oss-sec: by author

304 messages starting Nov 23 09 and ending Oct 17 09
Date index | Thread index | Author index


Alex Legler

CVE request: Argument injections in multiple PEAR packages Alex Legler (Nov 23)
CVE request: Wordpress 2.8.6 Alex Legler (Nov 15)
CVE request: Ruby on Rails: CSRF circumvention (from 2008) Alex Legler (Nov 28)
Re: CVE Request - Asterisk (AST-2009-008.html) Alex Legler (Nov 07)

Andrea Barisani

[oCERT-2009-015] KDE multiple issues Andrea Barisani (Oct 27)
[oCERT-2009-017] PHP multiple issues Andrea Barisani (Nov 30)
[oCERT-2009-014] Android denial-of-service issues Andrea Barisani (Oct 05)
[oCERT-2009-019] Ganeti path sanitization errors Andrea Barisani (Dec 17)

Anthon Pang

CVE Request - Open Flash Chart v2 Anthon Pang (Dec 14)
Re: Piwik <= 0.4.5 Cookie Unserialize() Vulnerability Anthon Pang (Dec 14)

ArkanoiD

Re: CVE-2009-3555 for TLS renegotiation MITM attacks ArkanoiD (Nov 08)

Brandon Philips

Re: CVE request: acl 2.2.47 always follows symlinks Brandon Philips (Dec 23)

CERT-FI Vulnerability Co-ordination

Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] CERT-FI Vulnerability Co-ordination (Oct 26)

Craig

CVE request: awstats Craig (Nov 21)
CVEs for nginx Craig (Nov 19)

Eren Türkay

Re: CVE request: php5: multiple issues Eren Türkay (Dec 17)
Piwik <= 0.4.5 Cookie Unserialize() Vulnerability Eren Türkay (Dec 09)
Re: CVE request: php 5.3.1 update Eren Türkay (Nov 20)

Eugene Teo

CVE request: kernel: get_instantiation_keyring() should inc the keyring refcount in all cases Eugene Teo (Oct 21)
Re: CVE request kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500 Eugene Teo (Oct 14)
CVE-2009-3547 kernel: fs: pipe.c null pointer dereference Eugene Teo (Nov 03)
Re: CVE request kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7 Eugene Teo (Oct 14)
CVE request: kernel: AF_UNIX: Fix deadlock on connecting to shutdown socket Eugene Teo (Oct 19)
CVE-2009-4138 kernel: firewire: ohci: handle receive packets with a data length of zero Eugene Teo (Dec 14)
Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389 Eugene Teo (Dec 29)
CVE request kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7 Eugene Teo (Oct 13)
CVE request: kernel: r128 IOCTL NULL pointer dereferences when CCE state is uninitialised Eugene Teo (Oct 18)
CVE request: kvm: update_cr8_intercept() NULL pointer dereference when running without an apic Eugene Teo (Oct 22)
CVE request: kernel: KVM: x86 emulator: limit instructions to 15 bytes Eugene Teo (Nov 25)
CVE request: kernel: NULL pointer dereference in nfs4_proc_lock() Eugene Teo (Nov 04)
CVE request - kernel: NOMMU: Dont pass NULL pointers to fput() in do_mmap_pgoff() Eugene Teo (Nov 08)
CVE request: kernel: mac80211: fix two remote exploits Eugene Teo (Nov 30)
Re: CVE request: kernel: mac80211: fix two remote exploits Eugene Teo (Dec 02)
CVE request: kernel: fuse: prevent fuse_put_request on invalid pointer Eugene Teo (Nov 19)
CVE request kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500 Eugene Teo (Oct 14)
CVE request: kernel: connector security bypass Eugene Teo (Nov 02)
CVE requests - kernel security regressions for CVE-2009-1385/and -1389 Eugene Teo (Dec 27)
Re: CVE request: kernel: mac80211: fix two remote exploits Eugene Teo (Dec 02)
Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389 Eugene Teo (Dec 28)
Re: CVE request kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500 Eugene Teo (Oct 15)
CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid() Eugene Teo (Oct 23)
CVE request: kvm: check cpl before emulating debug register access Eugene Teo (Oct 28)
Re: CVE request: kernel: tc: uninitialised kernel memory leak Eugene Teo (Oct 13)
CVE request - kernel: fuse_ioctl_copy_user() dos Eugene Teo (Dec 22)
CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client Eugene Teo (Oct 21)
CVE-2009-4020 kernel: hfs buffer overflow Eugene Teo (Dec 03)
CVE request: kernel: bad permissions on megaraid_sas sysfs files Eugene Teo (Nov 12)

