[Full-disclosure] [ MDVSA-2009:336 ] koffice

2009-12-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:336 http://www.mandriva.com/security/

[Full-disclosure] ZDI-09-099: Hewlett-Packard OpenView Data Protector Backup Client Service Buffer Overflow Vulnerability

2009-12-17 Thread ZDI Disclosures
ZDI-09-099: Hewlett-Packard OpenView Data Protector Backup Client Service Buffer Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-099 December 17, 2009 -- CVE ID: CVE-2007-2280 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Data Prot

[Full-disclosure] [ MDVSA-2009:335 ] ffmpeg

2009-12-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:335 http://www.mandriva.com/security/

[Full-disclosure] [ISecAuditors Security Advisories] QuiXplorer <=2.4.1beta Remote Code Execution vulnerability

2009-12-17 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-003 - Original release date: March 2nd, 2009 - Last revised: December 17th, 2009 - Discovered by: Juan Galiana Lara - Severity: 9/10 (CVSS scored) = I. VULNERABILITY ---

[Full-disclosure] [ISecAuditors Security Advisories] Horde 3.3.5 "PHP_SELF" Cross-Site Scripting vulnerability

2009-12-17 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-012 - Original release date: October 13th, 2009 - Last revised: December 16th, 2009 - Discovered by: Juan Galiana Lara - CVE ID: CVE-2009-3701 - Severity: 6.3/10 (CVSS Base Score) ===

[Full-disclosure] Last week || WebTel 2010 [ICIMP, AICT, ICIW] May 9 - 15, 2010 - Barcelona, Spain

2009-12-17 Thread Jaime Lloret Mauri
INVITATION December 20, 2009 is approaching. Thanks for forwarding the information on this Call for Submissions to those potentially interested to submit. = Call for Submissions === WebTel 2010, May 9 - 15, 2010 - Barcelona, Spain see: http://www.iaria.org/conferences2010/WebTel10.ht

[Full-disclosure] Last week to submit: ICIMP 2010 || May 9-15, 2010 - Barcelona, Spain

2009-12-17 Thread Jaime Lloret Mauri
INVITATION: = Note that we are entering the last week of submissions. Please consider to contribute to and/or forward to the appropriate groups the following opportunity to submit and publish original scientific results. = == ICIMP 2010 | Call for

[Full-disclosure] [ISecAuditors Security Advisories] Cisco ASA <= 8.x VPN SSL module Clientless URL-list control bypass

2009-12-17 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-013 - Original release date: December 7th, 2009 - Last revised: December 16th, 2009 - Discovered by: David Eduardo Acosta Rodriguez - Severity: 4/10 (CVSS Base Score) = I

[Full-disclosure] SEC Consult SA-20091217-0 :: Authentication bypass and file manipulation in Sitecore Staging Module

2009-12-17 Thread Lukas Weichselbaum
SEC Consult Security Advisory < 20091217-0 > == title: Authentication bypass and file manipulation in Sitecore Staging Module products: Sitecore Staging Module vulnerable v

[Full-disclosure] [tools] hostmap-0.2 released

2009-12-17 Thread Alessandro Tanasi
Hello, I am glad to release hostmap version 0.2. = Introduction = hostmap is a free, automatic, hostnames and virtual hosts discovery tool written in Ruby and licensed under GNU General Public License version 3 (GPLv3). It's goal is to enumerate all hostnames and configured virtual hosts on an I

[Full-disclosure] Secunia Research: Winamp Impulse Tracker Instrument Parsing Buffer Overflows

2009-12-17 Thread Secunia Research
== Secunia Research 17/12/2009 - Winamp Impulse Tracker Instrument Parsing Buffer Overflows - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: Winamp Impulse Tracker Sample Parsing Buffer Overflow

2009-12-17 Thread Secunia Research
== Secunia Research 17/12/2009 - Winamp Impulse Tracker Sample Parsing Buffer Overflow - == Table of Contents Affected Software...

[Full-disclosure] Secunia Research: Winamp Ultratracker File Parsing Buffer Overflow

2009-12-17 Thread Secunia Research
== Secunia Research 17/12/2009 - Winamp Ultratracker File Parsing Buffer Overflow - == Table of Contents Affected Software..

[Full-disclosure] Secunia Research: Winamp Oktalyzer Parsing Integer Overflow Vulnerability

2009-12-17 Thread Secunia Research
== Secunia Research 17/12/2009 - Winamp Oktalyzer Parsing Integer Overflow Vulnerability - == Table of Contents Affected Software..

Re: [Full-disclosure] (no subject)

2009-12-17 Thread Jeff Blaum
Wow, is you're site still down Dan? "Dan Kaminsky" wrote: > Easily the best environment for packet manipulation is scapy. > > The most guaranteed to work approach involves putting a system with two > interfaces in as an attacker, and running two scapy processes that copy frames > received on on