Vulnwatch: by author

95 messages starting Jan 11 06 and ending Mar 15 06
Date index | Thread index | Author index


ad () heapoverflow com

Critical excel vulnerability for sale, read inside. ad () heapoverflow com (Jan 11)

Advisories

[EEYEB-20051031] Apple QuickTime Malformed GIF Heap Overflow Advisories (Jan 11)
[EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability Advisories (Jan 10)
[EEYEB-20051220] Apple QuickTime QTIF Stack Overflow Advisories (Jan 11)
[EEYEB-20051117B] Apple iTunes (QuickTime.qts) Heap Overflow Advisories (Jan 11)
Updated Advisories - Incorrect CVE Information Advisories (Jan 11)
[EEYEB-20051117A] Apple QuickTime STSD Atom Heap Overflow Advisories (Jan 11)

ascii

Milkeyway Multiple Vulnerabilities ascii (Mar 17)

Cesar

WLSI - Windows Local Shellcode Injection - Paper Cesar (Mar 14)
[Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT} Cesar (Jan 26)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: IOS Stack Group Bidding Protocol Crafted Packet DoS Cisco Systems Product Security Incident Response Team (Jan 18)
Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Cisco Systems Product Security Incident Response Team (Jan 26)
Cisco Security Advisory: Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS) Cisco Systems Product Security Incident Response Team (Jan 11)
Cisco Security Advisory: Cisco Call Manager Denial of Service Cisco Systems Product Security Incident Response Team (Jan 18)
Cisco Security Advisory: TACACS+ Authentication Bypass in Cisco Anomaly Detection and Mitigation Products Cisco Systems Product Security Incident Response Team (Feb 15)
Cisco Security Advisory: Access Point Memory Exhaustion from ARP Attacks Cisco Systems Product Security Incident Response Team (Jan 12)
Cisco Security Advisory: Cisco Call Manager Privilege Escalation Cisco Systems Product Security Incident Response Team (Jan 18)

CORE Security Technologies Advisories

CORE-2006-0124: Cross-Site Scripting in Verisign’s haydn.exe CGI script CORE Security Technologies Advisories (Mar 21)

Digital Armaments

Digital Armaments: Apache auth_ldap module Multiple Format Strings Vulnerability Digital Armaments (Jan 30)
Digital Armaments: Gallery web-based photo gallery remote file execution Digital Armaments (Feb 16)
Digital Armaments: CMU SNMP utilities snmptrad Format String Vulnerability Digital Armaments (Feb 07)

dong-hun you

[INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability dong-hun you (Mar 12)
[INetCop Security Advisory] Global Hauri Virobot cookie exploit dong-hun you (Feb 22)

D . Snezhkov

Remote access to NeuSecure/Netcool backend database via web interface credentials leakage D . Snezhkov (Mar 08)

D.Snezhkov

Password disclosure and remote access in Netcool/NeuSecure Security information management platform D.Snezhkov (Feb 16)

eEye Advisories

[EEYEB-20051017] Windows Media Player BMP Heap Overflow eEye Advisories (Feb 15)

Eldon Sprickerhoff

Re: Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Eldon Sprickerhoff (Jan 31)

Fortinet Research

Fortinet Advisory - Apple QuickTime Player StripOffsets Improper Memory Acces Fortinet Research (Jan 12)
Fortinet Security Advisory: "Apple QuickTime Player Improper Memory Access Vulnerability" Fortinet Research (Jan 12)
Fortinet Advisory: Apple QuickTime Player Color Map Entry Size Buffer Overflow Fortinet Research (Jan 13)
Fortinet Advisory - Apple QuickTime Player StripByteCounts Buffer Overflow Vulnerability Fortinet Research (Jan 12)
Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability Fortinet Research (Jan 18)
Fortinet Advisory: "Apple QuickTime Player ImageWidth Integer Overflow Vulnerability" Fortinet Research (Jan 13)
Fortinet Advisory: Apple Quick Time Player ImageWidth Denial of Service Vulnerability Fortinet Research (Jan 12)

Infratech Research

[ Secuobs - Advisory ] Bluetooth : DoS on Nokia cell phones Infratech Research (Feb 10)
[ Secuobs - Advisory ] Another kind of DoS on Nokia cell phones Infratech Research (Feb 15)

Jean-Sébastien Guay-Leroux

zoo contains exploitable buffer overflows Jean-Sébastien Guay-Leroux (Feb 23)

Ken Pfeil

FW: failure notice Ken Pfeil (Mar 28)

