Vulnwatch: by author

36 messages starting Jun 02 06 and ending May 04 06
Date index | Thread index | Author index


advisories

Corsaire Security Advisory - VMware ESX Server Cross Site Scripting issue advisories (Jun 02)

advisory

Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability advisory (Apr 21)
Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows advisory (Apr 21)
Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error advisory (Apr 21)
Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key advisory (Apr 21)
Caucho Resin Windows Directory Traversal Vulnerability advisory (May 18)

Alex Park

BankTown's ActiveX Buffer Overflow Vulnerability Alex Park (May 04)

beSIRT

ISA Server 2004 Log Manipulation beSIRT (May 04)

Cesar

[Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure Cesar (Apr 20)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability Cisco Systems Product Security Incident Response Team (May 25)
Cisco Security Advisory: Cisco Unity Express Expired Password Reset Privilege Escalation Cisco Systems Product Security Incident Response Team (May 04)
Cisco Security Advisory: Cisco 11500 Content Services Switch HTTP Request Vulnerability Cisco Systems Product Security Incident Response Team (Apr 05)
Cisco Security Advisory: Cisco Optical Networking System 15000 series and Cisco Transport Controller Vulnerabilities Cisco Systems Product Security Incident Response Team (Apr 05)
Cisco Security Advisory: AVS TCP Relay Vulnerability Cisco Systems Product Security Incident Response Team (May 12)
Cisco Security Advisory: Cisco IOS XR MPLS Vulnerabilities Cisco Systems Product Security Incident Response Team (Apr 19)
Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Cisco Systems Product Security Incident Response Team (Apr 26)
Cisco Security Advisory: Multiple Vulnerabilities in Wireless Control System Cisco Systems Product Security Incident Response Team (Jun 30)
Cisco Security Advisory: Access Point Web-Browser Interface Vulnerability Cisco Systems Product Security Incident Response Team (Jun 30)
Cisco Security Advisory: Multiple Vulnerabilities in the WLSE Appliance Cisco Systems Product Security Incident Response Team (Apr 19)

eEye Advisories

[EEYEB-20060524] Symantec Remote Management Stack Buffer Overflow eEye Advisories (Jun 12)
[EEYEB-20060227] Juniper Networks SSL-VPN Client Buffer Overflow eEye Advisories (Apr 26)

Esteban Martinez Fayo

Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting Esteban Martinez Fayo (Apr 13)

Jean-Sébastien Guay-Leroux

Barracuda LHA archiver security bug leads to remote compromise Jean-Sébastien Guay-Leroux (Apr 04)
Barracuda ZOO archiver security bug leads to remote compromise Jean-Sébastien Guay-Leroux (Apr 04)

Matthew Murphy

PoC for Internet Explorer Modal Dialog Issue Matthew Murphy (Apr 28)
Internet Explorer User Interface Races, Redeux Matthew Murphy (Apr 26)

Michal Zalewski

MSIE (mshtml.dll) OBJECT tag vulnerability Michal Zalewski (Apr 23)

mozilla

ERNW Security Advisory 01/2006 mozilla (Jun 27)

news

Advisory - D-Link Access Point news (Jun 07)

NGSSoftware Insight Security Research

Heap overflow in OpenOffice.org suite leads to code execution NGSSoftware Insight Security Research (Jun 30)

NSFOCUS Security Team

NSFOCUS SA2006-02 : IBM AIX mklvcopy Local Privilege Escalation Vulnerability NSFOCUS Security Team (Apr 24)
NSFOCUS SA2006-03 : IBM AIX rm_mlcache_file Local Race Condition Vulnerability NSFOCUS Security Team (Apr 24)

Peter Thoeny

TWiki Security Advisory: Privilege elevation with crafted registration form (CVE-2006-2942) Peter Thoeny (Jun 20)

sectroyer

You tube html/javascript code injection sectroyer (Jun 12)

Stefano Di Paola

MySQL Anonymous Login Handshake - Information Leakage. Stefano Di Paola (May 04)
MySQL COM_TABLE_DUMP Information Leakage and Arbitrary command execution. Stefano Di Paola (May 04)