gmane.comp.security.bugtraq archive

397 archived articles, newest first (page 1 of 4). Latest articles →

APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10
Mon, 17 Aug 2026 15:00:58 -0700
Apple Product Security via Fulldisclosure <[email protected]> • #62222
[ES2023-01] Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
Fri, 15 Dec 2023 13:27:06 +0100
"Sandro Gauci" <[email protected]> • #62221
Asterisk Release 20.3.1
Fri, 07 Jul 2023 20:10:00 +0000
Asterisk Development Team <[email protected]> • #62220
Asterisk Release certified-18.9-cert5
Fri, 07 Jul 2023 19:39:14 +0000
Asterisk Development Team <[email protected]> • #62219
Asterisk Release 19.8.1
Fri, 07 Jul 2023 19:08:25 +0000
Asterisk Development Team <[email protected]> • #62218
Asterisk Release 18.18.1
Fri, 07 Jul 2023 19:07:40 +0000
Asterisk Development Team <[email protected]> • #62217
Asterisk Release 16.30.1
Fri, 07 Jul 2023 19:01:15 +0000
Asterisk Development Team <[email protected]> • #62216
S2-064: CVE-2023-34396: Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Wed, 14 Jun 2023 07:35:56 +0000
Yasser Zamani <[email protected]> • #62215
S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds
Wed, 14 Jun 2023 07:34:50 +0000
Yasser Zamani <[email protected]> • #62214
Defense in depth -- the Microsoft way (part 84): (no) fun with %COMSPEC%
Wed, 22 Mar 2023 19:50:40 +0100
"Stefan Kanthak" <[email protected]> • #62213
Re: Defense in depth -- the Microsoft way (part 83): instead to fix even their most stupid mistaskes, they spill barrels of snakeoil to cover them (or just leave them as-is)
Fri, 17 Mar 2023 08:18:03 +0100 (GMT+01:00)
Arik Seils <[email protected]> • #62212
Defense in depth -- the Microsoft way (part 83): instead to fix even their most stupid mistaskes, they spill barrels of snakeoil to cover them (or just leave them as-is)
Wed, 15 Mar 2023 13:39:22 +0100
"Stefan Kanthak" <[email protected]> • #62211
Defense in depth -- the Microsoft way (part 82): INVALID/BOGUS AppLocker rules disable SAFER on Windows 11 22H2
Wed, 22 Feb 2023 18:26:24 +0100
"Stefan Kanthak" <[email protected]> • #62210
Defense in depth -- the Microsoft way (part 81): enabling UTF-8 support breaks existing code
Fri, 10 Feb 2023 14:22:42 +0100
"Stefan Kanthak" <[email protected]> • #62209
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0011
Mon, 26 Dec 2022 18:15:30 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62208
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0010
Fri, 4 Nov 2022 14:58:14 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62207
Re: WebKitGTK and WPE WebKit Security Advisory WSA-2022-0009
Tue, 20 Sep 2022 14:19:08 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62206
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0009
Mon, 19 Sep 2022 14:44:45 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62205
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0008
Thu, 25 Aug 2022 23:34:04 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62204
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0007
Thu, 28 Jul 2022 22:32:00 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62203
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0006
Tue, 5 Jul 2022 13:16:55 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62202
XML External Entity (XXE) vulnerability in the WSO2 Management Console
Mon, 6 Jun 2022 17:37:11 +0300
Hakan Bayır ( Biznet Bilişim ) <hakan.bayir-bwKeqTGMmZm/[email protected]> • #62201
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0005
Mon, 30 May 2022 15:06:36 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62200
Defense in depth -- the Microsoft way (part 80): 25 (in words: TWENTY-FIVE) year old TRIVIAL bug crashes CMD.exe
Tue, 10 May 2022 17:01:51 +0200
"Stefan Kanthak" <[email protected]> • #62199
[SECURITY][ANNOUNCE] Apache Subversion 1.14.2 released
Tue, 12 Apr 2022 06:54:47 -0400
"[email protected]" <[email protected]> • #62198
[SECURITY][ANNOUNCE] Apache Subversion 1.10.8 released
Tue, 12 Apr 2022 06:54:32 -0400
"[email protected]" <[email protected]> • #62197
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0004
Fri, 8 Apr 2022 14:31:29 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62196
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0003
Thu, 17 Feb 2022 18:50:04 +0000
Carlos Alberto Lopez Perez <[email protected]> • #62195
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0002
Wed, 9 Feb 2022 13:23:18 +0000
Carlos Alberto Lopez Perez <[email protected]> • #62194
Re: WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001
Mon, 31 Jan 2022 18:49:31 +0000
Carlos Alberto Lopez Perez <[email protected]> • #62193
WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001
Fri, 21 Jan 2022 16:53:45 +0000
Carlos Alberto Lopez Perez <[email protected]> • #62192
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0007
Mon, 20 Dec 2021 14:16:15 +0000
Carlos Alberto Lopez Perez <[email protected]> • #62191
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006
Tue, 26 Oct 2021 20:05:36 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62190
[ES2021-07] FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
Mon, 25 Oct 2021 16:24:18 +0200
"Sandro Gauci" <[email protected]> • #62189
[ES2021-09] FreeSWITCH susceptible to Denial of Service via invalid SRTP packets
Mon, 25 Oct 2021 16:24:15 +0200
"Sandro Gauci" <[email protected]> • #62188
[ES2021-06] FreeSWITCH susceptible to Denial of Service via SIP flooding
Mon, 25 Oct 2021 16:24:13 +0200
"Sandro Gauci" <[email protected]> • #62187
[ES2021-08] FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
Mon, 25 Oct 2021 16:24:09 +0200
"Sandro Gauci" <[email protected]> • #62186
[ES2021-05] FreeSWITCH vulnerable to SIP digest leak for configured gateways
Mon, 25 Oct 2021 16:24:03 +0200
"Sandro Gauci" <[email protected]> • #62185
Defense in depth -- the Microsoft way (part 79): Local Privilege Escalation via Windows 11 Installation Assistant
Thu, 14 Oct 2021 20:47:54 +0200
"Stefan Kanthak" <[email protected]> • #62184
Defense in depth -- the Microsoft way (part 78): completely outdated, vulnerable open source component(s) shipped with Windows 10&11
Wed, 13 Oct 2021 01:18:46 +0200
"Stefan Kanthak" <[email protected]> • #62183
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0005
Mon, 20 Sep 2021 12:49:39 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62182
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0004
Fri, 23 Jul 2021 16:17:54 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62181
[KIS-2021-04] IPS Community Suite <= 4.5.4.2 (previewBlock) PHP Code Injection Vulnerability
Fri, 28 May 2021 19:15:34 +0200
[email protected] • #62180
Defense in depth -- the Microsoft way (part 77): access without access permission
Fri, 14 May 2021 19:03:59 +0200
"Stefan Kanthak" <[email protected]> • #62179
Defense in depth -- The Microsoft way (part 76): arbitrary code execution WITH elevation of privilege in user-writable directories below %SystemRoot%
Thu, 29 Apr 2021 17:50:42 +0200
"Stefan Kanthak" <[email protected]> • #62178
Defense in depth -- the Microsoft way (part 75): Bypass of SAFER alias Software Restriction Policies NOT FIXED
Thu, 29 Apr 2021 17:15:44 +0200
"Stefan Kanthak" <[email protected]> • #62177
Executable installers are vulnerable^WEVIL (case 61): arbitrary code execution WITH escalation of privilege via Intel WiFi drivers
Wed, 21 Apr 2021 20:18:56 +0200
"Stefan Kanthak" <[email protected]> • #62176
Defense in depth -- The Microsoft way (part 74): Windows Defender SmartScreen is rather DUMP, it allows denial of service
Fri, 2 Apr 2021 23:06:07 +0200
"Stefan Kanthak" <[email protected]> • #62175
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0003
Mon, 29 Mar 2021 23:38:05 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62174
CVE-2018-3635 revisited: executable installers are vulnerable^WEVIL (case 60): again arbitrary code execution WITH escalation of privilege via Intel Rapid Storage Technology User Interface and Driver
Tue, 23 Mar 2021 19:31:53 +0100
"Stefan Kanthak" <[email protected]> • #62173
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002
Mon, 22 Mar 2021 20:41:36 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62172
[KIS-2021-03] ExpressionEngine <= 6.0.2 (Translate::save) PHP Code Injection Vulnerability
Mon, 15 Mar 2021 20:13:46 +0100
[email protected] • #62171
ES2021-04: VoIPmonitor static builds are c ompiled without any standard memory corruption protection
Mon, 15 Mar 2021 13:50:26 +0100
"Sandro Gauci" <[email protected]> • #62170
ES2021-03: VoIPmonitor is vulnerable to a buffer overflow when using the live sniffer
Mon, 15 Mar 2021 13:48:26 +0100
"Sandro Gauci" <[email protected]> • #62169
ES2021-02: VoIPmonitor WEB GUI vulnerable to Cross-Site Scripting via SIP messages
Mon, 15 Mar 2021 13:46:43 +0100
"Sandro Gauci" <[email protected]> • #62168
Data Manipulation with X-Forwarded-For header at WordPress
Tue, 9 Mar 2021 13:18:08 +0300
Alphan YAVAS <[email protected]> • #62167
Defense in depth -- the Microsoft way (part 73): ignorance (of security advisories) is bliss!
Mon, 8 Mar 2021 21:00:41 +0100
"Stefan Kanthak" <[email protected]> • #62166
Unholy CRAP: Moziila's executable installers
Fri, 5 Mar 2021 23:45:45 +0100
"Stefan Kanthak" <[email protected]> • #62165
Advisory ID: VMSA-2021-0002
Fri, 5 Mar 2021 18:22:53 +0800
"☆月,缺也☆" <[email protected]> • #62164
Defense in depth -- the Microsof way (part 72): "compatibility" trumps security
Wed, 3 Mar 2021 18:54:28 +0100
"Stefan Kanthak" <[email protected]> • #62163
Online Tool for Discussion of Vulnerabilities
Tue, 23 Feb 2021 22:07:21 +0300
Yavuz <[email protected]> • #62162
[KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability
Sat, 20 Feb 2021 02:18:16 +0100
[email protected] • #62161
WebKitGTK and WPE WebKit Security Advisory WSA-2021-0001
Mon, 15 Feb 2021 16:26:27 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62160
SEC Consult SA-20210210-0 :: Reflected Cross-Site Scripting in Adobe Magento Commerce
Wed, 10 Feb 2021 14:53:43 +0100
SEC Consult Vulnerability Lab <research-SOMWcJgVuhyHT8/[email protected]> • #62159
[SECURITY][ANNOUNCE] Apache Subversion 1.10.7 released
Wed, 10 Feb 2021 14:37:00 +0100
Stefan Sperling <[email protected]> • #62158
[SECURITY][ANNOUNCE] Apache Subversion 1.14.1 released
Wed, 10 Feb 2021 14:36:33 +0100
Stefan Sperling <[email protected]> • #62157
X41 D-Sec GmbH Security Advisory X41-2021-001: Multiple Vulnerabilities in YARA
Fri, 29 Jan 2021 11:12:40 +0100
X41 D-Sec GmbH Advisories <[email protected]> • #62156
Re: [SECURITY] [DSA 4628-1] php7.0 security update
Sat, 16 Jan 2021 03:40:23 GMT
[email protected] • #62155
Re: BugTraq Shutdown
Sat, 16 Jan 2021 09:02:28 GMT
[email protected] • #62154
On Second Thought...
