BugTraq Mode:
(Page 1399 of 1748)  < Prev  1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404  Next >
Linux kernel sys_uselib local root vulnerability 2005-01-07
Paul Starzetz (ihaquer isec pl)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi all,

first of all I must comply about the handling of this vulnerability that I
reported to vendorsec. Obviously my code posted there has been stolen and
plagiated by Stefan Esser from Ematters. The posting containing the
plagiate will follow. Now I

[ more ]  [ reply ]
Mozilla XBM Image Vulnerability 2005-01-08
Luca Ercoli (luca ercoli inwind it)


Package: Mozilla

Auth: http://www.mozilla.org

Vulnerability Type: Remote Denial Of Service

Affected Software: Mozilla ver. 1.6 for Windows

(maybe vulnerable also prior versions)

Not vulnerable: Mozilla for Linux

What's Mozilla:

--------------

Mozilla is a

[ more ]  [ reply ]
grsecurity 2.1.0 release / 5 Linux kernel advisories 2005-01-07
spender grsecurity net (Brad Spengler)
Let's try this again, since web archives don't like multipart
attachments.

grsecurity 2.1.0 release / Linux Kernel advisories
--------------------------------------------------------------------

Table Of Contents:
1) grsecurity 2.1.0 announcement and changelog
2) Linux Kernel advisory introductio

[ more ]  [ reply ]
grsecurity 2.1.0 release / 5 Linux kernel advisories 2005-01-07
spender grsecurity net (Brad Spengler)
grsecurity 2.1.0 release / Linux Kernel advisories
--------------------------------------------------------------------

Table Of Contents:
1) grsecurity 2.1.0 announcement and changelog
2) Linux Kernel advisory introduction
3) 2.4/2.6 random poolsize sysctl handler integer overflow
4) 2.6 scsi ioct

[ more ]  [ reply ]
Santy and SSL 2005-01-06
Ofer Shezaf (Ofer Shezaf breach com)

Since my company sells a product that decrypts SSL traffic in order to
enable intrusion detection systems to inspect it, I was looking for
examples of real world attacks hidden in SSL traffic.

As part of this research I examined Santy and found out that:
a. there are many phpBB sites protected by

[ more ]  [ reply ]
WinAc AND WinHKI ZIP File Directory Transversal 2005-01-06
Rafel Ivgi, The-Insider (theinsider 012 net il)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application: WinAce, WinHKI
Vendors: http://www.webtoolmaster.com
Versions: 1.4d
Platforms: Windows
Bug: ZIP File Directory Transversal
Exploitation: Local (extract file)
Date: 24 Dec

[ more ]  [ reply ]
[ GLSA 200501-10 ] Vilistextum: Buffer overflow vulnerability 2005-01-06
Thierry Carrez (koon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[ GLSA 200501-09 ] xzgv: Multiple overflows 2005-01-06
Thierry Carrez (koon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[ GLSA 200501-08 ] phpGroupWare: Various vulnerabilities 2005-01-06
Luke Macken (lewk gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
MDKSA-2005:004 - Updated nasm packages fix buffer overflow vulnerability 2005-01-06
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: nasm
Advisory ID:

[ more ]  [ reply ]
MDKSA-2005:003 - Updated vim packages fix modeline vulnerabilities 2005-01-06
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: vim
Advisory ID:

[ more ]  [ reply ]
MDKSA-2005:002 - Updated wxGTK2 packages fix vulnerabilities 2005-01-06
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: wxGTK2
Advisory ID:

[ more ]  [ reply ]
re: All Symantec Products All Versions Until 2005 - Remote Stack Buffer Overflow 2005-01-06
Sym Security (secure symantec com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Symantec is aware and currently investigating this issue.

