Full Disclosure: by date

162 messages starting Feb 01 13 and ending Feb 28 13
Date index | Thread index | Author index


Friday, 01 February

[ MDVSA-2013:006 ] freetype2 security

Saturday, 02 February

Re: petition to remove Aaron Swartz prosecutor Jeffrey Walton
Re: petition to remove Aaron Swartz prosecutor Jeffrey Walton
FreeBSD 9.1 ftpd Remote Denial of Service Maksymilian Arciemowicz
[SECURITY] [DSA 2614-1] libupnp security update Yves-Alexis Perez
[SECURITY] [DSA 2615-1] libupnp4 security update Yves-Alexis Perez
[SECURITY] [DSA 2617-1] samba security update Luciano Bello
Defcon Kerala Information Security Meet 2013 Call For Papers Ajin Abraham
Multiple vulnerabilities in Flash News theme for WordPress MustLive
Armor Safe Technologies CacheTALK III Default Admin Password BugsNotHugs

Sunday, 03 February

Multiple Vulnerabilities: Nagios XI 2012R1.5b temp66 () gmail com
[SECURITY] [DSA 2616-1] nagios3 security update Jonathan Wiltshire

Monday, 04 February

[SE-2012-01] Details of issues fixed by Feb 2013 Java SE CPU Security Explorations
[IMF 2013] Call for Participation Oliver Goebel
Free Monthly Websites v2.0 - Multiple Web Vulnerabilities Vulnerability Lab
Paypal Bug Bounty #20 - Persistent Web Vulnerabilities Vulnerability Lab
Fortinet FortiMail 400 IBE - Multiple Web Vulnerabilities - full Vulnerability Lab
OSX (ML) assertion bug Gino O'Donnell

Tuesday, 05 February

Re: [SE-2012-01] Details of issues fixed by Feb 2013 Java SE CPU Security Explorations
A new Facebook Token Hijacker malware Vulncheck Security
[ MDVSA-2013:007 ] mysql security

Wednesday, 06 February

Hackito Ergo Sum 2013 - Call For Paper - HES2013 CFP Steeve BARBEAU
WirelessFiles v1.1 iPad iPhone - Multiple Web Vulnerabilities Vulnerability Lab
Microsoft Skype Shop - GiftCards Persistent Vulnerability Vulnerability Lab
[ MDVSA-2013:008 ] mysql security
Cisco Security Advisory: Cisco ATA 187 Analog Telephone Adaptor Remote Access Vulnerability Cisco Systems Product Security Incident Response Team

Thursday, 07 February

DefenseCode Security Advisory: Cisco Linksys Remote Preauth 0day Root Exploit Follow-Up DefenseCode
PayPal Bug Bounty #26 - Persistent Web Vulnerabilities Vulnerability Lab
Air Disk Wireless 1.9 iPad iPhone - Multiple Vulnerabilities Vulnerability Lab

Friday, 08 February

ifIndex overflow (Linux Kernel - net/core/dev.c) [maybe offtopic] Daniel Preussker
[SECURITY] [DSA 2618-1] ircd-hybrid security update Luciano Bello
Mathematica9.0.1 on Linux /tmp/MathLink vulnerability paul . szabo
Cybsec Advisory#2013-0208 Multiple Cross Site Request Forgery vulnerabilities in TP-LINK Admin Panel]] CYBSEC Labs
Re: [SECURITY] [DSA 2618-1] ircd-hybrid security update 303.100 () gmail com

Saturday, 09 February

[ MDVSA-2013:009 ] libssh security
George Bush's family emails, pics ransacked - and spewed online Georgi Guninski

Sunday, 10 February

[SECURITY] [DSA 2619-1] xen-qemu-dm-4.0 security update Moritz Muehlenhoff
[SECURITY] [DSA 2612-2] ircd-ratbox update Moritz Muehlenhoff
Re: ifIndex overflow (Linux Kernel - net/core/dev.c) [maybe offtopic] Daniel Corbe
New security advisories for Apache CXF Colm O hEigeartaigh
Arbitrary command execution and trivial password guessing on Brother printers auto61149890
Re: ifIndex overflow (Linux Kernel - net/core/dev.c) [maybe offtopic] Jeffrey Walton

Monday, 11 February

Atmel "secure" crypto co-processor series microprocessors (AT91SAM7XC) leaking keys, plus bonus DESFire hack Adam Laurie
Re: ifIndex overflow (Linux Kernel - net/core/dev.c) [maybe offtopic] Daniel Preussker
Huawei Mobile Partner | Permission Weakness Local Privilege Escalation YGN Ethical Hacker Group
#warning -- DICE.COM insecure passwords warning
[ MDVSA-2013:010 ] java-1.6.0-openjdk security

