Ahazu.com logo



Index

Computer-stuff:
Documents
The Forums
Crypto tools
Vulnerabilities

Other stuff:
Southpark episodes
Weblog
AD&D Stuff
Picture Gallery
The Ahazu-song
Facts about Ahazu

Links

Valid XHTML 1.0!


Exploits and Vulnerabilities

..and also how to patch them

Timeformat fixed, thanks to Eltvik.net

Search the archive:

View all exploits

Showing the 200 latest exploits:

Time Subject
Thu 1. Jan 2009 18:19 A tool to identify the MD5 certs on FF
Thu 1. Jan 2009 16:15 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit
Wed 31. Dec 2009 00:21 CFP uCon Security Conference 2009 - Recife, Brazil
Tue 30. Dec 2009 18:31 apache 1.x <=> 2.x suphp (suPHP_ConfigPath) bypass safe mode exploit&#8206;
Tue 30. Dec 2009 11:50 MD5 Considered Harmful Today: Creating a rogue CA certificate
Tue 30. Dec 2009 14:31 php-nuke 8.0 module sections artid blind sql inj vuln.
Tue 30. Dec 2009 07:45 Megacubo 5.0.7 (mega://) remote eval() injection exploit
Mon 29. Dec 2009 16:08 reliable IOS exploitation
Sat 27. Dec 2008 12:54 [SECURITY] [DSA 1693-1] New phppgadmin packages fix several vulnerabilities
Sun 28. Dec 2008 22:50 MagpieRSS XSS 0day
Thu 25. Dec 2008 13:23 Mavi Emlak Sql Injection
Mon 29. Dec 2009 09:45 [ MDVSA-2008:246 ] kernel
Mon 29. Dec 2009 05:58 ViArt Shopping Cart v3.5 Multiple Remote Vulnerabilities
Mon 29. Dec 2009 14:55 MSN messenger sends IP addresses Public and Private
Thu 25. Dec 2008 13:22 Madrese-Portal Sql Injection
Sat 27. Dec 2008 21:34 hm? new vulnerabilities? wav windows media
Sat 27. Dec 2008 10:49 [SECURITY] [DSA 1692-1] New php-xajax packages fix cross-site scripting
Fri 26. Dec 2008 12:40 Joomla Component mdigg 2.2.8 Blind SQL Injection Exploit
Fri 26. Dec 2008 12:16 ClubHack2008 presentations are now online
Thu 25. Dec 2008 15:12 PHP-Fusion Mod TI - Blog System Sql Injection
Thu 25. Dec 2008 07:35 Castlecops security site closed for good
Thu 25. Dec 2008 04:44 joomla com_lowcosthotels sql injection
Wed 24. Dec 2008 23:32 MS Windows Media Player * (.WAV) Remote Integrer Overflow
Tue 23. Dec 2008 06:11 PGP Desktop 9.0.6 Denial Of Service - ZeroDay
Tue 23. Dec 2008 23:15 [ GLSA 200812-21 ] ClamAV: Multiple vulnerabilities
Tue 23. Dec 2008 12:54 Google Chrome Browser (ChromeHTML://) remote parameter injection POC
Tue 23. Dec 2008 01:39 FreeBSD Security Advisory FreeBSD-SA-08:12.ftpd
Wed 24. Dec 2008 01:35 [ GLSA 200812-24 ] VLC: Multiple vulnerabilities
Tue 23. Dec 2008 23:23 [ GLSA 200812-22 ] Ampache: Insecure temporary file usage
Tue 23. Dec 2008 18:52 Personal Sticky Threads v1.0.3c vbulletin Add-on problem
Tue 23. Dec 2008 09:16 [USN-698-3] Nagios vulnerabilities
Tue 23. Dec 2008 23:40 [ GLSA 200812-23 ] Imlib2: User-assisted execution of arbitrary code
Wed 24. Dec 2008 10:15 FRHACK Registration open (Christmas offer)
