| Subject | Author | Date |
| [Full-disclosure] 0day analysis of the challenges |
| | yuange | 07 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-01 ] wxGTK: User-assisted execution of arbitrary code |
| | Alex Legler | 02 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-02 ] Maildrop: privilege escalation |
| | Pierre-Yves Rofes | 06 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-03 ] sudo: Privilege Escalation |
| | Alex Legler | 07 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-04 ] SARG: User-assisted execution of arbitrary code |
| | Stefan Behte | 07 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-05 ] Adobe Reader: Multiple vulnerabilities |
| | Stefan Behte | 07 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-06 ] Clam AntiVirus: Multiple vulnerabilities |
| | Tobias Heinlein | 07 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-07 ] libxml2: Denial of Service |
| | Stefan Behte | 21 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-08 ] python-updater: Untrusted search path |
| | Stefan Behte | 21 Sep 2010 |
| [Full-disclosure] [ GLSA 201009-09 ] fence: Multiple symlink vulnerabilites |
| | Stefan Behte | 29 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:168 ] openssl |
| | security_at_nospam | 01 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:169 ] mozilla-thunderbird |
| | security_at_nospam | 02 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:170 ] wget |
| | security_at_nospam | 02 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:171 ] lvm2 |
| | security_at_nospam | 06 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:172 ] kernel |
| | security_at_nospam | 09 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:173 ] firefox |
| | security_at_nospam | 11 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:174 ] quagga |
| | security_at_nospam | 11 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:175 ] sudo |
| | security_at_nospam | 12 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:176 ] tomcat5 |
| | Raj Mathur (राज माथुर) | 13 Sep 2010 |
| | security_at_nospam | 12 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:177 ] tomcat5 |
| | security_at_nospam | 12 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:178 ] ocsinventory |
| | security_at_nospam | 12 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:179 ] libglpng |
| | security_at_nospam | 12 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:180 ] rpm |
| | security_at_nospam | 13 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:181 ] ntop |
| | security_at_nospam | 14 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:182 ] kdegraphics |
| | security_at_nospam | 14 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:183 ] socat |
| | security_at_nospam | 15 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:184 ] samba |
| | security_at_nospam | 16 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:185 ] bzip2 |
| | security_at_nospam | 20 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:186 ] phpmyadmin |
| | security_at_nospam | 21 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:187 ] squid |
| | security_at_nospam | 22 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:188 ] kernel |
| | security_at_nospam | 23 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:189 ] pcsc-lite |
| | security_at_nospam | 24 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:189-1 ] pcsc-lite |
| | security_at_nospam | 24 Sep 2010 |
| [Full-disclosure] [ MDVSA-2010:190 ] libtiff |
| | security_at_nospam | 30 Sep 2010 |
| [Full-disclosure] [funsec] And they intend to do this securely, how, exactly? |
| | PsychoBilly | 27 Sep 2010 |
| [Full-disclosure] [GOATSE SECURITY] Clench: Goatse's way to say "screw you" to certificate authorities |
| | PsychoBilly | 10 Sep 2010 |
| | Shreyas Zare | 09 Sep 2010 |
| | Larry Seltzer | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | Tim | 08 Sep 2010 |
