oss-sec: by author

272 messages starting Aug 04 09 and ending Sep 20 09
Date index | Thread index | Author index


Alex Legler

CVE request: Wordpress Alex Legler (Aug 04)
CVE request: phpgroupware Alex Legler (Aug 12)
Re: viewvc: CVE request: XSS and illegal characters while printing name-value pairs Alex Legler (Sep 07)
CVE request(?): Thin: Client IP spoofing Alex Legler (Sep 12)
CVE request: XEmacs Multiple Integer Overflows Alex Legler (Jul 16)
CVE request: VLC -- Stack-based buffer overflows in three demuxers Alex Legler (Sep 17)
Re: CVE Request -- RubyGems Alex Legler (Jul 21)
Re: CVE Request -- Horde 3.3.5 Alex Legler (Sep 15)
Re: CVE Request -- HTMLDOC Alex Legler (Jul 26)
Re: CVE id request: compface Alex Legler (Jul 03)
CVE request: Wireshark <1.2.1 Multiple DoS Alex Legler (Jul 21)
Re: CVE Request -- HTMLDOC Alex Legler (Sep 01)
CVE request: Common Data Format (CDF) library multiple heap-based buffer overflows Alex Legler (Aug 14)

Andrea Barisani

[oCERT-2009-011] Android improper camera and audio permission verification Andrea Barisani (Jul 16)
[oCERT-2009-010] mimeTeX and mathTeX buffer overflows and command injection Andrea Barisani (Jul 13)
[oCERT-2009-007] FCKeditor input sanitization errors Andrea Barisani (Jul 03)
Re: [oCERT-2009-009] CamlImages integer overflows Andrea Barisani (Jul 02)
[oCERT-2009-009] CamlImages integer overflows Andrea Barisani (Jul 02)
[oCERT-2009-008] Dillo integer overflow Andrea Barisani (Jul 03)
Re: [oCERT-2009-009] CamlImages integer overflows Andrea Barisani (Jul 04)
[oCERT-2009-012] libtiff tools integer overflows Andrea Barisani (Jul 13)

Brad Spengler

Re: [Dailydave] [oss-security] Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Brad Spengler (Jul 20)

CERT-FI Vulnerability Coordination

Re: Re: expat bug 1990430 CERT-FI Vulnerability Coordination (Aug 27)
Re: expat bug 1990430 CERT-FI Vulnerability Coordination (Aug 26)

Chad Dougherty

Re: CVE for recent cyrus-imap issue Chad Dougherty (Sep 08)

dann frazier

kernel issues pending CVE assignment dann frazier (Aug 14)