Eygene Ryabinkin

Re: CVE-2009-3555 for TLS renegotiation MITM attacks Eygene Ryabinkin (Nov 06)

Florian Weimer

Re: CVE-2009-3555 for TLS renegotiation MITM attacks Florian Weimer (Nov 05)
Re: MFSA 2009-63 Florian Weimer (Oct 29)
Re: X server umask issue Florian Weimer (Nov 09)
CVE request: BIND 9 bug involving DNSSEC and the additional section Florian Weimer (Nov 24)
CVE request: Unbound Florian Weimer (Oct 09)

Giuseppe Iuculano

CVE request: phpLDAPadmin Giuseppe Iuculano (Dec 21)

Hanno Böck

CVE request: acl 2.2.47 always follows symlinks Hanno Böck (Dec 23)
CVE request: Serendipity < 1.5 upload of files with *.php.* possible Hanno Böck (Dec 21)
Re: CVE Request -- phpMyAdmin Hanno Böck (Oct 14)
CVE request: simplemachinesforum Hanno Böck (Dec 21)
CVE request: Wordpress Trackback DoS Hanno Böck (Oct 21)

Igor Sysoev

Re: CVEs for nginx Igor Sysoev (Nov 23)
Re: CVEs for nginx Igor Sysoev (Nov 23)

Jamie Strandboge

Some small KDE issues Jamie Strandboge (Dec 10)
Re: Re: Some small KDE issues Jamie Strandboge (Dec 11)
Linux/QEMU issue Jamie Strandboge (Dec 08)

Jan Lieskovsky

CVE Request -- Sahana Jan Lieskovsky (Oct 22)
CVE Request -- xfig Jan Lieskovsky (Dec 03)
CVE Request -- Snort - 2.8.5.1 Jan Lieskovsky (Oct 25)
CVE Request - Asterisk (AST-2009-008.html) Jan Lieskovsky (Nov 05)
Re: CVEs for nginx Jan Lieskovsky (Nov 23)
Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] Jan Lieskovsky (Oct 23)
CVE-2009-3626 assigment notification - Perl - perl-5.10.1 Jan Lieskovsky (Oct 23)
Re: CVE Request -- phpMyAdmin Jan Lieskovsky (Oct 14)
Regarding expat bug 1990430 Jan Lieskovsky (Oct 22)
Re: mysql-5.1.41 Jan Lieskovsky (Nov 24)
CVE Request - aria2 - 1.6.2 Jan Lieskovsky (Oct 16)
CVE Request -- coreutils -- unsafe temporary directory location use Jan Lieskovsky (Dec 08)
Re: CVEs for nginx Jan Lieskovsky (Nov 23)
CVE Request - MySQL - 5.0.88 Jan Lieskovsky (Nov 21)
CVE Request -- phpMyAdmin Jan Lieskovsky (Oct 14)
CVE Request -- alienarena - 7.31 Jan Lieskovsky (Oct 23)
Re: mysql-5.1.41 Jan Lieskovsky (Nov 24)
Re: CVE request: php 5.3.1 - proc_open() bypass PHP Bug #49026 [was: Re: [oss-security] CVE request: php 5.3.1 update] Jan Lieskovsky (Nov 23)
CVE assignment notification -- CVE-2009-2911 - Three SystemTap-1.0 DoS issues Jan Lieskovsky (Oct 21)
CVE Request - backintime Jan Lieskovsky (Oct 14)
Re: CVE Request -- Sahana Jan Lieskovsky (Oct 22)
CVE-2009-3627 assignment notification - HTML-Parser-3.63 Jan Lieskovsky (Oct 23)
CVE Request - Dovecot - 1.2.8 Jan Lieskovsky (Nov 21)
CVE Request - Cacti - 0.8.7e Jan Lieskovsky (Nov 25)
CVE Request -- moodle 1.9.7 and 1.8.11 Jan Lieskovsky (Dec 06)
Re: CVE request: php 5.3.1 - "max_file_uploads" [was: Re: [oss-security] CVE request: php 5.3.1 update] Jan Lieskovsky (Nov 23)
Re: Duplicate CVE assignment notification [was: CVE id request: django] Jan Lieskovsky (Oct 13)

