| 2009-11-06 |
p5-HTML-Parser -- denial of service |
| 2009-11-05 |
gd -- '_gdGetColors' remote buffer overflow vulnerability |
| typo3 -- multiple vulnerabilities in TYPO3 Core |
| 2009-11-03 |
vlc -- stack overflow in MPA, AVI and ASF demuxer |
| 2009-11-02 |
KDE -- multiple vulnerabilities |
| 2009-10-31 |
opera -- multiple vulnerabilities |
| 2009-10-28 |
Enhanced cTorrent -- stack-based overflow |
| mozilla -- multiple vulnerabilities |
| 2009-10-25 |
elinks -- buffer overflow vulnerability |
| 2009-10-22 |
squidGuard -- multiple vulnerabilities |
| 2009-10-20 |
Xpdf -- Multiple Vulnerabilities |
| 2009-10-16 |
django -- denial-of-service attack |
| 2009-10-13 |
phpmyadmin -- XSS and SQL injection vulnerabilities |
| 2009-10-12 |
php5 -- Multiple security issues |
| 2009-10-07 |
virtualbox -- privilege escalation |
| 2009-10-06 |
FreeBSD -- Devfs / VFS NULL pointer race condition |
| FreeBSD -- kqueue pipe race conditions |
| 2009-09-30 |
mybb -- multiple vulnerabilities |
| 2009-09-22 |
drupal -- multiple vulnerabilities |
| 2009-09-18 |
fwbuilder -- security issue in temporary file handling |
| 2009-09-17 |
bugzilla -- two SQL injections, sensitive data exposure |
| 2009-09-14 |
horde-base -- multiple vulnerabilities |
| nginx -- remote denial of service vulnerability |
| 2009-09-13 |
ikiwiki -- insufficient blacklisting in teximg plugin |
| xapian-omega -- cross-site scripting vulnerability |
| 2009-09-10 |
mozilla firefox -- multiple vulnerabilities |
| 2009-09-09 |
cyrus-imapd -- Potential buffer overflow in Sieve |
| 2009-09-08 |
silc-toolkit -- Format string vulnerabilities |
| 2009-09-04 |
opera -- multiple vulnerabilities |
| 2009-09-02 |
dnsmasq -- TFTP server remote code injection vulnerability |
| 2009-08-25 |
apache22 -- several vulnerability |
| 2009-08-20 |
pidgin -- MSN overflow parsing SLP messages |
| 2009-08-17 |
GnuTLS -- improper SSL certificate verification |
| GnuTLS -- multiple vulnerabilities |
| memcached -- memcached stats maps Information Disclosure Weakness |
| 2009-08-12 |
wordpress -- remote admin password reset vulnerability |
| 2009-08-11 |
fetchmail -- improper SSL certificate subject verification |
| 2009-08-07 |
joomla15 -- com_mailto Timeout Issue |
| 2009-08-06 |
subversion -- heap overflow vulnerability |
| 2009-08-05 |
bugzilla -- product name information leak |
| 2009-08-04 |
mozilla -- multiple vulnerabilities |
| silc-client -- Format string vulnerability |
| 2009-08-02 |
SquirrelMail -- Plug-ins compromise |
| 2009-08-01 |
BIND -- Dynamic update message remote DoS |
| 2009-07-29 |
mono -- XML signature HMAC truncation spoofing |
| 2009-07-27 |
squid -- several remote denial of service vulnerabilities |
| 2009-07-17 |
mozilla -- corrupt JIT state after deep return from native function |
| 2009-07-15 |
isc-dhcp-client -- Stack overflow vulnerability |
| 2009-07-13 |
drupal -- multiple vulnerabilities |
| 2009-07-03 |
nfsen -- remote command execution |
| 2009-06-30 |
nagios -- Command Injection Vulnerability |
| phpmyadmin -- XSS vulnerability |
| 2009-06-23 |
tor-devel -- DNS resolution vulnerabiliity |
| 2009-06-16 |
cscope -- buffer overflow |
| cscope -- multiple buffer overflows |
| joomla -- multiple vulnerabilities |
| pidgin -- multiple vulnerabilities |
| 2009-06-15 |
git -- denial of service vulnerability |
| 2009-06-13 |
ruby -- BigDecimal denial of service vulnerability |
| 2009-06-12 |
mozilla -- multiple vulnerabilities |
| 2009-06-08 |
apr -- multiple vulnerabilities |
| 2009-06-04 |
dokuwiki -- Local File Inclusion with register_globals on |
| 2009-05-30 |
eggdrop -- denial of service vulnerability |
| libsndfile -- multiple vulnerabilities |
| openssl -- denial of service in DTLS implementation |
| slim -- local disclosure of X authority magic cookie |
| wireshark -- PCNFSD Dissector Denial of Service Vulnerability |
| 2009-05-21 |
imap-uw -- University of Washington IMAP c-client Remote Format String Vulnerability |
| 2009-05-20 |
ntp -- stack-based buffer overflow |
| 2009-05-19 |
nsd -- buffer overflow vulnerability |
| 2009-05-17 |
libxine -- multiple vulnerabilities |
| libxine -- multiple vulnerabilities |
| 2009-05-16 |
libwmf -- embedded GD library Use-After-Free vulnerability |
| libwmf -- integer overflow vulnerability |
| mod_perl -- cross-site scripting |
| moinmoin -- cross-site scripting vulnerabilities |
| php -- ini database truncation inside dba_replace() function |
| 2009-05-15 |
cyrus-sasl -- buffer overflow vulnerability |
| 2009-05-14 |
drupal -- cross-site scripting |
| 2009-05-13 |
ghostscript -- buffer overflow vulnerability |
| moinmoin -- multiple cross site scripting vulnerabilities |
| pango -- integer overflow |
| 2009-05-09 |
wireshark -- multiple vulnerabilities |
| 2009-05-07 |
cups -- remote code execution and DNS rebinding |
| FreeBSD -- remotely exploitable crash in OpenSSL |
| 2009-05-06 |
quagga -- Denial of Service |
| 2009-05-04 |
openfire -- Openfire No Password Changes Security Bypass |
| 2009-04-30 |
drupal -- cross site scripting |
| 2009-04-22 |
mozilla -- multiple vulnerabilities |
| 2009-04-18 |
freetype2 -- multiple vulnerabilities |
| poppler -- Poppler Multiple Vulnerabilities |
| xpdf -- multiple vulnerabilities |
| 2009-04-17 |
ejabberd -- cross-site scripting vulnerability |
| 2009-04-15 |
phpmyadmin -- insufficient output sanitizing when generating configuration file |
| ziproxy -- multiple vulnerability |
| 2009-04-11 |
drupal6-cck -- cross-site scripting |
| 2009-03-27 |
pivot-weblog -- file deletion vulnerability |
| 2009-03-25 |
phpmyadmin -- insufficient output sanitizing when generating configuration file |
| 2009-03-23 |
amarok -- multiple vulnerabilities |
| 2009-03-22 |
wireshark -- multiple vulnerabilities |
| 2009-03-18 |
netatalk -- arbitrary command execution in papd daemon |
| 2009-03-16 |
ffmpeg -- 4xm processing memory corruption vulnerability |
| gstreamer-plugins-good -- multiple memory overflows |
| libsndfile -- CAF processing integer overflow vulnerability |
| php-mbstring -- php mbstring buffer overflow vulnerability |
| phppgadmin -- directory traversal with register_globals enabled |
| proftpd -- multiple sql injection vulnerabilities |
| roundcube -- webmail script insertion and php code injection |
| zabbix -- php frontend multiple vulnerabilities |
| 2009-03-15 |
opera -- multiple vulnerabilities |
| 2009-03-11 |
apache -- Cross-site scripting vulnerability |
| epiphany -- untrusted search path vulnerability |
| 2009-03-04 |
curl -- cURL/libcURL Location: Redirect URLs Security Bypass |
| pngcrush -- libpng Uninitialised Pointer Arrays Vulnerability |
| 2009-02-18 |
Zend Framework -- Local File Inclusion vulnerability in Zend_View::render() |
| 2009-02-17 |
dia -- remote command execution vulnerability |
| 2009-02-15 |
pycrypto -- ARC2 module buffer overflow |
| 2009-02-14 |
varnish -- Varnish HTTP Request Parsing Denial of Service |
| 2009-02-13 |
tor -- multiple vulnerabilites |
| 2009-02-11 |
codeigniter -- arbitrary script execution in the new Form Validation class |
| firefox -- multiple vulnerabilities |
| pyblosxom -- atom flavor multiple XML injection vulnerabilities |
| typo3 -- cross-site scripting and information disclosure |
| 2009-02-09 |
amaya -- multiple buffer overflow vulnerabilities |
| phplist -- local file inclusion vulnerability |
| squid -- remote denial of service vulnerability |
| typo3 -- multiple vulnerabilities |
| websvn -- multiple vulnerabilities |
| 2009-02-06 |
sudo -- certain authorized users could run commands as any user |
| 2009-02-04 |
drupal -- multiple vulnerabilities |
| 2009-02-03 |
perl -- Directory Permissions Race Condition |
| 2009-01-30 |
ganglia -- buffer overflow vulnerability |
| moinmoin -- multiple cross site scripting vulnerabilities |
| 2009-01-29 |
tor -- unspecified memory corruption vulnerability |
| 2009-01-28 |
glpi -- SQL Injection |
| 2009-01-25 |
openfire -- multiple vulnerabilities |
| 2009-01-21 |
ipset-tools -- Denial of Service Vulnerabilities |
| 2009-01-20 |
Teamspeak Server -- Directory Traversal Vulnerability |
| 2009-01-19 |
git -- gitweb privilege escalation |
| optipng -- arbitrary code execution via crafted BMP image |
| 2009-01-15 |
gtar -- GNU TAR safer_name_suffix Remote Denial of Service Vulnerability |
| mplayer -- vulnerability in STR files processor |
| 2009-01-13 |
cgiwrap -- XSS Vulnerability |
| 2009-01-12 |
nagios -- web interface privilege escalation vulnerability |
| 2009-01-11 |
imap-uw -- imap c-client buffer overflow |
| imap-uw -- local buffer overflow vulnerabilities |
| libcdaudio -- remote buffer overflow and code execution |
| mysql -- empty bit-string literal denial of service |
| mysql -- privilege escalation and overwrite of the system table information |
| mysql -- remote dos via malformed password packet |
| mysql -- renaming of arbitrary tables by authenticated users |
| pdfjam -- insecure temporary files |
| verlihub -- insecure temporary file usage and arbitrary command execution |
| 2009-01-05 |
FreeBSD -- arc4random(9) predictable sequence vulnerability |
| FreeBSD -- Cross-site request forgery in ftpd(8) |
| FreeBSD -- IPv6 Neighbor Discovery Protocol routing vulnerability |
| FreeBSD -- netgraph / bluetooth privilege escalation |
| php5-gd -- uninitialized memory information disclosure vulnerability |
| xterm -- DECRQSS remote command execution vulnerability |
| 2009-01-04 |
awstats -- multiple XSS vulnerabilities |
| 2009-01-03 |
p5-File-Path -- rmtree allows creation of setuid files |
| 2009-01-02 |
vim -- multiple vulnerabilities in the netrw module |
| 2008-12-31 |
vinagre -- format string vulnerability |
| 2008-12-30 |
mplayer -- twinvq processing buffer overflow vulnerability |
