[ MDVSA-2010:257 ] kernel

2010-12-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:257 http://www.mandriva.com/security/ _

www.eVuln.com : "titl","url" - Non-persistent XSS in Social Share

2010-12-17 Thread bt
www.eVuln.com advisory: "title" and "ur"l - Non-persistent XSS in Social Share Summary: http://evuln.com/vulns/164/summary.html Details: http://evuln.com/vulns/164/description.html ---Summary--- eVuln ID: EV0164 Software: Social Share Vendor: n/a Version: 2010-06-05 Cri

Re: XSS vulnerability in Lantern CMS

2010-12-17 Thread security curmudgeon
: Vulnerability ID: HTB22620 : Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_lantern_cms.html : Product: Lantern CMS : Vendor: Lantern ( http://www.lanterncms.com/www/html/7-home-page.asp ) : Vulnerable Version: Current at 18.09.2010 and Probably Prior Versions >From the vendo

www.eVuln.com : "link" and "linkdescription" XSS in Social Share

2010-12-17 Thread bt
www.eVuln.com advisory: "link" and "linkdescription" XSS in Social Share Summary: http://evuln.com/vulns/165/summary.html Details: http://evuln.com/vulns/165/description.html ---Summary--- eVuln ID: EV0165 Software: Social Share Vendor: n/a Version: 2010-06-05 Critical

[ GLSA 201012-01 ] Chromium: Multiple vulnerabilities

2010-12-17 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201012-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Alt-N WebAdmin Source Code Disclosure

2010-12-17 Thread wsn1983
Vulnerable: v3.3.3 Vendor: www.altn.com Category: Environment Error Vulnerable Alt-N WebAdmin 3.3.3 U-Mail for Windows V9.8 U-Mail GateWay for Windows V9.8 Details: = A source code disclosure vulnerability exists with Alt-N WebAdmin Server. Remote

Re: D-Link DIR-300 authentication bypass

2010-12-17 Thread Narendra Choyal
Hi Dlink confirmed my bug in DIR-320 and DIR-600. Links for relevant patched firmware: ftp://ftp.dlink.pl/dir/dir-320/driver_software/DIR-320_fw_revA_1-21B03_all_en_20101213.zip ftp://ftp.dlink.pl/dir/dir-600/driver_software/DIR-600_fw_revB_2-05B01_all_en_20101213.zip

Making Security Suck Less

2010-12-17 Thread Pete Herzog
Hi, "Now not everything about the old security model is bad. Personally, I really like the Zen feel of it. It's like raking the fine, white, beach sand into those concentric lines and around rocks and dead fish and stuff. It's very Zen. Then as the tide rises, the wind blows, and Frisbees get

Re: XSS vulnerability in Expression CMS

2010-12-17 Thread security curmudgeon
: Vulnerability ID: HTB22618 : Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_expression_cms_1.html : Product: Expression : Vendor: Backbone Technology ( http://www.backbonetechnology.com ) : Vulnerable Version: Current at 18.09.2010 and Probably Prior Versions How do you know

[USN-1033-1] Eucalyptus vulnerability

2010-12-17 Thread Kees Cook
=== Ubuntu Security Notice USN-1033-1 December 16, 2010 eucalyptus vulnerability CVE-2010-3905 === A security issue affects the following Ubuntu releases: Ubuntu 10.10 This adv

Apple Quicktime Memory Corruption - CVE-2010-3801

2010-12-17 Thread Rodrigo Branco
Dear List, I'm writing on behalf of the Check Point Vulnerability Discovery Team to publish the following vulnerability. Check Point Software Technologies - Vulnerability Discovery Team (VDT) http://www.checkpoint.com/defense/ Apple Quicktime Memory Corruption when parsing FPX files CVE-2010-