG-2002015: Microsoft Distributed Transaction Coordinator DoS
- RE: segfault in ntop
- From: Burton M. Strauss III
- Re: Amazon.com Password limit
- Re: Nortel CVX 1800s will dump all local user names and passwords via SNMP
- Xpede many vulnerabilities
- Re: KPMG-2002013: Coldfusion Path Disclosure
- Summercon 2002 CFP
- Tomcat 4.1 real path disclosure
- Re: NSFOCUS SA2002-02 : Microsoft Windows MUP overlong request kernel overflow
- Re: fragroute vs. snort: the tempest in a teacup
- Snitz Forums 2000 remote SQL query manipulation vulnerability
- Re: Tomcat 4.1 real path disclosure
- Re: Restricted Shells
- Re: Microsoft Security Bulletin - MS02-020
- OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow
- Re: Tomcat 4.1 real path disclosure
- Re: Remote Timing Techniques over TCP/IP
- Re: Microsoft Security Bulletin - MS02-020
- Another Faq-O-Matic XSS Vuln?
- Vulnerability in PostCalendar
- Re: fragroute vs. snort: the tempest in a teacup
- Re: fragroute vs. snort: the tempest in a teacup
- Cross site scripting in almost every mayor website
- Keyservers Cross Site Scripting (When CSS Gets Dangerous)
- DoS in Multiple IE Versions (Self-Referenced Directives)
- Re: Cross site scripting @verisign.com and @cybercash.com
- DOS for Icq 2001&2002
- Cross site scripting @verisign.com and @cybercash.com
Mail converted by MHonArc
This mailing list archive is a service of Copilotco.