Tue 23. Dec 2008 17:33 [USN-700-1] Perl vulnerabilities
Tue 23. Dec 2008 15:01 DDIVRT-2008-16 Citrix Broadcast Server 6.0 login.asp SQL Injection --- Update for BID 32832
Tue 23. Dec 2008 12:19 [ISecAuditors Security Advisories] PSI remote integer overflow DoS
Tue 23. Dec 2008 11:57 [USN-677-2] OpenOffice.org Internationalization update
Tue 23. Dec 2008 01:39 FreeBSD Security Advisory FreeBSD-SA-08:13.protosw
Mon 22. Dec 2008 16:03 [security bulletin] HPSBST02397 SSRT080187 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-078
Tue 23. Dec 2008 00:18 [SECURITY] [DSA 1688-2] New courier-authlib packages fix regression
Mon 22. Dec 2008 13:07 [ MDVA-2008:241 ] mailscanner
Mon 22. Dec 2008 14:20 rPSA-2008-0341-1 dovecot
Mon 22. Dec 2008 19:16 [ISecAuditors Security Advisories] Multiple vulnerabilities in WiFi router COMTREND CT-536/HG-536+
Mon 22. Dec 2008 07:49 [SECURITY] [DSA 1690-1] New avahi packages fix denial of service
Mon 22. Dec 2008 18:36 [ISecAuditors Security Advisories] Wordpress is vulnerable to an unauthorized upgrade and XSS
Mon 22. Dec 2008 15:30 CORE-2008-1210: Qemu and KVM VNC server remote DoS
Sun 21. Dec 2008 20:25 [ GLSA 200812-20 ] phpCollab: Multiple vulnerabilities
Sun 21. Dec 2008 15:24 [SECURITY] [DSA 1689-1] New proftpd-dfsg packages fix Cross-Site Request Forgery
Mon 22. Dec 2008 09:35 [USN-698-1] Nagios vulnerability
Mon 22. Dec 2008 09:35 [USN-697-1] Imlib2 vulnerability
Mon 22. Dec 2008 17:07 Secunia Research: Trend Micro HouseCall ActiveX Control Arbitrary Code Execution
Mon 22. Dec 2008 00:39 CoolPlayer 2.19 (Skin File) Local Buffer Overflow Exploit
Mon 22. Dec 2008 13:13 POC for CVE-2008-5619 (roundcubemail PHP arbitrary code injection)
Mon 22. Dec 2008 00:42 FreeSSHd Multiple Remote Stack Overflow Vulnerabilities
Mon 22. Dec 2008 10:55 [UPRSN] Ubuntu Privacy Remix 8.04r2 introduces "noexec"-mounting by default
Mon 22. Dec 2008 09:36 [USN-698-2] Nagios3 vulnerabilities
Mon 22. Dec 2008 09:27 [SECURITY] [DSA 1691-1] New moodle packages fix several vulnerabilities
Mon 22. Dec 2008 09:35 [USN-698-1] Nagios vulnerability
Mon 22. Dec 2008 09:34 [USN-699-1] Blender vulnerabilities
Sun 21. Dec 2008 11:04 [SECURITY] [DSA 1678-2] New perl packages fix regression
Sun 21. Dec 2008 09:47 Secunia Research: Trend Micro HouseCall "notifyOnLoadNative()" Vulnerability
Sat 20. Dec 2008 10:55 chicomas <=2.0.4 Multiple Vulnerabilities
Sat 20. Dec 2008 16:21 [SECURITY] [DSA 1688-1] New courier-authlib packages fix SQL injection
Fri 19. Dec 2008 22:43 [ GLSA 200812-19 ] PowerDNS: Multiple vulnerabilities
Fri 19. Dec 2008 16:07 rPSA-2008-0338-1 cups
Fri 19. Dec 2008 20:21 PHP APC vulnerable to local attacks
Fri 19. Dec 2008 16:23 HTC Touch vCard over IP Denial of Service