| | Harry Strongburg | 08 Sep 2010 |
| | Andrew Auernheimer | 08 Sep 2010 |
| | BMF | 08 Sep 2010 |
| | dvs_at_nospam | 08 Sep 2010 |
| | Dan Kaminsky | 08 Sep 2010 |
| | Tim | 08 Sep 2010 |
| | Tim | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | BMF | 08 Sep 2010 |
| | Andrew Auernheimer | 08 Sep 2010 |
| | Harry Strongburg | 08 Sep 2010 |
| | Tim | 08 Sep 2010 |
| | Andrew Auernheimer | 08 Sep 2010 |
| | Andrew Auernheimer | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | Tim | 08 Sep 2010 |
| | Andrew Auernheimer | 08 Sep 2010 |
| [Full-disclosure] [ISecAuditors Security Advisories] Insecure Direct Object Reference in tuenti.com allow to read of any message user |
| | ISecAuditors Security Advisories | 21 Sep 2010 |
| [Full-disclosure] [ISecAuditors Security Advisories] Reflected XSS in Atmail WebMail < v6.2.0 |
| | ISecAuditors Security Advisories | 21 Sep 2010 |
| [Full-disclosure] [ISecAuditors Security Advisories] SQL Injection and XSS in Motorito < v2.0 Ni 483 |
| | ISecAuditors Security Advisories | 23 Sep 2010 |
| [Full-disclosure] [New Tool Announcement] inspath - Path Disclosure Finder |
| | YGN Ethical Hacker Group | 28 Sep 2010 |
| [Full-disclosure] [Onapsis Security Advisory 2010-007] SAP Management Console Multiple Denial of Service |
| | Onapsis Research Labs | 29 Sep 2010 |
| [Full-disclosure] [RingoBingo Secuity] Wikipedia Reflected XSS (Unresponsive-Conpulsive Disclosure) |
| | ringobingo_at_nospam | 08 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2097-2] New phpmyadmin packages fix several vulnerabilities |
| | Thijs Kinkhorst | 11 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2098-2] New typo3-src packages fix regression |
| | Thijs Kinkhorst | 07 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2106-1] New xulrunner packages fix several vulnerabilities |
| | Moritz Muehlenhoff | 08 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2107-1] New couchdb package fixes arbitrary code execution |
| | Sebastien Delafond | 09 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2108-1] New cvsnt package fixes arbitrary code execution |
| | Sbastien Delafond | 14 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2110-1] New Linux 2.6.26 packages fix several issues |
| | dann frazier | 17 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2111-1] New squid3 packages fix denial of service |
| | Steffen Joeris | 19 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA 2113-1] New drupal6 packages fix several vulnerabilities |
| | Steffen Joeris | 20 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2102-1] New barnowl packages fix arbitrary code execution |
| | Sebastien Delafond | 03 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2103-1] New smbind packages fix sql injection |
| | Giuseppe Iuculano | 05 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2104-1] New quagga packages fix denial of service |
| | Florian Weimer | 06 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2105-1] New freetype packages fix several vulnerabilities |
| | Giuseppe Iuculano | 07 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2106-2] New xulrunner packages fix regression |
| | Stefan Fritsch | 19 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2109-1] New samba packages fix buffer overflow |
| | Stefan Fritsch | 16 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2112-1] New bzip2 packages fix integer overflow |
| | Stefan Fritsch | 20 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2114-1] New git-core packages fix regression |
| | Stefan Fritsch | 26 Sep 2010 |
| [Full-disclosure] [SECURITY] [DSA-2115-1] New moodle packages fix several vulnerabilities |
| | Florian Weimer | 29 Sep 2010 |
| [Full-disclosure] [SecurityArchitect-008]: Xterm Local Buffer Overflow Vulnerability |
| | musashi karak0rsan | 01 Sep 2010 |
