[Full-disclosure] SEC Consult SA-20130403-0 :: Multiple vulnerabilities in Sophos Web Protection Appliance

2013-04-03 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20130403-0 === title: Multiple vulnerabilities product: Sophos Web Protection Appliance vulnerable version: = 3.7.8.1 fixed version: 3.7.8.2

[Full-disclosure] Google AD Sync Tool - Exposure of Sensitive Information Vulnerability

2013-04-03 Thread Lists
Sense of Security - Security Advisory - SOS-13-001 Release Date. 03-Apr-2013 Last Update. - Vendor Notification Date. 03-Sep-2012 Product. Google Active Directory Sync (GADS) Tool Platform. Windows, Linux, Solaris

[Full-disclosure] [Security-news] SA-CONTRIB-2013-040 - Commerce Skrill (Formerly Moneybookers) - Access bypass

2013-04-03 Thread security-news
View online: http://drupal.org/node/1960338 * Advisory ID: DRUPAL-SA-CONTRIB-2013-040 * Project: Commerce Skrill (Formerly Moneybookers) [1] (third-party module) * Version: 7.x * Date: 2013-April-03 * Security risk: Critical [2] * Exploitable from: Remote * Vulnerability: Access

[Full-disclosure] [Security-news] SA-CONTRIB-2013-041 - Chaos tool suite (ctools) - Access bypass

2013-04-03 Thread security-news
View online: http://drupal.org/node/1960406 * Advisory ID: DRUPAL-SA-CONTRIB-2013-041 * Project: Chaos tool suite (ctools) [1] (third-party module) * Version: 7.x * Date: 2013-April-03 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Access bypass

[Full-disclosure] DoS vulnerability in Adobe Flash Player (BSOD)

2013-04-03 Thread MustLive
Hello list! I want to warn you about Denial of Service vulnerability (BSOD) in Adobe Flash Player. I've found this vulnerability at 27.01.2013. - Affected products: - Vulnerable version is Adode Flash 11.5.502.146. Attack works only on AMD/ATI

[Full-disclosure] [SECURITY] [DSA 2654-1] libxslt security update

2013-04-03 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2654-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso April 03, 2013

[Full-disclosure] Hackersh 0.1 Release Announcement

2013-04-03 Thread Itzik Kotler
Hi All, I am pleased to announce the first version of Hackersh ( http://www.hackersh.org). Hackersh (Hacker Shell) is a free and open source shell (command interpreter) written in Python with built-in security commands, and out-of-the-box wrappers for various security tools, using Pythonect as

Re: [Full-disclosure] DoS vulnerability in Adobe Flash Player (BSOD)

2013-04-03 Thread Jann Horn
On Thu, Apr 04, 2013 at 01:24:29AM +0300, MustLive wrote: Hello list! I want to warn you about Denial of Service vulnerability (BSOD) in Adobe Flash Player. I've found this vulnerability at 27.01.2013. - Affected products: - Vulnerable