Full Disclosure: by date

259 messages starting Jun 02 13 and ending Jun 30 13
Date index | Thread index | Author index


Sunday, 02 June

FPD and Security bypass vulnerabilities in AntiVirus for WordPress MustLive
[SECURITY] [DSA 2699-1] iceweasel security update Moritz Muehlenhoff
[SECURITY] [DSA 2700-1] wireshark security update Moritz Muehlenhoff
[SECURITY] [DSA 2701-1] krb5 security update Michael Gilbert
Lahana - Disposable VPN -> Tor bridges on EC2 Steve
Re: exploitation ideas under memory pressure Tavis Ormandy

Monday, 03 June

Vulnerable Microsoft VC++ 2005 RTM runtime libraries installed with "Microsoft Security Essentials" (and numerous other Microsoft products) Stefan Kanthak
Re: exploitation ideas under memory pressure Sabniveesu Shashank
Call For Papers - Balkan Computer Congress 2013 BalCCon Org
[SECURITY] [DSA 2702-1] telepathy-gabble security update Salvatore Bonaccorso

Tuesday, 04 June

[GTA-2013-01] - Libsrtp srtp_protect/hmac_compute buffer overflow Groundworks Technologies Advisories Team
[ISecAuditors Security Advisories] Multiple Vulnerabilities in Telaen <= 1.3.0 ISecAuditors Security Advisories
3COM NBX V3000 Networked Telephony Solution Information Disclosure Russell Butturini
Fwd: Iframe Injection On newsroom.cisco.com vinesh redkar
Re: Any.Do sends passwords in plaintext Peter Lustlos
OT github search: extension:php mysql_query $_GET Georgi Guninski
[UPDATED][GTA-2013-01] - Libsrtp srtp_protect/hmac_compute buffer overflow Groundworks Technologies Advisories Team
IA and AFU vulnerabilities in aCMS MustLive
[CORE-2013-0103] Mac OSX Server DirectoryService buffer overflow CORE Security Technologies Advisories

Wednesday, 05 June

[ANN] Struts 2.3.14.3 GA (fast-track) release available Lukasz Lenart
SEC Consult SA-20130605-0 :: Multiple vulnerabilities in CTERA Portal SEC Consult Vulnerability Lab
Plesk Apache Zeroday Remote Exploit king cope
XSS in www.paypal.com Jose Antonio Perez
[Security-news] SA-CONTRIB-2013-051 - Services - Cross site request forgery (CSRF) security-news
CORE-2013-0517 - Xpient Cash Drawer Operation Vulnerability CORE Security Technologies Advisories
Re: Plesk Apache Zeroday Remote Exploit David H
Re: XSS in www.paypal.com Ryan Dewhurst
Microsoft Internet Explorer textNode Use-After-Free Scott Bell
Re: XSS in www.paypal.com Daniel Preussker

Thursday, 06 June

Re: Plesk Apache Zeroday Remote Exploit Kingcope
Re: Plesk Apache Zeroday Remote Exploit Kingcope
Re: XSS in www.paypal.com Kingcope
Re: Plesk Apache Zeroday Remote Exploit Kingcope
Re: Plesk Apache Zeroday Remote Exploit David H
Re: Plesk Apache Zeroday Remote Exploit Milan Berger
Re: Plesk Apache Zeroday Remote Exploit Ed Velez
Botnet using Plesk vulnerability and takedown jtagtgc
Re: XSS in www.paypal.com Ryan Dewhurst
Re: Plesk Apache Zeroday Remote Exploit アドリアンヘンドリック

Friday, 07 June

Remote Execution Exploit in Zpanel 10.0.0.2 Zenny
DEFCON London - DC4420 - June CFP - Lightning talks!!! - Tuesday 25th June 2013 Major Malfunction

Saturday, 08 June

Re: Botnet using Plesk vulnerability and takedown kai
Re: Botnet using Plesk vulnerability and takedown Gichuki John Chuksjonia
XSS in store.apple.com Stefan Schurtz
List Charter John Cartwright
Re: Botnet using Plesk vulnerability and takedown jtagtgc
Bluetooth Chat Connect v1.0 iOS - Multiple Vulnerabilities Vulnerability Lab
Paypal Bug Bounty #12 - PayPal Manager Persistent Listing Vulnerability Vulnerability Lab
Linkedin Social Network - Persistent Web Vulnerability Vulnerability Lab
[SECURITY] [DSA 2703-1] subversion security update Salvatore Bonaccorso