| [Full-disclosure] [TEHTRI-Security Training + 0days] "Hunting Web Attackers" at HITBSecConf |
| | Laurent OUDOT at TEHTRI-Security | 07 Sep 2010 |
| [Full-disclosure] [USN-975-1] Firefox and Xulrunner vulnerabilities |
| | Jamie Strandboge | 08 Sep 2010 |
| [Full-disclosure] [USN-975-2] Firefox and Xulrunner regression |
| | Jamie Strandboge | 17 Sep 2010 |
| [Full-disclosure] [USN-978-1] Thunderbird vulnerabilities |
| | Jamie Strandboge | 08 Sep 2010 |
| [Full-disclosure] [USN-978-2] Thunderbird regression |
| | Jamie Strandboge | 17 Sep 2010 |
| [Full-disclosure] [USN-982-1] Wget vulnerability |
| | Marc Deslauriers | 02 Sep 2010 |
| [Full-disclosure] [USN-983-1] Sudo vulnerability |
| | Jamie Strandboge | 07 Sep 2010 |
| [Full-disclosure] [USN-984-1] LFTP vulnerability |
| | Marc Deslauriers | 07 Sep 2010 |
| [Full-disclosure] [USN-985-1] mountall vulnerability |
| | . | 20 Sep 2010 |
| | Kees Cook | 08 Sep 2010 |
| [Full-disclosure] [USN-986-1] bzip2 vulnerability |
| | Jamie Strandboge | 20 Sep 2010 |
| [Full-disclosure] [USN-986-2] ClamAV vulnerability |
| | Jamie Strandboge | 20 Sep 2010 |
| [Full-disclosure] [USN-986-3] dpkg vulnerability |
| | Jamie Strandboge | 20 Sep 2010 |
| [Full-disclosure] [USN-987-1] Samba vulnerability |
| | Marc Deslauriers | 14 Sep 2010 |
| [Full-disclosure] [USN-988-1] Linux kernel vulnerabilities |
| | Kees Cook | 17 Sep 2010 |
| [Full-disclosure] [USN-989-1] PHP vulnerabilities |
| | Marc Deslauriers | 20 Sep 2010 |
| [Full-disclosure] [USN-990-1] OpenSSL vulnerability |
| | Marc Deslauriers | 21 Sep 2010 |
| [Full-disclosure] [USN-990-2] Apache vulnerability |
| | Marc Deslauriers | 21 Sep 2010 |
| [Full-disclosure] [USN-991-1] quassel vulnerability |
| | Steve Beattie | 23 Sep 2010 |
| [Full-disclosure] [USN-992-1] Avahi vulnerabilities |
| | Marc Deslauriers | 29 Sep 2010 |
| [Full-disclosure] [USN-993-1] libgdiplus vulnerability |
| | Marc Deslauriers | 29 Sep 2010 |
| [Full-disclosure] [USN-994-1] libHX vulnerability |
| | Marc Deslauriers | 29 Sep 2010 |
| [Full-disclosure] [USN-995-1] libMikMod vulnerabilities |
| | Marc Deslauriers | 29 Sep 2010 |
| [Full-disclosure] [USN-996-1] Mako vulnerability |
| | Marc Deslauriers | 29 Sep 2010 |
| [Full-disclosure] Ac1db1tch3z vs x86_64 Linux Kernel |
| | ac1db1tch3z_at_nospam | 16 Sep 2010 |
| [Full-disclosure] Adobe Flash Player IE version 10.1.x Insecure DLL Hijacking Vulnerability (dwmapi.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| | MustLive | 12 Sep 2010 |
| | YGN Ethical Hacker Group | 10 Sep 2010 |
| [Full-disclosure] Adobe Flash Player – user-assisted privacy compromise |
| | Alexander Klink | 04 Sep 2010 |
| [Full-disclosure] AlSee version 6.20.0.1 <= Insecure DLL Hijacking Vulnerability (patchani.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] AlShow version 1.91 <= Insecure DLL Hijacking Vulnerability (mfc90enu.dll, mfc90loc.dll, dwmapi.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] AlZip version 8.0.6.3 <= Insecure DLL Hijacking Vulnerability (mfc90enu.dll, mfc90loc.dll, propsys.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Apple QuickTime Player version 7.64.17.73 <= Insecure DLL Hijacking Vulnerability (cfnetwork.dll, corefoundation.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Backward disassembler for ROP exploitation |
| | Adrian Furtuna | 28 Sep 2010 |
| [Full-disclosure] Binary Planting Attack Vectors - There's more than one way to skin a cat... or plant a binary, for that matter |
| | ACROS Security Lists | 20 Sep 2010 |
| [Full-disclosure] Brava PDF Reader version 3.3.0.18 <= Insecure DLL Hijacking Vulnerability (dwmapi.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Bug in vde_plug, remote exploitation possible? |
| | halfdog | 02 Sep 2010 |
| [Full-disclosure] Call for Papers H2HC Cancun/Mexico and H2HC Sao Paulo/Brazil |
| | Rodrigo Rubira Branco (BSDaemon) | 05 Sep 2010 |
