User login

Defcon News

New Files / Applications

Security Vulnerabilities

August 25, 2007

13:15
A remotely exploitable vulnerability has been discovered in the file parsing engine of Sophos AntiVirus versions prior to 2.48.0. The bug exists during the file parsing of GZIP packed files.
13:15
A remote exploitable vulnerability exists in clamav-milter when used with sendmail due to an insecure call to popen(). ClamAV versions prior to 0.91.2 are affected.
13:15
Tikiwiki version 1.9.7 is susceptible to cross site scripting attacks.
09:15
AST-2007-021: Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage
08:30
More on VMWare poor guest isolation design >> Advertisement ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
08:30
08:30
00:00
VMware Workstation VMStor-60 Driver Buffer Overflow Vulnerability >> Advertisement ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
00:00
GNU Tar Hostile Destination Path Variant Vulnerability
00:00
GNU Tar Dot_Dot Function Remote Directory Traversal Vulnerability
00:00
GNU Tar Hostile Destination Path Vulnerability
00:00
Sophos Antivirus UPX and BZIP Multiple Remote Vulnerabilities
00:00
RETIRED: SPIP Inc-Calcul.PHP3 Remote File Include Vulnerability >> Advertisement ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
00:00
Asterisk Malformed MIME Body Remote Denial of Service Vulnerability

August 24, 2007

17:00
ProFTPD version 1.x mod_tls remote buffer overflow exploit.
15:00
Ubuntu Security Notice 502-1 - It was discovered that Konqueror could be tricked into displaying incorrect URLs. Remote attackers could exploit this to increase their chances of tricking a user into visiting a phishing URL, which could lead to credential theft.
15:00
ESTsoft ALPass version 2.7 suffers from an arbitrary code execution vulnerability when importing a specially crafted DB file.
15:00
Bugzilla versions below 2.20.5 and versions below 3.0.1 are susceptible to input validation and cross site scripting vulnerabilities.