Sunday, 09 June

Re: Botnet using Plesk vulnerability and takedown kai
[SECURITY] [DSA 2704-1] mesa security update Raphael Geissert

Monday, 10 June

CVE-2013-3739 Local File Inclusion in Weathermap <= 0.97C Anthony Dubuissez
Hack Cup 2013 Nicolas Waisman
[SECURITY] [DSA 2705-1] pymongo security update Giuseppe Iuculano
[SECURITY] [DSA 2706-1] chromium-browser security update Giuseppe Iuculano
Why PRISM kills the cloud | Computerworld Blogs Ivan .Heca
Re: Why PRISM kills the cloud | Computerworld Blogs laurent gaffie
Re: Why PRISM kills the cloud | Computerworld Blogs Jeffrey Walton
Re: Why PRISM kills the cloud | Computerworld Blogs Ivan .Heca
Re: Why PRISM kills the cloud | Computerworld Blogs Kurt Buff
Re: Why PRISM kills the cloud | Computerworld Blogs Daniel Preussker
Re: [Dailydave] Hack Cup 2013 Fyodor
Re: Why PRISM kills the cloud | Computerworld Blogs Justin Ferguson

Tuesday, 11 June

Re: Why PRISM kills the cloud | Computerworld Blogs Lorenz Intichar
WordPress 3.5.1, Denial of Service Krzysztof Katowicz-Kowalewski
Fail2ban 0.8.9, Denial of Service (Apache rules only) Krzysztof Katowicz-Kowalewski
[CVE-2013-3961] iSQL in php-agenda <= 2.2.8 Anthony Dubuissez
t2'13: Call for Papers 2013 (Helsinki / Finland) Tomi Tuominen
Re: XSS in store.apple.com Stefan Schurtz
Re: Botnet using Plesk vulnerability and takedown dumMY's
Re: Why PRISM kills the cloud | Computerworld Blogs Reed Black
Re: Why PRISM kills the cloud | Computerworld Blogs Pablo
CORE-2013-0430 - Buffer overflow in Ubiquiti airCam RTSP service CORE Security Technologies Advisories
Re: Why PRISM kills the cloud | Computerworld Blogs Philip Whitehouse
Re: Why PRISM kills the cloud | Computerworld Blogs Justin Ferguson
Re: Why PRISM kills the cloud | Computerworld Blogs Justin Ferguson
Re: Why PRISM kills the cloud | Computerworld Blogs Ivan .Heca
Re: Why PRISM kills the cloud | Computerworld Blogs Justin Ferguson
Re: Why PRISM kills the cloud | Computerworld Blogs Valdis . Kletnieks

Wednesday, 12 June

Re: Why PRISM kills the cloud | Computerworld Blogs Noel Butler
Re: Why PRISM kills the cloud | Computerworld Blogs Noel Butler
Re: Why PRISM kills the cloud | Computerworld Blogs Philip Whitehouse
Re: Why PRISM kills the cloud | Computerworld Blogs Pedro Worcel
Security Analysis of IP video surveillance cameras Javier Repiso Sánchez
Re: Why PRISM kills the cloud | Computerworld Blogs Zenny
[ MDVSA-2013:172 ] wireshark security
Re: Security Analysis of IP video surveillance cameras Leif Nixon
Re: Why PRISM kills the cloud | Computerworld Blogs laurent gaffie
Re: Security Analysis of IP video surveillance cameras Andrew Smith
Re: Security Analysis of IP video surveillance cameras Paul Ammann
Re: Why PRISM kills the cloud | Computerworld Blogs William Reyor
Re: Security Analysis of IP video surveillance cameras Vitor Ventura
Re: Why PRISM kills the cloud | Computerworld Blogs Michael Hallgren
[Security-news] SA-CONTRIB-2013-052 - Display Suite - Cross Site Scripting (XSS) security-news
Re: Why PRISM kills the cloud | Computerworld Blogs Ivan .Heca
Slideware of recent presentations about IPv6 security Fernando Gont

