<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Webremixed Articles for tags: vulnerabilities</title>
    <link>http://www.webremixed.info/</link>
    <description>Aggregation of tags: vulnerabilities</description>
    <dc:creator>Webremixer</dc:creator>
    <item>
      <title>Bugtraq: [ MDVSA-2012:013 ] mozilla</title>
      <link>http://www.securityfocus.com/archive/1/521496</link>
      <description>[ MDVSA-2012:013 ] mozilla</description>
      <pubDate>Fri, 03 Feb 2012 23:08:13 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521496</guid>
      <dc:date>2012-02-03T23:08:13Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability</title>
      <link>http://www.securityfocus.com/archive/1/521481</link>
      <description>ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 22:53:13 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521481</guid>
      <dc:date>2012-02-03T22:53:13Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: RFC 6528 on Defending against Sequence Number Attacks</title>
      <link>http://www.securityfocus.com/archive/1/521480</link>
      <description>RFC 6528 on Defending against Sequence Number Attacks</description>
      <pubDate>Fri, 03 Feb 2012 22:38:13 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521480</guid>
      <dc:date>2012-02-03T22:38:13Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [SECURITY] [DSA 2403-1] php5 security update</title>
      <link>http://www.securityfocus.com/archive/1/521479</link>
      <description>[SECURITY] [DSA 2403-1] php5 security update</description>
      <pubDate>Fri, 03 Feb 2012 22:23:13 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521479</guid>
      <dc:date>2012-02-03T22:23:13Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4514</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4514</link>
      <description>The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4514</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4875</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4875</link>
      <description>Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4875</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4876</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4876</link>
      <description>Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4876</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4877</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4877</link>
      <description>HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4877</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4878</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4878</link>
      <description>Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4878</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4879</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4879</link>
      <description>miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not properly handle URIs beginning with a 0xfa character, which allows remote attackers to read data from arbitrary memory locations or cause a denial of service (application crash) via a crafted POST request.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4879</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51830</link>
      <description>PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51830</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability</title>
      <link>http://www.securityfocus.com/bid/29519</link>
      <description>C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/29519</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4513</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4513</link>
      <description>Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allow user-assisted remote attackers to execute arbitrary code via a crafted project file, related to the HMI web server and runtime loader.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4513</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4512</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4512</link>
      <description>CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4512</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4511</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4511</link>
      <description>Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4510.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4511</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Joomla! Multiple Information Disclosure Vulnerabilities</title>
      <link>http://www.securityfocus.com/bid/51857</link>
      <description>Joomla! Multiple Information Disclosure Vulnerabilities</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51857</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51752</link>
      <description>Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51752</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51754</link>
      <description>Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51754</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-0447 Information Disclosure Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51757</link>
      <description>Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-0447 Information Disclosure Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51757</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: project-open 'account-closed.tcl' Cross Site Scripting Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51842</link>
      <description>project-open 'account-closed.tcl' Cross Site Scripting Vulnerability</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51842</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4508</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4508</link>
      <description>The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime generates predictable authentication tokens for cookies, which makes it easier for remote attackers to bypass authentication via a crafted cookie.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4508</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4509</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4509</link>
      <description>The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime has an improperly selected default password for the administrator account, which makes it easier for remote attackers to obtain access via a brute-force approach involving many HTTP requests.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4509</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4510</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4510</link>
      <description>Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4511.</description>
      <pubDate>Fri, 03 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4510</guid>
      <dc:date>2012-02-03T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [ MDVSA-2012:012 ] apache</title>
      <link>http://www.securityfocus.com/archive/1/521467</link>
      <description>[ MDVSA-2012:012 ] apache</description>
      <pubDate>Thu, 02 Feb 2012 23:12:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521467</guid>
      <dc:date>2012-02-02T23:12:52Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: GLSA (Gentoo Linux Security Advisory) publication changes</title>
      <link>http://www.securityfocus.com/archive/1/521473</link>
      <description>GLSA (Gentoo Linux Security Advisory) publication changes</description>
      <pubDate>Thu, 02 Feb 2012 22:57:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521473</guid>
      <dc:date>2012-02-02T22:57:52Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [security bulletin] HPSBMU02739 SSRT100280 rev.1 - HP Data Protector Media Operations, Remote Execution of Arbitrary Code</title>
      <link>http://www.securityfocus.com/archive/1/521472</link>
      <description>[security bulletin] HPSBMU02739 SSRT100280 rev.1 - HP Data Protector Media Operations, Remote Execution of Arbitrary Code</description>
      <pubDate>Thu, 02 Feb 2012 22:42:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521472</guid>
      <dc:date>2012-02-02T22:42:52Z</dc:date>
    </item>
    <item>
      <title>Bugtraq: [CAL-2012-0004] opera array integer overflow</title>
      <link>http://www.securityfocus.com/archive/1/521471</link>
      <description>[CAL-2012-0004] opera array integer overflow</description>
      <pubDate>Thu, 02 Feb 2012 22:27:52 GMT</pubDate>
      <guid>http://www.securityfocus.com/archive/1/521471</guid>
      <dc:date>2012-02-02T22:27:52Z</dc:date>
    </item>
    <item>
      <title>Vuln: PHP CVE-2012-0057 Security Bypass Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51806</link>
      <description>PHP CVE-2012-0057 Security Bypass Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 11:28:58 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51806</guid>
      <dc:date>2012-02-02T11:28:58Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0314</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0314</link>
      <description>Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0314</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0976</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0976</link>
      <description>Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter.  NOTE: some of these details are obtained from third party information.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0976</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0977</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0977</link>
      <description>Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0977</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0978</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0978</link>
      <description>Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0978</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0979</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0979</link>
      <description>Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0979</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0980</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0980</link>
      <description>SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0980</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0975</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0975</link>
      <description>Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0975</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-2393</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2393</link>
      <description>The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2393</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-4563</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4563</link>
      <description>The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4563</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2010-4562</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4562</link>
      <description>Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4562</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Apache Tomcat Hash Collision Denial Of Service Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51200</link>
      <description>Apache Tomcat Hash Collision Denial Of Service Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51200</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Apache Tomcat Request Object Security Bypass Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51442</link>
      <description>Apache Tomcat Request Object Security Bypass Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51442</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: Apache Tomcat Parameter Handling Denial of Service Vulnerability</title>
      <link>http://www.securityfocus.com/bid/51447</link>
      <description>Apache Tomcat Parameter Handling Denial of Service Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/51447</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2011-4791</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4791</link>
      <description>DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4791</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0981</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0981</link>
      <description>Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php.  NOTE: Some of these details are obtained from third party information.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0981</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0982</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0982</link>
      <description>SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0982</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>CVE-2012-0983</title>
      <link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0983</link>
      <description>SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0983</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
    <item>
      <title>Vuln: WebKit 'Node.normalize' Method Remote Code Execution Vulnerability</title>
      <link>http://www.securityfocus.com/bid/40665</link>
      <description>WebKit 'Node.normalize' Method Remote Code Execution Vulnerability</description>
      <pubDate>Thu, 02 Feb 2012 00:00:00 GMT</pubDate>
      <guid>http://www.securityfocus.com/bid/40665</guid>
      <dc:date>2012-02-02T00:00:00Z</dc:date>
    </item>
  </channel>
</rss>