| [Full-disclosure] CelFrame Office Suite 2008 <= Insecure DLL Hijacking Vulnerability ( java_msci.dll, msci_java.dll, wintab32.dll, gswin32c.exe) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco IOS Software H.323 Denial of Service Vulnerabilities |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco IOS Software Internet Group Management Protocol Denial of Service Vulnerability |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco IOS Software Network Address Translation Vulnerabilities |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco IOS SSL VPN Vulnerability |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities |
| | Cisco Systems Product Security Incident Response Team | 22 Sep 2010 |
| [Full-disclosure] Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers |
| | Cisco Systems Product Security Incident Response Team | 08 Sep 2010 |
| [Full-disclosure] CYBSEC Advisory 2010 0901 Achievo 1.4.3 (Multiple Authorization Flaws) |
| | CYBSEC Labs | 28 Sep 2010 |
| [Full-disclosure] CYBSEC Advisory 2010 0902 Achievo 1.4.3 (CSRF) |
| | CYBSEC Labs | 28 Sep 2010 |
| [Full-disclosure] DDoS attacks via other sites execution tool (DAVOSET) |
| | MustLive | 20 Sep 2010 |
| [Full-disclosure] Deutsche Post Security Cup |
| | Ralph.Zwierzina_at_nospam | 18 Sep 2010 |
| [Full-disclosure] Did someone hack Dave Aitel's Twitter account or is it an impostor? |
| | dink_at_nospam | 05 Sep 2010 |
| [Full-disclosure] Directory Traversal in Axigen v7.4.1 running on Windows |
| | Bogdan Calin | 15 Sep 2010 |
| [Full-disclosure] DLL hijacking POC (failed, see for yourself) |
| | Christian Sciberras | 17 Sep 2010 |
| | huj huj huj | 17 Sep 2010 |
| | T Biehn | 16 Sep 2010 |
| | Stefan Kanthak | 15 Sep 2010 |
| | Stefan Kanthak | 15 Sep 2010 |
| | Stefan Kanthak | 15 Sep 2010 |
| | Jeffrey Walton | 15 Sep 2010 |
| | Christian Sciberras | 15 Sep 2010 |
| | Christian Sciberras | 15 Sep 2010 |
| | Stefan Kanthak | 14 Sep 2010 |
| | Christian Sciberras | 15 Sep 2010 |
| | Jacky Jack | 02 Sep 2010 |
| | p8x | 02 Sep 2010 |
| | Larry Seltzer | 02 Sep 2010 |
| | Christian Sciberras | 02 Sep 2010 |
| | Larry Seltzer | 02 Sep 2010 |
| | Darren McDonald | 02 Sep 2010 |
| | Darren McDonald | 02 Sep 2010 |
| | Christian Sciberras | 02 Sep 2010 |
| | Christian Sciberras | 02 Sep 2010 |
| | Darren McDonald | 02 Sep 2010 |
| | Christian Sciberras | 02 Sep 2010 |
| | YGN Ethical Hacker Group | 02 Sep 2010 |
| | YGN Ethical Hacker Group | 02 Sep 2010 |
| | Christian Sciberras | 02 Sep 2010 |
| | p8x | 02 Sep 2010 |
| | Christian Sciberras | 01 Sep 2010 |
| [Full-disclosure] DLL Hijacking vulnerability in Opera |
| | MustLive | 15 Sep 2010 |
| | Juha-Matti Laurio | 13 Sep 2010 |
| | MustLive | 13 Sep 2010 |
| [Full-disclosure] DLL hijacking with Autorun on a USB drive |
| | Stefan Kanthak | 15 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 15 Sep 2010 |
| | Stefan Kanthak | 14 Sep 2010 |
| | Stefan Kanthak | 14 Sep 2010 |
| | Larry Seltzer | 14 Sep 2010 |
| | Dan Kaminsky | 14 Sep 2010 |
| | Pavel Kankovsky | 05 Sep 2010 |
| | paul.szabo_at_nospam | 03 Sep 2010 |
| | coderman | 02 Sep 2010 |
| | coderman | 02 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 02 Sep 2010 |
| | Pavel Kankovsky | 02 Sep 2010 |
| | Christian Sciberras | 01 Sep 2010 |
| | paul.szabo_at_nospam | 01 Sep 2010 |
| | matt | 01 Sep 2010 |
| | Charles Morris | 01 Sep 2010 |
| [Full-disclosure] DLL hijacking with ZIP files in email? |
| | Mario Vilas | 01 Sep 2010 |
| | coderman | 01 Sep 2010 |
| | paul.szabo_at_nospam | 01 Sep 2010 |
| [Full-disclosure] E-Press ONE Office Suite <= Insecure DLL Hijacking Vulnerability |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Exploit Next Generation(R) Example Codes |
| | Nelson Brito | 25 Sep 2010 |
| [Full-disclosure] False Authentication Attack/Any Browser |
| | iforone | 19 Sep 2010 |
| [Full-disclosure] Firefox same-origin policy for fonts |
| | Daniel Veditz | 13 Sep 2010 |