Eugene Teo

Re: CVE request: kernel: cfg80211: missing NULL pointer checks Eugene Teo (Aug 16)
CVE-2009-1883 kernel: missing capability check in z90crypt Eugene Teo (Sep 14)
Re: CVE-2009-2903 kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams Eugene Teo (Sep 16)
Re: CVE request - kernel: information leak in sigaltstack Eugene Teo (Aug 04)
Re: CVE request: kernel: flat: fix uninitialized ptr with shared libs Eugene Teo (Aug 18)
CVE-2009-2903 kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams Eugene Teo (Sep 13)
Re: CVE-2009-1883 kernel: missing capability check in z90crypt Eugene Teo (Sep 14)
CVE request: kernel: cfg80211: fix looping soft lockup in find_ie() Eugene Teo (Sep 15)
Re: CVE request: kernel: AF_LLC getsockname 5-Byte Stack Disclosure Eugene Teo (Aug 26)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Eugene Teo (Sep 16)
CVE request: kernel: AF_LLC getsockname 5-Byte Stack Disclosure Eugene Teo (Aug 25)
Re: CVE-2009-2698 kernel: udp socket NULL ptr dereference Eugene Teo (Aug 30)
Re: CVE request: kernel: issue with O_EXCL creates on NFSv4 Eugene Teo (Sep 22)
CVE request: kernel: cfg80211: missing NULL pointer checks Eugene Teo (Aug 16)
Re: CVE-2009-2903 kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams Eugene Teo (Sep 17)
CVE request: kernel: issue with O_EXCL creates on NFSv4 Eugene Teo (Sep 20)
CVE request: kernel: flat: fix uninitialized ptr with shared libs Eugene Teo (Aug 12)
CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock Eugene Teo (Jul 02)
Re: CVE request: kernel: KVM: x86: Disallow hypercalls for guest callers in rings > 0 Eugene Teo (Sep 20)
CVE-2009-1895 kernel: personality: fix PER_CLEAR_ON_SETID Eugene Teo (Jul 15)
CVE request: kernel: perf_counter: Fix buffer overflow in perf_copy_attr() Eugene Teo (Sep 15)
CVE-2009-2691 kernel: /proc/$pid/maps visible during initial setuid ELF loading Eugene Teo (Aug 10)
CVE-2009-2698 kernel: udp socket NULL ptr dereference Eugene Teo (Aug 24)
CVE request - kernel: information leak in sigaltstack Eugene Teo (Aug 03)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Eugene Teo (Sep 07)
Re: CVE request: kernel: AF_LLC getsockname 5-Byte Stack Disclosure Eugene Teo (Aug 26)
Re: CVE request: kernel: KVM: x86: Disallow hypercalls for guest callers in rings > 0 Eugene Teo (Sep 22)
Re: md raid null ptr dereference (when sysfs is writable) Eugene Teo (Jul 25)
CVE request: kernel: parisc: isa-eeprom missing lower bound check Eugene Teo (Aug 09)
CVE request: kernel: tty: make sure to flush any pending work when halting the ldisc Eugene Teo (Aug 30)
CVE request - kernel: execve: must clear current->clear_child_tid Eugene Teo (Aug 04)
CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc Eugene Teo (Aug 13)
CVE request: kernel: clock_nanosleep() with CLOCK_MONOTONIC_RAW NULL pointer dereference Eugene Teo (Aug 05)
Follow oss_security on Twitter Eugene Teo (Aug 23)
CVE request: kernel: KVM: x86: Disallow hypercalls for guest callers in rings > 0 Eugene Teo (Sep 17)

Florian Weimer

Using NSS (Netscape Security Services) in setuid programs Florian Weimer (Aug 22)
Three Shibboleth issues Florian Weimer (Sep 23)
Fixing the XML signature HMAC truncation authentication bypass Florian Weimer (Jul 14)

Gerald Combs

Re: Wireshark - wnpa-sec-2009-05.html && wnpa-sec-2009-06.html -- CVE confirmation and CVE Request Gerald Combs (Sep 17)

Greg KH

Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Greg KH (Jul 20)

Hanno Böck

CVE request: serendipity freetag plugin Hanno Böck (Sep 12)

Henri Salo

Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Henri Salo (Aug 05)

ithilgore

Re: Apache 2.2 HTTP Basic Auth bypass ithilgore (Jul 28)

Jamie Strandboge

Re: GnuTLS CVE-2009-2730 Patches Jamie Strandboge (Aug 17)
Re: GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2) Jamie Strandboge (Aug 17)
Insecure pid directory permissions for postfix on Debian / Ubuntu Jamie Strandboge (Sep 18)
GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2) Jamie Strandboge (Aug 14)

Jan Lieskovsky

CVE Request -- FreeRADIUS 1.1.8 Jan Lieskovsky (Sep 09)
CVE Request -- RubyGems Jan Lieskovsky (Jul 21)
CVE Request -- Xen -- PyGrub Jan Lieskovsky (Sep 25)
Wireshark - wnpa-sec-2009-05.html && wnpa-sec-2009-06.html -- CVE confirmation and CVE Request Jan Lieskovsky (Sep 17)
CVE Request - Pidgin 2.6.2 Jan Lieskovsky (Sep 08)
CVE Request -- PHP 5 - 5.2.11 Jan Lieskovsky (Sep 18)
CVE duplicate notification (CVE-2009-2580 to be duplicate of CVE-2009-1862) Jan Lieskovsky (Jul 24)
Re: CVE request: Wireshark <1.2.1 Multiple DoS Jan Lieskovsky (Jul 27)
Re: CVE Request -- FreeRADIUS 1.1.8 Jan Lieskovsky (Sep 09)
CVE Request -- PostgreSQL Jan Lieskovsky (Sep 09)
CVE Request -- Ocsinventory-Agent Jan Lieskovsky (Jul 24)
CVE Request -- OCS Inventory NG Jan Lieskovsky (Aug 17)
CVE Request -- Drupal 6 Date / Calendar XSS vulnerability Jan Lieskovsky (Jul 24)
CVE Request - MySQL <= 5.0.45 Jan Lieskovsky (Jul 13)
CVE Request -- Horde 3.3.5 Jan Lieskovsky (Sep 15)
Re: CVE request: Wireshark <1.2.1 Multiple DoS Jan Lieskovsky (Jul 22)
CVE Request -- WordPress Jan Lieskovsky (Jul 21)
Re: CVE Request (Sort of urgent) -- Xen -- PyGrub Jan Lieskovsky (Sep 30)
CVE Request -- HTMLDOC Jan Lieskovsky (Jul 18)