| mysql -- MyISAM table privileges security bypass vulnerability for symlinked paths |
| roundcube -- remote execution of arbitrary code |
| twiki -- multiple vulnerabilities |
| 2008-12-26 |
ampache -- insecure temporary file usage |
| 2008-12-19 |
drupal -- multiple vulnerabilities |
| mediawiki -- multiple vulnerabilities |
| mozilla -- multiple vulnerabilities |
| opera -- multiple vulnerabilities |
| 2008-12-11 |
phpmyadmin -- cross-site request forgery vulnerability |
| 2008-12-08 |
php5 -- potential magic_quotes_gpc vulnerability |
| 2008-12-07 |
dovecot-managesieve -- Script Name Directory Traversal Vulnerability |
| habari -- Cross-Site Scripting Vulnerability |
| mgetty+sendfax -- symlink attack via insecure temporary files |
| php -- multiple vulnerabilities |
| wireshark -- SMTP Processing Denial of Service Vulnerability |
| 2008-12-06 |
mantis -- multiple vulnerabilities |
| mantis -- php code execution vulnerability |
| vlc -- arbitrary code execution in the RealMedia processor |
| 2008-12-04 |
squirrelmail -- Cross site scripting vulnerability |
| 2008-11-29 |
cups -- potential buffer overflow in PNG reading code |
| hplip -- hpssd Denial of Service |
| openoffice -- arbitrary code execution vulnerabilities |
| samba -- potential leakage of arbitrary memory contents |
| wordpress -- header rss feed script insertion vulnerability |
| 2008-11-24 |
imlib2 -- XPM processing buffer overflow vulnerability |
| 2008-11-23 |
streamripper -- multiple buffer overflows |
| 2008-11-22 |
mantis -- session hijacking vulnerability |
| 2008-11-19 |
dovecot -- ACL plugin bypass vulnerabilities |
| libxml2 -- multiple vulnerabilities |
| openfire -- multiple vulnerabilities |
| 2008-11-18 |
enscript -- arbitrary code execution vulnerability |
| syslog-ng2 -- startup directory leakage in the chroot environment |
| 2008-11-16 |
gnutls -- X.509 certificate chain validation vulnerability |
| 2008-11-14 |
net-snmp -- DoS for SNMP agent via crafted GETBULK request |
| 2008-11-13 |
mozilla -- multiple vulnerabilities |
| 2008-11-12 |
faad2 -- heap overflow vulnerability |
| 2008-11-10 |
clamav -- off-by-one heap overflow in VBA project parser |
| 2008-11-09 |
trac -- potential DOS vulnerability |
| 2008-11-08 |
vlc -- cue processing stack overflow |
| 2008-11-07 |
emacs -- run-python vulnerability |
| 2008-11-03 |
opera -- multiple vulnerabilities |
| 2008-11-02 |
qemu -- Heap overflow in Cirrus emulation |
| 2008-10-31 |
phpmyadmin -- Cross-Site Scripting Vulnerability |
| 2008-10-28 |
opera -- multiple vulnerabilities |
| 2008-10-27 |
libspf2 -- Buffer overflow |
| 2008-10-25 |
flyspray -- multiple vulnerabilities |
| openx -- sql injection vulnerability |
| 2008-10-24 |
wordpress -- snoopy "_httpsrequest()" shell command execution vulnerability |
| 2008-10-22 |
drupal -- multiple vulnerabilities |
| wordpress -- remote privilege escalation |
| 2008-10-19 |
libxine -- denial of service vulnerability |
| 2008-10-17 |
linux-flashplugin -- multiple vulnerabilities |
| 2008-10-15 |
libxml2 -- two vulnerabilities |
| 2008-10-12 |
drupal -- multiple vulnerabilities |
| 2008-10-10 |
cups -- multiple vulnerabilities |
| opera -- multiple vulnerabilities |
| 2008-10-01 |
mplayer -- multiple integer overflows |
| mysql -- command line client input validation vulnerability |
| 2008-09-27 |
lighttpd -- multiple vulnerabilities |
| 2008-09-26 |
bitlbee -- account recreation security issues |
| 2008-09-24 |
mozilla -- multiple vulnerabilities |
| 2008-09-23 |
phpmyadmin -- Cross-Site Scripting Vulnerability |
| proftpd -- Long Command Processing Vulnerability |
| squirrelmail -- Session hijacking vulnerability |
| 2008-09-19 |
gallery -- multiple vulnerabilities |
| 2008-09-17 |
phpmyadmin -- Code execution vulnerability |
| 2008-09-14 |
twiki -- Arbitrary code execution in session files |
| 2008-09-12 |
clamav -- CHM Processing Denial of Service |
| neon -- NULL pointer dereference in Digest domain support |
| 2008-09-11 |
horde -- multiple vulnerabilities |
| 2008-09-10 |
mysql -- MyISAM table privileges security bypass vulnerability |
| python -- multiple vulnerabilities |
| rubygem-rails -- SQL injection vulnerability |
| 2008-09-05 |
FreeBSD -- amd64 swapgs local privilege escalation |
| FreeBSD -- nmount(2) local arbitrary code execution |
| FreeBSD -- Remote kernel panics on IPv6 connections |
| 2008-08-25 |
opera -- multiple vulnerabilities |
| 2008-08-21 |
gnutls -- "gnutls_handshake()" Denial of Service |
| 2008-08-20 |
joomla -- flaw in the reset token validation |
| 2008-08-19 |
cdf3 -- Buffer overflow vulnerability |
| 2008-08-18 |
drupal -- multiple vulnerabilities |
| 2008-08-16 |
ruby -- DNS spoofing vulnerability |
| ruby -- DoS vulnerability in WEBrick |
| ruby -- multiple vulnerabilities in safe level |
| 2008-08-15 |
Bugzilla -- Directory Traversal in importxml.pl |
| 2008-08-07 |
openvpn-devel -- arbitrary code execution |
| 2008-07-18 |
phpmyadmin -- cross site request forgery vulnerabilites |
| 2008-07-13 |
drupal -- multiple vulnerabilities |
| FreeBSD -- DNS cache poisoning |
| 2008-07-09 |
poppler -- uninitialized pointer |
| 2008-07-04 |
py-pylons -- Path traversal bug |
| 2008-07-03 |
FreeType 2 -- Multiple Vulnerabilities |
| 2008-07-01 |
fetchmail -- potential crash in -v -v verbose mode (revised patch) |
| 2008-06-28 |
phpmyadmin -- Cross Site Scripting Vulnerabilities |
| 2008-06-24 |
apache -- multiple vulnerabilities |
| 2008-06-22 |
php -- input validation error in safe_mode |
| 2008-06-21 |
ruby -- multiple integer and buffer overflow vulnerabilities |
| vim -- Vim Shell Command Injection Vulnerabilities |
| 2008-06-20 |
fetchmail -- potential crash in -v -v verbose mode |
| 2008-06-15 |
xorg -- multiple vulnerabilities |
| 2008-06-14 |
moinmoin -- superuser privilege escalation |
| 2008-06-13 |
Courier Authentication Library -- SQL Injection |
| 2008-06-01 |
ikiwiki -- cleartext passwords |
| 2008-05-31 |
ikiwiki -- empty password security hole |
| 2008-05-30 |
linux-flashplugin -- unspecified remote code execution vulnerability |
| 2008-05-28 |
Nagios -- Cross Site Scripting Vulnerability |
| 2008-05-27 |
spamdyke -- open relay |
| 2008-05-21 |
peercast -- arbitrary code execution |
| 2008-05-17 |
libvorbis -- various security issues |
| 2008-05-14 |
django -- XSS vulnerability |
| 2008-05-11 |
vorbis-tools -- Speex header processing vulnerability |
| 2008-05-08 |
qemu -- "drive_init()" Disk Format Security Bypass |
| 2008-05-07 |
swfdec -- exposure of sensitive information |
| 2008-05-02 |
mt-daapd -- integer overflow |
| sdl_image -- buffer overflow vulnerabilities |
| 2008-04-26 |
gnupg -- memory corruption vulnerability |
| 2008-04-25 |
extman -- password bypass vulnerability |
| firefox -- javascript garbage collector vulnerability |
| mailman -- script insertion vulnerability |
| mksh -- TTY attachment privilege escalation |
| openfire -- unspecified denial of service |
| php -- integer overflow vulnerability |
| png -- unknown chunk processing uninitialized memory access |
| python -- Integer Signedness Error in zlib Module |
| serendipity -- multiple cross site scripting vulnerabilities |
| 2008-04-24 |
libxine -- array index vulnerability |
| phpmyadmin -- Shared Host Information Disclosure |
| phpmyadmin -- Username/Password Session File Information Disclosure |
| postgresql -- multiple vulnerabilities |
| 2008-04-15 |
clamav -- Multiple Vulnerabilities |
| 2008-04-13 |
ikiwiki -- cross site request forging |
| lighttpd -- OpenSSL Error Queue Denial of Service Vulnerability |
| 2008-04-06 |
postfix-policyd-weight -- working directory symlink vulnerability |
| 2008-04-05 |
opera -- multiple vulnerabilities |
| powerdns-recursor -- DNS cache poisoning |
| suphp -- multiple local privilege escalation vulnerabilities |
| 2008-03-30 |
mozilla -- multiple vulnerabilities |
| 2008-03-26 |
silc -- pkcs_decode buffer overflow |
| 2008-03-20 |
bzip2 -- crash with certain malformed archive files |
| 2008-03-11 |
qemu -- unchecked block read/write vulnerability |
| 2008-03-10 |
dovecot -- security hole in blocking passdbs |
| 2008-03-06 |
mplayer -- multiple vulnerabilities |
| 2008-03-05 |
ghostscript -- zseticcspace() function buffer overflow vulnerability |
| 2008-03-04 |
phpmyadmin -- SQL injection vulnerability |
| 2008-02-29 |
pcre -- buffer overflow vulnerability |
| 2008-02-26 |
libxine -- buffer overflow vulnerability |
| 2008-02-25 |
coppermine - multiple vulnerabilities |
| moinmoin - multiple vulnerabilities |
| 2008-02-22 |
mozilla -- multiple vulnerabilities |
| openldap -- modrdn Denial of Service vulnerability |
| opera -- multiple vulnerabilities |
| 2008-02-15 |
clamav -- ClamAV libclamav PE File Integer Overflow Vulnerability |
| 2008-02-12 |
cacti -- Multiple security vulnerabilities have been discovered |
| 2008-02-11 |
ikiwiki -- javascript insertion via uris |
| 2008-02-09 |
zenphoto -- XSS vulnerability |
| 2008-02-04 |
jetty -- multiple vulnerability |
| 2008-01-29 |
libxine -- buffer overflow vulnerability |
| 2008-01-23 |
xorg -- multiple vulnerabilities |
| 2008-01-22 |
claws-mail -- insecure temporary file creation |
| xfce -- multiple vulnerabilities |
| 2008-01-19 |
IRC Services-- Denial of Service Vulnerability |
| libxine -- buffer overflow vulnerability |
| 2008-01-15 |
geeklog xss vulnerability |
| 2008-01-11 |
drupal -- cross site request forgery |
| drupal -- cross site scripting (register_globals) |
| drupal -- cross site scripting (utf8) |
| 2008-01-10 |
maradns -- CNAME record resource rotation denial of service |
| 2008-01-04 |
linux-realplayer -- multiple vulnerabilities |
| 2008-01-03 |
linux-flashplugin -- multiple vulnerabilities |
| 2007-12-29 |