| | Dan Kaminsky | 12 Sep 2010 |
| | paul.szabo_at_nospam | 12 Sep 2010 |
| [Full-disclosure] Free Anti Social-Engineering Seminar |
| | Pete Herzog | 28 Sep 2010 |
| [Full-disclosure] FreeBSD 7.0 - 7.2 pseudofs null pointer dereference |
| | musnt live | 08 Sep 2010 |
| | Przemyslaw Frasunek | 08 Sep 2010 |
| [Full-disclosure] FreeBSD 8.1/7.3 vm.pmap kernel local race condition |
| | Maksymilian Arciemowicz | 07 Sep 2010 |
| [Full-disclosure] Freepbx |
| | Marsh Ray | 22 Sep 2010 |
| | Tyler Borland | 22 Sep 2010 |
| | Marsh Ray | 21 Sep 2010 |
| [Full-disclosure] full disclosure my dear (Microsoft IIS 6.0 Denial of Service) |
| | HI-TECH . | 01 Oct 2010 |
| [Full-disclosure] Full-Disclosure Digest, Vol 67, Issue 41 |
| | hmarti2_at_nospam | 25 Sep 2010 |
| [Full-disclosure] gDoc Fusion version 2.5.1 <= Insecure DLL Hijacking Vulnerability (wintab32.dll, ssleay32.dll) |
| | Jacky Jack | 12 Sep 2010 |
| | Zach C | 12 Sep 2010 |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Gödel and kernel backdoors |
| | dave b | 19 Sep 2010 |
| [Full-disclosure] Gdel and kernel backdoors |
| | wmsecurity | 18 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 20 Sep 2010 |
| | Georgi Guninski | 20 Sep 2010 |
| | Hurgel Bumpf | 20 Sep 2010 |
| | Christian Sciberras | 19 Sep 2010 |
| | Berend-Jan Wever | 19 Sep 2010 |
| | Georgi Guninski | 19 Sep 2010 |
| | Pavel Kankovsky | 19 Sep 2010 |
| | BMF | 19 Sep 2010 |
| | Giuseppe Fuggiano | 18 Sep 2010 |
| | mrx | 18 Sep 2010 |
| | Georgi Guninski | 18 Sep 2010 |
| [Full-disclosure] H2HC 2010 Sao Paulo - Capture the Flag |
| | Rodrigo Rubira Branco (BSDaemon) | 13 Sep 2010 |
| [Full-disclosure] H2HC So Paulo - Capture the Captcha |
| | Rodrigo Rubira Branco (BSDaemon) | 05 Sep 2010 |
| [Full-disclosure] i dont know security |
| | YGN Ethical Hacker Group | 09 Sep 2010 |
| | PsychoBilly | 09 Sep 2010 |
| | huj huj huj | 09 Sep 2010 |
| | p8x | 08 Sep 2010 |
| | YGN Ethical Hacker Group | 08 Sep 2010 |
| | Hurgel Bumpf | 08 Sep 2010 |
| | full-disclosure-bounces_at_nospam | 08 Sep 2010 |
| [Full-disclosure] IBM Lotus Symphony Office Suite version 3 beta 4 <= Insecure DLL Hijacking Vulnerability (eclipse_1114.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Internet Explorer 8 PoC: Twitter forced-tweet demo |
| | Chris Evans | 03 Sep 2010 |
| [Full-disclosure] Intro to Using the OSSTMM 3 |
| | Pete Herzog | 20 Sep 2010 |
| [Full-disclosure] Juniper Networks DLL Hijacking Vulnerability |
| | musnt live | 10 Sep 2010 |
| | musnt live | 09 Sep 2010 |
| [Full-disclosure] KeePass version 2.12 <= Insecure DLL Hijacking Vulnerability (dwmapi.dll) |
| | YGN Ethical Hacker Group | 13 Sep 2010 |
| | Rohit Patnaik | 13 Sep 2010 |
| | Stefan Kanthak | 11 Sep 2010 |
| | YGN Ethical Hacker Group | 09 Sep 2010 |
| | YGN Ethical Hacker Group | 09 Sep 2010 |
| | Christian Sciberras | 09 Sep 2010 |
| | Christian Sciberras | 09 Sep 2010 |
| | Christian Sciberras | 09 Sep 2010 |
| | Mitja Kolsek | 09 Sep 2010 |
| | jf | 09 Sep 2010 |
| | Christian Sciberras | 09 Sep 2010 |
| | YGN Ethical Hacker Group | 09 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | paul.szabo_at_nospam | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | paul.szabo_at_nospam | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | paul.szabo_at_nospam | 08 Sep 2010 |
| | Everhart, Glenn | 08 Sep 2010 |
| | Christian Sciberras | 08 Sep 2010 |
| | YGN Ethical Hacker Group | 08 Sep 2010 |
| | Jacky Jack | 07 Sep 2010 |
| | Christian Sciberras | 07 Sep 2010 |
| | Dan Kaminsky | 07 Sep 2010 |
| | Dan Kaminsky | 07 Sep 2010 |
| | YGN Ethical Hacker Group | 07 Sep 2010 |
| [Full-disclosure] KingSoft Office Suite 2010 | Insecure DLL Hijacking Vulnerability (plgpf.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] LDAP NULL Bind being picked up, making non PCI compliant |
| | Valdis.Kletnieks_at_nospam | 01 Sep 2010 |
| | Jason Nada | 01 Sep 2010 |
