Teams 1_1028_100809_1711 Joomla Component Multiple Blind SQL Injection Vulnerabilities

2010-08-10 Thread Salvatore Fresta aka Drosophila
Teams 1_1028_100809_1711 Joomla Component Multiple Blind SQL Injection Vulnerabilities Name Teams Vendorhttp://www.joomlamo.com Versions Affected 1_1028_100809_1711 AuthorSalvatore Fresta aka Drosophila Website http://www.salvatorefresta.net

Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities

2010-08-10 Thread Salvatore Fresta aka Drosophila
Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities Name Amblog Vendorhttp://robitbt.hu Versions Affected 1.0 AuthorSalvatore Fresta aka Drosophila Website http://www.salvatorefresta.net Contact salvatorefresta [at]

[USN-967-1] w3m vulnerability

2010-08-10 Thread Steve Beattie
=== Ubuntu Security Notice USN-967-1August 09, 2010 w3m vulnerability CVE-2010-2074 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04

[USN-965-1] OpenLDAP vulnerabilities

2010-08-10 Thread Steve Beattie
=== Ubuntu Security Notice USN-965-1August 09, 2010 openldap, openldap2.2, openldap2.3 vulnerabilities CVE-2010-0211, CVE-2010-0212 === A security issue affects the

Secunia Research: Windows Movie Maker String Parsing Buffer Overflow

2010-08-10 Thread Secunia Research
== Secunia Research 10/08/2010 - Windows Movie Maker String Parsing Buffer Overflow - == Table of Contents Affected

ZDI-10-147: Microsoft Windows MPEG Layer-3 Audio Decoder Remote Code Execution Vulnerability

2010-08-10 Thread ZDI Disclosures
ZDI-10-147: Microsoft Windows MPEG Layer-3 Audio Decoder Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-147 August 10, 2010 -- CVE ID: CVE-2010-1882 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Microsoft -- Affected Products: Microsoft

2Wire Broadband Router Session Hijacking Vulnerability

2010-08-10 Thread YGN Ethical Hacker Group
== 2Wire Broadband Router Session Hijacking Vulnerability == 1. OVERVIEW The 2Wire Broadband Router is vulnerable to Session Hijacking flaw which attackers can compromise the router administrator session. 2.

Cross-Site Scripting vulnerability in Mozilla Firefox, Opera and other browsers

2010-08-10 Thread MustLive
Hello Bugtraq! I want to warn you about Cross-Site Scripting vulnerability in Mozilla Firefox, Opera and other browsers. It allows to bypass protection from executing of JavaScript code in location-header redirectors (by redirecting to javascript: URI). Recently, 04.08.2010, I wrote about

ZDI-10-148: Microsoft Cinepak Codec CVDecompress Remote Code Execution Vulnerability

2010-08-10 Thread ZDI Disclosures
ZDI-10-148: Microsoft Cinepak Codec CVDecompress Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-148 August 10, 2010 -- CVE ID: CVE-2010-2553 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Microsoft -- Affected Products: Microsoft File

ToorCon 12 Call for Papers

2010-08-10 Thread h1kari
TOORCON 12 CALL FOR PAPERS It's that time of year again! ToorCon 12 is coming so get your code finished and submit a talk this time around. We're letting you decide if you want to be a part of our 50-minute talks on Saturday, 20-minute talks on Sunday, and 75-minute talks for our Deep

Re: ESA-2010-013: RSA, The Security Division of EMC, informs about potential security vulnerability in RSA enVision� versions prior to 3.7 SP1

2010-08-10 Thread Security_Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Second instance of CVSS v2 Base Core Vector in the advisory should also read (AV:N/AC:L/Au:S/C:N/I:N/A:P.) CVSS v2 Base Score for this issue is 4 (AV:N/AC:L/Au:S/C:N/I:N/A:P). EMC Product Security Response Center security_al...@emc.com

CORE-2010-0407: Microsoft Office Excel PivotTable Cache Data Record Buffer Overflow

2010-08-10 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://corelabs.coresecurity.com/ Microsoft Office Excel PivotTable Cache Data Record Buffer Overflow 1. *Advisory Information* Title: Microsoft Office Excel PivotTable Cache Data

[CORE-2010-0623] Microsoft Windows CreateWindow function callback vulnerability

2010-08-10 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://corelabs.coresecurity.com/ Microsoft Windows CreateWindow function callback vulnerability 1. *Advisory Information* Title: Microsoft Windows CreateWindow function callback

ZDI-10-149: Adobe Flash Player LocalConnection Memory Corruption Remote Code Execution Vulnerability

2010-08-10 Thread ZDI Disclosures
ZDI-10-149: Adobe Flash Player LocalConnection Memory Corruption Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-149 August 10, 2010 -- CVE ID: CVE-2010-2188 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe