Advisory for MS11-035 / ZDI-11-167

2011-09-13 Thread Luigi Auriemma
### Luigi Auriemma Application: Microsoft WINS service http://www.microsoft.com Versions: = 5.2.3790.4520 Platforms:Windows Bug: arbitrary memory corruption

XSS vulnerability in FortiMail Messaging Security Appliance

2011-09-13 Thread sschurtz
Advisory: XSS vulnerability in FortiMail Messaging Security Appliance Advisory ID:SSCHADV2011-011 Author: Stefan Schurtz Affected Software: v4.0,build0245,101208 (MR1 Patch 2) Vendor URL: http://www.fortinet.com/ Vendor Status: informed

Vulnerabilities in trading and SCADA softwares

2011-09-13 Thread Luigi Auriemma
Considering the current financial and global crysis in which we are fallen I thought that was enough funny to give a quick look at two particular types of softwares: technical analysis (trading) and SCADA. The tests have been performed as fast as possible without going deep in the softwares and

[security bulletin] HPSBMU02703 SSRT100242 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Denial of Service (DoS), Unauthorized Disclosure of Information, Unau

2011-09-13 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03005726 Version: 1 HPSBMU02703 SSRT100242 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Denial of Service (DoS), Unauthorized Disclosure of

Seeker Advisory Sep11: Reflected Cross Site Scripting in Microsoft SharePoint Portal

2011-09-13 Thread Irene Abezgauz
Seeker Research Center Security Advisory This vulnerability was discovered by SeekerĀ® Automatic Run-Time Application Security Testing Solution Disclosed By Irene Abezgauz, September 13th, 2011 = I. Overview = A Cross Site Scripting vulnerability has been identified in