Joe Orton

Re: CVE request: php 5.3.1 update Joe Orton (Nov 20)
Re: CVE request: php5: multiple issues Joe Orton (Dec 17)

Josh Bressers

Re: CVE Request -- coreutils -- unsafe temporary directory location use Josh Bressers (Dec 08)
Re: CVEs for nginx Josh Bressers (Nov 23)
Re: Piwik <= 0.4.5 Cookie Unserialize() Vulnerability Josh Bressers (Dec 10)
Re: CVE request: kernel: NULL pointer dereference in nfs4_proc_lock() Josh Bressers (Nov 05)
Re: CVE request: oping allows the disclosure of arbitrary file contents Josh Bressers (Nov 16)
Re: CVE Request (kernel) Josh Bressers (Oct 01)
Re: CVE request: oping allows the disclosure of arbitrary file contents Josh Bressers (Oct 15)
More kernel CVE info (CVE-2009-2909) Josh Bressers (Oct 07)
CVE Request (kernel) Josh Bressers (Oct 01)
Re: CVE request: kernel: AF_UNIX: Fix deadlock on connecting to shutdown socket Josh Bressers (Oct 19)
Re: CVE request: v1.2.8 released to fix the 0777 base_dir creation issue Josh Bressers (Nov 23)
Re: CVE request: Wordpress Trackback DoS Josh Bressers (Oct 21)
Re: CVE request: kernel: r128 IOCTL NULL pointer dereferences when CCE state is uninitialised Josh Bressers (Oct 19)
Re: libjson-ruby: catastrophic backtracking Josh Bressers (Nov 11)
Re: a new bind issue Josh Bressers (Nov 24)
Re: CVE request: kvm: update_cr8_intercept() NULL pointer dereference when running without an apic Josh Bressers (Oct 24)
Re: CVE request: Argument injections in multiple PEAR packages Josh Bressers (Nov 24)
Re: CVE request: kernel: bad permissions on megaraid_sas sysfs files Josh Bressers (Nov 13)
Re: CVE Request (kernel) Josh Bressers (Oct 09)
Re: CVE request - kernel: NOMMU: Dont pass NULL pointers to fput() in do_mmap_pgoff() Josh Bressers (Nov 13)
Re: CVE Request - backintime Josh Bressers (Oct 14)
Re: CVE request: kernel: fuse: prevent fuse_put_request on invalid pointer Josh Bressers (Nov 24)
Re: CVE id request: django Josh Bressers (Oct 12)
Re: CVE Request - aria2 - 1.6.2 Josh Bressers (Oct 16)
Re: CVE request: kernel: mac80211: fix two remote exploits Josh Bressers (Dec 02)
Re: CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid() Josh Bressers (Oct 23)
Re: viewvc: CVE request: XSS and illegal characters while printing name-value pairs Josh Bressers (Oct 16)
Re: CVE request: oping allows the disclosure of arbitrary file contents Josh Bressers (Nov 09)
Re: CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client Josh Bressers (Oct 22)
Re: CVE request: virtualbox-ose guest can trigger denial of service at host, mem consumption Josh Bressers (Nov 18)
Re: CVE request: Unbound Josh Bressers (Oct 09)
Re: CVE request: php 5.3.1 - "max_file_uploads" [was: Re: [oss-security] CVE request: php 5.3.1 update] Josh Bressers (Nov 23)
