gmane.comp.security.full-disclosure archive

377 archived articles, newest first (page 1 of 4). Latest articles →

S2-064: CVE-2023-34396: Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Wed, 14 Jun 2023 07:35:56 +0000
Yasser Zamani <[email protected]> • #92211
S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds
Wed, 14 Jun 2023 07:34:50 +0000
Yasser Zamani <[email protected]> • #92210
NEW: VMSA-2019-0003 - VMware Horizon update addresses Connection Server information disclosure vulnerability
Fri, 15 Mar 2019 10:21:46 +0000
VMware Security Response Center <[email protected]> • #92209
NEW: VMSA-2019-0002 - VMware Workstation update addresses elevation of privilege issues.
Fri, 15 Mar 2019 10:21:05 +0000
VMware Security Response Center <[email protected]> • #92208
Whonix 14 with XFCE or CLI for VirtualBox released!
Wed, 21 Nov 2018 14:27:00 +0000
Patrick Schleizer <[email protected]> • #92207
NEW VMSA-2018-0027 VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage
Fri, 9 Nov 2018 16:12:39 +0000
VMware Security Response Center <[email protected]> • #92206
[ANN] CVE-2018-11776 Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16
Wed, 22 Aug 2018 07:37:24 +0000
Yasser Zamani <[email protected]> • #92205
[ANN] CVE-2018-11776 Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16
Wed, 22 Aug 2018 07:37:24 +0000
Yasser Zamani <[email protected]> • #92204
[ANN] CVE-2018-11776 Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16
Wed, 22 Aug 2018 07:37:24 +0000
Yasser Zamani <[email protected]> • #92203
Re: Whonix 14 has been Released
Sat, 18 Aug 2018 07:54:17 -0300
Franz <[email protected]> • #92202
Silver Peak EdgeConnect < 8.1.7.x. multiple vulnerabilities
Fri, 17 Aug 2018 13:42:00 +0400
SCADA StrangeLove <[email protected]> • #92201
New VMSA-2018-0019 - Horizon 6, 7, and Horizon Client for Windows updates address an out-of-bounds read vulnerability
Tue, 7 Aug 2018 21:03:12 +0000
VMware Security Response Center <[email protected]> • #92200
Re: Whonix 14 has been Released
Tue, 7 Aug 2018 10:43:40 -0300
Franz <[email protected]> • #92199
Whonix 14 has been Released
Tue, 07 Aug 2018 10:17:00 +0000
Patrick Schleizer <patrick-mailinglists-hfd0J/[email protected]> • #92198
Updated VMSA-2018-0007.3: VMware Virtual Appliance updates address side-channel analysis due to speculative execution
Fri, 4 May 2018 02:47:57 +0000
VMware Security Response Center <[email protected]> • #92197
CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
Fri, 19 Jan 2018 08:46:40 -0600
Jason Lowe <[email protected]> • #92196
CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
Fri, 19 Jan 2018 08:46:40 -0600
Jason Lowe <[email protected]> • #92195
CVE-2017-3162: Apache Hadoop DataNode web UI vulnerability
Tue, 25 Apr 2017 18:16:11 -0700
Chris Douglas <[email protected]> • #92194
CVE-2017-3161: Apache Hadoop NameNode XSS vulnerability
Tue, 25 Apr 2017 18:16:08 -0700
Chris Douglas <[email protected]> • #92193
CVE-2017-3162: Apache Hadoop DataNode web UI vulnerability
Tue, 25 Apr 2017 18:16:11 -0700
Chris Douglas <[email protected]> • #92192
MobSF v0.9.3 is Released: Now supports Windows APPX Static Analysis
Tue, 22 Nov 2016 19:33:39 +0530
Ajin Abraham <[email protected]> • #92191
New VMSA-2016-0020 - VMware product updates address multiple information disclosure issues
Wed, 16 Nov 2016 06:27:36 +0000
VMware Security Response Center <[email protected]> • #92190
New VMSA-2016-0019 - VMware product updates address multiple information disclosure issues
Mon, 14 Nov 2016 07:04:35 +0000
VMware Security Response Center <[email protected]> • #92189
