Debian Security Advisory DSA 483-1 - The scripts mysqld_multi and mysqlbug in MySQL allow local users to overwrite arbitrary files via symlink attacks.
bee19f598e2eea511dddfaacc16b600f1e9d73c78441f166dabd4562e60f75f4
SuSE Security Advisory SuSE-SA:2004:008 - Two vulnerabilities have been discovered in CVS that can be exploited by malicious servers to compromise clients and by malicious users to retrieve arbitrary files from servers. Versions below 1.11.15 are affected.
634465bf9d0bf7d62e31bf17a6f6268ae520d0e80fc702c299ae1cadf2f0691f
Debian Security Advisory DSA 485-1 - Max Vozeler discovered two format string vulnerabilities in ssmtp, a simple mail transport agent. Untrusted values in the functions die() and log_event() were passed to printf-like functions as format strings. These vulnerabilities could potentially be exploited by a remote mail relay to gain the privileges of the ssmtp process (including potentially root).
dbb0ababf09e05e0182a9e13cbee4381b08e05056c33cc77cc8e03612c4fa654
Debian Security Advisory DSA 484-1 - Steve Kemp discovered a vulnerability in xonix, a game, where an external program was invoked while retaining setgid privileges. A local attacker could exploit this vulnerability to gain gid games.
95a2e6f0eb8456498067248b6ff0d47a81a32f4f950f5e93366646d58927a210
LiLith is a tool written in Perl to audit web applications. This tool analyses webpages and looks for html form tags, which often refer to dynamic pages that might be subject to SQL injection or other flaws. It works much like an ordinary webspider.
9cb6986b797426175a1291e3b23e30adf1943f258f3fe82b539799c2a65398c9
FTGateOffice/FTGatePro version 1.2 suffers from path exposure, cross site scripting, and validation errors.
eba70e4d82f4cdab0151b0d9a32d2ad8b4275d178450f866cc85fb930b059524
Hilarious write up on how to ensure a job for life. Entitled How To Write Unmaintainable Code.
072640834400115a882c5d33808600c3886403df3eac4bd1952275b7a1bd169b
Cross site scripting bugs exist in PHP-Nuke versions 6.x through 7.2.
0da992c6bc892cac7f6b99a84635a87953f1c508e250c836c2ccfb9e521244ce
Remote denial of service exploit for IIS SSL vulnerability documented in MS04-011.
f960c76a400cb9cfcd8e6e70117716d00cd34051375ddc7429703a7e73802833
Proof of concept exploit for the WinZip32 MIME Parsing Overflow. Tested against WinZip 8.1 on Windows XP SP1 and Windows 2000 SP1. Instructions for use are included.
8a7e5cb801e4ff9423fec6d0c994638590a6f7103e548f3888181d78cc1db3c2