VUPEN Security Research - VMware Products Movie Decoder Heap Overflow Vulnerability

2010-04-12 Thread VUPEN Security Research
VUPEN Security Research - VMware Products Movie Decoder Heap Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND - VMware is a provider of virtualization software which runs on Microsoft Windows, Linux, and Mac OS X. VMware's enterprise

HITBSecConf DUBAI 2010: Learn more about web attacks and stealth hacking

2010-04-12 Thread Laurent OUDOT at TEHTRI-Security
Hi Folks, If you are interested by web attacks and stealth hacking, come and join us at HITBSecConf Dubai [ http://conference.hackinthebox.org/hitbsecconf2010dxb/?page_id=680 ]. Next 21st April, TEHTRI-Security will talk about web security, during this presentation: Silent Steps: Improving the

AneCMS Multiple Vulnerabilities

2010-04-12 Thread admin
##www.BugReport.ir # #AmnPardaz Security Research Team # # Title:AneCMS Multiple Vulnerabilities # Vendor: http://anecms.com/ # Vulnerable Version: 1.0 (Latest version till now) # Exploitation:

[USN-927-3] Thunderbird regression

2010-04-12 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-927-3 April 11, 2010 thunderbird regression https://launchpad.net/bugs/559918 === A security issue affects the following Ubuntu releases:

CVE-2009-4510: TANDBERG VCS Static SSH Host Keys

2010-04-12 Thread VSR Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Virtual Security Research, LLC. http://www.vsecurity.com/ Security Advisory - -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Advisory Name:

CVE-2009-4511: TANDBERG VCS Arbitrary File Retrieval

2010-04-12 Thread VSR Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Virtual Security Research, LLC. http://www.vsecurity.com/ Security Advisory - -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Advisory Name:

Vulnerabilities in CMS SiteLogic

2010-04-12 Thread MustLive
Hello Bugtraq! I want to warn you about security vulnerabilities in CMS SiteLogic. It's Ukrainian commercial CMS. In addition to previously reported vulnerabilities (disclosed this year), I will report about vulnerabilities in this CMS, which I disclosed in 2009. -

[SECURITY] [DSA 2032-1] New libpng packages fix several vulnerabilities

2010-04-12 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2032-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano April 11, 2010

[USN-927-2] NSS regression

2010-04-12 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-927-2 April 11, 2010 nss regression https://launchpad.net/bugs/559881 === A security issue affects the following Ubuntu releases: Ubuntu 9.10

iDefense Security Advisory 04.09.10: VMware VMnc Codec Heap Overflow Vulnerability

2010-04-12 Thread iDefense Labs
iDefense Security Advisory 04.09.10 http://labs.idefense.com/intelligence/vulnerabilities/ Apr 09, 2010 I. BACKGROUND VMware Inc. markets several virtualization products such as ACE, Player, Server, and Workstation. These products include a video coder-decoder (codec) called 'vmnc.dll', or

Re: Vulnerabilities in phpCOIN

2010-04-12 Thread Susan Bradley
About Us: http://phpcoin.com/mod.php?mod=siteinfoid=4 It is with profound sorrow, sadness and regret, that COINSoft Technologies Inc. must announce the death of their lead developer Stephen M. Kitching (cantex) after a mercifully short battle with cancer. Stephen was both an inspiration and

CVE-2009-4509: TANDBERG VCS Authentication Bypass

2010-04-12 Thread Timothy D. Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Virtual Security Research, LLC. http://www.vsecurity.com/ Security Advisory - -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Advisory Name:

[USN-920-1] Firefox 3.0 and Xulrunner vulnerabilities

2010-04-12 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-920-1 April 09, 2010 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179

[USN-921-1] Firefox 3.5 and Xulrunner vulnerabilities

2010-04-12 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-921-1 April 09, 2010 firefox-3.5, xulrunner-1.9.1 vulnerabilities CVE-2010-0173, CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179, CVE-2010-0181, CVE-2010-0182