New VMSA-2016-0017 - VMware product updates address multiple information disclosure issues
Wed, 26 Oct 2016 04:47:48 +0000
VMware Security Response Center <[email protected]> • #92188
Directory Traversal Vulnerability in ColoradoFTP v1.3 Prime Edition (Build 8)
Thu, 11 Aug 2016 13:28:22 +0200
"Rv3Lab.org" <[email protected]> • #92187
NEW VMSA-2016-0009 VMware vCenter Server updates address an important reflective cross-site scripting issue
Wed, 15 Jun 2016 05:28:59 +0000
VMware Security Response Center <[email protected]> • #92186
Mobile Security Framework (MobSF) v0.9.2 Released
Tue, 3 May 2016 13:23:16 +0530
Ajin Abraham <[email protected]> • #92185
Multiple Reflected XSS vulnerabilities in Oliver (formerly Webshare) v1.3.1
Tue, 19 Apr 2016 14:59:06 +0200
"[email protected]" <[email protected]> • #92184
NEW VMSA-2016-0004 VMware product updates address a critical security issue in the VMware Client Integration Plugin
Thu, 14 Apr 2016 19:39:20 +0000
VMware Security Response Center <[email protected]> • #92183
CVE-2016-3672 - Unlimiting the stack not longer disables ASLR
Wed, 6 Apr 2016 14:58:48 +0200
Hector Marco-Gisbert <[email protected]> • #92182
server and client side remote code execution throu gh a buffer overflow in all git versions before 2.7.1 (un published ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ ‑2016‑2315)
Wed, 16 Mar 2016 01:31:47 +0100
Laël Cellier <[email protected]> • #92181
Releasing Mobile Security Framework (MobSF) v0.9
Mon, 14 Mar 2016 13:17:47 +0530
Ajin Abraham <[email protected]> • #92180
[SECURITY] CVE-2015-5345 Apache Tomcat Directory disclosure
Mon, 22 Feb 2016 11:23:17 +0000
Mark Thomas <[email protected]> • #92179
[SECURITY] CVE-2015-5345 Apache Tomcat Directory disclosure
Mon, 22 Feb 2016 11:23:17 +0000
Mark Thomas <[email protected]> • #92178
[SECURITY] CVE-2016-0706 Apache Tomcat Security Manager bypass
Mon, 22 Feb 2016 11:22:18 +0000
Mark Thomas <[email protected]> • #92177
[SECURITY] CVE-2015-5346 Apache Tomcat Session fixation
Mon, 22 Feb 2016 11:23:02 +0000
Mark Thomas <[email protected]> • #92176
[SECURITY] CVE-2016-0714 Apache Tomcat Security Manager Bypass
Mon, 22 Feb 2016 11:21:51 +0000
Mark Thomas <[email protected]> • #92175
[SECURITY] CVE-2015-5174 Apache Tomcat Limited Directory Traversal
Mon, 22 Feb 2016 11:22:49 +0000
Mark Thomas <[email protected]> • #92174
[SECURITY] CVE-2016-0763 Apache Tomcat Security Manager Bypass
Mon, 22 Feb 2016 11:23:30 +0000
Mark Thomas <[email protected]> • #92173
[SECURITY] CVE-2015-5351 Apache Tomcat CSRF token leak
Mon, 22 Feb 2016 11:22:35 +0000
Mark Thomas <[email protected]> • #92172
MediaAccess , unauthenticated file disclosure
Wed, 6 Jan 2016 01:37:03 +0200
Ahmed Sultan <[email protected]> • #92171
[SECURITY] CVE-2015-5349: Apache Directory Studio command injection vulnerability
Sat, 2 Jan 2016 15:32:51 +0100
Stefan Seelmann <[email protected]> • #92170
Back to 28: Grub2 Authentication Bypass 0-Day [CVE-2015-8370]
Tue, 15 Dec 2015 12:49:55 +0100
Hector Marco-Gisbert <[email protected]> • #92169
[ISecAuditors Security Advisories] URL Open Redirect in Google generic TLD and ccTLD
Thu, 15 Oct 2015 18:40:08 -0500
ISecAuditors Security Advisories <[email protected]> • #92168
[SPAM] Fw: important message
Tue, 15 Sep 2015 17:12:05 +0200
Tim Dressel <[email protected]> • #92167
[CVE-2014-7216] Yahoo! Messenger emoticons.xml Multiple Key Value Handling Local Buffer Overflow
Thu, 3 Sep 2015 20:38:30 +0200
Julien Ahrens <[email protected]> • #92166
[CVE-2015-5617]Enorth Webpublisher CMS SQL Injection from delete_pending_news.jsp cbNewsid
