[Full-disclosure] Pritlog v0.821 CMS - Multiple Web Vulnerabilities

2012-04-30 Thread Research
Title: == Pritlog v0.821 CMS - Multiple Web Vulnerabilities Date: = 2012-04-29 References: === http://www.vulnerability-lab.com/get_content.php?id=534 VL-ID: = 534 Introduction: = PRITLOG is an extremely simple, small (< 500K uncompressed) and powerful blog

[Full-disclosure] DoS vulnerabilities in Firefox, Internet Explorer and Opera

2012-04-30 Thread MustLive
Hello list! I want to warn you about Denial of Service vulnerability in Mozilla Firefox, Internet Explorer and Opera. Earlier there was published DoS vulnerability in browser Opera 10.10 found by Inj3ct0r (http://securityvulns.com/news/Opera/1002.html). And some time ago I've checked this expl

Re: [Full-disclosure] DoS vulnerabilities in Firefox, Internet Explorer and Opera

2012-04-30 Thread Valdis . Kletnieks
On Mon, 30 Apr 2012 15:37:08 +0300, "MustLive" said: > * Mozilla Firefox 3.0.19 consumes resources (50% CPU and a lot of RAM) and > crashes. > * Mozilla Firefox 3.5.11 consumes resources (50% CPU and a lot of RAM) and > crashes. > * Mozilla Firefox 3.6.8 consumes resources (50% CPU and a lot of

[Full-disclosure] CWEs translation

2012-04-30 Thread Jerome Athias
Hi list, I finished the translation into french of all available CWEs (Titles + Descriptions). We use it for our CERT. I should soon share this work with french CERTs, but I would like to know if others could provide a translation in other languages? (I know some spain guys are working on it) Tha

[Full-disclosure] XSS in UMP-Sarkozy mailer system

2012-04-30 Thread Jerome Athias
tk3.rylyo.com/14/usb.htm?p=cf&mel=jer...@netpeas.com&adm=alert('p0wned');&l=fr smime.p7s Description: Signature cryptographique S/MIME ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and spo

Re: [Full-disclosure] DoS vulnerabilities in Firefox, Internet Explorer and Opera

2012-04-30 Thread InterN0T Advisories
Hello list! I also want to warn you about Denial of Service vulnerability, in almost every Operating System there is, by e.g., opening a lot of programs at the same time, or by using Fork bombs such as this in the Linux console: :(){ :|:& };: (Reference: http://en.wikipedia.org/wiki/Fork_bomb ), i