gmane.comp.security.bugtraq archive
397 archived articles, newest first (page 1 of 4). Latest articles →
APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10
Mon, 17 Aug 2026 15:00:58 -0700[ES2023-01] Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
Fri, 15 Dec 2023 13:27:06 +0100Asterisk Release 20.3.1
Fri, 07 Jul 2023 20:10:00 +0000Asterisk Release certified-18.9-cert5
Fri, 07 Jul 2023 19:39:14 +0000Asterisk Release 19.8.1
Fri, 07 Jul 2023 19:08:25 +0000Asterisk Release 18.18.1
Fri, 07 Jul 2023 19:07:40 +0000Asterisk Release 16.30.1
Fri, 07 Jul 2023 19:01:15 +0000S2-064: CVE-2023-34396: Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Wed, 14 Jun 2023 07:35:56 +0000S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds
Wed, 14 Jun 2023 07:34:50 +0000Defense in depth -- the Microsoft way (part 84): (no) fun with %COMSPEC%
Wed, 22 Mar 2023 19:50:40 +0100Re: Defense in depth -- the Microsoft way (part 83): instead to fix even their most stupid mistaskes, they spill barrels of snakeoil to cover them (or just leave them as-is)
Fri, 17 Mar 2023 08:18:03 +0100 (GMT+01:00)Defense in depth -- the Microsoft way (part 83): instead to fix even their most stupid mistaskes, they spill barrels of snakeoil to cover them (or just leave them as-is)
Wed, 15 Mar 2023 13:39:22 +0100Defense in depth -- the Microsoft way (part 82): INVALID/BOGUS AppLocker rules disable SAFER on Windows 11 22H2
Wed, 22 Feb 2023 18:26:24 +0100Defense in depth -- the Microsoft way (part 81): enabling UTF-8 support breaks existing code
Fri, 10 Feb 2023 14:22:42 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2022-0011
Mon, 26 Dec 2022 18:15:30 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2022-0010
Fri, 4 Nov 2022 14:58:14 +0100Re: WebKitGTK and WPE WebKit Security Advisory WSA-2022-0009
Tue, 20 Sep 2022 14:19:08 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2022-0009
Mon, 19 Sep 2022 14:44:45 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2022-0008
Thu, 25 Aug 2022 23:34:04 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2022-0007
Thu, 28 Jul 2022 22:32:00 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2022-0006
Tue, 5 Jul 2022 13:16:55 +0200XML External Entity (XXE) vulnerability in the WSO2 Management Console
Mon, 6 Jun 2022 17:37:11 +0300WebKitGTK and WPE WebKit Security Advisory WSA-2022-0005
Mon, 30 May 2022 15:06:36 +0100Defense in depth -- the Microsoft way (part 80): 25 (in words: TWENTY-FIVE) year old TRIVIAL bug crashes CMD.exe
Tue, 10 May 2022 17:01:51 +0200[SECURITY][ANNOUNCE] Apache Subversion 1.14.2 released
Tue, 12 Apr 2022 06:54:47 -0400[SECURITY][ANNOUNCE] Apache Subversion 1.10.8 released
Tue, 12 Apr 2022 06:54:32 -0400WebKitGTK and WPE WebKit Security Advisory WSA-2022-0004
Fri, 8 Apr 2022 14:31:29 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2022-0003
Thu, 17 Feb 2022 18:50:04 +0000WebKitGTK and WPE WebKit Security Advisory WSA-2022-0002
Wed, 9 Feb 2022 13:23:18 +0000Re: WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001
Mon, 31 Jan 2022 18:49:31 +0000WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001
Fri, 21 Jan 2022 16:53:45 +0000WebKitGTK and WPE WebKit Security Advisory WSA-2021-0007
Mon, 20 Dec 2021 14:16:15 +0000WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006
Tue, 26 Oct 2021 20:05:36 +0100[ES2021-07] FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
Mon, 25 Oct 2021 16:24:18 +0200[ES2021-09] FreeSWITCH susceptible to Denial of Service via invalid SRTP packets
Mon, 25 Oct 2021 16:24:15 +0200[ES2021-06] FreeSWITCH susceptible to Denial of Service via SIP flooding
Mon, 25 Oct 2021 16:24:13 +0200[ES2021-08] FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
