[ Massive Mode ] [ تماس ]
 
 

Security Tracker Archive :
Samba Access Control Flaw Lets Remote Authenticated Users Gain Elevated Privileges
Microsoft Internet Explorer Invalid Pointer Reference Lets Remote Users Execute Arbitrary Code
Microsoft Office Excel Bugs Let Remote Users Execute Arbitrary Code
Windows Movie Maker Buffer Overflow Lets Remote Users Cause Arbitrary Code to Be Executed
HP Perfomance Insight Unspecified Flaw Lets Remote Users Execute Arbitrary Code
IBM AIX Buffer Overflow in qosmod Command Lets Local Users Gain Elevated Privileges
IBM AIX Buffer Overflow in qoslist Command Lets Local Users Gain Elevated Privileges
Energizer DUO Charger USB Software Contains Trojan Software That Lets Remote Users Execute Arbitrary Code
SpamAssassin Milter Plugin Input Validation Flaw Lets Remote Users Execute Arbitrary Code
Opera Integer Overflow in Processing HTTP 'Content-Length' Reponses Lets Remote Users Execute Arbitrary Code
Juniper Instant Virtual Extranet (IVE) Input Validation Hole in 'editbk.cgi' Permits Cross-Site Scripting Attacks
OpenSSL Missing Check in kssl_keytab_is_available() Lets Remote Users Deny Service
IBM Lotus Notes Integer Overflow in KeyView Filter in Processing OLE Documents Lets Remote Users Execute Arbitrary Code
Symantec Data Loss Prevention Integer Overflow in KeyView Filter in Processing OLE Documents Lets Remote Users Execute Arbitrary Code
Symantec Brightmail Integer Overflow in KeyView Filter in Processing OLE Documents Lets Remote Users Execute Arbitrary Code
Symantec Mail Security Integer Overflow in KeyView Filter in Processing OLE Documents Lets Remote Users Execute Arbitrary Code
CA SiteMinder Input Validation Flaw in WebWorks Help Permits Cross-Site Scripting Attacks
McAfee LinuxShield Discloses Whether Usernames Are Valid
McAfee LinuxShield Lets Remote Authenticated Users Execute Arbitrary Code
CUPS lppasswd Format String Bug Lets Local Users Gain Elevated Privileges
Fcron 'fcrontab' Symlink Flaw Lets Local Users View Files
Oracle Siebel Customer Relationship Management Input Validation Hole Permits Cross-Site Scripting Attacks
Novell iManager Stack Overflow in eDirectory Plugin Lets Remote Users Execute Arbitrary Code
libpng Decompression Process May Let Remote Users Deny Service
Cisco Digital Media Player Lets Remote Users Inject Arbitrary Video and Data Content

Bugtraq Posts :
Vulnerabilities in Hydra Engine
VUPEN Security Research - Microsoft Office Excel Record Processing Code Execution Vulnerability
Secunia Research: Employee Timeclock Software "mysqldump" Password Disclosure
[ MDVSA-2010:058 ] php
Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities
[xss] a xss on "threadid" parameter in BBSMAX
[security bulletin] HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands
[SECURITY] [DSA 2008-1] New typo3-src packages fix several vulnerabilities
Croogo CMS 1.2 Cross Site Scripting Vulnerabilities
IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability
SQL injection vulnerability in wILD CMS
ZoneAlarm Security Circumvention
[ MDVSA-2010:057 ] apache
"Writing JIT-Spray Shellcode for fun and profit" by DSecRG
[XSS] i found a xss on "page" parameter in "eccredit.php" in Dvbbs < 8.3.0
phpinfo() XSS Vulnerability
[xss] a xss on "action" parameter in BBSMAX
Apache mod_isapi Dangling Pointer Vulnerability - Security Advisory - SOS-10-002
[ MDVSA-2010:056 ] openoffice.org
[ MDVSA-2010:055 ] poppler

InfoSec News :
Thailand approves extradition of credit card hack suspect
RSA: Cybersecurity A Joint Fed, Industry Effort
Cybersecurity program has serious defects, GAO says
Ford Motor Rolls Out New Security Features To Prevent Car-Hacking
Backdoor found in Energizer Duo USB battery charger
FDIC: Hackers took more than $120M in three months
Tokyo's Cyber Emergency Centre at the vanguard of hacking defence
The Corporate Side of Snooping
Microsoft's tax-for-hacks 'horrible' idea, say security experts
Facebook founder Mark Zuckerberg 'hacked into emails of rivals and journalists'
Westin Bonaventure Los Angeles latest victim of hotel hackers
Linux Advisory Watch: March 6th, 2010
At RSA, Some Security Pros Don't Practice What They Preach
Iowa Homeland Security Web site "compromised"
Nation's cybersecurity suffers from a lack of information sharing
New BlackEnergy Trojan Targeting Russian, Ukrainian Banks
White House Cyber Czar: 'There Is No Cyberwar'
Heartland Aftershocks: Still at Risk?
Secunia Weekly Summary - Issue: 2010-09
FBI Director: Hackers have corrupted valuable data