Thu, 13 Aug 2015 17:29:54 +0800
xin.wang <xin.wang-8GNu1MUMqW6J1ku80POtVW/[email protected]> • #92165
ZTE ZXV10 W300 v3.1.0c_DR0 - UI Session Delete Vulnerability
Fri, 19 Jun 2015 15:00:52 +0200
Vulnerability Lab <[email protected]> • #92164
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Fri, 19 Jun 2015 14:59:04 +0200
Vulnerability Lab <[email protected]> • #92163
[SECURITY] CVE-2014-7810: Apache Tomcat Security Manager Bypass
Thu, 14 May 2015 15:03:08 +0100
Mark Thomas <[email protected]> • #92162
[SECURITY] CVE-2014-7810: Apache Tomcat Security Manager Bypass
Thu, 14 May 2015 15:03:08 +0100
Mark Thomas <[email protected]> • #92161
Re: AMD Bulldozer Linux ASLR weakness: Reducing entropy by 87.5%
Thu, 07 May 2015 16:48:46 +0200
Hector Marco-Gisbert <[email protected]> • #92160
[SECURITY] CVE-2014-0230: Apache Tomcat DoS
Tue, 05 May 2015 23:53:05 +0100
Mark Thomas <[email protected]> • #92159
[SECURITY] CVE-2014-0230: Apache Tomcat DoS
Tue, 05 May 2015 23:53:05 +0100
Mark Thomas <[email protected]> • #92158
AMD Bulldozer Linux ASLR weakness: Reducing entropy by 87.5%
Tue, 21 Apr 2015 18:32:51 +0200
Hector Marco-Gisbert <[email protected]> • #92157
MongoDB BSON Handling Remote Denial of Service Vulnerability
Fri, 6 Mar 2015 13:43:29 -0800
<[email protected]> • #92156
H2HC 12th Edition - Call for Papers
Fri, 06 Mar 2015 10:01:55 -0800
"Rodrigo Rubira Branco \(BSDaemon\)" <[email protected]> • #92155
[SECURITY] CVE-2015-0254 XXE and RCE via XSL extension in JSTL XML tags
Thu, 26 Feb 2015 22:16:33 -0800
Jeremy Boynes <[email protected]> • #92154
[SECURITY] CVE-2015-0254 XXE and RCE via XSL extension in JSTL XML tags
Thu, 26 Feb 2015 22:16:33 -0800
Jeremy Boynes <[email protected]> • #92153
[SECURITY] CVE-2015-0254 XXE and RCE via XSL extension in JSTL XML tags
Thu, 26 Feb 2015 22:16:33 -0800
Jeremy Boynes <[email protected]> • #92152
CVE-2014-7808
Wed, 18 Feb 2015 22:18:43 +0200
Martin Grigorov <[email protected]> • #92151
[FD] Crushftp 7.2.0 - Multiple CSRF & XSS Vulnerabilities
Tue, 17 Feb 2015 17:23:51 -0500
Rehan Ahmed <[email protected]> • #92150
[SECURITY] CVE-2014-0227 Apache Tomcat Request Smuggling
Mon, 09 Feb 2015 09:12:47 +0000
Mark Thomas <[email protected]> • #92149
[SECURITY] CVE-2014-0227 Apache Tomcat Request Smuggling
Mon, 09 Feb 2015 09:12:47 +0000
Mark Thomas <[email protected]> • #92148
[ANN] Apache Struts 2.3.20 GA release available with security fix
Mon, 8 Dec 2014 16:37:56 +0100
Lukasz Lenart <[email protected]> • #92147
[ANN] Apache Struts 2.3.20 GA release available with security fix
Mon, 8 Dec 2014 16:37:56 +0100
Lukasz Lenart <[email protected]> • #92146
Re: Offset2lib: bypassing full ASLR on 64bit Linux
Fri, 5 Dec 2014 19:58:43 +0800
Shawn <[email protected]> • #92145
Re: Offset2lib: bypassing full ASLR on 64bit Linux
Fri, 05 Dec 2014 12:10:51 +0100
Agostino Sarubbo <[email protected]> • #92144
Offset2lib: bypassing full ASLR on 64bit Linux
Thu, 04 Dec 2014 21:19:04 +0100
Hector Marco <[email protected]> • #92143
CVE-2014-5439 - Root shell on Sniffit [with exploit]
Wed, 26 Nov 2014 16:22:57 +0100
Hector Marco <[email protected]> • #92142
NEW VMSA-2014-0011 VMware vSphere Data Protection product update addresses a critical information disclosure vulnerability
Fri, 24 Oct 2014 19:45:14 +0000
VMware Security Response Center <[email protected]> • #92141
[FD] Fwd: Re: CSP Bypass on Android prior to 4.4
Tue, 14 Oct 2014 12:33:14 +0100
Vitor Ventura <[email protected]> • #92140
CVE-2014-3526
Mon, 22 Sep 2014 10:31:41 +0300
Martin Grigorov <[email protected]> • #92139
[FD] CVE-2014-2081 - VTLS Virtua InfoStation.cgi SQLi.