Re: a new bind issue Josh Bressers (Nov 24)
CVE assignment (libexif) Josh Bressers (Nov 19)
Re: CVE request: libpoppler4: buffer overflow in the Abiword backend Josh Bressers (Nov 11)
Re: CVE Request - Open Flash Chart v2 Josh Bressers (Dec 14)
Re: CVE request kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7 Josh Bressers (Oct 14)
Re: CVE request: ruby on rails XSS Weakness in strip_tags Josh Bressers (Dec 08)
Re: mysql-5.1.41 Josh Bressers (Nov 23)
X server umask issue Josh Bressers (Nov 09)
Re: CVE request: Ruby on Rails: CSRF circumvention (from 2008) Josh Bressers (Dec 02)
Re: CVE Request - Dovecot - 1.2.8 Josh Bressers (Nov 23)
Re: CVE Request - Cacti - 0.8.7e Josh Bressers (Nov 25)
Re: CVE request: oping allows the disclosure of arbitrary file contents Josh Bressers (Oct 15)
Re: a new bind issue Josh Bressers (Nov 24)
pidgin security flaw Josh Bressers (Oct 16)
Re: CVE Request -- alienarena - 7.31 Josh Bressers (Oct 23)
CVE assignment and second opinion needed Josh Bressers (Nov 11)
Re: CVE request: kernel: get_instantiation_keyring() should inc the keyring refcount in all cases Josh Bressers (Oct 22)
Re: presumptive php sec holes Josh Bressers (Oct 12)
Re: CVE Request - MySQL - 5.0.88 Josh Bressers (Nov 23)
Re: CVE id request: typo3 Josh Bressers (Oct 23)
Re: CVE Id request: request-tracker Josh Bressers (Nov 16)
Re: CVE request: Wordpress 2.8.6 Josh Bressers (Nov 16)
Kernel ecryptfs CVE id (CVE-2009-2908) Josh Bressers (Oct 06)
Re: CVE request: awstats Josh Bressers (Nov 23)
Re: CVE Request -- Sahana Josh Bressers (Oct 22)
Re: possible vulnerability in ghostscript >= 8.64 Josh Bressers (Dec 18)
Re: QEMU VNC use-after-free Josh Bressers (Oct 16)
Re: CVE request: kernel: KVM: x86 emulator: limit instructions to 15 bytes Josh Bressers (Nov 25)
CVE Assignment nginx Josh Bressers (Nov 20)
Re: CVE request for oCERT advisory 2009-013 (yTNEF/Evolution TNEF) Josh Bressers (Nov 06)
Re: CVE request: oping allows the disclosure of arbitrary file contents Josh Bressers (Oct 16)
Re: CVE request kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500 Josh Bressers (Oct 15)
Re: proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification Josh Bressers (Oct 23)
Re: CVE request: ruby on rails XSS Weakness in strip_tags Josh Bressers (Dec 07)
Re: CVE request: php 5.3.1 - proc_open() bypass PHP Bug #49026 [was: Re: [oss-security] CVE request: php 5.3.1 update] Josh Bressers (Nov 23)
NetworkManager CVE assignment Josh Bressers (Dec 16)
Re: CVE request: libpoppler4: buffer overflow in the Abiword backend Josh Bressers (Nov 18)
Re: CVE Request - Asterisk (AST-2009-008.html) Josh Bressers (Nov 05)

