<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>23 Nov  2009 19:49:13 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>CORE-2009-0910: Autodesk Maya Script Nodes Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:43:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70887</link>
</item><item>
<title>CORE-2009-0909: Autodesk 3DS Max Application Callbacks Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:42:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70886</link>
</item><item>
<title>CORE-2009-0908: Autodesk SoftImage Scene TOC Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:41:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70885</link>
</item><item>
<title>[SECURITY] [DSA 1938-1] New php-mail packages fix insufficient input sanitising</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>22 Nov  2009 23:40:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70884</link>
</item><item>
<title>Fwd: ICMPv4/IP fuzzer prototype.</title>
<description>Hell no random.randrang -&amp;gt; randrange(_) rtfm. and yeah u&amp;#039;r welcome.  2009/11/23 Andrew Farmer &amp;lt;andfarm@gmail.com&amp;gt; On 22 Nov 2009, at 19:48, lauren</description>
<pubDate>22 Nov  2009 22:09:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70882</link>
</item><item>
<title>[Bkis-13-2009] e107 Multiple Vulnerabilities</title>
<description>[Bkis-13-2009] e107 Multiple Vulnerabilities 1. General Information e107 is a free content management system (CMS) written in PHP language and is av</description>
<pubDate>22 Nov  2009 21:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70880</link>
</item><item>
<title>ICMPv4/IP fuzzer prototype.</title>
<description>Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html Enjoy.</description>
<pubDate>22 Nov  2009 19:48:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70879</link>
</item><item>
<title>Climategate: how the MSM reported the greatest scandal in modern science - Telegraph Blogs</title>
<description>hackers providing a public service...... http://blogs.telegraph.co.uk/news/jamesdelingpole/100017451/climategate-how-the-msm-reported-the-greatest-sc</description>
<pubDate>22 Nov  2009 14:44:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70878</link>
</item><item>
<title>Millions of PDF invisibly embedded with your internal disk paths</title>
<description>Millions of PDF invisibly embedded with your internal disk paths ---------------------------------------------------------------- I found an interest</description>
<pubDate>22 Nov  2009 12:14:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70876</link>
</item><item>
<title>HITB Security Conference 2010 Dubai Call for Papers</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The Call for Papers for HITB Security Conference 2010 Dubai is now open! Talks that are more technical</description>
<pubDate>22 Nov  2009 06:13:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70875</link>
</item><item>
<title>Vulnerabilities in plugins for WordPress</title>
<description>Hello Full-Disclosure! I want to tell you about different vulnerabilities in plugins for WordPress. About some of them there were posts to Bugtraq li</description>
<pubDate>21 Nov  2009 13:25:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70874</link>
</item><item>
<title>[ MDVSA-2009:302 ] php</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>21 Nov  2009 08:08:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70872</link>
</item><item>
<title>[SECURITY] [DSA 1937-1] New gforge packages fix cross-site scripting</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>20 Nov  2009 21:30:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70873</link>
</item><item>
<title>[ MDVSA-2009:301 ] kernel</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>20 Nov  2009 16:29:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70870</link>
</item><item>
<title>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability</title>
<description>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09</description>
<pubDate>20 Nov  2009 15:15:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70869</link>
</item><item>
<title>VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -----------------------------------------------------------------------          VMware Sec</description>
<pubDate>20 Nov  2009 12:56:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70867</link>
</item><item>
<title>Pussy and the right to free speech.</title>
<description>This whole thing is ridiculous. Kurt Greenbaum is an idiot. What kind of question is that in the first place? Only and idiot would post â€œwhatâ€</description>
<pubDate>20 Nov  2009 11:10:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70866</link>
</item><item>
<title>PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>Description ------------ PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we&amp;#039;ve reported on 27 Oct</description>
<pubDate>20 Nov  2009 04:03:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70864</link>
</item><item>
<title>n3td3v / Andrew Wallace&amp;#039;s psychological profile</title>
<description>Earlier this year, a very well educated FD member posted the psychological profile of Mr. Wallace. (Found here: http://seclists.org/fulldisclosure/200</description>
<pubDate>19 Nov  2009 19:40:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70863</link>
</item><item>
<title>SecurityReason: KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz</description>
<pubDate>19 Nov  2009 16:26:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70860</link>
</item><item>
<title>SecurityReason: Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ Opera 10.01 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and sp</description>
<pubDate>19 Nov  2009 16:25:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70859</link>
</item><item>
<title>SecurityReason: K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and</description>
<pubDate>19 Nov  2009 16:23:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70858</link>
</item><item>
<title>SecurityReason: SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz an</description>
<pubDate>19 Nov  2009 16:17:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70857</link>
</item><item>
<title>Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>I smell a lawsuit coming on for our friend Greenbaum. &amp;quot;ReadWriteWeb has an article up today discussing an incident in which a school employee lost hi</description>
<pubDate>19 Nov  2009 12:38:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70852</link>
</item><item>
<title>Auto Manager admin.cgi Multiple Field XSS</title>
<description>vendor: interactivetools.com, inc., http://www.interactivetools.com/products/automanager/ product: Auto Manager version: 2.52 script: admin.cgi fields</description>
<pubDate>19 Nov  2009 00:03:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70845</link>
</item>
</channel>
</rss>