| [Full-disclosure] List Charter |
| | John Cartwright | 09 Sep 2010 |
| [Full-disclosure] Mac OS X 10.6 Security Configuration Guides Released |
| | Darren Thurston | 10 Sep 2010 |
| [Full-disclosure] ManageEngine OpUtils 'Login.do' SQL Injection Vulnerability |
| | Packet Storm | 18 Sep 2010 |
| | information security | 18 Sep 2010 |
| [Full-disclosure] Medium security flaw in Apache Traffic Server |
| | Tim Brown | 08 Sep 2010 |
| [Full-disclosure] Microsoft Internet explorer 8 DLL Hijacking (IESHIMS.DLL) |
| | YGN Ethical Hacker Group | 04 Sep 2010 |
| [Full-disclosure] monitoring the media monitors for fun and profit! |
| | Benji | 22 Sep 2010 |
| | omfgomfg_at_nospam | 21 Sep 2010 |
| [Full-disclosure] Month of Abysssec Undisclosed Bugs - Day 1 |
| | muts | 01 Sep 2010 |
| [Full-disclosure] Moovida Media Player version 2.0.0.15 Insecure DLL Hijacking Vulnerability (libc.dll, quserex.dll) |
| | YGN Ethical Hacker Group | 02 Sep 2010 |
| [Full-disclosure] n.runs-SA-2010.001 - Alcatel-Lucent - unauthenticated administrative access to CTI CCA Server |
| | security_at_nospam | 20 Sep 2010 |
| [Full-disclosure] n.runs-SA-2010.002 - Alcatel-Lucent - arbitrary code execution on OmniVista 4760 |
| | security_at_nospam | 20 Sep 2010 |
| | security_at_nospam | 20 Sep 2010 |
| [Full-disclosure] New tool for pentesting |
| | Eyeballing Weev | 17 Sep 2010 |
| | excore_at_nospam | 17 Sep 2010 |
| | Mario Vilas | 17 Sep 2010 |
| | rdsears_at_nospam | 17 Sep 2010 |
| | Eyeballing Weev | 17 Sep 2010 |
| | Hurgel Bumpf | 17 Sep 2010 |
| | Taras | 17 Sep 2010 |
| | Jhfjjf Hfdsjj | 17 Sep 2010 |
| | Omar B Villa | 17 Sep 2010 |
| | runlvl | 17 Sep 2010 |
| [Full-disclosure] Nitro PDF Reader version 2.5.1 <= Insecure DLL Hijacking Vulnerability (dwmapi.dll, nprender.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] nmap <= 5.21 is vulnerable to Windows DLL Hijacking Vulnerability. |
| | Nikhil Mittal | 05 Sep 2010 |
| [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL Hijacking |
| | cons0ul | 15 Sep 2010 |
| [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL Hijacking Vulnerability |
| | Thor (Hammer of God) | 18 Sep 2010 |
| | Pavel Kankovsky | 18 Sep 2010 |
| | YGN Ethical Hacker Group | 11 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 11 Sep 2010 |
| | jai | 11 Sep 2010 |
| | Fyodor | 11 Sep 2010 |
| | Shreyas Zare | 10 Sep 2010 |
| | Nikhil Mittal | 10 Sep 2010 |
| | Dan Kaminsky | 10 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 10 Sep 2010 |
| | Nikhil Mittal | 10 Sep 2010 |
| | Michal Zalewski | 09 Sep 2010 |
| | Nikhil Mittal | 09 Sep 2010 |
| | jf | 08 Sep 2010 |
| | jf | 08 Sep 2010 |
| | paul.szabo_at_nospam | 09 Sep 2010 |
| | Rohit Patnaik | 09 Sep 2010 |
| | paul.szabo_at_nospam | 09 Sep 2010 |
| | paul.szabo_at_nospam | 08 Sep 2010 |
| | Fyodor | 08 Sep 2010 |
| [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL HijackingVulnerability |
| | Stefan Kanthak | 13 Sep 2010 |
| [Full-disclosure] NMAP Vulnerable to attack |
| | Mario Vilas | 11 Sep 2010 |
| | Jacky Jack | 11 Sep 2010 |
| | Stefano Angaran | 10 Sep 2010 |
| | mezgani ali | 10 Sep 2010 |
| | Andrew Kirch | 10 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 10 Sep 2010 |
| | Stefano Angaran | 10 Sep 2010 |
| | Valdis.Kletnieks_at_nospam | 10 Sep 2010 |
| | musnt live | 10 Sep 2010 |
| [Full-disclosure] Nuance PDF Reader version 6.0<= Insecure DLL Hijacking Vulnerability (dwmapi.dll, exceptiondumpdll.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] nullcon Goa dwitiya (2.0) Call For Papers |
| | nullcon | 01 Sep 2010 |
| [Full-disclosure] Online Binary Planting Exposure Test |
| | coderman | 01 Sep 2010 |
| | YGN Ethical Hacker Group | 01 Sep 2010 |
| | Christian Sciberras | 01 Sep 2010 |
| | ACROS Lists | 01 Sep 2010 |
| [Full-disclosure] OpenText LiveLink 9.7.1 multiple vulnerabilities (CSRF, XSS) |
| | A. Ramos | 22 Sep 2010 |