Fri 19. Dec 2008 05:50 [security bulletin] HPSBST02394 SSRT080183 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-070 to MS08-077
Fri 19. Dec 2008 13:14 SEC Consult SA-20081219-0 :: Fujitsu-Siemens WebTransactions remote command injection vulnerability
Thu 18. Dec 2008 16:36 [USN-696-1] Avahi vulnerabilities
Thu 18. Dec 2008 20:43 CONFidence 2009, CFP
Wed 17. Dec 2008 21:55 [ MDVSA-2008:245 ] firefox
Wed 17. Dec 2008 18:52 php python extension safe_mode bypass
Wed 17. Dec 2008 17:22 [USN-695-1] shadow vulnerability
Wed 17. Dec 2008 18:26 [USN-694-1] libvirt vulnerability
Wed 17. Dec 2008 18:19 [USN-690-3] Firefox vulnerabilities
Wed 17. Dec 2008 18:13 [USN-690-2] Firefox vulnerabilities
Wed 17. Dec 2008 16:12 [USN-693-1] LittleCMS vulnerability
Thu 18. Dec 2008 16:46 [SECURITY] CVE-2008-2938 - Apache Tomcat information disclosure vulnerability - Update 2
Wed 17. Dec 2008 16:12 [USN-692-1] Gadu vulnerability
Thu 18. Dec 2008 01:00 Firefox cross-domain text theft (CESA-2008-011)
Thu 18. Dec 2008 12:22 [TKADV2008-015] Sun Solaris SIOCGTUNPARAM IOCTL Kernel NULL pointer dereference
Wed 17. Dec 2008 23:22 EasySiteNetwork (joke.php?id) Remote SQL injection Vulnerability
Wed 17. Dec 2008 17:54 [USN-690-1] Firefox and xulrunner vulnerabilities
Wed 17. Dec 2008 16:18 [ MDVSA-2008:244 ] mozilla-firefox
Wed 17. Dec 2008 15:40 Network Security Scanner OpenVAS 2.0.0 Released
Wed 17. Dec 2008 16:06 n.runs-SA-2008.010 - Opera HTML parsing Code Execution
Tue 16. Dec 2008 23:06 [ GLSA 200812-18 ] JasPer: User-assisted execution of arbitrary code
Tue 16. Dec 2008 22:56 Joomla: Session hijacking vulnerability, CVE-2008-4122
Tue 16. Dec 2008 21:29 CVE-2008-0971 - Barracuda Networks products Multiple Cross-Site Scripting Vulnerabilities
Tue 16. Dec 2008 14:11 CVE-2008-1094 - Barracuda Span Firewall SQL Injection Vulnerability
Tue 16. Dec 2008 13:14 ZDI-08-088: Oracle E-Business Suite Business Intelligence SQL Injection Vulnerability
Tue 16. Dec 2008 21:37 [ GLSA 200812-17 ] Ruby: Multiple vulnerabilities
Tue 16. Dec 2008 10:18 [USN-691-1] Ruby vulnerability
Mon 15. Dec 2008 16:31 [ MDVSA-2008:243 ] enscript
Mon 15. Dec 2008 14:33 [SECURITY] [DSA 1687-1] New Linux 2.6.18 packages fix several vulnerabilities
Mon 15. Dec 2008 14:35 [ MDVSA-2008:242 ] wireshark
Sun 14. Dec 2008 13:12 Fwd: TmaxSoft JEUS Alternate Data Streams Vulnerability
Sat 13. Dec 2008 02:51 TmaxSoft JEUS Alternate Data Streams Vulnerability
Mon 15. Dec 2008 10:28 phpList vulnerability
Mon 15. Dec 2008 01:34 Multiple XSS Vulnerabilities in World Recipe 2.11
Sun 14. Dec 2008 17:32 [TKADV2008-014] MPlayer TwinVQ Processing Stack Buffer Overflow Vulnerability
Sun 14. Dec 2008 10:34 CFAGCMS Remote File Inclusion
Mon 15. Dec 2008 14:45 [ GLSA 200812-16 ] Dovecot: Multiple vulnerabilities
Sun 14. Dec 2008 18:15 [ GLSA 200812-15 ] POV-Ray: User-assisted execution of arbitrary code