Mon, 25 Aug 2014 16:56:40 -0300
"J. Tozo" <[email protected]> • #92138
CVE-2014-3524: Apache OpenOffice Calc Command Injection Vulnerability
Thu, 21 Aug 2014 15:01:32 +0200
Herbert Duerr <[email protected]> • #92137
CVE-2014-3575:OpenOffice Targeted Data Exposure Using Crafted OLE Objects
Thu, 21 Aug 2014 15:02:48 +0200
Herbert Duerr <[email protected]> • #92136
[FD] IBM GCM16/32 v1.20.0.22575 vulnerabilities
Mon, 21 Jul 2014 09:59:47 +0200
Alejandro Alvarez <[email protected]> • #92135
[FD] Microsoft MSN HBE - Blind SQL Injection Vulnerability
Fri, 18 Jul 2014 11:12:13 +0200
Vulnerability Lab <[email protected]> • #92134
[FD] Barracuda Networks Message Archiver 650 - Persistent Input Validation Vulnerability (BNSEC 703)
Fri, 18 Jul 2014 11:07:02 +0200
Vulnerability Lab <[email protected]> • #92133
[FD] Yahoo! Bug Bounty #30 YM - Application Side Mail Encoding (File Attachment) Vulnerability
Thu, 10 Jul 2014 14:52:43 +0200
Vulnerability Lab <[email protected]> • #92132
[FD] Yahoo! Bug Bounty #29 YM - Filter Bypass & Persistent Web Vulnerability
Thu, 10 Jul 2014 14:48:12 +0200
Vulnerability Lab <[email protected]> • #92131
[FD] Photo Org WonderApplications v8.3 iOS - File Include Vulnerability
Mon, 07 Jul 2014 18:29:26 +0200
Vulnerability Lab <[email protected]> • #92130
[FD] Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability
Mon, 07 Jul 2014 15:31:52 +0200
Vulnerability Lab <[email protected]> • #92129
[SECURITY] CVE-2014-3503 Apache Syncope
Mon, 07 Jul 2014 12:56:47 +0200
Francesco Chicchiriccò <[email protected]> • #92128
Re: [FD] Wordpress TimThumb 2.8.13 WebShot Remote Code Execution (0-day)
Tue, 24 Jun 2014 21:12:26 +0200
Ryan Dewhurst <[email protected]> • #92127
[FD] Wordpress TimThumb 2.8.13 WebShot Remote Code Execution (0-day)
Tue, 24 Jun 2014 15:24:04 +0700
Pichaya Morimoto <[email protected]> • #92126
[FD] Secunia CSI/VIM - Filter Bypass & Persistent Validation Vulnerabilities
Wed, 18 Jun 2014 15:59:41 +0200
Vulnerability Lab <[email protected]> • #92125
[FD] Secunia CSI/VIM - Filter Bypass & Persistent Validation Vulnerabilities
Wed, 18 Jun 2014 15:35:37 +0200
Vulnerability Lab <[email protected]> • #92124
[SECURITY] CVE-2013-2251: Apache Continuum affected by Remote Command Execution
Sat, 14 Jun 2014 00:57:45 +1000
Brett Porter <[email protected]> • #92123
Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:04 +1000 (EST)
cfp-ZRDujs/oHym3Zbb/[email protected] • #92122
Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:03 +1000 (EST)
cfp-ZRDujs/oHym3Zbb/[email protected] • #92121
[FD] CVE-2014-3718] ALEPH500 (Integrated library management system) Cross Site Scripting Vulnerability
Thu, 15 May 2014 19:43:20 +0800
"xxx" <[email protected]> • #92120
Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:04 +1000 (EST)
[email protected] • #92119
CVE-2014-0930 - Kernel Memory Leak And Denial Of Service Condition in IBM AIX
Tue, 06 May 2014 18:17:32 +0100
Portcullis Advisories <[email protected]> • #92118
CVE-2014-2882 - Lack of SSL Certificate Validation in Citrix Netscaler
Tue, 06 May 2014 18:16:51 +0100
Portcullis Advisories <[email protected]> • #92117
Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:03 +1000 (EST)
[email protected] • #92116
[clug] Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:03 +1000 (EST)
cfp-ZRDujs/oHym3Zbb/[email protected] • #92115
Ruxcon 2014 Call For Papers
Mon, 5 May 2014 20:17:04 +1000 (EST)
[email protected] • #92114
[ANN] Struts 2.3.16.3 GA release available - security fix
Mon, 5 May 2014 16:33:29 +0200
Lukasz Lenart <[email protected]> • #92113
CVE-2014-2881 - Poor Quality Implementation of Diffie-Hellman Key Exchange in Citrix Netscaler
Tue, 06 May 2014 18:16:08 +0100
Portcullis Advisories <[email protected]> • #92112
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.