Joe Orton

neon 0.28.6 - CVE-2009-2473, CVE-2009-2474 Joe Orton (Aug 18)
Re: CVE Request -- PHP 5 - 5.2.11 Joe Orton (Sep 18)
Re: Re: expat bug 1990430 Joe Orton (Aug 27)
Re: neon 0.28.6 - CVE-2009-2473, CVE-2009-2474 Joe Orton (Aug 20)

Jon Oberheide

Re: kernel issues pending CVE assignment Jon Oberheide (Aug 15)

Josh Bressers

CVE Request (django) Josh Bressers (Jul 29)
CVE Request pidgin Josh Bressers (Aug 19)

Julien Tinnes

Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Julien Tinnes (Jul 20)

Kees Cook

CVE Request - glib symlink copying permission exposure Kees Cook (Sep 08)
CVE request - Debian/Ubuntu PAM auth module selection Kees Cook (Sep 08)

Ludwig Nussel

CVE id request: strongswan Ludwig Nussel (Jul 27)
CVE request: perl-IO-Socket-SSL certificate hostname compare bug Ludwig Nussel (Aug 28)

Marcus Meissner

md raid null ptr dereference (when sysfs is writable) Marcus Meissner (Jul 24)
Re: OpenOffice.org CVE-2009-2139 Marcus Meissner (Sep 22)
Coverity / kernel issues Marcus Meissner (Jul 22)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Marcus Meissner (Jul 20)
Re: CVE request: kernel: perf_counter: Fix buffer overflow in perf_copy_attr() Marcus Meissner (Sep 17)
Re: CVE-2009-1895 kernel: personality: fix PER_CLEAR_ON_SETID Marcus Meissner (Jul 16)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Marcus Meissner (Jul 20)
Re: CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc Marcus Meissner (Aug 14)
new root exploit from Brad Marcus Meissner (Aug 13)
Re: http://www.securityfocus.com/bid/33672/info kernel issue Marcus Meissner (Aug 03)
CVE-2008-4609 / Outpost24 TCP issues Marcus Meissner (Sep 16)

Mark J Cox

SELinux and mmap_min_addr behaviour (CVE-2009-2695) Mark J Cox (Aug 17)

Matthias Andree

Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Matthias Andree (Aug 05)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Matthias Andree (Aug 05)
Re: "umbrella" CVE names (was: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass) Matthias Andree (Aug 21)
CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Matthias Andree (Aug 05)
Re: CVE-2007-1558 update (was: mailfilter 0.8.2 fixes CVE-2007-1558 (APOP)) Matthias Andree (Aug 18)

Michael K. Johnson

Re: CVE request - kernel: execve: must clear current->clear_child_tid Michael K. Johnson (Aug 05)

Michael S. Gilbert

CVE request: mantis Michael S. Gilbert (Aug 09)