dovecot -- Specific LDAP + auth cache configuration may mix up user logins |
| 2007-12-25 |
gallery2 -- multiple vulnerabilities |
| 2007-12-20 |
e2fsprogs -- heap buffer overflow |
| 2007-12-19 |
opera -- multiple vulnerabilities |
| peercast -- buffer overflow vulnerability |
| wireshark -- multiple vulnerabilities |
| 2007-12-17 |
ganglia-webfrontend -- XSS vulnerabilities |
| 2007-12-12 |
drupal -- SQL injection vulnerability |
| qemu -- Translation Block Local Denial of Service Vulnerability |
| samba -- buffer overflow vulnerability |
| smbftpd -- format string vulnerability |
| 2007-12-10 |
jetty -- multiple vulnerabilities |
| 2007-12-08 |
liveMedia -- DoS vulnerability |
| 2007-12-05 |
GNU finger vulnerability |
| 2007-12-04 |
Squid -- Denial of Service Vulnerability |
| 2007-11-28 |
rubygem-rails -- JSON XSS vulnerability |
| 2007-11-27 |
firefox -- multiple remote unspecified memory corruption vulnerabilities |
| ikiwiki -- improper symlink verification vulnerability |
| rubygem-rails -- session-fixation vulnerability |
| 2007-11-21 |
phpmyadmin -- Cross Site Scripting |
| samba -- multiple vulnerabilities |
| 2007-11-16 |
php -- multiple security vulnerabilities |
| 2007-11-13 |
flac -- media file processing integer overflow vulnerabilities |
| net-snmp -- denial of service via GETBULK request |
| 2007-11-12 |
mt-daapd -- denial of service vulnerability |
| plone -- unsafe data interpreted as pickles |
| xpdf -- multiple remote Stream.CC vulnerabilities |
| 2007-11-11 |
phpmyadmin -- cross-site scripting vulnerability |
| 2007-11-09 |
cups -- off-by-one buffer overflow |
| gallery2 -- multiple vulnerabilities |
| tikiwiki -- multiple vulnerabilities |
| 2007-11-06 |
pcre -- arbitrary code execution |
| perl -- regular expressions unicode data buffer overflow |
| 2007-11-05 |
gftp -- multiple vulnerabilities |
| perdition -- str_vwrite format string vulnerability |
| 2007-11-04 |
dircproxy -- remote denial of service |
| 2007-11-01 |
wordpress -- cross-site scripting |
| 2007-10-30 |
openldap -- multiple remote denial of service vulnerabilities |
| 2007-10-27 |
py-django -- denial of service vulnerability |
| 2007-10-25 |
opera -- multiple vulnerabilities |
| 2007-10-24 |
drupal --- multiple vulnerabilities |
| 2007-10-23 |
ldapscripts -- Command Line User Credentials Disclosure |
| 2007-10-22 |
firefox -- OnUnload Javascript browser entrapment vulnerability |
| 2007-10-17 |
phpmyadmin -- cross-site scripting vulnerability |
| 2007-10-16 |
phpmyadmin -- cross-site scripting vulnerability |
| 2007-10-11 |
nagios-plugins -- Long Location Header Buffer Overflow Vulnerability |
| png -- multiple vulnerabilities |
| 2007-10-10 |
ImageMagick -- multiple vulnerabilities |
| 2007-10-08 |
jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented |
| xfs -- multiple vulnerabilites |
| 2007-10-05 |
tcl/tk -- buffer overflow in ReadImage function |
| 2007-10-04 |
firebird -- multiple remote buffer overflow vulnerabilities |
| 2007-10-01 |
id3lib -- insecure temporary file creation |
| 2007-09-21 |
bugzilla -- multiple vulnerabilities |
| clamav -- multiple remote Denial of Service vulnerabilities |
| mediawiki -- cross site scripting vulnerability |
| samba -- nss_info plugin privilege escalation vulnerability |
| wordpress -- remote sql injection vulnerability |
| 2007-09-20 |
bugzilla -- "createmailregexp" security bypass vulnerability |
| coppermine -- multiple vulnerabilities |
| openoffice -- arbitrary command execution vulnerability |
| 2007-09-19 |
flyspray -- authentication bypass |
| kdm -- passwordless login vulnerability |
| konquerer -- address bar spoofing |
| mozilla -- code execution via Quicktime media-link files |
| 2007-09-11 |
apache -- multiple vulnerabilities |
| php -- multiple vulnerabilities |
| 2007-09-10 |
lighttpd -- FastCGI header overrun in mod_fastcgi |
| 2007-09-05 |
lsh -- multiple vulnerabilities |
| rkhunter -- insecure temporary file creation |
| 2007-09-02 |
fetchmail -- denial of service on reject of local warning message |
| 2007-09-01 |
gtar -- Directory traversal vulnerability |
| 2007-08-27 |
claws-mail -- POP3 Format String Vulnerability |
| 2007-08-21 |
rsync -- off by one stack overflow |
| 2007-08-15 |
opera -- Vulnerability in javascript handling |
| 2007-08-02 |
FreeBSD -- Buffer overflow in tcpdump(1) |
| FreeBSD -- Predictable query ids in named(8) |
| fsplib -- multiple vulnerabilities |
| joomla -- multiple vulnerabilities |
| 2007-07-31 |
xpdf -- stack based buffer overflow |
| 2007-07-29 |
mutt -- buffer overflow vulnerability |
| 2007-07-28 |
drupal -- Cross site request forgeries |
| drupal -- Multiple cross-site scripting vulnerabilities |
| p5-Net-DNS -- multiple Vulnerabilities |
| phpsysinfo -- url Cross-Site Scripting |
| 2007-07-27 |
vim -- Command Format String Vulnerability |
| 2007-07-26 |
libvorbis -- Multiple memory corruption flaws |
| 2007-07-24 |
dokuwiki -- XSS vulnerability in spellchecker backend |
| tomcat -- multiple vulnerabilities |
| tomcat -- XSS vulnerability in sample applications |
| 2007-07-21 |
lighttpd -- multiple vulnerabilities |
| 2007-07-19 |
mozilla -- multiple vulnerabilities |
| opera -- multiple vulnerabilities |
| 2007-07-18 |
linux-flashplugin -- critical vulnerabilities |
| 2007-07-06 |
wireshark -- Multiple problems |
| 2007-07-03 |
typespeed -- arbitrary code execution |
| 2007-06-29 |
gd -- multiple vulnerabilities |
| 2007-06-28 |
flac123 -- stack overflow in comment parsing |
| 2007-06-25 |
evolution-data-server -- remote execution of arbitrary code vulnerability |
| 2007-06-21 |
xpcd -- buffer overflow |
| 2007-06-19 |
clamav -- multiple vulnerabilities |
| 2007-06-18 |
p5-Mail-SpamAssassin -- local user symlink-attack DoS vulnerability |
| vlc -- format string vulnerability and integer overflow |
| 2007-06-12 |
cups -- Incomplete SSL Negotiation Denial of Service |
| 2007-06-09 |
c-ares -- DNS Cache Poisoning Vulnerability |
| webmin -- cross site scripting vulnerability |
| wordpress -- unmoderated comments disclosure |
| wordpress -- XMLRPC SQL Injection |
| 2007-06-07 |
mplayer -- cddb stack overflow |
| 2007-06-05 |
mod_jk -- information disclosure |
| 2007-06-04 |
phppgadmin -- cross site scripting vulnerability |
| typo3 -- email header injection |
| 2007-06-01 |
findutils -- GNU locate heap buffer overrun |
| 2007-05-24 |
FreeType 2 -- Heap overflow vulnerability |
| 2007-05-23 |
FreeBSD -- heap overflow in file(1) |
| 2007-05-21 |
squirrelmail -- Cross site scripting in HTML filter |
| 2007-05-16 |
png -- DoS crash vulnerability |
| samba -- multiple vulnerabilities |
| 2007-05-07 |
php -- multiple vulnerabilities |
| 2007-05-01 |
qemu - several vulnerabilities |
| 2007-04-30 |
p5-Imager - possibly exploitable buffer overflow |
| 2007-04-28 |
FreeBSD -- IPv6 Routing Header 0 is dangerous |
| 2007-04-24 |
mod_perl -- remote DoS in PATH_INFO parsing |
| 2007-04-19 |
claws-mail -- APOP vulnerability |
| 2007-04-14 |
lighttpd -- DOS when access files with mtime 0 |
| lighttpd -- Remote DOS in CRLF parsing |
| 2007-04-13 |
freeradius -- EAP-TTLS Tunnel Memory Leak Remote DOS Vulnerability |
| 2007-04-09 |
fetchmail -- insecure APOP authentication |
| 2007-04-08 |
mcweject -- exploitable buffer overflow |
| webcalendar -- "noSet" variable overwrite vulnerability |
| 2007-04-05 |
zope -- cross-site scripting vulnerability |
| 2007-03-21 |
Squid -- TRACE method handling denial of service |
| 2007-03-16 |
samba -- format string bug in afsacl.so VFS plugin |
| samba -- potential Denial of Service bug in smbd |
| sql-ledger -- security bypass vulnerability |
| 2007-03-11 |
ktorrent -- multiple vulnerabilities |
| 2007-03-09 |
mplayer -- DMO File Parsing Buffer Overflow Vulnerability |
| trac -- cross site scripting vulnerability |
| 2007-03-05 |
mod_jk -- long URL stack overflow vulnerability |
| 2007-02-27 |
bind -- Multiple Denial of Service vulnerabilities |
| FreeBSD -- Jail rc.d script privilege escalation |
| FreeBSD -- Kernel memory disclosure in firewire(4) |
| gtar -- name mangling symlink vulnerability |
| 2007-02-26 |
libarchive -- Infinite loop in corrupt archives handling in libarchive |
| OpenSSL -- Multiple problems in crypto(3) |
| 2007-02-24 |
mozilla -- multiple vulnerabilities |
| 2007-02-21 |
snort -- DCE/RPC preprocessor vulnerability |
| 2007-02-17 |
php -- multiple vulnerabilities |
| rar -- password prompt buffer overflow vulnerability |
| 2007-01-17 |
joomla -- multiple remote vulnerabilities |
| 2007-01-15 |
sircd -- remote operator privilege escalation vulnerability |
| sircd -- remote reverse DNS buffer overflow |
| 2007-01-12 |
cacti -- Multiple vulnerabilities |
| 2007-01-08 |
mplayer -- buffer overflow in the code for RealMedia RTSP streams. |
| 2007-01-06 |
fetchmail -- crashes when refusing a message bound for an MDA |
| fetchmail -- TLS enforcement problem/MITM attack/password exposure |
| 2007-01-05 |
drupal -- multiple vulnerabilities |
| opera -- multiple vulnerabilities |
| 2007-01-03 |
w3m -- format string vulnerability |
| 2006-12-27 |
plone -- user can masquerade as a group |
| 2006-12-21 |
proftpd -- remote code execution vulnerabilities |
| 2006-12-19 |
bind9 -- Denial of Service in named(8) |
| gzip -- multiple vulnerabilities |
| openssl -- Incorrect PKCS#1 v1.5 padding validation in crypto(3) |
| 2006-12-18 |
sql-ledger -- multiple vulnerabilities |
| 2006-12-14 |
dbus -- match_rule_equal() Weakness |
| evince -- Buffer Overflow Vulnerability |
| 2006-12-13 |
tdiary -- injection vulnerability |
| wv -- Multiple Integer Overflow Vulnerabilities |
| wv2 -- Integer Overflow Vulnerability |
| 2006-12-11 |
tnftpd -- Remote root Exploit |
| 2006-12-07 |