Full Disclosure :
[USN-908-1] Apache vulnerabilities
[ MDVSA-2010:059 ] virtualbox
credit union phishing scam
New Internet Explorer code-execution
Secunia Research: Employee Timeclock Software"mysqldump" Password Disclosure
Secunia Research: Employee Timeclock Software SQLInjection Vulnerabilities
Secunia Research: Employee Timeclock SoftwareBackup Information Disclosure
iDefense Security Advisory 03.09.10: Microsoft Excel FNGROUPNAME Record Uninitialized Memory Vulnerability
Vulnerabilities in Hydra Engine
iDefense Security Advisory 03.09.10: Microsoft Excel Sheet Object Type Confusion Vulnerability
iDefense Security Advisory 03.09.10: Microsoft Excel MDXTUPLE Record Heap Overflow Vulnerability
iDefense Security Advisory 03.09.10: Microsoft Excel MDXSET Record Heap Overflow Vulnerability
CVE-2010-0624: Heap-based buffer overflow in GNUTar and GNU Cpio
CORE-2009-1103: Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability
CORE-2009-0813: Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap Overflow
[ MDVSA-2010:058 ] php
ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability
ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability
List Charter
SQL injection vulnerability in wILD CMS

Secunia Advisories :
Error in connection !

CVE Compatible :
CVE-2010-0946 (com_ksadvertiser)
CVE-2010-0945 (com_hotbrackets)
CVE-2010-0944 (com_jcollection)
CVE-2010-0943 (com_jashowcase)
CVE-2010-0942 (com_jvideodirect)
CVE-2010-0941 (etek_systems_hit_counter)
CVE-2010-0940 (simple_php_guestbook)
CVE-2010-0939 (abb_forum)
CVE-2010-0938 (todoo_forum)
CVE-2010-0937 (visualization_library)
CVE-2010-0936 (dkvm-ip8)
CVE-2009-4679 (com_if_nexus)
CVE-2009-4678 (winn_guestbook)
CVE-2009-4677 (phpfk_php_forum)
CVE-2010-0935 (perforce_server)
CVE-2010-0934 (perforce_server)
CVE-2010-0933 (perforce_server)
CVE-2010-0932 (perforce_server)
CVE-2010-0931 (perforce_server)
CVE-2010-0930 (perforce_server)

Packetstorm Archive :
Botan-1.9.4.tgz
gnupg-2.0.15.tar.bz2
fwbuilder-4.0.0.tar.gz
anantasoft-xsrf.txt
secunia-etsdisclose.txt
secunia-etssql.txt
notepadpoc.zip
tarcpio-overflow.txt
ispcp-rfi.txt
secunia-etsb.txt
httpdx-breaksvc.txt
softbizjobsrecruitment-sql.txt
campsite-xsrf.txt
03.09.10-4.txt
03.09.10-3.txt
03.09.10-2.txt
60cyclecms-xss.txt
03.09.10-1.txt
friendlytr69-sql.txt
hydra-sqlxss.txt
dsa-2009-1.txt
TA10-068A.txt
tor.uclibc.i686.20100309.iso
CORE-2009-1103.txt
CORE-2009-0813.txt
rivercms-sql.txt
MDVSA-2010-058.txt
nusnewssystem-sql.txt
jevci-disclose.txt
ZDI-10-026.txt
mhproducts-sql.txt
easyftp.rb.txt
HPSBMA02489-SSRT090065.txt
energizer_duo_payload.rb.txt
orbital_viewer_orb.rb.txt

Distro Watch News :
Distribution Release: VortexBox 1.2
Development Release: Unity Linux 2010 RC1
Development Release: Fedora 13 Alpha
Development Release: MCNLive Kris Beta 1
Development Release: PCLinuxOS 2010 Beta 1
Development Release: SME Server 8.0 Beta 5
Distribution Release: Frugalware Linux 1.2
DistroWatch Weekly, Issue 344
Distribution Release: NuTyX 2009.3
Development Release: Nexenta Core Platform 3.0 Beta 1

Latest Packages From DW :
03/10 tar 1.23
03/09 sqlite 3.6.23
03/09 lvm 2.02.62
03/09 gnumeric 1.10.1
03/09 gnupg 2.0.15
03/08 gstreamer 0.10.28
03/08 gparted 0.5.2
03/08 dovecot 1.2.11
03/08 ImageMagick 6.6.0-4
03/08 ntfs-3g 2010.3.6
03/08 openssh 5.4p1
03/08 git 1.7.0.2

InfoSec Writers :
The Phishing Guide
Shedding Light on Quantum Cryptography
Securing a Virtual Environment
Investigating the SANS/CWE Top 25 Most Dangerous Programming Errors List
Hacking Tools & Techniques and How to Protect Your Network from Them
Computer Forensics: Breaking Down the 1’s and 0’s of Cyber Activity for Potential Evidence
Steps Involved in Exploiting a Buffer Overflow Vulnerability using a SEH Handler
Exploring Below the Surface of the GIFAR Iceberg
Anatomy of an XSS Attack
Failed: Information Security and Data Protection in a Consumer Digital World


نظرات و پیشنهادات :
 
نام :
ایمیل :
پیام :
Copyright 2008, Sepehr S. T. Co. Ltd. .