Thursday, 13 June

Re: Why PRISM kills the cloud | Computerworld Blogs Alexander Arlt
[CVE-2013-1768] Apache OpenJPA security vulnerability Jeremy Bauer
[CVE-2013-3684] NextGEN Gallery 1.9.12 Arbitrary File Upload Marcos Agüero
Re: Security Analysis of IP video surveillance cameras Marcos Agüero
Re: Why PRISM kills the cloud | Computerworld Blogs Justin Ferguson
Yet another (unpaid and unfixed) Paypal XSS samuel alp
libpcap: 2 concurrent threads acquiring on the same interface Descombes Thierry
[SECURITY] [DSA 2707-1] dbus security update Yves-Alexis Perez
LSE Leading Security Experts GmbH - LSE-2013-06-13 - Avira AntiVir Engine LSE Leading Security Experts GmbH (Security Advisories)
CFP Extended - OWASP InfoSec India Conference 2013 Dhruv Soi
Re: Lahana - Disposable VPN -> Tor bridges on EC2 François
[ MDVSA-2013:173 ] subversion security
CFP Ongoing - www.SEC-T.org September 2013 Mattias Bååth
PAYPAL BUG BOUNTY PROGRAM 2013 - UPDATES & TRANSPARENCY Vulnerability Lab
Re: PAYPAL BUG BOUNTY PROGRAM 2013 - UPDATES & TRANSPARENCY Jeffrey Walton

Friday, 14 June

SEC Consult SA-20130614-0 :: Multiple vulnerabilities in Siemens OpenScape Branch & Session Border Controller SEC Consult Vulnerability Lab
[ MDVSA-2013:174 ] apache security
0day - Microsoft SharePoint (Cloud) - Persistent Exception-Handling Web Vulnerability Vulnerability Lab
Android ICS "adb restore" directory traversal vulnerability Ariel Berkman
Maldives Telecom ISP - Remote SQL Injection Vulnerability Vulnerability Lab

Saturday, 15 June

TaxiMonger 2.6.2; 2.3.3 (Android) - Persistent Application Vulnerability Vulnerability Lab
Facebook Mobile Bug Bounty #7 - Redirect Vulnerability Vulnerability Lab
Various vulnerabilities on dreamhack related sites klondike
Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Defence in Depth
DoS vulnerability in Mozilla Firefox and Microsoft Internet Explorer MustLive

Sunday, 16 June

[SECURITY] [DSA 2708-1] fail2ban security update Yves-Alexis Perez

Monday, 17 June

Defense in depth -- the Microsoft way (part 3) Stefan Kanthak
GreHack 2013 - CFP ends on June, 30 - Conf: Nov. 15, Grenoble, France F. Duchene
Facebook Open URL Redirection Vulnerability 2013 Arul Kumar
Re: Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Valdis . Kletnieks
Re: Microsoft Outlook Vulnerability: S/MIME Lossof Integrity ACROS Security Lists
[ MDVSA-2013:175 ] owncloud security
Re: Microsoft Outlook Vulnerability: S/MIME Lossof Integrity Valdis . Kletnieks
Re: Microsoft Outlook Vulnerability: S/MIMELossof Integrity ACROS Security Lists
[SECURITY] [DSA 2709-1] wireshark security update Moritz Muehlenhoff
Re: Microsoft Outlook Vulnerability: S/MIMELossof Integrity Jeffrey Walton
Re: Microsoft Outlook Vulnerability: S/MIMELossof Integrity Daniël W . Crompton
Re: Microsoft Outlook Vulnerability: S/MIMELossof Integrity Jeffrey Walton
Apple and Wifi Hotspot Credentials Management Vulnerability Jeffrey Walton
Re: Apple and Wifi Hotspot Credentials Management Vulnerability Jeffrey Walton
Re: Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Patrick Dunstan
Re: Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Jeffrey Walton