gnupg -- remotely controllable function pointer |
| libxine -- multiple buffer overflow vulnerabilities |
| 2006-12-04 |
ruby -- cgi.rb library Denial of Service |
| 2006-12-02 |
ImageMagick -- SGI Image File heap overflow vulnerability |
| libmusicbrainz -- multiple buffer overflow vulnerabilities |
| tdiary -- cross site scripting vulnerability |
| 2006-11-30 |
gtar -- GNUTYPE_NAMES directory traversal vulnerability |
| kronolith -- arbitrary local file inclusion vulnerability |
| 2006-11-27 |
gnupg -- buffer overflow |
| 2006-11-14 |
proftpd -- Remote Code Execution Vulnerability |
| unzoo -- Directory Traversal Vulnerability |
| 2006-11-11 |
bugzilla -- multiple vulnerabilities |
| 2006-11-08 |
Imlib2 -- multiple image file processing vulnerabilities |
| 2006-11-04 |
ruby -- cgi.rb library Denial of Service |
| 2006-10-29 |
mysql -- database "case-sensitive" privilege escalation |
| mysql -- database suid privilege escalation |
| screen -- combined UTF-8 characters vulnerability |
| 2006-10-22 |
kdelibs -- integer overflow in khtml |
| 2006-10-21 |
Serendipity -- XSS Vulnerabilities |
| 2006-10-20 |
asterisk -- remote heap overwrite vulnerability |
| opera -- URL parsing heap overflow vulnerability |
| 2006-10-19 |
plone -- unprotected MembershipTool methods |
| 2006-10-18 |
drupal -- cross site request forgeries |
| drupal -- HTML attribute injection |
| drupal -- multiple XSS vulnerabilities |
| ingo -- local arbitrary shell command execution |
| 2006-10-16 |
clamav -- CHM unpacker and PE rebuilding vulnerabilities |
| nvidia-driver -- arbitrary root code execution vulnerability |
| 2006-10-15 |
tkdiff -- temporary file symlink privilege escalation |
| vtiger -- multiple remote file inclusion vulnerabilities |
| 2006-10-14 |
google-earth -- heap overflow in the KML engine |
| 2006-10-12 |
clamav -- Multipart Nestings Denial of Service |
| 2006-10-07 |
python -- buffer overrun in repr() for unicode strings |
| torrentflux -- User-Agent XSS Vulnerability |
| 2006-10-06 |
php -- _ecalloc Integer Overflow Vulnerability |
| 2006-10-05 |
mambo -- multiple SQL injection vulnerabilities |
| mono -- "System.CodeDom.Compiler" Insecure Temporary Creation |
| openldap -- slapd acl selfwrite Security Issue |
| php -- open_basedir Race Condition Vulnerability |
| tin -- buffer overflow vulnerabilities |
| 2006-10-04 |
phpbb -- NULL byte injection vulnerability |
| 2006-10-03 |
postnuke -- admin section SQL injection |
| 2006-10-02 |
cscope -- Buffer Overflow Vulnerabilities |
| freetype -- LWFN Files Buffer Overflow Vulnerability |
| gnutls -- RSA Signature Forgery Vulnerability |
| MT -- Search Unspecified XSS |
| phpmyadmin -- XSRF vulnerabilities |
| 2006-09-30 |
dokuwiki -- multiple vulnerabilities |
| dokuwiki -- multiple vulnerabilities |
| openssh -- multiple vulnerabilities |
| punbb -- NULL byte injection vulnerability |
| tikiwiki -- multiple vulnerabilities |
| 2006-09-26 |
freeciv -- Denial of Service Vulnerabilities |
| freeciv -- Packet Parsing Denial of Service Vulnerability |
| plans -- multiple vulnerabilities |
| 2006-09-25 |
eyeOS -- multiple XSS security bugs |
| 2006-09-22 |
libmms -- stack-based buffer overflow |
| opera -- RSA Signature Forgery |
| zope -- restructuredText "csv_table" Information Disclosure |
| 2006-09-15 |
mozilla -- multiple vulnerabilities |
| 2006-09-14 |
win32-codecs -- multiple vulnerabilities |
| 2006-09-13 |
drupal-pubcookie -- authentication may be bypassed |
| php -- multiple vulnerabilities |
| 2006-09-12 |
linux-flashplugin7 -- arbitrary code execution vulnerabilities |
| 2006-09-04 |
mailman -- Multiple Vulnerabilities |
| 2006-09-02 |
gtetrinet -- remote code execution |
| hlstats -- multiple cross site scripting vulnerabilities |
| 2006-08-30 |
joomla -- multiple vulnerabilities |
| 2006-08-23 |
sppp -- buffer overflow vulnerability |
| 2006-08-17 |
horde -- Phishing and Cross-Site Scripting Vulnerabilities |
| 2006-08-15 |
globus -- Multiple tmpfile races |
| 2006-08-13 |
alsaplayer -- multiple vulnerabilities |
| mysql -- format string vulnerability |
| postgresql -- encoding based SQL injection |
| postgresql -- multiple vulnerabilities |
| x11vnc -- authentication bypass vulnerability |
| 2006-08-12 |
squirrelmail -- random variable overwrite vulnerability |
| 2006-08-10 |
rubygem-rails -- evaluation of ruby code |
| 2006-08-08 |
clamav -- heap overflow vulnerability |
| 2006-08-02 |
drupal -- XSS vulnerability |
| gnupg -- 2 more possible memory allocation attacks |
| 2006-07-29 |
ruby - multiple vulnerabilities |
| 2006-07-28 |
apache -- mod_rewrite buffer overflow vulnerability |
| 2006-07-27 |
mozilla -- multiple vulnerabilities |
| 2006-07-14 |
zope -- information disclosure vulnerability |
| 2006-07-13 |
drupal -- multiple vulnerabilities |
| 2006-07-11 |
shoutcast -- cross-site scripting, information exposure |
| 2006-07-10 |
samba -- memory exhaustion DoS in smbd |
| twiki -- multiple file extensions file upload vulnerability |
| 2006-07-07 |
trac -- reStructuredText breach of privacy and denial of service vulnerability |
| 2006-07-05 |
horde -- various problems in dereferrer |
| mambo -- SQL injection vulnerabilities |
| 2006-07-03 |
phpmyadmin -- cross site scripting vulnerability |
| 2006-07-02 |
webmin, usermin -- arbitrary file disclosure vulnerability |
| 2006-06-30 |
Joomla -- multiple vulnerabilities |
| mutt -- Remote Buffer Overflow Vulnerability |
| 2006-06-27 |
hashcash -- heap overflow vulnerability |
| 2006-06-25 |
gnupg -- user id integer overflow vulnerability |
| 2006-06-17 |
horde -- multiple parameter cross site scripting vulnerabilities |
| 2006-06-16 |
webcalendar -- information disclosure vulnerability |
| 2006-06-14 |
sendmail -- Incorrect multipart message handling |
| 2006-06-11 |
dokuwiki -- multiple vulnerabilities |
| libxine -- buffer overflow vulnerability |
| 2006-06-09 |
smbfs -- chroot escape |
| ypserv -- Inoperative access controls in ypserv |
| 2006-06-08 |
freeradius -- authentication bypass vulnerability |
| freeradius -- multiple vulnerabilities |
| 2006-06-05 |
dokuwiki -- spellchecker remote PHP code execution |
| drupal -- multiple vulnerabilities |
| squirrelmail -- plugin.php local file inclusion vulnerability |
| 2006-06-01 |
MySQL -- Information Disclosure and Buffer Overflow Vulnerabilities |
| MySQL -- SQL-injection security vulnerability |
| 2006-05-23 |
cscope -- buffer overflow vulnerabilities |
| frontpage -- cross site scripting vulnerability |
| 2006-05-22 |
coppermine -- "file" Local File Inclusion Vulnerability |
| coppermine -- File Inclusion Vulnerabilities |
| coppermine -- Multiple File Extensions Vulnerability |
| 2006-05-21 |
phpmyadmin -- XSRF vulnerabilities |
| 2006-05-18 |
vnc - authentication bypass vulnerability |
| 2006-05-14 |
phpldapadmin -- Cross-Site Scripting and Script Insertion vulnerabilities |
| 2006-05-06 |
fswiki -- XSS vulnerability |
| mysql50-server -- COM_TABLE_DUMP arbitrary code execution |
| 2006-05-05 |
awstats -- arbitrary command execution vulnerability |
| 2006-05-03 |
clamav -- Freshclam HTTP Header Buffer Overflow Vulnerability |
| firefox -- denial of service vulnerability |
| phpwebftp -- "language" Local File Inclusion |
| 2006-05-02 |
trac -- Wiki Macro Script Insertion Vulnerability |
| 2006-05-01 |
jabberd -- SASL Negotiation Denial of Service Vulnerability |
| 2006-04-27 |
amaya -- Attribute Value Buffer Overflow Vulnerabilities |
| cacti -- ADOdb "server.php" Insecure Test Script Security Issue |
| ethereal -- Multiple Protocol Dissector Vulnerabilities |
| lifetype -- ADOdb "server.php" Insecure Test Script Security Issue |
| 2006-04-25 |
asterisk -- denial of service vulnerability, local system access |
| 2006-04-23 |
crossfire-server -- denial of service and remote code execution vulnerability |
| p5-DBI -- insecure temporary file creation vulnerability |
| wordpress -- full path disclosure |
| xine -- multiple remote string vulnerabilities |
| zgv, xzgv -- heap overflow vulnerability |
| 2006-04-22 |
cyrus-sasl -- DIGEST-MD5 Pre-Authentication Denial of Service |
| 2006-04-19 |
FreeBSD -- FPU information disclosure |
| 2006-04-18 |
plone -- "member_id" Parameter Portrait Manipulation Vulnerability |
| 2006-04-16 |
mailman -- Private Archive Script Cross-Site Scripting |
| mozilla -- multiple vulnerabilities |
| 2006-04-10 |
f2c -- insecure temporary files |
| 2006-04-07 |
kaffeine -- buffer overflow vulnerability |
| mplayer -- Multiple integer overflows |
| thunderbird -- javascript execution |
| 2006-04-06 |
clamav -- Multiple Vulnerabilities |
| phpmyadmin -- 'set_theme' Cross-Site Scripting |
| phpmyadmin -- XSS vulnerabilities |
| 2006-04-05 |
dia -- XFig Import Plugin Buffer Overflow |
| mediawiki -- cross site scripting vulnerability |
| mediawiki -- hardcoded placeholder string security bypass vulnerability |
| mod_pubcookie -- cross site scripting vulnerability |
| netpbm -- buffer overflow in pnmtopng |
| openvpn -- LD_PRELOAD code execution on client through malicious or compromised server |
| pubcookie-login-server -- cross site scripting vulnerability |
| samba -- Exposure of machine account credentials in winbind log files |
| zoo -- stack based buffer overflow |
| 2006-03-29 |
freeradius -- EAP-MSCHAPv2 Authentication Bypass |
| 2006-03-28 |
horde -- remote code execution vulnerability in the help viewer |
| 2006-03-27 |
linux-realplayer -- buffer overrun |
| linux-realplayer -- heap overflow |
| 2006-03-24 |
ipsec -- reply attack vulnerability |
| OPIE -- arbitrary password change |
| sendmail -- race condition vulnerability |
| 2006-03-21 |
xorg-server -- privilege escalation |
| 2006-03-20 |
curl -- TFTP packet buffer overflow vulnerability |
| heimdal -- Multiple vulnerabilities |
| 2006-03-17 |
drupal -- multiple vulnerabilities |
| 2006-03-15 |
horde -- "url" disclosure of sensitive information vulnerability |
| linux-flashplugin -- arbitrary code execution vulnerability |
| 2006-03-12 |
nfs -- remote denial of service |
| openssh -- remote denial of service |
| 2006-03-10 |
GnuPG does not detect injection of unsigned data |
| 2006-03-09 |
mplayer -- heap overflow in the ASF demuxer |
| 2006-03-04 |
SSH.COM SFTP server -- format string vulnerability |
| 2006-03-03 |
gtar -- invalid headers buffer overflow |
| 2006-02-27 |
bugzilla -- multiple vulnerabilities |
| 2006-02-24 |
squirrelmail -- multiple vulnerabilities |
| 2006-02-20 |
abiword, koffice -- stack based buffer overflow vulnerabilities |
| gedit -- format string vulnerability |
| WebCalendar -- unauthorized access vulnerability |
| 2006-02-18 |
postgresql81-server -- SET ROLE privilege escalation |
| 2006-02-17 |
gnupg -- false positive signature verification |
| 2006-02-16 |
heartbeat -- insecure temporary file creation vulnerability |
| libtomcrypt -- weak signature scheme with ECC keys |
| mantis -- "view_filters_page.php" cross site scripting vulnerability |
| phpbb -- multiple vulnerabilities |
| postgresql -- character conversion and tsearch2 vulnerabilities |
| rssh -- privilege escalation vulnerability |
| sudo -- arbitrary command execution |
| tor -- malicious tor server can locate a hidden service |
| 2006-02-15 |
kpdf -- heap based buffer overflow |
| perl, webmin, usermin -- perl format string integer wrap vulnerability |
| phpicalendar -- cross site scripting vulnerability |
| phpicalendar -- file disclosure vulnerability |
| 2006-02-14 |
FreeBSD -- Infinite loop in SACK handling |
| FreeBSD -- Local kernel memory disclosure |
| IEEE 802.11 -- buffer overflow |
| ipfw -- IP fragment denial of service |
| pf -- IP fragment handling panic |
| 2006-02-07 |
kpopup -- local root exploit and local denial of service |
| 2006-01-27 |
cpio -- multiple vulnerabilities |
| cvsbug -- race condition |
| ee -- temporary file privilege escalation |
| texindex -- temporary file privilege escalation |
| 2006-01-23 |
fetchmail -- crash when bouncing a message |
| sge -- local root exploit in bundled rsh executable |
| 2006-01-10 |
clamav -- possible heap overflow in the UPX code |
| 2006-01-09 |
milter-bogom -- headerless message crash |
| 2006-01-07 |
bogofilter -- heap corruption through excessively long words |
| bogofilter -- heap corruption through malformed input |
| 2006-01-04 |
rxvt-unicode -- restore permissions on tty devices |
| 2006-01-01 |
apache -- mod_imap cross-site scripting flaw |
| 2005-12-22 |
nbd-server -- buffer overflow vulnerability |
| scponly -- local privilege escalation exploits |
| 2005-12-19 |
fetchmail -- null pointer dereference in multidrop mode with headerless email |
| 2005-12-14 |
mantis -- "t_core_path" file inclusion vulnerability |
| mantis -- "view_filters_page.php" cross-site scripting vulnerability |
| 2005-12-11 |
horde -- Cross site scripting vulnerabilities in several of Horde's templates |
| kronolith -- Cross site scripting vulnerabilities in several of the calendar name and event data fields |
| mnemo -- Cross site scripting vulnerabilities in several of the notepad name and note data fields |
| nag -- Cross site scripting vulnerabilities in several of the tasklist name and task data fields |
| turba -- Cross site scripting vulnerabilities in several of the address book name and contact data fields |
| 2005-12-09 |
curl -- URL buffer overflow vulnerability |
| 2005-12-07 |
ffmpeg -- libavcodec buffer overflow vulnerability |
| phpmyadmin -- register_globals emulation "import_blacklist" manipulation |
| phpmyadmin -- XSS vulnerabilities |
| trac -- search module SQL injection vulnerability |
| 2005-12-01 |
drupal -- multiple vulnerabilities |
| 2005-11-30 |
mambo -- "register_globals" emulation layer overwrite vulnerability |
| opera -- command line URL shell command injection |
| opera -- multiple vulnerabilities |
| 2005-11-27 |
ghostscript -- insecure temporary file creation vulnerability |
| 2005-11-22 |
horde -- Cross site scripting vulnerabilities in MIME viewers |
| 2005-11-16 |
phpmyadmin -- HTTP Response Splitting vulnerability |
| 2005-11-13 |
Macromedia flash player -- swf file handling arbitrary code |
| phpSysInfo -- "register_globals" emulation layer overwrite vulnerability |
| 2005-11-10 |
flyspray -- cross-site scripting vulnerabilities |
| p5-Mail-SpamAssassin -- long message header denial of service |
| 2005-11-07 |
qpopper -- multiple privilege escalation vulnerabilities |
| 2005-11-04 |
pear-PEAR -- PEAR installer arbitrary code execution vulnerability |
| 2005-11-01 |
openvpn -- arbitrary code execution on client through malicious or compromised server |
| openvpn -- potential denial-of-service on servers in TCP mode |
| PHP -- multiple vulnerabilities |
| skype -- multiple buffer overflow vulnerabilities |
| squid -- FTP server response handling denial of service |
| 2005-10-31 |
base -- PHP SQL injection vulnerability |
| 2005-10-30 |
fetchmail -- fetchmailconf local password exposure |
| lynx -- remote buffer overflow |
| 2005-10-27 |
ruby -- vulnerability in the safe level settings |
| 2005-10-20 |
xloadimage -- buffer overflows in NIFF image title handling |
| 2005-10-18 |
snort -- Back Orifice preprocessor buffer overflow vulnerability |
| 2005-10-15 |
gallery2 -- file disclosure vulnerability |
| webcalendar -- remote file inclusion vulnerability |
| 2005-10-12 |
openssl -- potential SSL 2.0 rollback |
| 2005-10-11 |
phpmyadmin -- local file inclusion vulnerability |
| zope -- expose RestructuredText functionality to untrusted users |
| 2005-10-09 |
libxine -- format string vulnerability |
| 2005-10-05 |
imap-uw -- mailbox name handling remote buffer vulnerability |
| 2005-10-02 |
picasm -- buffer overflow vulnerability |
| weex -- remote format string vulnerability |
| 2005-10-01 |
cfengine -- arbitrary file overwriting vulnerability |
| uim -- privilege escalation vulnerability |
| 2005-09-29 |
phpmyfaq -- SQL injection, takeover, path disclosure, remote code execution |
| 2005-09-24 |
clamav -- arbitrary code execution and DoS vulnerabilities |
| 2005-09-23 |
firefox & mozilla -- multiple vulnerabilities |
| 2005-09-22 |
firefox & mozilla -- command line URL shell command injection |
| 2005-09-17 |
apache -- Certificate Revocation List (CRL) off-by-one vulnerability |
| squirrelmail -- _$POST variable handling allows for various attacks |
| 2005-09-15 |
squid -- possible denial of service condition regarding NTLM authentication |
| X11 server -- pixmap allocation vulnerability |
| 2005-09-13 |
unzip -- permission race vulnerability |
| 2005-09-10 |
firefox & mozilla -- buffer overflow vulnerability |
| 2005-09-04 |
htdig -- cross site scripting vulnerability |
| squid -- Denial Of Service Vulnerability in sslConnectTimeout |
| squid -- Possible Denial Of Service Vulnerability in store.c |
| 2005-09-03 |
bind -- buffer overrun vulnerability |
| bind9 -- denial of service |
| 2005-09-02 |
urban -- stack overflow vulnerabilities |
| 2005-08-29 |
fswiki - command injection vulnerability |
| 2005-08-27 |
evolution -- remote format string vulnerabilities |
| pam_ldap -- authentication bypass vulnerability |
| 2005-08-26 |
pcre -- regular expression buffer overflow |
| 2005-08-23 |
elm -- remote buffer overflow in Expires header |
| 2005-08-19 |
openvpn -- denial of service: client certificate validation can disconnect unrelated clients |
| openvpn -- denial of service: malicious authenticated "tap" client can deplete server virtual memory |
| openvpn -- denial of service: undecryptable packet from authorized client can disconnect unrelated clients |
| openvpn -- multiple TCP clients connecting with the same certificate at the same time can crash the server |
| 2005-08-17 |
tor -- diffie-hellman handshake flaw |
| 2005-08-16 |
acroread -- plug-in buffer overflow vulnerability |
| 2005-08-15 |
pear-XML_RPC -- remote PHP code injection vulnerability |
| 2005-08-14 |
awstats -- arbitrary code execution vulnerability |
| 2005-08-12 |
gaim -- AIM/ICQ away message buffer overflow |
| gaim -- AIM/ICQ non-UTF-8 filename crash |
| libgadu -- multiple vulnerabilities |
| xpdf -- disk fill DoS vulnerability |
| 2005-08-09 |
gforge -- XSS and email flood vulnerabilities |
| 2005-08-08 |
postnuke -- multiple vulnerabilities |
| 2005-08-05 |
devfs -- ruleset bypass |
| ipsec -- Incorrect key usage in AES-XCBC-MAC |
| mambo -- multiple vulnerabilities |
| zlib -- buffer overflow vulnerability |
| 2005-08-03 |
proftpd -- format string vulnerabilities |
| 2005-08-01 |
nbsmtp -- format string vulnerability |
| 2005-07-31 |
gnupg -- OpenPGP symmetric encryption vulnerability |
| phpmyadmin -- cross site scripting vulnerability |
| sylpheed -- MIME-encoded file name buffer overflow vulnerability |
| vim -- vulnerabilities in modeline handling: glob, expand |
| 2005-07-30 |
ethereal -- multiple protocol dissectors vulnerabilities |
| jabberd -- 3 buffer overflows |
| opera -- download dialog spoofing vulnerability |
| opera -- image dragging vulnerability |
| tiff -- buffer overflow vulnerability |
| 2005-07-26 |
apache -- http request smuggling |
| 2005-07-25 |
clamav -- multiple remote buffer overflows |
| 2005-07-23 |
egroupware -- multiple cross-site scripting (XSS) and SQL injection vulnerabilities |
| isc-dhcpd -- format string vulnerabilities |
| 2005-07-22 |
fetchmail -- denial of service/crash from malicious POP3 server |
| 2005-07-21 |
dnrd -- remote buffer and stack overflow vulnerabilities |
| PowerDNS -- LDAP backend fails to escape all queries |