17 Jan 2021 01:25:13 -0000
[email protected] • #62153
BugTraq Shutdown
15 Jan 2021 19:08:11 -0000
[email protected] • #62152
Advisory: ES2021-01 - Loopback access cont rol bypass in coturn by using 0.0.0.0, [::1] or [::] as the peer address
Mon, 11 Jan 2021 15:10:13 +0100
"Sandro Gauci" <[email protected]> • #62151
Defense in depth -- the Microsoft way (part 68): where compatibility means vulnerability
Tue, 15 Dec 2020 22:00:02 +0100
"Stefan Kanthak" <[email protected]> • #62150
Apache Struts 2: CVE-2020-17530: Potential RCE when using forced evaluation
Tue, 8 Dec 2020 07:55:04 +0100
Lukasz Lenart <[email protected]> • #62149
[ANN] [SECURITY] Potential RCE when using forced evaluation - CVE-2020-17530
Tue, 8 Dec 2020 07:55:04 +0100
Lukasz Lenart <[email protected]> • #62148
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0009
Mon, 30 Nov 2020 19:04:24 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62147
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0008
Mon, 23 Nov 2020 17:50:25 +0100
Carlos Alberto Lopez Perez <[email protected]> • #62146
Advisory: ES2020-02 - Asterisk crash due to INVITE flood over TCP
Fri, 06 Nov 2020 11:16:38 +0100
"Sandro Gauci" <[email protected]> • #62145
Kamailio vulnerable to header smuggling possible due to bypass of remove_hf
Tue, 01 Sep 2020 11:08:36 +0200
"Sandro Gauci" <[email protected]> • #62144
CVE-2016-3427 Apache Cassandra Unspecified vulnerability related to JMX
Mon, 31 Aug 2020 17:03:52 -0500
Brandon Williams <[email protected]> • #62143
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0007
Wed, 29 Jul 2020 12:40:42 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62142
Defense in depth -- the Microsoft way (part 70): CVE-2014-0315 alias MS14-019 revisited
Thu, 23 Jul 2020 23:40:48 +0200
"Stefan Kanthak" <[email protected]> • #62141
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0006
Fri, 10 Jul 2020 13:25:18 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62140
X41 D-Sec GmbH Security Advisory X41-2020-006: Memory Corruption Vulnerability in bspatch
Thu, 9 Jul 2020 18:42:53 +0200
X41 D-Sec GmbH Advisories <[email protected]> • #62139
SEC Consult SA-20200701-0 :: Reflected Cross-Site Scripting (XSS) in EQDKP Plus CMS
Wed, 1 Jul 2020 16:40:13 +0000
SEC Consult Vulnerability Lab <research-SOMWcJgVuhyHT8/[email protected]> • #62138
[KIS-2020-06] openSIS <= 7.4 Incorrect Access Control Vulnerabilities
Tue, 30 Jun 2020 15:25:06 +0200
Egidio Romano <[email protected]> • #62137
[KIS-2020-08] openSIS <= 7.4 Multiple SQL Injection Vulnerabilities
Tue, 30 Jun 2020 15:27:30 +0200
Egidio Romano <[email protected]> • #62136
[KIS-2020-07] openSIS <= 7.4 (Bottom.php) Local File Inclusion Vulnerability
Tue, 30 Jun 2020 15:25:50 +0200
Egidio Romano <[email protected]> • #62135
[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection
Fri, 19 Jun 2020 20:31:22 +0200
Martin <[email protected]> • #62134
[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection
Fri, 19 Jun 2020 20:31:22 +0200
Martin <[email protected]> • #62133
Defense in depth -- the Microsoft way (part 69): security remarks are as futile as the qUACkery!
Wed, 3 Jun 2020 15:50:59 +0200
"Stefan Kanthak" <[email protected]> • #62132
Defense in depth -- the Microsoft way (part 68): qUACkery is futile!
Wed, 3 Jun 2020 15:40:19 +0200
"Stefan Kanthak" <[email protected]> • #62131
TP-LINK Cloud Cameras NCXXX SetEncryptKey Command Injection
Wed, 29 Apr 2020 23:47:12 +0100
Pietro Oliva <[email protected]> • #62130
TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key
Wed, 29 Apr 2020 23:44:43 +0100
Pietro Oliva <[email protected]> • #62129
TP-LINK Cloud Cameras NCXXX Bonjour Command Injection
Wed, 29 Apr 2020 23:43:28 +0100
Pietro Oliva <[email protected]> • #62128
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0005
Mon, 27 Apr 2020 19:12:24 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62127
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004
Thu, 16 Apr 2020 14:10:59 +0200
Carlos Alberto Lopez Perez <[email protected]> • #62126
Defense in depth -- the Microsoft way (part 67): we maintain 20 year old bugs since we don't care about our customers safety and security
Mon, 13 Apr 2020 17:42:01 +0200
"Stefan Kanthak" <[email protected]> • #62125
SEC Consult SA-20200407-0 :: Multiple XSS vulnerabilities in TAO Open Source Assessment Platform
Tue, 7 Apr 2020 16:56:45 +0200
SEC Consult Vulnerability Lab <research-SOMWcJgVuhyHT8/[email protected]> • #62124
Defense in depth -- the Microsoft way (part 66): attachment manager allows to load arbitrary DLLs
Sat, 28 Mar 2020 01:07:04 +0100
"Stefan Kanthak" <[email protected]> • #62123
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.