Julien Cristau

Re: X server umask issue Julien Cristau (Nov 09)

Julien Tinnes

Re: CVE request: oping allows the disclosure of arbitrary file contents Julien Tinnes (Oct 15)
Re: CVE request: oping allows the disclosure of arbitrary file contents Julien Tinnes (Oct 15)

Ludwig Nussel

Re: viewvc: CVE request: XSS and illegal characters while printing name-value pairs Ludwig Nussel (Oct 16)

Marc Deslauriers

Re: Need more information on recent poppler issues Marc Deslauriers (Dec 01)

Marc Schoenefeld

Re: Regarding expat bug 1990430 Marc Schoenefeld (Oct 22)

Marcus Meissner

libtheora CVE-2009-3389? Marcus Meissner (Dec 22)
Re: CVE request: kernel: bad permissions on megaraid_sas sysfs files Marcus Meissner (Nov 13)
Re: Handling cases of CWE-776 Marcus Meissner (Oct 28)

Mark J Cox

CVE-2009-3555 for TLS renegotiation MITM attacks Mark J Cox (Nov 05)
Re: CVE request: kvm: check cpl before emulating debug register access Mark J Cox (Oct 29)
Re: CVE request: kernel: connector security bypass Mark J Cox (Nov 02)
Re: Re: ghostscript CVE for multiple NULL dereferences in JBIG2 decoder Mark J Cox (Oct 28)
Re: CVE request for oCERT advisory 2009-013 (yTNEF/Evolution TNEF) Mark J Cox (Oct 28)
Re: CVE request - asterisk, python-markdown, jetty, kde Mark J Cox (Oct 29)
SANS: Security Thought LeadersRe: [oss-security] CVE Request -- Snort - 2.8.5.1 Mark J Cox (Oct 25)
Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] Mark J Cox (Oct 28)

Marsh Ray

Re: [TLS] [oss-security] CVE-2009-3555 for TLS renegotiation MITM attacks Marsh Ray (Nov 07)
Re: [TLS] [oss-security] CVE-2009-3555 for TLS renegotiation MITM attacks Marsh Ray (Nov 08)

Michael Gilbert

Re: Re: Regarding expat bug 1990430 Michael Gilbert (Oct 22)
Re: Need more information on recent poppler issues Michael Gilbert (Dec 01)
Re: CVE-2009-3239 is a duplicate of CVE-2009-2139 and CVE-2009-2140 Michael Gilbert (Oct 26)
libjson-ruby: catastrophic backtracking Michael Gilbert (Nov 10)

Milen Rangelov

Re: CVE request: php 5.3.1 - proc_open() bypass PHP Bug #49026 [was: Re: [oss-security] CVE request: php 5.3.1 update] Milen Rangelov (Nov 27)

Moritz Muehlenhoff

Re: CVE Request - Asterisk (AST-2009-008.html) Moritz Muehlenhoff (Nov 07)
OpenTTD remote DoS Moritz Muehlenhoff (Dec 24)
Re: Need more information on recent poppler issues Moritz Muehlenhoff (Dec 01)
CVE requests: Zabbix Moritz Muehlenhoff (Dec 26)
CVE request: phpgroupware Moritz Muehlenhoff (Dec 20)

Nico Golde

CVE id request: typo3 Nico Golde (Oct 22)
CVE id request: jetty Nico Golde (Oct 07)

Oden Eriksson

a new bind issue Oden Eriksson (Nov 24)
mysql-5.1.41 Oden Eriksson (Nov 19)
Re: Re: ghostscript CVE for multiple NULL dereferences in JBIG2 decoder Oden Eriksson (Oct 29)
presumptive php sec holes Oden Eriksson (Oct 12)
proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification Oden Eriksson (Oct 23)

oss-security

Re: CVE Request - Cacti - 0.8.7e oss-security (Nov 25)

Peter Gutmann

Re: [TLS] [oss-security] CVE-2009-3555 for TLS renegotiation MITM attacks Peter Gutmann (Nov 08)

Raphael Geissert

CVE request - asterisk, python-markdown, jetty, kde Raphael Geissert (Oct 29)
CVE id request: django Raphael Geissert (Oct 10)
Re: CVE-2009-3239 is a duplicate of CVE-2009-2139 and CVE-2009-2140 Raphael Geissert (Oct 27)
CVE request: Mail PEAR module code injection vulnerability Raphael Geissert (Nov 23)
Re: ghostscript CVE for multiple NULL dereferences in JBIG2 decoder Raphael Geissert (Oct 27)
CVE request: php5: multiple issues Raphael Geissert (Dec 17)
CVE-2009-3239 is a duplicate of CVE-2009-2139 and CVE-2009-2140 Raphael Geissert (Oct 24)
Re: CVE request: php5: multiple issues Raphael Geissert (Dec 18)
CVE request: insecure usage of temporary files in docutils Raphael Geissert (Dec 11)
Re: CVE Request -- PHP 5 - 5.2.11 Raphael Geissert (Oct 15)
CVE request: polipo DoS via overly large "Content-Length" header Raphael Geissert (Dec 12)
Re: Some small KDE issues Raphael Geissert (Dec 10)
Re: CVE request: Argument injections in multiple PEAR packages Raphael Geissert (Dec 11)
Re: Re: Some small KDE issues Raphael Geissert (Dec 11)
Re: CVE request - asterisk, python-markdown, jetty, kde Raphael Geissert (Nov 23)
Re: Re: CVE Request -- PHP 5 - 5.2.11 Raphael Geissert (Oct 27)
Re: Re: Some small KDE issues Raphael Geissert (Dec 17)