Nico Golde

CVE id request: groff (pdfroff) Nico Golde (Aug 09)
Re: CVE id request: squirrelmail CSRF Nico Golde (Aug 31)
CVE id request: mediawiki Nico Golde (Jul 26)
CVE id request: squirrelmail CSRF Nico Golde (Aug 31)
CVE id request: drupal Nico Golde (Jul 02)
Re: incorrect upstream fix for CVE-2009-0840 (mapserver) Nico Golde (Jul 01)
Re: CVE Request -- HTMLDOC Nico Golde (Jul 25)
CVE id request: spip Nico Golde (Aug 09)
Re: CVE Request -- Ocsinventory-Agent Nico Golde (Jul 25)
CVE id request: silc-toolkit Nico Golde (Aug 31)
CVE id request: changetrack Nico Golde (Sep 16)
Re: squid DoS in external auth header parser Nico Golde (Aug 04)
Re: CVE Request -- PHP 5 - 5.2.11 Nico Golde (Sep 19)
Re: squid DoS in external auth header parser Nico Golde (Aug 04)
Re: CVE Request -- PHP 5 - 5.2.11 Nico Golde (Sep 18)
Re: CVE id request: groff (pdfroff) Nico Golde (Aug 14)
CVE id request: mplayer and vlc Nico Golde (Jul 27)
Re: CVE for recent cyrus-imap issue Nico Golde (Sep 08)
Re: debian bug report on bind9 DoS Nico Golde (Jul 29)

Reed Loden

CVE Request -- znc Reed Loden (Jul 21)
Re: CVE: Request Firefox 3.5 Reed Loden (Jul 19)

Robert Buchholz

Re: debian bug report on bind9 DoS Robert Buchholz (Jul 28)
Re: Fixing the XML signature HMAC truncation authentication bypass Robert Buchholz (Jul 14)
Re: [oCERT-2009-009] CamlImages integer overflows Robert Buchholz (Jul 02)
camlimages: Integer overflows in GIF and JPEG readers Robert Buchholz (Jul 25)
mailfilter 0.8.2 fixes CVE-2007-1558 (APOP) Robert Buchholz (Aug 15)
Re: Fixing the XML signature HMAC truncation authentication bypass Robert Buchholz (Jul 14)
expat bug 1990430 Robert Buchholz (Aug 21)
Re: Fixing the XML signature HMAC truncation authentication bypass Robert Buchholz (Jul 14)
Re: [oCERT-2009-009] CamlImages integer overflows Robert Buchholz (Jul 04)

Sebastian Krahmer

CVE for recent cyrus-imap issue Sebastian Krahmer (Sep 08)

security curmudgeon

Re: squid DoS in external auth header parser security curmudgeon (Aug 03)

Simon Josefsson

Re: GnuTLS CVE-2009-2730 Patches Simon Josefsson (Aug 15)
Re: GnuTLS CVE-2009-2730 Patches Simon Josefsson (Aug 18)

Solar Designer

Apache 2.2 HTTP Basic Auth bypass Solar Designer (Jul 28)
Re: debian bug report on bind9 DoS Solar Designer (Jul 29)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Solar Designer (Jul 20)
Re: CVE request - kernel: information leak in sigaltstack Solar Designer (Aug 25)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Solar Designer (Jul 20)
Re: CVE Request (syslog-ng) Solar Designer (Jul 14)
Re: debian bug report on bind9 DoS Solar Designer (Jul 29)
Re: CVE-2009-1883 kernel: missing capability check in z90crypt Solar Designer (Sep 14)
Re: CVE id request: groff (pdfroff) Solar Designer (Aug 14)
Re: Follow oss_security on Twitter Solar Designer (Aug 31)
Re: Apache 2.2 HTTP Basic Auth bypass Solar Designer (Jul 28)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Solar Designer (Jul 20)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Solar Designer (Jul 20)

Stefan Behte

CVE: Request Firefox 3.5 Stefan Behte (Jul 14)

Steffen Joeris

Re: CVE id request: xcftools Steffen Joeris (Jul 06)
CVE id request: pidgin Steffen Joeris (Aug 24)
CVE id request: xcftools Steffen Joeris (Jul 06)

Steffen Ullrich

Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Steffen Ullrich (Aug 29)
Re: Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Steffen Ullrich (Aug 31)
Re: Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Steffen Ullrich (Aug 31)

Steve Kemp

CVE request: oping allows the disclosure of arbitrary file contents Steve Kemp (Sep 28)