Sun 14. Dec 2008 21:23 [SECURITY] [DSA 1686-1] New no-ip packages fix arbitrary code execution
Sun 14. Dec 2008 01:38 [ GLSA 200812-14 ] aview: Insecure temporary file usage
Sat 13. Dec 2008 00:01 [ GLSA 200812-13 ] OpenOffice.org: Multiple vulnerabilities
Fri 12. Dec 2008 21:50 [ GLSA 200812-12 ] Honeyd: Insecure temporary file creation
Fri 12. Dec 2008 17:52 Moodle 1.9.3 Remote Code Execution
Fri 12. Dec 2008 07:36 [SECURITY] [DSA 1685-1] New uw-imap packages fix multiple vulnerabilities
Thu 11. Dec 2008 20:12 Nokia N70/N73 Bluetooth Stack OBEX Implementation Denial of Service
Thu 11. Dec 2008 17:52 rPSA-2008-0336-1 tshark wireshark
Thu 11. Dec 2008 13:12 ASP-CMS v.1.0 Sql Injection/Database Disclosure
Thu 11. Dec 2008 01:06 Meta Cart Free Database Disclosure
Thu 11. Dec 2008 18:27 Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities
Thu 11. Dec 2008 12:10 Secunia Research: CA ARCserve Backup RPC "handle_t" Argument Vulnerability
Thu 11. Dec 2008 08:15 facto Database Disclosure
Thu 11. Dec 2008 01:06 Meta Cart Free Database Disclosure
Thu 11. Dec 2008 06:21 aspProductCatalog Sql Injection
Wed 10. Dec 2008 16:57 Black Hat: New Webinar, Japan audio now on-line.
Wed 10. Dec 2008 17:36 AST-2008-012: Remote crash vulnerability in IAX2
Thu 11. Dec 2008 00:05 Browser Security Handbook
Wed 10. Dec 2008 23:16 [ GLSA 200812-11 ] CUPS: Multiple vulnerabilities
Wed 10. Dec 2008 14:01 [ MDVSA-2008:240 ] vinagre
Wed 10. Dec 2008 16:04 CA ARCserve Backup LDBserver Vulnerability
Wed 10. Dec 2008 20:29 Maxs Guestbook (XSS) Remote Vulnerability
Wed 10. Dec 2008 14:55 iDefense Security Advisory 12.10.08: Microsoft Excel Malformed Object Memoy Corruption Vulnerability
Wed 10. Dec 2008 17:53 [ GLSA 200812-10 ] Archive::Tar: Directory traversal vulnerability
Wed 10. Dec 2008 17:51 [ GLSA 200812-09 ] OpenSC: Insufficient protection of smart card PIN
Wed 10. Dec 2008 08:36 [security bulletin] HPSBUX02393 SSRT080057 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS)
Wed 10. Dec 2008 13:25 CORE-2008-0228: Microsoft Word Malformed FIB Arbitrary Free Vulnerability
Wed 10. Dec 2008 13:45 Microsoft SQL Server 2005 sp_replwritetovarbin memory overwrite (update to SEC Consult SA-20081209)
Wed 10. Dec 2008 17:39 [IVIZ-08-016] F-Secure f-prot Antivirus for Linux corrupted ELF header Security Bypass
Wed 10. Dec 2008 17:32 [IVIZ-08-015] Sophos Antivirus for Linux vulnerability
Wed 10. Dec 2008 17:31 [IVIZ-08-014] AVG antivirus for Linux vulnerability
Wed 10. Dec 2008 17:27 [IVIZ-08-013] Avast antivirus for Linux multiple vulnerabilities
Wed 10. Dec 2008 17:21 [IVIZ-08-012] Bitdefender antivirus for Linux multiple vulnerabilities
Wed 10. Dec 2008 17:18 [IVIZ-08-011] ClamAV lzh unpacking segmentation fault
