The bugtraq list thread archive for Feb-05
- Badblue HTTP Server Exploit,
Miguel Tarascó Acuña
- Firefox Software Update,
Kai Howells
- [SECURITYREASON.COM] PostNuke Critical SQL Injection 0.760-RC2=>x cXIb8O3.1,
Maksymilian Arciemowicz
- [SECURITYREASON.COM] PostNuke Critical XSS 0.760-RC2=>x cXIb8O3.2,
Maksymilian Arciemowicz
- [SECURITYREASON.COM] PostNuke SQL Injection 0.760-RC2=>x cXIb8O3.3,
Maksymilian Arciemowicz
- [Hat-Squad] GFI L.N.S.S 5.0 Insecure Credential Storage,
Hat-Squad Security Team
- iDEFENSE Security Advisory 02.28.05: KPPP Privileged File Descriptor Leak Vulnerability,
iDEFENSE Labs
- iDEFENSE Security Advisory 02.28.05: Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error,
iDEFENSE Labs
- WASC-Articles: 'The Insecure Indexing Vulnerability - Attacks Against Local Search Engines' By Amit Klein,
robert
- 7a69Adv#22 - UNIX unzip keep setuid and setgid files,
Albert Puigsech Galicia
- [ GLSA 200502-30 ] cmd5checkpw: Local password leak vulnerability,
Thierry Carrez
- Mozilla Firefox 1.0.1 Javascript Images are Draggable,
Paul
- Re: Office 10 applications & flashdrives can be used to browse restricted drives,
Paul
- Knet <= 1.04c Buffer Overflow Bug,
CorryL
- -==phpBB 2.0.12 Full path disclosure==-,
HaCkZaTaN
- CIS WebServer Directory Traversal Bug,
CorryL
- iDEFENSE Security Advisory 02.25.05: WU-FTPD File Globbing Denial of Service Vulnerability,
iDEFENSE Labs
- [USN-85-1] Gaim vulnerabilities,
Martin Pitt
- [FLSA-2005:2336] Updated kernel packages fix security issues,
Marc Deslauriers
- AW: phpWebSite-0.10.0_exploit,
webmaster
- CFP: WORM 2005,
David Moore
- Announce: RSBAC v1.2.4 released,
Amon Ott
- [SECURITY] [DSA 690-1] New bsmtpd packages fix arbitrary command execution,
Martin Schulze
- Firescrolling [Firefox 1.0],
mikx
- phpWebSite 0.10.0 Full Path disclosure,
HaCkZaTaN.
- [FLSA-2005:2005] Updated gdk-pixbuf packages fix security flaws,
Marc Deslauriers
- [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4,
Maksymilian Arciemowicz
- [FLSA-2005:2343] Updated vim packages fix security issues,
Marc Deslauriers
- phpWebSite-0.10.0_exploit,
tjomka
- [FLSA-2005:2043] Updated zlib package fixes security issues,
Marc Deslauriers
- MDKSA-2005:047 - Updated squid packages fix vulnerability,
Mandrakelinux Security Team
- MDKSA-2005:046 - Updated uim packages fix vulnerability,
Mandrakelinux Security Team
- Multiple vulns in punBB,
John Gumbel
- In-game cl_guid crash in Soldier of Fortune II 1.03,
Luigi Auriemma
- [Security Bulletin] SSRT4694 HP-UX ftpd remote unauthorized access,
Boren, Rich (SSRT)
- Cisco Security Advisory: ACNS Denial of Service and Default Admin Password Vulnerabilities,
Cisco Systems Product Security Incident Response Team
- iDEFENSE Security Advisory 02.23.05: Sun Solaris kcms_configure Arbitrary File Corruption Vulnerability,
iDEFENSE Labs
- RE: Avaya IP Office Phone Manager - Sensitive Information Cleartext Vulnerability,
Walton, John Michael (John)
- Multiple vulnerabilities found in CSGuestbook by CoolSerlets.com,
Josh884
- Office 10 applications & flashdrives can be used to browse restricted drives,
Discini, Sonny
- [Fwd: [arkeia-announce] Release of Arkeia Network Backup 5.3.5 fixes security issue],
Maciej Bogucki
- Release of Arkeia Network Backup 5.3.5 fixes security issue [bugtraq id 12594],
Arnaud Spicht
- Robustness patch for TWiki, vulnerability in ImageGalleryPlugin,
Florian Weimer
- [ GLSA 200502-29 ] Cyrus IMAP Server: Multiple overflow vulnerabilities,
Matthias Geerdsen
- Incorrect Classification of iDownload's Product as Spyware...,
Paul Laudanski
- [SECURITY] [DSA 689-1] New mod_python packages fix information leak,
Martin Schulze
- [SECURITY] [DSA 688-1] New squid packages fix denial of service,
Martin Schulze
- Software PBLang 4.65 pm.php XSS vulnerability,
Raven
- Software PBLang 4.65 pmpshow.php XSS vulnerability,
Raven
- Software PBLang 4.65 search.php XSS vulnerability,
Raven
- iDEFENSE Security Advisory 02.22.05: phpBB Group phpBB2 Arbitrary File Unlink Vulnerability,
iDEFENSE Labs
- Cross Site Scripting exploitation via malformed files,
Jerome ATHIAS
- paNews v2.0b4 - PHP Injection,
tjomka
- [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection,
pokley
- The WebConnect 6.4.4 and 6.5 contains several vulnerabilities,
CIRT Advisory
- [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure & Possible SQL Injection,
John Cobb
- SD Server 4.0.70 Directory Traversal Bug,
CorryL