Reed Loden

Re: MFSA 2009-63 Reed Loden (Oct 30)
Re: MFSA 2009-63 Reed Loden (Oct 29)
Re: MFSA 2009-63 Reed Loden (Oct 29)

security curmudgeon

Re: CVE request: php 5.3.1 update security curmudgeon (Nov 21)
Re: CVE request: Wordpress 2.8.6 security curmudgeon (Nov 15)
Re: CVE request: oping allows the disclosure of arbitrary file contents security curmudgeon (Nov 09)
Re: CVE-2009-3239 is a duplicate of CVE-2009-2139 and CVE-2009-2140 security curmudgeon (Oct 24)

Sergei Golubchik

Re: mysql-5.1.41 Sergei Golubchik (Nov 24)
Re: CVE assignment and second opinion needed Sergei Golubchik (Nov 11)
Re: mysql-5.1.41 Sergei Golubchik (Dec 17)
Re: CVE Request - MySQL - 5.0.88 Sergei Golubchik (Nov 21)

Stefan Behte

mmsclient: CVE request Stefan Behte (Dec 10)

Steffen Joeris

CVE Id request: request-tracker Steffen Joeris (Nov 14)

Steve Kemp

Re: X server umask issue Steve Kemp (Nov 09)

Steven M. Christey

Re: CVE request: Argument injections in multiple PEAR packages Steven M. Christey (Nov 28)
Re: CVE Request - Cacti - 0.8.7e Steven M. Christey (Nov 30)
Re: CVE request: Serendipity < 1.5 upload of files with *.php.* possible Steven M. Christey (Dec 23)
Re: CVE request: local root via setuid VBoxNetAdpCtl Steven M. Christey (Oct 15)
Re: Linux/QEMU issue Steven M. Christey (Dec 23)
Re: CVE request: oping allows the disclosure of arbitrary file contents Steven M. Christey (Oct 16)
Re: CVE request: polipo DoS via overly large "Content-Length" header Steven M. Christey (Dec 23)
Re: CVE request: Ruby on Rails: CSRF circumvention (from 2008) Steven M. Christey (Dec 11)
Re: CVE Request -- Xen -- PyGrub Steven M. Christey (Oct 01)
Re: CVE id request: typo3 Steven M. Christey (Oct 23)
Re: a new bind issue Steven M. Christey (Nov 24)
Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389 Steven M. Christey (Dec 31)
Re: Duplicate CVE assignment notification [was: CVE id request: django] Steven M. Christey (Oct 13)
Re: Handling cases of CWE-776 Steven M. Christey (Nov 09)
Re: mysql-5.1.41 Steven M. Christey (Nov 30)
Re: CVE requests: Zabbix Steven M. Christey (Dec 30)
Re: Duplicate CVE assignment notification [was: CVE id request: django] Steven M. Christey (Oct 13)
Re: CVE request for oCERT advisory 2009-013 (yTNEF/Evolution TNEF) Steven M. Christey (Nov 06)
Re: CVE id request: jetty Steven M. Christey (Oct 07)
Re: CVE request: kernel: mac80211: fix two remote exploits Steven M. Christey (Dec 02)
Re: CVE Request -- moodle 1.9.7 and 1.8.11 Steven M. Christey (Dec 11)
Re: CVE request: oping allows the disclosure of arbitrary file contents Steven M. Christey (Nov 09)
Re: CVEs for nginx Steven M. Christey (Nov 23)
Re: CVE Request -- phpMyAdmin Steven M. Christey (Oct 15)
Re: CVE request: ruby on rails XSS Weakness in strip_tags Steven M. Christey (Dec 07)
Re: CVE Request -- xfig Steven M. Christey (Dec 08)
Re: CVE request: oping allows the disclosure of arbitrary file contents Steven M. Christey (Nov 09)
Re: CVE request: acl 2.2.47 always follows symlinks Steven M. Christey (Dec 23)
Need more information on recent poppler issues Steven M. Christey (Nov 30)
Re: CVE request - kernel: fuse_ioctl_copy_user() dos Steven M. Christey (Dec 23)

