Bugtraq: by date

330 messages starting Apr 30 04 and ending May 31 04
Date index | Thread index | Author index


Friday, 30 April

Re: http://www.smashguard.org Pavel Machek
Re: http://www.smashguard.org Crispin Cowan
[product-security () apple com: APPLE-SA-2004-04-30 QuickTime 6.5.1] David Ahmad
Re: http://www.smashguard.org Pavel Machek

Saturday, 01 May

Re: http://www.smashguard.org Theo de Raadt
Re: http://www.smashguard.org Nicholas Weaver
Re: http://www.smashguard.org Coleman Kane
LNSA-#2004-0013: Multiple Vulnerabilities in Samba Vincenzo Ciaglia
RE: IE Certificate Stealing (Phising) bug Michael Wojcik
Props 0.6.1 XSS and Remote File Viewing Vulnerability Manuel Lopez
Re: http://www.smashguard.org Theo de Raadt
LNSA-#2004-0014: X-Chat vulnerability in Socks-5 proxy Vincenzo Ciaglia
Will the Sasser worm become the next Blaster? kers0r
New LSASS-based worm finally here (Sasser) Ben Ryan
Re: Will the Sasser worm become the next Blaster? Gadi Evron

Monday, 03 May

[SECURITY] [DSA 500-1] New flim packages fix insecure temporary file creation Matt Zimmerman
W32/Sasser a and b SNORT Sigs Martin Overton
[SECURITY] [DSA 499-1] New rsync packages fix directory traversal bug Matt Zimmerman
PaX Linux Kernel 2.6 Patches DoS Advisory chris
EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow Marc Maiffret
Re: New LSASS-based worm finally here (Sasser) Javier Fernandez-Sanguino
Re: Will the Sasser worm become the next Blaster? Damian Menscher
[waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke] Janek Vind
X-Chat[v1.8.0-v2.0.8]: socks-5 remote buffer overflow exploit. Vade 79
Serv-U LIST -l Parameter Buffer Overflow Aviram Jenik
RE: After Ms patches last Wed ... InfoSec
Crystal Reports Vulnerabilities Imperva Application Defense Center
Vulnerability in YaBB forum (Perl version without SQL) Dmitry Shurupov
Multible Vulnerabilites in Aldos Webserver oliver
RE: Will the Sasser worm become the next Blaster? Pullum, Stephen
[slackware-security] rsync update (SSA:2004-124-01) Slackware Security Team
[slackware-security] xine-lib update (SSA:2004-124-03) Slackware Security Team
[slackware-security] sysklogd update (SSA:2004-124-02) Slackware Security Team
Re: After Ms patches last Wed ... James Riden
[slackware-security] libpng update (SSA:2004-124-04) Slackware Security Team

Tuesday, 04 May

Re: After Ms patches last Wed ... Nicholas Weaver
RE: New LSASS-based worm finally here (Sasser) Marc Maiffret
[product-security () apple com: APPLE-SA-2004-05-03 Security Update 2004-05-03] David Ahmad
Re: [Full-Disclosure] Re: New LSASS-based worm finally here (Sasser) Javier Fernandez-Sanguino
Re: [Full-Disclosure] Re: New LSASS-based worm finally here (Sasser) Jason
RE: After Ms patches last Wed ... Nick FitzGerald
@stake: AppleFileServer Remote Command Execution @stake Advisories
SUSE Security Announcement: kernel (SuSE-SA:2004:010) Roman Drahtmueller
Sasser worm and Embedded Support Partner (ESP) port 5554/tcp SGI Security Coordinator

Wednesday, 05 May

Re: Crystal Reports Vulnerabilities Michael Ray
RE: Crystal Reports Vulnerabilities Imperva Application Defense Center
remote root exec vulnerability in omail Thijs Dalhuijsen
Re: (HOAX) Dameware Mini Remote Control Version 4.2 ? Weak Key Agreement Scheme DameWare Support
Vulnerabilities In PHPX 3.26 And Earlier JeiAr
[slackware-security] lha update in bin package (SSA:2004-125-01) Slackware Security Team
UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : apache multiple vulnerabilities, upgraded to apache-1.3.29 please_reply_to_security
SMF SIZE Tag Script Injection Vulnerability Cheng Peng Su
Corsaire Security Advisory - Verity Ultraseek path disclosure issue advisories
Fuse Talk Vunerabilities Stuart Jamieson
[OpenPKG-SA-2004.019] OpenPKG Security Advisory (kolab) OpenPKG
Titan FTP Server Aborted LIST DoS Aviram Jenik
[waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2] Janek Vind
IRIX Networking Security Updates SGI Security Coordinator
Multiple vulnerabilities in P4DB Jon McClintock
FreeBSD Security Advisory FreeBSD-SA-04:08.heimdal FreeBSD Security Advisories
FreeBSD Security Advisory FreeBSD-SA-04:09.kadmind FreeBSD Security Advisories

