Bugtraq: by date

155 messages starting Feb 03 14 and ending Feb 28 14
Date index | Thread index | Author index


Monday, 03 February

[SECURITY] [DSA 2850-1] libyaml security update Salvatore Bonaccorso
CVE-2014-1213 - Denial of Service in Sophos Anti Virus advisories
[SECURITY] [DSA 2851-1] drupal6 security update Salvatore Bonaccorso
Security advisory, LedgerSMB 1.3.0-1.3.36 Chris Travers

Tuesday, 04 February

[slackware-security] pidgin (SSA:2014-034-01) Slackware Security Team

Wednesday, 05 February

Security Advisory: NETGEAR Router D6300B Firmware: V1.0.0.14_1.0.14 marcel . mangold
ESA-2014-005: EMC Documentum Foundation Services (DFS) Content Access Vulnerability Security Alert

Thursday, 06 February

Multiple SQL Injection Vulnerabilities in AuraCMS High-Tech Bridge Security Research
SQL Injection in doorGets CMS High-Tech Bridge Security Research
[SECURITY] [DSA 2853-1] horde3 security update Luciano Bello
Inteno DG301 Command Injection post
[ISecAuditors Security Advisories] Multiple reflected XSS vulnerabilities in Atmail WebMail ISecAuditors Security Advisories
[SECURITY] [DSA 2855-1] libav security update Moritz Muehlenhoff
[SECURITY] CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS Mark Thomas
German Telekom Bug Bounty #9 - Code Execution Vulnerability Vulnerability Lab
CVE-2014-1214 - Remote Code Execution in Projoom NovaSFH Plugin advisories
German Telekom Bug Bounty #10 - Arbitrary File Upload Vulnerability Vulnerability Lab
German Telekom Bug Bounty #11 - Remote SQL Injection Vulnerability Vulnerability Lab
AlienVault OSSIM SQL Injection vulnerability jakx . ppr
CORE-2014-0001 - Publish-It Buffer Overflow Vulnerability CORE Advisories Team

Friday, 07 February

[SECURITY] [DSA 2852-1] libgadu security update Florian Weimer
Information on recently-fixed Oracle VM VirtualBox vulnerabilities Matthew Daley

Sunday, 09 February

gpEasy v4.3.x CMS - Multiple Web Vulnerabilities Vulnerability Lab
Facebook Bug Bounty #12 - Client Side Exception Web Vulnerability Vulnerability Lab
WHMCS Denial of Service Vulnerability iedb . team
[SECURITY] [DSA 2856-1] libcommons-fileupload-java security update Florian Weimer
[oCERT-2014-001] MantisBT input sanitization errors Andrea Barisani

Monday, 10 February

[SECURITY] [DSA 2857-1] libspring-java security update Moritz Muehlenhoff
[slackware-security] mozilla-firefox (SSA:2014-039-01) Slackware Security Team
#CONFidence 2014- Call for Papers, only 0111 days left to become CONFidence ninja Andrzej Targosz
[slackware-security] seamonkey (SSA:2014-039-03) Slackware Security Team
ASUS AiCloud Enabled Routers 12 Models - Authentication bypass and Sensitive file/path disclosure kyle Lovett
[slackware-security] mozilla-thunderbird (SSA:2014-039-02) Slackware Security Team

Tuesday, 11 February

Phpbb Forum Denial of Service Vulnerability iedb . team
Open-Xchange Security Advisory 2014-02-10 Martin Braun
[SECURITY] [DSA 2858-1] iceweasel security update Moritz Muehlenhoff
[SECURITY] [DSA 2859-1] pidgin security update Moritz Muehlenhoff
[mwrlabs advisory][CVE-2014-0748] Cray Aprun/Apinit Privilege Escalation john . fitzpatrick

Thursday, 13 February

Wordpress all_in_one_carousel Plugin /XSS/CSRF/ Vuln iedb . team
WiFi Camera Roll v1.2 iOS - Multiple Web Vulnerabilities Vulnerability Lab
[ MDVSA-2014:025 ] pidgin security
[SECURITY] [DSA 2860-1] parcimonie security update Salvatore Bonaccorso
[CVE-2014-1903] FreePBX 2.9 through 12 RCE rob . thomas
[SECURITY] [DSA 2850-2] libyaml regression update Salvatore Bonaccorso
jDisk (stickto) v2.0.3 iOS - Multiple Web Vulnerabilities Vulnerability Lab
[ MDVSA-2014:026 ] openldap security
Mybb All Version Denial of Service Vulnerability iedb . team
APPLE-SA-2014-02-11-1 Boot Camp 5.1 Apple Product Security
ASUS RT Series Routers FTP Service - Default anonymous access kyle Lovett
[ MDVSA-2014:027 ] php security
Re: ASUS RT Series Routers FTP Service - Default anonymous access kyle Lovett
Wordpress plugin Buddypress <= 1.9.1 stored xss vulnerability Pietro Oliva
Wordpress plugin Buddypress <= 1.9.1 privilege escalation vulnerability Pietro Oliva
[ISecAuditors Security Advisories] - Reflected XSS vulnerability in Boxcryptor (www.boxcryptor.com) ISecAuditors Security Advisories