Tuesday, 12 February

Re: Atmel "secure" crypto co-processor series microprocessors (AT91SAM7XC) leaking keys, plus bonus DESFire hack Adam Laurie
Crafted certificate can cause network exploitable exec/dos (Siemens Business Services Trust Center Root-CA V1.1.1) -- anniversary Dirk-Willem van Gulik
Re: #warning -- DICE.COM insecure passwords Valdis . Kletnieks
Re: ifIndex overflow (Linux Kernel - net/core/dev.c) [maybe offtopic] Valdis . Kletnieks
[SECURITY] [DSA 2620-1] rails security update Florian Weimer
Re: #warning -- DICE.COM insecure passwords Tim
List Charter John Cartwright
Polycom HDX Telnet Authorization Bypass Paul Haas
Re: #warning -- DICE.COM insecure passwords Travis Biehn
Re: #warning -- DICE.COM insecure passwords Jeffrey Walton
Paypal Bug Bounty #17 - Certificate Listing/Import Persistent Web Vulnerability Vulnerability Lab
Transferable Remote v1.1 iPad iPhone - Multiple Web Vulnerabilities Vulnerability Lab
Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability Vulnerability Lab

Wednesday, 13 February

[ MDVSA-2013:011 ] samba security
[Security-news] SA-CONTRIB-2013-016 - Banckle Chat - Access bypass - Unsupported security-news
[Security-news] SA-CONTRIB-2013-015 - Manager Change for Organic Groups - Cross site scripting (XSS) security-news
CA20130213-01: Security Notice for CA ControlMinder Kotas, Kevin J
Microsoft Internet Explorer SLayoutRun Use After Free Scott Bell
Sonicwall OEM Scrutinizer v9.5.2 - Multiple Web Vulnerabilities Vulnerability Lab

Thursday, 14 February

Simple password obfuscation in Enterprise Architect Diening, Holm
[SECURITY] [DSA 2621-1] openssl security update Thijs Kinkhorst
[SECURITY] [DSA 2622-1] polarssl security update Thijs Kinkhorst
[SECURITY] [DSA 2623-1] openconnect security update Florian Weimer
[IA46] Photodex ProShow Producer v5.0.3297 ColorPickerProc() Memory Corruption Inshell Security
Empirum Password Obfuscation Design Flaw otr
Re: CFP: InfoSec Southwest 2013 Tod Beardsley

Friday, 15 February

McAfee Vulnerability in VSE and Host IPS Anonymous Remailer (austria)
SilentCircle (Encrypted VoIP auditing) - Please cooperate sc2013a
GrrCON 2013: Grand Rapids, MI - Sept 12 -13 cfp
Sonar v.3.4.1 => XSS (CWE-79) Kacper R.
[ MDVSA-2013:012 ] postgresql security
CSRF, XSS and Redirector vulnerabilities in IBM Lotus Domino MustLive
CORE-2012-1128 - SAP Netweaver Message Server Multiple Vulnerabilities CORE Security Technologies Advisories

Saturday, 16 February

Re: SilentCircle (Encrypted VoIP auditing) - Please cooperate Ali-Reza Anghaie
Apple IOS 6.1 Simple Passcode Bypass Swair Mehta
[SECURITY] [DSA 2624-1] ffmpeg security update Moritz Muehlenhoff
SI6 Networks IPv6 Toolkit v1.3 released! Fernando Gont
АВТО: Я временно отсутствую (возврат 22.02.2013) Maksim . Filenko
[IA47] Photodex ProShow Producer v5.0.3297 PXT File title Value Handling Buffer Overflow Inshell Security
[SECURITY] [DSA 2625-1] wireshark security update Moritz Muehlenhoff
Scanning the IPv6 Internet with the scan6 tool (SI6 IPv6 toolkit) Fernando Gont

Sunday, 17 February

Re: Scanning the IPv6 Internet with the scan6 tool (SI6 IPv6 toolkit) Marc Heuse
Smoke Loader C&C panel lfi and arbitrary file deletion Ian French
Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 Vulnerability Lab
USB Sharp v1.3.4 iPad iPhone - Multiple Web Vulnerabilities Vulnerability Lab

Monday, 18 February

PACK 0.0.3 - Password Analysis and Cracking Kit iphelix
[SECURITY] [DSA 2626-1] lighttpd security update Thijs Kinkhorst
[SECURITY] [DSA 2627-1] nginx security update Thijs Kinkhorst
Re: Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 Julius Kivimäki
Re: Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 Juha-Matti Laurio
Sniffing HDCP crypto keys with a $30 Bus Pirate and a broken HDMI cable Adam Laurie
Re: Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 andfarm
Re: Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 Kirils Solovjovs
[SECURITY] [DSA 2628-1] nss-pam-ldapd security update Moritz Muehlenhoff
MyFi Wireless Disk 1.2 iPad iPhone - Multiple Vulnerabilities Vulnerability Lab
Air Transfer v1.2.0 iPad iPhone - File Include Vulnerability Vulnerability Lab
XSS vulnerabilities in ZeroClipboard MustLive

Tuesday, 19 February

LACSEC 2013: 8th Network Security Event for Latin America and the Caribbean (CFP) Fernando Gont
TWiki Security Alert CVE-2013-1751: MAKETEXT Variable Has Another Shell Command Execution Issue Peter Thoeny
Paper - Hiding Data in Hard-drive Service Areas Ariel Berkman
Foswiki Security: Alert CVE-2013-1666 - Remote Code Execution Vulnerability in MAKETEXT macro. George Clark
Re: Apple iOS v6.1 (10B143) - Code Lock Bypass Vulnerability #2 Vulnerability Lab

Wednesday, 20 February

XSS vulnerabilities in YAML, Multiproject for Trac, UserCollections for Piwigo, TAO and TableTools for DataTables for jQuery MustLive
[ MDVSA-2013:013 ] squid security

Wednesday, 27 February

[SECURITY] [DSA 2632-1] linux-2.6 security update dann frazier
Cisco Security Advisory: Cisco Unified Presence Server Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Prime Central for Hosted Collaboration Solution Assurance Excessive CPU Utilization Vulnerability Cisco Systems Product Security Incident Response Team
[SECURITY] [DSA 2634-1] python-django security update Nico Golde
[SECURITY] [DSA 2633-1] fusionforge security update Yves-Alexis Perez
Gambas 3.3.4 Directory hijack vulnerability Larry W. Cashdollar
test imipak
[ MDVSA-2013:015 ] apache security
[Security-news] SA-CONTRIB-2013-024 - Creative Theme - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-026 - Best Responsive Theme - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-025 - Fresh Theme - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-027 - Professional theme - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-032 - Company theme - Cross Site Scripting (XSS) security-news
[Security-news] SA-CONTRIB-2013-030 - Clean Theme - Cross Site Scripting (XSS) security-news
[CTF] nullcon Battle UnderGround 2013 will start at 01-03-2013, when the clock will strike at 10:00 am (IST) nullcon
Archlinux/x86-64 3.1.x-3.7.x x86-64 CVE-2013-1763 sock_diag_handlers[] warez sd
DC4420 - London DEFCON Tuesday 26th Feb 2013 Major Malfunction
NoSuchCon CFP 2.0 / 15-17 May 2013 / Paris, France Jonathan Brossard
Hacking Xerox MFP Firmware Patch Process - percX at foofus.net dh
user data collection taxakis
Re: user data collection Valdis . Kletnieks
Re: test coderman
Re: test Jeffrey Walton
Cisco 3560 DoS BugsNotHugs

Thursday, 28 February

[SE-2012-01] New security issues affecting Oracle's Java SE 7u15 (updated) Security Explorations
44CON 12th - 13th September London 2013 Call For Papers/Workshops Steve
Re: MySQL Denial of Service Zeroday PoC Sergei Golubchik
Advisory Notification Raffaele Addesso
[ MDVSA-2013:016 ] php security
TeamSHATTER Security Advisory: SQL Injection in Oracle Alter FBA Table (CVE-2012-1751) Shatter
[CTF] nullcon Battle UnderGround 2013 will start at 01-03-2013, when the clock will strike at 10:00 am (IST) nullcon
Fileutils ruby gem possible remote command execution and insecure file handling in /tmp Larry W. Cashdollar
TeamSHATTER Security Advisory: Oracle 11g Stealth Password Cracking Vulnerability (CVE-2012-3137) Shatter
TeamSHATTER Security Advisory: Oracle EM Cross Site Scripting in XDBResource cancelURL parameter (CVE-2013-0352) Shatter
TeamSHATTER Security Advisory: Oracle Database GeoRaster API overflow (CVE-2012-3220) Shatter
TeamSHATTER Security Advisory: HTTP Response Splitting in Oracle EM (policyViewSettings) (CVE-2013-0354) Shatter
TeamSHATTER Security Advisory: SQL Injection in Oracle EM (advReplicationAdmin) (CVE-2013-0372) Shatter
TeamSHATTER Security Advisory: SQL Injection in Oracle EM (dBClone) (CVE-2013-0374) Shatter
TeamSHATTER Security Advisory: SQL Injection in Oracle EM (SCPLBL_COLLECTED parameters) (CVE-2013-0353) Shatter
TeamSHATTER Security Advisory: Oracle EM Segment Advisor Arbitrary URL redirection/phishing (CVE-2012-3219) Shatter
TeamSHATTER Security Advisory: SQL Injection in Oracle EM (streams queue) (CVE-2013-0373) Shatter
TeamSHATTER Security Advisory: Cross-site scripting in Oracle EM (advReplicationAdmin) (CVE-2013-0355) Shatter
TeamSHATTER Security Advisory: SQL Injection in Oracle EM (Resource Manager) (CVE-2013-0358) Shatter
[waraxe-2013-SA#097] - Multiple Vulnerabilities in PHP-Fusion 7.02.05 Janek Vind
Re: test Hey, Lukas (KRZ)
ROOTCON 7 Call for Papers JJ Turla
Re: Arbitrary command execution and trivial password guessing on Brother printers auto61149890
Re: Arbitrary command execution and trivial password guessing on Brother printers Jeffrey Walton
Oracle Auto Service Request /tmp file clobbering vulnerability Larry W. Cashdollar
[CTF] nullcon Battle UnderGround is On nullcon
list patch Jan van Niekerk