| [Full-disclosure] Orange Spain disclosing user phone number |
| | Juha-Matti Laurio | 03 Sep 2010 |
| | xufi . | 01 Sep 2010 |
| [Full-disclosure] PAPER: JIT spraying and mitigations |
| | Piotr Bania | 06 Sep 2010 |
| [Full-disclosure] PGP Desktop version 9.10.x-10.0.0 Insecure DLL Hijacking Vulnerability (tsp.dll, tvttsp.dll) |
| | YGN Ethical Hacker Group | 09 Sep 2010 |
| [Full-disclosure] Profile - OSSTMM use at a Security Consultancy |
| | Pete Herzog | 28 Sep 2010 |
| [Full-disclosure] Python ssl handling could be better... |
| | dave b | 29 Sep 2010 |
| | dave b | 29 Sep 2010 |
| | dave b | 29 Sep 2010 |
| [Full-disclosure] question regarding RSA |
| | Pavel Kankovsky | 02 Sep 2010 |
| [Full-disclosure] reCaptcha secret key - where is the point? |
| | Harry Strongburg | 05 Sep 2010 |
| | Christian Sciberras | 04 Sep 2010 |
| | BlackHawk | 04 Sep 2010 |
| [Full-disclosure] Rooted CON 2011 - Call for Papers |
| | Romn Ramrez | 01 Sep 2010 |
| [Full-disclosure] rPSA-2010-0056-1 httpd mod_ssl |
| | rPath Update Announcements | 13 Sep 2010 |
| [Full-disclosure] Secunia Research: MailEnable SMTP Service Two Denial of Service Vulnerabilities |
| | Secunia Research | 13 Sep 2010 |
| [Full-disclosure] Secunia Research: Microsoft Outlook Content Parsing Integer Underflow Vulnerability |
| | Secunia Research | 14 Sep 2010 |
| [Full-disclosure] Security ie9? |
| | Christian Sciberras | 29 Sep 2010 |
| | yuange | 29 Sep 2010 |
| [Full-disclosure] Security problems in Zenphoto version 1.3 |
| | Bogdan Calin | 07 Sep 2010 |
| [Full-disclosure] Security vulnerabilities in Pligg CMS version 1.0.4 |
| | Bogdan Calin | 03 Sep 2010 |
| [Full-disclosure] SoMud P2P version 1.2.8 <= Insecure DLL Hijacking Vulnerability (wintab32.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Sorax PDF Reader version 2.0<= Insecure DLL Hijacking Vulnerability (dwmapi.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] SQL Injection and XSS vulnerabilities in CubeCart version 4.3.3 |
| | Bogdan Calin | 09 Sep 2010 |
| [Full-disclosure] stuxnet DATA decoder |
| | Mohammad Hosein | 10 Sep 2010 |
| [Full-disclosure] Sysinternals Process Explorer DLL Hijacking on x86 Windows systems (wow64cpu.dll) |
| | miom | 17 Sep 2010 |
| [Full-disclosure] TA-Mapper v1.1: Application Pen-Testing Effort Estimator |
| | Debasis Mohanty | 19 Sep 2010 |
| [Full-disclosure] Teamspeak default passwords? |
| | Gary Baribault | 23 Sep 2010 |
| [Full-disclosure] the real stuxnet authors plz stand up |
| | Kenneth Voort | 25 Sep 2010 |
| | coderman | 25 Sep 2010 |
| | coderman | 25 Sep 2010 |
| | coderman | 25 Sep 2010 |
| | coderman | 25 Sep 2010 |
| | coderman | 25 Sep 2010 |
| [Full-disclosure] THOTCON 0x2 - Call For Papers is Open -> 10.01.10 |
| | THOTCON Announce | 01 Oct 2010 |
| [Full-disclosure] Tuscl.net SQL injection with 30k Plain Text Passwords & 80k Email list |
| | Benji | 08 Sep 2010 |
| | Ben | 08 Sep 2010 |
| | Jhfjjf Hfdsjj | 03 Sep 2010 |
| | Ben | 03 Sep 2010 |
| | Ben | 03 Sep 2010 |
| [Full-disclosure] TWSL2010-005: FreePBX recordings interface allows remote code execution |
| | Richard Miles | 28 Sep 2010 |
| | Trustwave Advisories | 23 Sep 2010 |
| [Full-disclosure] UltraEdit Text Editor version 16.10.0.1036 <= Insecure DLL Hijacking Vulnerability (dwmapi.dll) |
| | YGN Ethical Hacker Group | 12 Sep 2010 |
| [Full-disclosure] Verizon Wireless security contact? |
| | auto666077_at_nospam | 02 Sep 2010 |
| [Full-disclosure] Virus submission site |
| | Shreyas Zare | 04 Sep 2010 |
| | Hacxx 20 | 04 Sep 2010 |
| | Hacxx 20 | 03 Sep 2010 |
| | Hacxx 20 | 03 Sep 2010 |
| | Hanno Böck | 03 Sep 2010 |
| | T Biehn | 03 Sep 2010 |
| | IndianZ | 03 Sep 2010 |
| | Shreyas Zare | 03 Sep 2010 |
| | Christian Sciberras | 03 Sep 2010 |
| | Hacxx 20 | 03 Sep 2010 |
| [Full-disclosure] VMSA-2010-0013 |
| | VMware Security Team | 01 Sep 2010 |
| [Full-disclosure] VMSA-2010-0013 VMware ESX third party updates for Service Console |
