Re: [SC-L] blog post and open source vulnerabilities to blog about

2010-03-17 Thread Jon Rose
http://codesearch0day.appspot.com/ On Mar 16, 2010, at 11:41 AM, Matt Parsons wrote: Hello, I am working on a software security blog and I am trying to find open source vulnerabilities to present and share. Does anyone else have any open source vulnerabilities that they could share and

Re: [SC-L] blog post and open source vulnerabilities to blog about

2010-03-17 Thread McGovern, James F. (P+C Technology)
Parsons Sent: Tuesday, March 16, 2010 11:41 AM To: owaspdal...@utdallas.edu Cc: websecur...@webappsec.org; SC-L@securecoding.org Subject: [SC-L] blog post and open source vulnerabilities to blog about Hello, I am working on a software security blog and I am trying to find open source

Re: [SC-L] blog post and open source vulnerabilities to blog about

2010-03-17 Thread Greg Beeley
Matt, You can find quite a list of OSS vulnerabilities over an CVE (cve.mitre.org) or NVD (nvd.nist.gov), but here are a couple ones that I tend to use for illustrative purposes when teaching. - Apache Chunked Encoding vuln (#CVE-2002-0392), an integer overflow. Of particular interest because

Re: [SC-L] blog post and open source vulnerabilities to blog about

2010-03-17 Thread Dan Cornell
...@securecoding.org [mailto:sc-l- boun...@securecoding.org] On Behalf Of Greg Beeley Sent: Tuesday, March 16, 2010 2:37 PM To: SC-L@securecoding.org Subject: Re: [SC-L] blog post and open source vulnerabilities to blog about Matt, You can find quite a list of OSS vulnerabilities over an CVE