Wed 10. Dec 2008 07:51 [SECURITY] [DSA 1684-1] New lcms packages fix multiple vulnerabilities
Tue 9. Dec 2008 19:00 [USN-678-2] GnuTLS regression
Tue 9. Dec 2008 16:37 [USN-689-1] Vinagre vulnerability
Tue 9. Dec 2008 18:33 ISOI 6, Dallas, TX - January 29, 30
Wed 10. Dec 2008 12:32 Insomnia : ISVA-081209.1 - IE Webdav Request Parsing Heap Corruption Vulnerability
Tue 9. Dec 2008 15:10 ZDI-08-087: Microsoft Internet Explorer Webdav Request Parsing Heap Corruption Vulnerability
Tue 9. Dec 2008 15:10 ZDI-08-086: Microsoft Office Word Document Table Property Stack Overflow Vulnerability
Tue 9. Dec 2008 15:09 ZDI-08-085: Microsoft Office RTF Drawing Object Heap Overflow Vulnerability
Tue 9. Dec 2008 15:08 ZDI-08-084: Microsoft Office RTF Consecutive Drawing Object Parsing Heap Corruption Vulnerability
Tue 9. Dec 2008 15:07 ZDI-08-083: Microsoft Animation ActiveX Control Malformed AVI Parsing Code Execution Vulnerability
Tue 9. Dec 2008 15:50 iDefense Security Advisory 12.09.08: Microsoft Windows Graphics Device Interface Integer Overflow Vulnerability
Tue 9. Dec 2008 21:17 Secunia Research: Microsoft Hierarchical FlexGrid Control Integer Overflows
Tue 9. Dec 2008 15:16 iDefense Security Advisory 12.09.08: Microsoft Internet Explorer 5.01 EMBED tag Long File Name Extension Stack Buffer Overflow Vulnerability (iDefense Exclusive)
Tue 9. Dec 2008 17:49 CORE-2008-1127 - Vinagre show_error() format string vulnerability
Tue 9. Dec 2008 20:06 Secunia Research: Microsoft Excel NAME Record Array Indexing Vulnerability
Tue 9. Dec 2008 19:38 Secunia Research: Microsoft Word RTF Polyline/Polygon Integer Overflow
Tue 9. Dec 2008 11:21 rPSA-2008-0332-1 kernel
Tue 9. Dec 2008 16:34 Multiple Vendor Anti-Virus Software Malicious WebPage Detection Bypass -Update-
Tue 9. Dec 2008 13:16 SEC Consult SA-20081109-0 :: Microsoft SQL Server 2000 sp_replwritetovarbin limited memory overwrite vulnerability
Tue 9. Dec 2008 07:52 PHP safe_mode can be bypassed via proc_open() and custom environment.
Mon 8. Dec 2008 19:38 [ MDVSA-2008:236-1 ] vim
Mon 8. Dec 2008 22:52 DoS attacks on MIME-capable software via complex MIME emails
Mon 8. Dec 2008 14:35 Multiple XSRF in DD-WRT (Remote Root Command Execution)
Mon 8. Dec 2008 13:38 ZDI-08-082: BMC PatrolAgent Version Logging Format String Vulnerability
Mon 8. Dec 2008 19:58 [SECURITY] [DSA 1683-1] New streamripper packages fix potential code execution
Mon 8. Dec 2008 11:20 DoS Vulnerability in Aruba Mobility Controller Caused by Malformed EAP Frame (Aruba Advisory ID: AID-12808)
Mon 8. Dec 2008 11:23 [security bulletin] HPSBMA02391 SSRT071481 rev.1 - HP OpenView Reporter and HP Reporter Running on Windows, Remote Denial of Service (DoS)
Mon 8. Dec 2008 12:12 Neostrada Livebox Remote Network Down PoC Exploit
Mon 8. Dec 2008 11:22 [security bulletin] HPSBMA02390 SSRT071481 rev.1 - HP OpenView Performance Agent, HP Performance Agent, Remote Denial of Service (DoS)
Mon 8. Dec 2008 11:39 [SVRT-07-08] Vulnerability in Face Recognition Authentication Mechanism of Lenovo-Asus-Toshiba Laptops
Mon 8. Dec 2008 15:21 [DSECRG-08-041] Stored XSS Vulnerability in Xoops 2.3.x
Mon 8. Dec 2008 15:18 [DSECRG-08-040] Multiple Local File Include Vulnerabilities in Xoops 2.3.x
Mon 8. Dec 2008 05:54 RadAsm <=2.2.1.5 Local Command Execution
Mon 8. Dec 2008 03:48 XSS in PHPepperShop v 1.4
Sun 7. Dec 2008 20:32 Two XSS Flaws in PrestaShop 1.1.0.3
Sun 7. Dec 2008 23:26 Multiple Vendor Anti-Virus Software Malicious WebPage Detection Bypass
Thu 1. Jan 1970 01:00 [SECURITY] [DSA 1682-1] New squirrelmail packages fix cross site scripting
Sat 6. Dec 2008 12:40 SecurityReason: PHP 5.2.6 SAPI php_getuid() overload
Sat 6. Dec 2008 18:53 [ GLSA 200812-08 ] Mgetty: Insecure temporary file usage
Fri 5. Dec 2008 19:42 [ MDVSA-2008:239 ] clamav
Fri 5. Dec 2008 02:06 CVE-2008-5079: multiple listen()s on same socket corrupts the vcc table
Thu 4. Dec 2008 18:34 [ MDVSA-2008:238 ] libsamplerate
Thu 4. Dec 2008 18:19 ZDI-08-081: Sun Java Web Start and Applet Multiple Sandbox Bypass Vulnerabilities
Thu 4. Dec 2008 18:18 ZDI-08-080: Sun Java AWT Library Sandbox Violation Vulnerability
Thu 4. Dec 2008 18:18 ZDI-08-079: Trillian AIM Plugin Malformed XML Tag Heap Overflow Vulnerability
Thu 4. Dec 2008 18:18 ZDI-08-078: Trillian IMG SRC ID Memory Corruption Vulnerability
Thu 4. Dec 2008 18:17 ZDI-08-077: Trillian AIM IMG Tag Parsing Stack Overflow Vulnerability
Thu 4. Dec 2008 17:35 iDefense Security Advisory 12.04.08: Sun Java JRE TrueType Font Parsing Integer Overflow Vulnerability
Thu 4. Dec 2008 17:29 [USN-687-1] nfs-utils vulnerability
Thu 4. Dec 2008 15:15 [ MDVSA-2008:237 ] apache2
Thu 4. Dec 2008 17:00 iDefense Security Advisory 12.04.08: Sun Java JRE Pack200 Decompression Integer Overflow Vulnerability
Thu 4. Dec 2008 16:39 iDefense Security Advisory 12.04.08: Sun Java Web Start GIF Decoding Memory Corruption Vulnerability
Thu 4. Dec 2008 13:33 Joomla Component mydyngallery
Thu 4. Dec 2008 14:41 iDefense Security Advisory 12.04.08: Sun Java JRE TrueType Font Parsing Heap Overflow Vulnerability
Thu 4. Dec 2008 10:59 [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities
Thu 4. Dec 2008 09:26 [SECURITY] [DSA 1680-1] New clamav packages fix potential code execution
Thu 4. Dec 2008 08:39 Advisory 06/2008: PHP ZipArchive::extractTo() Directory Traversal Vulnerability
Wed 3. Dec 2008 20:13 CVE-2008-2086: Java Web Start File Inclusion via System Properties Override
Wed 3. Dec 2008 21:16 [ MDVSA-2008:236 ] vim
Thu 4. Dec 2008 15:46 [UPRSN] Ubuntu Privacy Remix 8.04r1 fixes security issues
Thu 4. Dec 2008 07:51 DDIVRT-2008-18 Orb Denial of Service