Mon, 25 Oct 2021 16:24:09 +0200[ES2021-05] FreeSWITCH vulnerable to SIP digest leak for configured gateways
Mon, 25 Oct 2021 16:24:03 +0200Defense in depth -- the Microsoft way (part 79): Local Privilege Escalation via Windows 11 Installation Assistant
Thu, 14 Oct 2021 20:47:54 +0200Defense in depth -- the Microsoft way (part 78): completely outdated, vulnerable open source component(s) shipped with Windows 10&11
Wed, 13 Oct 2021 01:18:46 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2021-0005
Mon, 20 Sep 2021 12:49:39 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2021-0004
Fri, 23 Jul 2021 16:17:54 +0100[KIS-2021-04] IPS Community Suite <= 4.5.4.2 (previewBlock) PHP Code Injection Vulnerability
Fri, 28 May 2021 19:15:34 +0200Defense in depth -- the Microsoft way (part 77): access without access permission
Fri, 14 May 2021 19:03:59 +0200Defense in depth -- The Microsoft way (part 76): arbitrary code execution WITH elevation of privilege in user-writable directories below %SystemRoot%
Thu, 29 Apr 2021 17:50:42 +0200Defense in depth -- the Microsoft way (part 75): Bypass of SAFER alias Software Restriction Policies NOT FIXED
Thu, 29 Apr 2021 17:15:44 +0200Executable installers are vulnerable^WEVIL (case 61): arbitrary code execution WITH escalation of privilege via Intel WiFi drivers
Wed, 21 Apr 2021 20:18:56 +0200Defense in depth -- The Microsoft way (part 74): Windows Defender SmartScreen is rather DUMP, it allows denial of service
Fri, 2 Apr 2021 23:06:07 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2021-0003
Mon, 29 Mar 2021 23:38:05 +0200CVE-2018-3635 revisited: executable installers are vulnerable^WEVIL (case 60): again arbitrary code execution WITH escalation of privilege via Intel Rapid Storage Technology User Interface and Driver
Tue, 23 Mar 2021 19:31:53 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002
Mon, 22 Mar 2021 20:41:36 +0100[KIS-2021-03] ExpressionEngine <= 6.0.2 (Translate::save) PHP Code Injection Vulnerability
Mon, 15 Mar 2021 20:13:46 +0100ES2021-04: VoIPmonitor static builds are c ompiled without any standard memory corruption protection
Mon, 15 Mar 2021 13:50:26 +0100ES2021-03: VoIPmonitor is vulnerable to a buffer overflow when using the live sniffer
Mon, 15 Mar 2021 13:48:26 +0100ES2021-02: VoIPmonitor WEB GUI vulnerable to Cross-Site Scripting via SIP messages
Mon, 15 Mar 2021 13:46:43 +0100Data Manipulation with X-Forwarded-For header at WordPress
Tue, 9 Mar 2021 13:18:08 +0300Defense in depth -- the Microsoft way (part 73): ignorance (of security advisories) is bliss!
Mon, 8 Mar 2021 21:00:41 +0100Unholy CRAP: Moziila's executable installers
Fri, 5 Mar 2021 23:45:45 +0100Advisory ID: VMSA-2021-0002
Fri, 5 Mar 2021 18:22:53 +0800Defense in depth -- the Microsof way (part 72): "compatibility" trumps security
Wed, 3 Mar 2021 18:54:28 +0100Online Tool for Discussion of Vulnerabilities
Tue, 23 Feb 2021 22:07:21 +0300[KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability
Sat, 20 Feb 2021 02:18:16 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2021-0001
Mon, 15 Feb 2021 16:26:27 +0100SEC Consult SA-20210210-0 :: Reflected Cross-Site Scripting in Adobe Magento Commerce
Wed, 10 Feb 2021 14:53:43 +0100[SECURITY][ANNOUNCE] Apache Subversion 1.10.7 released
Wed, 10 Feb 2021 14:37:00 +0100[SECURITY][ANNOUNCE] Apache Subversion 1.14.1 released
Wed, 10 Feb 2021 14:36:33 +0100X41 D-Sec GmbH Security Advisory X41-2021-001: Multiple Vulnerabilities in YARA
Fri, 29 Jan 2021 11:12:40 +0100Re: [SECURITY] [DSA 4628-1] php7.0 security update
Sat, 16 Jan 2021 03:40:23 GMTRe: BugTraq Shutdown
Sat, 16 Jan 2021 09:02:28 GMTOn Second Thought...