Thursday, 06 May

[AppSecInc Security Alert] Microsoft Active Server Pages Cookie Retrieval Issue Aaron C. Newman (Application Security, Inc.)
Advisory: Heimdal kadmind version4 remote heap overflow Evgeny Demidov
[0xbadc0ded #03] DeleGate (SSL-filter) <= 8.9.2 Joel Eriksson
SUSE Security Announcement: Live CD 9.1 (SuSE-SA:2004:011) Roman Drahtmueller

Friday, 07 May

Will a smart worm be made in the near future? Taeho Oh
Fwd: [Re: cvs commit: src/sys/vm vm_map.c] Jacques A. Vidrine
Security issue with Trend OfficeScan Corporate Edition Matt
[SECURITY] [DSA 501-1] New exim packages fix buffer overflows Martin Schulze
Remote DoS IE Memory Access Violation E.Kellinis
Windows IPSec Vulnerabilty Steffen Pfendtner
Re: Titan FTP Server Aborted LIST DoS Gene Ken
Eudora file URL buffer overflow Paul Szabo
[CLA-2004:840] Conectiva Security Announcement - lha Conectiva Updates
Re: Titan FTP Server Aborted LIST DoS Noam Rathaus
Re: Will a smart worm be made in the near future? Jose Nazario
Streaming Video and Audio security lists

Saturday, 08 May

[OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp) OpenPKG
FW: [security bulletin] SSRT4717 Management Agents for HP-UX Remote DoS Boren, Rich (SSRT)
[FLSA-2004:1395] Updated OpenSSL resolves security vulnerability Jesse Keating
Status bar exploit hides spoofed URLs Eudora, possibly other e-mail clients Brett Glass
[waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke] Janek Vind

Monday, 10 May

[ GLSA 200405-01 ] Multiple format string vulnerabilities in neon 0.24.4 and earlier Kurt Lieber
PaX DoS proof-of-concept Michel Blomgren
OUTLOOK 2003: OuchLook http-equiv () excite com
a litle bypass with IE Nuno Costa
[ GLSA 200405-02 ] Multiple vulnerabilities in LHa Thierry Carrez
Monit 4.1 remote shell exploit (HTTP) Michel Blomgren
RE: An undetectable Online Bank Vulnerability? M Peterson
Arbitrary code inclusion in phpShop Calum Power
Emule 0.42e Remote Denial Of Service Exploit Rafel Ivgi, The-Insider
Re: a litle bypass with IE Neil Briscoe
msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh Rafel Ivgi, The-Insider
RE: a litle bypass with IE Eric Norbut
[Ulf Harnhammar]: LHA Advisory + Patch David Ahmad
DEEP SEA PHISHING: Internet Explorer / Outlook Express http-equiv () excite com

Tuesday, 11 May

PING: Outlook 2003 Spam http-equiv () excite com
Somebody exploiting (badly designed) yahoo service? Aleksandar Milivojevic
RE: a litle bypass with IE Thor Larholm
MDKSA-2004:042 - Updated rsync packages fixes potential to write outside of directory tree. Mandrake Linux Security Team
[SECURITY] [DSA 502-1] New exim-tls packages fix buffer overflows Martin Schulze
Re: Somebody exploiting (badly designed) yahoo service? Charles Mansmann
MDKSA-2004:043 - Updated apache2 packages fixes a denial of service vulnerability in mod_ssl Mandrake Linux Security Team
Linux Kernel sctp_setsockopt() Integer Overflow Shaun Colley
Re: NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP Florian Weimer
Re: a litle bypass with IE Emilio Casbas
[ GLSA 200405-04 ] OpenOffice.org vulnerability when using DAV servers Thierry Carrez
[ GLSA 200405-03 ] ClamAV VirusEvent parameter vulnerability Thierry Carrez
Advisory 04/2004: Net(Free)BSD Systrace local root vulnerabilitiy Stefan Esser
Hiding URLs from Outlook and other mail clients Carl
OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol please_reply_to_security

Wednesday, 12 May

Re: [Full-Disclosure] Linux Kernel sctp_setsockopt() Integer Overflow Tom Rini
MS04-015 - Windows Help Center - Dvdupgrade morning_wood
[OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache) OpenPKG
Re: msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh Gao Rui
Re: Somebody exploiting (badly designed) yahoo service? Nick FitzGerald
Re: NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP Bob Beck
surfboard1.1.6 local exploit. Anonymous
NetBSD Security Advisory 2004-007: Systrace systrace_exit() local root NetBSD Security-Officer

Thursday, 13 May

EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow Marc Maiffret
Re: NISCC Vulnerability Advisory 236929: Vulnerability Issues in TCP Darren Reed
EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service Marc Maiffret
EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow Marc Maiffret
EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption Marc Maiffret
Showhelp() local CHM file execution roozbeh afrasiabi
Re: surfboard1.1.6 local exploit. Meredydd
[ GLSA 200405-05 ] Utempter symlink vulnerability Kurt Lieber
[SECURITY] [DSA 503-1] New mah-jong packages fix denial of service Martin Schulze
[slackware-security] apache (SSA:2004-133-01) Slackware Security Team
Opera Telnet URI Handler Vulnerability also applies to other browsers Jannes
SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues Sym Security
[security bulletin] SSRT4722 rev.0 HP-UX Mozilla denial of service Boren, Rich (SSRT)
POA: Outlook Expresss 6.00 http-equiv () excite com

Friday, 14 May

IE URL Issue Being Used In Phishing In the Wild [USBank] Drew Copley
Vulnerability Scanning on Windows 2003 localhost will crash RPC farking
[security bulletin] SSRT4721 rev.0 HP-UX dtlogin unauthorized privileged access, DoS Boren, Rich (SSRT)
SUSE Security Announcement: mc (SuSE-SA:2004:012) Thomas Biege
Re: Showhelp() local CHM file execution roozbeh afrasiabi
DOE updated cybersecurity //no code or 0day sploits// just info System Administrator
Curious fileutils/coreutils behaviour. David Malone
TSLSA-2004-0027 - apache Trustix Security Advisor
Still Vulnerable in MSIE Greg Kujawa
[security bulletin] SSRT3613 rev.0 HP-UX B6848AB GTK+ Support Libraries - elevated privileges Boren, Rich (SSRT)
RE: Vulnerability Scanning on Windows 2003 localhost will crash RPC Drew Copley
Symantec Multiple Firewall DNS Response Denial-of-Service Exploit (PoC) houseofdabus HOD
TSLSA-2004-0029 - kernel Trustix Security Advisor
RE: IE URL Issue Being Used In Phishing In the Wild [USBank] Drew Copley
RE: Curious fileutils/coreutils behaviour. Michael Wojcik
Re: Curious fileutils/coreutils behaviour. David Malone
Re: IE URL Issue Being Used In Phishing In the Wild [USBank] Todd C. Campbell
Re: Curious fileutils/coreutils behaviour. Nicolas Rachinsky
[ GLSA 200405-07 ] Exim verify=header_syntax buffer overflow Thierry Carrez

Saturday, 15 May

[ GLSA 200405-06 ] libpng denial of service vulnerability Thierry Carrez
RE: Still Vulnerable in MSIE Thor Larholm
Denial of Service Vulnerability in IEEE 802.11 Wireless Devices albatross
Re: Curious fileutils/coreutils behaviour. Michael Shigorin
Re: Curious fileutils/coreutils behaviour. Luciano Miguel Ferreira Rocha
lha buffer overflow(s) again lw
more simple and flexible WinBlox(GET CONTROL OF WINNT SYSTEM) Liu Die Yu
Re: IE URL Issue Being Used In Phishing In the Wild [USBank] Nick FitzGerald
Re: Curious fileutils/coreutils behaviour. Martin
CiSCO IOS 12.* source code stolen Alexander Antipo
Re: Linux Kernel sctp_setsockopt() Integer Overflow Michael Tokarev
Re: Denial of Service Vulnerability in IEEE 802.11 Wireless Devices Casper Dik

Monday, 17 May

Re[2]: Denial of Service Vulnerability in IEEE 802.11 Wireless Devices Jason Ostrom
Wget race condition vulnerability Vázquez
WebCT: Cross Site Scripting Vulnerability spiffomatic 64
Multiple TTT-C XSS vulnerabilities Kaloyan Georgiev
[slackware-security] mc (SSA:2004-136-01) Slackware Security Team
KDE Security Advisory: URI Handler Vulnerabilities Waldo Bastian
NetChat HTTP Server Stack Overflow dbd
Safari remote arbitrary code execution kang
RE: Remote Buffer Overflow in MailEnable HTTPMail MailEnable Sales
Re: Denial of Service Vulnerability in IEEE 802.11 Wireless Devices Niels Bakker
Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Kurczaba Associates advisories
[waraxe-2004-SA#029 - Possible remote file inclusion in PhpNuke 6.x - 7.3] Janek Vind
oscommerce 2.2 file_manager.php file browsing Rene
RE: Still Vulnerable in MSIE Drew Copley
RE: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Drew Copley
[waraxe-2004-SA#030 - Multiple vulnerabilities in PhpNuke 6.x - 7.3] Janek Vind
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability thegeekmeister
Desktop.ini flaw results in executing folders roozbeh afrasiabi
ROCKET SCIENCE: Outllook 2003 http-equiv () excite com
Re: Safari remote arbitrary code execution Adam Shostack
Buffer Overflow in ActivePerl ? Oliver () greyhat de
MDKSA-2004:044 - Updated libuser packages fix vulnerability Mandrake Linux Security Team
MDKSA-2004:045 - Updated passwd packages fix vulnerabilities Mandrake Linux Security Team
MDKSA-2004:046 - Updated apache packages fix a number of vulnerabilities Mandrake Linux Security Team

Tuesday, 18 May

Re: Buffer Overflow in ActivePerl ? rich . sf
Advisory 05/2004: phpMyFAQ local file inclusion vulnerability Stefan Esser
[slackware-security] kdelibs (SSA:2004-238-01) Slackware Security Team
Zen Cart login.php SQL Injection Vulnerability Oliver Minack
[SECURITY] [DSA 504-1] New heimdal packages fix potential buffer overflow Martin Schulze
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Jan Kluka
Re: Buffer Overflow in ActivePerl? Axel Beckert
IRIX 6.5.24 rpc.mountd infinte loop SGI Security Coordinator
RE: [Full-Disclosure] Re: Buffer Overflow in ActivePerl ? Bill Royds
Overflow@OmniHTTPd Han_B
Vapid Labs Security Advisory for PrimeBase Database 4.2 (update) Larry W. Cashdollar
Unknown IE bug with css-styles henkie_is_leet
Re: Buffer Overflow in ActivePerl ? Nick FitzGerald
[ GLSA 200405-08 ] Pound format string vulnerability Thierry Carrez
MDKSA-2004:047 - Updated kdelibs packages fix URI handling vulnerabilities Mandrake Linux Security Team
Re: Buffer Overflow in ActivePerl ? noderat
Re: Unknown IE bug with css-styles Paolo Mattiangeli
Re: Buffer Overflow in ActivePerl ? Josh Tolley
RE: Buffer Overflow in ActivePerl ? Drew Copley

Wednesday, 19 May

[FLSA-2004:1546] Updated utempter resolves security vulnerability -- Reissue: updated 8.0 version numbers Jesse Keating
[ GLSA 200405-09 ] ProFTPD Access Control List bypass vulnerability Kurt Lieber
Advisory 06/2004: libneon date parsing vulnerability Stefan Esser
Advisory 07/2004: CVS remote vulnerability Stefan Esser
FreeBSD Security Advisory FreeBSD-SA-04:10.cvs FreeBSD Security Advisories
[SECURITY] [DSA 506-1] New neon packages fix buffer overflow Martin Schulze
[SECURITY] [DSA 505-1] New cvs packages fix remote exploit Martin Schulze
A new Sanctum paper: "Blind XPath Injection" Amit Klein
SUSE Security Announcement: cvs (SuSE-SA:2004:013) Sebastian Krahmer
Advisory 08/2004: Subversion remote vulnerability Stefan Esser
Idea for proactive worm protection Peter Surda
Non-logged Brute Force Attack Vulnerability for Fantastico-Created Databases on cPanel Based Hosts Michael Curtis
[SECURITY] [DSA 507-1] New cadaver packages fix buffer overflow Martin Schulze
Re: Buffer Overflow in ActivePerl ? David Cantrell
Re: Buffer Overflow in ActivePerl ? David Ahmad
[ GLSA 200405-10 ] Icecast denial of service vulnerability Thierry Carrez
Reporting a Security Vulnerability in a Microsoft Product Microsoft Security Response Center
MDKSA-2004:048 - Updated cvs packages fix remotely exploitable vulnerability Mandrake Linux Security Team
[ GLSA 200405-11 ] KDE URI Handler Vulnerabilities Thierry Carrez
MDKSA-2004:049 - Updated libneon packages fix heap variable overflow issues Mandrake Linux Security Team
[OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion) OpenPKG
[OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs) OpenPKG
[OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon) OpenPKG

Thursday, 20 May

SGI ProPack v2.4: Kernel Update #4 - Security and other fixes SGI Security Coordinator
[slackware-security] cvs (SSA:2004-140-01) Slackware Security Team
SGI ProPack 3: Kernel Update #1 - Security and other fixes SGI Security Coordinator
[security bulletin] SSRT4696 rev. 0 HP ProCurve Routing Switches TCP Denial of Service (DoS) Boren, Rich (SSRT)
[ GLSA 200405-14 ] Buffer overflow in Subversion Joshua J. Berry
[ GLSA 200405-13 ] neon heap-based buffer overflow Thierry Carrez
[ GLSA 200405-12 ] CVS heap overflow vulnerability Thierry Carrez
[ GLSA 200405-15 ] cadaver heap-based buffer overflow Thierry Carrez
Question About Ethics and Full Disclosure Tom
Auditor security collection released - a swiss army knife for security assessments. Max
Internet explorer .clsid vulnerability roozbeh afrasiabi
RE: Question About Ethics and Full Disclosure Drew Copley
Re: Question About Ethics and Full Disclosure T.J.
RE: Question About Ethics and Full Disclosure Kevin E. Casey

Friday, 21 May

[SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability snsadv
RE: Internet explorer .clsid vulnerability Thor Larholm
Stupid Phishing Tricks http-equiv () excite com
Re: Question About Ethics and Full Disclosure Michal Zalewski
Re: Non-logged Brute Force Attack Vulnerability forFantastico-Created Databases on cPanel Based Hosts Michael Curtis
e107 web portal Referers HTTP Injection Chinchilla
MDKSA-2004:046-1 - apache-mod_perl packages are now available Mandrake Linux Security Team
[OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync) OpenPKG
Eudora 6.1.1 attachment spoof, LaunchProtect Paul Szabo
[ GLSA 200405-16 ] Multiple XSS Vulnerabilities in SquirrelMail Rajiv Aaron Manglani
Re: Non-logged Brute Force Attack Vulnerability for Fantastico-Created Databases on cPanel Based Hosts Kenneth Peiruza

Saturday, 22 May

BNBT BitTorrent Tracker Denial Of Service badpack3t
Re: Internet explorer .clsid vulnerability roozbeh afrasiabi
Exploit codes for CVS Vulnerability and snort rules from ISC K-OTiK Security
Allegro RomPager/2.10 DoS exploit Seth Alan Woolley
MDKSA-2004:050 - Updated kernel packages fix multiple vulnerabilities Mandrake Linux Security Team
Liferay Cross Site Scripting Flaw Giri, Sandeep

Monday, 24 May

e107 web portal user.php XSS (Cross Site Scripting) Chris Norton
[SECURITY] [DSA 508-1] New xpcd packages fix buffer overflow Matt Zimmerman
Netgear RP114 URL filter fails if URL is too long Marc Ruef
[ GLSA 200405-18 ] Buffer Overflow in Firebird Thierry Carrez
cPanel mod_phpsuexec Vulnerability Rob Brown

Tuesday, 25 May

[ GLSA 200405-19 ] Opera telnet URI handler file creation/truncation vulnerability Kurt Lieber
SSH URI handler remote arbitrary code execution kang
[CLA-2004:841] Conectiva Security Announcement - libneon Conectiva Updates
ERRATA: [ GLSA 200405-16 ] Multiple XSS Vulnerabilities in SquirrelMail Kurt Lieber
[CLA-2004:842] Conectiva Security Announcement - mailman Conectiva Updates
[ GLSA 200405-20 ] Insecure Temporary File Creation In MySQL Thierry Carrez

Wednesday, 26 May

[security bulletin] SSRT4749 HP-UX Java Runtime Environment (JRE) remote DoS Boren, Rich (SSRT)
FreeBSD Security Advisory FreeBSD-SA-04:11.msync FreeBSD Security Advisories
SUSE Security Announcement: kdelibs (SuSE-SA:2004:014) Sebastian Krahmer
[security bulletin] SSRT4719 hp OpenView Select Access remote unauthorized access Boren, Rich (SSRT)
IEBUG: Archives of Internet Explorer Liu Die Yu
[Full-Disclosure] iDEFENSE Security Advisory 05.26.04: 3Com OfficeConnect Remote 812 ADSL Router Telnet Protocol Denial of Service Vulnerability idlabs-advisories
[ GLSA 200405-21 ] Midnight Commander: Multiple vulnerabilities Kurt Lieber
IRIX libcpr vulnerability SGI Security Coordinator
[ GLSA 200405-22 ] Apache 1.3: Multiple vulnerabilities Kurt Lieber
[security bulletin]SSRT4724 HP integrated Lights Out (iLO) Denial of Service (DoS) using port zero Boren, Rich (SSRT)
Orenosv HTTP/FTP Server Denial Of Service badpack3t
Re: IRIX libcpr vulnerability Jan Schaumann
[CLA-2004:843] Conectiva Security Announcement - kde Conectiva Updates
Re: [ GLSA 200405-18 ] Buffer Overflow in Firebird b0f www . b0f . net
SGI Advanced Linux Environment 3 Security Update #1 SGI Security Coordinator
DoS in MiniShare 1.3.2 Donato Ferrante

Thursday, 27 May

[OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache) OpenPKG
[ GLSA 200405-23 ] Heimdal: Kerberos 4 buffer overflow in kadmin Kurt Lieber
The Dangers of Cross-Site-Scripting: Rogers Hi-Speed Internet Network [Canada] http-equiv () excite com
Re: [ GLSA 200405-18 ] Buffer Overflow in Firebird KF (lists)
Re: [ GLSA 200405-18 ] Buffer Overflow in Firebird KF (lists)
Re: Exchange pop3 remote exploit Tal Schaeffer
MDKSA-2004:051 - Updated mailman packages fix password retrieval vulnerability Mandrake Linux Security Team
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability sandrijeski
Sun-Java-App-Server PE 8.0 path disclosure Marc Schoenefeld
WildTangent Web Driver Long FileName Stack Overflow NGSSoftware Insight Security Research
MDKSA-2004:052 - Updated kolab-server package fixes world readable file vulnerability Mandrake Linux Security Team
[PHP] include() bypassing filter with php://input Himeur Nourredine
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability http-equiv () excite com

Friday, 28 May

Re: [PHP] include() bypassing filter with php://input Keary Suska
Re: Linux Kernel sctp_setsockopt() Integer Overflow Michael Tokarev
Re: [Full-Disclosure] iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability Seth Alan Woolley
[ GLSA 200405-24 ] MPlayer, xine-lib: vulnerabilities in RTSP stream handling Thierry Carrez
SGI Advanced Linux Environment security update #20 SGI Security Coordinator
SGI Advanced Linux Environment 3 Security Update #2 SGI Security Coordinator
JPortal SQL Injects Maciek Wierciski
Re: WildTangent Web Driver Long FileName Stack Overflow Cesar
Re: [PHP] include() bypassing filter with php://input clez
Mollensoft ftp Server ver 3.6 Buffer overflow Chintan Trivedi

Saturday, 29 May

EnderUNIX Security Anouncement (Isoqlog and Spamguard) Murat Balaban
LDU (land down under) xss vulnerability tim de gier
[waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615] Janek Vind
[SECURITY] [DSA 509-1] New gatos packages fix privilege escalation Matt Zimmerman
[SECURITY] [DSA 510-1] New jftpgw packages fix format string vulnerability Matt Zimmerman
[Full-Disclosure] iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability idlabs-advisories

Monday, 31 May

[ GLSA 200405-25 ] tla: Heap-based buffer overflow in included libneon Thierry Carrez
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Robert J Taylor
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Valdis . Kletnieks
Users who have expired passwords can still log on to the domain if the FQDN is exactly eight characters long in Windows 2000 albatross
Re: Microsoft Internet Explorer ImageMap URL Spoof Vulnerability Peter Pentchev
Looking for a security contact of RealNetworks Live Rhapsody Philip Stoev
[SECURITY] [DSA 511-1] New ethereal packages fix buffer overflows Matt Zimmerman
Re: Linux Kernel sctp_setsockopt() Integer Overflow Jirka Kosina
Re: [PHP] include() bypassing filter with php://input Ali Campbell
Re: [PHP] include() bypassing filter with php://input bugtraq subscriber
Possible bug in PHPNuke and other CMS Luca Falavigna
Re: Linux Kernel sctp_setsockopt() Integer Overflow Shaun Colley
LinkSys WRT54G administration page availble to WAN Alan W. Rateliff, II