Tuesday, 18 June

CVE-2013-2153: Apache Santuario C++ signature bypass vulnerability Cantor, Scott
CVE-2013-2154: Apache Santuario C++ stack overflow vulnerability Cantor, Scott
CVE-2013-2155: Apache Santuario C++ denial of service vulnerability Cantor, Scott
Re: CVE-2013-2156: Apache Santuario C++ heap overflow vulnerability Cantor, Scott
Re: Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Darius Jahandarie
Re: Microsoft Outlook Vulnerability: S/MIME Loss of Integrity Alex
Canon Wireless Printer Disclosure & DoS Matt Andreko
Inkasso Trojaner Analysis - Part 1 Curesec Research Team
Re: Full-Disclosure Digest, Vol 100, Issue 21 Daniel Sichel
[SECURITY] [DSA 2710-1] xml-security-c security update Salvatore Bonaccorso
Joomla crypto vulnerability (all versions) Marco Beierer
[SECURITY] [DSA 2628-2] nss-pam-ldapd update Moritz Muehlenhoff
DDoS attacks via other sites execution tool MustLive
[SECURITY] [DSA 2698-1] tiff security update Michael Gilbert

Wednesday, 19 June

User Credentials Leakage in Panda Cloud Office Protection Buherátor
Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software Cisco Systems Product Security Incident Response Team
[SECURITY] [DSA 2711-1] haproxy security update Moritz Muehlenhoff
[CVE-2013-0523] IBM WebSphere Commerce: Encrypted URL Parameter Vulnerable to Padding Oracle Attacks VSR Advisories
[Security-news] SA-CONTRIB-2013-053 - Login Security - Multiple Vulnerabilities security-news
Re: Linkedin Social Network - Persistent Web Vulnerability Vulnerability Lab
[SECURITY] [DSA 2712-1] otrs2 security update Florian Weimer
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Samuel Ports
Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Hunger
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Steven Hartland
Microsofts NEW Bug Bounty Program 2013 & BlueHat Competition Bonus Update! Vulnerability Lab

Thursday, 20 June

Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Mark Felder
Re: Microsofts NEW Bug Bounty Program 2013 & BlueHat Competition Bonus Update! Vulnerability Lab
FPD, XSS and CS vulnerabilities in Slash WP theme for WordPress MustLive
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Valdis . Kletnieks
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Kurt Buff

Friday, 21 June

[DoS] - Real-debrid.fr Torrent2ddl Xpo Xpo
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Georgi Guninski
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Jeffrey Walton
DC4420 - London DEFCON - June meet - Lightning Talks!!! - Tuesday 25th June 2013 Tony Naggs
How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Thomas Dreibholz
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Hunger
Re: [WEB SECURITY] DDoS attacks via other sites execution tool Superman
Exploit: McAfee ePolicy 0wner (ePowner) – Preview Jérôme Nokin
[Newbie] How to search in all full-disclosure () lists grok org uk JOSE DAMICO
Re: [Newbie] How to search in all full-disclosure () lists grok org uk Ryan Dewhurst
Re: [Newbie] How to search in all full-disclosure () lists grok org uk Homer Parker
Re: [Newbie] How to search in all full-disclosure () lists grok org uk Carlos Pantelides
Re: DDoS attacks via other sites execution tool Julius Kivimäki
Re: [Newbie] How to search in all full-disclosure () lists grok org uk Jeffrey Walton
Re: How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Valdis . Kletnieks
DAVOSET v.1.0.6 MustLive
Re: Exploit: McAfee ePolicy 0wner (ePowner) – Preview Hurgel Bumpf

Sunday, 23 June

TOTP and clock advancement Erik Kamerling
Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Wojciech Puchar
Re: [Newbie] How to search in all full-disclosure () lists grok org uk Kingcope
Facebook Information Disclosure Packet Storm
DAVOSET v.1.0.7 MustLive

Monday, 24 June

Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) Kim Henriksen
HKSAR Government issues statement on Edward Snowden Kim Henriksen
SolusVM WHMCS module privilege escalation, also libcurl vuln? Sven Slootweg
Re: SolusVM WHMCS module privilege escalation, also libcurl vuln? Źmicier Januszkiewicz
[ MDVSA-2013:176 ] kernel security
CVE-2013-3685: Root exploit for LG Android devices (target sprite software's backup daemon) Justin Case
[SECURITY] [DSA 2713-1] curl security update Salvatore Bonaccorso