17 Jan 2021 01:25:13 -0000BugTraq Shutdown
15 Jan 2021 19:08:11 -0000Advisory: ES2021-01 - Loopback access cont rol bypass in coturn by using 0.0.0.0, [::1] or [::] as the peer address
Mon, 11 Jan 2021 15:10:13 +0100Defense in depth -- the Microsoft way (part 68): where compatibility means vulnerability
Tue, 15 Dec 2020 22:00:02 +0100Apache Struts 2: CVE-2020-17530: Potential RCE when using forced evaluation
Tue, 8 Dec 2020 07:55:04 +0100[ANN] [SECURITY] Potential RCE when using forced evaluation - CVE-2020-17530
Tue, 8 Dec 2020 07:55:04 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2020-0009
Mon, 30 Nov 2020 19:04:24 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2020-0008
Mon, 23 Nov 2020 17:50:25 +0100Advisory: ES2020-02 - Asterisk crash due to INVITE flood over TCP
Fri, 06 Nov 2020 11:16:38 +0100Kamailio vulnerable to header smuggling possible due to bypass of remove_hf
Tue, 01 Sep 2020 11:08:36 +0200CVE-2016-3427 Apache Cassandra Unspecified vulnerability related to JMX
Mon, 31 Aug 2020 17:03:52 -0500WebKitGTK and WPE WebKit Security Advisory WSA-2020-0007
Wed, 29 Jul 2020 12:40:42 +0200Defense in depth -- the Microsoft way (part 70): CVE-2014-0315 alias MS14-019 revisited
Thu, 23 Jul 2020 23:40:48 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2020-0006
Fri, 10 Jul 2020 13:25:18 +0200X41 D-Sec GmbH Security Advisory X41-2020-006: Memory Corruption Vulnerability in bspatch
Thu, 9 Jul 2020 18:42:53 +0200SEC Consult SA-20200701-0 :: Reflected Cross-Site Scripting (XSS) in EQDKP Plus CMS
Wed, 1 Jul 2020 16:40:13 +0000[KIS-2020-06] openSIS <= 7.4 Incorrect Access Control Vulnerabilities
Tue, 30 Jun 2020 15:25:06 +0200[KIS-2020-08] openSIS <= 7.4 Multiple SQL Injection Vulnerabilities
Tue, 30 Jun 2020 15:27:30 +0200[KIS-2020-07] openSIS <= 7.4 (Bottom.php) Local File Inclusion Vulnerability
Tue, 30 Jun 2020 15:25:50 +0200[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection
Fri, 19 Jun 2020 20:31:22 +0200[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection
Fri, 19 Jun 2020 20:31:22 +0200Defense in depth -- the Microsoft way (part 69): security remarks are as futile as the qUACkery!
Wed, 3 Jun 2020 15:50:59 +0200Defense in depth -- the Microsoft way (part 68): qUACkery is futile!
Wed, 3 Jun 2020 15:40:19 +0200TP-LINK Cloud Cameras NCXXX SetEncryptKey Command Injection
Wed, 29 Apr 2020 23:47:12 +0100TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key
Wed, 29 Apr 2020 23:44:43 +0100TP-LINK Cloud Cameras NCXXX Bonjour Command Injection
Wed, 29 Apr 2020 23:43:28 +0100WebKitGTK and WPE WebKit Security Advisory WSA-2020-0005
Mon, 27 Apr 2020 19:12:24 +0200WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004
Thu, 16 Apr 2020 14:10:59 +0200Defense in depth -- the Microsoft way (part 67): we maintain 20 year old bugs since we don't care about our customers safety and security
Mon, 13 Apr 2020 17:42:01 +0200SEC Consult SA-20200407-0 :: Multiple XSS vulnerabilities in TAO Open Source Assessment Platform
Tue, 7 Apr 2020 16:56:45 +0200Defense in depth -- the Microsoft way (part 66): attachment manager allows to load arbitrary DLLs
Sat, 28 Mar 2020 01:07:04 +0100
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.