BugTraq Mode:
(Page 1480 of 1748)  < Prev  1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485  Next >
Remote crash of Half-Life servers and clients (versions before the 07 July 2004) 2004-07-12
Luigi Auriemma (aluigi autistici org)

#######################################################################

Luigi Auriemma

Application: Half-Life engine
http://half-life.sierra.com
http://www.steampowered.com
Versions: before the 07 July 2004 (both Steam and not-Steam)
P

[ more ]  [ reply ]
MSIE Similar Method Name Redirection Cross Site/Zone Scripting Vulnerability 2004-07-11
Paul (paul greyhats cjb net)


Note: This vulnerability and many more can be found at http://www.greyhats.cjb.net

SimliarMethodNameRedir

Automatic Remote Compromise

[Tested]

IEXPLORE.EXE file version 6.0.2800.1106

MSHTML.DLL file version 6.00.2800.1400

Microsoft Windows XP sp2

[Discussion]

At first I thought this

[ more ]  [ reply ]
MSOE Javascript Execution Vulnerability 2004-07-11
Paul (paul greyhats cjb net)


Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net

Outlook Express Window Opener Script Execution Vulnerability

[Tested]

Microsoft Outlook Express version 6.0.2800.1123.

Microsoft Windows XP sp2

[Discussion]

Microsoft Outlook Express is prone

[ more ]  [ reply ]
Re: HijackClick 3 2004-07-12
http-equiv (at) excite (dot) com [email concealed] (1 malware com)


<!--

Microsoft just disabled those functions from
being called when the mouse button is down and called it
patched. No more hijackclick,
right?

Wrong.

-->

This is absolutely fantastic Paul, with a patented double-click
of the mouse we can remotely take over the target's computer:

Just sub

[ more ]  [ reply ]
MOZILLA: SHELL can execute remote EXE program 2004-07-09
liudieyu umbrella name


SUBJ: MOZILLA: SHELL can execute remote EXE program
DATE: 2004/07/09
FROM: Liu Die Yu <liudieyu AT umbrella D0T name>
############################################################
[START] Advisory
############################################################

COPYRIGHT
---------
This Advisory is Co

[ more ]  [ reply ]
RE: MSIE Download Window Filename + Filetype Spoofing Vulnerability 2004-07-12
Drew Copley (dcopley eEye com)
This is an open bug. (One which is rather disturbing, so I am
not sure why Microsoft has chosen to not fix it.)

Date: 21 October 2001
http://www.guninski.com/popspoof.html

"Demonstration:

Image moving over download/open dialog:
http://www.guninski.com/opf2.html "

> -----Original Message--

[ more ]  [ reply ]
HijackClick 3 2004-07-11
Paul (paul greyhats cjb net)


Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net

HijackClick 3!!!

Took the name from Liu Die Yu :)

[Tested]

IEXPLORE.EXE file version 6.0.2800.1106

MSHTML.DLL file version 6.00.2800.1400

Microsoft Windows XP sp2

[Discussion]

The HijackCli

[ more ]  [ reply ]
I small poem in JScript 2004-07-11
Berend-Jan Wever (skylined edup tudelft nl)
I just wrote a small poem in JScript:

<SCRIPT language="javascript">

MSIE = window.open; // for hackers to come in
for (every_bug_found in MSIE) { /* there are zillions more hiden */ }

</SCRIPT>

Ok, so it doen't rhyme... but it is another null-pointer exception DoS in MSIE 6.0sp1 (fully patc

[ more ]  [ reply ]
Media Preview Script Execution Vulnerability 2004-07-11
Paul (paul greyhats cjb net)


Note: This vulnerability as well as several more can be found at http://www.geryhats.cjb.net

Media Preview Script Execution Vulnerability

[Tested]

MSDXM.DLL file version 6.4.09.1128

Microsoft Windows 2000

[Discussion]

By using the windows media player control, media can be played in

[ more ]  [ reply ]
MSIE Download Window Filename + Filetype Spoofing Vulnerability 2004-07-11
Paul (paul greyhats cjb net)


Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net

Download Window Filename + Filetype Spoofing Vulnerability

[Tested]

IEXPLORE.EXE file version 6.0.2800.1106

MSHTML.DLL file version 6.00.2800.1400

Microsoft Windows XP sp2

[Discussion]

When

[ more ]  [ reply ]
[BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7 2004-07-10
David Miller (justdave bugzilla org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Bugzilla Security Advisory
July 10, 2004

Summary
=======

Bugzilla is a Web-based bug-tracking system, used by a large number of
software projects.