Friday, 14 February

Critical security flaws in Nagios NRPE client/server crypto Aaron Zauner
RE: CVE-2014-1219 - Unauthenticated Privilege Escalation in CA 2E Web Option Williams, James K
[ MDVSA-2014:028 ] mariadb security
[slackware-security] ntp (SSA:2014-044-02) Slackware Security Team
[slackware-security] curl (SSA:2014-044-01) Slackware Security Team
[ MDVSA-2014:029 ] mysql security

Monday, 17 February

ESA-2014-009: RSA BSAFE® SSL-J Multiple Vulnerabilities Security Alert
[ MDVSA-2014:034 ] yaml security
[ MDVSA-2014:031 ] drupal security
[ MDVSA-2014:033 ] socat security
[ MDVSA-2014:032 ] flite security
CISTI'2014: List of Workshops ML
[SWRX-2014-001] Open Web Analytics Pre-Auth SQL Injection no-reply
phpMyBackupPro-2.4 Cross-Site Scripting vulnerability iedb . team
Full Disclosure - Linksys EA2700, EA3500, E4200 and EA4500 - Authentication Bypass to Administrative Console kyle Lovett
Office Assistant Pro v2.2.2 iOS - File Include Vulnerability Vulnerability Lab
mbDriveHD v1.0.7 iOS - Multiple Web Vulnerabilities Vulnerability Lab
File Hub v1.9.1 iOS - Multiple Web Vulnerabilities Vulnerability Lab
[SECURITY] [DSA 2861-1] file security update Salvatore Bonaccorso
[SECURITY] [DSA 2862-1] chromium-browser security update Michael Gilbert
Jetro Cockpit Secure Browsing vulnerability - Client missing input validation allowing RCE Ronen Z
My PDF Creator & DE DM v1.4 iOS - Multiple Vulnerabilities Vulnerability Lab
[ MDVSA-2014:035 ] libpng security
[ MDVSA-2014:036 ] varnish security
Recon 2014 Call For Papers - June 27-29, 2014 - Montreal, Quebec cfp2014
[ MDVSA-2014:037 ] ffmpeg security
[ MDVSA-2014:038 ] kernel security

Tuesday, 18 February

Re: [Full-disclosure] CVE-2013-1643 - Unauthorised Access To Other Users Email Messages in Symantec PGP Universal Web Messenger Tim Brown
SEC Consult SA-20140218-0 :: Multiple critical vulnerabilities in Symantec Endpoint Protection SEC Consult Vulnerability Lab

Wednesday, 19 February

[ MDVSA-2014:040 ] puppet security
CVE-2014-1215 - Local Code Execution in CoreFTP Core FTP Server Portcullis Advisories
[SECURITY] [DSA 2863-1] libtar security update Luciano Bello
[ MDVSA-2014:039 ] libgadu security
CA20140218-01: Security Notice for CA 2E Web Option Williams, James K

Thursday, 20 February

[ MDVSA-2014:043 ] gnutls security
[ MDVSA-2014:042 ] tomcat6 security
Barracuda Message Archiver 650 - Persistent Web Vulnerability Vulnerability Lab
Cisco Security Advisory: Cisco UCS Director Default Credentials Vulnerability Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Firewall Services Module Cut-Through Proxy Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team
Post Exploitation - Getting username and password in the Lotus Sametime 8.5.1 adrianomarciomonteiro
[ MDVSA-2014:044 ] zarafa security
VideoCharge Studio v2.12.3.685 cc.dll CHTTPResponse::GetHttpResponse() Buffer Overflow Remote Code Execution Julien Ahrens
[ MDVSA-2014:041 ] python security
[slackware-security] kernel (SSA:2014-050-03) Slackware Security Team
Cisco Security Advisory: Unauthorized Access Vulnerability in Cisco Unified SIP Phone 3905 Cisco Systems Product Security Incident Response Team
SQL Injection in AdRotate High-Tech Bridge Security Research
Cisco Security Advisory: Multiple Vulnerabilities in Cisco IPS Software Cisco Systems Product Security Incident Response Team
[slackware-security] mariadb, mysql (SSA:2014-050-02) Slackware Security Team
[ MDVSA-2014:045 ] libtar security
Android & iOS Hands-on Exploitation at SyScan 2014 xys3c team
[HITB-Announce] Haxpo CFP Hafez Kamal

Friday, 21 February

[SECURITY] [DSA 2864-1] postgresql-8.4 security update Moritz Muehlenhoff
[CVE-2014-2035] XSS in InterWorx Web Control Panel <= 5.0.12 Eric Flokstra
[slackware-security] gnutls (SSA:2014-050-01) Slackware Security Team
[SECURITY] [DSA 2865-1] postgresql-9.1 security update Moritz Muehlenhoff
ASUS router drive-by code execution via XSS and authentication bypass buqtraq
Barracuda Bug Bounty #36 Firewall - Client Side Exception Handling Web Vulnerability Vulnerability Lab
[ MDVSA-2014:046 ] phpmyadmin security
CNNVD Gov CN #1 - Filter Bypass & Persistent Web Vulnerability Vulnerability Lab