| 2005-07-20 |
fetchmail -- remote root/code injection from malicious POP3 server |
| 2005-07-18 |
kdebase -- Kate backup file permission leak |
| 2005-07-16 |
drupal -- PHP code execution vulnerabilities |
| firefox & mozilla -- multiple vulnerabilities |
| 2005-07-09 |
mysql-server -- insecure temporary file creation |
| net-snmp -- fixproc insecure temporary file creation |
| phpbb -- multiple vulnerabilities |
| phpSysInfo -- cross site scripting vulnerability |
| shtool -- insecure temporary file creation |
| 2005-07-08 |
bugzilla -- multiple vulnerabilities |
| ekg -- insecure temporary file creation |
| nwclient -- multiple vulnerabilities |
| pear-XML_RPC -- information disclosure vulnerabilities |
| phppgadmin -- "formLanguage" local file inclusion vulnerability |
| 2005-07-06 |
acroread -- buffer overflow vulnerability |
| acroread -- insecure temporary file creation |
| clamav -- cabinet file handling DoS vulnerability |
| clamav -- MS-Expand file handling DoS vulnerability |
| zlib -- buffer overflow vulnerability |
| 2005-07-05 |
cacti -- multiple vulnerabilities |
| net-snmp -- remote DoS vulnerability |
| wordpress -- multiple vulnerabilities |
| wordpress -- multiple vulnerabilities |
| 2005-07-03 |
pear-XML_RPC -- arbitrary remote code execution |
| phpbb -- remote PHP code execution vulnerability |
| 2005-06-29 |
bzip2 -- denial of service and permission race vulnerabilities |
| kernel -- ipfw packet matching errors with address tables |
| kernel -- TCP connection stall denial of service |
| 2005-06-24 |
ethereal -- multiple protocol dissectors vulnerabilities |
| linux-realplayer -- RealText parsing heap overflow |
| tor -- information disclosure |
| 2005-06-23 |
ruby -- arbitrary command execution on XMLRPC server |
| 2005-06-21 |
cacti -- potential SQL injection and cross site scripting attacks |
| 2005-06-20 |
opera -- "javascript:" URL cross-site scripting vulnerability |
| opera -- redirection cross-site scripting vulnerability |
| opera -- XMLHttpRequest security bypass |
| razor-agents -- denial of service vulnerability |
| sudo -- local race condition vulnerability |
| trac -- file upload/download vulnerability |
| 2005-06-18 |
acroread -- XML External Entity vulnerability |
| gzip -- directory traversal and permission race vulnerabilities |
| p5-Mail-SpamAssassin -- denial of service vulnerability |
| squirrelmail -- Several cross site scripting vulnerabilities |
| tcpdump -- infinite loops in protocol decoding |
| 2005-06-17 |
fd_set -- bitmap index overflow in multiple applications |
| gaim -- MSN Remote DoS vulnerability |
| gaim -- Yahoo! remote crash vulnerability |
| gallery -- cross-site scripting |
| gallery -- remote code injection via HTTP_POST_VARS |
| kstars -- exploitable set-user-ID application fliccd |
| 2005-06-09 |
leafnode -- denial of service vulnerability |
| 2005-06-03 |
gforge -- directory traversal vulnerability |
| imap-uw -- authentication bypass when CRAM-MD5 is enabled |
| racoon -- remote denial-of-service |
| squid -- denial-of-service vulnerabilities |
| xli -- integer overflows in image size calculations |
| xloadimage -- arbitrary command execution when handling compressed files |
| xloadimage -- buffer overflow in FACES image handling |
| yamt -- buffer overflow and directory traversal issues |
| 2005-06-01 |
linux_base -- vulnerabilities in Red Hat 7.1 libraries |
| mailman -- generated passwords are poor quality |
| mailman -- password disclosure |
| squirrelmail -- XSS and remote code injection vulnerabilities |
| sympa -- buffer overflow in "queue" |
| tomcat -- Tomcat Manager cross-site scripting |
| xtrlock -- X display locking bypass |
| xview -- multiple buffer overflows in xv_parse_one |
| 2005-05-29 |
fswiki -- XSS problem in file upload form |
| 2005-05-22 |
freeradius -- sql injection and denial of service vulnerability |
| oops -- format string vulnerability |
| ppxp -- local root exploit |
| 2005-05-19 |
cdrdao -- unspecified privilege escalation vulnerability |
| squid -- DNS lookup spoofing vulnerability |
| squid -- possible abuse of cachemgr.cgi |
| 2005-05-14 |
gaim -- MSN remote DoS vulnerability |
| gaim -- remote crash on some protocols |
| 2005-05-13 |
kernel -- information disclosure when using HTT |
| leafnode -- fetchnews denial-of-service triggered by transmission abort/timeout |
| 2005-05-12 |
mozilla -- "Wrapped" javascript: urls bypass security checks |
| mozilla -- privilege escalation via non-DOM property overrides |
| 2005-05-11 |
mozilla -- code execution via javascript: IconURL vulnerability |
| 2005-05-09 |
groff -- groffer uses temporary files unsafely |
| groff -- pic2graph and eqn2graph are vulnerable to symlink attack through temporary files |
| 2005-05-01 |
coppermine -- IP spoofing and XSS vulnerability |
| rsnapshot -- local privilege escalation |
| sharutils -- unshar insecure temporary file creation |
| 2005-04-27 |
ImageMagick -- ReadPNMImage() heap overflow vulnerability |
| 2005-04-25 |
gaim -- AIM/ICQ remote denial of service vulnerability |
| gaim -- remote DoS on receiving malformed HTML |
| mplayer & libxine -- MMS and Real RTSP buffer overflow vulnerabilities |
| 2005-04-23 |
kdewebdev -- kommander untrusted code execution vulnerability |
| 2005-04-22 |
junkbuster -- heap corruption vulnerability and configuration modification vulnerability |
| kdelibs -- kimgio input validation errors |
| 2005-04-19 |
gld -- format string and buffer overflow vulnerabilities |
| 2005-04-17 |
axel -- remote buffer overflow |
| 2005-04-16 |
firefox -- arbitrary code execution in sidebar panel |
| firefox -- PLUGINSPAGE privileged javascript execution |
| jdk -- jar directory traversal vulnerability |
| mozilla -- code execution through javascript: favicons |
| mozilla -- javascript "lambda" replace exposes memory contents |
| mozilla -- privilege escalation via DOM property overrides |
| 2005-04-13 |
openoffice -- DOC document heap overflow vulnerability |
| 2005-04-12 |
portupgrade -- insecure temporary file handling vulnerability |
| 2005-04-10 |
gaim -- jabber remote crash |
| gaim -- remote DoS on receiving certain messages over IRC |
| gaim -- remote DoS on receiving malformed HTML |
| php -- readfile() DoS vulnerability |
| squid -- DoS on failed PUT/POST requests vulnerability |
| 2005-04-05 |
horde -- Horde Page Title Cross-Site Scripting Vulnerability |
| 2005-04-04 |
wu-ftpd -- remote globbing DoS vulnerability |
| 2005-04-02 |
hashcash -- format string vulnerability |
| 2005-03-26 |
clamav -- zip handling DoS vulnerability |
| 2005-03-24 |
firefox -- arbitrary code execution from sidebar panel |
| mozilla -- heap buffer overflow in GIF image processing |
| wine -- information disclosure due to insecure temporary file handling |
| 2005-03-23 |
sylpheed -- buffer overflow in header processing |
| 2005-03-21 |
kdelibs -- local DCOP denial of service vulnerability |
| xv -- filename handling format string vulnerability |
| 2005-03-15 |
phpmyadmin -- increased privilege vulnerability |
| 2005-03-14 |
ethereal -- multiple protocol dissectors vulnerabilities |
| grip -- CDDB response multiple matches buffer overflow vulnerability |
| mysql-server -- multiple remote vulnerabilities |
| 2005-03-13 |
rxvt-unicode -- buffer overflow vulnerability |
| 2005-03-08 |
libexif -- buffer overflow vulnerability |
| phpmyadmin -- arbitrary file include and XSS vulnerabilities |
| phpmyadmin -- information disclosure vulnerability |
| 2005-03-05 |
phpbb - Insuffient check against HTML code in usercp_register.php |
| 2005-03-04 |
postnuke -- cross-site scripting (XSS) vulnerabilities |
| postnuke -- SQL injection vulnerabilities |
| realplayer -- remote heap overflow |
| 2005-03-03 |
ImageMagick -- format string vulnerability |
| 2005-03-01 |
lighttpd -- script source disclosure vulnerability |
| uim -- privilege escalation vulnerability |
| 2005-02-28 |
phpbb -- privilege elevation and path disclosure |
| 2005-02-27 |
curl -- authentication buffer overflow vulnerability |
| cyrus-imapd -- multiple buffer overflow vulnerabilities |
| sup -- format string vulnerability |
| 2005-02-26 |
mozilla -- arbitrary code execution vulnerability |
| mozilla -- insecure temporary directory vulnerability |
| 2005-02-24 |
mkbold-mkitalic -- format string vulnerability |
| 2005-02-23 |
phpbb -- multiple information disclosure vulnerabilities |
| 2005-02-22 |
unace -- multiple vulnerabilities |
| 2005-02-20 |
putty -- pscp/psftp heap corruption vulnerabilities |
| 2005-02-18 |
bidwatcher -- format string vulnerability |
| gftp -- directory traversal vulnerability |
| kdelibs -- insecure temporary file creation |
| opera -- "data:" URI handler spoofing vulnerability |
| opera -- kfmclient exec command execution vulnerability |
| 2005-02-17 |
postgresql -- multiple buffer overflows in PL/PgSQL parser |
| 2005-02-16 |
awstats -- arbitrary command execution |
| 2005-02-14 |
emacs -- movemail format string vulnerability |
| powerdns -- DoS vulnerability |
| 2005-02-13 |
mod_python -- information leakage vulnerability |
| ngircd -- buffer overflow vulnerability |
| ngircd -- format string vulnerability |
| 2005-02-12 |
mailman -- directory traversal vulnerability |
| 2005-02-11 |
enscript -- multiple vulnerabilities |
| 2005-02-08 |
ethereal -- multiple protocol dissectors vulnerabilities |
| postgresql -- privilege escalation vulnerability |
| squid -- correct handling of oversized HTTP reply headers |
| 2005-02-03 |
python -- SimpleXMLRPCServer.py allows unrestricted traversal |
| 2005-02-02 |
perl -- vulnerabilities in PERLIO_DEBUG handling |
| 2005-02-01 |
newsfetch -- server response buffer overflow vulnerability |
| newsgrab -- directory traversal vulnerability |