This advisory covers security bugs that have recently been discovered
and fixed in the Bugzilla code: I

[ more ]  [ reply ]
[ GLSA 200407-09 ] MoinMoin: Group ACL bypass 2004-07-11
Kurt Lieber (klieber gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200407-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[ GLSA 200407-10 ] rsync: Directory traversal in rsync daemon 2004-07-12
Kurt Lieber (klieber gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200407-10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
Re: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!] 2004-07-10
Bipin Gautam (visitbipin hotmail com)
In-Reply-To: <40EEE9C0.4040108 (at) mojohosting (dot) com [email concealed]>

>The same thing happens with classic mail bombs like 42.zip, NAV can't

>handle them.

>

>Alan Parks

42.zip was a arc. BOMB and a different story... It's similar to my WinRar advisory that date back, 2003.

Well, within few seconds... after t

[ more ]  [ reply ]
[tool] p0f 2.0.4 is out 2004-07-10
Michal Zalewski (lcamtuf coredump cx)
I am proud to announce the availability of p0f 2.0.4, a passive OS
fingerprinter (and more). Since 2.0.1 (announced here over a year
ago), p0f has gained features such as:

- RST+ACK (connection refused) fingerprinting,
- Official SYN+ACK (outgoing connection) fingerprinting support,
- Sophist

[ more ]  [ reply ]
current leading bots used in drone armies [June/July 2004] 2004-07-08
Gadi Evron (gadie cbs gov il)
[For the list of the most used Trojan horses in drone armies for June/July,
2004, please skip to the end of this email message.]

I figured a list of this nature once in a while (maybe quarterly or monthly
depending on the changing threats) can be useful to some administrators who
wish to actively c

[ more ]  [ reply ]
Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-10
Marc Schoenefeld (schonef uni-muenster de) (1 replies)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi y'all,
I have not found the contact address for microsoft jvm
security issues, therefore maybe someone who reads
bugtraq can forward this:
in the Microsoft (R) VM for Java, 5.0 Release 5.0.0.3810
the implementation of some core system classes allows

[ more ]  [ reply ]
Re: Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-11
Siva Subbu (sivasub23 hotmail com) (1 replies)
Re: Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-11
Marc Schoenefeld (schonef uni-muenster de)
MDKSA-2004:067 - Updated ethereal packages fix multiple vulnerabilities 2004-07-09
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: ethereal
Advisory ID:

[ more ]  [ reply ]
RE: Microsoft Word Email Object Data Vulnerability 2004-07-09
Drew Copley (dcopley eEye com)
How did you find this? Did someone email this to you? Did
you discover this variation?

(Being that the original bug was mine, I have some interest
in a new variation being exploited by spammers... especially
if it was genuinely found in the wild.)

And, why is Microsoft ignoring this bug? If you f

[ more ]  [ reply ]
RE: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!] 2004-07-09
Eric McCarty (eric lawmpd com)
Norton Antivirus 2004 Confirmed Vulnerable, Pegged CPU on a 3ghz machine for indefinate amount of time scanning.

Eric

-----Original Message-----
From: Bipin Gautam [mailto:visitbipin (at) hotmail (dot) com [email concealed]]
Sent: Thursday, July 08, 2004 5:47 PM
To: bugtraq (at) securityfocus (dot) com [email concealed]
Subject: Norton AntiVirus Denial

[ more ]  [ reply ]
Re: Microsoft Word Email Object Data Vulnerability 2004-07-09
http-equiv (at) excite (dot) com [email concealed] (1 malware com)


<!--

Outlook 2000 and 2003 allow execution of remote web pages
specified within the data property of OBJECT tags when there is
no closing /OBJECT

-->

This reminds me of something I saw the other day. The following
and a variety of variations will work in Outlook Express
[probably IE as wel

[ more ]  [ reply ]
CYBSEC - Security Advisory: Denial of Service in IBM WebSphereEdge Server 2004-07-08
Leandro Meiners (lmeiners cybsec com)
The following advisory is also available in pdf for download at
http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf

CYBSEC S.A.
www.cybsec.com

Advisory Name: Denial of Service in WebSphere Edge Server.
Vulnerability Class: Denial of Service
Release Date: June 2nd 2004
Affected Application

[ more ]  [ reply ]
[ GLSA 200407-08 ] Ethereal: Multiple security problems 2004-07-09
Kurt Lieber (klieber gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200407-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
MOZILLA: execute local file and its fix 2004-07-09
liudieyu umbrella name


yet another important message appeared at fd, but not at bugtraq:
http://seclists.org/lists/fulldisclosure/2004/Jul/0333.html
it leads to:
http://www.mozilla.org/security/shell.html

you guys must monitor fd :-P

it cost me$$ N months to turn off codeBase - a smiliar issue in IE, but
mozilla made

[ more ]  [ reply ]
Microsoft Word Email Object Data Vulnerability 2004-07-08
James C. Slora, Jr. (james slora phra com)
==============================================
Microsoft Word Email Object Data Vulnerability
==============================================

==============================================
Summary:
==============================================
Outlook 2000 and 2003 allow execution of remote web pa

[ more ]  [ reply ]
(Page 1480 of 1748)  < Prev  1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus