Vulnwatch: by date

95 messages starting Jan 01 06 and ending Mar 29 06
Date index | Thread index | Author index


Sunday, 01 January

[xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities XFOCUS Security Team

Thursday, 05 January

RE: Download Accelerator Plus can be tricked to download malicious file NaPa
iDefense Security Advisory 01.05.06: Blue Coat WinProxy Remote DoS Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 01.05.06: Blue Coat Systems WinProxy Host Header Stack Overflow Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 01.05.06: Blue Coat WinProxy Telnet DoS Vulnerability labs-no-reply () idefense com

Monday, 09 January

iDefense Security Advisory 01.09.06: Multiple Vendor mod_auth_pgsql Format String Vulnerability labs-no-reply () idefense com

Tuesday, 10 January

iDefense Security Advisory 01.10.06: Sun Solaris uustat Buffer Overflow Vulnerability labs-no-reply () idefense com
[EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability Advisories

Wednesday, 11 January

Microsoft Exchange Critical Vulnerability NGSSoftware Insight Security Research
Microsoft Outlook Critical Vulnerability NGSSoftware Insight Security Research
Cisco Security Advisory: Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS) Cisco Systems Product Security Incident Response Team
[EEYEB-20051220] Apple QuickTime QTIF Stack Overflow Advisories
[EEYEB-20051117B] Apple iTunes (QuickTime.qts) Heap Overflow Advisories
[EEYEB-20051117A] Apple QuickTime STSD Atom Heap Overflow Advisories
[EEYEB-20051031] Apple QuickTime Malformed GIF Heap Overflow Advisories
Updated Advisories - Incorrect CVE Information Advisories
Critical excel vulnerability for sale, read inside. ad () heapoverflow com

Thursday, 12 January

Cisco Security Advisory: Access Point Memory Exhaustion from ARP Attacks Cisco Systems Product Security Incident Response Team
Fortinet Advisory - Apple QuickTime Player StripByteCounts Buffer Overflow Vulnerability Fortinet Research
Fortinet Advisory - Apple QuickTime Player StripOffsets Improper Memory Acces Fortinet Research
Fortinet Advisory: Apple Quick Time Player ImageWidth Denial of Service Vulnerability Fortinet Research
Fortinet Security Advisory: "Apple QuickTime Player Improper Memory Access Vulnerability" Fortinet Research

Friday, 13 January

Fortinet Advisory: "Apple QuickTime Player ImageWidth Integer Overflow Vulnerability" Fortinet Research
Fortinet Advisory: Apple QuickTime Player Color Map Entry Size Buffer Overflow Fortinet Research
iDefense Security Advisory 01.13.06: Novell SUSE Linux Enterprise Server Remote Manager Heap Overflow labs-no-reply () idefense com

Tuesday, 17 January

[ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess() Thierry Zoller
iDefense Security Advisory 01.17.06: Cisco Systems IOS 11 Web Service CDP Status Page Code Injection Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrd.exe Heap Overflow Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrexecd.exe Heap Overflow Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 01.17.06: EMC Legato Networker nsrd.exe DoS Vulnerability labs-no-reply () idefense com

Wednesday, 18 January

Cisco Security Advisory: Cisco Call Manager Privilege Escalation Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Call Manager Denial of Service Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: IOS Stack Group Bidding Protocol Crafted Packet DoS Cisco Systems Product Security Incident Response Team
Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability Fortinet Research

Monday, 23 January

fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321) ma+nomail
iDefense Security Advisory 01.23.06: Computer Associates iTechnology iGateway Service Content-Length Buffer Overflow Vulnerability labs-no-reply () idefense com

Thursday, 26 January

Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Cisco Systems Product Security Incident Response Team
[Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT} Cesar

Monday, 30 January

Digital Armaments: Apache auth_ldap module Multiple Format Strings Vulnerability Digital Armaments

Tuesday, 31 January

Re: Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Eldon Sprickerhoff

Wednesday, 01 February

Re: Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack Mike Iglesias
iDefense Security Advisory 02.01.06: Winamp m3u/pls .WMA Extension Buffer Overflow Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.01.06: Winamp m3u Parsing Stack Overflow Vulnerability labs-no-reply () idefense com

Monday, 06 February

[xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability XFOCUS Security Team

Tuesday, 07 February

[ Secuobs - Advisory ] Bluetooth : DoS on Sony/Ericsson cell phones Research Infratech
[ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC Research Infratech
[ Secuobs - Tools release ] BSS (Bluetooth Stack Smasher) fuzzer Research Infratech
Re: [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability XFOCUS Security Team
Digital Armaments: CMU SNMP utilities snmptrad Format String Vulnerability Digital Armaments
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phfont Race Condition Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phgrafx Command Buffer Overflow labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS su Command Buffer Overflow labs-no-reply () idefense com

Wednesday, 08 February

iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 Local Denial of Service Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS passwd Command Buffer Overflow labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS fontsleuth Command Format String Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability labs-no-reply () idefense com

Friday, 10 February

iDEFENSE Security Advisory 02.10.06: IBM Lotus Domino Server LDAP DoS Vulnerability labs-no-reply () idefense com
[ Secuobs - Advisory ] Bluetooth : DoS on Nokia cell phones Infratech Research

Saturday, 11 February

RS-2006-1: Multiple flaws in VHCS 2.x Roman Medina-Heigl Hernandez

Monday, 13 February

Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Matthew Murphy
Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Matthew Murphy

Wednesday, 15 February

iDefense Security Advisory 02.14.06: Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability labs-no-reply () idefense com
[EEYEB-20051017] Windows Media Player BMP Heap Overflow eEye Advisories
[ Secuobs - Advisory ] Another kind of DoS on Nokia cell phones Infratech Research
Cisco Security Advisory: TACACS+ Authentication Bypass in Cisco Anomaly Detection and Mitigation Products Cisco Systems Product Security Incident Response Team

Thursday, 16 February

Digital Armaments: Gallery web-based photo gallery remote file execution Digital Armaments
Password disclosure and remote access in Netcool/NeuSecure Security information management platform D.Snezhkov

Wednesday, 22 February

[INetCop Security Advisory] Global Hauri Virobot cookie exploit dong-hun you

Thursday, 23 February

zoo contains exploitable buffer overflows Jean-SĂ©bastien Guay-Leroux
NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability NSFOCUS Security Team

Friday, 24 February

iDefense Security Advisory 02.24.06: SCO Unixware Setuid ptrace Local Privilege Escalation Vulnerability labs-no-reply

Thursday, 02 March

iDefense Security Advisory 03.02.06: Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability labs-no-reply () idefense com
iDefense Security Advisory 03.02.06: Apple Mac OS X passwd Arbitrary Binary File Creation/Modification labs-no-reply () idefense com
iDefense Security Advisory 03.02.06: EMC Dantz Retrospect 7 Backup client DoS Vulnerability labs-no-reply () idefense com

Wednesday, 08 March

Remote access to NeuSecure/Netcool backend database via web interface credentials leakage D . Snezhkov

Sunday, 12 March

[INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability dong-hun you

Tuesday, 14 March

WLSI - Windows Local Shellcode Injection - Paper Cesar

Wednesday, 15 March

[xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability XFOCUS Security Team

Friday, 17 March

Milkeyway Multiple Vulnerabilities ascii
Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski
Re: Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski
Re: Remote overflow in MSIE script action handlers (mshtml.dll) Michal Zalewski
Re: Remote overflow in MSIE script action handlers (mshtml.dll) Konstantine

Tuesday, 21 March

CORE-2006-0124: Cross-Site Scripting in Verisign’s haydn.exe CGI script CORE Security Technologies Advisories

Thursday, 23 March

PasswordSafe 3.0 weak random number generator allows key recovery attack vkatalov
iDefense Security Advisory 03.23.06: RealNetworks RealPlayer and Helix Player Invalid Chunk Size Heap Overflow Vulnerability labs-no-reply
iDefense Security Advisory 03.23.05: ISS Multiple Products Local Privilege Escalation Vulnerability labs-no-reply

Tuesday, 28 March

EEYE: Temporary workaround for IE createTextRange vulnerability Steve Manzuik
FW: failure notice Ken Pfeil
Re: FW: failure notice Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]

Wednesday, 29 March

Re: FW: failure notice Michael Evanchik
[xfocus-SD-060329]MPlayer: Multiple integer overflows XFOCUS Security Team