Konstantine

Re: Remote overflow in MSIE script action handlers (mshtml.dll) Konstantine (Mar 17)

labs-no-reply

iDefense Security Advisory 02.24.06: SCO Unixware Setuid ptrace Local Privilege Escalation Vulnerability labs-no-reply (Feb 24)
iDefense Security Advisory 03.23.06: RealNetworks RealPlayer and Helix Player Invalid Chunk Size Heap Overflow Vulnerability labs-no-reply (Mar 23)
iDefense Security Advisory 03.23.05: ISS Multiple Products Local Privilege Escalation Vulnerability labs-no-reply (Mar 23)

labs-no-reply () idefense com

iDefense Security Advisory 02.01.06: Winamp m3u/pls .WMA Extension Buffer Overflow Vulnerability labs-no-reply () idefense com (Feb 01)
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrexecd.exe Heap Overflow Vulnerability labs-no-reply () idefense com (Jan 17)
iDefense Security Advisory 01.05.06: Blue Coat Systems WinProxy Host Header Stack Overflow Vulnerability labs-no-reply () idefense com (Jan 05)
iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phfont Race Condition Vulnerability labs-no-reply () idefense com (Feb 07)
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrd.exe Heap Overflow Vulnerability labs-no-reply () idefense com (Jan 17)
iDefense Security Advisory 03.02.06: EMC Dantz Retrospect 7 Backup client DoS Vulnerability labs-no-reply () idefense com (Mar 02)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS su Command Buffer Overflow labs-no-reply () idefense com (Feb 07)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phgrafx Command Buffer Overflow labs-no-reply () idefense com (Feb 07)
iDEFENSE Security Advisory 02.10.06: IBM Lotus Domino Server LDAP DoS Vulnerability labs-no-reply () idefense com (Feb 10)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 01.17.06: Cisco Systems IOS 11 Web Service CDP Status Page Code Injection Vulnerability labs-no-reply () idefense com (Jan 17)
iDefense Security Advisory 03.02.06: Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability labs-no-reply () idefense com (Mar 02)
iDefense Security Advisory 01.05.06: Blue Coat WinProxy Telnet DoS Vulnerability labs-no-reply () idefense com (Jan 05)
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrd.exe DoS Vulnerability labs-no-reply () idefense com (Jan 17)
iDefense Security Advisory 02.14.06: Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability labs-no-reply () idefense com (Feb 15)
iDefense Security Advisory 01.23.06: Computer Associates iTechnology iGateway Service Content-Length Buffer Overflow Vulnerability labs-no-reply () idefense com (Jan 23)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS passwd Command Buffer Overflow labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 01.10.06: Sun Solaris uustat Buffer Overflow Vulnerability labs-no-reply () idefense com (Jan 10)
iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 Local Denial of Service Vulnerability labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 01.09.06: Multiple Vendor mod_auth_pgsql Format String Vulnerability labs-no-reply () idefense com (Jan 09)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 02.01.06: Winamp m3u Parsing Stack Overflow Vulnerability labs-no-reply () idefense com (Feb 01)
iDefense Security Advisory 03.02.06: Apple Mac OS X passwd Arbitrary Binary File Creation/Modification labs-no-reply () idefense com (Mar 02)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS fontsleuth Command Format String Vulnerability labs-no-reply () idefense com (Feb 08)
iDefense Security Advisory 01.05.06: Blue Coat WinProxy Remote DoS Vulnerability labs-no-reply () idefense com (Jan 05)
iDefense Security Advisory 01.13.06: Novell SUSE Linux Enterprise Server Remote Manager Heap Overflow labs-no-reply () idefense com (Jan 13)
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability labs-no-reply () idefense com (Feb 07)

ma+nomail

fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321) ma+nomail (Jan 23)

Matthew Murphy

Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Matthew Murphy (Feb 13)
Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Matthew Murphy (Feb 13)

Michael Evanchik

Re: FW: failure notice Michael Evanchik (Mar 29)

Michal Zalewski

Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski (Mar 17)
Re: Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski (Mar 17)
Re: Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski (Mar 17)

Mike Iglesias

Re: Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Mike Iglesias (Feb 01)

NaPa

RE: Download Accelerator Plus can be tricked to download malicious file NaPa (Jan 05)

NGSSoftware Insight Security Research

Microsoft Outlook Critical Vulnerability NGSSoftware Insight Security Research (Jan 11)
Microsoft Exchange Critical Vulnerability NGSSoftware Insight Security Research (Jan 11)

NSFOCUS Security Team

NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability NSFOCUS Security Team (Feb 23)

Research Infratech

[ Secuobs - Advisory ] Bluetooth : DoS on Sony/Ericsson cell phones Research Infratech (Feb 07)
[ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC Research Infratech (Feb 07)
[ Secuobs - Tools release ] BSS (Bluetooth Stack Smasher) fuzzer Research Infratech (Feb 07)

Roman Medina-Heigl Hernandez

RS-2006-1: Multiple flaws in VHCS 2.x Roman Medina-Heigl Hernandez (Feb 11)

Steve Manzuik

EEYE: Temporary workaround for IE createTextRange vulnerability Steve Manzuik (Mar 28)

Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]

Re: FW: failure notice Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (Mar 28)

Thierry Zoller

[ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess() Thierry Zoller (Jan 17)

vkatalov

PasswordSafe 3.0 weak random number generator allows key recovery attack vkatalov (Mar 23)

XFOCUS Security Team

[xfocus-SD-060329]MPlayer: Multiple integer overflows XFOCUS Security Team (Mar 29)
[xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability XFOCUS Security Team (Feb 06)
Re: [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability XFOCUS Security Team (Feb 07)
[xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities XFOCUS Security Team (Jan 01)
[xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability XFOCUS Security Team (Mar 15)