Monday, 24 February

[ MDVSA-2014:047 ] postgresql security
44CON 2014 September 11th - 12th CFP Open Steve
CVE-2014-1223 - Cross-site Scripting in Telligent Evolution Portcullis Advisories
APPLE-SA-2014-02-21-1 iOS 6.1.6 Apple Product Security
APPLE-SA-2014-02-21-2 iOS 7.0.6 Mihaela Popescu-Stanesti
APPLE-SA-2014-02-21-3 Apple TV 6.0.2 Mihaela Popescu-Stanesti
APPLE-SA-2014-02-21-2 iOS 7.0.6 Apple Product Security
APPLE-SA-2014-02-21-1 iOS 6.1.6 Apple Product Security
APPLE-SA-2014-02-21-3 Apple TV 6.0.2 Apple Product Security
DC4420 - London DEFCON - meeting Tuesday, 25th February 2014 Major Malfunction
[SECURITY] [DSA 2866-1] gnutls26 security update Salvatore Bonaccorso
[CISTI'2014]: Iberian Conference on IST; Barcelona; Deadline: February 28 ML
[SECURITY] [DSA 2867-1] otrs2 security update Salvatore Bonaccorso
Barracuda Networks Bug Bounty #35 - Persistent Web Vulnerability Vulnerability Lab
WiFiles HD v1.3 iOS - File Include Web Vulnerability Vulnerability Lab
[security bulletin] HPSBMU02964 rev.1 - HP Service Manager, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access, Disclosure of Information and Authentication Issues security-alert

Tuesday, 25 February

[security bulletin] HPSBST02937 rev.1 - HP StoreVirtual 4000 and StoreVirtual VSA Software dbd_manager, Remote Execution of Arbitrary Code security-alert
[security bulletin] HPSBMU02971 rev.1 - HP Application Information Optimizer, Remote Execution of Code, Information Disclosure security-alert
[SECURITY] CVE-2014-0033 Session fixation still possible with disableURLRewriting enabled Mark Thomas
[SECURITY] CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service) Mark Thomas
[SECURITY] CVE-2013-4590 Information disclosure via XXE when running untrusted web applications Mark Thomas
[SECURITY] CVE-2013-4286 Incomplete fix for CVE-2005-2090 (Information disclosure) Mark Thomas
Barracuda Networks Firewall Bug Bounty #32 - Filter Bypass & Persistent Web Vulnerabilities Vulnerability Lab
[RT-SA-2014-001] McAfee ePolicy Orchestrator: XML External Entity Expansion in Dashboard RedTeam Pentesting GmbH

Wednesday, 26 February

APPLE-SA-2014-02-25-1 OS X Mavericks 10.9.2 and Security Update 2014-001 Apple Product Security
APPLE-SA-2014-02-25-2 Safari 6.1.2 and Safari 7.0.2 Apple Product Security
[security bulletin] HPSBPI02869 SSRT100936 rev.3 - HP LaserJet MFP Printers, HP Color LaserJet MFP Printers, Certain HP LaserJet Printers, Remote Unauthorized Access to Files security-alert
[security bulletin] HPSBMU02966 rev.1 - HP Operations Orchestration, Unauthorized Access to Information security-alert
[security bulletin] HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software Security - Apache Tomcat and Oracle Updates security-alert
APPLE-SA-2014-02-25-3 QuickTime 7.7.5 Apple Product Security
Authentication-Bypass in CosmoShop ePRO V10.17.00 (and lower, maybe higher) innate
Persistent XSS in Media File Renamer V1.7.0 wordpress plugin Larry W. Cashdollar
Barracuda Networks Bug Bounty #31 Firewall - Persistent Access Policy Vulnerability Vulnerability Lab
Cisco Security Advisory: Cisco Prime Infrastructure Command Execution Vulnerability Cisco Systems Product Security Incident Response Team

Thursday, 27 February

Barracuda Networks Backup Appliance Application - Persistent Web Vulnerability Vulnerability Lab
Office 365 - Account Hijacking Cookie Re-Use Flaw, extended Oei, Géry
Update: CVE-2014-0053 Information Disclosure when using Grails Pivotal Security Team
SEC Consult SA-20140227-0 :: Local Buffer Overflow vulnerability in SAS for Windows (Statistical Analysis System) SEC Consult Vulnerability Lab
Multiple Vulnerabilities in VideoWhisper Live Streaming Integration WP Plugin High-Tech Bridge Security Research

Friday, 28 February

[slackware-security] subversion (SSA:2014-058-01) Slackware Security Team
SEC Consult SA-20140228-0 :: Privilege escalation vulnerability in MICROSENS Profi Line Modular Industrial Switch SEC Consult Vulnerability Lab
SEC Consult SA-20140228-1 :: Authentication bypass (SSRF) and local file disclosure in Plex Media Server SEC Consult Vulnerability Lab