NULL pointer in the HTTP/XML-RPC service of Crysis 1.21

2008-06-17 Thread Luigi Auriemma
### Luigi Auriemma Application: Crysis http://www.ea.com/crysis/home.jsp Versions: <= 1.21 (1.1.1.6156 showed as gamever) Platforms:Windows Bug: NULL pointer in the HT

Hacking Coffee Makers.

2008-06-17 Thread Craig Wright
Hi All, I have a Jura F90 Coffee maker with the Jura Internet Connection Kit. The idea is to: "Enable the Jura Impressa F90 to communicate with the Internet, via a PC. Download parameters to configure your espresso machine to your own personal taste. If there's a problem, the engineers can run

[ GLSA 200806-06 ] Evolution: User-assisted execution of arbitrary code

2008-06-17 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Server freezed in Skulltag 0.97d2-RC2

2008-06-17 Thread Luigi Auriemma
### Luigi Auriemma Application: Skulltag http://www.skulltag.com Versions: <= 0.97d2-RC2 Platforms:Windows, Linux and FreeBSD Bug: loop during the parsing of the packe

S21SEC-044-en:OpenDocMan Cross Site Scripting (XSS)

2008-06-17 Thread S21sec labs
## - S21Sec Advisory - ## Title: OpenDocMan Cross Site Scripting (XSS) ID: S21sec-044-en Severity: Low History: 15.Apr.2008 Vulne

fetchmail security announcement fetchmail-SA-2008-01 (CVE-2008-2711)

2008-06-17 Thread ma+bt
fetchmail-SA-2008-01: Crash on large log messages in verbose mode Topics: Crash in large log messages in verbose mode. Author: Matthias Andree Version:1.0 Announced: 2008-06-17 Type: Dereferencing garbage pointer trigged by outside circumstances Impact:

[ GLSA 200806-05 ] cbrPager: User-assisted execution of arbitrary code

2008-06-17 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

fetchmail security announcement fetchmail-SA-2007-02 (CVE-2007-4565)

2008-06-17 Thread ma+bt
fetchmail-SA-2007-02: Crash when a local warning message is rejected Topics: Crash when a fetchmail-generated warning message is rejected Author: Matthias Andree Version:1.1 Announced: 2007-08-28 Type: NULL pointer dereference trigged by outside circumstance

iPhoneDbg Toolkit

2008-06-17 Thread Nicolas A. Economou
Hello! We are proud to announce the release of the iPhoneDbg Toolkit, an effort towards iPhone exploit development. You can find it here: http://oss.coresecurity.com/projects/iphonedbg.html. - What is the iPhoneDbg Toolkit? This set of tools will enable you to delve into iPhone Binary Reversin