Steven M. Christey

Re: CVE id request: silc-toolkit Steven M. Christey (Sep 11)
Re: CVE Request -- Horde 3.3.5 Steven M. Christey (Sep 16)
Re: CVE request: kernel: clock_nanosleep() with CLOCK_MONOTONIC_RAW NULL pointer dereference Steven M. Christey (Aug 18)
Re: CVE Request -- HTMLDOC Steven M. Christey (Sep 02)
Re: OpenOffice.org CVE-2009-2139 Steven M. Christey (Sep 21)
Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Steven M. Christey (Aug 31)
Re: CVE request: Wordpress Steven M. Christey (Aug 18)
Re: squid 3.x vulnerabilities Steven M. Christey (Jul 28)
Re: CVE Request -- FreeRADIUS 1.1.8 Steven M. Christey (Sep 09)
Re: CVE id request: changetrack Steven M. Christey (Sep 16)
Re: CVE request: kernel: KVM: x86: Disallow hypercalls for guest callers in rings > 0 Steven M. Christey (Sep 22)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Steven M. Christey (Aug 05)
Re: nagios: remote code execution Steven M. Christey (Jul 07)
Re: CVE Request - glib symlink copying permission exposure Steven M. Christey (Sep 22)
Re: md raid null ptr dereference (when sysfs is writable) Steven M. Christey (Aug 18)
Re: CVE request: kernel: perf_counter: Fix buffer overflow in perf_copy_attr() Steven M. Christey (Sep 16)
Re: CVE request - Debian/Ubuntu PAM auth module selection Steven M. Christey (Sep 16)
watch for LDAP anonymous binds and empty passwords Steven M. Christey (Sep 16)
Re: CVE request: kernel: issue with O_EXCL creates on NFSv4 Steven M. Christey (Sep 21)
Re: Re: CVE id request: php5 Steven M. Christey (Aug 27)
Re: CVE request: Common Data Format (CDF) library multiple heap-based buffer overflows Steven M. Christey (Aug 18)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Steven M. Christey (Sep 16)
Re: CVE request - kernel: execve: must clear current->clear_child_tid Steven M. Christey (Aug 18)
Re: CVE request: serendipity freetag plugin Steven M. Christey (Sep 24)
Re: CVE Request -- PostgreSQL Steven M. Christey (Sep 16)
Re: CVE Request -- OCS Inventory NG Steven M. Christey (Sep 01)
Re: Re: expat bug 1990430 Steven M. Christey (Aug 26)
Re: CVE Request -- WordPress Steven M. Christey (Aug 18)
Re: CVE request: XEmacs Multiple Integer Overflows Steven M. Christey (Aug 05)
Re: squid DoS in external auth header parser Steven M. Christey (Aug 18)
Re: CVE Request -- PHP 5 - 5.2.11 Steven M. Christey (Sep 22)
Re: CVE Request -- PHP 5 - 5.2.11 Steven M. Christey (Sep 21)
Re: CVE id request: nagios Steven M. Christey (Jul 01)
Re: incorrect upstream fix for CVE-2009-0840 (mapserver) Steven M. Christey (Jul 01)
Re: CVE request - kernel: information leak in sigaltstack Steven M. Christey (Aug 18)
Re: CVE request: Wireshark <1.2.1 Multiple DoS Steven M. Christey (Aug 03)
Re: CVE request: kernel: cfg80211: missing NULL pointer checks Steven M. Christey (Aug 18)
Re: CVE id request: spip Steven M. Christey (Sep 01)
Re: CVE request(?): Thin: Client IP spoofing Steven M. Christey (Sep 22)
Re: CVE Request: kernel: kvm: failure to validate cr3 after KVM_SET_SREGS Steven M. Christey (Jul 01)
Re: CVE id request: pidgin Steven M. Christey (Aug 31)
Re: CVE request: kernel: parisc: isa-eeprom missing lower bound check Steven M. Christey (Aug 18)
Re: CVE request: kernel: flat: fix uninitialized ptr with shared libs Steven M. Christey (Aug 18)
Re: CVE Request -- libtiff [was: Re: [oss-security] libtiff buffer underflow in LZWDecodeCompat] Steven M. Christey (Jul 01)
Re: CVE id request: compface Steven M. Christey (Jul 01)
Re: CVE for recent cyrus-imap issue Steven M. Christey (Sep 08)
Re: Re: CVE-2007-1558 update (was: mailfilter 0.8.2 fixes CVE-2007-1558 (APOP)) Steven M. Christey (Sep 01)
Re: CVE request: kernel: parisc: isa-eeprom missing lower bound check Steven M. Christey (Aug 18)
Re: CVE Request pidgin Steven M. Christey (Aug 31)
Re: CVE request: kernel: flat: fix uninitialized ptr with shared libs Steven M. Christey (Aug 18)
Re: CVE request: kernel: NULL pointer dereference in sg_build_indirect() Steven M. Christey (Sep 22)
Re: CVE for recent cyrus-imap issue Steven M. Christey (Sep 16)

