CORE-2010-1109 - Multiple vulnerabilities in BugTracker.Net

2010-12-01 Thread CORE Security Technologies Advisories
Core Security Technologies - CoreLabs Advisory http://corelabs.coresecurity.com/ Multiple vulnerabilities in BugTracker.Net 1. *Advisory Information* Title: Multiple vulnerabilities in BugTracker.Net Advisory Id: CORE-2010-1109 Advisory URL:

[ MDVSA-2010:246 ] krb5

2010-12-01 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:246 http://www.mandriva.com/security/

[ MDVSA-2010:245 ] krb5

2010-12-01 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:245 http://www.mandriva.com/security/

Digitalus 1.10.0 Alpha2 Arbitrary File Upload vulnerability.txt

2010-12-01 Thread eidelweiss
Digitalus 1.10.0 Alpha2 Arbitrary File Upload vulnerability __ ____ /\ _`\ /\ \ __

Secunia Research: Winamp NSV Table of Contents Parsing Integer Overflow

2010-12-01 Thread Secunia Research
== Secunia Research 30/11/2010 - Winamp NSV Table of Contents Parsing Integer Overflow - == Table of Contents Affected

[eVuln.com] Multiple XSS in Alguest

2010-12-01 Thread bt
New eVuln Advisory: Multiple XSS in Alguest Summary: http://evuln.com/vulns/151/summary.html Details: http://evuln.com/vulns/151/description.html ---Summary--- eVuln ID: EV0151 Software: Alguest Vendor: n/a Version: 1.1c-patched Critical Level: low Type: Cross Site Scripting

Re: D-Link DIR-300 authentication bypass

2010-12-01 Thread Karol CeliƄski
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Polish D-Link branch confirmed the bug and produced relevant patched firmware: DIR-300: ftp://ftp.dlink.pl/dir/dir-300/driver_software/DIR-300_fw_revA_1-05B09_all_en_20101130.zip

Vulnerabilities in Fabrica Engine

2010-12-01 Thread MustLive
Hello Bugtraq! I want to warn you about Cross-Site Scripting, Denial of Service and SQL Injection vulnerabilities in Fabrica Engine (which I found in 2008 and 2009 at web site of one online shop). It's commercial engine for online shops. SecurityVulns ID: 11274. -

[USN-1025-1] Bind vulnerabilities

2010-12-01 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1025-1 December 01, 2010 bind9 vulnerabilities CVE-2010-3613, CVE-2010-3614 === A security issue affects the following Ubuntu releases: Ubuntu

[SECURITY] [DSA-2129-1] New krb5 packages fix checksum verification weakness

2010-12-01 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2129-1 secur...@debian.org http://www.debian.org/security/ Stefan Fritsch December 1, 2010

[SECURITY] [DSA-2128-1] New libxml2 packages fix potential code execution

2010-12-01 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2128-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano December 01, 2010