Tuesday, 25 June

SEC Consult SA-20130625-0 :: Multiple vulnerabilities in IceWarp Mail Server SEC Consult Vulnerability Lab
[NSE] Release of nmap nse vulscan 1.0 Marc Ruef
[ MDVSA-2013:177 ] dbus security
[ MDVSA-2013:178 ] nfs-utils security
Magnolia CMS multiple access control vulnerabilities Adrian Furtuna
[SECURITY] [DSA 2714-1] kfreebsd-9 security update Moritz Muehlenhoff

Wednesday, 26 June

Re: How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Źmicier Januszkiewicz
Re: How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Agostino Sarubbo
[SECURITY] [DSA 2716-1] iceweasel security update Moritz Muehlenhoff
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Email Security Appliance Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Web Security Appliance Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Content Security Management Appliance Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco ASA Next-Generation Firewall Fragmented Traffic Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team
[ MDVSA-2013:179 ] firefox security
[Security-news] SA-CONTRIB-2012-136 - Apache Solr Search Autocomplete - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-054 - Fast Permissions Administration - Access Bypass security-news
Re: How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Nick Boyce
CVE-2013-2210 Cantor, Scott
[SECURITY] [DSA 2715-1] puppet security update Raphael Geissert
Re: How to lock up a VirtualBox host machine with a guest using tracepath over virtio-net network interface Źmicier Januszkiewicz

Thursday, 27 June

[ MDVSA-2013:180 ] curl security
[ MDVSA-2013:181 ] mesa security
[ MDVSA-2013:182 ] mesa security
[ MDVSA-2013:183 ] java-1.7.0-openjdk security
[ MDVSA-2013:184 ] perl-Dancer security
[ MDVSA-2013:185 ] perl-Module-Signature security
Denial of Service in WordPress MustLive
Re: Denial of Service in WordPress Ryan Dewhurst
Please update your plant. On recent WinCC SCADA fixes scadastrangelove
Re: Denial of Service in WordPress MustLive
Re: Denial of Service in WordPress Julius Kivimäki
Sony Playstation Network Account Service System - Password Reset (Session) Vulnerability Vulnerability Lab
eFile Wifi Transfer Manager 1.0 iOS - Multiple Vulnerabilities Vulnerability Lab
Mobile USB Drive HD 1.2 - Arbitrary File Upload Vulnerability Vulnerability Lab
Barracuda CudaTel 2.6.02.04 - Persistent Web Vulnerability Vulnerability Lab
Barracuda CudaTel 2.6.02.04 - Multiple Web Vulnerabilities Vulnerability Lab
Re: Denial of Service in WordPress Jann Horn
Re: Denial of Service in WordPress Michal Zalewski

Friday, 28 June

[ MDVSA-2013:186 ] puppet security
[SECURITY] [DSA 2717-1] xml-security-c security update Salvatore Bonaccorso
Abusing Windows 7 Recovery Process Anastasios Monachos
Re: Denial of Service in WordPress MustLive
DAVOSET v.1.0.8 MustLive
Re: Denial of Service in WordPress Jann Horn

Saturday, 29 June

Re: Abusing Windows 7 Recovery Process Alex
Re: Denial of Service in WordPress Julius Kivimäki
Windows XP cmd.exe crash Pedro Laguna
tor vulnerabilities? Neel Rowhoiser
Re: Abusing Windows 7 Recovery Process sec
Re: Abusing Windows 7 Recovery Process Grandma Eubanks
Re: Denial of Service in WordPress MustLive
Re: Denial of Service in WordPress Michal Zalewski
WordPress Denial of Service exploit MustLive
Re: tor vulnerabilities? Valdis . Kletnieks

Sunday, 30 June

GreHack 2013 - CFP EXTENDED TO JULY, 16 - Conf: Nov. 15, Grenoble, France F. Duchene
Multiple vulnerabilities found in NSA website macfags
Re: Denial of Service in WordPress Cool Hand Luke
Re: Abusing Windows 7 Recovery Process Cool Hand Luke
Content Spoofing vulnerabilities in TinyMCE and WordPress MustLive
Re: Multiple vulnerabilities found in NSA website Kingcope
HQ SQLi's found by hack_addicted.pt hack_addicted .pt