Thijs Kinkhorst

Re: debian bug report on bind9 DoS Thijs Kinkhorst (Jul 28)

Thomas Biege

Re: OpenOffice.org CVE-2009-2139 Thomas Biege (Sep 10)
Re: CVE for recent cyrus-imap issue Thomas Biege (Sep 08)
CVE request: ruby on rails authenticate_with_http_digest bypass Thomas Biege (Jul 02)
viewvc: CVE request: XSS and illegal characters while printing name-value pairs Thomas Biege (Sep 07)
Re: CVE request: XEmacs Multiple Integer Overflows Thomas Biege (Aug 05)

Todd Sabin

Re: [Dailydave] [oss-security] Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable Todd Sabin (Jul 22)

Tomas Hoger

PHP security fix in 5.2.10 Tomas Hoger (Jul 22)
Re: CVE id request: silc-toolkit Tomas Hoger (Sep 11)
Re: OpenOffice.org CVE-2009-2139 Tomas Hoger (Sep 10)
Re: CVE id request: squirrelmail CSRF Tomas Hoger (Aug 31)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Tomas Hoger (Aug 05)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Tomas Hoger (Aug 05)
Re: CVE for recent cyrus-imap issue Tomas Hoger (Sep 14)
Re: Re: CVE id request: php5 Tomas Hoger (Aug 27)
Re: CVE Request -- PostgreSQL Tomas Hoger (Sep 09)
Re: OpenOffice.org CVE-2009-2139 Tomas Hoger (Sep 11)
nilfs-utils privilege escalation Tomas Hoger (Jul 24)
Re: CVE id request: silc-toolkit Tomas Hoger (Sep 11)
Re: Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Tomas Hoger (Aug 31)
Re: Re: CVE request: perl-IO-Socket-SSL certificate hostname compare bug Tomas Hoger (Aug 31)
Re: More CVE-2009-2408 like issues Tomas Hoger (Sep 23)
OpenOffice.org CVE-2009-2139 Tomas Hoger (Sep 09)
Re: CVE for recent cyrus-imap issue Tomas Hoger (Sep 17)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass Tomas Hoger (Aug 05)
Re: CVE id request: groff (pdfroff) Tomas Hoger (Aug 10)

Vincent Danen

debian bug report on bind9 DoS Vincent Danen (Jul 28)
Re: squid DoS in external auth header parser Vincent Danen (Aug 04)
squid 3.x vulnerabilities Vincent Danen (Jul 27)
squid DoS in external auth header parser Vincent Danen (Jul 20)
Re: debian bug report on bind9 DoS Vincent Danen (Jul 28)
Re: CVE request: XEmacs Multiple Integer Overflows Vincent Danen (Aug 05)

Willy Tarreau

Re: CVE request: kernel: tc: uninitialised kernel memory leak Willy Tarreau (Sep 16)
Re: CVE-2009-2903 kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams Willy Tarreau (Sep 13)
Re: [Security] CVE-2008-4609 / Outpost24 TCP issues Willy Tarreau (Sep 16)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Willy Tarreau (Sep 07)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Willy Tarreau (Sep 07)

yersinia

Re: Re: [Dailydave] [oss-security] Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable yersinia (Jul 22)
Re: Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable yersinia (Jul 20)
Re: watch for LDAP anonymous binds and empty passwords yersinia (Sep 17)
Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable yersinia (Jul 17)
Re: CVE Request -- PHP 5 - 5.2.11 yersinia (Sep 20)