Thomas Biege

Re: CVE request: libpoppler4: buffer overflow in the Abiword backend Thomas Biege (Nov 17)
CVE request: libpoppler4: buffer overflow in the Abiword backend Thomas Biege (Nov 09)
CVE request: ruby on rails XSS Weakness in strip_tags Thomas Biege (Nov 27)
Re: CVE request: libpoppler4: buffer overflow in the Abiword backend Thomas Biege (Nov 17)
CVE request: php 5.3.1 update Thomas Biege (Nov 20)
CVE request: v1.2.8 released to fix the 0777 base_dir creation issue Thomas Biege (Nov 20)
CVE request: virtualbox-ose guest can trigger denial of service at host, mem consumption Thomas Biege (Nov 16)
CVE request: local root via setuid VBoxNetAdpCtl Thomas Biege (Oct 12)

Tim Brown

Re: CVE request - asterisk, python-markdown, jetty, kde Tim Brown (Nov 04)
Re: Handling cases of CWE-776 Tim Brown (Oct 28)
Re: Handling cases of CWE-776 Tim Brown (Oct 28)
Re: Re: Some small KDE issues Tim Brown (Dec 11)
Handling cases of CWE-776 Tim Brown (Oct 27)
Re: Re: Some small KDE issues Tim Brown (Dec 11)
Re: CVE request - asterisk, python-markdown, jetty, kde Tim Brown (Oct 29)
Re: Re: Some small KDE issues Tim Brown (Dec 16)

Tomas Hoger

Re: libtheora CVE-2009-3389? Tomas Hoger (Dec 23)
Re: CVE request: php 5.3.1 update Tomas Hoger (Nov 20)
Re: More CVE-2009-2408 like issues Tomas Hoger (Oct 26)
Re: Re: Some small KDE issues Tomas Hoger (Dec 16)
Re: CVE request - asterisk, python-markdown, jetty, kde Tomas Hoger (Oct 29)
Re: MFSA 2009-63 Tomas Hoger (Oct 30)
Re: MFSA 2009-63 Tomas Hoger (Oct 30)
Re: CVE Request -- PHP 5 - 5.2.11 Tomas Hoger (Oct 15)
Re: Need more information on recent poppler issues Tomas Hoger (Nov 30)
QEMU VNC use-after-free Tomas Hoger (Oct 16)
Re: Re: CVE Request -- PHP 5 - 5.2.11 Tomas Hoger (Oct 16)
Re: CVE request: oping allows the disclosure of arbitrary file contents Tomas Hoger (Nov 16)
MFSA 2009-63 Tomas Hoger (Oct 29)
Re: CVE-2009-3239 is a duplicate of CVE-2009-2139 and CVE-2009-2140 Tomas Hoger (Oct 25)
Re: CVE request: oping allows the disclosure of arbitrary file contents Tomas Hoger (Nov 17)
Re: mysql-5.1.41 Tomas Hoger (Dec 16)
Re: CVE request: local root via setuid VBoxNetAdpCtl Tomas Hoger (Oct 13)
Re: mysql-5.1.41 Tomas Hoger (Dec 17)

Vincent Danen

CVE request for planet Vincent Danen (Oct 08)
CVE request for oCERT advisory 2009-013 (yTNEF/Evolution TNEF) Vincent Danen (Oct 27)
possible vulnerability in ghostscript >= 8.64 Vincent Danen (Dec 17)
ghostscript CVE for multiple NULL dereferences in JBIG2 decoder Vincent Danen (Oct 26)

Will Drewry

[oCERT-2009-016] Poppler, xpdf integer overflow during heap allocation Will Drewry (Oct 21)

Willy Tarreau

Re: CVE request kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7 Willy Tarreau (Oct 14)

yersinia

Re: presumptive php sec holes yersinia (Oct 13)
Re: CVE request: oping allows the disclosure of arbitrary file contents yersinia (Oct 17)