Symantec Product Security Team
Symantec takes the security of our products seriously and is a
responsible disclosure company. You can view our response policies
at http://www.symantec.com/secur

[ more ]  [ reply ]
MDKSA-2005:001 - Updated libtiff packages fix multiple vulnerabilities 2005-01-06
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: libtiff
Advisory ID:

[ more ]  [ reply ]
[CLA-2005:913] Conectiva Security Announcement - samba 2005-01-06
Conectiva Updates (secure conectiva com br)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--

PACKAGE : samba
SUMMARY : Fixes for Samba vulnerabiliti

[ more ]  [ reply ]
[ GLSA 200501-07 ] xine-lib: Multiple overflows 2005-01-06
Thierry Carrez (koon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[USN-55-1] imlib2 vulnerabilities 2005-01-06
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-55-1 January 06, 2005
imlib2 vulnerabilities
CAN-2004-1025, CAN-2004-1026
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Wart

[ more ]  [ reply ]
[USN-54-1] TIFF library tool vulnerability 2005-01-06
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-54-1 January 06, 2005
tiff vulnerability
CAN-2004-1183
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The fol

[ more ]  [ reply ]
RE: All Symantec Products All Versions Until 2005 - Remote Stack Buffer Overflow 2005-01-06
Polazzo Justin (Justin Polazzo facilities gatech edu)
Does this affect Symantec Corporate Edition as well?

-----Original Message-----
From: Rafel Ivgi, The-Insider [mailto:theinsider (at) 012.net (dot) il [email concealed]]
Sent: Thursday, January 06, 2005 2:21 AM
To: vulnwatch (at) vulnwatch (dot) org [email concealed]; Windows NTBugtraq Mailing List;
list (at) securiteam (dot) com [email concealed]; full-disclosure (at) lists.netsys (dot) com [email concealed];

[ more ]  [ reply ]
Socket unreacheable in Amp II engine 2005-01-06
Luigi Auriemma (aluigi autistici org)

#######################################################################

Luigi Auriemma

Application: Amp II 3D engine
http://www.4drulers.com/amp.html
Versions: any version since there is no patch available
Games: Gore: Ultimate Soldier <= 1.5

[ more ]  [ reply ]
[SECURITY] [DSA 628-1] New imlib2 packages fix arbitrary code execution 2005-01-06
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 628-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
January 6th, 2005

[ more ]  [ reply ]
[SECURITY] [DSA 626-1] New tiff packages fix denial of service 2005-01-06
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 626-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
January 6th, 2005

[ more ]  [ reply ]
[SECURITY] [DSA 627-1] New namazu2 packages fix cross-site scripting vulnerability 2005-01-06
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 627-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
January 6th, 2005

[ more ]  [ reply ]
RE: Paper: SQL Injection Attacks by Example 2005-01-05
Sergey Chernyshev (Sergey courttv com)
I believe changing to stored procedures is good not just because it's
impossible to inject something to the query the same way it's done with
regular queries - but because in addition to that you can restrict
permissions for connected user to run only stored procedures and be even
more specific with

[ more ]  [ reply ]
All Symantec Products All Versions Until 2005 - Remote Stack Buffer Overflow 2005-01-06
Rafel Ivgi, The-Insider (theinsider 012 net il)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application: All Symantec Products All Versions Until 2005
Vendors: http://www.symantec.com/nav/nav_pro/
Platforms: Windows
Bug: Stack Buffer Overflow
Risk: Low - Crash - Not Exp

[ more ]  [ reply ]
[ GLSA 200501-06 ] tiff: New overflows in image decoding 2005-01-05
Thierry Carrez (koon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-06
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[ GLSA 200501-05 ] mit-krb5: Heap overflow in libkadm5srv 2005-01-05
Sune Kloppenborg Jeppesen (jaervosz gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
RE: Paper: SQL Injection Attacks by Example 2005-01-05
Scovetta, Michael V (Michael Scovetta ca com)
Chip--

I agree-- and for the Java junkies in the house:

ps = con.prepareStatement("update people set name = ? where nid = ?");
ps.setString(1, request.getParameter("name"));
ps.setString(2, request.getParameter("nid"));
ps.executeUpdate();

I must say, I like the Java syntax much better th

[ more ]  [ reply ]
(Page 1399 of 1748)  < Prev  1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus