Bugtraq: by date

383 messages starting Jan 31 02 and ending Feb 27 02
Date index | Thread index | Author index


Thursday, 31 January

Re: Script for find domino's users Chad Loder

Friday, 01 February

Re: tac_plus version F4.0.4.alpha on at least Solaris 8 sparc Devrim SERAL
NetScreen ScreenOS 2.6 Subject to Trust Interface DoS Chris Lathem
Vulnerability in all versions of DCForum from dcscripts.com shimi
RE: NetScreen ScreenOS 2.6 Subject to Trust Interface DoS Dave Killion
Re: Vulnerability in all versions of DCForum from dcscripts.com David Choi

Saturday, 02 February

new advisory UkR-XblP?
KICQ 2.0.0b1 can be remotely crashed _kiss_

Sunday, 03 February

Re: Sapgui 4.6D for Windows Nick Wilkens
Long path exploit on NTFS - F-Secure Anti-Virus not vulnerable Tomi Tuominen
Re: Script for find domino's users nicob
Re: rsync-2.5.2 has security fix (was: Re: [RHSA-2002:018-05] New rsync packages available) Steven M. Christey
RE: NetScreen ScreenOS 2.6 Subject to Trust Interface DoS Alexander Poizner

Monday, 04 February

Re: autoresponder program could be tricked by spamers to send unsolicitedmail to victim's address (fwd) Rodent of Unusual Size
RE: new advisory sj
Mrtg Path Disclosure Vulnerability Tamer Sahin
Re: Mrtg Path Disclosure Vulnerability Barney Wolff
Re: Long path exploit on NTFS Hans Somers
[SECURITY] [DSA-106-2] updated rsync fix Wichert Akkerman
KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service Peter Gründl
RE: DoS bug on Tru64 Jethro Rose
ICQ Bug possibly? Kronos Yademos
Lotus Domino password bypass Gabriel A. Maggiotti
Re: Mrtg Path Disclosure Vulnerability Dave Ahmad
Re: Lotus Domino password bypass Chad Loder
[SUPERPETZ ADVISORY #002- Faq-O-Matic Cross-Site Scripting Vulnerability] superpetz
Re:ICQ Bug possibly? w0o
Re: Long path exploit on NTFS Frank Heyne
Re: Mrtg Path Disclosure Vulnerability Frog Man
Netgear RT311/RT314 sq
Re : Lotus Domino password bypass Nicolas Gregoire
Re: PIX DOS (config problem) - Similar to NetScreen ScreenOS... David P. Maynard
MSN Messenger reveals your name to websites (and can reveal email addresses too) Richard Burton
Re: Lotus Domino password bypass David Litchfield
Re: Sapgui 4.6D for Windows Andreas Baetz
RE: Long path exploit on NTFS Fleming, Diane
Re: DoS bug on Tru64 bugtraq () t-swat com
Re: Vulnerability in Black ICE Defender advisories
cachemgr.cgi (squid 2.3STABLE4) Francisco Sáa Muñoz
Buffer overflow in mIRC allowing arbitary code to be executed. James Martin
PHP Safe Mode Filesystem Circumvention Problem Dave Wilson
Re: Re:ICQ Bug possibly? Lex de Heer
Microsoft .NET faults Johannes Westerink
Lotus Domino password bypass Red Wolf
Re: Script for find domino's users David Litchfield
Vulnerability in Black ICE Defender Matt Taylor

Tuesday, 05 February

Re: Buffer overflow in mIRC allowing arbitary code to be executed. Kevin Day
squirrelmail: squirrelspell plugin check_me.mod.php bug skylined
Re: Vulnerability in Black ICE Defender Swift Griggs
Viewing arbitrary file from the file system using Eshare Expressions 4 server Alex Forkosh
OSX ICQ DoS Stephen
RE: Vulnerability in Black ICE Defender Chris Paget
RE: svindel.net security advisory - web admin vulnerability in Ca cheOS Campbell, Dirk
Re: OSX ICQ DoS Stephen
Re: NetScreen ScreenOS 2.6 Subject to Trust Interface DoS Drew Simonis
Castelle Faxpress: Password used for NT Print queue can be discl osed in Plain Text Leon Ward
Re: Netgear RT311/RT314 Rzac`
Trojan / Spyware Connection made to 64.240.175.18 every time you use IE ANti-spyware Anti-virus wont detect it. Adonis.No.Spam
Sardonix Security Auditing Portal Crispin Cowan
Faq-O-Matic Cross-Site Scripting superpetz
Published Report of Vulnerability in Lucent VitalSuite Software Richard Hafner
NetScreen Response to ScreenOS Port Scan DoS Vulnerability Mike Kouri
And another (same) bug in DCForum at user registration process (dcscripts.com) shimi
Mrtg Path Disclosure Vulnerability (Revised) Tamer Sahin
Vulnerabilities in Astaro Security Linux 2.016 Jörg Lübbert
Re: Vulnerability in Black ICE Defender Troy Billington

Wednesday, 06 February

texis(CGI) Path Disclosure Vulnerability - phinegeek -
MSN Messenger and UDP 1900 Louie Martinez
Remote Compromise in Oracle 9i Database Server NGSSoftware Insight Security Research
-Possible- licq D.o.S ciscosux
Multiple Buffer Overflows in Oracle 9iAS NGSSoftware Insight Security Research
Intel.com Mailing List Arbitrary Address Removal Link E M
JSP translation file access under Oracle 9iAS NGSSoftware Insight Security Research
Hackproofing Oracle Application Server paper David Litchfield
Black ICE Ping Vulnerability Side Note Stoic forty-four
RE: Black ICE Ping Vulnerability Side Note Keith T. Morgan
Astaro Response: Vulnerabilities in Astaro Security Linux 2.016 Markus Hennig
Re: PIX DOS (config problem) - Similar to NetScreen ScreenOS... Zeke Gibson [STI]
Re: new advisory Andrew Simmons
RE: Long path exploit on NTFS Didier Arenzana
RE: Long path exploit on NTFS David Sexton
nmap vs. inetd on Caldera (ex-SCO) OpenServer, Re: DoS bug on Tru64 Bela Lubkin
Re: Netgear RT311/RT314 Christian Vezina
Infecting the KaZaA network? Andrew McClymont
CSS -> ign.com Knud Erik Højgaard
Insecure installations of cgi wrappers (RTFM people!) Nathan Neulinger
Re: NetScreen Response to ScreenOS Port Scan DoS Vulnerability Chris Lathem
Re: Long path exploit on NTFS Christophe Bousquet
Re: PIX DOS (config problem) - Similar to NetScreen ScreenOS... David P. Maynard
DW020203-PHP clarification Dave Wilson
Sambar Webserver Sample Script v5.1 DoS Vulnerability Exploit Tamer Sahin
RE: Long path exploit on NTFS Uidam, T (Tim)

Thursday, 07 February

Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA) obscure
Re: Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA) Mark Renouf
Cross-site Scripting Vulnerability in .Net Framework Microsoft Security Response Center
Re: Netgear RT311/RT314 Sullo sq
Re: Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA) Patrick Kuiper
Re: Intel.com Mailing List Arbitrary Address Removal Link Joel Maslak
AtheOS: escaping from a chroot jail Jedi/Sector One
Re: CSS -> ign.com Blake Frantz
Overflow Vulnerabilities in hanterm xperc
RE: Infecting the KaZaA network? Andrew McClymont
Cisco Security Advisory: Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability Cisco Systems Product Security Incident Response Team
Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service Nicolas Gregoire
Security Update: [CSSA-2002-SCO.3] UnixWare 7: message catalog environment variable vulnerability security
RE: Long path exploit on NTFS David Korn
Re: Infecting the KaZaA network? the Pull
PHP Advisory #2 Paul Brereton
Re: Infecting the KaZaA network? (unlikely) Adam Lydick
Re: Infecting the KaZaA network? Brad Maloney
Re: new advisory - (filtering problems) b0iler _
Re: CSS -> ign.com Steven Champeon
Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service Chad Loder
[SECURITY] [DSA 108-1] New wmtv packages fix symlink vulnerability Martin Schulze
[Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities Global InterSec Research
cachemgr.cgi (2.3STABLE4) (and 2) Francisco Sáa Muñoz
Security Advisory - #1 Paul Brereton
Re: Intel.com Mailing List Arbitrary Address Removal Link Thierry Zoller
RE: MSN Messenger and UDP 1900 Dustin Miller
Long Path Exploit on NTFS Mark Ng

Friday, 08 February

HELP ! : Trojanised HTML: Internet Exporer 5 and 6 [technical exercise] http-equiv () malware com
MDKSA-2002:012 - groff update Mandrake Linux Security Team
Hewlett Packard AdvanceStack Switch Managment Authentication Bypass Vulnerability Tamer Sahin
RE: -Possible- licq D.o.S Jon Keating
RE: Intel.com Mailing List Arbitrary Address Removal Link Knud Erik Højgaard
Re: Alteon ACEdirector signature/security bug Mike Rogers
Re: Infecting the KaZaA network? GertJan de Leeuw
Re: MSN Messenger and UDP 1900 Valdis . Kletnieks
verisign payment site backdoor ? Andrej Todosic
Re: Intel.com Mailing List Arbitrary Address Removal Link Ryan M Harris
Advisory #3 - PHP & JSP Paul Brereton
RE: Long path exploit on NTFS Frank Heyne
Re: Infecting the KaZaA network? Alun Jones
-possible- Bufferoverflow in ICQ 2001b tsr
Re: Security Advisory - #1 Dmitry Guyvoronsky
MSN contact list disclosure Tom Micklovitch
RE: HELP ! : Trojanised HTML: Internet Exporer 5 and 6 [technic al exercise] Thor Larholm
[SPSadvisory#46]Apple QuickTime Player "Content-Type" Buffer Overflow webmaster
[SECURITY] [DSA 079-2] New UUCP packages finally fix uucp uid/gid access Martin Schulze
Re: [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities KOJIMA Hajime
OT: Netscape security contact ? Jarno Huuskonen
large spam messages disable Hotmail accounts Stefan Demetz
Security Update [CSSA-2002-001.0] Linux - OpenLDAP attribute deletion problem Support Info
ALERT: ISS BlackICE Kernel Overflow Exploitable Marc Maiffret
Security Update [CSSA-2002-003.0] Linux - Remote attack on rsync Support Info
RE: Long path exploit on NTFS Elan Hasson
Re: Intel.com Mailing List Arbitrary Address Removal Link Todd Underwood
another hanterm exploit Stuart Moore
RE: Long path exploit on NTFS andy
Security Update [CSSA-2002-002.0] Linux - Remote exploit against mutt Support Info
arescom 800 authentification flaw Powertech
Re: another hanterm exploit Jose Nazario
Re: [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities Kris Kennaway

Saturday, 09 February

Arescom NetDSL-1000 telnetd DoS Pim van Riezen
RE: Intel.com Mailing List Arbitrary Address Removal Link jlewis
Security Issue in Icewarp Huseyin Uslu
Account theft vulnerability in MakeBid Auction Deluxe 3.30 Blake Frantz
MSN Messenger Hijacking Tom Gilder
InstantServers MiniPortal Multiple Vulnerabilities Strumpf Noir Society

Sunday, 10 February

RE: Security Advisory - #1 Colby Marks
MorningStar.ca Canada And Security Practices Noam Eppel
Re: verisign payment site backdoor ? Nojan Moshiri
RE: MSN contact list disclosure Geoff Sweet
RE: Script for find domino's users Jay D. Thomson
Re: HELP ! : Trojanised HTML: Internet Exporer 5 and 6 [technical exercise] dzzie
Re: Advisory #3 - PHP & JSP Ryan Fox
Re: Mrtg Path Disclosure Vulnerability Jason Hicks

Monday, 11 February

Sybex E-Trainer Directory Traversal Vulnerability ZeroBreak
Re: MSN contact list disclosure Tom McAdam
Re: Infecting the KaZaA network? Ben Laurie
EasyBoard 2000 Remote Buffer Overflow Vulnerability jhyou
Unixware Message catalog exploit code jGgM .
Vulnerability in Sawmill for Solaris v. 6.2.14 darky0da
Re: texis(CGI) Path Disclosure Vulnerability mark-bugtraq
This is the CORRECTED POST please ignore the one befor same subject MULTIPLE Remote Issues with II5.1 on Windows XP Adonis.No.Spam

Tuesday, 12 February

RUS-CERT Advisory 2002-02:01: Temporary file handling in GNAT Florian Weimer
[ GFISEC04102001 ] Internet Explorer and Access allow macros to be executed automatically Sandro Gauci
Deanonymizing SafeWeb Users David Martin
MDKSA-2002:013 - openldap update Mandrake Linux Security Team
CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many Implementations CERT Advisory
SNMP Vulnerabilities SGI Security Coordinator
SCO UnixWare 7.1.X Gogel, Derryle
Security Update: [CSSA-2002-SCO.4] Open UNIX, UnixWare 7: snmpd memory fault vulnerabilities security
[RHSA-2001:163-20] Updated ucd-snmp packages available bugzilla
more SNMP notes Robert Graham

Wednesday, 13 February

PowerFTP Personal FTP Server Multiple Vulnerabilities Strumpf Noir Society
Re: MorningStar.ca Canada And Security Practices Tomi Tuominen
Outlook will see non-existing attachments Valentijn Sessink
[SECURITY] [DSA 109-1] New Faq-O-Matic packages fix cross-site scripting vulnerability Martin Schulze
NetWin CWMail.exe Buffer Overflow NGSSoftware Insight Security Research
Exim 3.34 and lower (fwd) Dave Ahmad
dH & SECURITY.NNOV: buffer overflow in mshtml.dll 3APA3A
SIPS - vulnerable to anyone gaining admin access. b0iler _
[GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting pre
Falcon Web Server Authentication Circumvention Vulnerability Strumpf Noir Society
RE: BindView NetInventory NetRC hostcfg_ni password passed in cle ar text Blake, Scott
SNMP Enabled on Dell Servers Will Backman
[SECURITY] [DSA 110-1] New CUPS packages fix buffer overflow Martin Schulze
Re: Deanonymizing SafeWeb Users peleus
Identix BioLogon 3 Paul A Roberts
Re: [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities Tom Parker
Re: Authorize.Net Plain Text Login Transmission Brian Gallagher
Update on the MS02-005 patch, holes still remain Thor Larholm
Re: This is the CORRECTED POST please ignore the one befor same subject MULTIPLE Remote Issues with II5.1 on Windows XP sozni
Avirt Gateway 4.2 remote buffer overflow: proof of concept uid0x00
Re: mpg321 Joe Drew
Correction: Re: Deanonymizing SafeWeb Users peleus
RE: Astaro Security Linux Improper File Permissions Flaw Markus Hennig
Astaro Security Linux Improper File Permissions Flaw dendler

Thursday, 14 February

Microsoft C++ feature against buffer overflows itself vulnerable Chris Ren
[NGSEC-2002-1] Ettercap, remote root compromise NGSEC Research Team
Re: SNMP Enabled on Dell Servers Barry McGeorge
RE: Microsoft C++ feature against buffer overflows itself vulnerable David LeBlanc
SafeWeb Addresses Vulnerability in Consumer Privacy Technology Sandra Song
HP Secure OS Software for Linux security bulletins digest IT Resource Center
[SECURITY] [DSA-111-1] Multiple SNMP vulnerabilities Wichert Akkerman
Add2it Mailman command execution b0iler _
HP-UX security bulletins digest IT Resource Center
In response to alleged vulnerabilities in Microsoft Visual C++ security checks feature Brandon Bray
Aprisma Response to CERT Advisory Unknown
Security Update: [CSSA-2001-SCO.36.2] REVISED: Open UNIX, UnixWare 7: wu-ftpd ftpglob() vulnerability security
Security Update: [CSSA-2002-SCO.5] Open UNIX, UnixWare 7: encrypted password disclosure security
HP-UX security bulletins digest IT Resource Center

Friday, 15 February

Re: In response to alleged vulnerabilities in Microsoft Visual C++ security checks feature Crispin Cowan
Re: Outlook will see non-existing attachments Paul L Daniels
Remote DoS in Netgear RM-356 Ben Ryan
[ARL02-A02] DCP-Portal Root Path Disclosure Vulnerability Ahmet Sabri ALPER
[ARL02-A03] DCP-Portal Cross Site Scripting Vulnerability Ahmet Sabri ALPER
MDKSA-2002:014 - ucd-snmp update Mandrake Linux Security Team
MDKSA-2002:015 - cups update Mandrake Linux Security Team
Re: Deanonymizing SafeWeb Users Alexander K. Yezhov
Network Queuing Environment (NQE) vulnerabilities SGI Security Coordinator

Saturday, 16 February

Non existing attachments, more info Valentijn Sessink
SECURITY.NNOV: Bypassing content filtering software 3APA3A
SiteNews remote add user exploit Ulf H{rnhammar
SNMP test suite vs. Motorola SB4100 cable modem Powers, James L.
pforum: mysql-injection-bug Jens Liebchen
codeblue remote root Andrew Griffiths
Microsoft compiler flaw, Cigital responds Gary McGraw

Monday, 18 February

Windows XP Remote DOS attacks with SYN Flag. Make CPU 100 % Adonis.No.Spam
BlackIce 2.9 car Latest with patch "DOS attacks with URG Flag Set ARE NOT LOGGED" Adonis.No.Spam
Re: Outlook will see non-existing attachments David F. Skoll
[SECURITY] [DSA 112-1] New hanterm packages fix buffer overflow Martin Schulze
Phusion-Webserver-v1.0-Bugs&Exploits-Remotes Alex Hernandez
Re: SNMP test suite vs. Motorola SB4100 cable modem Chris Wilson
winamp and wma Song Licenses jelmer
Re: Remote DoS in Netgear RM-356 Simple Nomad

Tuesday, 19 February

RE: SECURITY.NNOV: Bypassing content filtering software Aidan O'Kelly
[CLA-2002:463] Conectiva Linux Security Announcement - uucp secure
Netwin Webnews Buffer Overflow Vulnerability (#NISR18022002) NGSSoftware Insight Security Research
Another local root vulnerability during installation of Tarantella Enterprise 3. Larry W. Cashdollar
Security BugWare : Alcatel 4400 PBX hack Irib
[SA-2002:01] Slashcode login vulnerability Jamie McCarthy
ITS4 from Cigital flawed David LeBlanc
[SECURITY] [DSA-113-1] New ncurses packages available Daniel Jacobowitz
RE: In response to alleged vulnerabilities in Microsoft Visual C++ security checks feature David LeBlanc
Outlook \r expliots - ripMIME fix. Paul L Daniels
Re: Non existing attachments, more info David F. Skoll
Re: Another local root vulnerability during installation of Tarantella Enterprise 3. Larry W. Cashdollar
Dino's Webserver v1.2 DoS, possible overflow 'ken'@FTU
CheckPoint FW1 HTTP Security Hole Volker Tanger
UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] William D. Colburn (aka Schlake)
Cert Advisory 2002-03 and HP JetDirect Information Security
gnujsp: dir- and script-disclosure Thomas Springer
Security Update: [CSSA-2002-SCO.5.1] REVISION: Open UNIX, UnixWare 7, OpenServer: encrypted password disclosure security
ScriptEase MiniWeb Server DoS Vulnerability Tamer Sahin
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Dennis Henderson

Wednesday, 20 February

RE: Non existing attachments, more info David F. Skoll
Whose X do I need to X to get on CERT? Jonathan G. Lampe
Re: gnujsp: dir- and script-disclosure Stefan Gybas
CSS visited pages disclosure Andrew Clover
RE: Non existing attachments, more info Grimes, Roger
MSDE, Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS c c
RE: Whose X do I need to X to get on CERT? Matt Groves
Symantec Enterprise Firewall (SEF) Notify Daemon data loss via SN MP Martin O'Neal
Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies Martin O'Neal
Re: Cert Advisory 2002-03 and HP JetDirect Russell Fulton
UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Steve VanDevender
Four More ScriptEase MiniWeb Server v0.95 DoS Attacks 'ken'@FTU
Re: Non existing attachments, more info William D. Colburn (aka Schlake)
Avirt 4.2 question nicolas brulez
Internet-Draft for "Responsible Disclosure Process" released Steven M. Christey
Re: Cert Advisory 2002-03 and HP JetDirect Joshua Newton
Re: Citrix NFuse 1.6 - additional network exposure Bob Fiero
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Mike Benham
Security issue with GroupWise 6 and LDAP authentication in PostOffice Frank Bulk
Why is Microsoft watching us watch DVD movies? Richard M. Smith
Re: Non existing attachments, more info Jason Haar

Thursday, 21 February

RE: ITS4 from Cigital flawed Gary McGraw
Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies Sym Security
AdMentor Login Flaw Frank
"Cthulhu xhAze" - Command execution in Ans.pl b0iler _
Squid HTTP Proxy Security Update Advisory 2002:1 Henrik Nordstrom
Check Point response to CERT CA-2002-03 (Multi-vendor SNMP vulnerabilities) Scott Walker Register
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Jason Haar
Netwin Webnews 1.1k Shai
SecurityOffice Security Advisory:// LilHTTP Web Server Protected File Access Vulnerability Tamer Sahin
Zero One Tech (ZOT) P100s PrintServer and SNMP Clinton Smith
Re: CheckPoint FW1 HTTP Security Hole Greg Fraize
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Ronald F. Guilmette
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Randal L. Schwartz
Re: Why is Microsoft watching us watch DVD movies? Jamie Oulman
[SECURITY] [DSA 114-1] New GNUJSP packages fix directory and script source disclosure Martin Schulze
RE: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint fire wall] Proescholdt, timo
Re: Why is Microsoft watching us watch DVD movies? Patrick M. Hausen

Friday, 22 February

CNet CatchUp arbitrary code execution Andrew Clover
Security Update: [CSSA-2002-004.0] Linux - Various security problems in ucd-snmp Support Info
Gator installer Plugin allows any software to be installed obscure
Remote crashes in Yahoo messenger Scott Woodward
SecurityOffice Security Advisory:// Essentia Web Server Directory Traversal Vulnerability Tamer Sahin
[RHSA-2002:020-05] Updated ncurses4 compat packages are available bugzilla
Security Update: [CSSA-2002-SCO.6] security
DoS Attack against many RADIUS servers Alan DeKok
Squid buffer overflow Jouko Pynnonen
SecurityOffice Security Advisory:// Essentia Web Server DoS Vulnerability Tamer Sahin
RE: Whose X do I need to X to get on CERT? Jonathan G. Lampe
Re: DoS Attack against many RADIUS servers David Frascone
Morpheus, Kazaa and Grokster Remote DoS. Also Identity faking vulnerability. mrjade 2k2
RE: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint fire wall] Peter Bieringer
TSLSA-2002-0031 - squid Trustix Secure Linux Advisor

Saturday, 23 February

RE: Gator installer Plugin allows any software to be installed Richard M. Smith
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Tommaso Di Donato
pforum: cross-site-scripting bug Jens Liebchen
Re: Why is Microsoft watching us watch DVD movies? Konrad Rieck
RE: ITS4 from Cigital flawed Jeremy Epstein
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Keith Simonsen
Windows Media Player executes WMF content in .MP3 files. David Korn
XMB cross-scripting vulnerability skizzik
RE: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint fire wall] Corey J. Steele
Re: Cert Advisory 2002-03 and HP JetDirect david evlis reign

Sunday, 24 February

Re: Why is Microsoft watching us watch DVD movies? Just Marc

Monday, 25 February

Greymatter 1.21c and earlier - remote login/pass exposure security curmudgeon
ScriptEase:WebServer Edition vulnerability Aleksander Posmyk
Re: CheckPoint FW1 HTTP Security Hole Scott Walker Register
Open Bulletin Board javascript bug. skizzik
Re: Remote crashes in Yahoo messenger Chris Bisnett
SuSE Security Announcement: cups (SuSE-SA:2002:005) Thomas Biege
Re: Symantec Enterprise Firewall (SEF) Notify Daemon data loss via SN MP Sym Security
Symantec LiveUpdate Javier Sanchez
A reason for concern over ie's GetObject() vulnerabilities... Hotmail... freewarecollector
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint firewall] Kurt Seifried
Re: Windows Media Player executes WMF content in .MP3 files. Brian McWilliams
Exploit for Tarantella Enterprise installation (bid 4115) Larry W. Cashdollar
Re: Re: Remote crashes in Yahoo messenger Chris Bisnett
Re: Zero One Tech (ZOT) P100s PrintServer and SNMP Clinton Smith
CERT Advisory CA-2002-04 Buffer Overflow in Microsoft Internet Explorer CERT Advisory

Tuesday, 26 February

Anti Virus Mailscanners DOS Eduardo R. Maciel
RE: Symantec LiveUpdate Peter Miller
BadBlue XSS vulnerabilities / Filesharing Server Worm Strumpf Noir Society
BadBlue Yet Another Directory Traversal Strumpf Noir Society
Re: Extracting a 3DES key from an IBM 4758 Todd Arnold
[Fwd: RE: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint fire wall]] Corey J. Steele
SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch) Tamer Sahin
Practical Exploitation of RC4 Weaknesses in WEP Environments h1kari
Re: Open Bulletin Board javascript bug. godminus
Re: Anti Virus Mailscanners DOS Piotr Klaban
Re: UPDATE: [wcolburn () nmt edu: SMTP relay through checkpoint fire wall] Menashe Eliezer
BUG: Kmail client DoS Andrey Kazakov
Re: Why is Microsoft watching us watch DVD movies? Konrad Rieck
Re: Anti Virus Mailscanners DOS Jedi/Sector One
Re: Anti Virus Mailscanners DOS David F. Skoll
RE: Symantec LiveUpdate Calanan, Michael
Re: Anti Virus Mailscanners DOS Martin Lesser
MDKSA-2002:016-1 - squid update Mandrake Linux Security Team
[RHSA-2002:029-09] New squid packages available bugzilla
Last Call for Papers - RAID 2002 Peter Mell
Century Software Term Exploit haiku

Wednesday, 27 February

Re: Symantec LiveUpdate saabstory
security advisory linux 2.4.x ip_conntrack_irc Harald Welte
Details and exploitation of buffer overflow in mshtml.dll (and few sidenotes on Unicode overflows in general) 3APA3A
Cisco Security Advisory: Data Leak with Cisco Express Forwarding Cisco Systems Product Security Incident Response Team
SECURITY.NNOV: Special device access in The Bat! 3APA3A
Auto file execution vulnerability in Mac OS vm_converter
LBYTE&SECURITY.NNOV: Buffer overflows in Worldgroup 3APA3A
BPM STUDIO PRO 4.2 DOS DEVICE PATH VULNERABILITY ][-][UNTER
mod_ssl Buffer Overflow Condition (Update Available) Ed Moyle
Advisory 012002: PHP remote vulnerabilities security
RE: Why is Microsoft watching us watch DVD movies? Russ
RE: Why is Microsoft watching us watch DVD movies? Richard M. Smith
RE: Open Bulletin Board javascript bug. Justin
[RHSA-2002:028-13] Updated 2.4 kernel available bugzilla
Using Environment for returning into Lib C Elie aka "Lupin" Bursztein
BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY ][-][UNTER