| newsgrab -- insecure file and directory creation |
| newspost -- server response buffer overflow vulnerability |
| 2005-01-28 |
squid -- buffer overflow in WCCP recvfrom() call |
| 2005-01-26 |
xpdf -- makeFileKey2() buffer overflow vulnerability |
| 2005-01-25 |
evolution -- arbitrary code execution vulnerability |
| zhcon -- unauthorized file access |
| 2005-01-24 |
bugzilla -- cross-site scripting vulnerability |
| mod_dosevasive -- insecure temporary file creation |
| opera -- multiple vulnerabilities in Java implementation |
| squid -- possible cache-poisoning via malformed HTTP responses |
| web browsers -- window injection vulnerabilities |
| 2005-01-23 |
yamt -- arbitrary command execution vulnerability |
| 2005-01-22 |
horde -- XSS vulnerabilities |
| squid -- HTTP response splitting cache pollution attack |
| 2005-01-21 |
egroupware -- arbitrary file download in JiNN |
| fcron -- multiple vulnerabilities |
| imlib -- xpm heap buffer overflows and integer overflows |
| mc -- multiple vulnerabilities |
| perl -- File::Path insecure file/directory permissions |
| quake2 -- multiple critical vulnerabilities |
| realplayer -- arbitrary file deletion and other vulnerabilities |
| sudo -- environmental variable CDPATH is not cleared |
| 2005-01-19 |
konversation -- shell script command injection |
| squid -- no sanity check of usernames in squid_ldap_auth |
| 2005-01-18 |
awstats -- remote command execution vulnerability |
| cups-base -- CUPS server remote DoS vulnerability |
| ImageMagick -- PSD handler heap overflow vulnerability |
| mozilla -- insecure permissions for some downloaded files |
| tiff -- divide-by-zero denial-of-service |
| zgv -- exploitable heap overflows |
| 2005-01-17 |
cups-base -- HPGL buffer overflow vulnerability |
| cups-lpr -- lppasswd multiple vulnerabilities |
| 2005-01-16 |
mysql-scripts -- mysqlaccess insecure temporary file creation |
| unrtf -- buffer overflow vulnerability |
| 2005-01-13 |
mozilla -- heap overflow in NNTP handler |
| mpg123 -- buffer overflow vulnerability |
| 2005-01-12 |
libxine -- DVD subpicture decoder heap overflow |
| libxine -- multiple buffer overflows in RTSP |
| libxine -- multiple vulnerabilities in VideoCD handling |
| squid -- buffer overflow vulnerability in gopherToHTML |
| squid -- denial of service with forged WCCP messages |
| 2005-01-11 |
hylafax -- unauthorized login vulnerability |
| xshisen -- local buffer overflows |
| 2005-01-10 |
helvis -- arbitrary file deletion problem |
| helvis -- information leak vulnerabilities |
| 2005-01-08 |
dillo -- format string vulnerability |
| 2005-01-07 |
tnftp -- mget does not check for directory escapes |
| 2005-01-06 |
pcal -- buffer overflow vulnerabilities |
| tiff -- directory entry count integer overflow vulnerability |
| tiff -- tiffdump integer overflow vulnerability |
| vim -- vulnerabilities in modeline handling |
| 2005-01-05 |
exim -- two buffer overflow vulnerabilities |
| 2005-01-03 |
golddig -- local buffer overflow vulnerabilities |
| greed -- insecure GRX file processing |
| mpg123 -- playlist processing buffer overflow vulnerability |
| 2005-01-02 |
up-imapproxy -- multiple vulnerabilities |
| 2005-01-01 |
kdelibs3 -- konqueror FTP command injection vulnerability |
| 2004-12-30 |
a2ps -- insecure temporary file creation |
| 2004-12-29 |
libxine -- buffer-overflow vulnerability in aiff support |
| 2004-12-26 |
jabberd -- denial-of-service vulnerability |
| 2004-12-23 |
ethereal -- multiple vulnerabilities |
| squid -- confusing results on empty acl declarations |
| xpdf -- buffer overflow vulnerability |
| 2004-12-22 |
phpbb -- arbitrary command execution and other vulnerabilities |
| 2004-12-21 |
acroread5 -- mailListIsPdf() buffer overflow vulnerability |
| ecartis -- unauthorised access to admin interface |
| krb5 -- heap buffer overflow vulnerability in libkadm5srv |
| mplayer -- multiple vulnerabilities |
| samba -- integer overflow vulnerability |
| 2004-12-17 |
php -- multiple vulnerabilities |
| 2004-12-16 |
mysql -- ALTER MERGE denial of service vulnerability |
| mysql -- erroneous access restrictions applied to table renames |
| mysql -- FTS request denial of service vulnerability |
| mysql -- GRANT access restriction problem |
| mysql -- mysql_real_connect buffer overflow vulnerability |
| 2004-12-15 |
phpmyadmin -- command execution vulnerability |
| phpmyadmin -- file disclosure vulnerability |
| 2004-12-14 |
wget -- multiple vulnerabilities |
| 2004-12-12 |
konqueror -- Password Disclosure for SMB Shares |
| 2004-12-11 |
mod_access_referer -- null pointer dereference vulnerability |
| 2004-12-09 |
squid -- possible information disclosure |
| 2004-12-08 |
viewcvs -- information leakage |
| 2004-12-07 |
cscope -- symlink attack vulnerability |
| 2004-12-04 |
bnc -- remotely exploitable buffer overflow in getnickuserhost |
| 2004-12-02 |
rockdodger -- buffer overflows |
| rssh & scponly -- arbitrary command execution |
| 2004-12-01 |
sudoscript -- signal delivery vulnerability |
| zip -- long path buffer overflow |
| 2004-11-30 |
jabberd -- remote buffer overflow vulnerability |
| 2004-11-27 |
Open DC Hub -- remote buffer overflow vulnerability |
| 2004-11-26 |
unarj -- directory traversal vulnerability |
| unarj -- long filename buffer overflow |
| 2004-11-25 |
jdk/jre -- Security Vulnerability With Java Plugin |
| ProZilla -- server response buffer overflow vulnerabilities |
| 2004-11-22 |
Cyrus IMAPd -- APPEND command uses undefined programming construct |
| Cyrus IMAPd -- FETCH command out of bounds memory corruption |
| Cyrus IMAPd -- IMAPMAGICPLUS preauthentification overflow |
| Cyrus IMAPd -- PARTIAL command out of bounds memory corruption |
| 2004-11-20 |
phpMyAdmin -- cross-site scripting vulnerabilities |
| 2004-11-18 |
Overflow error in fetch |
| 2004-11-17 |
smbd -- buffer-overrun vulnerability |
| 2004-11-15 |
proxytunnel -- format string vulnerability |
| twiki -- arbitrary shell command execution |
| 2004-11-13 |
ruby -- CGI DoS |
| sudo -- privilege escalation with bash scripts |
| 2004-11-12 |
gnats -- format string vulnerability |
| samba -- potential remote DoS vulnerability |
| squirrelmail -- cross site scripting vulnerability |
| 2004-11-11 |
ez-ipupdate -- format string vulnerability |
| hafiye -- lack of terminal escape sequence filtering |
| ImageMagick -- EXIF parser buffer overflow |
| 2004-11-10 |
apache2 multiple space header denial-of-service vulnerability |
| socat -- format string vulnerability |
| 2004-11-09 |
libxml -- remote buffer overflows |
| 2004-11-08 |
p5-Archive-Zip -- virus detection evasion |
| 2004-11-06 |
apache mod_include buffer overflow vulnerability |
| postgresql-contrib -- insecure temporary file creation |
| 2004-11-05 |
gd -- integer overflow |
| 2004-11-04 |
putty -- buffer overflow vulnerability in ssh2 support |
| 2004-11-03 |
wzdftpd -- remote DoS |
| 2004-10-27 |
horde -- cross-site scripting vulnerability in help window |
| 2004-10-26 |
bogofilter -- RFC 2047 decoder denial-of-service vulnerability |
| 2004-10-25 |
gaim -- buffer overflow in MSN protocol support |
| gaim -- Content-Length header denial-of-service vulnerability |
| gaim -- heap overflow exploitable by malicious GroupWise server |
| gaim -- malicious smiley themes |
| gaim -- MSN denial-of-service vulnerabilities |
| gaim -- multiple buffer overflows |
| rssh -- format string vulnerability |
| xpdf -- integer overflow vulnerabilities |
| 2004-10-23 |
mod_ssl -- SSLCipherSuite bypass |
| mpg123 -- buffer overflow in URL handling |
| 2004-10-21 |
apache2 -- SSL remote DoS |
| 2004-10-20 |
a2ps -- insecure command line argument handling |
| cabextract -- insecure directory handling |
| phpmyadmin -- remote command execution vulnerability |
| 2004-10-19 |
ifmail -- unsafe set-user-ID application |
| imwheel -- insecure handling of PID file |
| 2004-10-17 |
apache13-modssl -- format string vulnerability in proxy support |
| cacti -- SQL injection |
| 2004-10-15 |
tor -- remote DoS and loss of anonymity |
| 2004-10-13 |
CUPS -- local information disclosure |
| freeradius -- denial-of-service vulnerability |
| icecast -- Cross-Site Scripting Vulnerability |
| icecast -- HTTP header overflow |
| sharutils -- buffer overflows |
| tiff -- multiple integer overflows |
| tiff -- RLE decoder heap overflows |
| wordpress -- XSS in administration panel |
| xerces-c2 -- Attribute blowup denial-of-service |
| 2004-10-12 |
cyrus-sasl -- potential buffer overflow in DIGEST-MD5 plugin |
| mail-notification -- denial-of-service vulnerability |
| squid -- SNMP module denial-of-service vulnerability |
| zinf -- potential buffer overflow playlist support |
| 2004-10-08 |
cyrus-sasl -- dynamic library loading and set-user-ID applications |
| 2004-10-05 |
bmon -- unsafe set-user-ID application |
| gnutls -- certificate chain verification DoS |
| imp3 -- XSS hole in the HTML viewer |
| php -- php_variables memory disclosure |
| xv -- exploitable buffer overflows |
| 2004-10-04 |
Boundary checking errors in syscons |
| getmail -- symlink vulnerability during maildir delivery |
| 2004-10-03 |
distcc -- incorrect parsing of IP access control rules |
| racoon -- improper certificate handling |
| 2004-09-30 |
mozilla -- hostname spoofing bug |
| mozilla -- scripting vulnerabilities |
| mozilla -- users may be lured into bypassing security dialogs |
| samba -- remote file disclosure |
| 2004-09-28 |
mozilla -- BMP decoder vulnerabilities |
| mozilla -- multiple heap buffer overflows |
| mozilla -- vCard stack buffer overflow |
| 2004-09-27 |
php -- memory_limit related vulnerability |
| php -- strip_tags cross-site scripting vulnerability |
| 2004-09-26 |
subversion -- WebDAV fails to protect metadata |
| 2004-09-23 |
lha -- numerous vulnerabilities when extracting archives |
| mysql -- heap buffer overflow with prepared statements |
| 2004-09-22 |
mozilla -- automated file upload |
| mozilla -- built-in CA certificates may be overridden |
| mozilla -- NULL bytes in FTP URLs |
| mozilla -- security icon spoofing |
| 2004-09-21 |
rssh -- file name disclosure bug |
| 2004-09-20 |
gnu-radius -- SNMP-related denial-of-service |
| sudo -- sudoedit information disclosure |
| 2004-09-19 |
apache -- heap overflow in mod_proxy |
| 2004-09-15 |
apache -- ap_resolve_env buffer overflow |
| apache -- apr_uri_parse IPv6 address handling vulnerability |
| cups -- print queue browser denial-of-service |
| gdk-pixbuf -- image decoding vulnerabilities |
| mod_dav -- lock related denial-of-service |
| php -- vulnerability in RFC 1867 file upload processing |
| xpm -- image decoding vulnerabilities |
| 2004-09-14 |
mozilla -- POP client heap overflow |
| mozilla -- SOAPParameter integer overflow |
| mpg123 buffer overflow |
| openoffice -- document disclosure |
| samba3 DoS attack |
| webmin -- insecure temporary file creation at installation time |
| 2004-08-31 |
ImageMagick -- BMP decoder buffer overflow |
| imlib -- BMP decoder heap buffer overflow |
| imlib2 -- BMP decoder buffer overflow |
| krb5 -- ASN.1 decoder denial-of-service vulnerability |
| krb5 -- double-free vulnerabilities |
| 2004-08-27 |
nss -- exploitable buffer overflow in SSLv2 protocol handler |
| ripMIME -- decoding bug allowing content filter bypass |
| 2004-08-26 |
gnomevfs -- unsafe URI handling |
| kdelibs -- konqueror cross-domain cookie injection |
| moinmoin -- ACL group bypass |
| rsync -- path sanitizing vulnerability |
| SoX buffer overflows when handling .WAV files |
| 2004-08-23 |
SpamAssassin -- denial-of-service in tokenize_headers |
| 2004-08-22 |
courier-imap -- format string vulnerability in debug mode |
| fidogate -- write files as `news' user |
| mysql -- mysqlhotcopy insecure temporary file creation |
| qt -- image loader vulnerabilities |
| 2004-08-17 |
cvs -- numerous vulnerabilities |
| tnftpd -- remotely exploitable vulnerability |
| 2004-08-16 |
Ruby insecure file permissions in the CGI session management |
| squid -- NTLM authentication denial-of-service vulnerability |
| 2004-08-13 |
Arbitrary code execution via a format string vulnerability in jftpgw |
| 2004-08-12 |
acroread uudecoder input validation error |
| gaim remotely exploitable vulnerabilities in MSN component |
| kdelibs insecure temporary file handling |
| Mutiple browser frame injection vulnerability |
| popfile file disclosure |
| 2004-08-04 |
ImageMagick png vulnerability fix |
| libpng stack-based buffer overflow and other code concerns |
| 2004-07-30 |
Mozilla / Firefox user interface spoofing vulnerability |
| Mozilla certificate spoofing |
| 2004-07-21 |
Multiple Potential Buffer Overruns in Samba |
| 2004-07-11 |
multiple vulnerabilities in ethereal |
| multiple vulnerabilities in ethereal |
| 2004-07-05 |
"Content-Type" XSS vulnerability affecting other webmail systems |
| Format string vulnerability in SSLtelnet |
| MySQL authentication bypass / buffer overflow |
| 2004-07-03 |
Pavuk HTTP Location header overflow |
| Several vulnerabilities found in PHPNuke |
| 2004-07-02 |
GNATS local privilege elevation |
| Remote code injection in phpMyAdmin |
| 2004-06-30 |
Linux binary compatibility mode input validation error |
| 2004-06-28 |
MoinMoin administrative group name privilege escalation vulnerability |
| XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0 |
| 2004-06-25 |
isc-dhcp3-server buffer overflow in logging mechanism |
| Remote Denial of Service of HTTP server and client |
| 2004-06-24 |
Gallery 1.4.3 and ealier user authentication bypass |
| 2004-06-09 |
Buffer overflow in Squid NTLM authentication helper |
| 2004-06-07 |
jailed processes can manipulate host routing tables |
| 2004-05-26 |
buffer cache invalidation implementation issues |
| 2004-05-21 |
leafnode denial-of-service triggered by article request |
| leafnode fetchnews denial-of-service triggered by missing header |
| leafnode fetchnews denial-of-service triggered by truncated transmission |
| 2004-05-19 |
cvs pserver remote heap buffer overflow |
| neon date parsing vulnerability |
| subversion date parsing vulnerability |
| 2004-05-18 |
URI handler vulnerabilities in several browsers |
| 2004-05-12 |
Cyrus IMAP pre-authentication heap overflow vulnerability |
| Cyrus IMSPd multiple vulnerabilities |
| 2004-05-06 |
exim buffer overflow when verify = header_syntax is used |
| phpBB session table exhaustion |
| 2004-05-05 |
heimdal kadmind remote heap buffer overflow |
| 2004-05-02 |
lha buffer overflows and path traversal issues |
| libpng denial-of-service |
| Midnight Commander buffer overflows, format string bugs, and insecure temporary file handling |
| pound remotely exploitable vulnerability |
| proftpd IP address access control list breakage |
| rsync path traversal issue |
| xine-lib arbitrary file overwrite |
| 2004-04-23 |
ident2 double byte buffer overflow |
| phpBB IP address spoofing |
| TCP denial-of-service attacks against long lived connections |
| xchat remotely exploitable buffer overflow (Socks5) |
| 2004-04-16 |
MySQL insecure temporary file creation (mysqlbug) |
| 2004-04-15 |
kdepim exploitable buffer overflow in VCF reader |
| neon format string vulnerabilities |
| 2004-04-14 |
CVS path validation errors |
| racoon remote denial of service vulnerability (ISAKMP header length field) |
| 2004-04-07 |
jailed processes can attach to other jails |
| many out-of-sequence TCP packets denial-of-service |
| mksnap_ffs clears file system options |
| racoon fails to verify signature during Phase 1 |
| racoon remote denial of service vulnerability (IKE Generic Payload Header) |
| shmat reference counting bug |
| 2004-04-03 |
Midnight Commander buffer overflow during symlink resolution |
| 2004-04-02 |
Incorrect cross-realm trust handling in Heimdal |
| 2004-03-31 |
Courier mail services: remotely exploitable buffer overflows |
| isakmpd payload handling denial-of-service vulnerabilities |
| mplayer heap overflow in http requests |
| tcpdump ISAKMP payload handling remote denial-of-service |
| 2004-03-29 |
ecartis buffer overflows and input validation bugs |
| setsockopt(2) IPv6 sockets input validation error |
| zebra/quagga denial of service vulnerability |
| 2004-03-28 |
Buffer overflows and format string bugs in Emil |
| Critical SQL injection in phpBB |
| oftpd denial-of-service vulnerability (PORT command) |
| 2004-03-26 |
ezbounce remote format string vulnerability |
| insecure temporary file creation in xine-check, xine-bugreport |
| multiple vulnerabilities in ethereal |
| multiple vulnerabilities in phpBB |
| squid ACL bypass due to URL decoding bug |
| 2004-03-25 |
racoon security association deletion vulnerability |
| 2004-03-18 |
uudeview buffer overflows |
| 2004-03-17 |
ModSecurity for Apache 2.x remote off-by-one overflow |
| OpenSSL ChangeCipherSpec denial-of-service vulnerability |
| 2004-03-08 |
Apache 1.3 IP address access control failure on some 64-bit platforms |
| Apache 2 mod_ssl denial-of-service |
| wu-ftpd ftpaccess `restricted-uid'/`restricted-gid' directive may be bypassed |
| 2004-03-07 |
mpg123 vulnerabilities |
| 2004-03-06 |
GNU Anubis buffer overflows and format string vulnerabilities |
| 2004-03-05 |
multiple buffer overflows in xboing |
| 2004-03-03 |
mod_python denial-of-service vulnerability in parse_qs |
| 2004-02-25 |
Darwin Streaming Server denial-of-service vulnerability |
| fetchmail denial-of-service vulnerability |
| hsftp format string vulnerabilities |
| lbreakout2 vulnerability in environment variable handling |
| libxml2 stack buffer overflow in URI parsing |
| mailman denial-of-service vulnerability in MailCommandHandler |
| mailman XSS in admin script |
| mailman XSS in create script |
| mailman XSS in user options page |
| SQL injection vulnerability in phpnuke |
| 2004-02-22 |
file disclosure in phpMyAdmin |
| Vulnerabilities in H.323 implementations |
| 2004-02-18 |
metamail format string bugs and buffer overflows |
| 2004-02-15 |
mnGoSearch buffer overflow in UdmDocToTextBuf() |
| 2004-02-13 |
GNU libtool insecure temporary file handling |
| 2004-02-12 |
Buffer overflow in Mutt 1.4 |
| Buffer overflows in XFree86 servers |
| CCE contains exploitable buffer overflows |
| ChiTeX/ChiLaTeX unsafe set-user-id root |
| clamav remote denial-of-service |
| icecast 1.x multiple vulnerabilities |
| nap allows arbitrary file access |
| pine insecure URL handling |
| pine remote denial-of-service attack |
| pine remotely exploitable buffer overflow in newmail.c |
| pine remotely exploitable vulnerabilities |
| rsync buffer overflow in server mode |
| Samba 3.0.x password initialization bug |
| seti@home remotely exploitable buffer overflow |
| Several remotely exploitable buffer overflows in gaim |
| 2004-02-10 |
Apache-SSL optional client certificate vulnerability |
| 2004-01-19 |
fsp buffer overflow and directory traversal vulnerabilities |
| L2TP, ISAKMP, and RADIUS parsing vulnerabilities in tcpdump |
| 2004-01-08 |
Buffer overflow in INN control message handling |
| 2004-01-05 |
ProFTPD ASCII translation bug resulting in remote root compromise |
| 2003-12-12 |
bind8 negative cache poison attack |
| ElGamal sign+encrypt keys created by GnuPG can be compromised |
| lftp HTML parsing vulnerability |
| Mathopd buffer overflow |
| qpopper format string vulnerability |
| 2003-10-25 |
Buffer overflow in pam_smb password handling |
| Buffer overflows in libmcrypt |
| Fetchmail address parsing vulnerability |