| | VMware Security Team | 01 Sep 2010 |
| [Full-disclosure] VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues |
| | VMware Security team | 24 Sep 2010 |
| [Full-disclosure] VMSA-2010-0015 VMware ESX third party updates for Service Console |
| | VMware Security team | 30 Sep 2010 |
| [Full-disclosure] Vulnerabilities in CMS MYsite |
| | Jan G.B. | 27 Sep 2010 |
| | MustLive | 25 Sep 2010 |
| [Full-disclosure] Vulnerabilities in CMS WebManager-Pro |
| | MustLive | 02 Sep 2010 |
| [Full-disclosure] Vulnerabilities in IB Promotion Advanced Business Web Suite |
| | MustLive | 20 Sep 2010 |
| [Full-disclosure] Vulnerable 3rd-party DLLs used in TrendMicro's malware scanner HouseCall |
| | Stefan Kanthak | 20 Sep 2010 |
| [Full-disclosure] Web challenges from RootedCON'2010 CTF - Contest |
| | Roman Medina-Heigl Hernandez | 13 Sep 2010 |
| [Full-disclosure] Web commands injection through FTP Login in Synology Disk Station - CVE-2010-2453 |
| | Rodrigo Branco | 26 Sep 2010 |
| [Full-disclosure] WebserverX Google Dork |
| | Christian Sciberras | 11 Sep 2010 |
| [Full-disclosure] Workaround for Ac1db1tch3z exploit. |
| | Terje Malmedal | 16 Sep 2010 |
| [Full-disclosure] www.PasswordAnalytics.com Released!!! |
| | evil fingers | 18 Sep 2010 |
| [Full-disclosure] XSS in a lot of products |
| | hackyouridols_at_nospam | 30 Sep 2010 |
| | Jeffrey Walton | 30 Sep 2010 |
| | Benji | 30 Sep 2010 |
| | rancor | 29 Sep 2010 |
| | pepelotas | 29 Sep 2010 |
| [Full-disclosure] XSS in Horde Application Framework <=3.3.8, icon_browser.php |
| | Moritz Naumann | 06 Sep 2010 |
| [Full-disclosure] XSS in Horde IMP <=4.3.7, fetchmailprefs.php |
| | Moritz Naumann | 27 Sep 2010 |
| [Full-disclosure] XSS in lojaeshop ecommerce |
| | primehaxor | 30 Sep 2010 |
| [Full-disclosure] ZDI-10-169: Novell Netware SSHD.NLM Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-170: Apple Safari Webkit Runin Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-171: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-172: Mozilla Firefox tree Object Removal Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-173: Mozilla Firefox nsTreeSelection Dangling Pointer Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-174: Hewlett-Packard Data Protector DtbClsLogin Utf8cpy Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-176: Mozilla Firefox normalizeDocument Remote Code Execution Vulnerability |
| | ZDI Disclosures | 13 Sep 2010 |
| [Full-disclosure] ZDI-10-177: IBM Lotus Domino iCalendar MAILTO Stack Overflow Vulnerability |
| | ZDI Disclosures | 14 Sep 2010 |
| [Full-disclosure] ZDI-10-178: Novell PlateSpin Orchestrate Graph Rendering Remote Code Execution Vulnerability |
| | ZDI Disclosures | 15 Sep 2010 |
| [Full-disclosure] ZDI-10-179: IBM TSM FastBack Mount Service Arbitrary Overwrite Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-180: IBM TSM FastBack Server _SendToLog Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-181: IBM TSM FastBack Server ActivateLTScriptReply Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-182: IBM TSM FastBack Server FXCLI_OraBR_Exec_Command Remote Code Execution Vulnerabilities |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-183: IBM TSM FastBack Server FXCLI_checkIndexDBLocation Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-184: IBM TSM FastBack Server USER_S_AddADGroup Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Execution Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-186: IBM TSM FastBack _CalcHashValueWithLength Remote Denial of Service Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| [Full-disclosure] ZDI-10-187: IBM TSM FastBack Server _DAS_ReadBlockReply Remote Denial of Service Vulnerability |
| | ZDI Disclosures | 29 Sep 2010 |
| DLL hijacking with Autorun on a USB drive], also proxy in the middle detection / destruction |
| | coderman | 01 Sep 2010 |